Interlock and Negative Testing During MV Switchgear FAT

A comprehensive hazard- and state-based method for proving permitted and prohibited MV switchgear transitions during FAT.

An interlock is proven by the dangerous or invalid action it prevents, not only by the normal sequence it permits. Negative FAT deliberately attempts prohibited commands and mechanical operations under controlled conditions, then verifies the specific blocking element, the absence of actuator energy and the correct indication/alarm.

This guide develops a state-based interlock test for MV metal-enclosed switchgear. It covers mechanical, electrical, key and programmable interlocks; breaker racking, earthing switches, shutters, doors, control authority, auxiliary-power loss, welded/stale indications, GOOSE/PLC logic, bypasses, emergency releases, safe force limits and auditable evidence.

Executive conclusions

  • Convert the interlock philosophy into a complete state/transition matrix; prose alone misses combinations.
  • Test permitted and prohibited transitions from every safety-relevant state.
  • For “no operation” results, prove the command/attempt occurred and was blocked by the intended interlock—not by a dead supply, disconnected lead or unrelated fault.
  • Never apply destructive force. Use only the manufacturer’s specified handle force/torque and method.
  • Test mechanical and electrical layers independently where safe; one layer can hide failure of the other.
  • Validate physical position against auxiliary/limit-switch indication; a stale bit can defeat PLC/GOOSE logic.
  • Include loss and restoration of DC, local/remote mode, communication, IED reboot and redundant-channel failures.
  • Control every bypass, defeat key, test flag and forced point under a signed register.
  • Emergency release/defeat provisions require a separate authorised procedure, warning and post-use restoration.
  • Any interlock change requires regression across all affected states, panels and interfaces.

1. Interlock layers

LayerExampleFailure concern
MechanicalCam blocks racking while breaker closedWear, misadjustment, excessive force
Electrical hardwiredEarth-switch contact opens close circuitWrong contact/polarity, welded/bypassed wire
Key exchangeKey released only with earthing switch closedDuplicate/wrong key, removable in wrong state
Relay/PLC logicRemote close requires service position and no 86Stale input, wrong mapping, boot/default state
IEC 61850 GOOSEBus/earth permissive from another IEDBad quality, lost subscription, configuration error
ProceduralPermit/LOTO before emergency defeatHuman error; not a substitute for engineered interlock

Layering can improve safety, but only if common dependencies and precedence are understood. A software block cannot compensate for a mechanically unsafe access condition unless the qualified design explicitly relies on it.

2. Start with hazards and required invariants

  • A breaker shall not be racked while closed.
  • A breaker shall not close in an undefined/intermediate truck position.
  • An earthing switch shall not close onto an energised/connected circuit under prohibited conditions.
  • A breaker shall not connect to a circuit that is earthed where the design prohibits it.
  • Access doors/covers shall not open in states restricted by the qualified design.
  • Shutters shall prevent access to primary contacts when the withdrawable device is removed.
  • Remote commands shall not override local/maintenance authority.
  • A lockout or protection block shall have the specified precedence.
  • Loss of auxiliary power/communication shall move logic to the defined safe state.

Write invariants independently of the implementation. Then map each to mechanical, electrical and logic controls plus verification evidence.

3. Model the state space

A practical state vector can include:

S = {breaker O/C, truck DIS/TEST/SVC/TRANS, earth switch O/C, door O/C, spring CH/DIS, 86 RST/OP, local/remote, DC healthy/lost}

Not every mathematical combination is physically reachable, but listing variables exposes missing tests. Define each allowed transition with prerequisite and expected result.

From stateAttemptAllowed?Expected block/action
Breaker closed, truck serviceRack toward testNoMechanical block; no movement
Breaker open, truck service, earth openRack toward testYesControlled withdrawal; shutters/earth contact sequence
Truck serviceClose earthing switchNoMechanical/key/electrical block
Earth switch closedInsert/rack breaker to serviceNoRacking blocked
Truck intermediateElectrical close commandNoPosition permissive absent; coil no current

4. Preconditions and observability

  • Approved interlock matrix, schematics, key schedule, logic/SCL and device manuals available.
  • Main circuit de-energised, isolated and earthed; stored energy controlled.
  • Test force/torque limits and permitted attempts defined.
  • Physical state independently confirmed—not inferred only from HMI.
  • Command injection point and expected internal logic visible.
  • Coil voltage/current monitored for blocked electrical commands.
  • Position switches, PLC/IED inputs, outputs, alarms and SOE recorded.
  • Bypass/emergency defeat devices sealed/controlled.

