Large-Scale Energy Storage System: Safety and Risk Assessment
Large-Scale Energy Storage System: Safety and Risk Assessment
[Link]
Abstract
The International Renewable Energy Agency predicts that with current national policies, targets and energy plans,
global renewable energy shares are expected to reach 36% and 3400 GWh of stationary energy storage by 2050. How-
ever, IRENA Energy Transformation Scenario forecasts that these targets should be at 61% and 9000 GWh to achieve
net zero carbon emissions by 2050 and limit the global temperature rise within the twenty-first century to under 2 °C.
Despite widely known hazards and safety design of grid-scale battery energy storage systems, there is a lack of estab-
lished risk management schemes and models as compared to the chemical, aviation, nuclear and the petroleum
industry. Incidents of battery storage facility fires and explosions are reported every year since 2018, resulting
in human injuries, and millions of US dollars in loss of asset and operation. Traditional risk assessment practices such
as ETA, FTA, FMEA, HAZOP and STPA are becoming inadequate for accident prevention and mitigation of complex
energy power systems. This work describes an improved risk assessment approach for analyzing safety designs
in the battery energy storage system incorporated in large-scale solar to improve accident prevention and mitigation,
via incorporating probabilistic event tree and systems theoretic analysis. The causal factors and mitigation measures
are presented. The risk assessment framework presented is expected to benefit the Energy Commission and Sustain-
able Energy Development Authority, and Department of Standards in determining safety engineering guidelines
and protocols for future large-scale renewable energy projects. Stakeholders and Utility companies will benefit
from improved safety and reliability by avoiding high-cost asset damages and downtimes due to accident events.
Keywords Safety barrier, STPA, Frequency, PFD
© The Author(s) 2023. Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which
permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the
original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or
other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line
to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory
regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this
licence, visit [Link]
Moa and Go Sustainable Energy Research (2023) 10:13 Page 2 of 31
Literature review
Battery energy storage technologies
Battery Energy Storage Systems are electrochemi-
cal type storage systems defined by discharging stored
chemical energy in active materials through oxida-
tion–reduction to produce electrical energy. Typically,
battery storage technologies are constructed via a cath-
ode, anode, and electrolyte. The oxidation and reduc-
Fig. 2 Jimei Dahongmen Li‐ion battery fire (Accident analysis tion reactions at the electrodes generate an aggregate
of Beijing Jimei Dahongmen 25 MWh DC solarstorage-charging
integrated station project, 2021)
Moa and Go Sustainable Energy Research (2023) 10:13 Page 4 of 31
Lithium‑based battery
Lithium-ion batteries are known for their low self-dis-
charge rate. The anode is made up of graphite in a layer-
ing structure and the electrolytes are made up of lithium
salt. The cathode is made of a lithiated metal oxide. There
are several types of Li-ion batteries based on the metallic
element in the cathode, such as lithium nickel manganese
cobalt (NMC) oxide, lithium cobalt oxide, lithium nickel
cobalt aluminium (NCA) oxide and lithium iron phos-
phate (LFP) (Behabtu, 2020; Hossain et al., 2020; Kebede
et al., 2022). During the discharge phase, the Li atoms at
the anode ionize and are carried to the cathode in the
electrolyte due to difference in electrolytic concentration
on the anode and cathode side, shown in Fig. 4. Lithium-
ion batteries have high power densities of 500–2000 W/l, Fig. 5 Lead‐acid battery working principle (Hossain et al., 2020)
high energy densities of 200–500 Wh/l and high round
trip efficiencies of 85–95%. However, they are high power
and energy costs up to 4000 $/kW and 3000 $/kWh, Lead‑acid battery
which is the highest among the other battery technolo- Lead-acid batteries consist of a sponge lead cathode
gies (Behabtu, 2020; Hossain et al., 2020). and a lead dioxide anode submerged in sulphuric acid,
Lithium metal batteries use metallic lithium as the shown in Fig. 5. They are the most mature battery tech-
anode instead of lithium metal oxide, and titanium nology, being fully commercialized, with low power and
disulfide as the cathode. Due to the vulnerability to for- energy costs, and high power and energy densities at
mation of dendrites at the anode, which can lead to the 10–400 W/l and 50–880 Wh/l. they have moderate life-
damage of the separator leading to internal short-circuit, time of 5–15 years and 70–90% efficiency (Behabtu, 2020;
the Li metal battery technology is not mature enough for Hossain et al., 2020).
large-scale manufacture (Hossain et al., 2020). Vented lead-acid batteries, also known as flooded lead
acid batteries, contain sulphuric acid electrolyte that
is free to move around the battery casement. Internal
gases such as hydrogen gas are released directly to the
environment during the charging phase through vents.
They are known for having low energy cost but also have
weak internal construction and high internal resistance
(Behabtu, 2020). Valve regulated Lead acid batteries are
also known as sealed lead acid batteries. The electrolyte
is a coagulated form sulphuric acid contained in a sealed
compartment which does not leak, making it safer to use.
The batteries also contain vents to release gases (Behabtu,
2020).
Flow battery
For flow batteries as shown in Fig. 6, the energy is stored
in chemical form in the active electrolyte, stored in two
external reservoirs, and fed into the reactor via pumps.
The positive electrolyte is called the anolyte and the
negative electrolyte is called the catholyte. A mem-
brane in the reactor separates the catholytic and anolytic
side of the electrolyte and only allows limited num-
ber of ions to migrate through. The ions participate in
Fig. 4 Schematic construction of li‐ion battery (Hossain et al., 2020)
Moa and Go Sustainable Energy Research (2023) 10:13 Page 5 of 31
Table 1 Characteristics of BESS Technologies (Hossain et al., 2020, Behabtu, 2020, Kebede et al., 2022)
Battery technology Power density Energy density Power cost ($/ Energy cost ($/ Round trip Lifetime Technology
(W/l) (Wh/l) kW) kWh) efficiency (years) maturity
(%)
Table 2 Toxicity level classification by effects by LC50 (Agency, water can worsen the extent of the damage. Electrical arc
2020) flashes can occur at high-current contactors and gener-
Level Health effect LC50 (ppm) ate high pressure and thermal loads inside the electrical
enclosure (Zalosh et al., 2021). Arc flashes with incident
1 Significant irritation 5000–10000 energy above 5 J/cm2 are capable of serious harm and
2 Temporary Incapacitation 3000–5000 the use of personal protective equipment and hazard
3 Serious or permanent injury 1000–3000 labelling and markings are required by regulation (Inter-
4 Lethal Gas: < 1000 national Electrotechnical Commission, 2020). During
Liquid: 10–200 mg/L
abnormal conditions, the battery holding a significant
amount of stored charge can pose risks of electrical
shock and arc flash to the on-site technicians or emer-
the Identification of the Hazards of Materials for Emer-
gency responders.
gency Response, summarized in Tables 2 and 3.
The inherent hazards of battery types are determined
Reactive metals can cause violent chemical reactions
by the chemical composition and stability of the active
with moisture in the air. By design, reactive metals are
materials, potentially causing release of flammable or
protected under normal operating conditions but may
toxic gases. High operating temperatures pose high risks
become exposed during abnormal situations. Exposure to
for human injuries and fires. Electrical hazards are pre-
oxidizer material can increase the flammability potential
of other materials present and lead to increased intensity sent in each BESS type due to the power control systems
of fires (Agency, 2020). for grid integration.
Physical hazards for batteries include hot parts and Lithium-ion battery cells vent combustible gases under
moving parts, often discussed in the context of direct abnormal conditions. Hydrogen fluoride, HF, hydrogen
harm to human beings exposed to the hazard. Hot sur- cyanide (HCN) are toxic gases vented from the battery
found in BESS in thermal runaway events (Gully, 2019).
faces on the battery components can cause burns if it
Lithium metal batteries contain lithium metal electrodes
comes into contact with human skin (Agency, 2020). If
which can undergo aggressive chemical reaction when
any mechanical impact affects the battery cells and com-
exposed to water or air. Lead acid batteries and vanadium
promises their internal structural integrity, internal short
redox batteries may vent hydrogen gases, from the sul-
circuit may be induced, leading to a thermal runaway.
Electrical hazards such as electrical shock and arc phuric acid electrolyte. The acid electrolyte is extremely
flashes can cause serious harm to maintenance work- corrosive and can cause serious human injuries. Sodium-
based batteries operate at high-temperature ranges (270–
ers. Energy storage systems with voltages above 50 V
350 °C) and contain reactive metal sodium in a molten
can cause serious harm to workers who may be exposed
state. Damages to the air-tight seal may expose sodium to
to live parts. The presence of conductive fluids such as
Table 4 Summary of batteries and associated hazards (Agency, 2020) (International Electrotechnical Commission, 2020)
Battery technology Hazard type
Thermal, Firea Chemical Electrical Physical
air and moisture and initiate violent chemical reactions. Safety and risk assessment
The zinc bromide flow battery contains zinc bromide A variety of commonly practiced risk assessment
electrolyte, a corrosive acid with LC50 Level 3 inhalation methods are discussed, with applications in aeronau-
toxicity. Flow batteries require manual replenishing of tic, automotive, chemical, manufacturing, nuclear and
electrolytes, where mishandling may cause spill of toxic petroleum industries. A hazard is defined as a danger-
and corrosive material. Table 4 summarizes the inherent ous substance or state that may lead to a loss in the
hazards present with each battery storage technology. form or damage to equipment, loss of output, injury,
Natech events are cascading events involving the death, or environmental damage. A risk is an expres-
release of hazards of a technological system, triggered sion of the likelihood of an event and the severity of its
by the effect of natural events such as floods, earth- consequences (Rovins, 2015).
