Gas monitoring begins before ‘sensor selection’

In lithium-ion battery ESS, gas monitoring is not a final device for confirming a fire; it is a protective layer that secures time to make decisions before an abnormal condition progresses to ignition and explosion. When a cell undergoes thermal, electrical, or mechanical stress, electrolyte vapours, carbon monoxide, carbon dioxide, hydrogen, hydrocarbons, and particulates may be released before and during thermal runaway. Their composition and release rate vary with cell chemistry, state of charge, ageing, fault-initiation mode, and module construction. Therefore, applying one specific gas or one specific concentration to every ESS has a weak safety basis.

UL 9540A test method evaluates thermal-runaway characteristics and the composition and flammability of released gases at the cell level, and the potential for heat and gas release and propagation at the module and higher levels. The practical value of these data lies not in the certification name itself but in determining what is released and how quickly from the product being designed. NREL’s introduction to battery safety research likewise emphasizes designing systems to mitigate risk not only in normal operation but also under worst-case conditions, and characterizing thermal behaviour before and after failure rather than simply judging pass or fail. Gas-monitoring design should begin with this product-specific test data and site-specific risk assessment.

1. Define the maximum credible failure scenarios

The first step is not to ask ‘Which sensors should be installed?’ but to define ‘Which accident progression should be detected and interrupted?’ At a minimum, distinguish single-cell venting, propagation within a module, propagation between racks, DC arcing, loss of cooling, overcharge, ingress of an external fire, and door opening during maintenance. For each scenario, create a table of early indications, expected gases, release quantity and duration, ignition sources, natural and mechanical ventilation conditions, and the likelihood of human access. Also record cleaning-agent vapours, cable or plastic emissions, and exhaust from external vehicles that may arise during normal operation as potential causes of false alarms.

Sandia’s system safety analysis report notes that hazardous conditions can arise not only from the failure of an individual component but also from interactions among components operating normally. This perspective matters because a flammable mixture may remain inside a container because of an incorrect sequence or loss of power even when BMS shutdown, fire-suppression discharge, and ventilation-fan startup each succeed. Risk assessment must cover not only detection failures but also coupled failures between protective layers, such as communication delays, loss of auxiliary power, fan failure, a damper that does not open, sensor saturation, and a maintenance bypass left in place.

Gas-concentration targets should likewise be set using product-test results and the container volume, leakage, and mixing conditions. Sandia research explains that thermal-runaway vent gas can include hydrogen, carbon monoxide, methane, and other gases, and that an ignition source can cause an explosion when a mixture in an enclosed space reaches its flammability limit. However, specific cell-test values in a report must not be copied directly to a different chemistry or container. The objective is not to match publicly stated general values, but to define the maximum credible release using test data such as UL 9540A for the system concerned and retain a design basis that can be calculated, tested, and reviewed.

2. Select the sensor combination for the detection purpose

It is difficult for one sensor to address early abnormalities, flammability hazards, toxic exposure, and fire confirmation all at once. Electrolyte vapours or volatile-organic-compound signals may be useful for early warning, while hydrogen, carbon monoxide, or combustible-gas measurement are candidates for assessing flammability hazards. Smoke and temperature detection contribute to fire confirmation and cross-validation, while BMS deviations in cell voltage, temperature, and current help estimate the fault location. Select the actual combination by comparing the indicators that first appear in cell tests, sensor selectivity, response time, measurement range, poisoning by toxic gases or silicone, and humidity and temperature effects.

It is not enough to rely solely on the clean laboratory response time in a sensor datasheet. Gas may take longer to travel to the sensor inside a container, and a high-concentration release may saturate the sensor or cross-sensitivity to another gas may create a false alarm. Verify candidate sensors under the expected mixed-gas and temperature-humidity conditions, and test long-term drift and zero recovery as well. Combining sensors based on different principles with BMS signals makes it easier to identify a malfunction in one channel, but ‘advisory alarms’ and ‘protective-action alarms’ must be distinguished so that majority-voting logic does not ignore an early single signal and delay the alarm.

