Functional Safety Assessment of Lithium-Ion Battery Systems for Battery Energy Storage Systems: A Comparative Analysis and Unified Approach

As the global energy transition accelerates toward the “dual carbon” goals of carbon peak and carbon neutrality, battery energy storage systems have become a cornerstone of modern power grids. Among various storage technologies, lithium-ion battery systems dominate due to their high energy density, long cycle life, and declining costs. However, the safety of these systems — particularly functional safety — remains a critical concern. Functional safety ensures that the system operates correctly in response to faults, preventing hazardous events such as thermal runaway, fire, or explosion. Different regions and standards bodies have developed their own requirements for functional safety assessment of lithium-ion battery systems used in battery energy storage systems. This diversity poses challenges for manufacturers, engineers, and regulators who must navigate multiple regulatory landscapes. In this article, I present a first-person perspective on the functional safety requirements from five major standards: IEC 62619, UL 1973, UL 9540, VDE-AR-E 2510-50, and GB/T 34131. I compare and analyze their differences, and propose a unified methodology that can cover the gaps across these standards. The goal is to provide a practical reference for engineers working on functional safety of battery energy storage systems.

Introduction

The rapid deployment of battery energy storage systems (BESS) in utility-scale, commercial, and residential applications has highlighted the need for robust safety standards. Lithium-ion batteries, while efficient, pose inherent risks due to their high energy content and sensitivity to operating conditions. Overcharging, overdischarging, short circuits, and thermal abuse can lead to catastrophic failures. Functional safety, as defined by IEC 61508, is the part of the overall safety that depends on a system or equipment operating correctly in response to its inputs. For BESS, functional safety encompasses the battery management system (BMS), protection circuits, and software that monitor and control the battery within safe limits.

In my experience as a functional safety engineer, I have encountered multiple standards that specify requirements for safety analysis, risk assessment, hardware and software design, and testing. The lack of harmonization means that a product certified to one standard may not automatically meet another, leading to additional costs and time for re-assessment. In this paper, I aim to demystify the differences and provide a consolidated approach that satisfies the key requirements of the most influential standards for battery energy storage systems.

Functional Safety Requirements in Major Standards

1. IEC 62619:2022

IEC 62619 is a global standard for secondary lithium cells and batteries used in industrial applications, including battery energy storage systems. Its functional safety requirements are outlined in clauses 8.1 and 8.2.1. The standard mandates that for safety-critical functions implemented via electronic and software controls, a functional safety analysis must be conducted. This analysis should include hazard identification, risk assessment, and mitigation using methods such as FMEA (IEC 60812) or FTA (IEC 61025). The standard references IEC 61508, IEC 60730-1 Annex H, or ISO 13849 as acceptable functional safety standards. It explicitly requires that the BMS control the cell operating range (voltage, temperature, current) and ensure safety during charging. However, IEC 62619 does not specify a minimum safety integrity level (SIL) or performance level (PL), nor does it address discharging control or remote software updates.

2. UL 1973:2022

UL 1973 covers stationary and motive auxiliary power batteries used in battery energy storage systems. Its functional safety section (7.8 and 7.9) requires a system safety analysis including hazard identification, risk analysis, and risk assessment. Active protection devices implementing critical safety functions must have redundancy and be certified to at least SIL 2 (IEC 61508), PL c (ISO 13849), or ASIL C (ISO 26262). The standard also requires compliance with UL 991 (FMEA for solid-state devices), UL 60730-1 or CSA C22.2 No. 0.8 for internal fault protection (Class B), and software evaluation per UL 1998 (Class 1) or CSA C22.2 No. 0.8 Class B. Additionally, EMI immunity per IEC 61000-4 series is required, and if remote software updates are possible, UL 5500 applies. UL 1973 explicitly considers single fault conditions and charging/discharging control.

3. UL 9540:2023

UL 9540 is the standard for energy storage systems and equipment. It refers to UL 1973 for battery system requirements and adds its own system-level functional safety requirements in Chapter 15. The standard requires a safety analysis covering hazard identification, risk analysis, and risk assessment, with FMEA consideration for critical components and interactions. Acceptable functional safety standards include UL 991 + UL 1998, CSA C22.2 No. 0.8 Class B, UL 60730-1 Annex H Class B, IEC 61508 (SIL 2), ISO 13849-1/2 (PL c), or ISO 26262 (ASIL C). Remote software updates must comply with UL 5500. UL 9540 does not specify detailed battery-level parameters but relies on the battery standard.