quakes, and hurricanes. Natech risks are often consid-
ered in risk management plans in the chemical section Event tree analysis
or and oil and gas facilities, where natural disaster The Event Tree Analysis (ETA) evaluates sequences of
events can damage the containment vessels of flam- events leading to different outcomes from an initiat-
mable or toxic substances leading to the atmospheric ing event, usually the event of a release of hazard. This
release of these chemicals (Misuri et al., 2021). method is a bottom-up approach. First, the initiating
In context of the Malaysian LSSPV scheme, major event is identified, followed by identification of event
natural hazard events of concern are floods, flash tree branches and the final outcomes and consequences
floods, and landslides. Flash floods are characterized are evaluated based on the escalation of each event tree
by excessive rainfall within hours causing heavy flow path. If Event 2, E2 is an event succeeding Event 1, E1
in riverbeds and urban waterways, whereas floods are on an event tree path, the probability, P(E2) of Event 2
characterized by overflow of waterways over time spans occurring can be expressed in Eq. 1, where P(E2|E1) is the
of days to weeks. Over the past 20 years, Peninsular conditional probability of E2 occuring given that E1 has
Malaysia has experienced floods and landslide events already occurred:
with varying severities, most notably floods of 2014 and
2021 caused by heavy monsoon season rainfall affect-
P(E2 ) = P(E1 )P(E1 |E1 ). (1)
ing simultaneously in multiple states, causing exten- The probability of one outcome j of an event tree with
sive property damage, loss of lives, mass evacuations n branches is the product of the probabilities of each
and billions of Malaysian Ringgit spent on rebuilding, branch of its event tree path leading to the outcome:
victim support and rescue efforts. Such Natech events
would cause extensive damage to power system com- P(Eif ) = P(Ej1 )P(Ej2 |Eji )P(Ej3 |Ej2 )....... × P(Ejn |Ej(n−1) ). (2)
ponents of LSSPV and BESS and subsequently release Hermansyah’s demonstration of ETA of the escalation
of hazards, such as active chemicals in the battery cells of gas leakage in buildings identified the gas leak as the
into floodwater or unmitigated battery fires. initial event and four escalation events as the branches,
e.g. ignition, delayed, ignition, fire escalation, and evacu-
ation leading to nine possible outcomes, as shown in
Fig. 9. Two possible paths were evaluated for each of the
Moa and Go Sustainable Energy Research (2023) 10:13 Page 10 of 31
Fig. 9 Example of event tree analysis for gas leakage to fire escalation (Hermansyah et al., 2018)
four event tree branches, e.g. whether ignition occurred subsystem failures. Barrerre et al. modelled the failure
or did not occur. of a fire protection system using FTA to sensor failures,
The probabilities of each sequence in the Event Tree communication failures, and external cyber-attacks, as
cannot be calculated with absolute certainty, as each fail- shown in Fig. 10 (Barrere & Hankin, 2020).
ure event in each system is unique to its own conditions, The FTA is systematic in the use of logic operators
thus probabilities used are often based on failure models and flexible in allowing the safety engineer to define the
with assumptions or statistics with limited sample sizes. number of levels and detail for each individual branch as
The probabilities here serve to guide the safety reviewer needed. An undesired outcome is identified as the top
to pinpoint areas for mitigation improvement rather than event of the FTA is a failure of a complex system. Thus,
as an absolute reference. Often, only binary states are the analysis does not extend to the resulting accident and
considered at mitigation stages e.g. detection success or the consequential damage extent caused by this system
failure, thereby ignoring the case of late detection possi- failure. Like the ETA, this method also allows for proba-
bly leading to a different sequence of events (Aitugan & bilistic estimation for the failure event using probabili-
Li, 2020). ties of individual component failure and assuming failure
probabilities of each subsystem are mutually exclusive.
Fault tree analysis By considering the equations for AND and OR gates, the
The Fault Tree Analysis (FTA) Method is a top-down minimal cut set (MCS) of basic level events or failures
approach to assessing the contributing factors leading to are identified, and their probabilities are calculated. The
a failure event. This method is typically used in the risk quality of analysis on the FTA method is highly depend-
assessment of complex systems in high-severity risk fields ent on the knowledge of the analyst on possible failure
such as the aerospace industry and nuclear power plants. modes that may otherwise be overlooked (Choo & Go,
In this method, a single undesired outcome (top event) 2022).
is first identified, then traced back to lower-level causal
factors or failures that led to this outcome via Boolean Failure modes and effects analysis
AND and OR logic operators (Aitugan & Li, 2020). Basic The Failure Modes and Effects Analysis (FMEA) method
events are often human failures, hardware, or software is an analysis tool that assesses failure of components or
Moa and Go Sustainable Energy Research (2023) 10:13 Page 11 of 31
Fig. 10 Example of fault tree diagram of fire protection system failure. (Barrere & Hankin, 2020)
processes in a system and identifies failure causes and suitable to deeply investigate the causes of the failures
consequences. This analysis is commonly practiced in on a low level to develop prevention measures. FMEA
the aeronautical, automotive, and chemical and pro- is suitable to briefly examine possible failure points of a
cess industry. A semi-quantitative analysis is performed large system and identify areas for improvement. Further
by assigning ratings to likelihood of failure occurrence detailed failure analysis can then be extended using Fault
(OCC), detectability of failure mode (DET) and severity Tree analysis.
of consequence (SEV), on scale of 0–10. Depending on
the industry, the scales of OCC, DET, SEV can be attrib- Hazards and operability
uted to the corresponding processes. For example, for a The Hazards and Operability (HAZOP) Analysis is an
production line in a manufacturing plant an OCC score efficient way to quickly identify possible hazards that
of 0 can be defined as one stoppage occurrence of under by analysing each piece of equipment across a facility,
30 min in a month, and a score of 10 can correspond to originally developed for the chemical industry. HAZOP
one stoppage occurrence of over 2 h in 1 week, depend- analysis is done via brainstorming by a team. The pro-
ing on the reviewer’s knowledge of the processes or sys- cess first draws out the overall design of the system i.e.
tem being assessed (Aitugan & Li, 2020). the machinery and their designated function. Then, pos-
A Risk Priority Number (RPN) is a calculated risk sible process deviations or abnormal conditions for each
score for each failure mode described by Eq. 3. The RPN machinery are brainstormed and the resulting hazards
is calculated on the FMEA form and high RPN scores are identified. Suitable preventive and mitigation meas-
exceeding an acceptable range are evaluated to how the ures are then considered (Aitugan & Li, 2020). It is an
contributing OCC, DET or SEV score can be reduced effective risk assessment option to identify unforeseen
by modifications of detection and prevention measures. hazards that may arise due to abnormal conditions in
Then, the new RPN score is calculated (American Society operation. At its basic form of application, it is a purely
for Quality & “American Society for Quality”, 2022): qualitative method. However, HAZOP analyses are often
RPN = (OCC)(DET )(SEV ). (3) supplemented with other quantitative methods, such as
the Fault Tree Analysis method or simple risk ratings.
The standard FMEA table form is easy for the safety The purpose of having a quantitative element is to help
reviewer to use, and the quantitative aspect is easy to the risk assessment team prioritize mitigation actions
understand (0–10 ratings are more intuitive than prob- (Fuentes-Bargues et al., 2017).
abilities or 10–6 per year). However, this method is not
Moa and Go Sustainable Energy Research (2023) 10:13 Page 12 of 31
Systems theoretic process analysis allows failures in very complex systems to be analyzed
System-theoretic accident model and process (STAMP) from a viewpoint of system functions, before tracing it
is a method that views complex socio-technical sys- down to lower-level components. The STAMP model
tems as a multi-level structure of physical components, also considers human factors and hierarchical organi-
engineering activities, organizational hierarchies, and zational structures of complex systems, thereby iden-
operational instructions. The interactions between the tifying related causal factors which may otherwise be
components are modelled as control loops, with mul- overlooked by other risk assessment methods previ-
tiple control loops within in a large STAMP model. A ously discussed (Leveson et al., 2018). To cover as many
typical control loop concept around a controlled pro- risks as possible, the level of detail and accuracy of
cess follows a signal detected from a sensor sent to a the STAMP model is critical. Hence, extensive expert
controller. The controller processes the signal and knowledge is required to generate a substantial STAMP
sends a command to an actuator, to perform a control model.
action. The control action affects a corrective change to
the controlled process. Figure 11 shows a basic control Layers of protection analysis
loop. Within a STAMP system, a large combination of The Layers of Protection Analysis (LOPA) is a semi quan-
control loops forms a safety network, where the con- titative technique often used in chemical process indus-
trolled processes are maintained in a safe state via con- try which allows safety reviewers to assess safeguards
trol actions (Rosewater & Williams, 2015). between hazardous events and consequences. In LOPA,
Systems Theoretic Process Analysis views hazardous these safeguards are termed independent protection lay-
states as a result of unsafe control actions (UCAs). It is ers (IPL), which are expected to perform or fail indepen-
a top-down approach, beginning with the identification dently of the conditions of the initial event or other IPLs.
of hazards or system losses. The STAMP model of the The LOPA method has been referenced in documents
system is generated, the safety constraints are identi- from the Centre of Chemical Process Safety (CCPS),
fied, then the causes and effects of UCAs within certain International Electrotechnical Commission (IEC), Inter-
control loops are evaluated. Unsafe control actions are national Society of Automation (ISA) and Institute of
actions that put the safety of a process or system at risk. Electrical and Electronics Engineers (IEEE), with sug-
These actions violate established standard operating gested failure rates for various types of components and
procedures and safety protocols which can eventually subsystems (Willey, 2014).
result in serious dangers or threats to equipment, indi- The safeguards can be classified into different lay-
viduals, or the surroundings. ers such as inherent safe designs, critical alarms, system
STPA is a purely qualitative method, with no proba- automatic response, physical protection barriers and
bilistic assessment or risk rating aspect to compare risk emergency response. An initiating event is identified,
likelihoods or severities to help the assessor prioritize that leads to severe outcomes upon the failure of its IPLs.
points of improvement in the system. This method The performance of the IPLs is defined by the probability
of failure on demand (PFD), that is the probability that
the safety system will fail to operate when required. The
frequency of a consequence, fi for scenario i with initial
event frequency.
fi0 [per year] and n number of IPLs are described in
Eq. 4 (Willey, 2014). Tolerable risk for fi ranges are often
set around 10-4 to 10-6 occurrences per year:
fi = f10 × PFDi1 × PFDi2 × PFDi3 ...... × PFDin . (4)
Landucci et al. quantified the risk reduction effect of
safety barriers in accident consequences on industrial
facilities on vessel leak events and fire escalation, intro-
ducing another parameter to the performance of IPLs,
effectiveness. Effectiveness describes the probability of
success of an IPL in mitigating the escalation scenario,
given that it has been successfully activated (Landucci
et al., 2017). Misuri et al. assessed the probability of acci-
Fig. 11 Basic STAMP control loop structure (Rosewater & Williams, dent outcomes of an industrial facility in Natech events
2015) using LOPA-based event tree and fault tree analysis.
