
BESS Incident Response Workflow That Protects Assets
A battery container can appear normal while a failing cell is already releasing hydrogen and electrolyte vapours. By the time smoke is visible, the operating window for controlled intervention may be extremely limited. A BESS incident response workflow must therefore begin with early-stage detection, not with fire suppression. For asset owners and operators, that distinction determines whether an abnormal event becomes an orderly shutdown or a prolonged emergency affecting people, equipment and grid availability.
The workflow should be written for the actual site, battery chemistry, enclosure design, fire strategy, SCADA architecture and emergency-service access arrangements. It is not a document to file away after commissioning. It is an operational control that must be tested, understood and updated after every significant change.
Why early detection changes the response
Thermal runaway is not a single, predictable event. A cell may experience internal damage, overheating, overcharging, manufacturing defects or external mechanical stress. During degradation and the early failure phase, lithium-ion batteries can release gases and vapours before a visible fire develops. These precursors can include hydrogen, volatile organic compounds and electrolyte vapours, often alongside changes in temperature and humidity.
Traditional smoke and heat detection remains part of a fire safety system, but it may operate later in the failure sequence. A purpose-designed off-gas detection layer can provide an earlier operational signal: investigate, isolate, reduce energy and prepare for escalation before personnel are confronted by smoke, flame or an explosive atmosphere.
Early warning does not mean an incident is automatically safe to manage internally. It gives the site more time to follow a disciplined decision process. The response must still prioritise life safety, evacuation triggers and emergency-service direction.
A practical BESS incident response workflow
A useful workflow separates the event into clear stages, with defined ownership at every handover. The exact alarm setpoints and actions should be established through the site risk assessment, battery manufacturer guidance, insurer requirements and applicable Australian standards, codes and authority requirements.
1. Detect, verify and classify the alarm
When an off-gas detector reports an abnormal condition, the control system should capture the alarm value, time, location, detector status, battery rack or container status, ambient conditions and any associated BMS faults. The first task is not to assume a false alarm. It is to determine whether the signal is credible and whether it is increasing.
Operators should verify the condition remotely wherever practical through SCADA, BMS data, CCTV and other installed monitoring. They should check for concurrent indicators such as cell voltage deviation, high temperature, cooling failure, abnormal pressure indications, insulation faults or loss of communications. Personnel should not enter an affected enclosure simply to confirm an alarm unless the site procedure confirms it is safe and appropriate.
Classification helps prevent both underreaction and unnecessary shutdowns. A low-level, stable reading may require enhanced monitoring and technical investigation. A rising reading, multiple sensor alarm, BMS fault or evidence of abnormal heating should trigger a higher response level without delay. The procedure should make these thresholds unambiguous.
2. Control energy and isolate the affected system
Once the event reaches the defined action threshold, the site should move from observation to control. This can include stopping charge and discharge, opening relevant contactors, placing the BESS in a safe operational state, isolating affected DC strings where designed to do so, and preventing automatic restart.
Isolation is not the same as making a battery harmless. Stored energy remains within the cells, and a damaged battery can continue to heat or re-enter thermal runaway after an apparent lull. Operators must follow the equipment manufacturer’s approved shutdown sequence and avoid actions that could worsen the fault, including indiscriminate re-energisation or resetting alarms before the cause is understood.
SCADA integration matters at this stage. Detection systems with configurable relay outputs and Modbus RTU compatibility can be used to send alarms to the BMS, site controller or central operations room. The preferred cause-and-effect logic depends on the facility. At an unattended renewable site, automatic curtailment and remote escalation may be essential. At a data centre or critical facility, the response may require staged isolation to protect continuity while managing the affected battery area.
3. Protect people and establish exclusion zones
If off-gassing is confirmed or conditions are escalating, access control becomes a life-safety measure. Restrict entry to the battery room, container or nominated danger area. Account for personnel, notify site security where relevant, and establish an exclusion zone based on the emergency plan and advice from qualified responders.
Off-gases can be flammable and toxic, while damaged cells may release heat rapidly. Ventilation actions must be site-specific. Some enclosures have engineered ventilation or pressure-relief arrangements; others have controls that must be activated only under defined conditions. Staff should never improvise by opening container doors or panels. Opening an enclosure can expose personnel to gases, flame ejection or a sudden change in oxygen concentration.
