A bay interlock must prevent a hazardous operation despite a credible single failure, yet still distinguish a genuinely unsafe state from loss of indication, DC supply or an intermediate mechanism position. “Use normally closed contacts” is not a fail-safe philosophy. The design must start with safety invariants, device states and failure consequences, then allocate mechanical, electrical and logical barriers.
This practical guide covers hardwired MV switchgear interlocking for circuit breakers, withdrawable trucks, disconnectors, earthing switches, doors, local/remote control and lockout. It also explains contact selection, supervision, bypass control, FMEA and negative testing.
Executive rules
- Write safety invariants and a state/permissive matrix before drawing contacts.
- Use inherent mechanical/key interlocks for primary switching/access hazards where the assembly design requires them; electrical logic supplements rather than casually replaces them.
- Define every contact by the physical device state that operates it—not only NO/NC on the page.
- For a close permissive, loss of a proof signal normally blocks closing; for a trip path, loss of auxiliary DC must not be mistaken for successful tripping.
- Treat intermediate/contradictory positions as invalid and normally inhibit operation.
- Analyse common DC feeds, common contacts, diode backfeeds, welded relays, broken wires and bypasses.
- Rate every contact for the actual DC inductive duty and verify auxiliary-contact timing/bounce.
- Test forbidden states and inserted failures, not only successful operations.
1. Standards and responsibility boundary
| Reference | Use |
|---|---|
| IEC 62271-200:2021+AMD1:2024 | MV metal-enclosed assembly context, interlocks, access and mechanical-test requirements |
| IEC 62271-1:2017+AMD1:2021 | Common switchgear/controlgear requirements and auxiliary/control framework |
| IEC 62271-100:2021+AMD1:2024 | AC circuit-breaker and operating-mechanism requirements |
| IEC 60255-27:2023 | Protection/control product safety, not the complete interlocking safety case |
| IEC 61082-1:2014 / IEC 81346-1:2022 | Schematic presentation and traceable object reference designations |
| Manufacturer/site rules | Actual interlock sequence, key scheme, access procedure, contact ratings and safe operation |
Compliance of individual switchgear does not validate a project-specific bus transfer, remote control or cross-panel interlock. The assembly manufacturer, system designer, protection/control engineer and operating authority must have explicit interface responsibilities.
2. Define safety invariants
An invariant is a statement that must remain true in every permitted mode. Typical—but not universal—MV examples are:
- A breaker cannot be racked between test and service while closed.
- A breaker cannot close in an undefined/intermediate truck position.
- An earthing switch cannot close onto an energised circuit within the defined interlock zone.
- A breaker cannot close while its associated earthing switch is closed.
- Access to a hazardous compartment is prevented until the required isolation/earthing state is established.
- Two incomers cannot parallel unsynchronised or non-parallelable sources.
- A lockout condition prevents closing until authorised reset and cause clearance.
- One maintained close command produces at most one close operation (anti-pumping).
Each invariant needs a defined protected boundary. “Bus dead” is not an invariant until measurement source, thresholds, delays, VT-failure response, induced voltage and all possible infeeds are defined.
3. Build a state and permissive matrix
| Requested operation | Typical required proofs | Invalid/blocked examples |
|---|---|---|
| Breaker close | Truck in service or approved test position; earth switch open; mechanism ready; no lockout; valid control mode; topology/synchronism permissive | Truck intermediate, earth closed, spring not charged, close circuit unhealthy, maintained command after a trip |
| Breaker open | Trip supply/path available; command authorised | Opening is generally not blocked by process interlocks; unsafe maintenance/test routing is separately controlled |
| Rack breaker | Breaker proven open; racking handle/door/secondary plug state as designed | Breaker closed or position indication contradictory |
| Close earth switch | Breaker open; disconnector/truck isolated; no alternate infeed; key/access conditions | Service position, live cable/bus, remote backfeed possible |
| Open access door | Required isolation/earthing/shutter state | Primary circuit accessible while live |
The exact matrix comes from the switchgear topology and operating rules. Mark whether each proof is mechanical, hardwired, IED logic, key-controlled or procedural; do not count two contacts driven by one shaft as fully independent barriers.
4. Barrier hierarchy
- Inherent arrangement: equipment geometry or switching topology removes the hazard.
- Mechanical interlock: direct mechanism prevents incompatible movement.
- Trapped-key system: physical key exchange enforces an operating sequence across equipment.
- Hardwired electrical permissive: field contacts directly interrupt control energy.
- IED/PLC/IEC 61850 logic: flexible topology-aware logic with communications/configuration dependencies.
- Indication/alarm/procedure: operator awareness and administrative control.
Use the risk assessment and product design to choose layers. A mimic screen or SCADA confirmation is not an equivalent replacement for a mechanical access interlock. Conversely, hardwiring dozens of remote topology contacts can create an untestable series chain; a validated distributed scheme may be appropriate if its availability, cyber, failure state and independent barriers are defined.