Moa and Go Sustainable Energy Research (2023) 10:13 Page 13 of 31
Worst case outcome frequencies, where all safety barriers landslides history in ’’Safety Hazards’’ section. The litera-
failed to activate were calculated to be in the magnitudes ture review topics are summarized in Tables 5 and 6.
of 10–8 to 10–11 per year. Results from both quantified Safety Risk assessments of Li-ion battery safety stud-
safety risk as individual probability of fatality and risk of ies insufficiently analyse failure mechanisms, where
multiple fatalities, mapping out safety distance ranges correct actions performed as designed, while the sys-
largely dependent on the layout of the facility (Misuri tem is under unforeseen conditions lead to hazardous
et al., 2021). states. Due to complexity of the systems such as an LSS
Plant with BESS, it can be difficult to predict all pos-
sible hazardous system states. Accident reports often
Research gaps and reviewed work reveal system actions performed in the wrong condi-
A range of literature topics were examined as background tions leading to accidents with severe consequences.
for this work. In ’’Battery energy storage technologies’’ , For example, the Arizona Public Service BESS explo-
’’Safety Hazards’’ covering battery storage technologies, sion of 2019 was caused by the action of the HAZMAT
battery safety hazards and design requirements, fail- team opening the BESS door, introducing fresh air to
ure behaviours were reviewed, from academic journal the combustible air mixture that was inside the BESS
articles, official safety standards and industrial report. space. The action was intended to vent the gas mixture
In ’’Safety and Risk Assessment’’ section risk assess- that had built up in the BESS room, but because the
ment methods and publications were reviewed from risk gas concentrations had built up over three hours, the
assessment handbooks and academic journal articles. act of opening the BESS door caused the escalation of
Web sources from ASEAN disaster information network, hazardous event (McKinnon et al., 2020). The discrep-
EU Emergency Response Coordination Center, Malaysia ancy between the safety risk assessment case studies
National News Agency, and UN Office for Coordina- and accident reports highlight that the risk assessment
tion of Humanitarian Affairs were for major floods and methods failed to facilitate identification of such system
1 Kuala Lumpur APR & Flash flood N/A Buslima & Jamaluddin, 2018)
DEC 2002
2 Kedah, Penang, Perak OCT 2003 Flood N/A Buslima & Jamaluddin, 2018)
3 Taman Bukit Mewah, Kuala Lumpur DEC 2008 Landslide N/A Reliefweb 2008)
4 Kedah, Perlis NOV 2010 Flood 4 deaths Buslima & Jamaluddin, 2018)
45,000 hectares
of paddy fields
destroyed
50 000 evacuated
5 Most states in Peninsular Malaysia DEC 2014 Flood 21 deaths Buslima & Jamaluddin, 2018)
JAN 2015 200 000 people affected
RM1 bil damage
6 Selangor, Kuala Lumpur DEC 2016 Flash floods N/A BERNAMA & “BERNAMA - Malaysian National News
Agency”, 2022a)
7 Tambun, Perak NOV 2020 Landslide 2 deaths European Civil Protection & Humanitarian Aid
Operations, 2020a)
8 Kuala Muda, Kedah MAR 2020 Landslide 2 deaths European Civil Protection & Humanitarian Aid
Operations, 2020b)
9 Gombak & Sungai Buloh,Selangor SEPT 2021 Landslide N/A Disaster Information Network & “Malaysia, Flood-
ing & Landslide in SelangorandSabah”, 2021)
10 Selangor, Kuala Lumpur DEC 2021 Floods, 54 deaths BERNAMA & “BERNAMA - Malaysian National News
Agency”, 2022a)
JAN 2022 Flash floods RM6.5bil damage BERNAMA & “BERNAMA - Malaysian National News
Agency”, 2022b)
11 Hulu Langat, Selangor MAR 2022 Landslide, trig- 4 deaths, 1 missing European Civil Protection And Humanitarian Aid
gered by heavy 15 houses damaged Operations 2022)
rain
Moa and Go Sustainable Energy Research (2023) 10:13 Page 14 of 31
1 Review of energy storage technologies Power density, energy density, round trip Hossain (2020), Behabtu (2020), Kebede (2022)
efficiencies, power cost, energy cost
2 Recent development of organic electrode Specific energy Esser ( 2020)
batteries
3 Prospective on aluminium based batteries Specific energy, efficiency Elia (2021)
4 Standard for stationary energy system instal- Ventilation rate flammability limit lc50, ph NFPA (Agency, 2020), IEC (2020)
lation voltage
5 Review of lithium‐ion battery safety concerns Heat release vented gas composition cell Chen ( 2022), Wang, ( 2019), Gully, DNV (2019)
temperature
6 Thermal runaway and fire behavior of lithium‐ Time to Ignition Zou (2022), Liu ( 2020)
ion batteries
7 Lithium‐ion battery explosion analysis Overpressure temperature Jin (2021), Zalosh (2021)
8 Malaysia natural disaster history (Information) Fatalities quantified damage Buslima (2018), UN OCHA (Reliefweb 2008),
BERNAMA (2022a; BERNAMA 2022b), EU ERCC
( 2020a; European Civil Protection & Humani-
tarian Aid Operations, 2020b; European Civil
Protection And Humanitarian Aid Operations
2022), ASEAN (Disaster Information Network
& “Malaysia, Flooding & Landslide in Selan-
gorandSabah”, 2021)
10 Risk assessment (Handbook) Probability of fatalities probability of event Rovins (2015)
repair cost
11 Event tree analysis of potential gas leakage Probabilitiy of outcome risk Hermansyah ( 2018)
in building
12 Risk and economic analysis for aero engines Repair costs rate Aitugan (2020)
(ETA, FTA, FMEA, HAZOP)
13 Fault tree analysis Probability of failure minimal cut set prob- Barrere (2020)
ability
14 Failure modes and effects analysis Occurrence probability detectability, severity American society for quality (2022)
15 Fault tree analysis and hazards and operability Frequency of failure importance weightage Fuentes‐Bargues, (2017)
risk analysis on fuel storage terminal
16 Safety analysis of lithium‐ion grid Energy Unsafe control action Rosewater (2015)
storage
17 Systems theoretic process analysis (Handbook) Unsafe control action Leveson (2018)
18 Layers of protection analysis Probability of failure on demand Gully, DNV (2019), Willey (2014)
19 Risk assessment of domino effect mitigation Probability of failure on demand effectiveness Misuri (2021), Landucci (2017)
by safety barriers on
Industrial facilities Frequency of event location specific individual
risk probability of loss of life
20 Safety risk assessment of large‐scale energy Reliability risk achievement worth Choo (2022)
storage system
21 Safety risk assessment of grid energy storage Probability of failure on demand frequency This work
system for large scale solar PV of event unsafe control actions
states and potential risk of response actions that would pressures present quality data on BESS failure perfor-
otherwise be safe. mance. However, there is no consolidation of the avail-
There is a lack of quantitative risk analysis models for able data to develop a fragility model to analyse the safety
the safety risk assessment of energy storage systems. risk for BESS, that is scalable to most BESS of the same
Example of Vulnerability and fragility models for the technologies.
petroleum facility describe escalation thresholds of haz- Failure modes and causes identified by FMEA, STPA
ardous states or safety distances based on thresholds case studies often highlight failures of individual com-
in pressure, heat release rate, and radiation intensity ponents and ignore failures caused by interactions of
(Alileche & Cozzani, 2015). Various studies on BESS subsystems. The analysis of component failures are tied
fires, thermal runaway performance and explosion to safety risk assessment and solutions for improvement
Moa and Go Sustainable Energy Research (2023) 10:13 Page 15 of 31
focus on system components (Baschel & Roy, 2018; Choo to incorporate BESS is performed to validate the quan-
& Go, 2022; Wang et al., 2019). While these improve- tification of severe damage frequency. For further refer-
ments reduce the likelihood of hazard release, reliability encing in this work, the proposed methodology is called
of essential safety subsystems such as detection systems, event-centric systemic analysis (EcS) method. The EcS
fire suppression and emergency ventilation are often not risk assessment method adopts assessment of safety bar-
considered. They are often suggested as the ‘solutions’ rier failures in both accident analysis (ETA-based) and
and not further assessed in detail despite being essential systemic-based assessment (STPA-based) to identify
in mitigating severe consequences of hazardous events. more causal scenarios and mitigation measures against
Quantitative assessment methods (probabilistic ETA severe damage accidents overlooked by conventional
and FTA, FMEA) and qualitative assessment methods ETA, STPA and STPA-H method. Safety barrier failure
(systemic analysis, HAZOP) risk assessment frameworks rates and consequences in event tree-based analysis is
do not complement each other to identify effective pre- used to compute frequencies of severe damage scenarios
vention and mitigation measures. ETA and FTA methods of BESS in LSS plant. Through inclusion of safety barriers
can highlight weak points in a system but do not provide as part of the overall STPA control structure, the STPA-
a framework for evaluating improvements. STPA and based analysis can be applied to investigate the failure
HAZOP methods can produce long lists of failure causes of pre-existing mitigation measures by viewing them as
and safeguards but can be redundant and unfocused in unsafe control actions.
its exhaustivity. FMEA provides a good balance for quan-
titative risk rating and failure mode, causes and effects Development of stages of EcS assessment model
analysis but can overlook certain failure causes that Figure 12 shows the flow diagram of the proposed risk
require deeper analysis. assessment method. Steps are labelled 1–12 for refer-
ences made in the following section ions. Steps 7–9 and
Methodology 10–12 can be performed simultaneously.
