Summary

  • The identity bridge is unusually clear: Canada’s federal corporate record assigns one corporation number to Automation Industrielle April Inc. from 1987 to 2001 and AIA automation Inc. thereafter; the same record shows a 2022 discontinuance, a legal mechanism that normally moves a corporation out of federal law rather than dissolving it.
  • Public procurement records place the exact Quebec contractor in potable-water electrical monitoring, wastewater pumping, filtration-plant computer migration, dam-gate control panels and engineering work. They demonstrate a real installed footprint, but not a complete inventory of every AIA project.
  • Excelpro’s 2021 acquisition preserved staff and customer agreements and began a staged brand transition. That provides a plausible successor support path, but plant owners still need their own source code, backups, drawings, licences, credentials, change history and acceptance evidence.
  • The durable risk is not simply an obsolete PLC. It is loss of the chain of custody around logic, safety functions, network settings and operator knowledge. A migration is defensible only when an owner can reconstruct the baseline, assess cyber and safety consequences, and prove equivalent operation under realistic conditions.

A fault at 2 a.m., years after the letterhead changed

Imagine a municipal operator arriving at a pumping station after an alarm. The motor is healthy, the wet well is rising, and the human-machine interface shows a status that does not agree with the field instrument. Inside the cabinet are a programmable logic controller, input and output modules, relays, a network switch and a neatly labelled terminal strip. The latest drawing bears an integrator’s old trading name. A laptop in a locked cupboard contains an engineering package, but nobody is certain whether its licence still activates. The last employee who understood the sequence retired.

The corporation named on the purchase order no longer appears as an active federal company.

This is a composite scenario, not a reported incident at an AIA installation. It is nevertheless the right way to read AIA’s record. Industrial automation is experienced at the moment a plant must diagnose, restore or change a running process—not when a corporate announcement is published. A company’s legal and commercial history matters because it affects whom an owner can call. The machine’s history matters more because it determines whether that call can produce a safe result.

The exact Quebec company in this article left enough public traces to make the problem concrete. Montréal disclosed AIA Automation work associated with continuous monitoring of emergency electrical substations and software for the city’s potable-water service in 2016. A later Montréal disclosure names a client workstation for an emergency-substation server in potable-water distribution. Thurso council records refer to work at a principal wastewater pumping station, a Windows 7-to-Windows 10 migration at a filtration plant, and a later filtration-plant invoice under the AIA name. Quebec’s environment ministry disclosed AIA’s assembly of control cabinets for gates at the Beaudet dam. Ormstown recorded engineering services at Station Dumas. These are not generic marketing categories; they are pieces of an installed-base archaeology assembled from public purchasing records. (Montréal, 2016, Montréal, 2019, Thurso, 2018, Thurso, 2020, Quebec environment ministry, 2019, Ormstown, 2018, Thurso, 2023)

Each installation can outlive the commercial wrapper around it. A control cabinet may operate for twenty years while its operating system, development software, network assumptions and vendor support status change several times. A plant may still possess the binary program that the controller executes but lack the commented source from which a competent engineer can understand it. It may have a drawing that represents the cabinet on commissioning day but not later field modifications. It may own the hardware while depending on an integrator’s account for licences, backups or remote access.

Those gaps are where routine support becomes forensic work.

The useful question is therefore not whether AIA “still exists” in ordinary speech. Federal registration, provincial continuance, brand consolidation, employment and old equipment labels can tell different but compatible stories. For an owner facing the alarm, the decisive questions are narrower: What is the authoritative control-system version? Who can access it, and what must be tested before a change is trusted?

One corporation, two names, and a discontinuance that was not a tombstone

The identity bridge begins with the federal record, not with a web search for a familiar acronym. Corporations Canada records corporation number 218327-7 as incorporated under the Canada Business Corporations Act on April 23, 1987. Its name history is “Automation Industrielle April Inc.” from that date until March 9, 2001, followed by “AIA automation Inc.” The record lists the same federal corporation as inactive because it was “discontinued” on November 28, 2022, and shows a registered office at 11400 boulevard Louis-Loranger in Trois-Rivières. (Corporations Canada company record)

That sequence proves the essential bridge. AIA was not selected merely because its initials resemble Automation Industrielle April. It was the renamed federal corporation. A secondary Canadian company directory independently reproduces the corporation number, name history, office and discontinuance date, which is useful corroboration but not a substitute for the official record. (Companies of Canada)

“Discontinued” can sound like a euphemism for business failure. Under Canadian corporate law, that reading is unsafe. Corporations Canada describes continuance, or export, as the process by which a federal corporation continues under another corporate statute. Once the certificate of discontinuance is effective, the corporation continues to exist but is no longer governed by the Canada Business Corporations Act. The statute adds the continuity that matters to counterparties: a continuance does not make the corporation’s property vanish, release its obligations or terminate legal proceedings. (Corporations Canada continuance policy, Canada Business Corporations Act, section 188)

The public federal page does not state the destination statute or the transaction-specific reason for AIA’s discontinuance. It would therefore be wrong to report that the corporation was dissolved, bankrupt or simply shut down in 2022. A Quebec-registry-derived company record associates the same AIA history with Quebec enterprise number 1143571694, historical names including Automation Industrielle April and AIA Automation, the Louis-Loranger address, and the current or alternate name Excelpro Fabrication Inc. That is consistent with provincial continuity after the federal discontinuance, although the source is a commercial mirror and should be confirmed against a fresh official Quebec registry extract before a legal decision. (B2BHint Quebec registry mirror)

