Hardwired Bay Interlocking Logic and Fail-Safe Contact Philosophy

A rigorous IEC 62271-based guide to mechanical and hardwired barriers, NO/NC semantics, fail-safe states, FMEA and FAT/SAT.

A bay interlock must prevent a hazardous operation despite a credible single failure, yet still distinguish a genuinely unsafe state from loss of indication, DC supply or an intermediate mechanism position. “Use normally closed contacts” is not a fail-safe philosophy. The design must start with safety invariants, device states and failure consequences, then allocate mechanical, electrical and logical barriers.

This practical guide covers hardwired MV switchgear interlocking for circuit breakers, withdrawable trucks, disconnectors, earthing switches, doors, local/remote control and lockout. It also explains contact selection, supervision, bypass control, FMEA and negative testing.

Executive rules

  • Write safety invariants and a state/permissive matrix before drawing contacts.
  • Use inherent mechanical/key interlocks for primary switching/access hazards where the assembly design requires them; electrical logic supplements rather than casually replaces them.
  • Define every contact by the physical device state that operates it—not only NO/NC on the page.
  • For a close permissive, loss of a proof signal normally blocks closing; for a trip path, loss of auxiliary DC must not be mistaken for successful tripping.
  • Treat intermediate/contradictory positions as invalid and normally inhibit operation.
  • Analyse common DC feeds, common contacts, diode backfeeds, welded relays, broken wires and bypasses.
  • Rate every contact for the actual DC inductive duty and verify auxiliary-contact timing/bounce.
  • Test forbidden states and inserted failures, not only successful operations.

1. Standards and responsibility boundary

ReferenceUse
IEC 62271-200:2021+AMD1:2024MV metal-enclosed assembly context, interlocks, access and mechanical-test requirements
IEC 62271-1:2017+AMD1:2021Common switchgear/controlgear requirements and auxiliary/control framework
IEC 62271-100:2021+AMD1:2024AC circuit-breaker and operating-mechanism requirements
IEC 60255-27:2023Protection/control product safety, not the complete interlocking safety case
IEC 61082-1:2014 / IEC 81346-1:2022Schematic presentation and traceable object reference designations
Manufacturer/site rulesActual interlock sequence, key scheme, access procedure, contact ratings and safe operation

Compliance of individual switchgear does not validate a project-specific bus transfer, remote control or cross-panel interlock. The assembly manufacturer, system designer, protection/control engineer and operating authority must have explicit interface responsibilities.

2. Define safety invariants

An invariant is a statement that must remain true in every permitted mode. Typical—but not universal—MV examples are:

  • A breaker cannot be racked between test and service while closed.
  • A breaker cannot close in an undefined/intermediate truck position.
  • An earthing switch cannot close onto an energised circuit within the defined interlock zone.
  • A breaker cannot close while its associated earthing switch is closed.
  • Access to a hazardous compartment is prevented until the required isolation/earthing state is established.
  • Two incomers cannot parallel unsynchronised or non-parallelable sources.
  • A lockout condition prevents closing until authorised reset and cause clearance.
  • One maintained close command produces at most one close operation (anti-pumping).

Each invariant needs a defined protected boundary. “Bus dead” is not an invariant until measurement source, thresholds, delays, VT-failure response, induced voltage and all possible infeeds are defined.

3. Build a state and permissive matrix

Requested operationTypical required proofsInvalid/blocked examples
Breaker closeTruck in service or approved test position; earth switch open; mechanism ready; no lockout; valid control mode; topology/synchronism permissiveTruck intermediate, earth closed, spring not charged, close circuit unhealthy, maintained command after a trip
Breaker openTrip supply/path available; command authorisedOpening is generally not blocked by process interlocks; unsafe maintenance/test routing is separately controlled
Rack breakerBreaker proven open; racking handle/door/secondary plug state as designedBreaker closed or position indication contradictory
Close earth switchBreaker open; disconnector/truck isolated; no alternate infeed; key/access conditionsService position, live cable/bus, remote backfeed possible
Open access doorRequired isolation/earthing/shutter statePrimary circuit accessible while live

The exact matrix comes from the switchgear topology and operating rules. Mark whether each proof is mechanical, hardwired, IED logic, key-controlled or procedural; do not count two contacts driven by one shaft as fully independent barriers.

4. Barrier hierarchy

  1. Inherent arrangement: equipment geometry or switching topology removes the hazard.
  2. Mechanical interlock: direct mechanism prevents incompatible movement.
  3. Trapped-key system: physical key exchange enforces an operating sequence across equipment.
  4. Hardwired electrical permissive: field contacts directly interrupt control energy.
  5. IED/PLC/IEC 61850 logic: flexible topology-aware logic with communications/configuration dependencies.
  6. Indication/alarm/procedure: operator awareness and administrative control.

