IT system — disconnection on a second fault (§411.6)
IT system — disconnection on a second fault (§411.6)
The guide on IT systems and insulation monitoring (IMD) covers how a first insulation fault in an IT system is signalled without disconnecting the installation, and qualitatively notes why a second fault does become dangerous. This article goes one step further: what §411.6 of the standard concretely requires once that second fault occurs, and why the actual fault loop — and therefore the required disconnection time — depends on whether the neutral of the IT system is distributed and bonded or not.
The principle: a first fault may persist, a second may not
As the IMD guide describes, an IT system may keep operating normally after a first insulation fault — there is no low-impedance return path to earth, so no dangerous touch voltage arises. As soon as a second fault occurs on a different live conductor, however, while the first fault has not yet been cleared, a fault loop forms via earth between the two fault locations that is comparable in danger to a direct fault in a TN system. §411.6 therefore requires this situation to still result in automatic disconnection, in a manner comparable to TN or TT, but with a fault-loop calculation specific to the IT system.
Neutral not distributed: the fault loop runs via two line conductors
Where the IT system has no distributed neutral (the most common case for a three-phase IT installation with no phase-to-neutral load), the fault loop for a second fault runs between two line conductors: the phase carrying the first fault and the phase carrying the second fault, via the interconnected protective conductors of both fault locations. The voltage across this fault loop is therefore not the phase voltage (U₀) as with a TN fault, but the full line voltage (U, typically 400 V) — a higher voltage that, at equal loop impedance, produces a larger fault current than an equivalent TN fault at the same voltage would.
Neutral distributed: conditions closer to TN
Where the neutral of the IT system is distributed and bonded to the protective conductor, a second fault can also occur between a line conductor and the neutral. In that configuration, conditions closer to the regular TN conditions apply (fault loop at phase voltage U₀), depending on the precise position of both fault locations relative to each other and to the neutral.
Note: the exact disconnection times for the second-fault condition are given in a separate table in the full standard (alongside the familiar TN/TT first-fault table) and differ per situation (neutral distributed or not, protective conductors commonly earthed or not). Always consult the full standard text for the precise table values when working on a concrete design.
Practical relevance
When designing or assessing an IT system — for example in an operating theatre (medical IT system) or a continuous industrial process — it is not enough to check first-fault detection via an IMD (see the IMD guide); it must also be verified that the regular overcurrent or residual-current protection actually disconnects within the required time once a second fault occurs. This requires a separate fault-loop calculation that depends on the specific neutral configuration of the IT system.
Common mistakes
- Checking only the IMD's operation and not separately assessing the §411.6 second-fault condition — the IMD signals the first fault, but actual safety on a second fault depends on the regular overcurrent/residual-current protection and the associated fault-loop impedance.
- Using the phase voltage (U₀) instead of the line voltage (U) when calculating the fault-loop impedance for an IT system without a distributed neutral — the second fault runs between two line conductors, not between a line conductor and neutral.
- Assuming an IT system inherently has a less strict disconnection requirement than TN/TT — the second-fault condition can in fact present a higher line voltage across the fault loop, requiring a lower loop impedance (and therefore a more careful design) to disconnect within the allowed time.
- Letting a first fault persist for a long time because the installation still appears to work — the longer the first fault remains uncleared, the longer the period during which a second fault can trigger this disconnection (and the resulting interruption).
Related
Further reading
- §411Automatic Power Off (AUV)
- NEN-EN-IEC 61557-8IT system and insulation monitoring (IMD) — first-fault detection
- §411.5 (IEC 60364-4-41)The TT system — why an installation's own earth electrode makes an RCD mandatory
- §413.3Electrical separation (§413.3) — an isolating transformer as a protective measure without earthing
- §442Temporary overvoltage from an earth fault in the high-voltage network (§442) — why the substation voltage rise reaches the low-voltage installation
- §703Sauna cabins (§703) — temperature zones, heat-resistant cabling and switchgear outside the cabin