There is another independent identifier. A 2017 bulletin from Quebec’s Autorité des marchés financiers lists AIA AUTOMATION INC., Quebec enterprise number 1143571694, as receiving an authorization associated with public contracts. This connects the AIA legal name to the same provincial number years before the acquisition and federal discontinuance. It does not describe individual contracts or certify technical performance, but it strengthens the identity chain. (AMF bulletin, September 2017)

The commercial bridge is similarly documented. On April 1, 2021, Neksys-Excelpro announced that it had acquired AIA Automation. The buyer described AIA as operating from Quebec City and Laval with roughly fifty engineers and technicians and said there would be no job losses, while former shareholders would remain during a transition. A partner letter preserved by Quebec’s automation-industry association said existing agreements with AIA and the buyer’s other businesses would be honoured. These are buyer statements rather than independent audits, but they directly address ownership and transition. (Excelpro acquisition announcement, partner letter hosted by REAI)

Two months later, the group said AIA would retain its name temporarily as a member of the Excelpro Group while vehicles, signs, websites and other branding moved toward a common identity. Excelpro later announced that AIA, Envitech Automation and Conrad Lavoie had officially become Excelpro. The sequence supports a measured conclusion: operational consolidation began in 2021, public-brand consolidation followed, and the federal discontinuance arrived in November 2022. It does not reveal the internal legal rationale for every step. (Excelpro brand transition, Excelpro unification announcement)

This distinction is not pedantry. An owner deciding whom to contact may reasonably begin with Excelpro because the buyer presented itself as the commercial successor and promised continuity. An owner deciding who holds a contract, warranty, intellectual-property right or liability should examine the actual agreement and current registry documents. A maintenance technician deciding whether a program is safe to download needs neither a branding history nor a press release first; the technician needs the controlled source, the hardware and firmware match, the change record, and an approved test plan.

What the public record proves AIA actually touched

AIA’s own and successor-company descriptions cast a broad net. The 2021 acquisition announcement attributed to AIA industrial automation, industrial computing, mechanical design and machine safety, serving mining and metals, pulp and paper, petrochemicals and projects outside Canada. Excelpro’s corporate history says AIA had specialized since 1987 in industrial automation, networking, mechanical engineering and machine safety. A historical system-integrator profile adds PLC and control-panel systems, distributed-control-system migration, industrial Ethernet and SCADA, and lists experience with multiple industrial vendors. A 2020 Rockwell Automation publication lists AIA among its Solution Partners, a category Rockwell describes as system integrators able to design, implement, manage and maintain automation systems. (Excelpro acquisition announcement, Excelpro history, WTWH system-integrator profile, Rockwell Automation Journal, 2020)

Those descriptions establish marketed capability and an ecosystem affiliation. They do not prove that every listed technology appeared at every customer. Public procurement records give the analysis a firmer floor.

In March 2016, Montréal’s contract disclosure lists AIA Automation in two potable-water entries. One describes continuous monitoring of emergency electrical substations and records an invoiced amount of C$19,559; the other describes the supply, installation and configuration of software and records C$3,139. The disclosure does not expose the complete architecture, acceptance tests or contract total, so the two figures should not be treated as a full project valuation. What it does show is that AIA’s work reached monitoring and software configuration inside a public water operation. (Montréal contract disclosure, 2016)

A Montréal disclosure with a January 10, 2019 row records C$7,349 for a client workstation associated with the emergency electrical-substation server in potable-water distribution. The PDF’s file naming and surrounding header material reflect an older report series, so the narrow claim should remain tied to the dated row rather than generalized into a citywide deployment. Even so, a client workstation is a meaningful lifecycle boundary: it sits between industrial servers and operators, and its operating system, credentials, display software and network rules can become obsolete before the controlled process does. (Montréal contract disclosure, 2019 row)

Thurso’s August 2018 council minutes authorize payment of an AIA invoice for work at the principal wastewater pumping station. The record confirms the site and vendor but does not say whether the work involved logic, instruments, communications or power equipment. Its March 2020 minutes are more specific: council approved C$5,260 plus taxes for a Windows 7-to-Windows 10 migration at the filtration plant, including Office 365 and software. That line item is a small but revealing example of automation support extending into the computing layer. An operating-system migration can affect drivers, engineering tools, HMI runtimes, licence managers and communications even when the PLC program itself does not change. (Thurso council minutes, August 2018, Thurso council minutes, March 2020)

In July 2019, Quebec’s environment ministry disclosed C$28,400 in technical services for AIA to act as a panel builder assembling control cabinets for the gates at the Beaudet dam. This is the clearest public evidence of a physical AIA deliverable: a cabinet brings together protective devices, control hardware, terminals, power supplies and field connections, while its documentation is supposed to describe how that assembly corresponds to the controlled machinery. The disclosure does not say who wrote the gate-control logic, selected the safety architecture or commissioned the finished system, so those tasks cannot be assigned to AIA on this evidence alone. (Quebec environment ministry financial disclosure, July 2019)

Ormstown’s December 2018 minutes record C$5,703.61 for AIA engineering services at Station Dumas. Again, the scope is not given. It proves an engineering purchase at a named municipal site, not the engineering discipline or final deliverable. Thurso’s January 2023 minutes also list a November 30, 2022 AIA Automation invoice of C$4,529.15 for work at the filtration plant—two days after the federal discontinuance date. That timing shows why purchase-order names and corporate status must not be conflated. The work may have been performed earlier, the invoice may have moved through an existing vendor account, or a legacy trading name may have persisted after a legal change. The minutes do not choose among those explanations. (Ormstown council minutes, December 2018, Thurso council minutes, January 2023)

The resulting installation picture is specific but incomplete: municipal water and wastewater sites, emergency-power monitoring, an industrial workstation and software migration, dam-gate control cabinets, and other engineering work whose details are not public. It supports the conclusion that AIA’s legacy can reside in both physical panels and software-dependent operating layers.

