← All reports
PDF Excel ReqIF

Emergency Diesel Generator for a UK Nuclear Licensed Site

Verification Plan (SVP) — ISO/IEC/IEEE 15289 — Plan | IEEE 29148 §6.6
Generated 2026-03-27 — UHT Journal / universalhex.org

109
Verification Entries
198
Verification Links
0
Orphans

Verification Requirements (VER)

RefRequirementMethodTags
VER-REQ-001 Verify IFC-REQ-001: Apply a simulated LOOP condition at the ALC input. Measure voltage at ECP relay input terminal within 10 ms window using calibrated oscilloscope. Pass criteria: signal present ≥19.2V (80% of 24VDC) within 10ms, signal path resistance ≤500Ω measured with 4-wire method, cable physically routed in dedicated conduit confirmed by inspection.
Rationale: Integration test verifying the hardwired start demand interface at the system boundary. Direct measurement of contact closure voltage and latency at ECP terminals is the only method that confirms actual cable routing, contact wetting, and latency under realistic conditions.
Test verification, starting-control, session-574, idempotency:ver-ifc001-574
VER-REQ-002 Verify IFC-REQ-002: Energise and de-energise start air solenoid valve 20 times. Measure opening time with pressure transducer downstream of valve. Remove control power and confirm valve closed position. Pass criteria: opening time ≤100ms in all cycles, fail-closed confirmed on power removal, cycle count ≥20 with no mechanical degradation observed.
Rationale: Test verifies solenoid valve opening latency and fail-safe behaviour at the air system boundary. Pressure transducer measurement directly confirms opening time in the pneumatic circuit rather than inferred from electrical signal alone.
Test verification, starting-control, session-574, idempotency:ver-ifc002-574
VER-REQ-003 Verify IFC-REQ-003: Apply step load change from 0 to 50% rated power to EDG at rated speed. Record speed transient and fuel rack position on data logger at 100 Hz. Measure gap between dual MPU sensor positions on flywheel housing. Pass criteria: speed recovery to ±1% rated within 3 seconds, fuel rack slew rate ≥100%/s confirmed from data log, MPU sensor separation ≥90mm confirmed by direct measurement.
Rationale: Governor-engine interface verification requires an actual load step test to confirm combined governor and actuator dynamic response. Static bench testing of the fuel actuator alone does not verify end-to-end latency including mechanical linkage and engine response.
Test verification, starting-control, session-574, idempotency:ver-ifc003-574
VER-REQ-004 Verify SYS-REQ-001 and SYS-REQ-003 end-to-end: Simulate LOOP condition by dropping Class 1E bus voltage to 0V. Record time from voltage drop to EDG breaker close command (GCB close) and to voltage/frequency within tolerance on safety bus. Pass criteria: GCB close command issued within 10 seconds, safety bus voltage 390–441V (415V ±6%) and frequency 49.5–50.5 Hz (50 Hz ±1%) within 12 seconds, no Class 1E protection trips during load pickup.
Rationale: End-to-end system integration test exercising the complete start chain from LOOP detection through EDG run-up to Class 1E load pickup. This is the primary system-level acceptance test for the emergency power function and cannot be decomposed into subsystem tests because timing dependencies span component boundaries.
Test verification, system, sil-3, session-574, idempotency:ver-e2e-start-574
VER-REQ-005 Verify SUB-REQ-009: Inject a simulated 87G differential fault condition into the Generator Protection Relay secondary test terminals at 3 rated current differential, and measure time from fault injection to trip signal output using a 1ms resolution timer. Test at no-load, 50% rated, and 110% rated conditions. Pass: trip signal issued within 80ms in all three test conditions.
Rationale: Secondary injection testing is the accepted method for numerical relay protection function verification per IEC 60255 (Measuring relays and protection equipment). Testing at three load points confirms load-independence of the trip time.
Test verification, electrical-protection-and-switchgear, sil-3, session-575, idempotency:ver-sub-req-009-575
VER-REQ-006 Verify SUB-REQ-013: With MGCB in the closed position, issue a close command to the SBTC and measure time from command to mechanical interlock engagement using a proximity sensor. Repeat with SBTC closed and issue close command to MGCB. Pass: interlock prevents closure in both cases within 10ms; no voltage appears on the opposing device close coil circuit.
Rationale: Direct physical test of the hardwired interlock is required to confirm the mechanical and electrical interlock functions independently of any software logic, as mandated by the SIL 3 classification for this protection function.
Test verification, electrical-protection-and-switchgear, sil-3, session-575, idempotency:ver-sub-req-013-575
VER-REQ-007 Verify IFC-REQ-004: De-energise the 110V DC trip circuit supply and measure time from de-energisation to MGCB open position using a 1ms timer. Introduce a deliberate open-circuit fault in the trip wiring and verify the trip circuit monitoring alarm is raised on the Engine Control Panel within 60 seconds. Pass: MGCB opens within 10ms of de-energisation; alarm raised within 60 seconds of open-circuit insertion.
Rationale: Tests both the fail-safe trip function and the continuous monitoring capability of the trip circuit. 60-second monitoring detection time is consistent with periodic self-test interval requirements for SIL 3 systems under IEC 61508 proof test interval calculations.
Test verification, electrical-protection-and-switchgear, sil-3, session-575, idempotency:ver-ifc-req-004-575
VER-REQ-008 Verify IFC-REQ-006 and SUB-REQ-012 combined: Simulate a LOOP event at the ALC input and measure total time from ALC bus transfer command output to contactor closed position confirmation signal received at ALC. Repeat 10 times. Pass: position feedback received within 150ms in all 10 attempts; volt-free contact continuity confirmed on ECP mimic.
Rationale: Combined test exercises both the ALC-SBTC interface (IFC-REQ-006) and the transfer completion timing requirement (SUB-REQ-012). Ten repeat tests provide statistical confidence in the timing margin without requiring full endurance testing at this stage.
Test verification, electrical-protection-and-switchgear, sil-3, session-575, idempotency:ver-ifc-req-006-combined-575
VER-REQ-009 Verify IFC-REQ-005: Connect a calibrated current source to the VSMU 4-20mA output loop and apply 4mA (0V), 12mA (60% nominal), 16mA (100% nominal), and 20mA (120% nominal) signals. Measure GPR input voltage displayed against injected current at each point. Introduce an open circuit and confirm GPR receives <4mA (fault detection). Pass: accuracy within ±2% at each calibration point; open-circuit detected within 20ms.
Rationale: Calibration injection test verifies the 4-20mA interface accuracy and the living-zero fault detection capability of IFC-REQ-005. The 20ms detection time is verified against the VSMU-GPR signal latency budget.
Test verification, electrical-protection-and-switchgear, sil-2, session-575, idempotency:ver-ifc-req-005-575
VER-REQ-010 Verify IFC-REQ-008: Connect calibrated fuel pressure and temperature measurement at injection pump inlet during engine run-up from idle to full rated load. Record supply pressure and temperature at 25%, 50%, 75%, and 100% load. Pass criteria: pressure remains 3–6 bar and temperature remains below 40°C at all load points. Verify return line back-pressure below 0.5 bar using inline pressure gauge.
Rationale: Fuel supply interface parameters must be verified under real operating load conditions, not bench test, because Fuel Oil System pump output varies with demand and engine-room temperature affects fuel temperature. Test at four load points covers the full EDG operating range.
Test verification, diesel-engine-subsystem, session-578, idempotency:ver-ifc-008-578
VER-REQ-011 Verify IFC-REQ-009: Commission a lateral critical speed analysis (torsional vibration analysis) of the engine-alternator coupled shaft system using manufacturer rotor data and coupling stiffness. Pass criteria: lowest lateral critical speed is greater than 1800 RPM (20% above 1500 RPM). Also inspect coupling flange bolt torque after 100-hour endurance run and confirm no fretting or micro-movement.
Rationale: Critical speed analysis is required by design before assembly because it cannot be safely tested by overspeed (doing so risks destructive resonance). The post-run inspection confirms that the coupling torque margin is adequate for transient load conditions experienced during acceptance test.
Analysis verification, diesel-engine-subsystem, session-578, idempotency:ver-ifc-009-578
VER-REQ-012 Verify IFC-REQ-010: Instrument jacket water inlet temperature and charge air outlet temperature during full-rated-load endurance run at ambient temperature design maximum. Record temperatures at steady-state 25%, 50%, 75%, and 100% rated load, and during a step load acceptance from 0 to 100% rated. Pass criteria: jacket water inlet 70–85°C and charge air outlet below 45°C at all steady-state load points and within 60 seconds of step load application.
Rationale: Cooling interface verification requires sustained load conditions because coolant temperatures take several minutes to stabilise; spot checks or bench tests do not capture steady-state thermal equilibrium. Step load test confirms the intercooler transient response is sufficient to prevent charge air temperature exceedance during sudden load acceptance.
Test verification, diesel-engine-subsystem, session-578, idempotency:ver-ifc-010-578
VER-REQ-013 Verify SUB-REQ-019: With engine running at rated speed, progressively restrict oil supply to reduce oil pressure. Measure elapsed time from 2.0 bar threshold crossing to shutdown signal on ECP. Pass criteria: shutdown signal asserted within 1.5 seconds of threshold crossing on three consecutive tests. Also verify trip independence: with governor control channel disabled, confirm trip still operates.
Rationale: SIL-2 safety function requiring measured response time under controlled conditions. The three-test repeatability requirement provides statistical confidence without excessive engine risk. Governor channel independence test confirms the SIL-2 diversity requirement between control and safety trip paths is maintained.
Test verification, diesel-engine-subsystem, sil-2, session-578, idempotency:ver-sub-019-578
VER-REQ-014 Verify SUB-REQ-020: With the engine at no-load, manually actuate the mechanical overspeed trip device and confirm fuel rack physically disengages to zero-fuel position within 0.5 seconds of actuation. Confirm actuation is not affected by governor control power removal. Pass criteria: fuel rack at zero-fuel position confirmed by physical inspection within 0.5 seconds and engine speed drops to zero within 30 seconds.
Rationale: Mechanical overspeed trip must be verified by direct actuation rather than overspeed run to avoid damaging the engine or alternator. The fuel rack physical position check confirms the mechanical linkage is functional, independent of any electronic indication that might mask a failure. Governor power removal test confirms independence from electronic systems.
Test verification, diesel-engine-subsystem, sil-2, session-578, idempotency:ver-sub-020-578
VER-REQ-015 Verify end-to-end Diesel Engine Subsystem integration: Start EDG from cold standby condition (coolant at preheat temperature, fuel system primed). Record time from start signal to rated shaft speed (1500 RPM ±15 RPM). Apply 100% rated load in single step. Record time to re-stabilise to rated speed within ±0.5%. Pass criteria: rated speed reached in 8 seconds or less; frequency re-stabilised within 3 seconds of 100% load step.
Rationale: End-to-end integration test exercises all five diesel engine components simultaneously and provides system-level evidence that the combined subsystem meets SYS-REQ-001 and SYS-REQ-003. The 8-second target for the diesel provides 2-second margin for the ALC and switchgear actions within the 10-second system start requirement.
Test verification, diesel-engine-subsystem, sil-2, session-578, idempotency:ver-diesel-engine-integration-578
VER-REQ-016 Verify SUB-REQ-001: With EDG in standby and offsite power connected, simulate a Class 1E bus voltage loss by tripping the upstream transformer protection relay. Record time from voltage collapse to ALC start demand signal assertion. Pass criterion: start demand asserted within 200ms in each of 10 consecutive trials, with no spurious start demands over a 24-hour standby observation period.
Rationale: SUB-REQ-001 is a SIL-3 requirement for the critical LOOP detection function. The 200ms timing criterion is the ALC sub-budget from SYS-REQ-003. Ten consecutive trials provide statistical confidence in consistent detection performance. The 24-hour standby observation tests for spurious start demand generation, which could cause unplanned EDG starts and nuclear safety bus disturbance.
Test verification, starting-control, sil-3, session-587, idempotency:ver-sub-req-001-587
VER-REQ-017 Verify SUB-REQ-002: With compressed air receivers fully charged, perform 3 complete cranking cycles at maximum cranking duration (as specified by the engine manufacturer) in immediate succession without recharging. Confirm engine reaches cranking speed during each cycle and that receiver pressure remains above the minimum cranking pressure limit at the end of the third cycle. Pass criterion: 3 consecutive full-duration cranks completed with terminal receiver pressure above the minimum cranking threshold.
Rationale: SUB-REQ-002 is the compressed air energy storage requirement for the Starting and Control Subsystem. Three consecutive cranking attempts without recharging is the design basis for the nuclear class emergency start scenario, where AC power to recharge the air receivers may not be available. The pass criterion confirms the stored energy budget is sufficient for the worst-case start sequence.
Test verification, starting-control, sil-3, session-587, idempotency:ver-sub-req-002-587
VER-REQ-018 Verify SUB-REQ-003: With the EDG running at rated speed and connected to a resistive load bank, apply step load changes from 25% to 75% and 75% to 25% rated load. Log governor output and engine speed at 100ms sample rate for 30 seconds following each step change. Pass criterion: steady-state speed deviation does not exceed ±7.5 RPM from 1500 RPM after the transient recovery period; transient recovery to within ±1% within 3 seconds of the load step.
Rationale: SUB-REQ-003 specifies the steady-state governor accuracy that determines output frequency compliance for safety bus consumers. The ±0.5% (±7.5 RPM) limit maintains generator frequency within the ±2% system tolerance. Load step testing is the standard commissioning verification for isochronous governor performance per BS 5514 (Reciprocating internal combustion engines) and IEC 60034-3 generator specifications.
Test verification, starting-control, sil-3, performance, session-587, idempotency:ver-sub-req-003-587
VER-REQ-019 Verify SUB-REQ-015: Induce a simulated internal self-test failure in the Generator Protection Relay by interrupting the watchdog keep-alive signal. Measure time from watchdog timeout to MGCB trip coil energisation and relay-failed alarm assertion at ECP. Pass criterion: MGCB trip coil energised within 500ms of watchdog timeout; relay-failed alarm asserted within the same 500ms window; MGCB opens and generator output de-energises within the circuit breaker interrupting time.
Rationale: SUB-REQ-015 is a SIL-3 safe-state requirement. The Generator Protection Relay must fail to the safe state (generator disconnected) on internal failure, not to a stuck-at-normal state that could leave an unprotected generator connected to the safety bus. The 500ms timing criterion and MGCB trip verification demonstrate compliance with the IEC 61508 (Functional safety of E/E/PE safety-related systems) fail-safe requirement.
Test verification, electrical-protection-and-switchgear, sil-3, session-587, idempotency:ver-sub-req-015-587
VER-REQ-020 Verify SUB-REQ-016: With the EDG running at rated speed and no-load, interrupt the governor processor watchdog keep-alive path. Measure time from watchdog interrupt to governor fuel rack command reaching 0% (fuel-off). Monitor engine speed to confirm shutdown initiates. Pass criterion: fuel rack command reaches 0% within 100ms of watchdog interrupt; engine decelerates below 50% rated speed within 30 seconds confirming fuel cut-off is effective.
Rationale: SUB-REQ-016 is a SIL-3 fail-safe requirement for the overspeed protection path. The governor watchdog is the last line of electronic defence against uncontrolled engine acceleration in the event of governor processor failure. The 100ms watchdog timeout is derived from the overspeed detection time budget in the engine safety case. Testing must confirm both the timing criterion and the effectiveness of fuel cut-off in achieving engine shutdown.
