Beyond the Battery: Why Insurers Want a Hazard Mitigation Analysis Before They'll Cover Your BESS
Share
Battery energy storage systems (BESS) are becoming central to data-center resilience. They can support UPS systems, reduce generator dependence, manage peak demand, and help facilities ride through grid disturbances. But a BESS is not simply a larger battery cabinet. It is a high-energy electrical and fire-risk installation that can affect property damage, business interruption, emergency response, and insurance capacity.
That is why insurers increasingly want more than a product datasheet and a certificate of installation. They want evidence that the facility understands how the system could fail, what those failures could affect, and whether the proposed safeguards will work under credible worst-case conditions. A site-specific Hazard Mitigation Analysis (HMA) provides that evidence.
Why insurers are looking beyond battery capacity
For years, battery procurement discussions focused on capacity, runtime, chemistry, and lifecycle cost. Those factors still matter, but they do not fully describe risk.
A modern BESS may contain hundreds of battery modules, power-conversion equipment, control systems, cooling equipment, and interconnected electrical components. If a cell enters thermal runaway, heat and gases can propagate through modules or racks. Depending on the design, the event may also produce smoke, toxic gases, flammable gases, flame projection, or overpressure.
For a data center, the consequences can extend far beyond the battery enclosure:
- Damage to electrical rooms, switchgear, or UPS equipment
- Smoke migration into white space or network areas
- Loss of cooling or fire-protection systems
- Extended business interruption
- Delayed emergency response because responders lack accurate system information
- Reignition after the initial event
- Contamination from firewater runoff or damaged battery materials
An HMA gives an insurer a structured way to evaluate these scenarios. It also helps the Authority Having Jurisdiction (AHJ): typically the local fire marshal, building official, or code authority: review whether the installation meets applicable requirements.
The National Fire Protection Association’s NFPA 855 resources provide the primary U.S. framework for stationary energy storage systems. Depending on the jurisdiction and project configuration, the HMA may also need to align with the International Fire Code, local amendments, manufacturer testing, and insurer-specific engineering guidance.

What an HMA actually evaluates
An HMA is not a generic safety checklist. It is a site-specific engineering analysis that connects hazards, consequences, and mitigation measures.
A strong HMA normally evaluates:
1. Thermal runaway and propagation
The analysis should explain how thermal runaway could begin and whether it could spread from one cell to a module, rack, cabinet, container, or adjacent system.
Relevant evidence may include:
- Battery chemistry and module construction
- Battery management system safeguards
- Cell, module, unit, and installation-level test results
- Heat-release data
- Flame behavior and duration
- Propagation between adjacent modules or racks
- Automatic shutdown and fault-isolation sequences
UL 9540 and UL 9540A-related test data are often important inputs. UL 9540 addresses system-level safety listing, while UL 9540A is a test method used to characterize thermal runaway, fire propagation, gas generation, and explosion hazards.
The HMA should not merely state that testing was completed. It should explain how the test results apply to the actual site design. A test performed on one enclosure configuration may not automatically validate a different rack layout, module size, state of charge, or ventilation arrangement.
2. Gas generation and explosion potential
Thermal runaway can generate flammable and toxic gases. The HMA should identify the expected gas composition, release rate, accumulation zones, and potential ignition sources.
The analysis should address:
- Gas detection locations and alarm setpoints
- Mechanical ventilation capacity
- Automatic exhaust activation
- Deflagration venting or pressure relief
- Isolation of BESS exhaust from data-hall air systems
- Prevention of gas migration into occupied or critical areas
- Electrical equipment classification where applicable
Ventilation assumptions should be supported by test data and engineering calculations: not by a generic air-change number. Where the BESS is located inside a room or container, the HMA should demonstrate how gas concentrations remain below applicable flammability or exposure thresholds under the selected failure scenario.
3. Fire spread and physical separation
Location is one of the most important controls in an insurance review. A BESS positioned outside the primary data-center building may present a lower business-interruption risk than a system located inside or directly below a critical electrical room.
Common design considerations include:
- Separation from data halls, electrical rooms, generators, and cooling plants
- Separation from doors, windows, intake openings, and roof overhangs
- Fire-rated walls and floors
- Noncombustible construction
- Rack-to-rack spacing and barriers
- Access for emergency responders
- Protection from flooding, vehicle impact, seismic events, and severe weather
Some insurer guidance uses benchmarks such as 25 feet from critical building exposures, 10 feet between BESS containers, or a two-hour fire-rated assembly where reduced separation is proposed. These are not universal substitutions for code review. The applicable distance depends on the equipment, test data, site conditions, jurisdiction, and carrier requirements.
For lithium-ion systems, FM Global’s Data Sheet 5-33 is an example of insurer engineering guidance that addresses construction, separation, detection, suppression, operations, and maintenance.
How to build an HMA that satisfies both the AHJ and the underwriter
The best approach is to develop one coordinated technical package rather than creating a code submission for the AHJ and a separate, weaker document for the insurer.
1. Define the system and its relationship to the facility
Start with a clear project description:
- Total energy capacity in kWh or MWh
- Maximum power output in kW or MW
- Battery chemistry and manufacturer
- Number of racks, cabinets, containers, or rooms
- State-of-charge limits
- BESS function: UPS support, peak shaving, microgrid operation, or backup
- Distance from critical loads
- Electrical interconnection and protection scheme
For AI and high-density computing environments, identify the affected load profile. A data hall with 30–100 kW per rack has a very different continuity risk than a conventional enterprise room. The HMA should show how a BESS event could affect UPS systems, cooling, network rooms, and redundant power paths.
