Operational guide / Updated September 2026 / 9 min read

What a control system does not show you on an electrolyser plant

By Bhavik Modi / CEO & Co-Founder LinkedIn

Instrumentation and process engineering, electrolyser technology and machine learning, with experience at Siemens, L&T, Mitsubishi and Newtrace.

A distributed control system keeps a plant inside its limits and stops it safely when it cannot. It was never designed to explain why specific energy consumption moved over a quarter, or which of three stacks should carry the load when renewable supply halves in the afternoon. Those are different questions and they need different measurements. Five gaps sit in between, and each one is a measurement and attribution problem rather than a control problem.

Green HydrogenElectrolyzer AnalyticsPredictive MaintenancePhysics-driven AI

The plant is instrumented for control, not for explanation

A distributed control system exists to hold a plant inside its operating limits and to shut it down safely when it cannot. It is good at that, and nothing here suggests replacing it.

It was not built to answer a different class of question. Why did specific energy consumption move by two per cent over a quarter. Which of three stacks, each in a different state of health, should take the load when renewable supply halves at four in the afternoon. Whether the deviation on stack two is the stack, the rectifier, the cooling circuit or the measurement.

Those questions need measurements the control system was never specified to make, and attribution logic it was never asked to carry. Five gaps open up in between. Each one is set out below with what it looks like on a plant that is running normally, and what closing it requires.

One: nothing reports what is happening inside the cell

Control systems aggregate at stack level. Cell voltage distribution, the measurement that tells you whether a problem is one cell or the whole population, is rarely instrumented at all, and several of the variables that decide the operating decision are not measured on any plant.

On a running plant. Stacks operate slightly outside their best envelope. Current density a little high, temperature a little off the optimum, electrolyte chemistry drifting. No alarm fires, because alarms are rationalised around gross faults rather than subtle drift. Degradation accumulates quietly across the fleet, and the first visible sign is a stack-level efficiency figure that has already moved.

What closes it. Measurement at the level where the physics happens, and a model that estimates the states no sensor reports. The diagnostic reasoning is set out in electrolyser diagnostics and the modelling side in what a digital twin of an electrolyser models. The related question of where to run, rather than what has gone wrong, is covered in why an electrolyser uses more kWh per kg than the datasheet says.

Two: the damage is permanent, and the monitoring is not early

Most electrolyser degradation is irreversible. A thinned membrane does not recover, contamination effects are not undone by running cleaner, and efficiency lost to a fault is carried for the remaining life of the asset. That changes what monitoring is for. On rotating equipment a late warning costs an outage; here it costs a permanent shift in the plant's operating curve.

On a running plant. Membrane behaviour drifts in one part of the stack. Conventional monitoring stops at stack-level aggregates, so nothing surfaces. By the time a purity reading crosses its alarm threshold, the condition behind it has been developing for some time and the response options have narrowed to the ones available at the threshold.

What closes it. A trend that moves while the reading is still inside its normal band, and a clear statement of what can be done inside the warning it buys. Your purity alarm is a threshold, not a warning sets out that case for crossover specifically, diagnosing membrane thinning covers which signals move and in what order, and start-stop cycling degradation covers the duty that drives it.

Three: operations and finance are in different systems

Plant data sits in the historian. Cost sits in the ERP. Certification evidence sits in spreadsheets. Connecting them is manual, retrospective and done by somebody with other work to do, which means the connection is made at reporting time rather than at decision time.

On a running plant. Renewable supply drops to half in the afternoon. Three stacks show different degradation states. Nothing on any screen answers whether to optimise for production this hour, for stack life over the year, or for cost per kilogram across the contract. The decision gets made on judgement, which is often the right decision, and there is no record of what was chosen, why, or how it turned out.

What closes it. A live energy balance expressed as a cost per kilogram rather than as an efficiency percentage, and a degradation trend expressed as a replacement date and a reserve. That is the same arithmetic a lender applies from the other side, described in remaining useful life and reporting to lenders after COD.