4. VDE-AR-E 2510-50:2017

This German standard specifically addresses stationary battery energy storage systems with lithium batteries. Its functional safety requirements (Section 4 and 7) mandate a risk assessment covering the entire lifecycle (production, transport, installation, operation, maintenance, decommissioning). Risk reduction measures must be evaluated per IEC 61508, ISO 26262, ISO 13849, or IEC 62061. The standard requires the BMS to ensure cell voltage, current, and temperature are within permissible limits even under single fault conditions. It includes practical test requirements such as voltage measurement plausibility, open-circuit detection for sensor lines, interlock function checks, and light-load functional testing. Residual risks must be documented in the operating manual. VDE-AR-E 2510-50 also emphasizes software design and development according to functional safety principles.

5. GB/T 34131:2023

GB/T 34131 is the Chinese national standard for battery management systems in electrical energy storage. It specifies technical requirements for BMS including data acquisition, communication, alarm, protection, control, state estimation, balancing, insulation resistance detection, parameter setting, data storage, display, dielectric strength, electrical adaptability, electromagnetic compatibility, and system availability. It also provides test verification methods in Chapter 7. However, this standard does not explicitly require a functional safety analysis or reference a functional safety standard like IEC 61508. It focuses more on performance and reliability rather than systematic safety integrity.

Comparative Analysis of Standards

To better understand the differences and commonalities, I have summarized key aspects in Table 1 below.

Table 1: Comparison of Functional Safety Requirements in Major BESS Standards
Aspect IEC 62619:2022 UL 1973:2022 UL 9540:2023 VDE-AR-E 2510-50:2017 GB/T 34131:2023
Safety analysis (FMEA/FTA) Required (ref. IEC 60812, IEC 61025) Required (ref. IEC 60812, IEC 61025, MIL-STD-1629A) Required (ref. IEC 60812, IEC 61025, MIL-STD-882E) Required (lifecycle risk assessment) Not specified
Functional safety standard reference IEC 61508, IEC 60730-1 Annex H, ISO 13849 IEC 61508 (SIL 2), ISO 13849 (PL c), ISO 26262 (ASIL C) UL 991+UL1998, CSA C22.2 No.0.8 Class B, IEC61508 SIL2, ISO13849 PL c, ISO26262 ASIL C IEC 61508, ISO 26262, ISO 13849, IEC 62061 None
Minimum safety integrity level Not specified SIL 2 / PL c / ASIL C SIL 2 / PL c / ASIL C Not specified (depends on risk) N/A
Controlled parameters Voltage, current, temperature (charging) Voltage, current, temperature (charging/discharging) Refer to UL 1973 Voltage, current, temperature Voltage, current, temperature, SOC, etc.
Single fault consideration Implied by functional safety analysis Explicitly required Explicitly required Explicitly required Not mentioned
Software requirements Referenced via IEC 61508 etc. UL 1998 Class 1 or CSA C22.2 No.0.8 Class B Same as UL 1973 Functional safety design Specific BMS functions, no safety standard
EMI/EMC Not explicitly IEC 61000-4 series Not explicitly Not explicitly Yes (electromagnetic compatibility)
Remote software update Not addressed UL 5500 UL 5500 Not addressed Not addressed
Lifecycle risk assessment Not explicit Not explicit Not explicit Yes (production to disposal) No
Test verification BMS charging safety, operating range FMEA, internal fault tests, software tests System-level tests per UL 1973 Voltage plausibility, open-circuit detection, light-load tests Detailed test procedures (Chapter 7)

From Table 1, it is evident that UL 1973 and UL 9540 have the most comprehensive requirements for safety integrity levels and specific component certification. VDE-AR-E 2510-50 stands out for its lifecycle approach and detailed practical test requirements. IEC 62619 provides a flexible framework but lacks concrete levels. GB/T 34131 is more focused on BMS performance and reliability but omits functional safety assessment altogether. This gap means that a BMS certified to GB/T 34131 may not be accepted in regions requiring a functional safety standard like IEC 61508.