Test verification, starting-control, sil-3, session-587, idempotency:ver-sub-req-016-587
VER-REQ-021 Verify IFC-REQ-007: With normal 415V AC supply removed, confirm the 24VDC Class 1E distribution panel switches to battery supply. Measure terminal voltage at the ALC hardwired interface terminals at 15-minute intervals for 2 hours. Apply the rated interface load (start demand, bus transfer command, and all status return circuits simultaneously) throughout. Pass criterion: terminal voltage remains within 22V to 28VDC for the full 2-hour duration under rated interface load.
Rationale: IFC-REQ-007 defines the Class 1E power supply interface that maintains ALC hardwired functions during loss of offsite power. The 2-hour battery endurance is the design-basis mission duration for post-accident EDG operation. Supply voltage limits of 22–28VDC ensure correct logic threshold levels for all hardwired circuits. This is an integration test verifying the interface between the 24VDC panel and the ALC under design-basis conditions.
Test verification, starting-control, sil-3, session-587, idempotency:ver-ifc-req-007-587
VER-REQ-022 Verify SUB-REQ-031: With the EDG running at rated speed and a calibrated signal injector on each sensor channel, step the injected oil pressure signal below 2.5 bar and record the time from threshold crossing to relay contact opening at the Engine Control Panel input. Pass criterion: trip output achieved within 200ms on 10 successive trials; no false trip occurs on the healthy channel when one channel is held above threshold.
Rationale: Direct measurement of trip time under controlled conditions with calibrated injection is the only method providing traceability to the 200ms requirement. Testing 10 successive cycles provides statistical confidence at SIL 2 PFD level. Single-channel tolerance test verifies the 1oo2D voting architecture.
Test verification, monitoring-and-instrumentation, sil-2, session-588, idempotency:ver-sub031-ptlu-trip-588
VER-REQ-023 Verify SUB-REQ-032: With the EDG running and M&I system energised, reduce the 110VDC supply to the Protective Trip Logic Unit to 85VDC using a variable DC source and record the time from 88VDC threshold to de-energisation of all trip relay contacts. Pass criterion: all trip contacts de-energise within 100ms; engine shutdown initiates; no contacts remain energised when supply is at 0VDC.
Rationale: Power-loss safe-state test must be performed with a controlled voltage ramp to verify the exact threshold and response time. Testing to 0VDC verifies complete de-energisation and prevents latent partial energisation failures.
Test verification, monitoring-and-instrumentation, sil-2, session-588, idempotency:ver-sub032-safe-state-588
VER-REQ-024 Verify IFC-REQ-011: With the M&I system energised from 24VDC supply, apply open-circuit and short-to-supply faults to each sensor loop in turn and verify: (a) fault annunciation on Local Alarm and Indication Panel within 500ms; (b) trip function on the unfaulted channel remains operative; (c) fault condition clears upon loop restoration. Pass criterion: all 10 fault conditions detected and annunciated within 500ms with no spurious trip on healthy channel.
Rationale: Fault injection tests must be performed per channel to verify the 1oo2D diagnostic coverage claim. Testing all 10 sensor channels (5 parameters x 2 channels) is required for SIL 2 independent channel validation.
Test verification, monitoring-and-instrumentation, sil-2, session-588, idempotency:ver-ifc011-epsa-ptlu-588
VER-REQ-025 Verify IFC-REQ-012: With the EDG stopped, energise each PTLU trip relay in turn and measure contact resistance (pass: below 0.1 ohm). With contacts energised and a 24VDC 2A load applied, de-energise each relay and verify the ECP shutdown input circuit receives the de-energise signal within 50ms. Pass criterion: all contacts operate within specification; no logic device is in series between PTLU contacts and ECP input terminals (verified by circuit topology inspection).
Rationale: Hardwired interface verification requires both electrical measurement and topology inspection to prove no software path exists between PTLU and ECP. Contact resistance measurement confirms integrity. Topology inspection is a mandatory Inspection verification step for safety-classified hardwired circuits per BS IEC 61511-1.
Test verification, monitoring-and-instrumentation, sil-2, session-588, idempotency:ver-ifc012-ptlu-ecp-588
VER-REQ-026 Verify CS cooling capacity (SUB-REQ-038): Run EDG at 100% rated load for 4 hours at 38 deg C ambient. Record coolant outlet temperature at 30-minute intervals. Pass criterion: coolant outlet temperature stabilises below 92 deg C and does not trend upward after 2 hours; radiator fan runs continuously without thermal overload trip.
Rationale: 4-hour run is sufficient to achieve thermal equilibrium (typically within 45 minutes). 38 deg C represents a conservative sub-maximum ambient test condition achievable in the UK climate during summer surveillance testing. Stability criterion distinguishes genuine steady-state from transient cooldown.
Test verification, cooling-system, session-588, idempotency:ver-cs-capacity-588
VER-REQ-027 Verify SUB-REQ-040: Fill the Day Tank to High (H) level, stop the Fuel Transfer Pump Set, run the EDG at 100% rated load, and measure elapsed time to Low-Low (LL) level activation. Pass criterion: LL activation no sooner than 8 hours from test start. Verify tank volume markings on level gauge correspond to calculated 8-hour consumption volume at rated specific fuel consumption. Record test as witnessed test in EDG commissioning certificate.
Rationale: Direct measurement of tank endurance at full load is the only reliable acceptance criterion — analysis of tank volume and fuel consumption alone does not capture real-world effects of temperature variation, pump cycling, and fill-pipe backflow.
Test verification, fuel-oil-system, sil-2, session-590, idempotency:ver-sub040-day-tank-590
VER-REQ-028 Verify SUB-REQ-042: With EDG running and Fuel Transfer Pump Set in automatic, drain the Day Tank to below Low (L) set-point via test drain valve. Measure time from L contact actuation to duty pump motor start signal confirmation. Pass criterion: duty pump starts within 10 seconds. Manually trip duty pump and confirm standby pump starts within 10 seconds. Measure time to fill Day Tank from L to H level at rated EDG fuel consumption drain rate. Pass criterion: L to H fill completed within 30 minutes.
Rationale: Auto-start timing and fill rate are safety-functional behaviours that cannot be verified by inspection or analysis alone; full end-to-end test with the EDG running is required to account for actual pipeline losses and pump performance at operating temperature.
Test verification, fuel-oil-system, sil-2, session-590, idempotency:ver-sub042-pump-autostart-590
VER-REQ-029 Verify IFC-REQ-015: With EDG running at 100% rated load, install calibrated pressure gauges at the fuel inlet to the Fuel Injection System. Record pressure and flow rate over a 30-minute run. Pass criterion: pressure remains 0.3-0.7 bar gauge throughout; flow rate equals or exceeds 110% of rated specific fuel consumption. Repeat with the filter element loaded to 0.3 bar DP (simulated blockage condition) and confirm pressure stays above 0.3 bar.
Rationale: Interface compliance must be verified under load and at worst-case filter condition (0.3 bar DP blockage alarm). Gravity-head pressure depends on tank level, which varies during operation — measurement at both H and L tank levels confirms the full operating range is maintained within specification.
Test verification, fuel-oil-system, sil-2, session-590, idempotency:ver-ifc015-day-tank-pressure-590
VER-REQ-030 Verify IFC-REQ-017: With the Day Tank and Bulk Tank level instruments energised from 24VDC, verify each level switch (Day Tank LL, L, H, HH and Bulk Tank L, LL) presents a normally-energised volt-free contact in the normal state. Disconnect instrument supply to one level switch and confirm the LAIP shows the critical alarm state (not de-energised/healthy). Pass criterion: LAIP displays low-level alarm within 5 seconds of supply loss to any field instrument.
Rationale: 100ms first-out display latency is required because nuclear EDG protective trip chains can produce cascading secondary trips within 200–500ms of the initiating event (e.g., low oil pressure initiates followed by overspeed as the engine governor reacts): if the LAIP (Local Alarm and Indication Panel) display latency exceeds the inter-trip interval, the displayed first-out may incorrectly show a secondary trip as the initiating cause. IEC 62138 (Software for computers important to safety for nuclear power stations) and NUREG/CR-6572 guidance for nuclear annunciation systems establish ≤100ms as the required maximum response time for first-out discrimination. ONR inspection requirements for nuclear EDGs specify that first-out identification must be unambiguous for both surveillance testing post-trips and licensing event reports. The 500ms value in the superseded SUB-REQ-035 was insufficient to meet this discrimination requirement. Supersedes SUB-REQ-035.
Test verification, fuel-oil-system, sil-2, session-590, idempotency:ver-ifc017-level-laip-590, tech-author-session-613
VER-REQ-031 Verify SUB-REQ-046: With EDG running at rated speed and connected to a programmable load bank, apply a steady-state resistive load of 100% rated kVA and measure terminal voltage for 10 minutes. Pass criterion: voltage deviation from set-point less than ±0.5%. Then apply a 40% kVA step load increase and measure peak transient deviation and recovery time. Pass criterion: peak deviation within ±6% of rated, recovery to within ±2% within 3 seconds.
Rationale: Steady-state test at full load provides direct evidence of regulation under the worst-case sustained condition. Step-load test reproduces the block-load application scenario from SYS-REQ-007. Both tests must be performed at rated power factor (0.8 lagging) to exercise the AVR's reactive power control loop.
Test verification, alternator-subsystem, sil-2, session-590, idempotency:ver-sub046-avr-regulation-590
VER-REQ-032 Verify SUB-REQ-049: Start the EDG from cold standby with no pre-existing excitation supply (confirm PMG output is the only excitation source). At 95% rated engine speed, measure elapsed time to terminal voltage reaching within ±6% of rated. Record voltage trace during build-up and measure peak overshoot above rated voltage. Pass criterion: voltage within ±6% within 3 seconds of 95% speed threshold; overshoot less than 10% of rated voltage at any point during transient. Repeat 3 times to confirm repeatability.
Rationale: Black-start voltage build-up must be demonstrated under real conditions because PMG magnetic saturation and AVR initial state affect the transient behaviour in ways that cannot be fully predicted by analysis alone. Three repeats are required to confirm reliability consistent with the safety-functional PFD requirement.
Test verification, alternator-subsystem, sil-2, session-590, idempotency:ver-sub049-excitation-build-590
VER-REQ-033 Verify IFC-REQ-018: With EDG running at rated speed, apply known reference voltages from a calibrated voltage source to the VSMU input terminals at 0%, 25%, 50%, 75%, 100%, and 120% of rated terminal voltage. Measure the 4-20mA output at the AVR input connector. Pass criterion: measured current values within ±0.3% of the linear interpolated expected value at each reference point. Verify isolation by applying 500V DC between the 4-20mA signal circuit and earth and confirming insulation resistance exceeds 10 MΩ.
Rationale: Six-point calibration check confirms linearity across the full operating range including the 120% overvoltage point that the AVR OEL must respond to. 500V isolation test demonstrates compliance with IEC 61010-1 requirements and confirms the cable screening is correctly earthed at one end only (a wiring error that would cause ground loop noise cannot be detected at DC but the isolation test would reveal un-screened conductors).
Test verification, alternator-subsystem, sil-2, session-590, idempotency:ver-ifc018-vsmu-avr-590
VER-REQ-034 Verify IFC-REQ-020: With the EDG stopped, connect a calibrated resistance decade box in place of each PT100 RTD in turn and verify PTLU displays the correct temperature to within ±2°C at decade box settings corresponding to 20°C, 130°C, and 155°C. With the EDG running, open-circuit and short-circuit each PT100 in turn via test disconnect terminals and confirm: PTLU detects the instrument fault within 5 seconds and presents an alarm (not a trip) without de-energising the EDG. Pass criterion: instrument fault alarm generated within 5 seconds; EDG continues to run.
Rationale: Resistance substitution test is the standard acceptance test for PT100 instrumentation channels (IEC 60751). The fault injection test is critical for confirming the fail-to-alarm (not spurious trip) design principle: an instrument cable fault during an active LOOP mission must not cause an unnecessary EDG trip. This test must be performed with the EDG running under load because some PTLU inputs behave differently when the trip logic chain is energised vs de-energised.
Test verification, alternator-subsystem, sil-2, session-590, idempotency:ver-ifc020-stator-rtd-ptlu-590
VER-REQ-035 Verify SUB-REQ-051: With the EDG running at 50% load, disconnect the primary speed sensor channel. Confirm: (a) governed speed deviation does not exceed ±3% of rated 1500 RPM (i.e., stays within 1455–1545 RPM) during and after the transition, measured by the secondary channel and confirmed against the PTLU engine speed reading; (b) channel failure alarm annunciated on Local Alarm Panel within 2 seconds; (c) no engine trip occurs. Restore primary channel and confirm normal dual-channel operation resumes.
Rationale: Fault injection test with the EDG running under load is required because governor channel behaviour under load differs from bench test. ±3% speed deviation tolerance corresponds to the ±1% frequency tolerance in SYS-REQ-001 plus a transient margin; testing at 50% load represents a worst-case governor response scenario due to the load-to-speed gain characteristic.
Test verification, starting-and-control, sil-3, session-592, idempotency:ver-sub051-governor-redundancy-592
VER-REQ-036 Verify SUB-REQ-053: With the EDG running at 100% load and the duty fuel transfer pump active, simulate pump failure by closing the duty pump discharge isolation valve. Confirm: (a) standby pump starts within 30 seconds; (b) Day Tank level continues to rise (pump discharge pressure ≥0.8 bar on standby pump); (c) no interruption to engine fuel supply (engine continues to run). Restore duty pump and confirm automatic reversion or manual selection as per design intent.
Rationale: Pump switchover test under full load is required because Day Tank level dynamics at rated fuel consumption are the most demanding test condition for the 30-second changeover criterion. Testing at 100% load confirms the standby pump delivery rate is sufficient when engine fuel consumption is highest.
Test verification, fuel-oil-system, sil-2, session-592, idempotency:ver-sub053-fuel-pump-redundancy-592
VER-REQ-037 Verify SUB-REQ-055: Inspect IEC 60255-151 and IEC 60255-181 type-test certificates from an accredited test laboratory for the Generator Protection Relay prior to installation. Certificates must reference the specific relay type and firmware version to be installed. Pass criterion: certificates present, cover all required functions (over/under voltage, frequency), issued by UKAS-accredited body, dated within 5 years of installation date.
Rationale: Type-test certificate inspection is the appropriate verification method for standard compliance of safety-classified protection relays — in-situ re-testing to IEC 60255 is not practicable on an energised generator. The 5-year certificate validity window aligns with typical relay firmware revision cycles that would invalidate earlier certificates.
Inspection verification, electrical-protection-switchgear, sil-3, session-592, idempotency:ver-sub055-relay-standards-592
VER-REQ-038 Verify SUB-REQ-059: With the EDG disconnected from the safety bus (load bank connected), initiate test mode via key-switch on Engine Control Panel. Ramp EDG to 100% rated load on load bank. Confirm: (a) safety bus voltage remains within ±5% of nominal throughout the test; (b) test mode cannot be activated without the key-switch; (c) an attempt to initiate test mode with EDG connected to safety bus is rejected by the control logic. Duration: 2-hour full-load test. Pass criterion: safety bus unaffected, all control interlocks function correctly.
Rationale: Operational testing verification must demonstrate the safety bus isolation function (not just EDG load performance) because the critical safety claim is that the test does not interrupt normal plant safety functions. The 2-hour test duration exceeds the monthly operational test duration requirement to provide margin.
