Key takeaways:
The article stresses that electric shock protection and machine earthing must be clearly defined at the design stage. The greatest risks and costs arise where responsibility for protective bonding and continuity of protection after service, modernization, or at machine interfaces has not been specified.
- IEC 60204-1 is most valuable at the design stage, when it clarifies the machine limits, the power supply, and the protective documentation.
- The effectiveness of the protective measures depends on the machine architecture, not just on the protective conductor and the final test.
- Risk increases when conductor functions are mixed and random structural contacts are relied on as the path for fault current.
- Critical points are often outside the cabinet: doors, panels, drives, guards, conveyor sections, and interfaces between modules.
- The cost of errors usually results from inconsistent safeguarding logic, document updates, and re-verification of safety measures.
Protection against electric shock in a machine is not determined simply by the presence of a protective conductor or by a satisfactory acceptance test result. Its effectiveness depends on whether, already at the design stage, the machine boundaries, power supply logic, fault current path, and responsibility for connections between modules and at the interface with the plant installation were clearly defined. When these decisions remain unclear, the problem usually surfaces only during commissioning, retrofitting, or incident analysis—when the fix is no longer simple and starts to affect the entire electrical architecture of the solution. That is why IEC 60204-1 is most valuable not at the end of the process, but when it brings order to design thinking, execution, and the way the effectiveness of protection is documented.
Electric shock does not begin with a failure
The most serious mistake is to treat protection against electric shock as an add-on to a finished machine. In that approach, the issue is supposedly resolved by the protective conductor, a bonding jumper on the cabinet door, or a set of final tests. In reality, the effectiveness of protection results from the entire architecture of the equipment: the power supply arrangement, the chosen protective bonding system, circuit segregation, mechanical design, equipment selection, and the way the machine boundaries and its interface with the building installation were defined. If these elements do not form a coherent whole, even careful assembly will not ensure predictable behaviour under fault conditions, and the final measurement will show only the consequence of the problem.
In design practice, separating functions is critical. Risk increases wherever the functions of protective, functional, and equipotential bonding conductors are mixed, or where protective connections are subordinated to ease of assembly. In that case, fault current is expected to flow along a path that looks correct on the diagram, but in the actual machine depends on incidental contact through a painted structure, a door hinge, a drive mounting bolt, or a section assembled after modification. This is not a deficiency at the end of the process, but an error in the concept of basic protection and fault protection measures.
For the design team, this means deciding in advance which exposed conductive parts and which extraneous conductive parts will be included in the protective bonding system, where the fault current paths run, which components may be disconnected for service, and how continuity of connections is to be maintained after disassembly, segment replacement, or line extension. Without such decisions, it is easy to build a machine that appears correct in its nominal state but loses the integrity of its protection after the first service intervention.
What is most misleading is that the problem usually does not show up in the control cabinet itself. That is where conductors, terminals, and markings are easiest to see, but the critical points are usually elsewhere: on doors and operator panels, in drives mounted on the structure, on movable guards, in conveyor sections, between modules, and in equipment installed outside the cabinet. In painted or bolted structures, it is particularly easy to achieve an assembly that appears correct but does not provide a reliable protective connection under vibration, corrosion, disconnection for transport, or later maintenance work. The same often happens at the interface between two machines, where each one looks correct on its own, but there is no clear logic defining responsibility for equipotential bonding, auxiliary power supply, and assessment of fault effects at the interface.
The cost of this error usually becomes visible only when the change is already expensive: at acceptance, during retrofitting, after an incident, or in the course of conformity assessment. At that point, it turns out that what is missing is not a single conductor, but a coherent logic for the solution and evidence of its effectiveness. It is unclear whether the problem lies in execution or stems from the protection concept itself; it is impossible to demonstrate unambiguously why those measures were chosen; the scope of acceptance tests does not cover the actual critical points. This is exactly where reference to IEC 60204-1 begins to make sense: not as a final formality, but as a framework for electrical solutions that must be consistent with the machine boundaries, the protection measures adopted, and the technical documentation.
Where the cost really increases
The most expensive mistakes in protection against electric shock rarely involve a complete absence of a protective connection. Usually, the problem is more serious precisely because the solution appears complete and yet still does not create a coherent logic of operation under fault conditions. The design assumes a specific power architecture, prefabrication simplifies execution, site installation adapts cable routing to the conditions of the facility, and acceptance reveals that responsibility for continuity of protection has been fragmented across several parties. In that case, the cost does not come from adding a single conductor, but from the need to reconstruct the original machine design intent, re-verify the selection of protective devices, update the documentation, and determine responsibility for sections that were correctly made at workshop level but are inconsistent with the logic of the machine as a whole.
