Gas Detection System with Fail-Safe Relays: Correctly Programming Normally Energised Operation, Latching and Acknowledgement

Gaswarnanlage mit Gasmaster Zentrale, XgardIQ Gasdetektor und Fail Safe Abschaltung
→ Product category: Gas detectors

 

A fixed gas detection system must do more than detect an elevated gas concentration. It must also initiate the correct technical response. This may include a pre-alarm, main alarm, visual and audible warnings, ventilation control, closing a gas valve, shutting down equipment or forwarding an alarm to a control room.

Relay logic is a crucial part of this alarm chain. If an alarm contact is wired according to the normally de-energised principle, a power failure may prevent the relay from energising and the intended shutdown may not take place. With the normally energised principle, the relay drops out in the event of an alarm, cable break or power failure. This can provide safer behaviour, but only produces the intended result if the contactor, valve, fan and power supply have also been designed accordingly.

Latching and acknowledgement are equally important. A main alarm should not disappear unnoticed simply because the gas concentration falls below the alarm threshold after a temporary release. At the same time, an acknowledgement button must not reset an alarm that is still active or automatically restart equipment that has been shut down.

The relay configuration must therefore be derived from the risk assessment and the intended protective function. Terms such as normally closed, normally open, normally energised, fail-safe, latching and acknowledgeable must not be confused.

Complete control and evaluation systems can be found in the gas detection systems category. Suitable permanently installed detectors are grouped together under fixed gas detectors.

What function does the relay logic perform?

Gas detectors measure the concentration of a target gas and transmit the measured value to a gas detection control panel or another evaluation device. The control panel compares the measured value with the configured alarm thresholds and switches defined outputs depending on the current status.

Relay outputs provide an interface between the gas detection system and external safety equipment. Their volt-free contacts can be used to initiate functions such as:

  • activating visual and audible alarm devices,
  • switching on mechanical ventilation,
  • closing a solenoid valve,
  • shutting down machines or burners,
  • transmitting a message to a PLC, control room or building management system,
  • signalling a fault or power failure.

The gas detection control panel does not normally switch the high-power load directly. Its relay contact only provides a control signal to an interposing relay, contactor, safety relay or PLC. Contact rating, inrush current and inductive loads must be checked against the technical specifications.

The relay logic answers three central questions: What state is the relay in during fault-free operation? Which events should cause it to change state? And must the switched state remain active after the triggering gas concentration has fallen again?

Understanding volt-free contacts, normally closed and normally open contacts

A volt-free relay contact is galvanically isolated from the power supply and the internal electronics of the gas detection control panel. This allows an external circuit with its own voltage to be switched. However, volt-free does not automatically mean fail-safe or cable-break monitored.

A changeover contact generally provides three terminals:

  • COM: common relay contact,
  • NC: connected to COM when the relay coil is de-energised,
  • NO: disconnected from COM when the relay coil is de-energised.

The terms NC and NO refer to the electrically de-energised state of the relay coil. They do not automatically describe the normal operating state of the gas detection system. If the relay is continuously energised during fault-free operation, the normal process state already corresponds to the energised relay state. The actual contact positions are then reversed compared with the markings for the de-energised relay state.

This distinction is crucial when wiring the system. An electrician must not assume from the designation “NC” alone that the contact is closed during normal operation. It must first be established whether the relevant relay is configured as normally energised or normally de-energised.

Distinguishing between normally energised and normally de-energised operation

Principle State without alarm Response to alarm Behaviour during power failure
Normally de-energised principle Relay normally de-energised Relay energises Relay cannot energise; alarm function may fail to operate
Normally energised principle Relay normally energised Relay drops out Relay also drops out and can initiate a safe state

With the normally de-energised principle, the relay coil is energised only when an alarm occurs. This principle is simple and requires no coil power during normal operation. However, it has a safety-related disadvantage: if the power supply fails, the relay can no longer energise. A warning or shutdown that depends exclusively on the relay energising may therefore not be initiated.

With the normally energised principle, the relay is energised during normal, fault-free operation. In the event of a gas alarm, an appropriately configured fault or loss of power, it drops out. A closed monitoring circuit can therefore be opened and initiate a downstream shutdown.

The normally energised principle is therefore often preferred for safety-related functions. However, it does not turn a conventional relay circuit into a certified safety function. The complete chain consisting of gas detector, control panel, wiring, evaluation, actuator and power supply must be suitable for the required risk reduction.

