14.3 FAT, SAT & Final Acceptance Testing Criteria
Key Takeaways
- Factory acceptance testing (FAT) proves a staged or factory system against written scripts before shipment; it does not replace site testing.
- Site acceptance testing (SAT) proves the installed system on this site, with owner witness and recorded results, against the same design intent.
- Life-safety and high-security portals are typically tested at 100 percent; sampling interior identical readers does not excuse sampling delayed-egress or fire-release interfaces.
- Unresolved life-safety items—maglock fire release, delayed egress, inoperative egress hardware, elevator-recall conflicts—block final acceptance even if cameras look sharp.
- Substantial completion is not a waiver of SAT, fail criteria, or remaining life-safety defects, and it is not by itself final system acceptance.
Factory acceptance testing (FAT), site acceptance testing (SAT), and final system acceptance are three different contractual proofs. Independent OpenExamPrep teaching for published PSP Domain 3 Task 3 knowledge is that mixing them is how an owner signs for a warehouse demo and occupies a building whose maglocks still ignore the fire alarm. This section is the criteria language: what is tested, where, by whom, against which script, and what happens when a result is a fail.
FAT is not SAT, and neither is automatic final acceptance
FAT happens before the system is the owner’s problem on this floor plate. Typical FAT is a staged head-end, a representative door kit, simulated inputs, failover, reporting, and software version checks at the vendor’s facility or a staging room. FAT is valuable for custom integration, uncommon software loads, and owner witness of a workflow before crates ship. FAT is a ship hold when scripts fail. FAT is not a photograph of a brochure rack. Commodity cameras with no custom code may have little FAT beyond production testing; an integrated ACS/VSS/IDS head-end with SOC maps usually deserves a real FAT. Passing FAT means the staged system met the scripts in that room. It does not mean the homeruns, hardware coordination, or elevator recall on this site work.
SAT happens on the installed system: these doors, these cameras, this fire-alarm interface, this elevator, this SOC. SAT uses test scripts with numbered steps, expected results, and a pass/fail rule written before the test, not invented when a lock sticks. SAT is where installation quality from 14.1 and commissioning integration from 14.2 become contractual evidence. A start-up sheet that says “Door 4 OK” with no expected result is not a script.
Final system acceptance is the owner’s (or the contractually designated representative’s) written decision that the system meets the contract, punch items that were allowed to remain are listed, training and close-out from 14.4 are complete enough to occupy, and remaining work is warranty or listed exceptions—not hidden life-safety defects. Final acceptance can follow SAT immediately on a small job. On a large job it follows punch closure, training, as-builts, and often a burn-in period. SAT pass plus a handshake is not automatically final acceptance if the contract listed other deliverables.
| Proof | Where | What it can show | What it cannot show |
|---|---|---|---|
| FAT | Factory or staging | Software, I/O logic, failover, sample devices against scripts | This site’s pathways, hardware stacks, AHJ interfaces |
| SAT | Installed site | This system, these portals, these integrations, owner-witnessed | That punch, training, passwords, and as-builts are complete |
| Final acceptance | Contract close | Owner takes the system as meeting the agreement | A waiver of remaining life-safety fails |
Scripts, sampling versus 100 percent, fail criteria, witness, records
Test scripts are the acceptance instrument. Each script names the device or interface, preconditions (door closed, schedule in night mode, fire panel normal), action (present a revoked badge, open without grant, trip a pull station in a coordinated fire test), expected result (deny, forced-open within n seconds, maglock release, camera call-up), and recording fields (time, tester, witness, pass/fail, notes). Scripts come from the specification and the commissioning plan, not from memory. If the specification required encrypted reader traffic, the script includes a supervision or crypto check, not only a green LED.
Sampling versus 100 percent is a written risk decision, not a tired tester’s shortcut. Life-safety interfaces and high-security portals are 100 percent: every delayed-egress leaf, every maglock fire-release, every stair tower, every vault, every elevator recall related to security outputs. Identical interior office readers on the same typical may be sampled if the specification said so and the sample fails trigger 100 percent of that typical. Sampling ten percent of delayed-egress doors because they “are all the same model” is how one miswired leaf traps people. Exam stems that offer sampling as a way around life-safety testing are wrong.
