
September 23, 2026 · 7 min
A legionella water management program in operation: what running one actually involves
The article of 10 August described the document. This one describes the weeks after it is signed: who reads the log, who acts on it, and what the sampling is for.
A hundred and ten searches a month, $7.44 a click, competition 0.02: almost nobody is advertising against this query, and its general form, water management program at 40 searches a month, carries a measured cost per click of $50.53 on the same low competition. That pairing says something about the market. Buyers arrive expensively and find sellers of documents. The article of 10 August described what the document has to contain. This one is about the program as a thing that runs, week after week, once the document is signed.
The document is the starting condition, not the result
A program exists when the checks it describes are being done, recorded, and acted on by named people. Until then the facility owns a plan, and a plan is a statement of intent. The transition from one to the other is not a ceremony; it is the first week in which every scheduled check was performed and signed, and the first time a check that failed produced the action the document said it would. Most facilities can date the plan. Fewer can date the program.
Monitoring: the checks somebody signs
Temperatures at the control points, disinfectant residual where the program names it, flushing of little-used outlets, inspection of storage and of any tower or aerosol-generating device. Each check has an owner, a schedule, a record, and a limit. The record is the program’s memory, and its value depends on being kept honestly: a check logged as done when it was not is worse than a gap, because it hides the gap. The schedule has to be one the building’s staff can actually keep, or the log will eventually be filled in from the desk.
Corrective action: what a failed check triggers
A reading outside its limit is the program working, not failing, provided something happens next. The document names the response; the program is the response actually occurring, with a record of what was done, by whom, and whether the follow-up reading came back within range. Where the response is repeated flushing, adjusting a mixing valve, or calling a contractor, the record closes the loop. Where it is investigate, nothing has been specified, and that is the most common weak point we see.
Verification: is the program being followed
Somebody other than the person doing the checks looks at the log and asks whether it is complete, current and plausible. This is an audit of the paperwork, not of the water, and it catches the slow decay that turns a program back into a document: the check missed in a busy week, then another, then a schedule that quietly stopped. Verification belongs to the program owner, on a calendar, with a note that it happened.
Validation: is the program actually working
This is where sampling sits. Every check above measures whether the controls are in place. Validation asks whether the controls, in place, are controlling anything, and the only direct answer is a laboratory result from defined points, taken the same way each time, as set out in how a sample is taken. A stable series of results says the controls are doing their work. A series that drifts, or a single result that breaks the pattern, says something changed, and it says so earlier than the annual review would. What the program does with a result is written into the program in advance, not decided on the day the report lands.
Who owns it
A named team, with one person accountable. Facilities engineering usually holds the day-to-day, but the team needs whoever can authorise spending, whoever knows the occupants, and, in a healthcare setting, infection prevention. A program owned by the binder is owned by nobody. The ownership question comes before the sampling plan, because a plan is only useful if someone will read what it returns.
How testing feeds back
A result is information about the system. It can confirm the program, or it can send the team back to the schematic: a point that keeps returning growth points to a dead leg, a low-flow branch, a storage vessel running cool, a device that was never on the map. The program changes, the next round tests the change, and the series records whether it worked. Testing that does not feed back into the program is a subscription to reports. How we design the sampling side of that loop is described under water management programs.
What forces a review
A refurbishment, a change of use, a shutdown and restart, a new aerosol-generating device, an occupancy change, a result outside the program’s limits. The document lists them as triggers. The program is the review actually happening when one occurs. That is the whole difference, and it is the difference the click price is paying for.
Give the program its validation round
Monitoring says the controls are in place. Sampling says whether they are controlling anything. We supply the second.