It does not support a named AIA warehouse-robotics installation. That absence matters because the successor’s present capabilities are broader than the acquired company’s documented historical footprint. Excelpro’s own history attributes its 2023 expansion into custom robotic and automated equipment to a separate acquisition of Génik. A buyer’s later robotics capability cannot be projected backwards onto AIA without project evidence. (Excelpro history)

For warehouse and industrial-robotics owners, the AIA case is still relevant. A robot cell, conveyor line, automated storage system or palletizer has the same chain-of-custody problem, often multiplied across robot controllers, safety PLCs, machine-vision recipes, servo parameters, warehouse interfaces and vendor-specific project files. The transferable lesson is about maintainability after corporate change, not an unsupported claim that AIA installed those systems.

A control system is a chain of custody, not a box

A panel door encourages a hardware view of automation. The controller, input/output rack and switch are visible; therefore, it is tempting to think the asset can be supported by buying compatible replacements. In practice, the operational asset is a synchronized set of representations.

One representation is executable: the logic, configuration, HMI project, recipes and communication settings that devices run. Another is explanatory: source comments, function descriptions, cause-and-effect matrices, network diagrams, alarm philosophy and operator procedures. A third is physical: cabinet layouts, electrical schematics, instrument ranges, terminal plans and field labels. A fourth is administrative: software entitlements, passwords, certificates, remote-access approvals, warranty terms and the record of who accepted each change.

The plant is supportable when those representations agree closely enough that a competent person can understand a fault, make a controlled change and demonstrate the result.

NIST’s 2026 guidance on operational-technology resilience is unusually explicit about what a recoverable baseline contains. It calls for backups of program and logic files, configuration files, input/output lists, firmware, HMI graphics, licence keys, vendor tools, documentation, operating-system or virtual-machine images, and information about spare parts. It also notes that restoration may require specialized engineering software, physical cables and licences, and recommends hashing backup files, keeping redundant copies and testing recovery in a non-production environment where possible. (NIST SP 1339, Cybersecurity for Operational Technology)

That list exposes four forms of lock-in that are frequently confused.

The first is product lock-in. A particular controller family may require proprietary development software, project formats, cables or runtime licences. The second is version lock-in. A source project may open only in a particular software release, which may in turn require an old operating system or activation method. The third is knowledge lock-in. A standard PLC can still be effectively closed if only one integrator understands undocumented sequences, custom libraries or field modifications. The fourth is evidence lock-in.

Even when another engineer can rewrite the application, the owner may lack the test records and process knowledge needed to prove that the rewrite preserves safety, quality and environmental performance.

Corporate consolidation can reduce one kind of risk and increase another. A larger successor may offer more staff, broader service coverage and stronger purchasing relationships. At the same time, a brand transition can scatter project records among old file servers, email archives, former employees and new document systems. The buyer’s promise to retain AIA’s people and honour agreements was therefore commercially important, because people are often the index to the documentation. It was not a substitute for customer-controlled handover. (Excelpro acquisition announcement, partner letter hosted by REAI)

The chain of custody should answer a simple question for each material file: Is this the version that corresponds to the running plant? A PLC upload taken today can show what is in the processor, but it may omit source comments or symbols. An integrator archive may be richly documented but precede an emergency field edit. A drawing can be formally issued yet fail to show a jumper installed during a shutdown. A virtual-machine image can preserve the toolchain but contain expired licences or unknown credentials. None is authoritative alone.

The owner must reconcile them. That means recording controller checksums or other vendor-supported signatures; comparing online and offline projects; walking critical input and output points against drawings; identifying forced values and bypasses; exporting alarm and recipe definitions; documenting firmware and module revisions; and linking every discrepancy to a disposition. The objective is not archival elegance. It is to prevent the next technician from treating an unexplained difference as either harmless or disposable.

This is also why “we have a backup” is an inadequate answer. A backup has operational value only if the owner knows what it contains, can access the software and credentials needed to use it, can verify its integrity, and has rehearsed an appropriate restoration path. A directory of files named “final,” “final2” and “current” is evidence of storage, not recoverability.

The handover hidden inside the 2021 acquisition

The AIA acquisition announcement makes continuity sound orderly: no planned job losses, former shareholders remaining during transition, existing agreements respected, and a larger group offering a fuller set of services. Those commitments are rational reasons for a customer to expect support. The temporary retention of the AIA name also reduced immediate disruption while branding changed. (Excelpro acquisition announcement, Excelpro brand transition)

Yet a corporate handover and a technical handover operate at different resolutions. The acquisition can transfer shares or assets, personnel and contracts without giving each plant owner a verified copy of every site-specific dependency. Conversely, an owner may possess complete technical records even if its old maintenance agreement was not assigned. The two transitions should be tested separately.

For a customer, the commercial test begins with the exact contracting party. Which name appears on the original proposal, purchase order, acceptance certificate and software licence? Was the contract with the federal corporation, a Quebec registration, an affiliate or a predecessor? Does it contain an assignment clause? Were warranties still alive at acquisition? Does the agreement make source code or native project files a deliverable? Who owns custom code and reusable libraries? The public sources cannot answer those customer-specific questions.

The technical test begins with a project register. Every AIA-era installation should be mapped to site, process area, cabinet, controller, HMI or SCADA node, network segment, safety function, engineering software, current backup, drawing set and responsible owner. The register should distinguish what AIA supplied from what it merely modified. That distinction matters when a cabinet bears one integrator’s label but contains logic written by another and later changes made by plant staff.