Demonstration verification, starting-and-control, sil-3, session-592, idempotency:ver-sub059-test-mode-592
VER-REQ-039 Verify SUB-REQ-004: With the EDG running at rated speed (1500 RPM), inject a simulated overspeed signal via the magnetic pick-up trip circuit input to exceed 1650 RPM threshold. Measure elapsed time from threshold crossing to ECP fuel rack trip command using a high-speed data logger (≥1 kHz). Pass criterion: shutdown initiated within 500 ms on ≥3 of 3 test runs. Verify trip circuit is independent of the governor by disabling the governor processor and repeating test.
Rationale: SUB-REQ-004 is the primary overspeed protection function derived from SYS-REQ-004. The 500 ms criterion must be verified by direct injection test, not analysis, because it depends on hardware relay response time and cannot be analytically bounded without physical characterisation. Independence of the trip circuit from the governor must be confirmed by deliberate governor isolation.
Test session-593, qc, verification, starting-control, idempotency:ver-sub-004-overspeed-trip-593
VER-REQ-040 Verify SUB-REQ-010: Commission secondary injection test on the Generator Protection Relay overcurrent element (51/51N). Apply test currents at 110%, 150%, and 200% rated current via primary injection test set and record measured operate times. Pass criterion: operate time at 200% rated current ≤200ms; coordinate with upstream breaker scheme per the site protection coordination study. Repeat test for neutral overcurrent element (51N) with asymmetric test current injection.
Rationale: SUB-REQ-010 specifies 500ms for terminal faults and 200ms for through-faults at 200% rated. These time-current characteristics must be verified by secondary injection because relay coordination cannot be confirmed analytically without site-specific relay settings. The test validates both the timing and coordination compliance with the downstream protection scheme.
Test session-593, qc, verification, electrical-protection, idempotency:ver-sub-010-gpr-overcurrent-593
VER-REQ-041 Verify SUB-REQ-024: With the EDG stopped and isolated from fuel, manually actuate the crankcase explosion relief valve and simultaneously measure propagation time from relief valve actuation sensor to ECP trip signal output. Pass criterion: trip signal generated within 2 seconds. Verify that the hardwired trip path is independent of engine management software by isolating the engine management ECU and repeating actuation test. Confirm trip signal is maintained for ≥5 seconds after actuation.
Rationale: SUB-REQ-024 is a safety shutdown function for an extreme engine failure mode (crankcase explosion). The 2-second timing and software independence are fundamental to the safe state — a delayed or software-dependent trip could escalate a crankcase event. Physical actuation test is the only valid verification method; analysis cannot confirm hardware path integrity.
Test session-593, qc, verification, diesel-engine, idempotency:ver-sub-024-crankcase-trip-593
VER-REQ-042 Verify SUB-REQ-033: With the EDG running at rated speed and the M&I system energised, simulate each sensor channel fault condition in turn — open circuit (disconnect 4-20mA loop), short to supply (force loop to >20mA), and out-of-range (force loop to <4mA or >21mA) — on each of the four critical parameter channels. Pass criterion: PTLU generates a channel-fault alarm to the Local Alarm and Indication Panel within 1 second of fault application on each test run. Verify the protection function on the healthy channel remains active throughout fault injection.
Rationale: SUB-REQ-033 requires fault detection within 1 second with no inhibition of the healthy channel — these are quantified safety properties that must be tested under realistic fault conditions. Each fault mode (OC, S-supply, OOR) produces different loop current profiles; all three must be confirmed. Analysis cannot substitute because the detection algorithm depends on PTLU firmware implementation.
Test session-593, qc, verification, monitoring-instrumentation, idempotency:ver-sub-033-ptlu-fault-detect-593
VER-REQ-043 Verify SUB-REQ-044: With the EDG stopped and fuel isolation valve in the open state, simulate a confirmed fire detection signal at the Fuel Supply Pipework and Valve Assembly fire detection input. Measure elapsed time from fire signal assertion to confirmed bulk isolation valve closure using a position transmitter on the valve stem. Pass criterion: valve fully closed within 10 seconds. Verify day tank gravity-feed path remains open throughout the test by confirming zero pressure drop on the day tank outlet line during the 10-second closure window.
Rationale: SUB-REQ-044 is a fire safety mitigation function with a 10-second timing criterion. Late valve closure allows fire to propagate via bulk fuel supply. The day tank gravity-feed continuity condition is equally critical — closing bulk supply without confirming day tank path means the engine cannot be brought to controlled shutdown. Both must be verified by physical actuation test.
Test session-593, qc, verification, fuel-oil, idempotency:ver-sub-044-fire-isolation-593
VER-REQ-044 Verify SUB-REQ-047: Using calibrated PT100 decade resistance boxes substituted for each stator winding PT100 RTD, simulate temperatures at 125°C, 130°C, 135°C, 155°C, and 160°C on each PT100 channel. Pass criteria: (a) PTLU generates alarm at ≤130°C threshold on each channel, (b) PTLU initiates protective trip at ≤155°C threshold on each channel, (c) PT100 signal accuracy within ±2°C of applied reference across 20–180°C by comparison with NAMAS-calibrated reference. Test each channel independently to verify no cross-channel interaction.
Rationale: SUB-REQ-047 specifies alarm at 130°C and trip at 155°C with ±2°C accuracy — all three are quantified thresholds that must be verified by PT100 simulation. Stator thermal protection prevents insulation failure from overtemperature; incorrect trip thresholds could allow winding damage or cause spurious trips. Calibration traceability to NAMAS is required for Class 1E instrument validation on nuclear sites.
Test session-593, qc, verification, alternator, idempotency:ver-sub-047-stator-thermal-593
VER-REQ-045 Verify SUB-REQ-058: With the Local Alarm and Indication Panel energised and all process instrument loops active, inject step-change signals at each alarm threshold for all monitored parameters. Pass criterion: alarm annunciation visible on the LAIP within 2 seconds of signal application on ≥10 consecutive injections per parameter. Verify EEMUA 191 compliance by inspection of the alarm management documentation, alarm priority schedule, and suppression control procedures. Verify alarm visibility during start-up and shutdown transients by running a complete start-stop cycle and confirming display continuity throughout.
Rationale: SUB-REQ-058 specifies a 2-second alarm presentation criterion that must be confirmed by timed injection test — operator response to process alarms depends on prompt display. EEMUA 191 compliance requires documentary evidence of priority classification and suppression design. Testing during transients is essential because start/stop transients generate many out-of-range signals that could inhibit real alarms if suppression is misconfigured.
Test session-593, qc, verification, monitoring-instrumentation, idempotency:ver-sub-058-alarm-timing-593
VER-REQ-046 Verify SUB-REQ-050: With the EDG at rated speed, simulate a GPR stator earth fault trip signal at the Alternator Subsystem input. Measure: (a) time from trip signal assertion to de-energisation of anti-condensation heaters (pass: ≤200ms), (b) time from trip signal to AVR voltage collapse (pass: ≤200ms). Using a clamp-on current sensor on the stator neutral connection, confirm zero stator current from both generator terminal side and excitation supply side within 200ms. Repeat ×3 and confirm consistent timing.
Rationale: SUB-REQ-050 specifies 200ms isolation of both voltage sources from the stator winding after a GPR earth fault trip. This dual-path isolation timing is a measurable safety criterion that prevents continued fault current flow that could degrade stator insulation. Both heater and AVR de-energisation must be confirmed independently — failure of either leaves a voltage source on a faulted winding.
Test session-593, qc, verification, alternator, idempotency:ver-sub-050-earth-fault-isolation-593
VER-REQ-047 Verify SUB-REQ-005: With the EDG in standby and the starting system functional, command 3 consecutive failed start attempts (simulate cranking timeout by inhibiting the speed feedback signal). Measure: (a) time from 3rd failed attempt to failed-to-start alarm assertion at the MCR (pass: ≤45 seconds from original start demand), (b) confirm automatic start is inhibited (apply a 4th start demand — EDG SHALL NOT start), (c) confirm latch releases only upon key-operated reset. Repeat ×3 and confirm consistent behaviour.
Rationale: Simulating 3 consecutive cranking failures exercises the same logic path as genuine start failures. Inhibiting speed feedback isolates the test to starting-circuit logic without requiring manual engine immobilisation. MCR: Main Control Room. 45-second alarm latency is realistic given 3×15s cranking cycles plus logic sequencing time — derived from SUB-REQ-005. The latch function prevents automatic start cycling during a sustained fault (e.g., frozen fuel at –20°C, fuel pickup line blockage) that would cycle-damage the battery and starter. ×3 repetitions are required to validate that the interlock state is consistent and not affected by prior test history or transient state.
Test session-595, qc, verification, starting-control, idempotency:ver-sub-005-fts-latch-595, tech-author-session-613
VER-REQ-048 Verify SUB-REQ-006: Review the ALC hardware design documentation and software V&V report to confirm dual-channel 2oo2 voting architecture. Verify that: (a) channel independence is achieved by physically separate processing paths with no shared hardware between channels except the hardwired voting logic, (b) a single-channel hardware failure (simulated by removing power to one channel) does not produce a spurious start demand, (c) with one channel in a confirmed fail state, the ALC continues to process start demands through the healthy channel without generating a false start. Review IEC 61513 compliance assessment for the voting logic.
Rationale: Verification of SUB-REQ-006 dual-channel 2oo2 architecture is achieved by inspecting the ALC hardware design documentation and software V&V report against IEC 61513 compliance checklist, and by simulating single-channel hardware failure to confirm no spurious start demand. The primary evidence is document review (Inspection); the channel isolation test provides corroborating evidence. Inspection is the appropriate IEC 61508 verification method for software-intensive voting architectures where the compliance argument is embodied in the design documentation.
Inspection session-595, qc, verification, alc, sil-3, idempotency:ver-sub-006-alc-2oo2-595, idempotency:ver-sub-006-alc-2oo2-595
VER-REQ-049 Verify SUB-REQ-007: With the EDG in standby, activate the key-operated inhibit switch at the local control panel. Confirm: (a) local indication illuminates within 2 seconds, (b) remote indication at MCR activates within 2 seconds, (c) apply a simulated LOOP signal — EDG SHALL NOT start automatically, (d) the inhibit state persists after simulated power cycling of the ALC, (e) rotating the key switch to normal and applying the LOOP signal causes the EDG to start normally. Inspect the wiring schematic to confirm the inhibit is implemented in hardwired logic, not software.
Rationale: SUB-REQ-007 requires a hardwired key-switch inhibit to prevent unintended automatic starts during maintenance. The functional test confirms inhibit effectiveness and latch behaviour. The wiring inspection confirms the inhibit cannot be bypassed by a software failure, which is an IEC 61513 Class 1E requirement for maintenance override functions.
Test session-595, qc, verification, alc, idempotency:ver-sub-007-alc-inhibit-595, idempotency:ver-sub-007-alc-inhibit-595
VER-REQ-050 Verify SUB-REQ-008: With the EDG running in isochronous mode at rated load, operate the manual speed trim control at the local control panel. Confirm: (a) frequency is adjustable between 49 Hz and 51 Hz in 0.1 Hz increments (confirm step size with a calibrated frequency meter), (b) trim requires no power interruption or software modification, (c) issue a synchronise command and confirm frequency returns to 50.0 Hz ±0.1 Hz automatically within 5 seconds. Repeat frequency step verification at ×3 separate load levels (25%, 50%, 100% rated).
Rationale: SUB-REQ-008 requires operator-accessible frequency trimming without software modification for manual synchronisation. The demonstration at multiple load levels confirms the trim function is effective across the operating range and that the auto-revert on synchronise command prevents operator error leaving the EDG at an incorrect frequency when connecting to the safety bus.
Demonstration session-595, qc, verification, governor, idempotency:ver-sub-008-gov-trim-595, idempotency:ver-sub-008-gov-trim-595
VER-REQ-051 Verify SUB-REQ-011: Review the MGCB type test certificates to confirm short-circuit breaking capacity of ≥31.5 kA symmetrical (11kV) or ≥50 kA symmetrical (415V) as applicable to the site installation. Confirm breaker clearing time ≤20ms from trip coil energisation by manufacturer's type test data. Review BS EN 62271-100 (High-voltage switchgear and controlgear: alternating current circuit-breakers) type approval certificate for the equipment class installed. For site-specific installation, witness an operational trip test from the Generator Protection Relay trip output to confirm trip coil continuity and MCB trip mechanism actuation.
Rationale: SUB-REQ-011 sets the fault-clearing duty for the MGCB based on site short-circuit level. Type test certificates provide the primary verification of breaking capacity since site fault level testing at full prospective current is not practicable. The operational trip test confirms installed wiring integrity without requiring full current injection.
Test session-595, qc, verification, mgcb, electrical-protection, idempotency:ver-sub-011-mgcb-595, idempotency:ver-sub-011-mgcb-595
VER-REQ-052 Verify SUB-REQ-012: With the EDG running at rated voltage and frequency, and the safety bus connected to the normal offsite supply, command the ALC to issue a bus transfer command. Measure: (a) time from transfer command signal (at ALC output terminal) to contactor position feedback (closed) at Engine Control Panel (pass: ≤150 ms), using a millisecond timer triggered on ALC output energisation and stopped on ECP feedback receipt. Repeat ×5 consecutive transfers and confirm all within 150 ms. Record mean and maximum transfer times.
Rationale: SUB-REQ-012 sets the 150 ms safety bus transfer time to ensure safety system power is restored within the allowable interruption time for Class 1E equipment. The timed test directly measures the parameter. Repeating ×5 times provides statistical confidence that the timing is consistently met and not an isolated result.
Test session-595, qc, verification, electrical-protection, bus-transfer, idempotency:ver-sub-012-bus-transfer-595, idempotency:ver-sub-012-bus-transfer-595
VER-REQ-053 Verify SUB-REQ-014: With the EDG running, inject a test voltage into one channel of the Voltage Sensing and Monitoring Unit such that channel 1 reads 5.1% above the nominal voltage while channel 2 reads nominal. Measure: (a) time from discrepancy injection to alarm at ECP (pass: ≤2 seconds), (b) confirm alarm indicates dual-channel discrepancy (not a trip). Repeat with channel 2 offset and channel 1 nominal. Confirm both channels process independently by reviewing the VSMU design documentation for separate signal conditioning paths.
Rationale: SUB-REQ-014 requires dual-channel voltage monitoring with a 2-second discrepancy alarm to detect instrument failures before they propagate to incorrect relay trip decisions. The 5.1% injection (just over the 5% threshold) and timing test directly measures the alarm latency criterion. The documentation review confirms independent processing — a shared component failure could defeat the redundancy.
Test session-595, qc, verification, electrical-protection, vsmu, idempotency:ver-sub-014-vsmu-595, idempotency:ver-sub-014-vsmu-595
VER-REQ-054 Verify IFC-REQ-013: With the EDG running, confirm optically isolated contact signal transmission from the Protective Trip Logic Unit to the Remote Monitoring Gateway. Test each status signal (running, trip, alarm, channel fault, test mode) by: (a) injecting the relevant PTLU output state and measuring the signal at the RMG input within 2 seconds, (b) measuring isolation between PTLU and RMG signal commons using a 500V insulation resistance meter (pass: ≥1 MΩ). For analogue retransmission: inject calibrated reference values at the EPSA outputs, confirm 4-20mA signal at RMG input for engine speed, coolant temperature, and lube oil pressure matches within ±2% of full scale, with maximum latency 2 seconds.
