Functional Safety for Battery Storage and Hydrogen: New Hazards, Same Lifecycle
Grid-scale battery energy storage and hydrogen production are being built by organizations with deep functional safety capability applied to hazards they have not encountered before. The IEC 61511 lifecycle transfers without modification. What does not transfer is the scenario library, the failure data, and the assumptions about how a hazard develops.
Thermal runaway does not behave like an overpressure event. Hydrogen does not disperse like natural gas. Teams applying refinery-derived scenario thinking to these facilities produce SIL targets that look rigorous and rest on the wrong physics. This guide covers what changes and what does not. If you need the underlying framework first, see our guide to functional safety standards.
What Transfers Without Change
The lifecycle is the lifecycle. Hazard and risk assessment, SIL allocation, safety requirements specification, design, validation, proof testing and periodic assessment all apply exactly as they do in a chemical plant. So does the requirement for a cybersecurity risk assessment under Clause 8.2.4, which matters more than usual here because these assets are heavily networked and often remotely operated.
The competence requirement transfers too, and it is where most gaps appear. A practitioner who has run twenty refinery HAZOPs is competent in method but not automatically in battery chemistry failure modes. That distinction is one an assessor will examine.
Battery Energy Storage: The Hazards That Are Different
- Thermal runaway propagation. A single cell failure can cascade through a module and a rack. The safety function is often about detection speed and isolation rather than about pressure relief, and conventional gas detection may be too slow.
- Off-gassing before fire. Cells vent flammable and toxic gas before visible thermal event, which creates a detection opportunity that does not exist in most process hazards.
- Deflagration in enclosures. Vented gas accumulating in a container is an explosion hazard requiring specific ventilation and suppression logic.
- The BMS is not a safety system. Battery management systems are control functions, not safety instrumented functions, unless specifically designed and assessed as such. Treating a vendor BMS as a protection layer without evidence is a frequent and serious LOPA error.
|
The credit that most often does not survive assessment Taking risk reduction credit for the vendor battery management system as an independent protection layer. To count in LOPA, a layer must be independent, auditable and of demonstrated integrity. A proprietary BMS supplied without failure data, without independence from the control function, and without an integrity claim satisfies none of those. Removing that credit frequently changes the SIL target for the whole facility. |
Hydrogen: The Hazards That Are Different
- Very wide flammable range and low ignition energy. Leak scenarios that would be tolerable for methane are not tolerable for hydrogen.
- Buoyancy and dispersion behaviour. Hydrogen rises and accumulates at high points, so detector placement derived from heavier-than-air gas experience will miss releases.
- Invisible flame. Hydrogen fires are difficult to detect visually, which changes both the detection design and the emergency response assumptions in your scenarios.
- Material compatibility. Embrittlement affects component selection and therefore the failure data behind SIL verification.
Practical Implications for the Lifecycle
Three consequences follow, and they are all about evidence rather than method.
Your hazard study needs people who know the technology, not only people who know HAZOP. The guideword method works fine; the scenarios it surfaces depend entirely on who is in the room. Second, failure data for newer devices and configurations is thinner than for established process instrumentation, so SIL verification assumptions need documenting more carefully than usual. Third, because these facilities are typically remotely operated and heavily networked, the cybersecurity risk assessment required alongside the safety lifecycle carries real weight rather than being a formality.
Grid-connected storage also now sits inside a broader regulatory conversation about supply chain and equipment provenance, which is worth tracking alongside the safety work.
Why Choose Arista Cyber
Arista Cyber delivers the IEC 61511 lifecycle for energy transition assets with TUV Rheinland certified practitioners, and works across both functional safety and OT cybersecurity. For heavily networked, remotely operated facilities that combination is not optional, since Clause 8.2.4 requires the security assessment and these assets are exactly the case it was written for.
We work extensively across energy and utilities OT environments, so the analysis accounts for how these assets are actually monitored and controlled rather than how a design document says they are. And because we deliver from hazard study through validation, the evidence chain holds together.
Next Steps
If you are developing or operating battery storage or hydrogen assets, the first question is whether your hazard study team includes genuine technology competence. Explore our functional safety services, read about functional safety assessment stages, or contact the Arista Cyber team.
Common Questions
Does IEC 61511 apply to battery energy storage?
Yes. IEC 61511 applies to safety instrumented systems in the process industries, and grid-scale storage with protective instrumented functions falls within that scope. Sector-specific standards and codes also apply, but the functional safety lifecycle is IEC 61511.
Can we take LOPA credit for the battery management system?
Only with evidence. An independent protection layer must be independent of the initiating cause and of other layers, auditable, and of demonstrated integrity. A proprietary BMS supplied without failure data or an integrity claim does not meet that. Where the credit is removed, SIL targets frequently rise.
Do we need different competence for hydrogen HAZOPs?
The method is the same but the scenarios are not. Hydrogen dispersion, ignition energy, invisible flame and embrittlement all change what deviations matter and what consequences follow. A team competent in HAZOP but unfamiliar with hydrogen behaviour will run a well-structured study that misses the scenarios that matter.
|
Building battery storage or hydrogen assets? Arista Cyber delivers the IEC 61511 lifecycle for energy transition facilities, including the cybersecurity assessment Clause 8.2.4 requires. |