Common Methodology for Unified Functional Safety Assessment

Based on the analysis, I propose a unified approach that can satisfy the essential requirements of all the above standards for battery energy storage systems. This methodology consists of three main phases: risk assessment, hardware/software design, and verification testing.

Phase 1: Risk Assessment

The risk assessment must cover the entire lifecycle of the battery energy storage system, including production, transport, installation, operation, maintenance, and disposal. The following steps are recommended:

  • Hazard identification: Use FMEA (bottom-up) and FTA (top-down) methods as per IEC 60812 and IEC 61025. Consider hazards such as overvoltage, undervoltage, overtemperature, undervoltage, overcurrent, short circuit, reverse polarity, external short, internal short, thermal runaway, electrolyte leakage, gas emission, fire, explosion, electromagnetic interference, and physical abuse.
  • Risk analysis and evaluation: Determine the severity and probability of each hazardous event. Use a risk matrix to define acceptable risk levels. For battery energy storage systems, typical risk acceptance criteria are based on IEC 61508, SIL 2 or equivalent.
  • Risk reduction: Implement safety functions to reduce the risk to an acceptable level. Re-assess after implementation. Document residual risks in the user manual.

Phase 2: Hardware and Software Architecture Design

Hardware architecture must ensure that critical safety functions are robust to single faults. Two common architectures are:

  • Single channel with dual protection (Class B): One channel with two independent protection mechanisms (e.g., overvoltage detection by two separate voltage sensors). This architecture is acceptable for up to SIL 2 or PL c if the diagnostic coverage is high.
  • Dual channel architecture (Class B or C): Two independent channels, each capable of performing the safety function. This provides redundancy and is required for higher SIL levels.

Software development should follow a structured lifecycle model such as the V-model, as shown in Figure 1. The V-model emphasizes verification and validation at each development phase. For Class B or C, the software must avoid systematic faults through techniques like defensive programming, diversity, and testing.

Figure 1: Example of a V-model for software development in functional safety (adapted from IEC 61508-3). The left side represents system and software specification, the bottom represents implementation, and the right side represents integration and testing.

For hardware, the single fault consideration must include all components and integrated circuits. For ICs, fault simulation should include shorts and stuck-at faults on output pins, considering all combinations as a single fault. This is in line with UL 991 and UL 60730-1 Annex H.

Phase 3: Verification and Testing

Testing must cover the battery management system and its protection functions. The following tests are recommended based on the standards:

  • Voltage measurement accuracy and plausibility: Verify that the BMS can detect sensor faults (e.g., open circuit, drift) and respond appropriately.
  • Current and temperature measurement tests: Ensure accuracy under all operating conditions.
  • Protection function tests: Induce overvoltage, undervoltage, overtemperature, undervoltage, overcurrent, and short circuit conditions to verify that the BMS transitions the system to a safe state within required time.
  • Single fault injection tests: Simulate a single fault in the protection circuit (e.g., a stuck-at fault in an ADC) and verify that the redundant path still operates.
  • Software verification: Perform static analysis, dynamic testing, and fault injection testing to ensure software meets the required safety integrity level.
  • EMC tests: Conduct immunity tests per IEC 61000-4 series to ensure the BMS does not malfunction in electromagnetic environments.
  • Environmental tests: Include thermal cycling, humidity, vibration, and transport tests to ensure reliability over the product lifecycle.

Table 2 summarizes the recommended minimum test matrix to cover the requirements of the five standards.

Table 2: Recommended Minimum Test Matrix for Functional Safety of BESS Lithium-Ion Battery Systems
Test Item Applicable Standard Reference Acceptance Criteria
Voltage measurement accuracy VDE-AR-E 2510-50, IEC 62619 Within ±1% or as per manufacturer specification
Current measurement accuracy IEC 62619, UL 1973 Within ±2%
Temperature measurement accuracy All standards Within ±2°C
Overvoltage protection All standards Activation within given voltage threshold, reaction time < 100 ms
Undervoltage protection All standards Activation within threshold, reaction time < 1 s
Overtemperature protection All standards Activation within threshold, reaction time < 10 s
Overcurrent protection (charge/discharge) UL 1973, VDE Activation within predefined time-current curve
Single fault (e.g., sensor open circuit) UL 1973, VDE System switches to safe state via redundant path
Software functional test UL 1998, IEC 61508 No unintended behavior; all safety functions passed
EMC immunity (radiated, conducted) UL 1973, GB/T 34131 No malfunction up to severity level specified
Thermal cycling (temperature shock) GB/T 34131 No physical damage, insulation integrity maintained
Transport simulation (vibration, drop) IEC 62619, UL 1973 No leakage, no short circuits, no loss of functionality

