Water management programme structure

A water management programme under Standard 188-2021 connects responsibility, system knowledge, hazard analysis, operational control, review, documentation and communication. Validation and verification are distinct activities and are not interchangeable.

Overview

ASHRAE Standard 188, published by ASHRAE, a registered mark of that society, structures building water risk management as a continuing organisational programme. Standard 188-2021, titled Legionellosis: Risk Management for Building Water Systems, requires more than a collection of maintenance procedures. It connects responsibility, system knowledge, hazard analysis, operational control, review, documentation and communication so that the organisation can show both what it intended to do and what actually occurred.

Programme team and composition

The programme begins with a designated team. Its composition should reflect the building, the relevant water systems and the organisation responsible for them. Suitable participation may come from facilities management, engineering, maintenance, building management and other functions able to contribute system knowledge or decision authority.

Team membership should not be ceremonial. The programme needs people who understand how the systems are configured, how the building is used and how operational changes are authorised. It also needs authority to obtain records, require corrective action and communicate matters to those responsible for affected systems.

External expertise can support the team where specialist knowledge is needed. However, appointing a contractor does not by itself create an effective programme. The building organisation still needs defined responsibility for accepting recommendations, coordinating access, reviewing records and ensuring that actions are completed.

Roles should be documented. The record should distinguish programme leadership, technical input, routine monitoring, record control, review and communication. Named responsibility reduces uncertainty when an abnormal result, missed task or system change requires a prompt decision.

Description of building water systems

The programme must describe the building water systems within its scope. The description establishes a shared understanding of what is being managed and prevents decisions from relying on incomplete personal knowledge. It should be detailed enough to support analysis without becoming an unmanageable reproduction of every construction drawing.

Existing drawings can provide a starting point, but the programme team must consider whether they represent the installed and operating systems. Refurbishment, tenant alterations and maintenance changes can leave formal drawings behind actual conditions. A controlled programme description should therefore reflect verified system knowledge.

The description also identifies boundaries and interfaces. Shared plant, landlord systems, tenant systems and independently managed equipment may involve different responsible parties. The programme must make those divisions visible so that no relevant section is omitted through an assumption that another party controls it.

The description should be reviewed when the building changes. A document that accurately represented the system at programme launch may become misleading after alterations. Change control keeps the analysis connected to the real building.

The system flow diagram

A flow diagram provides a functional representation of the systems covered by the programme. Its purpose is to show how water enters, moves through, is stored or conditioned within, and leaves the defined system. It supports analysis by making connections and branches easier to understand than they would be in narrative text alone.

The diagram is not necessarily a construction drawing. It should contain sufficient information for the programme team to identify relevant components, flow paths and control locations. Excessive detail can obscure the management purpose, while insufficient detail can conceal important branches or interfaces.

The diagram should be checked against the building. Where records conflict with observed conditions, the discrepancy needs to be resolved or recorded. An unverified diagram copied from an earlier manual may create false confidence and direct monitoring towards locations that no longer represent the system.

Standard 188 requires the programme to develop its own system representation. Reproducing a generic flowchart or a publisher's form would not meet that need. The diagram must describe the particular building and remain controlled as part of its documentation.

Analysis of hazardous conditions

Using the system description and flow diagram, the programme team analyses where hazardous conditions may occur. The analysis considers how the system is designed and operated, where control is necessary and how departures could develop. It is a structured decision process rather than a general statement that all water systems require equal attention.

The analysis should record its reasoning. A list of locations without an explanation provides little support for later review, particularly after personnel change. The programme needs enough context to show why a location matters, what condition is being controlled and how the selected control relates to that condition.

Technical information may come from Guideline 12-2023, titled Managing the Risk of Legionellosis Associated with Building Water Systems, and from other competent sources. The guideline can assist implementation, but the programme team remains responsible for applying technical judgement to the actual system.

The organism, its behaviour, sampling and treatment are subjects for separate specialist resources. Within the programme structure, the emphasis is on documenting how relevant hazardous conditions are identified, controlled and reviewed.

Control locations and control limits

The analysis leads to the identification of locations where control can be applied or observed. Each control location should have a defined purpose and a connection to the system analysis. Selecting locations simply because they are easy to reach may leave the programme unable to demonstrate control of the conditions it identified.

A control limit defines the boundary of acceptable operation at that location. The programme must state the limit clearly enough for the person monitoring it to decide whether the condition is acceptable. It must also explain what action follows when the limit is not met.

Control limits are building- and system-specific decisions made within the applicable technical framework. No generic value can replace the programme team's assessment of the system, operating conditions and selected control strategy. Standard 188 should be consulted directly for the management requirements, with suitable technical guidance used to support selection.

The programme should also identify responsibility for changing a limit. An informal adjustment made to accommodate repeated failures can undermine the control strategy. Revisions need technical justification, approval and a documented update to the programme.

Monitoring and records

Monitoring shows whether the selected controls remain within their defined limits. The programme should state what is monitored, where it is monitored, who performs the task, how the result is recorded and what happens when the required activity cannot be completed.