5. What “NO” and “NC” really mean
Contact symbols normally describe the device in a stated reference/unactuated condition, not necessarily the process-safe state. “Normally closed” is meaningless unless the drawing says whether the breaker is open, truck isolated, relay de-energised, spring discharged and earth switch open/closed.
- Name breaker auxiliary contacts 52a/52b and define their relationship to main-contact/mechanism position.
- For a disconnector or earth switch, label contacts by proven open/closed end position.
- Use two end-position contacts to detect intermediate/contradictory states when needed.
- Show relay coils de-energised and device states in the drawing legend.
- State logical inversion at the IED; do not hide it behind a signal name.
- Validate contact timing: an “open proof” may change before the primary gap reaches its guaranteed isolating position.
6. Fail-safe philosophy by function
| Function | Typical safe treatment | Important limitation |
|---|---|---|
| Close permissive | Require energised/closed proof path; broken wire or lost DC blocks close | Common DC loss may also remove alarm/indication |
| Trip command | Direct dependable energise-to-trip path, supervised end-to-end | De-energising a relay cannot trip if the coil/DC source is dead unless a separate stored-energy/undervoltage release is designed |
| Lockout | Mechanically/electrically latched state with controlled reset | Reset circuit must not silently bypass the initiating cause |
| Alarm | Normally energised relay can alarm on wire/DC loss | Creates nuisance alarm on maintenance and may share common failures |
| Position validity | Evaluate complementary contacts; 00/11 becomes invalid after travel allowance | Both contacts may share one mechanism/plug/common |
| Remote interlock | Loss/invalid data defaults to block close | Operational recovery/bypass must be governed |
“De-energise to trip” and “energise to trip” are not slogans to apply globally. Select the failure direction for each hazard, prove that the physical actuator can achieve it, and account for DC loss, coil/open circuit and stored energy.
7. Typical breaker close-permissive chain
A common hardwired concept is close command → local/remote authority → anti-pumping → lockout reset/no trip → truck valid position → earth switch open → required door/key/inter-panel proofs → synchronism/dead-bus permission → spring charged → close coil. The order on paper should aid troubleshooting; electrically, any series contact can remove the path.
- Do not put an unreliable indication contact in the trip-opening path.
- Separate “mechanism ready” from “safe to close”; neither substitutes for the other.
- Ensure a protection trip concurrent with close has priority and anti-pumping prevents repeated closing.
- Check low-DC voltage at the coil through the entire contact chain.
- Where an IED creates a master close permissive, define its power-up, watchdog, test-mode and output-contact failure state.
- Use indication to identify the first missing permissive without bypassing the safety chain.
8. Truck, disconnector and earthing-switch logic
- Breaker racking: direct mechanical proof of breaker open is preferable; electrical 52b may supplement and control motorised racking.
- Valid truck state: service and test/isolated end positions are valid; neither end proof means intermediate and normally blocks close.
- Earth switch close: require primary isolation from every relevant source, not merely local breaker open.
- Earth switch open: often permitted for restoration, but key/access conditions and operator safety remain.
- Door access: use assembly interlock/key sequence; do not depend only on SCADA bus voltage.
- Shutters: their safety function and any padlocking/interlock must match the assembly documentation.
9. Cross-panel and bus-topology interlocks
Two-incomer/bus-coupler schemes introduce remote breaker states, source synchronism and alternate infeeds. Define the primary topology truth table and then decide whether hardwired contacts, IEC 61850 GOOSE or a controller carries each proof.
- Use complementary breaker states and position validity, not a single “open” bit where failure matters.
- Define behaviour on inter-panel cable open/short, DC loss, network failure and stale data.
- Prevent diode/LED/test circuits from backfeeding a permissive through another panel.
- Analyse shared auxiliary supply and common marshalling terminals across “independent” boards.
- For parallel closing, require approved synchronism and source-parallel capability; for dead-bus closing, validate dead-source logic and VT health.
- Time-stamp and alarm blocked/invalid states so operators understand why a command failed.
10. Contact and circuit electrical design
- Use actual DC voltage envelope, coil current/inrush, L/R and make/carry/break duty.
- Confirm whether the field contact or a 52a/52b contact interrupts the inductive coil.
- Include series contact/terminal/cable voltage drop at hot/minimum-DC conditions.
- Check contact minimum wetting current for high-impedance IED inputs.
- Select suppression for contact protection without unacceptable release delay or unsafe retained energy.
- Check cable capacitance, induced voltage and input leakage on long inter-panel circuits.
- Protect each conductor/branch selectively without one fuse defeating independent safety channels.
- Provide test isolation that cannot leave a hidden permanent bypass.
11. Supervision and diagnostics
- Supervise DC feeder/MCB, IED watchdog, close circuit and trip circuit separately.