This section ion explains the steps of the proposed risk Steps 1–3 Hazards and safety barriers are identi-
assessment methodology in its relations to the Event Tree fied. These details are available from literature of bat-
and STPA methods discussed in ’’Literature Review’’ sec- tery energy safety articles, or NFPA855 and IEC62933
tion. A case study for Malaysian LSS Plant site selection safety standards for varieties of battery energy storage
technologies listed in ’’Literature Review’’ section. The Failure modes are considered on 3 levels, as described
STPA control structure of the grid-connected PV system in Table 7, where a single failure affects one battery rack,
with BESS is adapted from Rosewater et al., IEC62933 one BESS unit or all BESS units. The frequency of flood
and SANDIA National Laboratories, and modified on occurrence as an initiating failure mode is calculated using
project-to-project basis. Monte Carlo simulation of the reported history of natural
Steps 4–9 The primary event of the Event Tree is iden- hazard events of the specified region. In the case study of
tified, usually the release of a certain hazard, where Malaysia, natural hazard events concerned are flood and
unmitigated outcomes lead to severe consequences. landslide events.
For example, start of external fire in the BESS room or The frequency of ETA initial event from one failure mode
uncontrolled toxic gas release. Probabilities of safety bar- can be described by the following equation (Willey, 2014):
rier failure on demand are listed and used to compute
event tree outcomes and the frequency (per year) of the
fm = (f0,m ) × PFDm1 × PFDm2 × .... × PFDmk (5)
ETA primary event, explained and demonstrated in the where fm is the frequency of mth base failure mode with k
following section. The final outcomes of the event tree are number of prevention barriers to the ETA initiating event
calculated, and the frequencies (per year) are evaluated. and (f0,m) is the frequency of the base failure mode. The
Steps 10–12 The STPA control actions are identified frequency of an ETA initiating event, f is then the mini-
based on the control diagram produced earlier in Step 2. mal cut set of n initiating failure modes and subsequent
This is followed by an assessment of unsafe control actions failures of prevention measures leading to it, described
and corresponding mitigation measures. Mitigation meas- by the following equation:
ures can be in the form of additional safety constraints or n
improved safety design. fa = [fm ]. (6)
m=1
Probabilistic event tree analysis The frequency of initial event on the ETA, f(E0) is then
In this approach, the initiating event is described as an obtained by the sum of minimal cut sets on battery rack
event of release of hazard i.e. release of toxic gas, thermal level, BESS unit level and global level, described by Eq. 7,
runaway, or an external fire not initiated by a battery unit. where Na and fa are number of units of system level
The frequency of occurrence of an initiating event can components and frequencies of failures, as described in
be obtained via historical data and failure rates of failure Table 7:
modes of the battery systems leading to the initial event.
The Institute of Electrical and Electronics Engineers (IEEE) f (E0 ) = N2 [(N1 × f1 ) + f2 ] + f3 . (7)
and Centre for Chemical Process Safety (CCPS) have speci-
The safety barriers identified for the BESS safety analy-
fied estimated frequencies of component failures covering
sis are listed in Tables 8, 9, and 10, using failure rates by
frequencies of hazard release events from electrical com-
IEEE and CCPS, based on systems components and soft-
ponent failures, mechanical impacts, internal short cir-
wares. These PFD values are used to compute initiating
cuits, overcharging, etc. for electrical power systems.
event frequencies of the event trees or as safety barriers
The release of hazard of the ETA initial event is con-
of the event tree to compute the outcomes of event trees.
ceptualized as occurrence of the initial failure and the
The safety barriers are classified as detection types, pas-
subsequent failure of prevention barriers e.g. BMS voltage–
sive barriers, active barriers and emergency response bar-
current control, cooling, shutdown and circuit breakers.
riers. Detection types cover BMS temperature, voltage,
1 Battery rack level Single failure affects one battery Internal short circuit, overcharg- f1 = MCS of frequency of battery N1 = Number
rack ing, communications failure rack level failures of battery
racks per BESS
unit
2 BESS unit Level Single failure affects one BESS unit Cooling system failure, external f2 = MCS of Frequency of BESS unit N2 = Number
or container short circuit, mechanical impact level failures of BESS units
in LSSPV
system
3 Global level Single occurrence affects all BESS Natural hazard event (e.g. flood) f3 = MCS of frequency of global
units level failures
Moa and Go Sustainable Energy Research (2023) 10:13 Page 17 of 31
BMS monitoring BMS Electrical, thermal Active 0.10 Currrent, voltage, SoC, temperature monitoring
Cooling system T1 Thermal Active 0.10 Temperature regulation of BESS
Space
Thermal Insulation T2 Thermal Passive 0.10 Minimize heat transfer between battery modules/racks
Fire and smoke detector FD Fire Detection 0.01 Detect smoke and produce visual and audible alert at control centre
Active fire suppression F1 Fire Active 0.10 Fire suppression, extinguishment, and cooling
Emergency fire response F2 Fire Emergency 0.10 Firefighter action plan
Gas detection XD Explosion Detection 0.01 Early detection for accumulation of flammable gases before reaching
explosive
Emergency ventilation X1 Explosion Active 0.10 Removal of gas before reaching explosive concentration
Emergency shutdown E1 Electrical/Fire Active 0.01 Electrical isolation
Circuit breaker E2 Electrical Active 0.10 Electrical isolation
Table 9 Conditional probability formula of each safety barrier (Landucci et al., 2017)
Type Safety barrier parameters Outcome value Description Formula
Table 10 Hazards for STPA (Leveson et al., 2018) the control room or automatically triggered. In context of
ID Hazard
fire mitigation, the cooling and ventilation are expected
to be working as the BESS is in operation, their rates are
H-1 Thermal runaway increased when sudden temperature or vented-gas con-
H-2 Fire centration is detected by the detection barriers.
H-3 Explosion The probabilistic event tree is used to evaluate the
H-4 Toxic gas venting probability of consequences for thermal runaway
H-5 Flammable gas venting starting in one cell and its subsequent propagation
H-6 Electrical arc flash to adjacent cells, and modules called cascading ther-
H-7 Hot surface mal runaway event, and escalation to fire or explosion
H-8 Electric shock event. The branches of the event tree are constructed
based on Misuri and Landucci’s domino effect model
of safety barrier performance on escalation scenarios
(International Electrotechnical Commission, 2020;
current monitoring functions and smoke and gas detec-
NFPA, 2022). Safety barriers are viewed as layers of
tors in the BESS room, where conditions outside accept-
protection against hazard escalation. For example, early
able operational limits produce alerts to operators in the
smoke detection and active fire suppression are safety
control room. Passive barrier types are safety designs that
barriers against an internal battery fire spreading to
do not require activation or triggering from a detection
multiple racks.
system i.e. thermal insulation design to prevent thermal
Applying the Layers of Protection Analysis (LOPA)
spread among battery modules. Active barriers such as
approach, safety barrier performance can be described by
the cooling system, fire suppression and ventilation are
probability of failure on demand, PFD and effectiveness,
safety functions dependent on the alert of a detection
η. The PFD of a safety barrier describes the conditional
system. They can be activated manually by operators in
probability of failure to activate when it is required. The
Moa and Go Sustainable Energy Research (2023) 10:13 Page 18 of 31
effectiveness describes its effect on mitigation given the A demonstration of the event tree is considered for
safety barrier is successfully activated (Misuri et al., 2021; the initiating event of a thermal runaway induced fire
Willey, 2014). in one battery rack, based on Cozzani’s model Event
For safety barriers considering only probability of fail- Tree sequences of industrial accident events and Mis-
ure on demand, two possible event paths considered uri’s demonstration of safety barrier performance assess-
are the success and failure to activate on demand. Once ment using event tree (Cozzani et al., 2010; Misuri et al.,
activated, the safety barrier is assumed to be fully effec- 2021). The event tree can be used to analyse events such
tive in mitigating the escalation of the hazard scenario. as external battery fire (fire in BESS space not directly
For safety barriers described by probability of failure on caused by battery cells), toxic chemical release, expo-
demand and effectiveness parameter, three outcomes are sure of reactive chemical to air and their consequences.
considered, where the safety barrier failed to activate on For example, an initiating event of toxic chemical release
demand, activated but not effective in mitigation of esca- can lead to consequences of water contamination, soil
lation of hazard scenario and activated and effective in contamination and toxic gas dispersion, analysable with
mitigation. the event tree. The initiating event of thermal runaway-
The conditional probability of each final ETA outcome induced fire is chosen as it is most commonly cited as
P(Ei) given the initiating event,
with n levels of safety bar- the scenario leading to prolonged battery fires and explo-
riers considered, where P Ein is the probability of the sion events in high-profile, BESS accidents with severe
outcome at each ith safety barrier is described by the fol- outcomes.
lowing equation (Misuri et al., 2021): The safety barriers between the event of fire and cata-
strophic event identified are the detection system (FD),
P(Ei) = �ni=1 P(Ein ). (8) the automated fire suppression (F1) and emergency fire
The frequency of occurrence is described by Eq. 9, response (F2), as shown in Fig. 13. Success of each stage
where fij is the frequency (per year) of a specified ETA of mitigation leads to reduced severity of final conse-
outcome Ei given an initiating event j with occurrence quence i.e. damage to BESS and fire hazard level. Here,
frequency f(Ej) per year. fij is computed for all outcomes fire hazard level represents the risk to the firefighters on
for each LSSPV site according to the number of battery site. The effectiveness, η of the Active Fire Suppression
units present (Misuri et al., 2021): considered is 0.953 (Landucci et al., 2017). Therefore,
three outcomes are considered for active fire suppression
fij = f(Ej) P(Ei). (9) gate. The outcomes considered are labelled 1.1 to 1.7 and
their probabilities and frequencies are evaluated in the cycle, Cycle 4 are expected to be commissioned between
Results section. 2022 and 2023. The EC offers two packages based on LSS
PV capacity range with their own Power Purchase Agree-
ment Pricing (Commission, 2022).