At the design stage, cost is controlled primarily by clearly separating functions. You need to define what serves as the protective conductor, what serves as equipotential bonding, where the connection points are located, which interfaces between the cabinet, the machine frame, and peripheral equipment are critical, and whether structural parts may be relied on at all as a current path. That last point is often the source of the most deceptive solutions. A connection made through a hinge, guide rail, painted sheet metal, a bolted profile, or a screw selected solely for mechanical purposes may work during assembly, yet lose reliability after a few operating cycles, after corrosion, under vibration, with contamination, or after service disassembly.
If the design does not provide dedicated protective bonding jumpers for moving and removable parts, and does not identify which mechanical connections must not be treated as a reliable protective conductor path, the risk is built into execution. In practice, these are exactly the places where it is worth looking for points at which the protective connection is only apparently reliable. Such an error does not have to cause an immediate failure; it is enough that, after disconnection for transport, after surface painting, or after a minor module modification, continuity of protection is no longer obvious.
This is most visible in modular machines and lines assembled by several suppliers. As long as each module is assessed separately, the problem remains hidden. Cost rises sharply only when sections are connected, if the protective conductor connection points, equipotential bonding rules, and responsibility for inter-module connections have not been clearly defined. One party then assumes that the plant installation ensures protective effectiveness, another that the protection concept is self-contained within the machine, while a third makes a process connection that was intended to be neither conductive nor insulated. The cost of a protective conductor planned in advance and a prepared connection point is incomparably lower than later reworking a completed line, reopening cable routes, start-up delays, repeated testing, and documentation corrections after changes. The same applies to a retrofit in which a new module introduces its own power supply logic and disrupts the original protective bonding arrangement, even though everything still looks correct on the drawings; such issues often become visible only during retrofitting.
A separate cost category is formal correctness without any real protective effect. The mere presence of a protective connection does not determine the effectiveness of protection in the event of a fault if the protective devices, conductor cross-sections, or circuit segregation have been selected incorrectly. This type of error is usually revealed only during fault condition analysis, during expansion, or in acceptance tests carried out on the completed installation. That is why electrical decisions must be tied from the outset to the architecture of the entire machine: where the fault loop closes, which sections depend on the plant installation, which environmental conditions will degrade contact quality, and which connections must maintain continuity despite guard removal or the operation of moving parts.
The most underestimated cost, however, arises in the documentation. If the schematics, assembly drawings, connection point markings, and test records do not consistently show how the protective connections and equipotential bonding were implemented, every change becomes more expensive than the technical correction itself. Acceptance, audit, or post-incident analysis then starts with reconstructing the actual condition. In practice, it is therefore better to look not at abstract “compliance with the standard,” but at whether the design remains under control: how many ambiguous interfaces there are between modules, how many connections depend on mechanical parts, how many changes were introduced after prefabrication, and for how many sections responsibility was not clearly assigned. This usually shows most clearly where the most expensive errors return later.
Design decisions before measurement
The effectiveness of electric shock protection is determined before the protective conductor continuity test and before machine acceptance. First, the power supply architecture must be established: where the machine is supplied from and under what conditions, where the boundary of responsibility lies between the machine manufacturer and the plant installation, and which protective measures are appropriate for the actual conditions of use, assembly, and service. This is not merely a matter of the schematic. This decision determines the later selection of protective devices, the method of power disconnection, the logic of protective conductor distribution, and whether the solution can be defended during conformity assessment and during later modifications.
If the interface boundary with the facility installation remains unclear, even correctly executed connections within the machine itself do not eliminate the risk of incorrect coordination of protective devices, unforeseen fault currents, or disputes over the scope of responsibility at acceptance. For this reason, the decision on the power supply boundary cannot be left to be resolved at the commissioning stage. It should result from the machine design and be clear both for prefabrication and for site installation.
A second decision, often underestimated, is to treat protective conductors and equipotential bonding as a complete functional system rather than an add-on to the working wiring. The design must clearly define connection points, routing, identification method, installation requirements, and the conditions for mechanical and operational durability. As early as the schematic and installation drawing stage, the team should determine which exposed conductive parts and which extraneous conductive parts are to be included in the bonding system, and how continuity will be maintained after removing a guard, replacing a component, or changing materials. This is also the stage to define installation and acceptance requirements for field subcontractors.
In practice, the critical points are fairly repetitive. Problems keep recurring at cabinet doors, guards, moving parts, withdrawable modules, disconnectable units, and equipment installed outside the cabinet, especially where the protective connection depends on a hinge, guide, fixing screw, or an undocumented workshop solution. In such cases, continuity of the protective connections is often weakened not by a flawed design assumption, but by prefabrication practice, later retrofits, or service work. A typical example is a door fitted with electrical equipment, where power supply to the control components was provided for but no requirements were defined for a flexible protective connection able to withstand repeated opening. The same happens with pumps, sensors, conveyors, and other equipment installed outside the main enclosure, where the protective conductor is formally present, but its routing is not predictable and the connection point disappears after a change of supplier or contractor.