2. Map credible failure scenarios
Use a bow-tie or equivalent risk methodology. On the left, document initiating events such as:
- Internal cell defect
- Overcharge or overtemperature
- Cooling failure
- BMS malfunction
- Ground fault or short circuit
- Physical damage
- Flooding or water intrusion
- Control-system or communications failure
In the center, define the top event: for example, uncontrolled thermal runaway in one BESS container. On the right, map consequences and mitigation barriers:
- Detection
- Shutdown
- Isolation
- Ventilation
- Suppression
- Fire-rated separation
- Emergency response
- Business-continuity procedures
This format is easy for both an AHJ and an insurer to review because it shows not only what can go wrong, but also which barriers are expected to prevent escalation.
3. Connect every mitigation to evidence
Avoid unsupported statements such as “the system is safe” or “the BMS prevents propagation.” Instead, identify the evidence behind each claim:
- UL 9540 listing
- UL 9540A test results
- Manufacturer failure-mode and effects analysis
- Fire modeling or computational fluid dynamics
- Electrical coordination studies
- Ventilation calculations
- Sprinkler hydraulic calculations
- Factory acceptance and commissioning records
- Remote monitoring and alarm-response procedures
Where an HMA proposes a performance-based alternative to a prescriptive requirement, include the engineering justification and clearly identify residual risk.
4. Address fire protection in practical terms
Insurers typically want to know how the facility will detect, control, and respond to a battery event. Depending on the installation, this may include:
- Smoke, heat, flame, and gas detection
- Continuous temperature monitoring
- Automatic fire alarm notification
- Wet-pipe sprinkler or water-based protection
- Exposure protection for adjacent equipment
- Deflagration venting
- Emergency shutdown
- Fire department connections and responder access
- Water supply duration and runoff management
FM guidance for lithium-ion BESS, for example, has used sprinkler criteria of approximately 0.30 gpm/ft² over the room area, plus a hose-stream allowance. The exact design must be confirmed by the project fire-protection engineer, adopted code, and insurer.
Clean-agent systems should not automatically be treated as a complete substitute for water-based protection in lithium-ion BESS applications. They may protect surrounding electronics, but they do not necessarily stop battery thermal runaway.
5. Include operations, monitoring, and lifecycle controls
A technically sound installation can still create an underwriting problem if operating procedures are incomplete.
Document:
- 24/7 alarm routing and escalation
- Battery state-of-health and state-of-charge monitoring
- Preventive maintenance
- Thermal imaging and inspection schedules
- Firmware and control-system change management
- Emergency shutdown procedures
- First-responder training
- Battery replacement and end-of-life handling
- Post-event inspection and re-energization criteria
Remote monitoring should be integrated into the facility’s broader power-management strategy. A UPS or BESS that reports temperature, voltage, current, state of charge, and state of health in real time gives operators a better opportunity to identify abnormal conditions before they become an outage or fire event.
Common HMA gaps that delay coverage
Coverage delays often result from incomplete documentation rather than a fundamentally unsafe design. Common gaps include:
-
Generic analysis instead of site-specific analysis. A vendor brochure cannot replace an evaluation of the actual building, exposures, layout, and operating model.
-
Missing or mismatched test data. The HMA references UL 9540A, but the test configuration does not match the proposed battery enclosure or module design.
-
No business-interruption analysis. The document describes fire controls but does not explain what happens to UPS paths, cooling, network connectivity, or critical operations.
-
Unclear emergency procedures. The fire department has not received site plans, shutdown instructions, access information, or battery-specific response guidance.
-
Unsupported ventilation or separation assumptions. The HMA lists distances or airflow rates without showing the calculations and performance basis.
-
No lifecycle plan. Maintenance, remote monitoring, inspection, battery replacement, and incident reporting are absent.
The Real-Time Solutions approach
BESS safety and insurability should be addressed during design: not after equipment arrives on site. Ace Real Time Solutions helps data-center and business customers evaluate power protection requirements across UPS systems, batteries, monitoring, electrical distribution, and ongoing support.
That is the standard for modern Real-Time Solutions: connect power continuity, safety engineering, remote visibility, and operational resilience into one design.
Visit acerts.com to request an enterprise solution design, review battery solutions, or connect with the team for a power audit. A coordinated design package can help your facility satisfy the AHJ, give underwriters the evidence they need, and reduce the risk that a power-protection project becomes an insurance bottleneck.
FAQ
What is a Hazard Mitigation Analysis for a BESS?
A Hazard Mitigation Analysis is a site-specific engineering assessment of how a battery energy storage system could fail and how design, detection, ventilation, fire protection, separation, monitoring, and emergency procedures will limit the consequences. It is commonly used to support AHJ approval and insurer underwriting.
How does an HMA help a data center obtain BESS insurance coverage?
An HMA gives underwriters documented evidence about thermal runaway, gas generation, fire spread, explosion potential, physical separation, suppression, emergency response, and business-interruption exposure. It helps the insurer evaluate both the likelihood of an event and the probable severity of a loss.
How does UL 9540A support an HMA?
UL 9540A testing provides technical data about battery fire behavior, thermal runaway propagation, heat release, gas generation, flame extension, and explosion hazards. Engineers can use that data to support ventilation, separation, detection, suppression, and containment decisions for the proposed BESS installation.