What does fail-safe mean for a gas detection system?

Fail-safe means that a detected fault or the loss of required energy should lead to a defined safe state wherever possible. With a normally energised alarm relay, for example, both a main alarm and failure of the gas detection control panel can cause the relay to drop out.

The safe state depends on the application. For a gas supply, it may be a normally closed valve that closes when de-energised. For a machine, it may mean removing an enable signal. Ventilation is more difficult because a fan requires electrical energy to operate. A relay dropping out during a mains failure does not in itself ensure that the ventilation continues to function.

A fail-safe assessment must therefore include at least the following points:

  • failure of the gas detector,
  • open circuit or short circuit in the signal cable,
  • failure of the gas detection control panel,
  • open circuit in the relay wiring,
  • failure of an interposing relay or contactor,
  • loss of the actuator power supply,
  • mechanical failure of a valve or fan.

A volt-free relay contact cannot determine whether a valve has actually closed or a fan has actually started. For important functions, feedback contacts, airflow monitors, valve-position monitoring or other suitable feedback signals should therefore be considered.

Handling gas alarms, faults and power failures separately

A gas detection system should distinguish between a hazardous gas concentration and reduced monitoring capability. Both conditions may require a protective response, but they do not have the same meaning.

A gas alarm means that the measured value has reached a defined alarm threshold. A fault, by contrast, may be caused by a defective sensor, cable interruption, implausible measured value, internal device fault or interrupted communication.

The cause-and-effect matrix may specify, for example, that both a main alarm and a fault isolate the gas supply, but generate different messages. A horn for an acute gas hazard should not signal in exactly the same way as a maintenance fault if this prevents operating personnel from distinguishing between the conditions.

A power failure must also be clearly identifiable. If the main alarm relay is configured as normally energised, its drop-out can initiate a safe shutdown. However, a separate fault or mains-failure signal should also be provided so that the condition is not incorrectly interpreted as a confirmed gas concentration.

Assigning pre-alarm and main alarm functions appropriately

Many gas detection systems have at least two alarm levels. The pre-alarm responds at a lower concentration and is intended to allow an early countermeasure. The main alarm indicates a more hazardous condition and triggers more extensive protective measures.

A typical assignment, which must always be checked for the specific project, is:

  • Pre-alarm: message to the control room, yellow warning beacon, starting or increasing ventilation and investigating the cause,
  • Main alarm: red warning beacon, horn, isolating the gas supply, shutting down equipment and prohibiting access.

In some applications, the pre-alarm may be configured as non-latching if it controls only an early ventilation function. The main alarm, by contrast, is often configured as latching so that a temporary hazardous event remains recorded and does not disappear automatically.

The alarm thresholds and associated measures must not be copied generally from an example. The target gas, occupational exposure limits, lower explosive limit, room, ventilation, response times and risk assessment determine the appropriate strategy.

When must an alarm be latching?

With a latching alarm, the alarm state remains stored even after the measured value falls below the alarm threshold. The relay returns to its normal state only after a permissible reset.

Latching is particularly useful when:

  • a temporary gas release must not go unnoticed,
  • equipment must be released in a controlled manner after shutdown,
  • a valve must not reopen automatically,
  • the cause must be investigated before restart,
  • personnel may only re-enter the area after it has been released.

Latching should not be implemented only in a downstream visualisation system if the actual protective relay already resets automatically. If a safety shutdown is required, it must be clear at which point in the chain the interlock is implemented and how it is protected against unintended reset.

On some gas detection control panels, the available configuration options differ between alarm relays. A pre-alarm may be permanently non-latching, while main and common alarms are configurable. The required logic must therefore be compared with the actual device functions before ordering and commissioning.

Distinguishing between acknowledgement, muting and reset

In everyday language, the term “acknowledge” is often used for several different operating actions. For unambiguous programming, at least three functions should be separated.

Mute the audible alarm

The operating personnel confirm that the warning has been noticed. The horn can be muted while the warning beacon, relay state and alarm indication remain active. If a new alarm occurs or the alarm level increases, the audible warning should be reactivated according to the alarm philosophy.

Acknowledge the alarm

The alarm is marked as having been noticed. This may change the indication, but must not remove the existing hazardous condition.