STPA‑based analysis For the case study of this work, one site from LSSPV
The benefit of STPA to apply in this methodology is to P1 Package and one site from LSSPV P2 Package has
identify causal factors of UCAs by considering the LSSPV been chosen for quantitative risk assessment. Refer-
system, from its main components (PV modules, invert- ring to Table 11, Site 5 of 13.0 MW capacity in the
ers, Battery units) up to organizational structures (on- state of Selangor and Site 9 of 50.0 MW capacity in the
site operators, Fire Department, LSSPV owner). First, state of Perak are considered, labelled site A and site B
the system level hazards are defined. As a validity check, in Table 12. Based on research carried out by Laajimi
Leveson discussed that to keep hazards analysis on a sys- et al. (Mahmoud Laajimi, 2021), the total battery stor-
tem level, identification of any specific system compo- age capacity for each site configuration was calculated
nents should be avoided, and hazard count usually kept using the annually averaged ratio of storage energy out-
under 10 (Leveson et al., 2018). put to the energy output from the solar farm. PV sizing
is done via 550 W monocrystalline PV modules. For the
STPA control structure (step 3) 13.0 MW capacity site A, 2.0 MVA central inverters units
The control structure is constructed considering based and 2.510 MWh Li-ion NMC BESS units are deployed
on the Malaysian organizational structure of LSSPV and and for site B, 4.2 MVA central inverters and 4.18 MWh
BESS management, where the Energy Commission gov- Li-ion NMC BESS units are deployed (Electric, 2018; Sie-
erns the scheme for LSSPV and BESS grid-operation, mens & Flyer, 2020; Solar & “Hi-MO5”, 1011, 2021). The
whereas the Department of Standards are responsible configurations are verified in PVSyst to ensure no over-
for safety standards to protect the equipment and work- sizing or undersizing of PV array and inverters.
ers in the vicinity of the equipment. Arrows between sys-
tem elements represent communication of information Event tree analysis and probabilistic assessment
or commands (control actions) between component ele- BESS sizing, units and racks quantity
ments. The control diagram used for this STPA analysis Two configurations for site A, A1–A2 and five configu-
is shown in Fig. 14, adapted from Choo and Rosewater’s rations for site B, B1–B5 are assessed for the probabilis-
STPA analyses of Grid connected Li-ion Batteries (Choo tic event tree analysis, as shown in Table 12. Varying A
& Go, 2022; Rosewater et al., 2020). value from 20% to 60%, the Kuala Selangor site installed
Control actions between component elements are BESS capacity required corresponds to 5–10 MWh. For
identified. Typically control actions are characterized 20–60% A value in Batang Padang site, installed battery
as commands from a controller type element of higher storage capacity corresponds to 16–48 MWh. Therefore,
authority in the control structure, to a lower-level com- Site A will have 2–4 units of the 2510 kWh BESS, housing
ponent or subsystem. Here, feedback (e.g. battery mod- 12 racks per BESS unit. Site B will have 4–11 units of the
ule temperature, voltage, current, etc.) and commands 4184 kWh BESS, with 20 racks per unit (Electric, 2018).
(e.g. alarm activation, increased cooling rate or physical In total, site A houses 24–48 total battery racks, and site
actions) are considered as control actions. As Leveson B houses 80–220 racks. The number of battery storage
explains, that mischaracterizing feedback and control units and total battery racks are used in the evaluation of
actions will result in the same causal factors identified in event tree outcomes.
latter steps of STPA. Based on each control action, unsafe
control actions (UCAs) are then identified by considering Event tree outcome evaluation
how a purposeful control action not provided, provided, The probability of outcomes the Battery Rack Fire Event
provided too late or too early, or stopped too early or too Tree in Fig. 13 is presented in Table 13. Outcomes of
late may lead to a system hazard state. safety barriers FD, F1 and F2 are labelled based on
Table 9 outcome values 0, 1, 2 or “X” denoting success
Results and discussion or failures in mitigation. Outcome Probabilities, P(E) are
A case study on two LSS sites in Malaysia was used to conditional probabilities of each event tree outcome or
validate the EcS quantification of frequencies of severe path in the event of the initiating event i.e. battery rack
damage per year via Event tree-based analysis. The fire. Using this analysis, the probability of successful early
Energy Commission of Malaysia promotes development fire suppression expressed by Outcome 1.1 is 0.8491. This
of large-scale solar PV plants through its competitive is the ideal situation, where fire detection and active fire
bidding programme. Projects on the current bidding suppression system are successful, and no emergency
Moa and Go Sustainable Energy Research (2023) 10:13 Page 20 of 31
Energy Commission
Controller
Load
BESS Room/Container
Fig. 14 STPA control diagram of grid connected LSSPV with BESS (Choo & Go, 2022) (Rosewater et al., 2020)
response is required. The worst-case scenario in consid- to contain the fire. This worst-case scenario is expected
eration is Outcome 1.7, where fire detection system fails to occur at probability of 0.001 in the event of a battery
to produce an alert, the fire suppression system is not rack fire. Another severe outcome scenario is Outcome
activated, and the emergency responders (Fire Team) fail 1.5, where fire detection and alert is successful, but fire
Moa and Go Sustainable Energy Research (2023) 10:13 Page 21 of 31
Table 11 List of approved bidders for LSS cycle 4 (Commission and “LSSPV Bidding Cycle 4 (LSS@MEnTARI)”, 2022)
No Bidder Location Capacity Package PPA price (RM/kWh)
(MW)
LSSPV + BESS
Size Total capacity MW 13.0 50.0
A–storage/LSSPV output % 20–30 40–60 20 30 40 50 60
PV modules PV module rating W 550.0
No. PV modules 29,457 109096
No. strings 1091 1091 4196 4196 4196 4196 4196
Balance of system
String fuse 1091 1091 4196 4196 4196 4196 4196
DC switch 8 8 11 11 11 11 11
AC circuit breaker 8 8 11 11 11 11 11
Central inverter MVA 2.0 4.2
No of inverters 8 8 11 11 11 11 11
Battery energy
Storage Li‐NMC BESS unit size kWh 2510 4184
Total BESS capacity MWh 5.02 10.04 16.74 25.10 33.47 41.84 46.02
No. of BESS units 2 4 4 6 8 10 11
No. battery racks/unit 12 12 20 20 20 20 20
Total battery racks 24 48 80 120 160 200 220
suppression fails to activate and emergency responder of 2.173 × 10–7 per year. For site B1, which has the most
actions fail, with probability of 0.0099. number of battery units and racks, it had a frequency
Given the frequency of initiating event of site config- of occurrence of 2.5753 × 10–6 per year. The frequencies
urations A1–B5, calculated based on Eq. 7, the frequen- of damage levels and BESS damage levels are consoli-
cies of each outcome of the event tree are tabulated in dated in Table 15. Frequency of multiple battery rack
Table 14. For the worst outcome which is outcome 1.7 damage for sites A1 to A2 ranges from 2.222 × 10–5
in Table 13, site A1 with the least number of battery to 4.028 × 10–5, whereas for site B1 to B5 ranges from
units and racks resulted in a frequency of occurrence 9.802 × 10–5 to 2.398 × 10–4, due to higher number
Moa and Go Sustainable Energy Research (2023) 10:13 Page 22 of 31
1.1 1 1 1 1 X 8.491E–01
1.2 2 1 1 2 1 3.769E–02
1.3 2 2 1 2 0 4.188E–03
1.4 3 2 1 0 1 8.910E–02
1.5 3 3 1 0 0 9.900E–03
1.6 3 2 0 X 1 9.000E–03
1.7 3 3 0 X 0 1.000E–03
of total battery racks and BESS units. For the same A UCAs where control actions are provided as designed,
values, site A has lower risk of severe damage to BESS and lead to hazard escalation provide assessments
from thermal runaway-induced fire by 3.3 to 4.5 times of abnormal conditions of the system which require
compared to site B. Evaluating from the event tree different action plans. For example, in the event of
paths, failures of either the fire detection system or combustible gas mix build up in the BESS enclosure,
the active fire suppression system leads to unmitigated opening the door of the BESS room in attempt to vent
fire spread inside the BESS room. Targeted mitigation the gas would introduce fresh air, increasing the flam-
measures should be assessed to reduce the failure rates mability of the gas mixture thereby increasing the risk
of these two systems to reduce the risk of severe dam- of instantaneous explosion (McKinnon et al., 2020).
age in the event of battery rack fire, demonstrated in UCAs of regulation actions pertaining to safety train-
’’STPA Results’’ section. ing and BESS site acceptance test requirements are
also considered. Following this step, causal factors and
STPA results corresponding mitigation measures are suggested.