Then comes the personnel bridge. Former AIA employees may now work under the successor’s banner, but an owner should not assume institutional memory is permanent or searchable. It should identify who last commissioned or materially changed the installation, capture unresolved design decisions, and convert oral knowledge into controlled records. Interviews are most valuable when tied to evidence: walk the sequence beside the running process, annotate the cause-and-effect matrix, identify unusual interlocks, explain restart conditions, and reconcile the explanation with code and drawings.

The rights bridge is equally important. An owner may have paid for a system without receiving the reusable source, passwords or engineering licences. It may have a contractual right to them but no practical mechanism for delivery. It may own site-specific logic while the integrator retains a proprietary library. The solution is not automatically to demand every piece of the integrator’s intellectual property. It is to define the minimum package another qualified party would need to diagnose, recover, validate and migrate the owner’s installation, then resolve rights and escrow arrangements before an emergency.

Finally, there is the remote-support bridge. Old integrator accounts, virtual-private-network profiles, shared passwords, remote desktop tools and firewall exceptions should be inventoried whenever ownership changes. Accounts should be tied to named people or managed service identities, approved for a specific purpose and removed when no longer needed. A brand change is a natural trigger for that review because the organization that originally justified an access path may have changed even if the same engineer remains.

The 2022 federal discontinuance created another trigger. It did not by itself erase obligations, but it changed the legal-registry context in which an owner might identify its counterparty. The prudent response is not panic. It is a documented contact and contract refresh: obtain the successor’s current legal name and service contact, confirm the status of support agreements, update emergency escalation details, and connect that commercial record to the technical project register.

Four support paths, each with a different burden of proof

When the original name has gone, an owner has four practical support paths. They are not mutually exclusive, and none should be chosen solely on hourly price.

The first is the successor organization. Excelpro is the obvious initial route for AIA-era work because it announced the acquisition, staff transition, contract continuity and later brand unification. The successor may retain personnel, project archives, vendor partnerships and knowledge of custom libraries. Its evidentiary burden is to show that it has the relevant site records and competence—not merely that it bought the company. The owner should ask for the archive inventory, named technical lead, supported product versions, response terms, access controls and a demonstration that the offline project matches the running system.

The second is the automation product manufacturer or an authorized partner. A manufacturer may be best placed to replace obsolete hardware, interpret lifecycle status or provide conversion tooling. Rockwell, for example, distinguishes active, mature, end-of-life and discontinued hardware, and uses separate software lifecycle categories; it warns that retired software is no longer available for download and that anomalies or operating-system support are no longer addressed. Those categories show why the right migration moment depends on the whole toolchain, not merely whether spare PLC modules can still be found. (Rockwell Automation product lifecycle status)

The manufacturer’s limitation is application context. It may understand the platform without knowing why a municipal pump must wait for a valve, how a dam gate is interlocked, or which alarm an operator treats as a precursor to failure. Vendor conversion tools can accelerate translation, but they do not prove process equivalence.

The third path is an independent system integrator. A qualified independent can reduce dependence on the successor, benchmark pricing and challenge undocumented assumptions. Independence is most valuable when the owner supplies a coherent baseline. Without one, the new integrator must reverse-engineer the system and may recreate the same dependency under a new name.

Its burden of proof includes competence in the installed platforms, experience in the relevant process and safety context, a controlled engineering method, professional liability coverage where appropriate, and willingness to deliver native source and documentation back to the customer.

The fourth path is an internal automation team. In-house capability can shorten response times, preserve process knowledge and keep access under owner control. It also creates obligations: training, segregation of duties, software licensing, secure engineering workstations, peer review, after-hours coverage and retention of scarce staff. “We maintain it ourselves” is not resilience if only one employee knows the password and keeps the sole project copy on a laptop.

For many owners, the best structure is layered. The successor handles difficult legacy interpretation; an independent integrator reviews or competes for major migrations; product manufacturers provide lifecycle and compatibility support; and internal staff own the asset inventory, backups, change authority and acceptance criteria. That arrangement separates institutional memory from commercial monopoly.

The choice must also reflect the process consequence. A packaging line that can be stopped and simulated differs from a water pumping station, dam gate or continuous industrial process. The less tolerant the process is of downtime or unexpected movement, the more the owner should invest in offline testing, spares, staged cutover and an executable rollback plan.

The evidence pack every owner should be able to open

An AIA-era support file should be designed for the competent stranger who arrives after the last familiar engineer has left. It should not require that person to infer the plant from a sequence of invoices.

Start with identity. Record the legal owner of the equipment, site and process area; the original supplier and all known successors; current service contacts; contract and purchase-order references; intellectual-property terms; warranty status; and the exact name under which software licences and support accounts are registered. Keep the acquisition and name-change evidence as context, but do not let corporate documents replace technical acceptance records.

Next, establish an asset and dependency inventory. Canada’s Cyber Centre recommends a structured OT asset inventory and taxonomy as a foundation for cyber risk management. For a control system, that inventory should include controllers, remote input/output, safety controllers, drives, robots where present, HMIs, servers, engineering workstations, network appliances, time sources, remote-access components and connected instruments. It should capture vendor, product designation, serial number, firmware, physical location, network identity, owner, criticality and lifecycle state. (Canadian Centre for Cyber Security, OT asset inventory guidance)

Then preserve the executable baseline. Keep native editable project files, not only PDFs and processor uploads. Include PLC and safety-PLC logic, HMI and SCADA applications, historian and alarm configuration, recipes, drive and servo parameters, robot jobs and calibration data where applicable, switch and firewall configurations, database schemas, scripts, certificates, and any custom communication gateway. Record the software version required to open each file and the firmware or runtime version against which it was commissioned.