Mathematical Equations for Safety Integrity Level Determination

Functional safety often involves quantifying probabilities of failure. The target failure measure for a safety function can be expressed by the average probability of failure on demand (PFD) for low-demand mode or probability of failure per hour (PFH) for high-demand mode. According to IEC 61508, the relationship between SIL and PFD or PFH is shown in Equation (1) and (2).

$$
\text{For low demand mode: } \text{SIL 1: } 10^{-2} \leq PFD_{avg} < 10^{-1} \\
\text{SIL 2: } 10^{-3} \leq PFD_{avg} < 10^{-2} \\
\text{SIL 3: } 10^{-4} \leq PFD_{avg} < 10^{-3} \\
\text{SIL 4: } 10^{-5} \leq PFD_{avg} < 10^{-4}
$$

$$
\text{For high demand / continuous mode: } \text{SIL 1: } 10^{-6} \leq PFH < 10^{-5} \ \text{failures per hour} \\
\text{SIL 2: } 10^{-7} \leq PFH < 10^{-6} \\
\text{SIL 3: } 10^{-8} \leq PFH < 10^{-7} \\
\text{SIL 4: } 10^{-9} \leq PFH < 10^{-8}
$$

For battery energy storage systems, the safety functions (e.g., overvoltage protection) are typically operated in high-demand mode because the battery may be operating continuously. Therefore, a SIL 2 requirement corresponds to a PFH in the range of [10^{-7}, 10^{-6}) failures per hour. This must be demonstrated through reliability block diagrams, Markov analysis, or fault tree analysis, considering the diagnostic coverage and common cause failures.

Similarly, for standards using ISO 13849, the performance level PL c requires a probability of dangerous failure per hour of less than 10^{-6} to 3×10^{-6}. This is roughly equivalent to SIL 2. The relationship is not exact but is often accepted as comparable.

Discussion on Harmonization Challenges

Despite the proposed unified methodology, some gaps remain. For example, UL 1973 and UL 9540 require specific component certifications (UL 991, UL 1998) that are not commonly used in Europe or China. The German VDE standard has very specific hardware test requirements like sensor open-circuit detection with defined test methods, which are not explicit in other standards. GB/T 34131 provides comprehensive BMS functional tests but lacks any functional safety standard reference, which means a BMS designed to GB/T 34131 cannot automatically claim compliance with IEC 61508.

To achieve truly global acceptance, manufacturers of battery energy storage systems should consider designing their protection circuits and software to meet the most stringent requirements: SIL 2 (or PL c) as a minimum, with dual-channel or single-channel-with-redundancy architecture, and software developed per IEC 61508-3 with verification according to UL 1998 Class 1 or equivalent. Additionally, including lifecycle risk assessment as per VDE-AR-E 2510-50 will further enhance safety documentation.

Conclusion

In this article, I have compared the functional safety requirements of five major standards for lithium-ion battery systems used in battery energy storage systems. The analysis reveals significant differences in safety integrity levels, analysis methods, software requirements, and testing. While no single standard is universally applied, a unified approach combining risk assessment per IEC 61508, hardware architecture with single-fault tolerance, software development following the V-model, and comprehensive testing covering environmental and EMI aspects can satisfy the majority of requirements. The inclusion of lifecycle risk assessments and residual risk documentation, as required by VDE-AR-E 2510-50, further strengthens the safety case. By adopting this consolidated methodology, engineers can streamline the certification process for global markets, ensuring that their battery energy storage systems are safe, reliable, and compliant across jurisdictions. The tables and equations provided here serve as practical tools for implementation. As the industry moves toward harmonization, it is my hope that future revisions of these standards will converge on a common set of functional safety criteria, reducing complexity for all stakeholders.

Scroll to Top