Reset the alarm

The stored alarm state is cleared and the relay can return to its normal state. A reset should only be possible when the gas concentration is back within the permissible range and no relevant fault remains active.

An acknowledgement button must not suppress a gas concentration that is still present. Resetting the gas detection control panel should also not automatically restart the complete production system. Restart permission should be implemented as a separate, controlled process.

Controlling fans, valves and equipment shutdowns

The relay contacts of a gas detection control panel are primarily signal outputs. Large fan motors, solenoid valves with high inrush current or extensive machine circuits should be controlled through suitable interposing relays, contactors or safety switching devices.

For each actuator, the required behaviour upon loss of electrical power must be defined:

  • A normally closed gas valve can interrupt the gas supply when the voltage fails.
  • A fan stops during a power failure and may therefore require a protected or uninterruptible power supply.
  • A machine enable can be removed according to the normally energised principle and initiate a controlled stop.
  • A warning beacon or horn still requires energy to provide a warning during a mains failure.

For ventilation control, it must also be checked whether the fan is suitable for the installation area and the possible gas. The ventilation system must not carry released gas uncontrollably into other areas or create an airflow that diverts the leak away from the detector.

Considering cable breaks and line monitoring

The normally energised principle can make an open circuit between a relay contact and the evaluation system detectable if the monitored circuit is closed during normal operation. If the cable is interrupted, the downstream control system loses its enable signal.

However, this does not automatically apply to every cable within the alarm chain. A cable break in a parallel signal line, a short circuit between two conductors or a welded relay contact may remain undetected.

Depending on the system, reliable line monitoring may use measures such as:

  • 4–20 mA signals with manufacturer-defined fault-current ranges,
  • monitored digital input circuits with end-of-line resistors,
  • separate feedback contacts,
  • redundant contacts or safety relays,
  • digital communication with diagnostics and communication monitoring.

The precise meaning of current values below or above the measuring range is device-specific. It must not be defined without checking the data sheet and gas detection control panel documentation.

Connecting the gas detection control panel to a PLC and building management system

A PLC or building management system can display and record alarm conditions and control additional plant functions. The local gas detection control panel should nevertheless continue to indicate clearly which detector has generated an alarm or fault.

Clear signal names are important in the PLC program. Designations such as “Relay 1” or “Input 14” are not sufficient for a safety-related message. More useful descriptions include:

  • gas detection system operational,
  • pre-alarm area 1,
  • main alarm area 1,
  • common fault gas detection system,
  • mains failure or battery operation,
  • alarm acknowledged but still active.

Additional logical inversion in several systems should be avoided. If a signal uses the normally energised principle, it must be documented whether PLC input “1” represents the healthy condition or the alarm condition.

For critical shutdowns, it must be checked whether conventional PLC evaluation is sufficient or whether an appropriate safety-related architecture is required. A standard PLC and a single relay contact do not automatically meet the requirements of a particular Performance Level or Safety Integrity Level.

Planning for power failure, backup power and restart

A normally energised fail-safe relay drops out during a power failure. This can, for example, close a valve or remove a machine enable. However, visual warning, audible alarm, measurement and ventilation will continue without mains power only if an appropriate backup power supply is available.

The planning process should clarify:

  • Which components are supplied by a UPS or battery?
  • How long must gas monitoring continue during a mains failure?
  • Do alarm devices and communication remain operational?
  • Can the ventilation system operate from an emergency power supply?
  • How is failure of the main power supply indicated?
  • What happens when power returns?

After a power failure, equipment that was shut down safely should not restart automatically if the cause has not been clarified. The gas detection system may be operational again after power returns, while valves, machines or burners still require a separate manual release.

Creating a relay and cause-and-effect matrix

A clear cause-and-effect matrix should be prepared before wiring begins. It describes which relay switches for each condition, whether the output is latching and which external function is initiated.

Condition Example response Latching Reset condition
Normal operation Enable relay energised, no warning No Not required
Pre-alarm Start ventilation, yellow warning, notify control room Project-dependent Measured value below reset threshold
Main alarm Horn, red warning, close gas valve, lock out equipment Often yes Gas value safe, cause checked, manual reset
Sensor or cable fault Fault message and, where applicable, safe shutdown Project-dependent Fault cleared and acknowledged
Power failure Fail-safe shutdown, battery operation or fault message Often until controlled release Supply stable and equipment checked

This table is only an example. The specific response must be derived from the risk assessment. In particular, whether ventilation is appropriate for a particular gas and which equipment must be shut down cannot be answered universally.

