Specified vs. Delivered: Reliability Engineering Applies to Documentation Too
Why a power system study must be checked before issue, not after the incident
By Harald Zieger, Dipl.-Ing. (EE)
Every reliability engineer knows the component that fails in service because nobody checked it at receiving inspection. Power system studies belong on that list. A specification calls for power flow with voltage drop, short circuit and arc-flash analysis. A study group delivers a report, the report goes to the customer, and far more often than not it sits in the contract papers until something happens.
Then it becomes the most important document on site. OSHA has not adopted NFPA 70E. It cites 29 CFR 1910.132(d), which requires a hazard assessment for PPE, and 29 CFR 1910.335, which requires appropriate electrical protective equipment. NFPA 70E serves as evidence of recognized practice and is the practical benchmark. The labels come from the study. If the study is wrong, so are the labels and the PPE.
The case below is a disguised composite; names, ratings and system details are changed. It is not about an individual engineer. When I rebuilt the network, the calculations reproduced correctly. The problems were in everything around them, the kind an organization produces when reports are built from earlier reports, schedules are compressed, and nobody independent checks the document before issue.
Deliver what was specified
The specification asked for a load flow with voltage drop. The report delivered short circuit, coordination and arc flash, with no documented scope change. Its top-priority recommendations replaced breakers to meet a 0.1 s selectivity criterion attributed to Article 700. The loads were not emergency loads, and 0.1 s comes from 517.31(G), a health care rule. If the loads are legally required standby, 701.32 demands full-range selective coordination; if optional standby (Article 702), there is no requirement. Either way, the stated basis did not hold.
Make the inputs match reality
Generator ratings and reactances in the model did not match the data sheet. Utility X/R and minimum fault current were assumed without a utility letter. One feeder's conductor material was ambiguous. Without a load flow, operating voltage, transformer taps and motor status were assumed as well. That matters because arcing current, not bolted current, decides how fast a breaker trips.
An illustrative example, with invented numbers computed to IEEE 1584-2018: a 480 V panel is protected by a breaker with a 4,000 A short-time pickup. At nominal voltage the reduced arcing current is 4.21 kA, the breaker clears in 0.10 s, and the label reads 1.0 cal/cm². At 5% below nominal the reduced arcing current falls to 3.89 kA, below pickup. The 2 s cap applies and the label becomes 11.8 cal/cm². Same panel, same breaker, more than ten times the energy.
Most buses in the composite were labeled at that 2 s cap, and no clearing device was named at the service entrance. A 2 s label is a finding, not a result. The curves also carried an earlier revision than the results, one device ID served two breakers, and the labels assumed settings not yet installed.
Copy, paste, then correct
Most of these findings are what you would expect when a report is built by copying a previous one and correcting it. Templates save time, but they also carry forward whatever was specific to the old job: a health care criterion, an empty promised section, assumptions that no longer fit, curves from an earlier run. In reliability terms this is a common-cause failure: one latent defect replicates into every report built from it. The person filling in the template under deadline is rarely the one to catch it. The defense is organizational: controlled templates and an independent check, signed before issue.
Before leaving harbor
Earlier in my career I served aboard a fishing trawler in the Barents Sea. We had a departure checklist for each section of the vessel's electrical systems, and everything was verified before we left harbor. A separate checklist covered spare parts, because there is no store in the middle of the Barents Sea. A study works the same way. Once it is issued and the labels are on the equipment, you are at sea. The checking has to happen before issue.
Reliability engineering applies to documentation. A study must deliver what was specified, its inputs must match reality, and it must be checked independently before issue, because errors in an issued study end up on labels in the field. Owners and reviewers can ask for that check as a deliverable.
Departure checklist for a study
1 | Scope | Every specified study delivered, or a scope change documented. | ☐ |
2 | Code basis | Governing NEC article and selectivity criterion stated per alternate source. | ☐ |
3 | Source data | Utility letter and generator data sheet match the model. | ☐ |
4 | Assumptions | Every assumed input listed with its source; conductors confirmed. | ☐ |
5 | Load flow | Operating voltages, taps and motor status used in fault and arc-flash cases. | ☐ |
6 | Arc flash | Clearing device named for every bus; any 2 s cap justified. | ☐ |
7 | Sensitivity | Buses near a trip pickup checked for voltage and pickup tolerance. | ☐ |
8 | Revision | One revision throughout; unique device IDs; labels match installed settings. | ☐ |
9 | Templates | Nothing carried over from a previous job unless confirmed. | ☐ |
10 | Independent check | Documented before issue by someone other than the preparer. | ☐ |
Harald Zieger, Dipl.-Ing. (EE), has spent decades on the plant floor in electrical maintenance and reliability. He is the author of textbooks on maintenance engineering and reliability engineering.
References
[1] IEEE Std 1584-2018, IEEE Guide for Performing Arc-Flash Hazard Calculations.
[2] NFPA 70E, Standard for Electrical Safety in the Workplace, 2024 edition.
[3] NFPA 70, National Electrical Code, 2023 edition: 517.31(G); 701.32; Article 702.
[4] 29 CFR 1910.132(d) and 29 CFR 1910.335.