Fail criteria must exist before SAT starts. Examples: any life-safety interface fail fails SAT; more than a stated percentage of functional (non-life-safety) fails fails SAT or forces a retest window; a single forced-open that does not alarm fails that portal and its typical until retested. “We’ll see how it feels” is not a criterion. Cosmetic issues (a scratched housing) go to punch with a severity class. They do not get relabeled as SAT fails to punish a contractor, and they do not get used to paper over a maglock that will not release.
Owner witness means the owner’s designated representative—often security operations, facilities, and, for life safety, sometimes the AHJ or fire-protection engineer—is present for the scripts that matter, or reviews recorded evidence the contract allowed. Vendor-only SAT with a selfie video is demonstration, not owner acceptance. Witnesses initial the script. If the witness is “whoever was in the lobby,” you do not have an owner witness.
Recording results is part of the test, not a lawsuit hobby. Keep dated sheets or an electronic log keyed to device IDs, expected versus actual, initials, and deficiency numbers that feed the punch list. If it is not recorded, it will be re-argued at occupancy. Record failures honestly. A tester who writes “pass” on a door that needed two tries taught the SOC that the log is fiction.
Worked hospital: FAT at the vendor showed map call-up on a staged Door 4. SAT on site found the real Door 4 maglock still energized when the fire alarm was tested. That is a SAT fail and a block on acceptance, not a punch-list paint item to be “caught in warranty.” The FAT pass remains true and irrelevant to the fire-release defect.
What substantial completion is not
Substantial completion is a construction-administration idea: the work is sufficiently complete that the owner can occupy or use it for its intended purpose, with remaining work as a punch list. Security practitioners get hurt when someone treats that certificate as final system acceptance or as permission to occupy with unresolved life-safety items. It is not.
Substantial completion is not:
- A waiver of SAT scripts or recorded results.
- Permission to occupy while maglock fire release, delayed egress, stair locks, or elevator recall still fail.
- A finding that sampling 10 percent of life-safety doors was enough.
- A substitute for owner witness.
- Final acceptance of configuration, training, passwords, or as-builts that the contract still requires.
- A statement that “the cameras look sharp, so the system is done.”
If an architect or owner’s project manager issues substantial completion while a delayed-egress leaf is inoperative, the physical security professional’s job is to document the life-safety block, notify the responsible parties, and refuse to treat that opening as accepted. Occupancy pressure is real. It does not rewrite the fire code or the specification’s shall-language on release.
Unresolved life-safety items block acceptance. That sentence is the exam’s bright line. Cosmetic punch can remain. Incomplete nice-to-have analytics can remain if the contract allowed it. A maglock that does not release on fire alarm, a door that does not let people out, a security output that inhibits elevator recall, or an inoperative egress device does not remain. Those items stop final acceptance and should stop occupancy of the affected area. Warranty language is for latent defects after a proper pass, not for known traps left in the path of egress.
The professional SAT close is a bound (or electronic) book: scripts, witness names, fail list classified as life-safety versus functional versus cosmetic, and a clear recommendation—accept, accept with listed exceptions that are not life-safety, or do not accept. Anything vaguer is how “substantial completion” gets used as a magic wand.
Read the mermaid left to right as a delivery chain, not as five labels for one afternoon. FAT can stop a shipment. SAT can stop occupancy. Punch without life-safety closure cannot proceed to a honest acceptance. Training and configuration turnover belong before the owner is told the system is theirs. If a stem skips from a factory demo to “the building is substantially complete, accept it,” look for the missing SAT, the missing witness, and the life-safety item still open.
Which description correctly distinguishes FAT, SAT, and final acceptance?
SAT is otherwise favorable, but one maglock does not release on fire-alarm test and one delayed-egress leaf is inoperative. Cameras look sharp. What is the correct acceptance posture?
An owner’s project manager cites substantial completion and asks security to sign final acceptance without completed SAT scripts. What is the most accurate statement?