Typical relay configuration errors

Error Possible consequence Suitable measure
Alarm relay configured only as normally de-energised Shutdown may not take place during a power failure Assess the fail-safe behaviour of the complete chain
NC and NO wired without considering the relay state Contact operates in exactly the opposite way during operation Show the energised and de-energised states in the circuit diagram
Main alarm not configured as latching A temporary hazardous condition disappears unnoticed Check interlocking and manual reset
Acknowledgement resets an active alarm Warning is cleared even though the hazard remains present Program muting, acknowledgement and reset as separate functions
Gas alarm and fault indicated identically Operating personnel cannot distinguish the cause Define clear messages and alarm devices
Fan switched directly by the control-panel relay Relay contact is overloaded by motor or inrush current Use a suitable interposing relay or contactor
Fail-safe considered only at the relay Actuator remains in a hazardous position during power failure Include the valve, contactor, feedback and power supply
Automatic restart after reset Equipment starts without investigation of the cause Provide a separate manual restart release
Only the relay contact is tested electrically Sensor, horn, valve or fan may still be defective Test the complete cause-and-effect chain using suitable test equipment

Practical example: Gas detection system in a plant room

Several gas-consuming devices are monitored in a plant room. Two fixed gas detectors are connected to a gas detection control panel via 4–20 mA. When a release begins, the mechanical ventilation should start first. At a higher concentration, a horn and red warning beacon must also be activated, the gas supply closed and the affected equipment locked out.

The pre-alarm is configured as non-latching. If the concentration falls consistently below the reset threshold, the ventilation can return to normal operation after a defined run-on period. The pre-alarm event nevertheless remains recorded in the event log.

The main alarm, by contrast, is configured as latching. The main alarm relay is energised during normal operation and drops out when an alarm occurs. This removes the enable signal from a downstream interposing relay. The gas valve is designed as normally closed and also closes if the power supply fails.

The horn can be muted after the alarm has been noticed. The warning beacon, main alarm indication, equipment interlock and closed gas valve remain active. A reset is only possible once both gas detectors again provide a permissible measured value and no fault remains active.

After the reset, the gas valve does not open automatically. The operator must first investigate the cause and switch the gas supply back on using a separate release. Alarm acknowledgement and equipment restart are therefore deliberately separated.

The fault relay is also normally energised. If a detector cable breaks or an internal fault occurs, the system reports that monitoring capability is reduced. Depending on the risk assessment, the gas supply is also isolated in this condition because reliable detection is no longer ensured.

Testing the complete alarm chain

A functioning display on the gas detection control panel does not confirm that the complete protective function is working. During commissioning and periodic testing, the entire cause-and-effect chain should be checked.

Depending on the system, this includes:

  1. Expose the gas detector to suitable test gas.
  2. Check measured-value transmission and alarm thresholds.
  3. Trigger the pre-alarm and main alarm separately.
  4. Measure relay states and contact assignments.
  5. Check the horn, warning beacon, ventilation and valve functions.
  6. Test latching, muting and reset.
  7. Simulate a cable break or detector fault.
  8. Check power failure and battery operation.
  9. Check transmission to the PLC, BMS or control room.
  10. Test restart and manual release.

For detectors with a 4–20 mA output, a UPS4E loop calibrator can be used to simulate defined input signals at the gas detection control panel. This allows the scaling, alarm thresholds, relay logic and signal forwarding to be tested systematically.

However, current simulation does not replace testing the gas detector with suitable test gas. It tests only the electrical signal path from the injection point onwards. Sensor response, gas access, filters, sensor drift and actual response time are not assessed.

Which products are suitable?

Gas detection systems and control panels

The gas detection systems category includes control panels and system solutions for the shared evaluation of several gas detectors. Depending on the size of the installation, compact control panels, addressable systems and solutions with multiple relay or communication outputs are available.

Gasmaster gas detection control panel

The Gasmaster gas detection control panel is suitable for the central monitoring of gas detectors and, depending on the version, other detector types. It provides alarm and fault relays as well as analogue and digital interfaces for external warning and control systems.