Rationale: IFC-REQ-013 defines the signal protocol and latency for the PTLU-to-RMG interface. Testing with injected values and a timing measurement directly verifies both signal type (optically isolated contacts, 4-20mA) and the 2-second latency criterion. The isolation test confirms the 24VDC isolation required to prevent RMG-side faults from propagating to Class 1E PTLU circuits.
Test session-595, qc, verification, monitoring, ptlu, idempotency:ver-ifc-013-ptlu-rmg-595, idempotency:ver-ifc-013-ptlu-rmg-595
VER-REQ-055 Verify IFC-REQ-014: Inspect the Jacket Water Pump to Radiator and Fan Assembly pipework installation. Confirm: (a) pipe bore is 50mm nominal using measured internal diameter check, (b) maximum rated operating pressure is ≥1.8 bar gauge per nameplate and pressure test certificate, (c) pipe and fittings are rated for 100°C continuous per material specifications and weld inspection records, (d) isolation valves are installed on both inlet and outlet and can be closed and re-opened without coolant loss from the engine. Witness one isolation valve operation to confirm leak-free isolation. Review weld inspection certificates confirming rated temperature capability.
Rationale: IFC-REQ-014 defines the mechanical interface between the jacket water pump and radiator, including bore size, pressure and temperature rating, and isolation valve provision for maintainability. Inspection of the installed pipework and pressure test certificate provides the primary verification — the dimensional and material requirements cannot be verified by functional test alone without risk of damage to the cooling circuit.
Inspection session-595, qc, verification, cooling, ifc, idempotency:ver-ifc-014-jwp-rad-595, idempotency:ver-ifc-014-jwp-rad-595
VER-REQ-056 Verify IFC-REQ-016: With the EDG running at 100% rated load (measuring fuel consumption at the engine fuel meter), confirm the Fuel Transfer Pump Set delivers ≥150% of measured fuel consumption into the Day Tank. Measure flow rate at the transfer pump discharge using a calibrated ultrasonic or turbine flow meter over a 15-minute run. Confirm fill line terminates below Day Tank High (H) level mark. Measure Day Tank pressure during pump operation to confirm delivery pressure does not exceed the overflow return setting. Record actual engine fuel consumption rate and transfer pump delivery rate.
Rationale: IFC-REQ-016 sets a minimum 150% delivery margin to ensure the Day Tank cannot be depleted during continuous full-load operation. The flow meter test at full load directly measures compliance with the 150% margin. Confirmation that fill line terminates below High level prevents air entrainment in the fuel injection system, which could cause fuel quality degradation.
Test session-595, qc, verification, fuel-oil, ifc, idempotency:ver-ifc-016-ftp-daytank-595, idempotency:ver-ifc-016-ftp-daytank-595
VER-REQ-057 Verify IFC-REQ-019: Review the torsional vibration analysis report for the diesel-generator coupled shaft system. Confirm: (a) calculated torsional natural frequencies are outside the critical ranges 0–100 RPM and 2800–3200 RPM, (b) the coupling is rated for the full rated torque plus 100% transient overload factor, (c) the analysis methodology complies with ISO 14694 (Industrial fans: requirements for balance quality and vibration levels) acceptance criteria, (d) coupling type is rigid disc-pack torsional. Review coupling manufacturer's type test data confirming rated torque capacity. Confirm no resonant peaks within ±10% of governed speed (1350–1650 RPM).
Rationale: IFC-REQ-019 sets the torsional coupling requirements between engine and alternator. Analysis is the only practicable verification method for torsional natural frequencies — measurement during operation risks equipment damage if resonances are present. ISO 14694 compliance provides independent validation of the analysis method.
Analysis session-595, qc, verification, mechanical, coupling, idempotency:ver-ifc-019-coupling-595, idempotency:ver-ifc-019-coupling-595
VER-REQ-058 Verify SUB-REQ-017: From cold standby, issue a start demand and measure: (a) time from start initiation to alternator output frequency reaching 50 Hz ±1% (pass: ≤10 seconds), (b) at the 10-second mark, confirm voltage and frequency are within specification under no-load conditions using calibrated panel meters. Test at ambient temperatures across the specified range (minimum specified ambient to maximum specified ambient). Record time-to-rated-speed for each test run.
Rationale: SUB-REQ-017 sets the engine torque delivery requirement by specifying 50 Hz ±1% within 10 seconds under no-load, which is the precondition for load pickup in SUB-REQ-001. The timed test from cold standby directly measures whether the engine block and rotating assembly meets the acceleration requirement. Testing at temperature extremes confirms performance margin is maintained across the operating envelope.
Test session-595, qc, verification, diesel-engine, idempotency:ver-sub-017-engine-torque-595, idempotency:ver-sub-017-engine-torque-595
VER-REQ-059 Verify SUB-REQ-018: Conduct a 168-hour continuous load test at 100% rated load with all auxiliary systems within specified operating limits. Monitor at ≤1-hour intervals: engine load (kW), coolant temperature, lube oil pressure, fuel consumption rate, engine speed, generator output voltage and frequency. Pass criteria: no unplanned shutdown, all parameters within limits throughout, total fuel consumed ≤90% of available bulk storage (≥10% reserve confirmed by tank level gauge at test end), all alarm events logged and cleared.
Rationale: Pass criteria must be binary and measurable. Replacing 'adequate fuel supply' with a specific ≥10% reserve threshold allows unambiguous pass/fail determination at test completion. The 168-hour test at 100% load is the primary verification method for SUB-REQ-018 endurance performance; IEC 61508 (Functional safety of E/E/PE safety-related systems) requires safety-critical performance to be demonstrated by test, not extrapolation.
Test session-595, qc, verification, diesel-engine, endurance, idempotency:ver-sub-018-168hr-595, idempotency:ver-sub-018-168hr-595
VER-REQ-060 Verify SUB-REQ-065: Review the Bulk Fuel Storage Tank design documentation. Confirm: (a) nominal tank capacity is declared in litres on the tank data sheet, (b) calculate 168h fuel consumption at rated load from engine test bed data sheet fuel consumption figure (litres/hour), (c) calculate required volume = 168h × consumption rate × 1.15 (for 115% factor), (d) confirm nominal tank capacity ≥ required volume. Verify the 115% factor breakdown (3% sump, 2% thermal expansion, 10% pump submersion) matches the installed design. Review calculation record against ENA TS 09-3 (Energy Networks Association Technical Specification: Diesel fuel storage) fuel system allowances.
Rationale: SUB-REQ-065 sets the tank capacity as a calculated value from test bed fuel consumption data. Analysis of the calculation against the declared design data sheet is the correct verification method — volumetric capacity cannot be confirmed by functional test. The ENA TS 09-3 reference provides an independent standard for the 115% factor components.
Analysis session-595, qc, verification, fuel-oil, idempotency:ver-sub-065-bulk-tank-595, idempotency:ver-sub-065-bulk-tank-595
VER-REQ-061 Verify SUB-REQ-064: With the EDG under test, run load acceptance steps at 25%, 50%, 75%, and 110% of rated load. At each step, measure: (a) turbocharger boost pressure against the engine manufacturer's performance map (pass: within ±5% of map value at the measured load point), (b) exhaust smoke level (pass: Bosch Smoke Number ≤3.0 at all load points), (c) absence of turbocharger surge (audible surge or inlet pressure oscillation >0.1 bar amplitude). Review turbocharger type approval certificate for surge margin at rated speed.
Rationale: SUB-REQ-064 references the manufacturer's performance map as the defined acceptance criterion. The test directly compares measured boost pressure against the map at key load points. The Bosch Smoke Number criterion (≤3.0) is the industry-standard pass/fail for incomplete combustion. Turbocharger surge would indicate operation outside the compressor map, which is a precursor to compressor wheel damage.
Test session-595, qc, verification, diesel-engine, turbo, idempotency:ver-sub-064-turbo-595, idempotency:ver-sub-064-turbo-595
VER-REQ-062 Verify SUB-REQ-026: With the ALC supplied from 24VDC Class 1E bus, assert the LOOP input discrete by closing a calibrated relay contact. Measure elapsed time from contact closure to the ALC start-sequence output signal (starter motor energise command). Record using a data logger at 1ms resolution. Repeat 10 times. Pass criterion: all 10 measurements ≤200ms from contact closure to start command assertion.
Rationale: SUB-REQ-026 allocates 200ms to the ALC detection and initiation step within the 500ms SYS-REQ-003 system budget. A 10-repeat relay injection test at 1ms resolution directly measures this timing allocation. Ten repeats confirm repeatability; a single-shot test would not distinguish a marginal design from a compliant one. SIL-3 requires Test verification for timing-critical functions.
Test session-596, validation, starting-control, sil-3, idempotency:ver-sub026-alc-timing-596
VER-REQ-063 Verify SUB-REQ-027: Commission a seismic qualification analysis of the Diesel Engine Subsystem to IEEE 344 (Recommended Practice for Seismic Qualification of Class 1E Equipment for Nuclear Power Generating Stations) using site-specific Floor Response Spectra (FRS) at the EDG building slab level derived from the site seismic hazard assessment. Analysis SHALL confirm that dynamic stresses in the engine block mountings, exhaust pipework hangers, and fuel injection system hold-down brackets remain below yield under SSE loading. Alternatively, witnessed shake-table test to the site FRS may be accepted as ONR-equivalent evidence. Pass criterion: qualified analysis report or shake-table test certificate accepted by ONR-approved Qualifying Engineer.
Rationale: SUB-REQ-027 seismic qualification for a UK nuclear site is verified by inspecting the qualified seismic analysis report (to IEEE 344) or the witnessed shake-table test certificate issued by an ONR-approved Qualifying Engineer. The verification activity is review of a formal qualification document — Inspection is the correct IEC 61508 evidence type. Analysis is the technique used within the qualification report; the EDG project team inspects the results, not re-performs the analysis.
Inspection session-596, validation, diesel-engine-subsystem, sil-3, seismic, idempotency:ver-sub027-seismic-qual-596
VER-REQ-064 Verify SUB-REQ-028: Subject the Isochronous Governor System and Engine Control Panel to BS EN IEC 61000-6-2 (Electromagnetic compatibility — Immunity for industrial environments) conducted and radiated immunity tests using UKAS-accredited test laboratory facilities. Additionally, subject the Automatic Load Controller and Generator Protection Relay to BS EN IEC 61000-6-7 (Electromagnetic compatibility — Immunity requirements for equipment intended to perform functions in a safety-related system) testing. Pass criterion: all equipment passes the relevant standard with no malfunction, spurious output, or mode change during test; test report issued by UKAS-accredited laboratory. Verify that ALC and GPR SIL-3 function (start initiation and protection trip) remains operational throughout all immunity test sequences.
Rationale: SUB-REQ-028 requires EMC immunity compliance as a condition of maintaining SIL-3 function integrity. Third-party UKAS-accredited laboratory testing is the only accepted method for demonstrating compliance with IEC 61000-6-7 — analysis or inspection cannot substitute for radiated and conducted immunity testing. The explicit verification of SIL-3 function during testing goes beyond standard EMC compliance to confirm safety function availability under EMC stress.
Test session-596, validation, starting-control, electrical-protection-and-switchgear, sil-3, emc, idempotency:ver-sub028-emc-compliance-596
VER-REQ-065 Verify SUB-REQ-056: Obtain the circuit breaker type test certificate from the manufacturer issued by a UKAS-accredited body. Review the certificate against BS EN 62271-100 (High-voltage switchgear and controlgear — AC circuit-breakers) or BS EN 61439-1 (Low-voltage switchgear and controlgear assemblies) as applicable to the rated voltage. Confirm the certificate covers: (a) rated breaking capacity (rms symmetrical short-circuit current) equal to or exceeding the site fault level, (b) short-time current withstand (rated duration, rated current), (c) electrical endurance class E2 (10,000 operating cycles). Pass criterion: valid type test certificate from UKAS-accredited body covering all three attributes, issued within 10 years of installation commissioning.
Rationale: SUB-REQ-056 is a standards compliance requirement satisfied by type-test certification, not by repeat testing at site. Inspection of the manufacturer's type test certificate against the standard's requirements is the correct and accepted verification method for switchgear standards compliance. Re-testing at rated fault current on site would be destructive. The E2 class (10,000 cycles) aligns with the EDG's expected surveillance test frequency over a 40-year plant life.
Inspection session-596, validation, electrical-protection-and-switchgear, sil-3, idempotency:ver-sub056-mgcb-type-cert-596
VER-REQ-066 Verify SYS-REQ-011: Commission an independent architectural safety analysis demonstrating that common-cause failure of both EDG trains does not prevent reactor core cooling. Analysis SHALL demonstrate: (a) physical and electrical separation between EDG Train A and Train B meeting ONR separation criteria, (b) diverse non-EDG AC supply exists (e.g., gas turbine, mobile generator) with startup time within station blackout DC battery coping window, (c) DC battery system autonomy ≥8 hours under station blackout load profile, (d) passive decay heat removal system is available without AC power and is not susceptible to EDG common-cause failure. Pass criterion: safety analysis accepted by ONR-licensed qualifying engineer, with no outstanding open items against IEC 61508-2 SIL-4 architectural constraints.
Rationale: SYS-REQ-011 common-cause failure argument for SIL-4 is verified by inspecting the independent architectural safety analysis submitted to ONR. The verification team inspects the analysis methodology, separation evidence, and passive cooling arguments against IEC 61508-2 SIL-4 architectural constraints. The analysis is commissioned externally; the project team's role is Inspection of the resulting safety case document, not re-derivation of the analysis.
Inspection session-596, validation, sil-4, ccf, station-blackout, safety, idempotency:ver-sys011-ccf-architecture-596
VER-REQ-067 Verify SUB-REQ-034: With the Remote Monitoring Gateway powered and connected to a simulated I&C network test port, transmit write commands, parameter set commands, and configuration change messages to the RMG Ethernet interface at 100% rated network load for 30 minutes. Monitor the PTLU side of the optical isolation barrier for any response, write acknowledgement, or parameter change. Pass criterion: zero write acknowledgements or parameter changes observed on the PTLU side during the 30-minute test; optical isolation resistance measured at >100MΩ between I&C network and PTLU circuits.
Rationale: SUB-REQ-034 provides a one-way isolation barrier (RMG) between the I&C network and the SIL-2 PTLU — this is the primary mitigation for H-010 (Cyber attack) hazard. A functional penetration test confirming zero write-through is the only way to demonstrate the read-only isolation property. Isolation resistance measurement confirms the 1500Vrms optical barrier is intact. Test is required (not Analysis) because SUB-REQ-034 is a SIL-2 safety function claim.
Test session-596, validation, monitoring-and-instrumentation, sil-2, cyber, idempotency:ver-sub034-rmg-isolation-596
VER-REQ-068 Verify SUB-REQ-025: With the EDG in standby mode, apply a simulated LOOP signal to the Automatic Load Controller input representing bus voltage drop below 80% of nominal. Measure the time from LOOP signal receipt to ALC initiating the diesel start signal. Verify the start signal is a hardwired relay output independent of any software path. Pass criterion: start signal initiated within 100ms of LOOP detection; signal path confirmed hardwired via relay contact verification.
Rationale: SUB-REQ-025 is SIL-3 (H-001: Failure to start on demand). The LOOP signal processing is the triggering event for the entire EDG start sequence. A functional test with measured latency is mandatory for SIL-3 — analysis alone cannot demonstrate the hardwired independence claim. 100ms criterion is derived from the 10-second start budget (SYS-REQ-001).