Use the risk assessment and product design to choose layers. A mimic screen or SCADA confirmation is not an equivalent replacement for a mechanical access interlock. Conversely, hardwiring dozens of remote topology contacts can create an untestable series chain; a validated distributed scheme may be appropriate if its availability, cyber, failure state and independent barriers are defined.

5. What “NO” and “NC” really mean

Contact symbols normally describe the device in a stated reference/unactuated condition, not necessarily the process-safe state. “Normally closed” is meaningless unless the drawing says whether the breaker is open, truck isolated, relay de-energised, spring discharged and earth switch open/closed.

  • Name breaker auxiliary contacts 52a/52b and define their relationship to main-contact/mechanism position.
  • For a disconnector or earth switch, label contacts by proven open/closed end position.
  • Use two end-position contacts to detect intermediate/contradictory states when needed.
  • Show relay coils de-energised and device states in the drawing legend.
  • State logical inversion at the IED; do not hide it behind a signal name.
  • Validate contact timing: an “open proof” may change before the primary gap reaches its guaranteed isolating position.

6. Fail-safe philosophy by function

FunctionTypical safe treatmentImportant limitation
Close permissiveRequire energised/closed proof path; broken wire or lost DC blocks closeCommon DC loss may also remove alarm/indication
Trip commandDirect dependable energise-to-trip path, supervised end-to-endDe-energising a relay cannot trip if the coil/DC source is dead unless a separate stored-energy/undervoltage release is designed
LockoutMechanically/electrically latched state with controlled resetReset circuit must not silently bypass the initiating cause
AlarmNormally energised relay can alarm on wire/DC lossCreates nuisance alarm on maintenance and may share common failures
Position validityEvaluate complementary contacts; 00/11 becomes invalid after travel allowanceBoth contacts may share one mechanism/plug/common
Remote interlockLoss/invalid data defaults to block closeOperational recovery/bypass must be governed

“De-energise to trip” and “energise to trip” are not slogans to apply globally. Select the failure direction for each hazard, prove that the physical actuator can achieve it, and account for DC loss, coil/open circuit and stored energy.

7. Typical breaker close-permissive chain

A common hardwired concept is close command → local/remote authority → anti-pumping → lockout reset/no trip → truck valid position → earth switch open → required door/key/inter-panel proofs → synchronism/dead-bus permission → spring charged → close coil. The order on paper should aid troubleshooting; electrically, any series contact can remove the path.

  • Do not put an unreliable indication contact in the trip-opening path.
  • Separate “mechanism ready” from “safe to close”; neither substitutes for the other.
  • Ensure a protection trip concurrent with close has priority and anti-pumping prevents repeated closing.
  • Check low-DC voltage at the coil through the entire contact chain.
  • Where an IED creates a master close permissive, define its power-up, watchdog, test-mode and output-contact failure state.
  • Use indication to identify the first missing permissive without bypassing the safety chain.

8. Truck, disconnector and earthing-switch logic

  • Breaker racking: direct mechanical proof of breaker open is preferable; electrical 52b may supplement and control motorised racking.
  • Valid truck state: service and test/isolated end positions are valid; neither end proof means intermediate and normally blocks close.
  • Earth switch close: require primary isolation from every relevant source, not merely local breaker open.
  • Earth switch open: often permitted for restoration, but key/access conditions and operator safety remain.
  • Door access: use assembly interlock/key sequence; do not depend only on SCADA bus voltage.
  • Shutters: their safety function and any padlocking/interlock must match the assembly documentation.

9. Cross-panel and bus-topology interlocks

Two-incomer/bus-coupler schemes introduce remote breaker states, source synchronism and alternate infeeds. Define the primary topology truth table and then decide whether hardwired contacts, IEC 61850 GOOSE or a controller carries each proof.

  • Use complementary breaker states and position validity, not a single “open” bit where failure matters.
  • Define behaviour on inter-panel cable open/short, DC loss, network failure and stale data.
  • Prevent diode/LED/test circuits from backfeeding a permissive through another panel.
  • Analyse shared auxiliary supply and common marshalling terminals across “independent” boards.
  • For parallel closing, require approved synchronism and source-parallel capability; for dead-bus closing, validate dead-source logic and VT health.
  • Time-stamp and alarm blocked/invalid states so operators understand why a command failed.

10. Contact and circuit electrical design

  • Use actual DC voltage envelope, coil current/inrush, L/R and make/carry/break duty.
  • Confirm whether the field contact or a 52a/52b contact interrupts the inductive coil.
  • Include series contact/terminal/cable voltage drop at hot/minimum-DC conditions.
  • Check contact minimum wetting current for high-impedance IED inputs.
  • Select suppression for contact protection without unacceptable release delay or unsafe retained energy.
  • Check cable capacitance, induced voltage and input leakage on long inter-panel circuits.
  • Protect each conductor/branch selectively without one fuse defeating independent safety channels.
  • Provide test isolation that cannot leave a hidden permanent bypass.