3. Validate placement by actual flow rather than gas density

Placement based only on the rule that hydrogen rises and heavy vapours fall can miss local hazards. Thermal-runaway gas is discharged as a high-temperature jet, contains a mixture of components, and is affected by rack aisles, cable trays, cooler discharge, and ventilation inlets. Sensors should cover both locations that capture releases rapidly near expected sources and locations representative of the condition across the mixed container volume. Consider spaces where stagnation is possible, such as above racks and in internal aisles, ceiling plenums, HVAC returns, emergency-exhaust inlets, and floors or cable pits. If PCS and battery compartments are separated, evaluate each compartment separately.

Placement validation does not end with distance calculations on drawings. Conduct smoke visualization, tracer-gas testing, or appropriate flow analysis by operating mode, including normal cooling, fan shutdown, emergency exhaust, doors closed and partly open, and blocked filters. Identify the sensor that is reached latest from representative release locations and the time to detection, and assess whether that time is shorter than the time allowed for protective action. A sensor installed directly in front of strong outdoor-air ingress may respond late because of dilution, while one installed in a completely enclosed blind spot may overrepresent only one zone. It must be possible to inject calibration gas and replace the sensor while avoiding physical impact, condensate, wash water, and electromagnetic interference.

4. Divide the container into monitoring and protection zones

Zoning identifies the alarm location and reduces unnecessary operation of the entire facility. Divide battery-rack zones, power-conversion-equipment zones, control-panel zones, HVAC and exhaust zones, cable pits, and external container access zones according to function and airflow. Using the same rack number or aisle and sensor address on SCADA screens, site signage, and fire-response drawings allows remote operators and on-site responders to understand the same location. External sensors may assist in assessing conditions near an outlet or along fire-service access routes, but they do not replace sensors intended to prevent an internal explosion.

Electrical hazardous-area classification is not determined in reverse after gas sensors have been installed. A qualified designer must determine area classification and equipment suitability according to expected releases, ventilation reliability, ignition potential, and the codes adopted. Sensors, fans, damper actuators, lights, and switches can themselves be potential ignition sources, so review together the ratings and installation methods of equipment that must continue operating in an emergency. Position exhaust outlets so they do not send gas toward an adjacent container’s intake, evacuation route, ignition source, or building opening, and reflect release areas in the site layout plan.

5. Distinguish ventilation for thermal management from explosion-risk reduction

Routine cooling manages battery temperature, but it does not automatically ensure performance that reduces a large emergency vent-gas release below a safe concentration. Determine emergency-ventilation capacity using the release quantity and rate of the relevant cell or module, container volume, duct losses, make-up-air path, and fan-start delay. Do not state only an average air-change rate; verify the concentration at the worst location and the time to complete discharge. DOE energy-storage safety strategy explains that thermal runaway and combustible-gas generation may continue in an enclosed space even if flames alone are suppressed, and that a design for removing gas is important.

A ventilation system needs confirmation of actual flow or differential pressure, not merely a fan-run command. Review independent auxiliary power so that fans, dampers, detectors, and communications operate for the required time even in an event that cuts off the main power. Fan-start failure or a damper that does not open must immediately become a separate fault alarm. Also test exhaust-duct leakage, backflow, and re-entrainment. Conversely, if responders manually ventilate by opening a door without understanding the situation, oxygen ingress and changing flow may cause rapid combustion. Do not treat automatic door opening or simultaneous operation of fire-suppression equipment and ventilation as a general solution; adopt only sequences validated by product testing and risk analysis.

NFPA 855 is a framework covering fire and explosion hazards, commissioning, and operation and maintenance for stationary ESS installations. However, editions and adoption vary by jurisdiction, and NFPA materials likewise instruct users to check the complete document and jurisdictional rules. Accordingly, the ventilation principles in this article do not present a particular airflow or alarm value as a legal standard. For application in Korea, current fire-protection, electrical, and occupational-safety regulations, permitting conditions, manufacturer instructions, and authority having jurisdiction requirements must be confirmed separately.