Test session-598, validation, starting-control, sil-3, idempotency:ver-sub025-598
VER-REQ-069 Verify SUB-REQ-062: With compressed air receivers at minimum pressure (25 bar gauge), perform 3 consecutive cranking cycles without recharging between attempts. Monitor air pressure after each cycle. After 3rd cycle, verify receiver pressure remains above 25 bar. Pass criterion: minimum 3 complete cranking cycles from 25 bar initial charge; air receiver pressure not below 25 bar after 3rd cycle.
Rationale: SUB-REQ-062 is SIL-3 (H-001: Failure to start). The compressed air starting store is the primary start energy source — insufficient air pressure is a known EDG failure mode. Three-start minimum ensures the system can re-attempt after a wet-stack or failed start attempt without recharging. Minimum pressure threshold must be demonstrated by test per IEC 61508 (Functional safety of E/E/PE safety-related systems) SIL-3 requirements.
Test session-598, validation, starting-control, sil-3, idempotency:ver-sub062-598
VER-REQ-070 Verify SUB-REQ-039: With the EDG running at rated load, use an external calibrated temperature source to inject a simulated coolant outlet temperature above 95°C into the Protective Trip Logic Unit thermocouple input. Confirm the hardwired trip relay opens and the EDG trips to safe state within 2 seconds of the setpoint being exceeded. Pass criterion: EDG trip confirmed within 2 seconds; relay contact opening verified by independent contact state monitor.
Rationale: SUB-REQ-039 is SIL-2 (H-006: Cooling system failure). The 95°C high-temperature trip is a primary mitigation for engine seizure. A functional injection test is required rather than analysis because the hardwired relay path must be proven end-to-end — software-based simulation cannot confirm the physical trip circuit.
Test session-598, validation, cooling-system, sil-2, idempotency:ver-sub039-598
VER-REQ-071 Verify SUB-REQ-021: With the EDG running at 50% rated load, command a step demand change to 100% rated load via the governor. Measure the fuel rack position response time from command to full rack displacement using a calibrated position transducer. Perform 5 test runs. Pass criterion: fuel rack response within 200ms for all 5 runs; no hunting or instability observed over 30 seconds post-step.
Rationale: SUB-REQ-021 is SIL-2 (H-003: Engine overspeed). Fuel rack response time is the primary control input affecting speed transient magnitude — a slow or oscillatory rack response leads to overspeed. The 200ms limit is derived from governor stability analysis; functional test is required to confirm real hardware meets the analytical model.
Test session-598, validation, diesel-engine-subsystem, sil-2, idempotency:ver-sub021-598
VER-REQ-072 Verify SUB-REQ-041: Perform volumetric survey of Bulk Fuel Storage Tank at installation, confirming usable capacity not less than required for 168 hours of EDG operation at rated fuel consumption rate. Measure tank dimensions, calculate gross volume, deduct sump and unusable heel volumes. Pass criterion: confirmed usable volume ≥ (168h × rated fuel consumption rate l/h) with 10% margin.
Rationale: SUB-REQ-041 is SIL-2 (H-005: Fuel contamination/exhaustion). Fuel volume is a physical measurement — Inspection (dimensional survey with calculation) is the appropriate method; continuous Test operation for 168h is not warranted. The 10% margin accounts for measurement uncertainty and unusable heel variation.
Inspection session-598, validation, fuel-oil-system, sil-2, idempotency:ver-sub041-598
VER-REQ-073 Verify SUB-REQ-036: Following seismic qualification testing per IEEE 344 (Recommended Practice for Seismic Qualification of Class 1E Equipment), subject Engine Parameter Sensor Array and Protective Trip Logic Unit samples to the site Design Basis Earthquake (DBE) response spectrum. Following shake testing, perform functional test: energise sensors, verify PTLU logic outputs respond correctly to simulated trip inputs. Pass criterion: PTLU and all sensors functional post-shake; no alarms due to seismic input alone.
Rationale: SUB-REQ-036 is SIL-2 (H-008: Seismic damage). The I&C instruments protecting the EDG must survive the DBE to maintain safety function. Seismic qualification by test per IEEE 344 is the industry standard for nuclear Class 1E equipment; Analysis alone is not acceptable for SIL-2 safety instruments.
Test session-598, validation, monitoring-and-instrumentation, sil-2, seismic, idempotency:ver-sub036-598
VER-REQ-074 Verify SUB-REQ-030: Connect calibrated reference instruments in parallel with the Engine Parameter Sensor Array 4-20mA dual-channel outputs for lube oil pressure, coolant temperature, and shaft speed. Run EDG at rated load for 30 minutes. Compare channel A vs channel B outputs at 1-minute intervals. Pass criterion: dual-channel output deviation ≤ 0.5% of full scale for all parameters; both channels independently trigger a simulated trip input at PTLU when setpoints are exceeded by injected fault signal.
Rationale: SUB-REQ-030 is SIL-2 (H-006 and H-003). Dual-channel I&C is the primary diversity mechanism for safety parameter monitoring. A cross-comparison test validates channel independence and confirms both channels are able to initiate trips — Analysis cannot substitute for functional channel separation proof per IEC 61511 (Functional safety of safety-instrumented systems for the process industry sector).
Test session-598, validation, monitoring-and-instrumentation, sil-2, idempotency:ver-sub030-598
VER-REQ-075 Verify SUB-REQ-054: With the EDG running at no-load and jacket water temperature pre-stabilised at preheat temperature (35°C ±5°C), apply a step load of 100% rated power. Record jacket water outlet temperature at 30-second intervals for 20 minutes post-load application. Pass criterion: coolant temperature reaches and stabilises within 70°C–88°C operational band within 10 minutes of full-load application; no overshoot above 95°C trip setpoint.
Rationale: SUB-REQ-054 is SIL-2 (H-006: Cooling system failure). The cooling system response to cold-start/full-load is the worst-case thermal transient — the 95°C trip setpoint must not be exceeded during normal LOOP load pickup. Test under actual thermal conditions is required because cooling model uncertainties (thermostat hysteresis, airflow resistance) are too large to verify by Analysis alone.
Test session-598, validation, cooling-system, sil-2, idempotency:ver-sub054-598
VER-REQ-076 Verify SUB-REQ-022: With the EDG running at rated speed and full load for 30 minutes (thermal steady state), measure charge air manifold pressure with a calibrated pressure transducer at the turbocharger outlet. Compare measured boost pressure against manufacturer rated boost pressure at 100% load. Pass criterion: measured charge air boost pressure within 5% of manufacturer's rated value; no surge, choke, or surging noise observed during rated load operation.
Rationale: SUB-REQ-022 is SIL-2 (H-003: Engine overspeed via under-fuelling from inadequate air). Turbocharger boost pressure determines the air-fuel ratio at rated power. Insufficient boost causes either under-fuelling (output drop, possible LOOP fail) or rich-burn (black smoke, possible engine damage). Functional test at rated load conditions is the only way to confirm the real turbocharger matches the engine power curve — Analysis uses test data that may not reflect installation effects.
Test session-598, validation, diesel-engine-subsystem, sil-2, idempotency:ver-sub022-598
VER-REQ-077 Verify SYS-REQ-012: Induce a non-trip fault in the Isochronous Governor System (simulated sensor failure causing governor to operate in degraded open-loop mode). Measure EDG electrical output power and frequency under 60% of rated load. Monitor for 2 hours. Confirm control room alarm received within 60 seconds of fault injection. Pass criterion: EDG sustains ≥60% rated power output; frequency within 50Hz ±2%; annunciation confirmed within 60 seconds of fault.
Rationale: SYS-REQ-012 is SIL-2 (H-002: Loss of output during operation). The degraded mode requirement must be verified by inducing a representative non-trip fault and confirming minimum output is sustained. Analysis cannot verify the annunciation path or the minimum 60% power floor under degraded governor operation — physical test under actual fault conditions is required.
Test session-598, validation, system, sil-2, degraded-mode, idempotency:ver-sys012-598
VER-REQ-078 Verify SYS-REQ-002: Run the EDG at rated load continuously for 168 hours. Monitor fuel consumption rate, coolant temperature, lube oil pressure, and bearing temperatures at 4-hour intervals. Pass criteria: no manual intervention required, all parameters remain within design limits throughout the full 168-hour period.
Rationale: SYS-REQ-002 specifies a 168-hour minimum continuous run capability — IEC 60034 (Rotating electrical machines) and CEGB diesel generator requirements mandate endurance demonstration by full-duration test. Spot checks or extrapolation are not acceptable for this safety-critical performance requirement.
Test verification, diesel-engine, sil-3, session-599, idempotency:ver-sys-req-002-endurance-599
VER-REQ-079 Verify SYS-REQ-004: Inject each trip condition in sequence (overspeed, low lube oil pressure, high coolant temperature, high exhaust temperature, overcurrent, earth fault) into the Protective Trip Logic Unit. Measure elapsed time from condition onset to fuel solenoid de-energisation and GCB trip. Pass criteria: trip execution ≤2 seconds for all conditions, GCB trips confirmed by relay test unit, engine decelerates to rest within 30 seconds.
Rationale: SYS-REQ-004 specifies the safety trip response chain at SIL-3. IEC 61508 (Functional safety of E/E/PE safety-related systems) requires that SIL-3 safety functions be verified by Test with full stimulus-response measurement; Analysis alone cannot demonstrate the actual trip time for the hardware-in-the-loop trip path.
Test verification, starting-control, sil-3, session-599, idempotency:ver-sys-req-004-trip-599
VER-REQ-080 Verify SYS-REQ-005: Perform reliability block diagram (RBD) and fault tree analysis (FTA) for the EDG system using failure rate data per IEC 61508 (Functional safety of E/E/PE safety-related systems) Annex B or plant-specific historical data (minimum 10-year dataset). Calculate PFD_avg across the 10-year surveillance interval with 24-month proof test interval. Pass criteria: calculated PFD_avg ≤1×10⁻³ per demand with 90% confidence bound; all failure mode assumptions documented and peer-reviewed.
Rationale: PFD_avg reliability calculations are analytical computations (RBD, FTA), not documentary inspections. IEC 61508 (Functional safety of E/E/PE safety-related systems) Part 6 Annex B classifies probabilistic assessment as Analysis. Inspection applies to physical artefacts; Analysis applies to mathematical models and calculations. Updated from Inspection to Analysis.
Analysis verification, system, session-599, idempotency:ver-sys-req-005-pfd-599, verifies-sil-3, session-604
VER-REQ-081 Verify SYS-REQ-006: Review the seismic qualification analysis report for all EDG building structural elements and mechanical equipment. Confirm analysis uses Design Basis Earthquake spectrum with 0.25g PGA at frequency range 1-33 Hz. Verify that natural frequencies of all EDG-mounted components are above 33 Hz or that dynamic amplification has been considered. Pass criteria: ONR-approved analysis report confirms ≥0.25g PGA survivability, all critical bolted connections torqued and lock-wired, no resonance peaks within EDG operational speed range.
Rationale: SYS-REQ-006 seismic survivability to 0.25g PGA is verified by inspecting the ONR-approved seismic qualification analysis report. The report confirms Design Basis Earthquake spectrum compliance, natural frequency margins, and bolted connection adequacy. Inspection of an externally commissioned and independently approved analysis report is the appropriate verification method for structural seismic qualification on a UK nuclear licensed site.
Inspection verification, system, sil-2, session-599, idempotency:ver-sys-req-006-seismic-599
VER-REQ-082 Verify SUB-REQ-023: With EDG in standby mode (heaters energised), measure jacket water temperature using calibrated thermocouple at engine inlet and outlet over a 72-hour period at minimum ambient temperature. Pass criteria: coolant temperature maintained ≥35°C continuously with no heater cycling gaps >30 minutes, start-to-rated transition completed within 10 seconds during any standby measurement window.
Rationale: SUB-REQ-023 requires standby coolant pre-heat temperature maintenance for rapid start capability at SIL-2. Compliance cannot be demonstrated by analysis alone — the thermal lag of the cooling system depends on actual heat loss rates, heater capacity, and ambient temperature that must be measured in situ.
Test verification, diesel-engine, sil-2, session-599, idempotency:ver-sub-req-023-standby-coolant-599
VER-REQ-083 Verify SUB-REQ-037: With engine at operating temperature (coolant 75-85°C), install calibrated ultrasonic flow meter on jacket water pump outlet. Measure flow rate at 100% rated engine load and at idle (600 RPM minimum). Pass criteria: flow ≥120 L/min at rated load, ≥60 L/min at idle; no cavitation noise detectable.
Rationale: SUB-REQ-037 specifies minimum coolant flow for engine thermal management at SIL-2. Flow rate must be measured directly; pump curve analysis is insufficient because pipe losses and temperature-dependent viscosity affect actual delivered flow. In-situ measurement validates the installed configuration.
Test verification, cooling-system, sil-2, session-599, idempotency:ver-sub-req-037-jw-flow-599
VER-REQ-084 Verify SUB-REQ-043: Sample fuel downstream of the Fuel Filtration Assembly during EDG operation at rated load. Analyse sample using ISO 4406 particle counting (optical). Pass criteria: ISO cleanliness code ≤16/14/11 (equivalent to <10 micron particles per IEC 60770 (Transmitters for use in industrial-process control systems) service class requirements), measured in three independent samples taken at 30-minute intervals.
Rationale: SUB-REQ-043 specifies fuel cleanliness for fuel injection system protection at SIL-2. Filter ratings must be verified by downstream particle count, not upstream specification, as filter bypass or bypass valve operation can admit contaminated fuel. Direct measurement is required per BS EN ISO 16889 (Hydraulic fluid power — Filters).
Test verification, fuel-oil-system, sil-2, session-599, idempotency:ver-sub-req-043-fuel-filter-599
VER-REQ-085 Verify SUB-REQ-045: Monitor Day Tank fuel temperature at minimum ambient winter conditions (site minimum -5°C, or use temperature-controlled test chamber). Confirm fuel heater maintains temperature ≥5°C after 12 hours exposure at minimum ambient. Pass criteria: fuel temperature ≥5°C throughout test with no fuel heater failures; if analysis-based, present validated thermal model with uncertainty bounds showing ≥5°C with 95% confidence.
Rationale: SUB-REQ-045 requires fuel temperature ≥5°C at site minimum ambient. Verification requires physical measurement of fuel temperature at minimum ambient (−5°C or equivalent chamber test) over a 12-hour soak with the heater system active. This is a Test: quantified environmental condition applied, temperature measured at prescribed intervals, pass/fail against a numeric threshold. The analysis-based alternative (thermal model) is accepted only if the physical test is not practicable during commissioning; the primary verification method is Test.
Test verification, fuel-oil-system, sil-2, session-599, idempotency:ver-sub-req-045-fuel-temp-599
VER-REQ-086 Verify SUB-REQ-048: Inject a simulated PT100 RTD resistance value equivalent to 91°C into the Protective Trip Logic Unit input for each generator bearing channel in turn. Verify alarm appears at local indication panel and control room annunciator within 5 seconds. Pass criteria: alarm triggered for all bearing channels at ≤91°C simulated temperature; no false alarms at 89°C; alarm latches correctly until acknowledged.
Rationale: SUB-REQ-048 specifies the bearing high-temperature alarm at SIL-2. The PT100 input, alarm logic, and annunciator output form a safety-related measurement chain that must be proven end-to-end. Injection testing at the field instrument connection verifies the full chain without requiring actual bearing overheating.