For a blocked close test, a complete record can show: HMI command accepted, local/remote authority true, earth-switch permissive false, close output false, zero close-coil current, breaker remains open, “close blocked—earth switch closed” event generated.

4A. Achieving complete coverage without random testing

The theoretical state count grows rapidly, so use hazard-based reduction rather than ad-hoc sampling. First test every transition that can connect, energise, earth, expose or remotely operate a primary circuit. Then add boundary and failure states:

  • each valid source state immediately before and after a position switch changes;
  • every mechanical intermediate position that can persist;
  • each independent interlock channel opened/stuck where safe to simulate;
  • all control-authority modes and command sources;
  • loss/restoration of each shared supply or communication dependency;
  • representative identical panels only after wiring/configuration identity is proven, with full escalation if one fails;
  • every design variant: incomer, feeder, bus coupler, VT, motor and earthing panel as applicable.

Maintain bidirectional coverage. Proving that “earth switch closed blocks breaker insertion” does not prove that “breaker connected blocks earth-switch closure”; the two directions can use different cams, keys or contacts. Link every test row to a hazard and an implemented blocking layer so omissions are visible.

5. Breaker racking interlocks

  • Attempt to insert/rack a closed breaker using only allowed force; movement must be blocked.
  • Attempt electrical close during transition/intermediate position; output/coil must remain de-energised.
  • Verify racking is permitted with breaker open and other prerequisites satisfied.
  • Verify service/test/disconnected stops and positive position indication.
  • Attempt operation with racking handle inserted if the design blocks close or handle insertion.
  • Attempt removal before disconnected/released state; retention must work.
  • Check secondary plug connection/disconnection restrictions in each state.
  • Test identical/interchangeable breaker combinations required by the ITP.

6. Earthing-switch interlocks

  • With breaker/truck in prohibited connected state, attempt earth-switch close.
  • With earthing switch closed, attempt breaker insertion/racking and close.
  • Verify permitted operation only in the defined isolated state.
  • Check indicator and auxiliary contacts against actual blade/contact position.
  • Test door/key release conditions tied to the earthing switch.
  • Simulate a discrepant auxiliary contact in logic-based schemes and verify safe response/alarm.
  • Check motorised earth-switch local/remote authority and command timeout.
  • Verify emergency/manual operation cannot casually bypass required block.

7. Door, cover and shutter interlocks

  • Attempt door access in every prohibited truck/breaker/earth state.
  • Verify permitted access only when the qualified design says it is safe.
  • Check door closure/latching prerequisite for racking or energisation where provided.
  • Remove breaker and verify shutters close/lock automatically.
  • Attempt shutter access using only the allowed inspection method/force.
  • Test padlocks and key release without damaging the mechanism.
  • Confirm access interlock is not defeated by door misalignment or partially latched state.
  • Check pressure-relief panels are not mistaken for routine access covers.

LSC/IAC/IP classifications and manufacturer instructions determine permitted access/door conditions. Do not infer a universal rule from another switchgear family.

8. Electrical close/trip interlocks

  • service/test position permissives and intermediate-state block;
  • earthing-switch/disconnector/door permissives;
  • spring charged, mechanism pressure/energy and breaker-ready;
  • 86 lockout, protection block and maintenance/test mode;
  • synchronism-check, live/dead bus/line and transfer permissives;
  • local/remote authority and remote-enable;
  • anti-pumping and close-command reset;
  • trip precedence over close and trip-free operation;
  • dual trip/close channels and common-mode dependencies.

Trip circuits are normally designed to remain available under conditions that block closing; verify the philosophy rather than applying one universal rule.

9. Key-interlock testing

  • Match every lock/key engraving and unique code to the approved key schedule.
  • Verify key can be inserted/removed only in intended mechanism states.
  • Execute the complete exchange sequence across panels/devices.
  • Try incorrect keys and duplicate/master keys under controlled scope.
  • Check trapped-key retention under light specified pull—not destructive force.
  • Verify spare keys are controlled/sealed and not available operationally without authorisation.
  • Test mechanical operation after key-cylinder adjustment.
  • Record all keys at FAT closeout/packing.