Preserve the toolchain. A recoverable archive may require installer media, patches, licence files or activation procedures, a supported operating system, virtual-machine images, communication drivers, vendor-specific cables and secure hardware keys. NIST’s resilience guidance explicitly includes these dependencies because a source file without a working engineering environment may be unusable during an outage. (NIST SP 1339)

Document physical truth. Store issued electrical drawings, cabinet layouts, bills of material, terminal and cable schedules, network diagrams, instrument lists, input/output lists and photographs of panel interiors and nameplates. Mark field deviations. For safety-related control, include risk assessments, safety-requirements specifications, calculations, validation plans and results, proof-test procedures, bypass controls and records of authorized changes.

Explain operation. A functional description should state modes, sequences, permissives, interlocks, alarm priorities, failure responses, restart conditions and manual fallbacks. Operator procedures should cover normal start, controlled stop, recovery after power loss, communication failure and degraded operation. Maintenance procedures should identify safe isolation, backup and restoration steps, periodic tests and escalation thresholds.

Show provenance. Each controlled file needs a version, date, author or approver, related change request and status. A cryptographic hash can help show that a stored backup has not changed, but it cannot show that the backup matches the running plant. That requires a documented comparison or an upload made under controlled conditions. Keep at least one protected offline copy and another geographically or administratively separate copy, with access tested rather than assumed.

Prove restoration. A tabletop exercise is useful, but a real recovery test is better. On spare hardware, a test rack, a digital twin or an isolated virtual environment, demonstrate that the engineering tools open, the project compiles, required licences work, communications can be configured and backups can be restored. Where a full simulation is impossible, document the limits and design a staged production verification that minimizes risk.

Record spares and substitutions. For each critical module, list installed quantity, stocked quantity, storage condition, tested status, vendor lifecycle state and approved replacement. An untested second-hand module is an option, not a recovery guarantee. Canada’s Cyber Centre advises organizations operating obsolete products to maintain accurate inventories, plan transitions, preserve trained internal resources and consider spares while avoiding unnecessary external connectivity. (Canadian Centre for Cyber Security, obsolete products guidance)

Finally, keep the acceptance evidence. A signed purchase order shows that money changed hands. It does not prove that every interlock was tested. Preserve factory and site acceptance procedures, test results, punch lists, resolved deviations, performance benchmarks, operator training, as-built delivery and formal acceptance. This package becomes the reference against which a successor, independent integrator or internal team can defend a repair or migration.

Migration is a validation exercise disguised as an upgrade

Obsolescence rarely arrives as a single deadline. A controller may remain reliable while its programming software becomes incompatible with current computers. A workstation may require an operating-system upgrade while its HMI runtime depends on an old driver. Replacement input/output modules may be available while the communication adapter is discontinued. Cyber requirements may force removal of a remote-access method before the owner has a new support arrangement.

Manufacturers present migration as a managed path. Rockwell’s installed-base services emphasize inventory, lifecycle analysis, bills of material, spares and software or operating-system compatibility. Schneider Electric describes modernization services that address legacy PLC risk and seek to preserve application familiarity through conversion. Siemens describes a staged approach from assessment and concept through migration, implementation and commissioning, including HMI and application work. These sources are vendor service descriptions, not neutral proof that any one conversion is suitable for an AIA-era project. They nevertheless identify the right stages. (Rockwell Installed Base Evaluation, Schneider Electric PLC modernization, Siemens factory-automation migration services)

Assessment should begin with consequence, not product age. What happens if this controller fails? How long can the process be unavailable? Can operators run manually? Could a false command release energy, damage equipment, contaminate water or defeat an environmental control? Which components are single points of failure? Which dependencies are already unsupported? Which backups have actually been restored?

The concept phase chooses among sustain, emulate, partially migrate and replace. Sustaining may be rational when spares, expertise and a secure support environment remain available. Emulation or virtualization may preserve a workstation long enough to plan a larger change, but it can also preserve vulnerabilities and licensing uncertainty. Partial migration can reduce immediate risk but creates gateways and mixed generations. Full replacement may simplify the future architecture while maximizing commissioning exposure.

Before code conversion, freeze and explain the current behaviour. Extract the running logic, reconcile it with source, record scan-dependent behaviour, enumerate alarms and recipes, and capture representative process trends. Identify undocumented operator practices. A technically awkward routine may embody a hard-won response to hydraulic delay, sensor noise or mechanical backlash. Cleaning it up without understanding its purpose can remove a safety margin.

Build traceability from old requirement to new implementation and test. Every critical permissive, trip, timing condition, mode transition, alarm, manual action and communication failure should have an expected result. Automated comparison can help for deterministic logic; simulation can exercise sequences and failure cases; hardware-in-the-loop testing can expose timing and interface problems. None eliminates the need for field verification.

Machine-safety changes deserve separate governance. Quebec’s workplace-safety regulator explains that, since July 27, 2023, a machine modification that could affect worker safety must be carried out under an engineer’s supervision, and it describes documentation obligations for machines placed in service under the revised rules. Quebec’s occupational health and safety regulation also requires lockout or another energy-control method before work in a machine’s danger zone in covered circumstances. Those requirements mean a control migration cannot be treated as an information-technology refresh when it can alter hazardous motion or protective functions. (CNESST machine-safety regulatory revision, Quebec Regulation respecting occupational health and safety)

ISA/IEC 62443 provides a useful division of responsibility around industrial automation and control-system security. The series distinguishes obligations for asset owners, service providers and product suppliers, including owner security programs, service-provider requirements and system risk assessment. That separation is especially valuable after an acquisition: changing the service organization does not transfer the asset owner’s responsibility to define risk, authorize access and accept the resulting system. (ISA/IEC 62443 series overview)

Cutover needs a rollback that is physical as well as digital. If the new controller fails acceptance, can the old hardware be reinstalled? Are terminal adapters, cables and labelled conductors preserved? Is the old program confirmed and loadable? How long does reversal take, and what happens to the process during it? A rollback plan that depends on an untested backup or discarded panel is merely a hope.