A list of unsafe control actions is described in Table 16,
presenting UCAs focused on the failure modes of the Causes and mitigation measures
active safety systems i.e. active cooling, active fire Based on the full list of unsafe control actions, the causal
suppression and active ventilation and emergency scenarios are assessed and mitigation measures are iden-
responder actions. UCA types are categorized as “not tified accordingly. Multiple causal scenarios are found to
provided”, “provided”, “provided too early or late” and be redundant for different categories of control actions
“stopped too early or late”, all UCA types lead to haz- e.g. gas detection system and smoke detection system
ardous states or escalation. The full list is available in UCAs are found to have overlapping causal factors, thus
supplementary material. grouped together in Table 17. Gas detection and smoke
UCAs identified cover failures of the hazard detec- detection systems are grouped together. BMS monitoring
tion systems i.e. BMS temperature, voltage, current sensor systems (voltage, temperature, current monitoring
monitoring systems and the smoke and gas detection circuits) are grouped together.
systems of the BESS. Active safety systems are hazard For safety sensors and alerts, mitigation measures
prevention or mitigation systems that require a detec- include strategic placement of gas concentration sen-
tion trigger, e.g. for the ventilation system, the venti- sors at different height levels in the BESS room, to ensure
lation rate is increased once the BESS gas detection detectability of gases lighter than air, heavier than air or
sensors detect a quick increase of concentration of stratified by coolant compound. Faults in the sensor cir-
flammable gases. UCAs on the failure of active safety cuits should also produce alerts to operators in the con-
systems e.g. fire suppression activation not provided, trol room. Failure causes of the active safety systems can
provided incorrectly, provided late or stopped early be mechanical failure of fans or pumps. Among mitiga-
lead to similar outcomes i.e. unmitigated fire spread. tion measures identified is for the HVAC coolant mate-
The effects and causes of these UCAs are generally rial to be detectable by gas sensors in case of leakage.
foreseeable with basic knowledge of safety. However, For the emergency ventilation system, positive pressure
Moa and Go Sustainable Energy Research
system is suggested, to pump chemically inert gas into the causality and progression of events. This approach
the BESS space to displace a toxic or combustible gas may overlook failures caused by the interactions between
mixture safely. Tables 17 and 18 cover causal scenarios system components under abnormal system states. Based
and mitigation measures suggested for the safety sensors, on this understanding, the EcS method proposed further
BMS monitoring systems, active safety systems, designs analyses the indirect interactions of the LSSPV + BESS
to assist the fire and rescue team, and institutional-level systems and components leading to hazardous states. The
measures such as having clear numerical design require- qualitative findings of the EcS method includes causal
ments for the active safety systems for BESS set by the scenarios and mitigation measures derived from possible
local authority. failures contributed by these indirect interactions. For
example, the fire suppression system failure and effec-
Risk assessment evaluation tiveness, and failure consequence analysis is evaluated
The risk assessment methods reviewed in ’’Safety and in ’’STPA-based Analysis’’ section and its indirect failure
Risk Assessment’’ section adopt different assessment causes and mitigations are assessed in ’’STPA Results’’
parameters to fit different purposes of assessment e.g. section. The initiating event analysis also incorporates
to analyse minimal cut sets of conditions for failure, to various contributory failure mechanisms, scalable to the
evaluate hazard escalation sequences and consequences component sizing of the LSS + BESS system.
of failures or to improve detectability and preventabil- Quantitative assessments for severe BESS damage due
ity of failures. The combinations of parameters facilitate to thermal runaway induced fire found that likelihood of
the intended focus and purpose of the assessment and total BESS unit damage for 5–46 MWh Li-NMC storage
its results. The parameters of the proposed EcS method systems ranged from 2.489 × 10–6 to 2.807 × 10–5 occur-
are compared against the methods reviewed in ’’Safety rence per year. This translates to risk of one worst case
and Risk Assessment’’ section and Choo’s Holistic-STPA outcome per 35,000–400000 years. Worst case scenario
method (Choo & Go, 2022). The parameter types are unmitigated fire risk to human ranges from 2.489 × 10–5
categorized by system definition parameters such as sys- to 2.807 × 10–4 per year. Higher capacity LSS systems
tem constraints and control actions. Accident analysis incorporating more BESS units and battery racks require
parameters cover contributing causes and consequences increased monitoring and safety barrier safeguards to
of undesired system failure events. Corrective action lower the risk of hazardous events causing damage to the
parameters describe preventive measures, mitigation equipment. The incorporation of LOPA and Event Tree
measures incorporated into system design and actions analysis provides a quantitative framework to compare
taken at an organizational level or emergency response risks of severe outcomes from an undesired initiating
level. Parameters for quantitative risk analysis include event. Mitigation measures can then be considered. For
risk ranking, component or safety barrier failure prob- example, Outcome 1.5 of Table 13 where the fire detec-
abilities, and damage severity. tion system succeeds but fire suppression and emergency
Traditional applications of chain of events model, responder actions fail, contribute to the same severe
namely ETA, adopt a direct, linear and exclusive view on
Moa and Go Sustainable Energy Research (2023) 10:13 Page 25 of 31
Alert: Smoke/fire Smoke detection BMS Not provided: Operators Not provided
unaware and unable to take
action. Vented gas can build
up to flammable mixture
Smoke detection BMS Incorrect (esp. Undermeasure) Provided
of concentration value can
mislead operator decision
Smoke detection BMS Late response due to late alert Provided too early or late
Temperature Modules/ cells BMS Loss of real‐time monitoring Not provided
data hazardous situation may
escalate unmitigated: over-
heating and thermal runaway
propagation
Modules/cells BMS Inaccurate temperature Provided
measurements lead to misin-
terpretation of hazard status
and wrong decision
Modules/cells BMS Wrongly timestamped data Provided
leads operators and ERT
to misinterpret hazard status
Activate cooling BMS HVAC (cooling) Command not given: thermal Provided
runaway propagation to adja-
cent cells
BMS HVAC (cooling) Stopped too soon may allow Stopped too soon or late
heat propagation to continue
BMS HVAC (cooling) Introducing fresh cold air Provided
may cause explosion if there
is an explosive concentration
of gas mixture and hot
Surface to auto‐ignite one
of the gas mixture constitu-
ents
Activate fire suppression BMS Active fire suppression Heat and fire spread unmiti- Not provided
gated to adjacent modules/
racks
BMS Active fire suppression In case of partial area fire Provided
suppression system activating
fire suppression at incorrect
area is
Equivalent to not activating,
fire and heat spread
Unmitigated
BMS Active fire suppression Activating late is equivalent Provided too early or late
to not activating, fire and heat
spread unmitigated
BMS Active fire Stopped too soon, residual Stopped too
heat may cause re‐ignition
Suppression soon or late
BMS Active fire Incorrect clean agent may Provided
create pressurized
Suppression combustible mixture
Activate BMS Exhaust/ Gas build‐up reaches com- Not provided
bustible/explosive
Emergency Ventilation Deflagration ventilation concentration
BMS Exhaust/deflagration Insufficient ventilation rate Provided
may be ineffective in reduc-
ing concentration of accumu-
lated gas mixture to
Ventilation Safe levels
Moa and Go Sustainable Energy Research (2023) 10:13 Page 26 of 31
Table 16 (continued)
Control action Source Destination Unsafe control actions UCA type
BMS Exhaust/deflagration Ventila- Stopped too soon gas con- Stopped too soon or late
tion centration and pressure build
up in BESS room may con-
tinue if cell is still undergoing
thermal runaway
Fire Suppression Emergency response Team Modules/cells Fire spread unmitigated Not provided
(Manual)
Open access door/Panel Emergency response team Modules/ cells Introduces fresh air (oxygen) Provided
for fire to combustible gas mixture.
In presence of burning flame
in BESS roommay cause
instant explosion
Suppression
Emergency response team Modules/cells Fire spread unmitigated Not provided
Emergency response team Modules/ cells Providing late: fire spread Provided too early or late
unmitigated
Continued Emergency Modules/ Risk of residual heat causing Stopped too
thermal runaway and re‐
Cooling and monitoring Response team Cells Ignition Soon or late
Emergency response Modules/cells Providing late: increased Provided too early or late
likelihood of thermal runaway
and re‐ignition
Team
Emergency response team Modules/ cells Stopped too soon: increased Stopped too soon or late
likelihood of thermal runaway
and re‐ignition
Emergency Modules/ Insufficient cooling and alert- Provided
ness increases likelihood
Response team Cells of thermal runaway and re‐
ignition
Emergency shutdown BMS Modules/cells Affected battery modules Not provided
continue charge/discharge
operation increasing likeli-
hood of thermal runaway
escalation
BMS Modules/cells Providing late equivalent Provided too early or late
to not providing increasing
likelihood of thermal runaway
escalation
Site acceptance Dept of Standards LSSPV operator/ Inaccurate testing require- Provided
ments for various types
of BESS technologies
Test requirements Owner
Safety function Dept of Standards Equipment manufacturer Safety functions built Provided
into BESS with wrong param-
eters
Requirements
Emergency response Emergency response team Site operator/technicians Inadequate information Provided
training hinders operators from cor-
rect early mitigation action
in hazard scenario delay
causes hazard escalation
Emergency response Site operator/ Operators take wrong action Not provided
in hazard release event lead-
ing to hazard escalation
Team Technicians
Moa and Go Sustainable Energy Research (2023) 10:13 Page 27 of 31
Safety sensors & alert Sensor circuit failure Audible and visual alert function checking in SAT
and maintenance plan
Sensor fault diagnosis and alert function
Gas detection & smoke detection Physical damage to collector, probe or cables Data cables protected in appropriate conduit
Sensor contamination or corrosion Humidity control as part of BESS room HVAC function
Inadequate sensor coverage Adequate and strategic placement of sensors
Gas composition measurement probes at low levels
to detect stratification of combustible gas mixture
BMS monitoring sensor circuits Sensor/communications circuit failure Sensor fault diagnosis and alert function at control room
Temperature Thermal imaging feed of BESS room available in control
room
Voltage BMS to isolate affected module/rack and enter sensor
failure safe mode
Current Physical damage to collector, probe Data cables pro- Data cables protected in appropriate conduit
tected in appropriate conduit or cables