6. Link alarms to actions

A monitoring system is not complete merely because gas values appear on a screen. Define who does what at every alarm level. For example, Level 1 may begin operator verification and data preservation on an abnormal single early signal; Level 2 may stop charging and discharging and isolate the relevant rack when multiple signals or the rate of rise are confirmed; and Level 3 may initiate emergency ventilation, on-site evacuation, access control, and fire-service notification when a flammability hazard or fire is confirmed. Determine the actual levels and thresholds by analyzing test data, the cost of false alarms, and the consequences of action failure.

Integration targets include the BMS, EMS, PCS, SCADA, fire alarm control panel, HVAC, access control, on-site warning lights and sirens, and remote-notification system. Electrically disconnecting the battery does not eliminate its stored energy, so ‘shutdown complete’ must not be displayed as a ‘safe condition.’ The alarm screen should retain, in chronological order, the first detection time, sensor location, concentration and rate of rise, BMS abnormality, actual fan operating status, fire-suppression-equipment status, and communication quality. Also test whether on-site alarms and protective actions are retained during a communication outage and whether the event sequence is preserved after recovery.

Alarm logic must include conditions for returning to normal. Do not restart automatically because concentration has temporarily fallen; establish an approval procedure that checks residual heat, re-ignition, recovery after sensor saturation, and the risk of accessing the container interior. Before instructing that a door be opened, a remote operator must share status information with the on-site incident commander; fire services must be given the equipment layout, isolation points, gas and fire alarm history, emergency-ventilation status, and manufacturer response instructions.

7. Maintenance is the process of demonstrating detection performance

From the moment they are installed, sensors experience contamination, drift, and declining service life. A maintenance plan includes visual inspection, zero and span calibration, bump tests to confirm functionality, inspection of filters and sampling lines, replacement at sensor end of life, and alarm-transmission testing. Adjust intervals according to manufacturer instructions, site conditions, and calibration history. A status bit that merely indicates live communications does not demonstrate an actual gas response. Use test gas for end-to-end testing from detection through the operator display, isolation command, fan startup, flow confirmation, and on-site alarm.

Ventilation fans, dampers, and auxiliary power are also part of the same protective layer. Regularly check blocked filters, belt and bearing condition, damper stroke, exhaust-outlet obstructions, and UPS duration. During calibration, it is safer for a bypass to record the approver, start and end times, and alternative monitoring measure, and to expire automatically. Do not solve repeated false alarms simply by raising thresholds; investigate the causal gas, airflow changes, sensor poisoning, and the possibility of a battery abnormality.

If there is battery expansion, a change in cell supplier, a software update, rack relocation, or HVAC modification, review the existing detection basis as well. If the product configuration in a UL test report differs from the site installation configuration, confirm whether the gas-generation and flow assumptions remain valid. Trending incident and maintenance data to compare baselines, rates of rise, and response times by sensor can identify ageing sensors and new fault patterns early.

Design review checklist

  1. Are test data available for the chemistry, state of charge, and thermal-runaway gases of the cells, modules, and racks to which this applies?

  2. Are scenarios including the maximum credible release, ignition sources, loss of ventilation, and door opening documented?

  3. Are the sensors and limitations distinguished by detection purpose: early abnormality, flammability hazard, and fire confirmation?

  4. Have sensor arrival times and blind spots been checked by tracer-gas or flow validation in every operating mode?

  5. Are the zones and addressing scheme consistent for the battery, PCS, plenum, pit, exhaust, and external access areas?

  6. Have emergency-ventilation capacity, auxiliary power, flow confirmation, discharge location, and fault alarms been validated?

  7. Are the staged actions and responsible parties defined from detection through stopping charging and discharging, isolation, ventilation, evacuation, and notification?

  8. Are calibration, bump testing, end-to-end integration testing, and change-management records included in operating procedures?

Gas monitoring for an ESS container is a design task that brings product-specific release characteristics, space-specific flow, reliable ventilation, and human response together on a single timeline. A good system is not one that produces many alarm numbers; it captures the earliest reliable indication, confirms that the next protective action was actually performed, and enables on-site responders to understand the hazardous condition before opening the door.


Cover photo

Original photo on Pexels