The final acceptance should compare outcomes, not screenshots. Verify safe states, interlocks, timing, alarm annunciation, operator authority, data quality, restart behaviour, communications loss, power recovery, manual controls, cybersecurity logging and production performance. Record deviations and who accepted them. Only then should the owner declare the old baseline retired.

Cybersecurity when yesterday’s integrator still has a door

Operational technology interacts with the physical environment, so security measures must respect performance, reliability and safety. NIST’s principal OT security guide frames those constraints directly. The implication for an inherited AIA system is that access cleanup and hardening must be engineered around the process; simply applying an office-IT policy can interrupt necessary communications or create unsafe recovery behaviour. (NIST SP 800-82 Revision 3)

Start with identities. List every local account, domain account, service credential, vendor portal, VPN profile, remote desktop tool, cellular modem and shared password connected to the installation. Determine who owns it now, when it was last used, what it can reach and how activity is logged. Disable obsolete paths under a change plan; rotate shared secrets; give the successor or any new integrator named, time-bound access; and require approval for elevation. A company acquisition is not evidence that every old account was transferred correctly.

Then establish topology. An owner should know which AIA-era controllers and workstations communicate with business systems, vendor clouds, remote sites and the internet. The Canadian Cyber Centre’s water-sector guidance recommends current inventories and network-topology diagrams, backups that include PLC logic and drawings, documented exceptions for remote access, and protection of industrial controllers from direct public-internet exposure. It also calls for tested manual controls and compensating measures when patching is not immediately possible. (Canadian Centre for Cyber Security, water-systems threat assessment)

The water context is not abstract for AIA because Montréal and Thurso records place the contractor in potable-water and filtration or pumping environments. That does not show that any AIA installation was insecure or suffered an incident. No verified AIA-specific cyber incident appears in the frozen public evidence for this article. It shows only why inherited access and recovery deserve a threat-informed review.

Remote support should use a controlled gateway rather than a permanent direct path to controllers. Strong authentication, least privilege, session approval and recording, segmentation, restricted source addresses, bounded access windows and immediate revocation reduce the chance that a convenience channel becomes an enduring exposure. NIST’s 2026 practice guide for secure remote access in water and wastewater systems is designed around precisely this operational problem. (NIST NCCoE secure remote-access guidance for water and wastewater)

Security automation can help, but only after the asset and process context is credible. Automated collection can identify firmware, configurations or unexpected network connections. Central systems can alert on failed logins, changes to firewall rules, new remote sessions or controller program downloads. Backup jobs can generate integrity evidence and overdue-test alerts. None should autonomously block safety-critical traffic or rewrite control configurations without an engineered policy. In OT, a high-confidence cyber alert can still require a process-aware response.

Procurement is the point at which future access risk is cheapest to change. Joint guidance hosted by Canada’s Cyber Centre recommends asking digital-product suppliers for configuration management, baseline logging, secure defaults and communications, authentication, vulnerability management, patch tooling, open standards, data ownership and protection, and evidence of threat modelling. For an integrator engagement, those demands should extend to the delivered project: named accounts, customer-owned logs, a documented remote-support architecture, a vulnerability notification route, supported-version commitments and an exit package. (Secure by Demand OT procurement guidance)

Patching remains a risk decision rather than a calendar ritual. The owner must know whether a vendor patch is approved for the installed software and firmware combination, whether it affects drivers or licences, how it was tested, what compensating controls exist, and how to reverse it. When an obsolete workstation cannot be safely updated, segmentation, removal of unnecessary services, application control, restricted removable media and a planned migration can be more defensible than an untested upgrade.

Incident response must include engineering recovery. A corporate response plan that can reset email accounts but cannot restore a PLC, HMI or network switch leaves the physical process exposed. The evidence pack, spare strategy and validated restore procedure are security controls because they reduce the pressure to reconnect an unsafe system or trust an unverified file during a crisis.

Pricing the unknown, not merely the technician’s hour

The disclosed AIA purchases range from a few thousand Canadian dollars for software or workstation work to C$28,400 for dam-gate control-cabinet assembly. They are not comparable rate cards. The records describe different scopes, omit many commercial terms and sometimes show invoice lines rather than entire contracts. No public AIA price list appears in the frozen evidence. (Montréal, 2016, Montréal, 2019, Quebec environment ministry, 2019, Ormstown, 2018, Thurso, 2020)

For legacy support, price follows uncertainty. A contractor asked to change a well-documented system can estimate engineering and test effort. Asked to recover an unknown program from a running controller with no verified backup, it must price discovery, travel, outage risk, scarce expertise and the possibility that the source cannot be reconstructed cleanly. The owner pays for missing information twice: first through investigative labour and again through larger contingencies.

A useful commercial framework separates five costs.

The first is readiness: inventory, backup verification, archive normalization, licence recovery, network mapping and training. It produces no immediate process improvement, which makes it tempting to defer, but it lowers the cost of every later intervention.

The second is routine support: scheduled maintenance, lifecycle reviews, minor changes and an agreed response mechanism. Retainers can reserve scarce expertise, but an owner should know what response is guaranteed, which versions are covered and whether unused hours buy any transferable deliverable.