Test verification, alternator, sil-2, session-599, idempotency:ver-sub-req-048-bearing-temp-599
VER-REQ-087 Verify SUB-REQ-052: Using a crankshaft position sensor and calibrated fuel pressure transducer at injector inlet, measure injection timing relative to TDC at engine idle (600 RPM), 50%, and 100% rated load. Pass criteria: injection timing within ±2° crankshaft angle of nominal advance angle at all three load points; data logged over 10 consecutive injection events per point to confirm repeatability.
Rationale: SUB-REQ-052 specifies fuel injection timing accuracy for combustion efficiency and emission compliance at SIL-2. Injection timing drift is a known failure mode leading to hard starting and excessive smoke; direct measurement at three load points is required per BS EN ISO 4165 (Road vehicles — Electrical connections) diesel test standards. Analysis cannot substitute for measurement of the mechanical injection pump's actual timing.
Test verification, diesel-engine, sil-2, session-599, idempotency:ver-sub-req-052-inj-timing-599
VER-REQ-088 Verify SUB-REQ-057: Inspect all fuel oil bunding and containment around the Day Tank, service tank, and fuel transfer pipework. Verify bund capacity ≥110% of the largest vessel it contains. Review Environmental Permitting (England and Wales) Regulations 2016 compliance documentation and compare against CIRIA C736 (Containment systems for the prevention of pollution — secondary, tertiary and other measures) checklist. Pass criteria: inspection report signed by qualified civil/environmental engineer confirms full compliance, zero observed penetrations in bund lining, drainage valve in closed/locked position.
Rationale: SUB-REQ-057 is an environmental compliance requirement mandated by UK environmental regulations. Inspection by a qualified engineer against CIRIA C736 checklist is the standard compliance verification method; analysis cannot substitute for physical inspection of bund integrity and volume.
Inspection verification, fuel-oil-system, sil-2, session-599, idempotency:ver-sub-req-057-bunding-599
VER-REQ-089 Verify SUB-REQ-060: With EDG in Maintenance Out-of-Service mode (LOTO applied), inspect access routes and clearances around all major subsystems (Diesel Engine Subsystem, Alternator Subsystem, Fuel Oil System, Cooling System, Starting and Control Subsystem, Electrical Protection and Switchgear Subsystem). Verify that all maintenance access points specified in the OEM maintenance manual can be reached without disturbing adjacent plant. Pass criteria: all identified maintenance tasks achievable without confined-space entry, minimum 750mm aisle clearance maintained, all lifting equipment anchor points accessible and in-date certified.
Rationale: SUB-REQ-060 addresses maintainability and safe access at SIL-2 (common cause failure prevention through maintainability). Physical inspection is the only valid verification method; drawings cannot confirm that as-built plant matches design intent or that all maintenance tools physically fit in the space.
Inspection verification, maintenance, sil-2, session-599, idempotency:ver-sub-req-060-access-599
VER-REQ-090 Verify SYS-REQ-007: Apply a simulated LOOP event and initiate load sequencing with three load blocks representing: safety injection (50kW), emergency lighting (15kW), and HVAC (30kW). Apply each block at 2-second intervals and record voltage and frequency transients on a data logger at 200Hz sampling. Pass criteria: voltage dip per load application ≤15% of 415V (i.e., ≥353V minimum during transient), frequency deviation ≤3Hz from 50Hz nominal during transient, recovery to within tolerance (390–441V, 49.5–50.5Hz) within 3 seconds of each block application.
Rationale: SYS-REQ-007 specifies load sequencing constraints directly driven by the 10-second LOOP Response ConOps scenario. An uncontrolled voltage dip >15% risks contactor dropout on safety-classified loads, breaking the load sequencing chain. Testing at the exact threshold with a data logger at 200Hz confirms the 3-second recovery requirement is met under worst-case thermal load conditions and is not achievable by analysis alone.
Test session-600, validation, system, sil-3, load-sequencing, idempotency:ver-sys007-load-seq-600
VER-REQ-091 Verify SYS-REQ-008: Subject the EDG control and protection electronics (ALC, ECP, PTLU, Governor System) to EMC immunity testing in accordance with BS EN IEC 61000-4-2 (electrostatic discharge, 8kV contact/15kV air), BS EN IEC 61000-4-4 (EFT/burst testing per IEC 61000-4-4, Level 4), and BS EN IEC 61000-4-5 (surge immunity, Level 3) with test levels representative of the EDG building electromagnetic environment during engine cranking and load pickup. Monitor all protective trip outputs and control signals during and after each test burst. Pass criteria: no spurious trips, no loss of control functionality, no parameter deviation >10% of setpoint during or within 5 seconds after each test.
Rationale: SYS-REQ-008 addresses BS EN IEC 61000 (Electromagnetic compatibility) compliance for EDG control electronics in a high-EMI environment generated by the EDG itself (ignition transients, large motor switching). A spurious trip during a real LOOP event caused by conducted EMI would be a SIL-3 failure. EMC testing at Level 4 is the only way to demonstrate immunity; analysis cannot predict EMI coupling paths in the as-installed plant configuration.
Test session-600, validation, system, emc, idempotency:ver-sys008-emc-600
VER-REQ-092 Verify SYS-REQ-009: Configure EDG for surveillance test mode with SBTC isolating the safety bus. Conduct a 30-minute full-rated-load test using the load bank connected to the test bus output. Record load (kW), voltage, frequency, and engine parameters throughout. At test completion, isolate load bank, allow engine cooldown, and measure time from load removal to ECP indicating 'hot standby' status (oil pressure confirmed, starting air charged, ALC armed). Pass criteria: 30 minutes continuous at rated load with no protective trips; hot standby status confirmed within 10 minutes of load removal.
Rationale: SYS-REQ-009 is the direct implementation requirement for the Monthly Surveillance Test ConOps scenario. The 30-minute duration and 10-minute hot standby recovery are site licence condition requirements; failure to demonstrate these would put the plant in a limiting condition for operation. Demonstration against the as-installed test infrastructure confirms the test mode works without any safety bus perturbation.
Demonstration session-600, validation, system, surveillance-test, idempotency:ver-sys009-surveillance-600
VER-REQ-093 Verify SYS-REQ-010: Inspect site stores inventory records and compare against the EDG OEM-specified minor servicing consumables list (filters, belts, gaskets, coolant) and the major overhaul tooling list. Inspect maintenance schedule records for the last 5 years confirming minor service intervals ≤12 months and confirm major overhaul is scheduled within the 5-year interval. Inspect all specialised tooling items on the OEM overhaul list and confirm physical presence in site stores. Pass criteria: all consumables and tools present in stores; no service interval exceedance recorded; scheduled overhaul date within 5-year cycle confirmed.
Rationale: SYS-REQ-010 is a maintainability requirement driven by STK-REQ-006 (maintenance team access without off-site tools) and the Planned Overhaul ConOps scenario. Inspection of stores inventory and maintenance records is the appropriate method because the requirement governs material availability and organisational process, not a measurable physical performance parameter.
Inspection session-600, validation, system, maintainability, idempotency:ver-sys010-maintainability-600
VER-REQ-094 Verify SUB-REQ-035: Inject each protective trip function (oil pressure, coolant temp, overspeed, vibration, channel fault) one at a time into the Protective Trip Logic Unit test terminals while the Local Alarm and Indication Panel is energised. For each injection, record time from trip signal onset to first-out alarm display illumination and audible alarm activation using a 1ms-resolution timer. Confirm the alarm annunciation is latched (remains active after trip signal is removed) until manually acknowledged at the LAIP panel. Pass criteria: first-out display and audible alarm active within 500ms in all cases; latching confirmed for each trip function; no subsequent trip function displays the first-out indication while the first alarm is unacknowledged.
Rationale: SUB-REQ-035 is a 500ms first-out annunciation requirement for the LAIP. This is the diagnostic interface for the Failure to Start and EDG Trip During Extended LOOP scenarios — the operator needs to identify the trip cause within the first 500ms to initiate correct recovery action. Only physical injection testing through the trip logic confirms the timing and latching logic; simulation cannot account for relay coil delay and indicator driver response time.
Test session-600, validation, monitoring-instrumentation, sil-2, idempotency:ver-sub035-firstout-alarm-600
VER-REQ-095 Verify SUB-REQ-029: Schedule and witness a minor servicing event on the Diesel Engine Subsystem. Confirm that all tools and consumables used (cylinder head inspection tools, injector calibration equipment, belt and filter replacements) are drawn from the site-approved store inventory list. Record start and finish times of the servicing event. Confirm no specialised tools not on the site inventory list were called up. Pass criteria: all maintenance activities completed using only site-held tools and consumables; servicing completed within the maintenance window defined in the site maintenance schedule; no off-site tool requests raised.
Rationale: SUB-REQ-029 is a maintainability constraint ensuring independence from OEM field-service visits for planned minor maintenance. This supports the Planned Overhaul ConOps scenario where 14-day maintenance must be completable without off-site tooling logistics. Witnessing an actual servicing event is the only way to confirm site stores coverage — analysis would merely confirm the written inventory, not whether the stored items are serviceable and appropriate.
Demonstration session-600, validation, diesel-engine, maintainability, idempotency:ver-sub029-diesel-maintain-600
VER-REQ-096 Verify SUB-REQ-061: Inspect the Fuel Oil System design documentation, construction records, and operating licence against: (a) DSEAR (Dangerous Substances and Explosive Atmospheres Regulations 2002) ATEX zone classification drawings and hazardous area assessment; (b) Petroleum (Consolidation) Regulations 2014 — site petroleum licence and storage certificates; (c) BS EN ISO 4064 flow measurement — calibration certificates for fuel flow meters; (d) CIRIA C736 (Containment systems for the storage of polluting liquids) — secondary containment design calculations and inspection records for day tank and bulk tank installations. Pass criteria: current petroleum storage licence held; ATEX zone classification drawings approved; all secondary containment installations documented as compliant with CIRIA C736 calculation methodology.
Rationale: SUB-REQ-061 requires compliance with DSEAR, Petroleum (Consolidation) Regulations 2014, and CIRIA C736 — all of which are regulatory/statutory requirements enforced by inspection of documentation, licences, and design records rather than physical testing. The 168-hour fuel endurance test (VER-REQ-059) verifies operational performance; this requirement verifies the legal compliance basis.
Inspection session-600, validation, fuel-oil, compliance, regulatory, idempotency:ver-sub061-dsear-compliance-600
VER-REQ-097 Validate STK-REQ-001 (stakeholder acceptance): Conduct a witnessed system acceptance test with the site safety authority. From a cold standby state, apply a genuine LOOP by opening the Class 1E bus interties; record time-to-rated-voltage using the plant SCRAM data logger. Conduct three consecutive repetitions, varying ambient temperature across the operating range (5°C, 20°C, 40°C). Pass criteria: all three starts achieve rated voltage and frequency on the safety bus within 10 seconds; no auxiliary system failures requiring operator intervention; SCRAM data logger records confirm timing without manual stopwatch reliance.
Rationale: STK-REQ-001 is the primary emergency start stakeholder requirement — the criterion that motivates the entire EDG system. A witnessed acceptance Demonstration with the site safety authority is the appropriate validation method at stakeholder level (above system-level Test VER-REQ-004) because it closes the gap between design verification and operational validation in the presence of the licensing body.
Demonstration session-602, validation, stk, stk-acceptance, sil-3, idempotency:ver-stk001-acceptance-demonstration-602
VER-REQ-098 Verify H-010 cyber security mitigation (SYS-REQ-004 and control system architecture): Conduct a structured cyber security assessment of all digital control system interfaces (ALC, Governor, PTLU, Remote Monitoring Gateway) in accordance with IEC 62645 (Nuclear power plants — Instrumentation, control and electrical power systems — Cybersecurity requirements). Confirm that: (a) the ALC, Governor, and PTLU have no IP-addressable remote access ports; (b) the Remote Monitoring Gateway is physically isolated with a one-way data diode on the read path; (c) hardwired trip circuits (oil pressure, coolant temperature, overspeed) are implemented in relay logic with no software path to inhibit. Pass criteria: cyber architecture review by ONR-recognised assessor confirms air-gapped control architecture; no network path to safety-critical functions; hardwired trip logic verified by continuity test independent of digital channels.
Rationale: H-010 identifies cyber attack as a SIL-3 hazard with safe state of air-gapped backup and hardwired trips. No dedicated cyber security VER requirement existed prior to this session. IEC 62645 is the primary standard for nuclear I&C cyber security assessment. Inspection is appropriate because the primary control measure is architectural (air-gap, one-way diode, hardwired relays) — these are verified by physical inspection and architectural review, not by simulated cyber attack.
Inspection session-602, validation, cyber-security, h-010, sil-3, idempotency:ver-h010-cyber-security-inspection-602
VER-REQ-099 Verify H-007 CCF safe state — DC battery coping time under station blackout load profile (SYS-REQ-011): With both EDGs inhibited and all AC power removed, connect a calibrated DC load bank to the Class 1E DC battery system simulating the station blackout load profile (DC-powered instrumentation, rod control inhibit, passive decay heat removal initiation circuit). Record battery terminal voltage versus time at rated temperature (20°C). Pass criteria: battery terminal voltage remains ≥105V DC for a minimum of 8 hours under the station blackout load profile without AC charging; voltage recovery within 30 minutes upon restored AC supply. Test to be repeated at end-of-life battery capacity (80% rated Ah). This directly tests the SYS-REQ-011 CCF safe state assumption for DC battery coping time.
Rationale: H-007 (CCF both EDGs, SIL-4) has a safe state of diverse AC, DC batteries, and passive cooling. Session 600 flagged that SYS-REQ-011→VER-REQ-066 relies entirely on analysis — no Test-method verification of DC battery coping time existed. IEC 61508-2 SIL-4 requires hardware fault tolerance (HFT=1) to be demonstrated, not just analysed. VER-REQ-066 is an architecture analysis review; this Test requirement directly measures the 8-hour battery coping claim under realistic station blackout load.
Test session-602, validation, station-blackout, h-007, sil-4, ccf, dc-battery, idempotency:ver-h007-ccf-battery-coping-test-602
VER-REQ-100 The EDG system SHALL be tested in degraded mode: introduce a simulated subsystem fault (simulate a cooling fan belt fault via belt tension sensor override) while the EDG is running at rated load. Verify: (a) no automatic safety trip is triggered, (b) EDG continues to run, (c) electrical output remains ≥60% rated power (3.0 MW from 5.0 MW rated), (d) frequency remains within 50Hz ±2% (49.0–51.0 Hz), (e) degraded condition alarm appears on MCR within 30 seconds, (f) condition persists for a minimum of 2 hours. Pass criteria: all five measurements within bounds; MCR alarm within 30 seconds; no spurious trip. Verify at two load levels: 60% rated and 80% rated.
Rationale: Degraded mode operation test verifies REQ-SEEMERGENCYDIESELGENERATORFORAUKNUCLEARLICENSEDSITE-001 under simulated fault conditions. MCR: Main Control Room. Coolant fan belt fault is selected because (a) it's a realistic non-safety-critical fault (loose belt, belt wear, slipping pulley) that can be detected via belt tension sensor override, (b) it reduces cooling capacity without immediately causing overheat trip, and (c) it can be simulated without disabling safety interlocks or modifying protection setpoints. The 2-hour duration matches STK-REQ-002 (degraded operation must sustain sufficient time for operator diagnosis and load transfer) — 2 hours is derived from nuclear site operating procedures for fault diagnosis and EDG load transfer. The 60% rated power floor (3.0 MW from 5.0 MW) ensures priority safety loads can be supplied while excluding non-essential loads. Two load levels (60% and 80%) are required to validate that degraded mode is not a pass/fail state change but a gradual performance envelope degradation.