11. Supervision and diagnostics

  • Supervise DC feeder/MCB, IED watchdog, close circuit and trip circuit separately.
  • Use open/closed contact disagreement after a mechanism-specific travel delay.
  • Alarm intermediate truck/earth-switch position beyond normal transition time.
  • Identify the missing permissive on HMI without exposing an unauthorised software bypass.
  • Latch intermittent interlock failures with SOE where troubleshooting value justifies it.
  • Define alarm response: whether closing is blocked, local-only operation allowed or equipment removed from service.
  • Avoid alarm floods from one lost common; group root-cause logic while preserving individual diagnostics.

12. Bypass and maintenance modes

A bypass is a temporary change to the safety case. It requires a defined owner, written justification, compensating controls, visible indication, time limit and restoration evidence.

  • Use keyed/permission-controlled selectors or configuration authority appropriate to risk.
  • Bypass only the minimum failed proof, not an entire interlock chain.
  • Alarm locally and remotely; include bypass in shift handover and permit records.
  • Prevent bypass persistence after power cycle unless explicitly intended and governed.
  • Test mode must block unintended outputs while still allowing safe functional proof.
  • Never use a loose terminal jumper as an undocumented operational solution.
  • After restoration, remove bypass, test the repaired path and independently verify normal configuration.

13. FMEA: credible failures to insert

FailureExpected response
Open permissive wire / lost commonClose blocked; diagnostic alarm
Shorted/welded permissive contactIndependent barrier/state check still prevents hazardous operation or risk is documented
52a/52b contradictoryInvalid state, closing/racking blocked after transition delay
Truck between positionsClose inhibited and clear indication
IED power/watchdog failureDefined output dropout state; hardwired essential barrier remains where required
Remote interlock cable/network lostClose blocked; no stale “permission” retained
Diode short/openNo false parallel path; affected supervision operates
Close output stuck with maintained commandAnti-pumping limits to one close attempt; trip has priority
VT fuse failureNo false dead-bus/synchronism permission

14. FAT/SAT scenario testing

  1. Inspect mechanical/key interlocks against manufacturer sequence and primary topology.
  2. Prove every device end position and intermediate/contradictory contact state.
  3. Execute all allowed operations from local, remote and maintenance/test modes.
  4. Attempt every forbidden operation; verify the physical actuator does not energise/move.
  5. Insert open, short, welded-contact simulation, lost DC/common and IED/network failure.
  6. Test simultaneous trip and close, maintained close, spring recharge and anti-pumping.
  7. Exercise bus-coupler/incomer topologies, VT failure, dead-bus and synchronism conditions.
  8. Measure critical coil voltage and operation timing through the as-built permissive chain.
  9. Verify alarms/SOE, operator text, reset/bypass authority and power-cycle behaviour.
  10. Restore all links/keys/configuration; independently check as-left state and archive evidence.

15. Frequent design errors

ErrorWhy it failsCorrection
NC assumed fail-safeReference/process state undefinedDefine state and failure consequence
Single 52b proves breaker openContact/shaft/wiring can failUse required independent/mechanical proof and plausibility
Electrical logic replaces access interlockDC/software failure removes barrierRetain product/risk-required mechanical layer
Lost VT interpreted as dead busUnsafe close/earthing permissionVT supervision and topology-aware dead-bus logic
Long series chain without voltage studyClose coil undervoltageCalculate/minimise drops or use engineered interposing logic
Bypass has no expiryTemporary defeat becomes permanentGovern, alarm and independently restore
FAT tests only valid closeForbidden/failure behaviour unprovenNegative and fault-insertion matrix

16. Design-release checklist

  • Safety invariants and boundaries formally approved?
  • All valid/invalid primary states included?
  • Mechanical, key, hardwired, IED and procedural barriers allocated?
  • Contact physical state and timing unambiguous?
  • Broken wire, welded contact, common DC and intermediate position analysed?
  • Trip not improperly blocked by close interlocks?
  • Coil voltage and contact DC duty demonstrated?
  • Cross-panel/topology/VT failure responses fail safe?
  • Supervision identifies actionable root cause?
  • Bypass/test mode controlled, alarmed and restorable?
  • FAT/SAT includes forbidden operations and inserted failures?
  • As-built drawings, keys, logic/settings and operator instructions aligned?

References and further reading

Engineering note: Examples describe common patterns, not universal interlock rules. The approved primary topology, hazard assessment, switchgear manufacturer’s instructions and operating authority determine the final scheme.

LearnSwitchgear

Search the engineering library