The third is emergency response: call-out, travel, premium time and rapid diagnostics. The key question is not the hourly rate; it is whether the responder arrives with the right project, tools, access and authority. A cheap responder who spends a shift locating software can cost more in downtime than a specialist.

The fourth is modernization: design, hardware, software, panel work, testing, training and cutover. Fixed-price bids are meaningful only when the baseline and acceptance criteria are sufficiently defined. Otherwise, a low fixed price may hide exclusions or create pressure to treat unexpected behaviour as a change order.

The fifth is residual risk: production loss, environmental consequence, safety exposure, rejected product, emergency rentals and reputational damage. It may never appear on the integrator’s proposal, yet it should dominate the owner’s decision about staging, redundancy and validation.

Competitive bidding works best after the owner has purchased information. Give bidders the same asset inventory, source package, functional requirements and required test outcomes. Ask each to identify assumptions, exclusions, unsupported components and customer prerequisites. Price the handover deliverables explicitly. Require native source files, as-built drawings, licence records, training and a tested backup before final payment.

An owner should also decide how much platform concentration it accepts. Standardizing controllers and HMIs can reduce training and spares but deepen product dependence. Using open protocols and documented interfaces can improve future competition, though it does not eliminate proprietary engineering environments. Multiple integrators can reduce commercial dependence but increase configuration drift unless the owner controls the baseline. There is no lock-in-free architecture; there are only dependencies made visible, governed and replaceable to different degrees.

Competition is between continuity approaches, not company logos

After the AIA brand transition, the apparent choice is between Excelpro and another integrator. The real competition is among continuity approaches.

One approach sells institutional continuity: the successor argues that it inherited people, archives and vendor relationships. This is strongest when it can retrieve the exact site project, explain past design choices and offer a supported migration path. Its weakness is that the customer may remain dependent on one institutional memory.

A second approach sells platform continuity: a product vendor or authorized specialist keeps the customer within a controller family and uses official lifecycle tools. This can reduce conversion risk and preserve operator familiarity. Its weakness is that an application can remain poorly documented, and official conversion does not validate process intent.

A third sells engineering independence: a new integrator reconstructs requirements, normalizes documentation and creates a customer-owned baseline. It can improve commercial leverage and challenge legacy conventions. Its weakness is the cost and risk of learning an installed system without the original designers.

A fourth sells operational sovereignty: the owner builds internal competence and treats external suppliers as augmentations. This can place decisions closest to the process and keep archives under customer control. Its weakness is recruitment, retention and the difficulty of maintaining deep expertise across several aging platforms.

The right test is portability. At the end of a support or modernization engagement, could another qualified team take over without repeating discovery? If the answer is no, the project may have restored operation while preserving the structural risk.

For warehouse and industrial-robotics systems, portability requires more than PLC code. Robot programs, safety signatures, mastering or calibration records, vision configurations and recipes, motion parameters, conveyor coordination, warehouse-control interfaces, simulation files and tool geometry may belong to different suppliers. A general automation successor may support the line PLC while a robot manufacturer controls controller access and a software vendor controls the warehouse interface. The owner must map those seams.

For water and other public infrastructure, continuity also intersects procurement. The AMF bulletin shows that AIA held a Quebec authorization associated with public contracting in 2017, while municipal disclosures show named purchases. A successor or competing bidder must satisfy the current procurement and qualification rules applicable to the new engagement; an old supplier’s authorization is historical evidence, not a transferable technical credential. (AMF bulletin, September 2017)

No marketing claim resolves these trade-offs. A buyer announcement can establish ownership and intended continuity. A partner badge can establish an ecosystem relationship. A procurement record can establish that work was purchased. Only site records and testing establish that a particular team can safely support a particular installation today.

Twelve procurement tests for an inherited control system

Plant owners can turn the AIA lesson into concrete questions before awarding support or migration work.

1. Prove the identity and succession path. Name the legal contracting entity, trading name, affiliates and subcontractors. Explain the relationship to the original integrator and identify which contracts, archives, licences and personnel actually transferred. Provide current registry evidence where the contract requires it.

2. Demonstrate archive possession. In a controlled session, retrieve the specific site’s project and open it with the required engineering tools. Show its version history and compare it with the running controller or system. Do not accept a generic statement that “the files came with the acquisition.”

3. Declare unsupported dependencies. List hardware, firmware, operating systems, development tools, runtime software, drivers and licences that are mature, obsolete, retired or otherwise unsupported. Separate lack of manufacturer support from lack of the bidder’s internal competence.

4. Map access before granting it. Specify the remote-support path, authentication, approval, segmentation, logging, session retention and revocation process. State whether any subcontractor or product vendor can connect and under whose authority.

5. Deliver the native project. Require editable source, libraries, symbols, comments and build instructions, subject to clearly stated intellectual-property limits. A PDF printout or processor binary alone does not create maintainability.

6. Explain safety governance. Identify which changes could affect hazardous motion or worker protection, who is professionally responsible, which standard or regulatory requirements apply, and how safety functions will be independently validated.

7. Test failure, not only normal production. Acceptance should cover sensor faults, communications loss, power interruption, abnormal sequence transitions, emergency stops, interlocks, invalid operator commands and recovery from partial completion.

8. Provide a physical rollback. Name the hardware, backups, cables, staff and time required to reverse the cutover. State the point after which rollback is no longer possible and who authorizes crossing it.

9. Transfer knowledge in evidence. Training should produce updated functional descriptions, annotated code, troubleshooting trees and recorded demonstrations tied to the actual installation. Attendance sheets alone do not preserve competence.

10. Price discovery separately. If the baseline is uncertain, buy a bounded assessment before demanding a fixed modernization price. Require the resulting inventory and findings to belong to the owner so that competitors can bid from the same facts.