State of charge Electrical isolation and replacement procedures for faulty
sensor
Vent state Hysteresis leads to lagging measured value Temperature sensor integrated with hysteresis feedback
control loop
Cooling system Coolant leak Coolant compound to be detectable by gas sensor
Selection of chemically inert coolant compound
Cooling capacity mismatch Adequate design of cooling system (coolant thermal
conductivity and circulation rate)
Pump failure Insulated piping for coolant delivery
Redundant back‐up pumps to be installed
Pumps to follow scheduled maintenance plan
Auto fire suppression system Water supply failure Adequate design to provide sufficient water pressure,
compliant with local fire code
Pump failure Back‐up pumps to be installed
Pump scheduled maintenance plan
Inadequate sprinkler head coverage Adequate sprinkler head placement and coverage
Human error: operator turns off sprinkler system Operator trained on all known abnormal situations
prematurely
Ventilation system Damaged HEPA filter Maintenance plan to include filter check and replace-
ment
Fan failure Ventilation fans to follow scheduled maintenance plan
Airflow, quality, and humidity monitoring at operator
control centre
Introduction of oxygen to Positive pressure emergency Positive pressure emergency ventilation system using
ventilation system combustible mixture inert gas to displace combustible/toxic gas mixture
Fire and rescue team Firefighters unaware of status inside portable multi‐gas Portable multi‐gas meters, colorimetric tubes,thermal
meters, colorimetric tubes, BESS room (gas composition, imaging equipment
thermal runaway status)
Glass panel(s) on BESS room to provide visual feed
Live feed of data from BMS control server available
for firefighters on site
BESS Gas detection system to require gas composition
measurement and relation to safety limits (toxicity ppm,
explosivity limit, flammability limit)
Firefighters inadequately trained on all ESS hazards Complete ESS hazard scenarios and mitigation plans
and escalation factors to be included in training curriculum
No remote option to manually ventilate BESS room/ Deflagration vents incorporated into design of BESS
open BESS door
Water or inert gas supply inlet for firefighters to be
located at safe distance from BESS structure
Moa and Go Sustainable Energy Research (2023) 10:13 Page 28 of 31
Table 17 (continued)
Category Cause Mitigation
Remaining stored charge in battery modules Decommissioning process to disconnect and discharge
battery modules in safe environment before
Dept of standards Inadequate details for cascading thermal runaway Set clear numerical limits on safety systems (ventilation
prevention requirements for manufacturers & Set clear rate, coolant volume, etc.) and suggested methods
numerical limits on safety systems (ventilation rate,
coolant volume, etc.) and suggested methods BESS
system owners (NFPA855/IEC62933)
Further research into prevention of cascading thermal
runaway
Table 18 Comparison of proposed EcS assessment parameters against reviewed risk assessment methods and recently developed
STPA‐H method (Choo & Go, 2022)
Safety/risk assessment Safety and risk
parameters assessment
method
ETA FTA FMEA HAZOP STPA LOPA STPA‐H (Choo & Go, 2022) EcS
System definition Design ETA FTA FMEA HAZOP STPA‐H STPA‐H EcS
Parameter/elements guide- ETA FTA FMEA HAZOP
words
Constraints STPA STPA‐H EcS
Control structure STPA STPA‐H EcS
Control actions STPA STPA‐H EcS
Accident analysis ETA FTA FMEA HAZOP STPA LOPA STPA-H EcS
Events ETA FTA FMEA HAZOP STPA LOPA STPA‐H EcS
Causes ETA HAZOP LOPA STPA‐H EcS
Consequences
Corrective action
Preventive measures FTA FMEA HAZOP STPA LOPA STPA‐H
Mitigation measures ETA FMEA HAZOP STPA LOPA STPA‐H EcS
Action required HAZOP STPA STPA‐H EcS
Quantitative risk Analysis ETA FTA FMEA LOPA STPA‐H EcS
Probabilistic risk Ranking ETA FTA FMEA LOPA STPA‐H EcS
Failure probability
Component failure FTA FMEA LOPA STPA‐H EcS
Safety barrier failure ETA FTA FMEA LOPA EcS
Damage severity FMEA EcS
a
EcS Event-centric systems analysis included quantitative analysis of safety barrier failures and mitigation measures targeted at safety systems
consequences as Outcome 1.7, but Outcome 1.5 has in ’’Literature Review’’section followed by a review of
higher probability. Mitigation measures can be targeted risk assessment methods and case studies, outlining the
to reduce the likelihood of Outcome 1.5. advantages and limitations of each method. Industrial
safety standards NFPA855 and IEC62933, BESS safety
Conclusions review articles, and BESS accident reports provided
Various research of large-scale solar (Isaac & Ii, 2023; crucial information on identifying safety failures that
Mohanan, 2020; Rehan Khan & Yun Ii Go, 2019) had were previously overlooked. The proposed risk assess-
been carried out including grid integration, power man- ment methodology was presented and demonstrated in
agement and system sizing etc. A literature review cover- ’’Methodology’’ section. The formulation of the event tree
ing various energy storage (Citalingam, 2022; Faruhaan & and quantitative method to evaluate frequencies of out-
Ii, 2021; Mahmoud, 2019; Mohammed & Go, 2021; Teo & comes for each site based on probabilities of failures of
Go, 2021) technologies and hazards had been presented the LSS + BESS subsystems were presented. The STAMP
Moa and Go Sustainable Energy Research (2023) 10:13 Page 29 of 31
control structure used in the STPA was introduced, with assessment framework presented would benefit the
modifications from references placing more importance Malaysian Energy Commission and Sustainable Energy
on safety systems, along with principles for identifying Development Authority in increased adoption of battery
hazards and unsafe control actions. storage systems with large-scale solar plants, contribut-
For large-scale solar plant with a total capacity of ing to IRENA 2050 energy transformation scenario tar-
13.0 MW and 50.0 MW, and A value of 20–60%, it is gets for global temperature control and net zero carbon
recommended to adopt BESS capacities that ranging emissions.
from 5.0 to 10.0 MWh and 16.0–48.0 MWh, respec-
tively. Analysis of the worst-case outcomes for fire
Abbreviations
hazard to human injuries ranged from 2.368 × 10–5 to LSS Large-scale solar
2.807 × 10–4 per year, and for BESS damage ranged from BMS Battery management system
2.368 × 10–6 to 2.807 × 10–5 per year. Further improve- MCS Minimal cut set
CCPS Centre of chemical process safety
ment measures were assessed qualitatively in the STPA NMC Nickel manganese cobalt
analysis with emphasis on failures of safety barriers by DET Detectability
indirect causes or abnormal system states. Causal fac- NaNiCl2 Sodium nickel chloride
EC Energy commission
tors identified covered component failures, loss of data NaS Sodium sulphur
to guide emergency response actions and inadequate EcS Event-centric system analysis
information or organizational framework pertain- NFPA National fire protection agency
ETA Event tree analysis
ing to BESS safety. The mitigation measures identified OCC Occurrence
covered improvements to sensor coverage, emergency FTA Fault tree analysis
responder contingencies for data on BESS state and SEDA Sustainable energy development authority
HAZMAT Hazardous materials
redundancy measures for safety systems components STAMP Systems-theoretic accident model and process
(pumps and fans). HAZOP Hazards and operability
SEV Severity
HVAC Heating, ventilation and air conditioning
• 13.0 MW LSS site with 5–10 MWh Li-NMC BESS, SOC State of charge
the frequency of worst-case total BESS unit dam- IEC International electrotechnical commission
age due to thermal runaway fire is observed to be STAMP Systems-theoretic accident model and process
IREN International renewable energy agency
2.368 × 10–6 to 4.363 × 10–6 per year. STPA System-theoretic process analysis
• 50.0 MW LSS site with 16–46 MWh Li-NMC BESS, IPL Independent protection layers
the frequency of worst-case total BESS unit dam- UCA Unsafe control actions
LC Lethal concentration
age due to thermal runaway fire is observed to be VRLA Valve regulated lead acid
1.037 × 10–5 to 2.800 × 10–5 per year. LFL Lower flammability limit
• Safety barrier failure modes analysed via STPA-based VRFB Vanadium redox flow battery
LIP Lithium iron phosphate
identified causal factors such as component failures, ZnB Zinc bromine
system failures and failures in organizational proto-
cols Acknowledgements
Not applicable.
• Mitigation measures analysis identified required
improvements to safety design, contingencies for Author contributions
emergency responders and redundancy measures for EA involved in data analysis, interpretation of data and manuscript writing, GYI
involved in supervision, design of the work, manuscript revision.
safety system components
Funding
Not applicable.
Principles of incorporating both component and sys-
temic view, assessment of safety barrier failures and Data Availability
assessment of indirect causal factors in abnormal sys- The datasets generated during and/or analysed during the current study are
available from the corresponding author on reasonable request.
tem states are necessary to develop an adequate safety
framework for complex energy systems such as an LSS Availability of data and materials
with BESS. Stakeholders and LSS owners are expected The datasets generated during and/or analysed during the current study are
available from the corresponding author on reasonable request.
to benefit from reduced risk of severe equipment dam-
age and asset loss from accident events. Emergency
responders benefit from improved safety protocols and Declarations
safety requirements leading to reduced risk of severe Competing interests
injuries or fatalities in accident events. The EcS risk The authors declare that they have no competing interests.
Moa and Go Sustainable Energy Research (2023) 10:13 Page 30 of 31
Received: 27 March 2023 Accepted: 5 August 2023 European civil protection and humanitarian aid operations. (2022). ERCC—
Emergency Response Coordination Centre 2022. Retrieved. Mar 14 2022,
From. [Link]
daily-flasharchive/4448.
Faruhaan, A., & Ii, G. Y. (2021). Energy storage sizing and enhanced dispatch
References strategy with temperature and safety considerations: a techno-economic
Accident analysis of Beijing Jimei Dahongmen 25 MWh DC solarstorage- analysis. Energy Storage Wiley. [Link]
charging integrated station projec,” 04 (2021).Retrieved July 15 2022, Fuentes-Bargues, J. L., González-Cruz, C., González-Gaya, C., & Baixauli- Pérez,
From. [Link] P. (2017). Risk analysis of a fuel storage terminal using HAZOP and FTA.
20%281%29.pdf. International Journal of Environmental Research and Public Health. [Link]
Aitugan, S., & Li, L. (2020). Risk and economic analysis methods of commercial doi.org/10.3390/ijerph14070705
aero engines in safety and risk assessment of civil aircraft during operation. General Electric. (2018). GE power energy storage units. Retrieved July 22 2022,
IntechOpen. From. [Link]
Alileche, N., Cozzani, V., Reniers, G., & Estel, L. (2015). Thresholds for domino documents/Reservoir%20Solutions%20Product%20Specification%20She
effects and safety distances in the process industry: are view of ets.pdf.
approaches and regulations. Reliability Engineering and System Safety, Gully, B. (2019). Technical reference for li-ion battery explosion risk and fire
143(74), 84. suppression. DNV GL, Hovik
American Society for Quality. (2022). American Society for Quality Retrieved Hajeforosh, S., Nazir, Z., Bollen., M 2020. Reliability aspects of battery energys-
Mar 30 2022 From. [Link] torage in the power grid. IEEE.