Depending on the function and device version, the relays can be configured in different ways. These include normally energised fail-safe states and latching or non-latching alarm functions. The configuration options differ between the individual relays. The current operating instructions and the specific wiring diagram are therefore authoritative.

Fixed gas detectors

The fixed gas detectors section contains detectors for flammable and toxic gases as well as oxygen monitoring. Depending on the device, 4–20 mA, Modbus, HART and local relays for pre-alarm, main alarm or fault may be available.

Local detector relays can be useful for individual measuring points. For several sensors, shared alarm zones or complex cause-and-effect matrices, central evaluation is often clearer and easier to test.

UPS4E loop calibrator

The UPS4E loop calibrator measures and simulates 4–20 mA signals and therefore supports commissioning and troubleshooting at detector, control-panel and PLC inputs. It is particularly suitable for checking scaling, alarm thresholds and electrical signal transmission.

Conclusion: Fail-safe behaviour must be planned across the complete alarm chain

The relay logic of a gas detection system determines whether a detected gas alarm, cable break or power failure initiates the intended protective response. A normally energised relay can make fault conditions more apparent than a contact operated solely according to the normally de-energised principle.

However, a fail-safe relay alone does not guarantee a safe plant condition. Interposing relays, contactors, valves, fans, feedback signals and power supplies must all be included in the assessment. For ventilation functions in particular, it must be remembered that a fan cannot operate without electrical energy.

Pre-alarm, main alarm and fault should be clearly distinguished. A main alarm is often configured as latching, while the audible warning can be muted separately. A reset must only be possible when the triggering gas concentration is no longer present. Restarting equipment that has been shut down should additionally require a deliberate release.

A documented cause-and-effect matrix must be prepared before programming begins. During commissioning, the complete chain from the gas detector through the control panel and relay outputs to the actual actuator must then be tested.

Frequently asked questions about relay logic in gas detection systems

What does the normally energised principle mean in a gas detection system?

The relay is energised during normal, fault-free operation. In the event of an alarm, an appropriately evaluated fault or a power failure, it drops out. This can remove a downstream enable signal or initiate a shutdown.

Is a normally closed contact automatically fail-safe?

No. NC and NO describe the contact position when the relay coil is de-energised. It is also essential to know whether the relay is energised during normal system operation and how the downstream circuit is evaluated.

Does a volt-free contact detect a cable break?

Not automatically. In a closed normally energised circuit, a cable break can remove the enable signal. However, additional measures such as end-of-line resistors, feedback signals or monitored circuits may be required for comprehensive line monitoring.

Should the main alarm be latching?

In many applications, latching is useful so that a hazardous condition does not disappear unnoticed and equipment that has been shut down is only released after the cause has been investigated. The specific requirement is derived from the risk assessment.

May an acknowledgement button reset the alarm?

Acknowledgement should initially only confirm that the alarm has been noticed. Resetting a latching alarm must only be possible when the measured value is safe again and no relevant fault remains active.

Can the horn be muted while a gas alarm remains active?

A separate mute function can be provided. The visual warning, alarm indication, relay function and equipment interlock must remain active. A new alarm or higher alarm level should reactivate the audible warning.

Can a gas control-panel relay switch a fan directly?

Generally, the relay contact should control only a suitable control circuit, interposing relay or contactor. The motor power, inrush current and inductive load may exceed the permissible contact rating of the control panel.

What happens during a power failure?

A normally energised relay drops out and can, for example, close a valve or remove an enable signal. Measurement, warning and ventilation continue only if the relevant components are supplied by a battery, UPS or emergency power source.

Should a gas alarm and a fault initiate the same shutdown?

This may be appropriate if reliable gas monitoring is no longer available during a fault. Nevertheless, gas alarms and faults must be indicated and recorded separately and unambiguously.

Is a 4–20 mA simulation sufficient for functional testing?

No. It tests the electrical input, alarm thresholds and downstream relay logic. The gas detector itself must additionally be tested using suitable test gas or the specified test procedure.

May equipment that has been shut down restart automatically after an alarm reset?

Automatic restart can be hazardous. In many applications, a separate manual release is required after the reset so that the cause, gas-free condition and equipment status can be checked beforehand.

Diese Website benutzt Cookies. Wenn du die Website weiter nutzt, gehen wir von deinem Einverständnis aus.