That is why the design decision should also cover future servicing from the outset. It must specify which elements may be disconnected, which activities require the protective connection to be restored, and how design changes are to be managed without losing the integrity of the whole system. A simple set of decisions helps here and should be closed out before prefabrication:
- the boundary of the power supply and responsibility in relation to the facility installation,
- PE points and parts requiring equipotential bonding,
- moving and disconnectable elements requiring special solutions,
- the scope of tests, the stages at which they are performed, and the evidence required for the technical documentation.
A sound electric shock protection architecture must include a verification method from the start. It should be agreed in advance which tests will be performed, at what stage of prefabrication, installation, and commissioning, who is responsible for them, and in what form the result will be entered into the machine’s technical documentation. A completed cabinet is tested differently from connections made on site, and differently again from a module that is reconnected to the customer’s installation after transport. From the conformity assessment perspective, what matters is not only that the test was performed, but also whether the decision logic can be reconstructed: why a given element was considered to require a protective connection, where this was shown on the schematic, how the connection point was identified, and what record confirms the effectiveness of the solution after installation. Only in that order does the reference to IEC 60204-1 bring structure to the design, execution, testing, and documentary evidence.
Practice first, then the standard
In practice, most problems arise not because someone omitted the protective conductor entirely, but because the original protection logic broke down during design, installation, or a later modification. A different split of responsibilities between the machine manufacturer, integrator, and installation contractor is enough, as is a change in how modules are mounted, the addition of a moving part, or replacement of a flexible connection without checking its protective function. That is why the effectiveness of protection is not determined by the PE symbol on the schematic alone, but by the consistency of decisions from design to acceptance.
From an organizational standpoint, a simple but rigorous structure is needed. Protective connections made inside the machine must be separated from those made on site, interfaces between modules must be described, moving parts requiring equipotential bonding must be identified, and it must be defined what is subject to repeat inspection after each configuration change. This also matters as evidence. The technical documentation should make it possible to reconstruct not only the test result, but also the design assumption, the scope of responsibility, and the boundary conditions of use. Only then can one reasonably answer whether the machine’s current condition still matches the original design assumptions.
A good example is a modular line in which each cabinet had its own protective conductor, and acceptance of the prefabricated sections revealed no irregularities. The problem became apparent only after the line was installed at the customer’s site and a conveyor with a hinged guard and a bridge between two support frames were added. The protective connection between modules was in fact based on bolted elements which, after the configuration change and painting of the surfaces, no longer ensured reliable continuity, while the moving part was given a connection too susceptible to operational damage. Formally, grounding was present, but protection as a system had ceased to be coherent. The correction therefore did not consist in adding another conductor to the report, but in rebuilding the connection points, clearly marking the inter-module connections, updating the schematics, and extending the tests after final installation; this is the kind of issue often reviewed during a safety audit.
Against this background, the role of IEC 60204-1 is clear. The standard is not a formality used to close out a project, but a practical reference point for the electrical equipment of machines. It structures the rules for protection against electric shock, protective bonding, inspection, and testing, and in doing so enforces technical discipline. However, it does not replace sound design judgment or risk analysis. It will not answer for the team how responsibility for connections between the machine and the plant infrastructure should be allocated, nor what impact a change in the mechanical design, hydraulics, or the machine cleaning method will have on protection.
In the Polish and EU context, referring to a recognised standard has not only technical but also evidential value. It shows that the manufacturer or integrator adopted a recognisable and rational standard for design and verification in the conformity assessment process. The practical conclusion is simple: the cheapest and safest grounding is not the one that can be measured after the fact, but the one designed from the outset as an integral part of the machine, its documentation, and any later changes.
Electric shock protection and machine earthing in accordance with IEC 60204-1: design decisions that reduce risk and cost
At the design stage, not only at final acceptance. The text indicates that the effectiveness of the protection is determined by the machine boundaries defined earlier, the power supply logic, and the path of the fault current.
No. The effectiveness of the protection depends on the device’s overall architecture, not just on the presence of a protective conductor or the result of a single measurement.
Not only in the control cabinet, but often on doors, operator panels, drives mounted on the structure, movable guards, conveyor sections, and between modules. That is where a connection may appear sound yet lose reliability after vibration, corrosion, or servicing.
Because it blurs the logic of protection in the event of a fault. When protective, operational, and equipotential bonding conductors are not clearly separated, the fault current may take an unintended path determined by the design or installation.
It organizes electrical solutions from the design stage through implementation and the preparation of protection documentation. This makes it easier to avoid costly rework during commissioning, modernization, conformity assessment, or after an incident.