Test session-603, validation, degraded-mode, sil-2, idempotency:ver-sys013-degraded-mode-test-603, tech-author-session-613
VER-REQ-101 The EDG system SHALL demonstrate Post Maintenance Test (PMT) completion: following a simulated major maintenance activity (oil and filter change, injector calibration, governor adjustment), with LOTO released and all connections reinstated, command one start from standby. Record: (a) time from start command to rated voltage (pass: ≤10 seconds), (b) voltage and frequency at rated (pass: 400V ±2%, 50Hz ±1%), (c) acceptance of 50% rated load block without voltage dip below 380V, (d) all protective trip functions respond to their respective test inputs within 2 seconds. The PMT shall be witnessed by the shift supervisor and recorded in the plant maintenance log before handback.
Rationale: SUB-REQ-066 requires a PMT before reinstatement. This Demonstration verifies that maintenance has not degraded start performance, governor function, or protective trip operation. The 50% load acceptance test is chosen as a representative functional test that exercises the fuel system, governor, and alternator without requiring full-rated load bank deployment during routine post-maintenance checks.
Demonstration session-603, validation, pmt, maintenance, return-to-service, idempotency:ver-sub066-pmt-demonstration-603
VER-REQ-102 The EDG system SHALL be demonstrated to have physical and electrical separation between Train A and Train B meeting CCF exclusion criteria: using a power injection test set, conduct a fault injection test on EDG Train A control power supply (disconnect Train A Class 1E DC supply) and verify: (a) Train B ALC, ECP, and PTLU remain energised with normal indication within 1 second, (b) Train B completes a start-to-rated test cycle independently without any cross-coupling to Train A circuitry, (c) no common terminal or junction box contains conductors from both trains simultaneously. Pass criteria: Train B fully functional with Train A de-energised; physical separation inspection confirms no shared enclosures. This test shall be performed by an independent nuclear safety engineer under ONR oversight.
Rationale: SYS-REQ-011 is SIL-4 and requires HFT=1 — architectural independence of the two EDG trains. IEC 61508-2 (Requirements for E/E/PE safety-related systems) SIL-4 mandates that hardware fault tolerance be demonstrated under fault injection, not only confirmed by documentation Inspection. VER-REQ-066 (Inspection) and VER-REQ-099 (DC battery test) address specific aspects but neither demonstrates Train B operability under Train A total failure. This Demonstration closes the SIL-4 verification gap for the CCF exclusion argument.
Demonstration session-603, validation, ccf, sil-4, train-separation, h-007, idempotency:ver-sysreq011-ccf-train-separation-demo-603
VER-REQ-103 Verify SYS-REQ-014: Following a full-rated-load run test, restore offsite power supply and transfer the Class 1E bus to normal supply. Inhibit the EDG stop command and monitor for 5 minutes at no-load. Record: (a) coolant temperature at 0, 1, 3, and 5 minutes — pass: temperature does not exceed 80°C and decreases monotonically; (b) lubricating oil pressure at ALC display — pass: maintained within normal standby band throughout; (c) confirm automatic engine stop does not occur until the 5-minute timer elapses. Pass criteria: all three conditions met; thermocouple calibration certificate within 12-month validity.
Rationale: SYS-REQ-014 requires 5-minute minimum cooldown at ≤10% load with coolant below 80°C. This test verifies the ALC timer logic, the coolant temperature trending, and lubricant circulation under actual post-run thermal conditions. Analytical methods cannot substitute for the thermal transient measurement — the test must be performed under hot conditions following a loaded run to capture real cooldown dynamics.
Test session-604, validation, cooldown-shutdown, mode-coverage, sil-2, idempotency:ver-sys014-cooldown-shutdown-604
VER-REQ-104 Verify SYS-REQ-015: Perform a battery capacity test per IEEE 450 (Recommended Practice for Maintenance, Testing, and Replacement of Vented Lead-Acid Batteries) on the Class 1E battery system under the worst-case DC load profile. Test procedure: (a) discharge battery at the documented worst-case DC load profile (emergency lighting, protection relays, control systems, annunciators), (b) record discharge curve at 1-minute intervals until battery reaches 105V minimum cell voltage threshold, (c) calculate measured Ah capacity with temperature correction for minimum design ambient (5°C), (d) apply end-of-life derating factor (80% of measured capacity per IEEE 1188), (e) analytically demonstrate that derated measured capacity supports ≥8-hour DC coping time at worst-case load. Pass criterion: derated measured capacity demonstrates ≥8-hour autonomy with ≥10% margin, test witnessed and accepted by independent nuclear safety engineer, results documented in the nuclear QA programme. Battery replacement required if capacity <80% rated at end-of-life.
Rationale: SYS-REQ-015 specifies the 8-hour DC coping window for single-train failure (SIL-3, H-001/H-002). Verification changed from pure analysis to Test: IEEE 450 capacity test directly measures the actual battery capacity under load, eliminating reliance on design data that may not reflect actual installed condition, cell aging, or electrolyte condition. The test also constitutes mandatory nuclear surveillance per IEEE 450 Section 6 interval requirements. Using measured rather than design capacity satisfies the IEC 61508 requirement for Test verification of SIL-3 functions.
Test session-605, validation, sil-3, single-train-failure, idempotency:ver-sys015-single-train-dc-605
VER-REQ-105 Verify SYS-REQ-016 cyber isolation: Inspect the EDG control system design documentation, network architecture diagram, and cable schedule. Confirm: (a) no Ethernet, fieldbus, or wireless interface present on ALC, ECP, PTLU, or IGS units, (b) remote monitoring path uses certified one-way data diode hardware with no reverse channel, (c) all control wiring is point-to-point hardwired with no intermediate protocol converters, (d) software version is locked and change-controlled through the nuclear QA programme. Pass criterion: all four points confirmed by inspection with no open findings; inspection witnessed and accepted by ONR-approved nuclear cybersecurity assessor.
Rationale: SYS-REQ-016 is a design-phase cyber isolation requirement. The verification method is inspection of documentation and physical hardware because network isolation is a property of the design, not of runtime behaviour. An Inspection by an ONR-approved assessor is the required evidence under the ONR Security Assessment Principles for Category A safety systems.
Inspection session-605, validation, sil-3, cyber, h-010, idempotency:ver-sys016-cyber-605
VER-REQ-106 Verify SUB-REQ-006 channel voting under single-channel failure: (a) Disable ALC Channel A processing unit by removing power connector; confirm EDG does NOT start (voting logic correctly inhibits start on single-channel assertion). (b) With Channel A re-enabled, disable Channel B; confirm EDG does NOT start. (c) Apply LOOP signal simultaneously to both Channel A and Channel B inputs; confirm start demand generated within 500ms. (d) Apply LOOP to Channel A only (Channel B normal); confirm NO start demand. (e) Re-enable Channel A, apply LOOP to both channels; confirm start demand generated. Pass criteria: (a)–(b) no start demand in 5s; (c) start demand ≤500ms; (d) no start demand in 5s; (e) start demand ≤500ms. All five conditions passed without manual intervention.
Rationale: SUB-REQ-006 specifies SIL-3 2oo2 voting to prevent both loss-of-start (single-channel failure prevents demand) and spurious start (single-channel assertion causes demand). H-001 (Failure to start, SIL-3) and H-009 (Spurious start, SIL-1) are mitigated by this architecture. VER-REQ-048 (Inspection of design documentation) verifies the design intent but does not demonstrate the functional voting behaviour under failure conditions. This functional test closes the IEC 61508 requirement for Test verification of safety-critical SIL-3 logic at the commissioning stage.
Test session-606, validation, starting-control, sil-3, alc, 2oo2, h-001, h-009, idempotency:ver-sub006-alc-voting-failure-606
VER-REQ-107 Verify SYS-REQ-017 degraded mode exit recovery: With the EDG running at 60% rated load in simulated degraded mode (subsystem fault injected via test input), clear the simulated fault at t=0. Record time from fault clearance acknowledgement at ECP to EDG output reaching ≥95% rated power and voltage 415V ±6%, frequency 50Hz ±1%. Pass criteria: full output restored within 60 seconds of operator acknowledgement, without engine trip or restart.
Rationale: SYS-REQ-017 requires fault-cleared recovery to full power within 60 seconds without restart. Demonstrating this by test confirms the governor and load control system can smoothly ramp from degraded to full power following fault isolation. Analysis alone cannot confirm the dynamic ramp behaviour of the combined governor-fuel system, which depends on commissioning tuning.
Test session-606, validation, degraded-mode, mode-transition, sil-2, idempotency:ver-sys017-degraded-exit-606
VER-REQ-108 Verify SYS-REQ-016 cyber resilience under active attack simulation: Engage an independent nuclear cyber security assessor to conduct a structured penetration test against the EDG control system interface (test bed replica with identical software image). Test SHALL include: (a) attempted unauthorised access to Automatic Load Controller via RS-485 maintenance port; (b) attempted signal injection on 24VDC LOOP signal input; (c) replay attack on hardwired trip circuit. Pass criteria: no unauthorised control action executed, no trip circuit bypassed, all intrusion attempts logged and alarmed within 60 seconds, EDG continues operating or achieves safe state (hardwired trip). Simulation environment must be certified equivalent to production hardware.
Rationale: SYS-REQ-016 is SIL-3 (H-010 cyber attack, catastrophic severity). VER-REQ-105 provides only Inspection of design documentation. For SIL-3 cyber requirements in nuclear applications, IEC 62443-3-3 (Security for Industrial Automation and Control Systems) and ONR Safety Assessment Principles require demonstration under adversarial conditions, not documentation review alone. This Test verification adds active penetration testing using a hardware-identical test bed, closing the verification adequacy gap for H-010.
Test session-607, validation, cyber-security, sil-3, h-010, idempotency:ver-sys016-cyber-pentest-607, idempotency:ver-sys016-cyber-pentest-607
VER-REQ-109 Verify SUB-REQ-067 Maintenance Out-of-Service mode entry: Simulate a maintenance transition request with EDG in Standby Ready state. Confirm: (a) unavailability signal transmitted to control room within 30 seconds; (b) start demand interlock removed (verified by attempting LOOP signal injection — EDG SHALL NOT start); (c) LOTO Maintenance Access Permit issued only after energy source isolation confirmed. Repeat with EDG in post-test shutdown state. Pass criteria: all three sequential conditions satisfied in correct order, automatic start inhibited throughout, no unauthorised start on LOOP demand.
Rationale: SUB-REQ-067 (session 607) defines the controlled entry into Maintenance Out-of-Service mode. Inspection alone cannot verify that the start demand interlock is actually removed and that the EDG is unable to respond to a spurious LOOP demand while maintenance access is granted. This Test verification confirms the interlock removal is effective by attempting a live LOOP signal injection.