10. Programmable and IEC 61850 interlocks

  • Trace physical input → IED data object → logic → output/GOOSE → receiving logic → actuator.
  • Verify normal true/false polarity and fail-safe meaning.
  • Test GOOSE quality/test/simulation states and subscription supervision.
  • Open publisher/network path; verify defined fail-safe block/alarm.
  • Test IED/network-switch reboot and delayed/stale value handling.
  • Verify redundant network failure behaviour and no duplicate command.
  • Check SCD/CID dataset, APPID/VLAN and subscriber mapping.
  • Record logic/SCL checksum and time-stamped events at both ends.

11. Auxiliary-power loss and restoration

ConditionTest question
DC control lossDoes mechanical safety remain; are commands blocked and loss alarmed?
One redundant supply lostDoes designed function continue without unsafe state?
Position-input supply lostDoes logic treat unknown as safe/block and alarm discrepancy?
DC restored with command heldCan a stale close command cause unintended operation?
IED/PLC rebootAre outputs fail-safe; when are permissives revalidated?
Communication restoredAre stale states discarded and new quality accepted correctly?

12. Single-failure and discrepancy tests

  • open/welded/stuck simulation of critical auxiliary contact;
  • service and test position switches simultaneously true/false;
  • earth-switch physical/auxiliary mismatch;
  • door switch failed closed;
  • loss of one hardwired permissive channel;
  • GOOSE bad quality/loss versus last known value;
  • duplicate/conflicting local and remote commands;
  • trip active while close command held;
  • 86 reset attempt while initiating condition remains.

Only perform fault injection at safe test boundaries. Do not damage sealed safety switches or short outputs. Use approved simulators/test blocks and restore immediately.

13. Bypasses and emergency defeat

  • Identify every manufacturer-provided defeat, emergency release, maintenance switch and software force.
  • Require authorisation, risk assessment and no-energisation boundary for use.
  • Verify warning/label and controlled tool/key access.
  • Test only the documented purpose and recovery sequence.
  • Alarm/log bypass state where designed.
  • Seal/lock and independently verify normal state after use.
  • Never create an improvised jumper to expedite FAT without engineering approval.

14. Safe force and negative attempt

A successful mechanical interlock should resist the specified operating attempt, but “try harder” is not a test method. Define handle length, applied force/torque, direction and duration from the product procedure. Use a calibrated force/torque tool where required. Stop on deformation, abnormal noise or unintended movement and open an NCR.

15. Test execution sequence

  1. Review hazard/invariant and exact matrix row.
  2. Set/independently confirm physical and logic initial state.
  3. Verify safe energy/earthing boundary and permitted test force.
  4. Apply the command/mechanical attempt once in a controlled way.
  5. Observe block layer, motion, coil current/output, logic and alarm/SOE.
  6. Record actual result before changing state.
  7. Return to known state; verify no damage or latched force.
  8. Proceed through all permitted/prohibited transitions.
  9. Close deviations, repeat and regress affected rows.
  10. Remove bypasses/forces and verify final as-left matrix sanity test.

16. Record and acceptance

  • matrix row, hazard and requirement reference;
  • panel/breaker/IED and configuration IDs;
  • initial physical/logic states;
  • attempted transition, source and force/torque;
  • intended blocking layer and observed internal state;
  • movement/coil voltage-current/output result;
  • indication, alarm and SOE;
  • permitted transition result and final state;
  • NCR/adjustment/change/regression;
  • bypass/force removal and witness sign-off.

Common mistakes

  • Testing only normal permitted sequence.
  • Accepting no motion when the test command never arrived.
  • Using excessive force on a mechanical block.
  • Relying on one layer while another is untested.
  • Trusting auxiliary indication without physical position.
  • Ignoring intermediate truck states and DC recovery.
  • Not testing GOOSE loss/bad quality/stale states.
  • Leaving duplicate/spare keys uncontrolled.
  • Using temporary jumpers with no register.
  • Changing one interlock and repeating only one row.

Official standards and primary references

Engineering note: The manufacturer’s qualified interlock design and project philosophy control. Negative testing must never create the hazard it is intended to prevent.

LearnSwitchgear

Search the engineering library