11. Commit to exit deliverables. Define what the owner receives at contract end: current backups, source, drawings, licence and account inventory, change log, open issues, lifecycle status and tested restoration instructions. Set retention and deletion duties for supplier-held copies.

12. Measure supportability. Track backup age, restoration-test age, undocumented changes, unsupported assets, shared accounts, critical spares, unresolved safety deviations and the number of people able to recover each critical system. A migration that installs new hardware but leaves these measures unchanged has not solved the continuity problem.

These tests align incentives. They let a capable successor demonstrate genuine continuity, allow an independent integrator to price the unknown honestly, and give the owner assets that survive the next acquisition or retirement.

What the evidence cannot tell us

The public record is strong enough to identify the company and establish a limited set of installations. It is not a complete operating history.

It does not disclose the destination jurisdiction or internal business reason for the November 2022 federal discontinuance. Canadian law supports the conclusion that discontinuance follows continuance under another legislation and preserves the corporation’s existence and obligations; the Quebec-registry-derived record is consistent with provincial continuity. A current certified registry extract and transaction documents would be required to state the exact legal path with full confidence.

It does not provide a comprehensive customer list. Municipal disclosures and the dam-cabinet entry prove specific work, while the company’s acquisition announcement and integrator profile describe broader sectors and international reach. Those broader statements remain company or directory claims unless corroborated by named project evidence.

It does not reveal which source files, drawings, credentials, warranties or intellectual-property rights transferred to Excelpro, or what each customer already possesses. The promise to respect agreements and keep former shareholders during transition is evidence of intended continuity, not proof that every site archive is complete.

It does not prove a particular AIA robotics or warehouse installation. Excelpro’s later acquisition of Génik explains at least part of the successor group’s present custom-equipment and robotics capacity. Attributing that later capability to AIA would collapse two different acquisition histories.

It does not document an AIA-specific safety or cybersecurity failure. The discussion of remote access, backups, obsolescence and validation applies established OT guidance to the known classes of AIA work; it is risk analysis, not an allegation that the company or its customers neglected those controls.

It does not support a conclusion about customer satisfaction, current headcount or social-media reach. A legacy LinkedIn page describes the acquisition and later brand transition, but its present employee associations can reflect the larger successor group and are unsuitable as an AIA workforce measure. (AIA Automation legacy LinkedIn page)

It does not establish a public price schedule. Disclosed municipal amounts are individual purchases or invoice lines with different scopes. They can illustrate the range and character of work, not an hourly rate, margin or lifetime cost.

These limits strengthen rather than weaken the central thesis. Public corporate and procurement evidence can tell an owner where to begin. It cannot replace the plant’s own technical record. The most important facts—whether the current program matches the archive, whether an interlock was changed, whether a backup restores, whether a remote account remains active—are usually private operational facts that the owner must govern.

The watchlist for an AIA-era installation

An owner with AIA-labelled drawings, panels or software should first resolve the name without assuming extinction. Record the 1987-to-2001 name bridge, the 2021 acquisition and brand transition, and the 2022 federal discontinuance. Obtain current legal and service details from the proposed successor. Link that corporate evidence to the exact site contract rather than relying on a general history.

Second, ask the successor to retrieve the project while people with AIA-era knowledge are still available. Compare it with the running system. Identify every unexplained difference. Secure a customer-controlled copy of the native source, toolchain, drawings, licences and credentials that the contract permits.

Third, inventory lifecycle exposure. Give special attention to operator workstations and industrial servers because the Montréal and Thurso records show that AIA work included computing and software layers as well as panels. Check operating systems, HMI and SCADA runtimes, communication drivers, licence servers and engineering laptops alongside PLC hardware.

Fourth, inspect cabinets and field documentation. The Beaudet dam record confirms AIA panel-building work. Verify labels, protective devices, spare modules, drawings and the correspondence between physical wiring and input/output documentation. Do not assume the builder also owns or authored every layer of logic.

Fifth, review remote support and old identities. Remove or reauthorize legacy accounts, rotate credentials, map network paths and test logging. Preserve a method for emergency support that does not require bypassing normal security under pressure.

Sixth, make safety evidence explicit before modifying controls. Identify which functions protect people or equipment, which changes require engineering supervision, and how validation will be witnessed and recorded. Test manual and degraded modes, not only automatic production.

Seventh, rehearse recovery. Open the archive, activate the tools, restore to safe test hardware where feasible and prove that staff can find the procedure during an incident. Record how long recovery takes and which external dependencies remain.

Eighth, choose a migration trigger before crisis chooses it. A trigger might be the loss of manufacturer support, inability to obtain tested spares, an operating-system dependency that cannot be secured, failure of a restore exercise, departure of the last knowledgeable person, or a process expansion that the old architecture cannot support. Tie the trigger to an approved capital and outage plan.

Finally, design the next contract for the next corporate change. No clause can stop suppliers from merging, renaming or retiring products. A good contract can still secure a portable baseline, controlled access, tested recovery, clear rights and acceptance evidence before the name changes again.

AIA’s history is therefore not a story of automation disappearing in 2022. The federal record itself cautions against that simplification, and the Excelpro acquisition provides a visible continuity path. It is a story about the mismatch between corporate time and industrial time. Legal names can change in a filing; brands can change across vehicles and websites; a control sequence keeps executing every scan.

The owner’s durable asset is not the old logo on the cabinet or the new logo on a service proposal. It is the ability to explain, recover, alter and validate the system without depending on an unrecorded memory. When that ability exists, a successor can compete on service rather than custody. When it does not, the quietest PLC in the plant may contain the most expensive unanswered question.