Five Electrical Design Mistakes That Can Compromise DC Resilience
Why redundancy on a single-line diagram does not necessarily mean a resilient electrical system
Data center electrical systems are designed around redundancy, availability and the ability to maintain equipment without affecting critical loads. On a single-line diagram, this can appear straightforward: redundant utility supplies, transformers, generators, UPS systems and independent distribution paths. But resilience is not created by duplicating equipment. It depends on how the complete electrical system behaves during failures, maintenance and switching operations. Here are five design issues that can undermine an apparently resilient architecture.
1. Looking at redundancy without looking at failure modes
Two independent electrical paths may appear to provide redundancy while still sharing components, control functions or operating dependencies capable of affecting both. The important question is therefore not simply whether Path A and Path B exist, but what happens when individual components fail. A proper review needs to consider credible failure scenarios and identify common points that can defeat the intended redundancy. The architecture should be assessed by its behavior under failure, not by its appearance on the SLD.
2. Designing redundancy without considering maintenance
A system may tolerate an equipment failure and still be difficult to maintain safely. Switchgear sections, transformers, UPS systems and other critical equipment eventually require inspection, testing or replacement. If isolating one component removes redundancy elsewhere, creates an unacceptable operating configuration or requires extensive temporary arrangements, the design may not provide the maintainability originally intended.Resilience therefore needs to consider both unplanned failures and planned equipment outages.
A genuinely maintainable system should allow foreseeable interventions without unnecessarily exposing the critical load.
3. Underestimating switching and interlocking philosophy
Additional sources, bus couplers and alternative supply paths increase flexibility, but they also increase the number of possible operating configurations. The electrical architecture therefore needs a clear switching philosophy supported by appropriate interlocking, protection and control logic.A configuration that is electrically possible is not necessarily one that should be operationally permitted. This becomes particularly important during abnormal conditions, when operators may need to restore supply quickly. Ambiguous switching sequences or inadequate interlocking can turn redundancy into operational risk.
4. Reviewing protection independently from the operating architecture
Protection studies are sometimes treated as calculations that demonstrate compliance with fault-clearing and equipment requirements. But protection settings also need to remain appropriate across the operating configurations that the system is expected to use. Bus couplers, alternative sources, generators and changes in network configuration can alter fault levels and protection coordination. A setting that performs correctly under the normal arrangement may behave differently after switching or during maintenance. Protection should therefore be reviewed as part of the electrical operating philosophy, not as an isolated study.
5. Assuming the documented design represents the real installation
This becomes especially important in existing or brownfield facilities. Over time, electrical systems are modified, equipment is replaced, temporary arrangements become permanent and documentation does not always evolve at the same pace as the installation.
In my experience, even recently issued as-built documentation cannot always be assumed to represent the actual installation. On one data center project, a field survey of the existing MV/LV network identified significant discrepancies between the documented and installed configurations, despite an as-built survey having been completed only the previous year. Reconstructing the network directly from field verification provided the reliable baseline needed for subsequent engineering activities.
A technically sound modification designed against an inaccurate SLD can therefore introduce risks that are invisible during the engineering review. Before modifying a critical electrical system, confidence in the existing configuration is essential.
Where documentation cannot provide that confidence, verification in the field becomes part of the engineering process.
Resilience needs to be demonstrated, not assumed
Redundancy remains fundamental to data center electrical design, but redundancy alone does not guarantee resilience.
The system must also remain understandable, maintainable and controllable through the operating conditions it is expected to encounter. That requires looking beyond equipment quantities and nominal architecture to understand failure modes, maintenance conditions, switching configurations, protection behaviour and the actual installed system.
A resilient electrical system is therefore not simply one with alternative supply paths.
It is one in which those paths continue to perform as intended when the system is no longer operating under ideal conditions.