Test session-607, validation, maintenance, loto, mode-coverage, idempotency:ver-sub067-maintenance-entry-607, sil-3

Traceability Matrix — Verification

RequirementVerified ByDescription
VER-REQ-032 ARC-REQ-007 Brushless excitation cold start test verifies Alternator Subsystem architecture
VER-REQ-027 ARC-REQ-006 Day tank fuel reserve and gravity-feed test verifies Fuel Oil System architecture
VER-REQ-026 ARC-REQ-005 Cooling system capacity test verifies five-component Cooling System architecture
VER-REQ-073 ARC-REQ-004 Post-seismic M&I system test verifies Monitoring and Instrumentation architecture
VER-REQ-059 ARC-REQ-003 168-hour continuous load test verifies Diesel Engine Subsystem five-component architecture
VER-REQ-008 ARC-REQ-002 SBTC + bus transfer test verifies Electrical Protection Subsystem architecture
VER-REQ-015 ARC-REQ-001 DES end-to-end integration test verifies Starting and Control Subsystem architecture
VER-REQ-099 STK-REQ-007 DC battery coping time Test verifies stakeholder 8-hour DC backup requirement
VER-REQ-097 STK-REQ-001 Witnessed acceptance demonstration validates emergency start stakeholder requirement
VER-REQ-089 STK-REQ-006 LOTO access inspection validates maintenance isolation stakeholder requirement
VER-REQ-081 STK-REQ-005 Seismic qualification analysis validates EDG survivability stakeholder requirement
VER-REQ-092 STK-REQ-004 Surveillance test demonstration validates periodic full-load testing stakeholder requirement
VER-REQ-080 STK-REQ-003 SIL-3 PFD_avg reliability analysis validates ONR Safety Assessment Principles compliance
VER-REQ-078 STK-REQ-002 168-hour continuous test validates sustained emergency power stakeholder need
VER-REQ-004 STK-REQ-001 End-to-end LOOP simulation validates emergency start stakeholder requirement
VER-REQ-063 SUB-REQ-027 Seismic qualification analysis verifies SUB-REQ-027 IEEE 344 compliance
VER-REQ-068 SUB-REQ-026 ALC LOOP signal latency test verifies SUB-REQ-026 200ms timing
VER-REQ-109 SUB-REQ-067 Maintenance mode entry test verifies controlled LOTO entry procedure
VER-REQ-106 SUB-REQ-006 ALC 2oo2 channel voting functional failure test verifies single-channel failure behavior required by SUB-REQ-006
VER-REQ-101 SUB-REQ-066 PMT Demonstration verifies post-maintenance return-to-service requirement
VER-REQ-096 SUB-REQ-061 VER-REQ-096 inspects petroleum licence, ATEX zoning, and CIRIA C736 containment records against SUB-REQ-061
VER-REQ-095 SUB-REQ-029 VER-REQ-095 demonstrates minor servicing with site-held tools only, verifying SUB-REQ-029 maintainability constraint
VER-REQ-094 SUB-REQ-035 VER-REQ-094 tests first-out alarm timing (500ms) and latching for all LAIP trip functions in SUB-REQ-035
VER-REQ-089 SUB-REQ-060 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-088 SUB-REQ-057 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-087 SUB-REQ-052 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-086 SUB-REQ-048 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-085 SUB-REQ-045 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-084 SUB-REQ-043 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-083 SUB-REQ-037 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-082 SUB-REQ-023 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-076 SUB-REQ-022 Turbocharger boost pressure at rated load
VER-REQ-075 SUB-REQ-054 Cooling thermal transient test under full load step
VER-REQ-074 SUB-REQ-030 Dual-channel sensor cross-comparison test
VER-REQ-073 SUB-REQ-036 Seismic qualification test per IEEE 344
VER-REQ-072 SUB-REQ-041 Fuel volume dimensional survey
VER-REQ-071 SUB-REQ-021 Fuel rack response time test
VER-REQ-070 SUB-REQ-039 High-temp trip injection test
VER-REQ-069 SUB-REQ-062 3-start air pressure endurance test
VER-REQ-068 SUB-REQ-025 ALC LOOP signal latency test
VER-REQ-015 SUB-REQ-063 Integration test verifies engine acceleration requirement
VER-REQ-065 SUB-REQ-056 VER test for SUB-REQ-056
VER-REQ-064 SUB-REQ-028 VER test for SUB-REQ-028
VER-REQ-063 SUB-REQ-027 VER test for SUB-REQ-027
VER-REQ-062 SUB-REQ-026 VER test for SUB-REQ-026
VER-REQ-061 SUB-REQ-064 VER test for SUB-REQ-064
VER-REQ-060 SUB-REQ-065 VER test for SUB-REQ-065
VER-REQ-059 SUB-REQ-018 VER test for SUB-REQ-018
VER-REQ-058 SUB-REQ-017 VER test for SUB-REQ-017
VER-REQ-053 SUB-REQ-014 VER test for SUB-REQ-014
VER-REQ-052 SUB-REQ-012 VER test for SUB-REQ-012
VER-REQ-051 SUB-REQ-011 VER test for SUB-REQ-011
VER-REQ-050 SUB-REQ-008 VER test for SUB-REQ-008
VER-REQ-049 SUB-REQ-007 VER test for SUB-REQ-007
VER-REQ-048 SUB-REQ-006 VER test for SUB-REQ-006
VER-REQ-047 SUB-REQ-005 VER test for SUB-REQ-005
VER-REQ-046 SUB-REQ-050 VER test for SUB-REQ-050
VER-REQ-045 SUB-REQ-058 VER test for SUB-REQ-058
VER-REQ-044 SUB-REQ-047 VER test for SUB-REQ-047
VER-REQ-043 SUB-REQ-044 VER test for SUB-REQ-044
VER-REQ-042 SUB-REQ-033 VER test for SUB-REQ-033
VER-REQ-041 SUB-REQ-024 VER test for SUB-REQ-024
VER-REQ-040 SUB-REQ-010 VER test for SUB-REQ-010
VER-REQ-039 SUB-REQ-004 VER test for SUB-REQ-004
VER-REQ-038 SUB-REQ-059 VER test for SUB-REQ-059
VER-REQ-037 SUB-REQ-055 VER test for SUB-REQ-055
VER-REQ-036 SUB-REQ-053 VER test for SUB-REQ-053
VER-REQ-035 SUB-REQ-051 VER test for SUB-REQ-051
VER-REQ-032 SUB-REQ-049 VER test for SUB-REQ-049
VER-REQ-031 SUB-REQ-046 VER test for SUB-REQ-046
VER-REQ-026 SUB-REQ-038 VER test for SUB-REQ-038
VER-REQ-023 SUB-REQ-032 VER test for SUB-REQ-032
VER-REQ-022 SUB-REQ-031 VER test for SUB-REQ-031
VER-REQ-020 SUB-REQ-016 VER test for SUB-REQ-016
VER-REQ-019 SUB-REQ-015 VER test for SUB-REQ-015
VER-REQ-018 SUB-REQ-003 VER test for SUB-REQ-003
VER-REQ-017 SUB-REQ-002 VER test for SUB-REQ-002
VER-REQ-016 SUB-REQ-001 VER test for SUB-REQ-001
VER-REQ-014 SUB-REQ-020 VER test for SUB-REQ-020
VER-REQ-013 SUB-REQ-019 VER test for SUB-REQ-019
VER-REQ-008 SUB-REQ-012 Combined MGCB test verifies SUB-REQ-012
VER-REQ-006 SUB-REQ-013 VER test for SUB-REQ-013
VER-REQ-005 SUB-REQ-009 VER test for SUB-REQ-009
VER-REQ-067 SUB-REQ-034 RMG penetration test and isolation resistance measurement verifies SUB-REQ-034
VER-REQ-065 SUB-REQ-056 MGCB type test certificate inspection verifies SUB-REQ-056
VER-REQ-064 SUB-REQ-028 EMC immunity test verifies SUB-REQ-028 IEC 61000-6-2/6-7 compliance
VER-REQ-006 SUB-REQ-013 SUB-REQ-013 SBTC mechanical interlock spec → VER-REQ-006 interlock test
VER-REQ-005 SUB-REQ-009 SUB-REQ-009 GPR 87G differential protection spec → VER-REQ-005 differential fault injection test
VER-REQ-014 SUB-REQ-020 Mechanical overspeed trip actuation test verifies SUB-REQ-020
VER-REQ-013 SUB-REQ-019 Lube pressure trip timing test verifies SUB-REQ-019
SUB-REQ-040 VER-REQ-027 Endurance test verifies 8h day tank capacity
SUB-REQ-042 VER-REQ-028 Functional test verifies pump auto-start timing and fill rate
VER-REQ-038 SUB-REQ-059 Test mode demonstration verifies non-disruptive full-load testing capability
VER-REQ-037 SUB-REQ-055 Type-test certificate inspection verifies IEC 60255 compliance
VER-REQ-036 SUB-REQ-053 Duty/standby pump switchover test verifies fuel transfer redundancy
VER-REQ-035 SUB-REQ-051 Governor channel fault injection test verifies dual-channel redundancy
VER-REQ-026 SUB-REQ-038 Cooling capacity commissioning test verifies Radiator 280 kW dissipation requirement
VER-REQ-032 SUB-REQ-049 Black-start test verifies excitation build-up time and overshoot
VER-REQ-031 SUB-REQ-046 Load bank test verifies AVR voltage regulation at steady state and step load
VER-REQ-039 SUB-REQ-004 Overspeed trip timing test verifies ECP 500ms shutdown requirement
VER-REQ-040 SUB-REQ-010 Secondary injection test verifies GPR overcurrent timing and coordination
VER-REQ-041 SUB-REQ-024 Crankcase relief actuation test verifies hardwired trip path timing
VER-REQ-042 SUB-REQ-033 Sensor fault injection test verifies PTLU 1-second channel-fault detection
VER-REQ-043 SUB-REQ-044 Fire isolation actuation test verifies 10s valve closure with day tank path maintained
VER-REQ-044 SUB-REQ-047 PT100 simulation test verifies stator thermal alarm/trip thresholds and accuracy
VER-REQ-045 SUB-REQ-058 Alarm injection test verifies 2-second presentation criterion and EEMUA 191 compliance
VER-REQ-046 SUB-REQ-050 Earth fault isolation timing test verifies 200ms stator de-energisation from both sources
VER-REQ-028 SUB-REQ-042 Functional test verifies pump auto-start timing and fill rate
VER-REQ-027 SUB-REQ-040 Endurance test verifies 8h day tank autonomous reserve
VER-REQ-023 SUB-REQ-032 Power loss safe state test verifies fail-safe requirement
VER-REQ-022 SUB-REQ-031 Trip response time test verifies PTLU timing requirement
VER-REQ-020 SUB-REQ-016 Governor watchdog trip test verifies SUB-REQ-016 fail-safe timing
VER-REQ-019 SUB-REQ-015 GPR fail-safe test verifies SUB-REQ-015 safe state requirement
VER-REQ-018 SUB-REQ-003 Governor load step test verifies SUB-REQ-003 speed accuracy
VER-REQ-017 SUB-REQ-002 Compressed air endurance test verifies SUB-REQ-002
VER-REQ-016 SUB-REQ-001 ALC LOOP detection test verifies SUB-REQ-001
VER-REQ-047 SUB-REQ-005 Failed-to-start latch and MCR alarm timing test
VER-REQ-048 SUB-REQ-006 ALC 2oo2 dual-channel voting architecture analysis
VER-REQ-049 SUB-REQ-007 ALC key-switch inhibit functional test and wiring inspection
VER-REQ-050 SUB-REQ-008 Governor manual speed trim range and auto-revert on synchronise demonstration
VER-REQ-051 SUB-REQ-011 MGCB fault interruption capacity and clearing time verification
VER-REQ-052 SUB-REQ-012 Safety bus transfer contactor 150ms timing test
VER-REQ-053 SUB-REQ-014 VSMU dual-channel discrepancy alarm 2s timing test
VER-REQ-058 SUB-REQ-017 Engine torque and 10-second rated-speed attainment test
VER-REQ-059 SUB-REQ-018 168-hour continuous endurance test at rated load
VER-REQ-017 SUB-REQ-062 Compressed air starting system 3-attempt cranking test - updated requirement
VER-REQ-058 SUB-REQ-063 Engine acceleration to 1500 RPM within 10 seconds - updated requirement
VER-REQ-060 SUB-REQ-065 Bulk fuel storage tank capacity calculation analysis
VER-REQ-061 SUB-REQ-064 Turbocharger boost pressure map compliance and anti-surge test
VER-REQ-027 SUB-REQ-040 Day tank 8h autonomous reserve test verifies SUB-REQ-040
VER-REQ-028 SUB-REQ-042 Fuel transfer pump auto-start test verifies SUB-REQ-042
VER-REQ-062 SUB-REQ-026 ALC 200ms start initiation timing test verifies SUB-REQ-026
VER-REQ-057 IFC-REQ-019 VER test for IFC-REQ-019
VER-REQ-056 IFC-REQ-016 VER test for IFC-REQ-016
VER-REQ-055 IFC-REQ-014 VER test for IFC-REQ-014
VER-REQ-054 IFC-REQ-013 VER test for IFC-REQ-013
VER-REQ-034 IFC-REQ-020 VER test for IFC-REQ-020
VER-REQ-033 IFC-REQ-018 VER test for IFC-REQ-018
VER-REQ-025 IFC-REQ-012 VER test for IFC-REQ-012
VER-REQ-024 IFC-REQ-011 VER test for IFC-REQ-011
VER-REQ-021 IFC-REQ-007 VER test for IFC-REQ-007
VER-REQ-012 IFC-REQ-010 VER test for IFC-REQ-010
VER-REQ-011 IFC-REQ-009 VER test for IFC-REQ-009
VER-REQ-010 IFC-REQ-008 VER test for IFC-REQ-008
VER-REQ-009 IFC-REQ-005 VER test for IFC-REQ-005
VER-REQ-008 IFC-REQ-006 VER test for IFC-REQ-006
VER-REQ-007 IFC-REQ-004 VER test for IFC-REQ-004
VER-REQ-003 IFC-REQ-003 VER test for IFC-REQ-003
VER-REQ-002 IFC-REQ-002 VER test for IFC-REQ-002
VER-REQ-001 IFC-REQ-001 VER test for IFC-REQ-001
VER-REQ-030 IFC-REQ-017 Fuel level switch NC topology test verifies IFC-REQ-017
VER-REQ-029 IFC-REQ-015 Day tank gravity-feed pressure test verifies IFC-REQ-015
VER-REQ-057 IFC-REQ-019 Torsional vibration analysis and coupling torque rating review
VER-REQ-056 IFC-REQ-016 Fuel transfer pump 150% delivery margin and fill line position test
VER-REQ-055 IFC-REQ-014 JWP-radiator pipe bore, pressure, temperature and isolation valve inspection
VER-REQ-054 IFC-REQ-013 PTLU-RMG signal protocol, latency and isolation test
VER-REQ-029 IFC-REQ-015 Day tank fuel supply pressure test verifies gravity-feed interface specification
VER-REQ-021 IFC-REQ-007 24VDC battery endurance test verifies IFC-REQ-007
VER-REQ-024 IFC-REQ-011 Loop fault detection test verifies EPSA-PTLU interface
VER-REQ-025 IFC-REQ-012 Hardwired relay topology test verifies PTLU-ECP interface
VER-REQ-030 IFC-REQ-017 Fail-safe test verifies level switch normally-energised logic to LAIP
VER-REQ-033 IFC-REQ-018 Calibration and isolation test verifies VSMU to AVR 4-20mA interface
VER-REQ-034 IFC-REQ-020 PT100 substitution and fault injection test verifies stator RTD to PTLU interface
IFC-REQ-017 VER-REQ-030 REVERSED-LINK-TO-DELETE: was IFC-REQ-017 verifies VER-REQ-030
IFC-REQ-015 VER-REQ-029 Pressure test verifies fuel supply interface compliance
VER-REQ-010 IFC-REQ-008 Fuel supply interface test verifies IFC-REQ-008 pressure/temperature parameters
VER-REQ-011 IFC-REQ-009 Critical speed analysis and coupling inspection verifies IFC-REQ-009
VER-REQ-012 IFC-REQ-010 Cooling interface temperature test verifies IFC-REQ-010
VER-REQ-001 IFC-REQ-001 IFC-REQ-001 ALC→ECP start demand spec → VER-REQ-001 signal verification test
VER-REQ-002 IFC-REQ-002 IFC-REQ-002 ECP→starting system solenoid spec → VER-REQ-002 solenoid valve timing test
VER-REQ-003 IFC-REQ-003 IFC-REQ-003 governor interface response spec → VER-REQ-003 step load response test
VER-REQ-007 IFC-REQ-004 IFC-REQ-004 GPR→MGCB trip circuit spec → VER-REQ-007 de-energise trip time test
VER-REQ-008 IFC-REQ-006 IFC-REQ-006 ALC→SBTC bus transfer spec → VER-REQ-008 end-to-end transfer test
VER-REQ-009 IFC-REQ-005 IFC-REQ-005 VSMU output signal spec → VER-REQ-009 calibration accuracy test
VER-REQ-100 SYS-REQ-012 Degraded mode Test verifies 60% rated power and 2-hour performance floor
VER-REQ-108 SYS-REQ-016 Active penetration test verifies cyber isolation requirement under adversarial conditions
VER-REQ-107 SYS-REQ-017 Degraded mode exit recovery test verifies fault-cleared transition requirement
VER-REQ-105 SYS-REQ-016 Cyber isolation inspection verifies EDG control system network isolation requirement
VER-REQ-104 SYS-REQ-015 Battery coping analysis verifies single-train failure DC coping requirement
VER-REQ-103 SYS-REQ-014 Verification test for cooldown shutdown mode requirement
VER-REQ-102 SYS-REQ-011 Train separation Demonstration verifies SIL-4 CCF independence architectural requirement
VER-REQ-099 SYS-REQ-011 DC battery coping time Test verifies CCF safe state architecture in SYS-REQ-011
VER-REQ-098 SYS-REQ-004 Cyber security inspection verifies hardwired trip architecture in SYS-REQ-004
VER-REQ-093 SYS-REQ-010 VER-REQ-093 inspects stores inventory, maintenance records and tooling availability against SYS-REQ-010 intervals and site-only tooling constraint
VER-REQ-092 SYS-REQ-009 VER-REQ-092 demonstrates 30-minute surveillance test and 10-minute hot standby recovery
VER-REQ-091 SYS-REQ-008 VER-REQ-091 tests EMC immunity of EDG control electronics per BS EN IEC 61000 industrial levels
VER-REQ-090 SYS-REQ-007 VER-REQ-090 tests load sequencing voltage and frequency transient thresholds specified in SYS-REQ-007
VER-REQ-081 SYS-REQ-006 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-080 SYS-REQ-005 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-079 SYS-REQ-004 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-078 SYS-REQ-002 VER → SYS/SUB verification trace for SIL-gap closure
VER-REQ-077 SYS-REQ-012 Degraded mode functional test
VER-REQ-004 SYS-REQ-003 End-to-end start test verifies SYS-REQ-003
VER-REQ-004 SYS-REQ-001 VER test for SYS-REQ-001
VER-REQ-066 SYS-REQ-011 CCF architectural safety analysis verifies SYS-REQ-011
VER-REQ-015 SYS-REQ-001 End-to-end diesel engine integration test verifies SYS-REQ-001 rated output
VER-REQ-015 SYS-REQ-003 End-to-end diesel engine integration test verifies SYS-REQ-003 start time
VER-REQ-004 SYS-REQ-001 SYS-REQ-001 startup performance → VER-REQ-004 end-to-end LOOP acceptance test