- Use open/closed contact disagreement after a mechanism-specific travel delay.
- Alarm intermediate truck/earth-switch position beyond normal transition time.
- Identify the missing permissive on HMI without exposing an unauthorised software bypass.
- Latch intermittent interlock failures with SOE where troubleshooting value justifies it.
- Define alarm response: whether closing is blocked, local-only operation allowed or equipment removed from service.
- Avoid alarm floods from one lost common; group root-cause logic while preserving individual diagnostics.
12. Bypass and maintenance modes
A bypass is a temporary change to the safety case. It requires a defined owner, written justification, compensating controls, visible indication, time limit and restoration evidence.
- Use keyed/permission-controlled selectors or configuration authority appropriate to risk.
- Bypass only the minimum failed proof, not an entire interlock chain.
- Alarm locally and remotely; include bypass in shift handover and permit records.
- Prevent bypass persistence after power cycle unless explicitly intended and governed.
- Test mode must block unintended outputs while still allowing safe functional proof.
- Never use a loose terminal jumper as an undocumented operational solution.
- After restoration, remove bypass, test the repaired path and independently verify normal configuration.
13. FMEA: credible failures to insert
| Failure | Expected response |
|---|---|
| Open permissive wire / lost common | Close blocked; diagnostic alarm |
| Shorted/welded permissive contact | Independent barrier/state check still prevents hazardous operation or risk is documented |
| 52a/52b contradictory | Invalid state, closing/racking blocked after transition delay |
| Truck between positions | Close inhibited and clear indication |
| IED power/watchdog failure | Defined output dropout state; hardwired essential barrier remains where required |
| Remote interlock cable/network lost | Close blocked; no stale “permission” retained |
| Diode short/open | No false parallel path; affected supervision operates |
| Close output stuck with maintained command | Anti-pumping limits to one close attempt; trip has priority |
| VT fuse failure | No false dead-bus/synchronism permission |
14. FAT/SAT scenario testing
- Inspect mechanical/key interlocks against manufacturer sequence and primary topology.
- Prove every device end position and intermediate/contradictory contact state.
- Execute all allowed operations from local, remote and maintenance/test modes.
- Attempt every forbidden operation; verify the physical actuator does not energise/move.
- Insert open, short, welded-contact simulation, lost DC/common and IED/network failure.
- Test simultaneous trip and close, maintained close, spring recharge and anti-pumping.
- Exercise bus-coupler/incomer topologies, VT failure, dead-bus and synchronism conditions.
- Measure critical coil voltage and operation timing through the as-built permissive chain.
- Verify alarms/SOE, operator text, reset/bypass authority and power-cycle behaviour.
- Restore all links/keys/configuration; independently check as-left state and archive evidence.
15. Frequent design errors
| Error | Why it fails | Correction |
|---|---|---|
| NC assumed fail-safe | Reference/process state undefined | Define state and failure consequence |
| Single 52b proves breaker open | Contact/shaft/wiring can fail | Use required independent/mechanical proof and plausibility |
| Electrical logic replaces access interlock | DC/software failure removes barrier | Retain product/risk-required mechanical layer |
| Lost VT interpreted as dead bus | Unsafe close/earthing permission | VT supervision and topology-aware dead-bus logic |
| Long series chain without voltage study | Close coil undervoltage | Calculate/minimise drops or use engineered interposing logic |
| Bypass has no expiry | Temporary defeat becomes permanent | Govern, alarm and independently restore |
| FAT tests only valid close | Forbidden/failure behaviour unproven | Negative and fault-insertion matrix |
16. Design-release checklist
- Safety invariants and boundaries formally approved?
- All valid/invalid primary states included?
- Mechanical, key, hardwired, IED and procedural barriers allocated?
- Contact physical state and timing unambiguous?
- Broken wire, welded contact, common DC and intermediate position analysed?
- Trip not improperly blocked by close interlocks?
- Coil voltage and contact DC duty demonstrated?
- Cross-panel/topology/VT failure responses fail safe?
- Supervision identifies actionable root cause?
- Bypass/test mode controlled, alarmed and restorable?
- FAT/SAT includes forbidden operations and inserted failures?
- As-built drawings, keys, logic/settings and operator instructions aligned?
References and further reading
- IEC 62271-200:2021+AMD1:2024 — MV metal-enclosed switchgear
- IEC 62271-1:2017+AMD1:2021 — Common specifications
- IEC 62271-100:2021 — AC circuit-breakers
- IEC 60255-27:2023 — Protection-equipment product safety
- IEC 61082-1:2014 — Electrotechnical document rules
- IEC 81346-1:2022 — Reference designations
Engineering note: Examples describe common patterns, not universal interlock rules. The approved primary topology, hazard assessment, switchgear manufacturer’s instructions and operating authority determine the final scheme.