The incident controller should make a clear decision on evacuation based on alarm level, battery condition, location, wind conditions, occupancy and potential for escalation. Where there is any indication of smoke, fire, rapid gas increase, enclosure damage or thermal runaway, contact emergency services immediately and provide accurate information about the lithium-ion battery installation.
4. Escalate with information responders can use
Emergency response is faster and safer when the information is ready before the incident. The site should maintain an accessible emergency pack containing the BESS layout, container and rack identifiers, emergency isolation points, battery chemistry, installed capacity, SDS documentation, contact numbers, access routes and current operating status.
During the callout, give responders facts rather than assumptions. State whether there is visible smoke or flame, whether off-gas detection has activated, whether the BESS has been shut down, whether people are accounted for, and whether there are adjacent exposures such as transformers, switchrooms, diesel plant or occupied buildings.
The site team should remain available to support Fire and Rescue personnel, but it must not obstruct their incident command. The emergency plan should define who has authority to communicate with the network operator, insurer, asset owner, battery integrator and regulator if notification is required.
5. Monitor the event through stabilisation
A low or falling gas concentration is encouraging, but it is not an automatic all-clear. The affected battery system should remain isolated and monitored until qualified technical personnel and emergency responders agree that the immediate risk has reduced. Depending on the incident, monitoring may need to continue for an extended period because damaged cells can retain energy and fail later.
Trend data is particularly valuable. A gradual rise in hydrogen or electrolyte vapours may point to a developing fault; a sharp rise alongside temperature change may indicate a more urgent failure pathway. Recording these trends assists technical investigation and supports decisions on whether an asset can be returned to service, requires module replacement, or must remain quarantined.
6. Recover only after a controlled investigation
Recovery begins with evidence preservation, not restart. Secure SCADA histories, BMS records, detector readings, CCTV footage, alarm acknowledgements and maintenance logs. Inspect the system only under an approved method statement and with competent personnel. The investigation should consider battery condition, thermal management, charging profile, workmanship, environmental exposure, sensor placement and any preceding faults.
The return-to-service decision should be documented and authorised. It may require battery manufacturer assessment, electrical testing, replacement of damaged equipment, cleaning or decontamination, detector bump testing or calibration checks, and validation of emergency systems. If the cause cannot be confidently addressed, restarting the asset may create a repeat event with fewer warning signs.
Designing detection into the workflow
Detection hardware is only effective when its alarm outputs lead to defined action. Gas sensors should be positioned according to enclosure airflow, likely gas accumulation areas, rack configuration and manufacturer recommendations. A detector installed in a convenient location but outside the expected gas path can create false confidence.
For BESS projects with constrained space and existing controls, compact industrial off-gas detectors can support practical integration. NexaGuard Systems supplies the Evikon E2673 for applications requiring early detection of hydrogen, VOCs, electrolyte vapours, humidity and temperature changes associated with failing lithium batteries. Its deployment should sit within a complete engineered design, including alarm logic, power resilience, maintenance access and tested communications to SCADA.
Procurement teams should also assess sensor service requirements, expected operating life, environmental suitability, alarm relays, communication protocol, fault indication and the availability of local technical support. Maintenance-free or long-life claims should always be reviewed against the actual operating environment and the manufacturer’s documented maintenance schedule.
Test the workflow before an alarm tests it
A response plan that has not been exercised is a set of assumptions. Commissioning should include end-to-end testing from detector alarm through SCADA display, notification, BESS control action and escalation procedure. Operators need to know what the alarm looks like, who receives it after hours, who can authorise isolation, and when emergency services are called.
Run scenario-based drills at least after major system changes and at intervals suited to site risk. Test a low-level off-gas alert, a rapidly escalating event, loss of communications and an after-hours alarm. Each exercise should produce actions: correct contact details, improve alarm descriptions, refine access arrangements and remove delays in decision-making.
The objective is not to promise that every battery incident can be prevented. It is to detect danger before disaster, give people time to act, and ensure that every action taken protects the site’s people, critical assets and ability to recover.




Comments