Four: root cause runs through the OEM

When something moves, the diagnosis usually starts with a call to the equipment supplier. That is reasonable, since they know the machine. It also means the plant has no independent position, and the wait is time the plant runs without an answer.

On a running plant. A fault triggers in the early hours. The call connects in the morning, and root cause lands on the second day. Through that window the plant is operating on an unexplained deviation. When a warranty or availability conversation follows, the operator is arguing from the supplier's own data.

What closes it. Independent measurement and independent attribution, read-only, on the plant's side of the boundary. What that costs and what it does not touch is set out in reading plant data without modifying the control system, the contractual position in does connecting to a DCS void the OEM warranty, and the evidence a guarantee conversation actually turns on in electrolyser performance guarantees.

Five: certification is a separate, retrospective exercise

Evidence for a certification claim is typically assembled per cycle, by hand, from systems that were not designed to produce it together. That works until an auditor picks a period the plant cannot reconstruct.

On a running plant. Interval data was kept as monthly totals because nothing needed more. Clocks on the electricity meter, the production meter and the historian were never synchronised, so the reconciliation does not close. The power purchase agreement is silent on who owns the renewable attributes. None of that is visible while the plant is running well, and none of it can be repaired after the period ends.

What closes it. The record has to be a by-product of operating rather than a project that starts when the audit is booked. Which evidence each regime actually asks for is in green hydrogen certification: RFNBO, 45V and GHCI, and what an auditor samples is in chain of custody audit evidence.

What the five have in common

None of them is a control problem, which is why adding screens to the control system does not close any of them. All five are measurement and attribution problems: something is not measured where it matters, or it is measured and never tied to a cause, a cost or a record.

That is the layer Yunify is built to be. It runs on plant-resident hardware, reads from the existing PLC, DCS or SCADA over standard protocols without modifying them, and keeps the data inside the plant boundary. Multi-physics models of the electrochemistry, thermodynamics and process behaviour give it a statement of how the plant should behave, and the machine learning works on the difference between that and what the plant is actually doing. Cell-level measurement fills the gap where the stack signals live. The same operating record produces the tamper-evident chain of custody a certification claim needs. The inference and traceability methods behind it are patent pending.

Indian green hydrogen is moving from demonstration towards gigawatt scale, and Yunify will be running at that scale before long. The argument for putting this layer in at pilot is not that a pilot has these problems badly. It is that every fault signature and operating rule learned at pilot is the playbook for the commercial plant, and arriving at scale with a plant your own team already understands is worth considerably more than arriving with a larger version of a plant nobody has explained yet.

Questions teams ask

Frequently asked questions

Does this mean replacing the control system?

No. The control system holds the plant inside its limits and stops it safely, and an analytics layer should never be in that path. This sits alongside it, reading through an interface the plant already exposes, and writing nothing back. The boundary is set out in reading plant data without modifying the control system.

Why is cell-level measurement worth the hardware?

Because a stack-level aggregate hides the distribution. A small number of substantially degraded cells barely moves the average, while the spread is what decides whether the action is a local intervention or a planned replacement. Cell voltage distribution helps distinguish a stack problem from a system problem when it is corroborated with flow, temperature and measurement quality.

Is this predictive maintenance?

Partly, and the electrochemical half of it does not resemble predictive maintenance on rotating equipment. There are no bearings and no vibration signature. What replaces them is voltage behaviour, crossover trend, thermal distribution and electrolyte condition, interpreted against a model of what the stack should be doing at that load.

How much of this needs new instrumentation?

Less than most teams expect for the balance of plant, which is usually already instrumented and already in the historian, and more than most expect at cell level, which is rarely instrumented at all. The honest answer for a specific plant comes out of a tag review rather than a general rule.

Where does the certification evidence come from?

From the same operating data, recorded at interval resolution on a synchronised clock and retained. That is why certification belongs in this list rather than in a separate programme: the measurement decisions that make an audit possible are the same ones that make diagnosis possible, and both have to be made before the plant produces.