A record should be understandable after the event. It needs to identify the relevant location or asset, the observation, the result, the person responsible and any follow-up. Ambiguous entries make it difficult to distinguish a satisfactory condition from an incomplete check.

Monitoring frequency and technique must be selected through the programme's technical process and are not reproduced here. Whatever approach is chosen, it should be practicable and integrated into routine operations. A theoretically comprehensive schedule that is repeatedly missed does not provide effective control.

Records also support trend review. An isolated result may appear acceptable while a sequence reveals deterioration, recurring instability or repeated dependence on corrective action. The programme team should use records as management information, not merely as evidence that a form was completed.

Corrective action

When a control limit is not met, the programme needs a predetermined corrective-action process. The response should identify immediate responsibility, escalation, investigation, restoration of control and the records required to close the event.

Corrective action is not complete merely because the monitored condition later returns within its limit. The team should consider why the departure occurred, whether the response addressed its cause and whether similar conditions may exist elsewhere. Repeated departures can indicate that the control strategy or monitoring plan requires review.

The programme should distinguish a temporary operational response from a lasting system correction. Both may be necessary, but they serve different purposes. Records should show what was done, who authorised it and how completion was confirmed.

No treatment or disinfection method is described here. The standard's programme structure requires the organisation to define and document appropriate responses using competent technical input.

Verification and validation

Verification asks whether the programme is being implemented as written. It examines whether monitoring occurred, records were completed, corrective actions were followed, responsibilities were discharged and reviews took place. It is fundamentally a check on conformity with the established programme.

Validation asks whether the programme is effective in controlling the identified risk. A programme can be followed precisely yet still be ineffective if its analysis, control locations or limits are unsuitable. Validation therefore examines the adequacy of the programme's design and outcomes, not merely compliance with its procedures.

The terms are not interchangeable. Calling every review validation can conceal missed implementation, while calling every effectiveness assessment verification can reduce the review to a paperwork exercise. The programme should state which activity is being performed and what evidence supports its conclusion.

The method and evidence used for each activity depend on the programme and building. The distinction should remain visible in plans, meeting records, audit findings and revisions so that both implementation and effectiveness receive proper attention.

Documentation, communication and change

Programme documentation includes team responsibilities, system descriptions, flow diagrams, analysis, controls, monitoring records, corrective actions, reviews and revisions. These records form an operational history and allow later decisions to be understood in context.

Communication ensures that relevant information reaches those who operate, maintain, alter or manage the systems. A technically sound programme can fail if a contractor changes a component without notifying the team or if an operational departure is recorded but not escalated.

Change of use and refurbishment should trigger review. Altered occupancy, modified layouts, replaced plant, disconnected branches or new equipment can affect system boundaries and earlier analysis. The programme must be treated as a living management process rather than a handover document preserved unchanged.

Continuity becomes especially important when personnel change. Controlled records allow new team members to understand why controls were selected, how previous departures were resolved and which assumptions underpinned the programme. Documentation therefore protects organisational knowledge as well as demonstrating activity.

Edition references in UAE instruments

Edition years matter here more than they usually do, because UAE instruments reference these standards in two incompatible ways. Al Sa'fat, Dubai's green building system, whose Silver Sa'fa requirements are mandatory for new buildings, requires the latest edition of Standards 62.1, 62.2 and 170 and deliberately attaches no year, so the applicable requirements move as the standards are revised. Estidama's Pearl Building Rating System, Version 1.0 of April 2010, does the opposite: it names specific editions — the 2007 edition of Standard 62.1, the 2007 edition of Standard 62.2, the 2004 edition of Standard 55 and the 2007 edition of Standard 90.1 — so the requirements it imposes are frozen at those editions regardless of what has been published since. Dubai Municipality's Technical Guidelines for Indoor Air Quality for Healthy Life, Version 4 of 11 December 2024, references Standard 62.1 without giving an edition year. Anyone reading a requirement should therefore establish which instrument imposes it and whether that instrument names a year, before establishing what the current edition says.

Al Sa'fat §401.01 (2nd edition, January 2023) requires the latest edition and attaches no year — Estidama PBRS Version 1.0 (April 2010) names fixed editions

Is a flow diagram the same as a construction drawing?

No. A programme flow diagram is a functional representation designed to support system analysis and management. Construction drawings may provide useful source information, but the programme diagram should show the relevant flow paths, components, boundaries and control locations clearly enough for its specific purpose.

What happens when a control limit is not met?

The programme follows its defined corrective-action process. That process should allocate responsibility, require escalation where appropriate, restore control, investigate the cause and document completion. The exact technical response depends on the system and competent assessment.

What is the difference between verification and validation?

Verification confirms that the programme is being followed as written. Validation determines whether the programme is effective. Both are necessary because accurate completion of an unsuitable programme does not demonstrate effective risk management.

When should the programme be reviewed?

Review is needed at planned intervals and when material change occurs. Changes in use, system configuration, plant, responsibility or operating conditions may alter the original analysis. Personnel changes also require attention to handover, authority and access to controlled records.

This is an independent information resource. It is not affiliated with, endorsed by, or connected to ASHRAE. ASHRAE and the names of its standards are the trademarks of their respective owners and are used here only to identify the standards described.