Antweiler, PW. (2014). Can flow batteries solve the electricity storage problem Hermansyah, H., Hidayat, M. E. N., Kumaraningrum, A. R., & Yohda, M. (2018).
Retrieved April 12 2022, from. [Link] Assessment, mitigation, and control of potential gas leakage in existing
item=2014-09-28 buildings not designed for gas installation in Indonesia. Energies. [Link]
ASEAN Disaster Information Network. Malaysia, Flooding and Landslide in doi.org/10.3390/en11112970
Selangor and Sabah 2021. Retrieved Mar 12 2022. Hossain, E., Faruque, H. M. R., Sunny, M. S. H., Mohammad, N., & Nawar, N.
Barrere, M., Hankin. C (2020) Fault tree analysis identifying maximum probabili- (2020). A comprehensive review on energy storage systems: types, com-
tyminimal cut sets with MaxSAT. Valencia. parison, current scenario, applications, barriers, and potential solutions,
Behabtu, M. (2020). Coosemans and berecibar, a review of energy storage policies, and future prospects. Energies, 13, 3651.
technologies’ application potentials in renewable energy sources grid International Electrotechnical Commission. (2020). IEC 62933-5-2:2020. Geneva:
integration. Sustainability, 12, 10511. IEC.
BERNAMA. BERNAMA—Malaysian National News Agency. Retrieved Febrauary International renewable energy agency. (2050). Global renewables outlook:
26 2022a. [Link] Energy transformation 2050, IRENA, Abu Dhabi 2020.
id=2044085 IRENA. (2021). IRENA World renewable energy statistics
BERNAMA. BERNAMA—Malaysian National News Agency, 2022b. Retrieved. Isaac, F. M., & Ii, G. Y. (2023). Power management scheme development for
Febrauary. 26 2022b, From. [Link] large-scale solar grid integration. Journal of Electrical Systems and Informa-
news_disaster.php?id=2040627 tion Technology. [Link]
BuslimaJamaluddin, O. (2018). Flood and flash flood geo-hazards in Malaysia. Jin, Y., Zhao, Z., Miao, S., Wang, Q., Sun, L., & Lu, H. (2021). Explosion hazards
International Journal of Engineering & Technology., 7, 760–764. study of grid-scale lithium-ion battery energy storage station. Journal of
Chen, Y., Kang, Y., Yun, Z., & Wang, L. (2022). A review of lithium-ion battery Energy Storage. [Link]
safety concerns: the issues, strategies, and testing standards. Journal of Kebede, A. A., Kalogiannis, T., & Mierlo, J. V. (2022). A comprehensive review
Energy Chemistry., 59, 83–99. of stationary energy storage devices for large scale renewable energy
Choo, B. L., & Go, Y. I. (2022). Energy storage for large scale/utility renewable sources grid integration. Renewable and Sustainable Energy Reviews, 159,
energy system—an enhanced safety model and risk assessment. Renew- 112213.
able Energy Focus, 42, 79–96. Khan, R., & Go, Yl. (2020). Assessment of Malaysia’s large scale solar projects:
Citalingam, K., & Go, Y. I. (2022). Hybrid energy storage design and dispatch power system analysis for solar PV grid integration. Global Challenges.
strategy evaluation with sensitivity analysis: Techno-economi-cenviron- [Link]
mental assessment. Energy Storage Wiley, 4, e353. [Link] Koubli, B., & Roy, G. (2018). Impact of component reliability on large scale
est2.353 photovoltaic systems performance. Energies, 11, 1579–1590.
Colthorpe, A. (2019). Energy storage news solar media Ltd. 19 06 2019. Landucci, G., Necci, A., Antonioni, G. A., & Cozzani, F. (2017). Risk assessment
Retrieved July 16 202, From. [Link] of mitigated domino scenarios in process facilities. Reliability Engineering
ess-fires-batteries-not-to-blame-but-industry-takes-hit-anyway/ and System Safety. [Link]
Cozzani, V., Campedel, M., Rennia, E., & Krausmann, E. (2010). Industrial Leveson, N., Thomas, J. (2018). STPA Handbook.
accidents triggered by flood events analysis of past accidents. Journal of Lin, Yi., & Go, T. Y. I. (2021). Techno-economic-environmental analysis of solar/
Hazardous Materials, 175, 501–509. hybrid/storage for vertical farming system a case study. Malaysia. Renew-
Elia, G., & Kravchyk, K. (2021). An overview and prospective on al and al-ion able Energy Focus Elsevier, 37, 1–18. [Link]
battery technologies. Journal of Power Sources. [Link] 005
jpowsour.2020.228870 Liu, Y., Sun, P., & Lin, S. (2020). Self-heating ignition of open-circuit cylindrical li-
Energy commission. (2022). LSSPV bidding cycle 4 (LSS@MEnTARI). Energy ion battery pile: towards fire-safe storage and transport. Journal of Energy
Commission 2022. Retrieved. April 11 2022, From[Link] Storage. [Link]
ms/web/industry/details/2/15 Mahmoud, L., & Go, Y. I. (2019). Energy storage system design for large-scale
Esser, B., Dolhem, F., & Becuwe, M. (2020). A perspective on organic electrode solar pv in malaysia: technical and environmental assessments. Journal of
materials and technologies for next generation batteries. Journal of Power Energy Storage Elsevier. [Link]
Sources. [Link] McKinnon, MB, DeCrane, S. Kerber, S. (2020). Four firefighters injured in lith-
European civil protection and humanitarian aid operations. emergency ium—ion battery energy storage system explosion-arizona. Underwriters
response coordination centre (ERCC) Portal. Retrieved Mar 12 2022, Laboratory. Columbia
From, [Link] Mexis, I., & Todeschini, G. (2020). Battery energy storage systems in the united
ECHO-Flash-old/ECHO-Flash-List/yy/2020a/mm/11 kingdom: A review of current state-of-the-art and future applications.
European civil protection and humanitarian aid operations, “emergency Energies, 13, 3616.
response coordination centre (ERCC) Portal. Retrieved Mar 12 2022, Misuri, A., Landucci, G., & Cozzani, V. (2021). Assessment of risk modification
From. [Link] due to safety barrier performance degradation in natech events. Reli-
ECHO-Flash-old/ECHO-Flash-List/yy/2020b/mm/3 ability Engineering and System Safety. [Link]
107634
Moa and Go Sustainable Energy Research (2023) 10:13 Page 31 of 31
Mohammed, A. M., & Go, Y. I. (2021). Large energy storage system design and
optimization for large scale solar photovoltaic in Malaysia. Energy Storage
Wiley. [Link]
Mohanan, M., & Go, Y. (2020). Optimized power system management scheme
for LSS PV grid integration in malaysia using reactive power compensa-
tion technique”. Global Challenge Wiley. [Link]
201900093
National fire protection agency. (2020). Standard for the Installation of
stationary energy storage systems. Quincy, Massachusetts: National Fire
Protection Agency.
NFPA. (2022) National fire protection association. Retrieved April 05 2022,
From. [Link]
ards/List-of-Codes-and-Standards.
Pierce, M. (2019). Quantitative riskanalysis for battery energy storage sites. DNV
GL 2019.
Rehan, K., & Go, Y. I. (2019). Assessment of Malaysia’s large-scale solar projects
power system analysis for solar PV grid integration. Global Challenge.
[Link]
Reliefweb, “Malaysia: A second landslide to wreak havoc in Taman Bukit
Mewah?. 2008. Retrieved Mar 11 2022. [Link]
sia/malaysia-second-landslide-wreak-havoc- taman-bukit-mewah
Rosewater, D., Lamb, J., & Hewson, J. (2020). Grid-scale energy storage hazard
analysis & design objectives for system safety. Sandia National Laboratories.
Rosewater, D., & Williams, A. (2015). Analyzing system safety in lithium-ion grid
energy storage. Journal of Power Sources, 300, 460–471.
Rovins, W., & Jensen, H. (2015). Risk assessment handbook. Method Massey
University.
SEDAFiT Rates. (2021). Retrieved November15 2021, From. [Link]
gov.my/iframe/
Sinacon S, Flyer PV. (2020). 01 2020. Retrieved May 05 2022, from. [Link]
assets.new.siemens.com/siemens/assets/api/uuid:cb65b0d3-6425-48f5-
92cb-cc217d2d5285/sinacon-pv-technical-data-en.pdf?ste_sid=c36e0
e6bfb43763c3c951eb34aa3f589
Solar. L (2022). Hi-MO5. 10 11 2021. Retrieved July 26 2022, From. [Link]
longi.com/L_Gi_LE_T_TMD_059_108_LR_5_72_HBD_530_550_M_35_
30_and_15_V14_4c79e9b9a7.pdf.
Voima, S., Kauhaniemi, K. (2012). Technical challenges of smart—and micro-
grids. Vaasa
Wang, Q., Mao, B., Stoliarov, S. I., & Sun, J. (2019). A review of lithium ion battery
failure mechanisms and fire prevention strategies”. Progress in Energy and
Combustion Science, 73, 95–131.
Willey, R. (2014). Layer of protection analysis. Procedia Engineering. [Link]
org/10.1016/j.proeng.2014.10.405
Wood, C. (2014). LC50 in encyclopedia of toxicology. Academic Press.
Yi, G., & Laajimi, M. (2021). Energy storage system for large-scale solar PV in
Malaysia: techno-economic analysis. Renewables Wind Water and Solar.
[Link]
Yoon-seung, K. (2020). Yonhap News Yonhap News Agency, 06 06 2020.
Retrieved July 15 2022, From. [Link]
6005900320
Zalosh, R., Gandhi, P., & Barowy, A. (2021). Lithium-ion energy storage battery
explosion incidents. Journal of Loss Prevention in the Process Industries, 72,
104560.
Zou, K., Li, Q., & Lu, S. (2022). an experimental study of thermal runaway and
fire behaviour of large-format LiNi08Co01Mn01O2 pouch power cell.
Journal of Energy Storage. [Link]
Publisher’s Note
Springer Nature remains neutral with regard to jurisdictional claims in pub-
lished maps and institutional affiliations.