How Do I Interlock a Boiler Room CO Sensor Safely?

David Krause7 min read
Best PracticesOther ManufacturerSafety Systems
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Carbon monoxide (CO) is a toxic combustion product measured as a concentration in air. A CO detector can initiate an alarm or boiler shutdown, but those functions are not interchangeable. The required functions, setpoints, delays, reset method, and legal status depend on the governing jurisdiction and the approved boiler-room design.

Governing requirement

No universal legal requirement or minimum shutdown concentration can be established from the installation description. Requirements vary by jurisdiction, building classification, fuel system, boiler equipment, and adopted rules. Historical inspection practice in several northeastern US states did not identify a general boiler-room CO-interlock requirement, but that observation does not decide the current requirement for another location.

The authority having jurisdiction is the organization that interprets and enforces the applicable requirements for the site. Before selecting hardware or a setpoint, obtain a written decision from that authority and compare it with the boiler manufacturer’s instructions, detector documentation, combustion-control design, and facility safety requirements.

Question Required reading or record Decision
Is CO detection mandatory? Current requirement accepted by the authority having jurisdiction If mandatory, implement every specified alarm, shutdown, reset, and supervision function. If not mandatory, document the engineered basis for any voluntary interlock.
What concentration initiates an alarm? Approved alarm setpoint and any specified delay Program only the approved value; do not derive it from an informal rule of thumb.
What concentration shuts down the boiler? Approved trip setpoint, delay, and affected equipment list Treat this as a separate safety action unless the approved design explicitly combines it with the alarm.
What happens on detector failure? Approved fault response Apply the specified alarm, shutdown, or maintenance response rather than treating a fault as a valid zero-CO reading.

Interlock mechanism

A detector samples the room atmosphere and produces status outputs such as normal, alarm, trip, or fault. The boiler safety circuit or an approved safety controller then removes the burner-permissive condition when the trip logic becomes true. A shutdown output should act through the burner’s designated safety input; it should not imitate a routine operating command or depend solely on a supervisory display.

Use a fail-safe signal arrangement where the approved design calls for one. In a typical de-energize-to-trip architecture, loss of detector power, a broken interlock conductor, or removal of the relay changes the permissive state instead of leaving the burner enabled. Detector fault and high-CO trip remain distinct conditions so maintenance personnel can diagnose the initiating event.

Room concentration is not necessarily uniform. Detector position, air inlets, exhaust flow, heat sources, partitions, and combustion-air movement affect what reaches the sensing element. Placement therefore comes from the detector instructions and the approved room assessment, not from a convenient mounting location.

Check 1: Required functions and setpoints

Check 1: read the approved design documents and the current jurisdictional determination. Expect a defined answer for each controlled function: local indication, remote alarm, boiler shutdown, ventilation response, latching, reset, detector fault, and loss of power.

  • If the documents define all functions and setpoints, continue to Check 2.
  • If they specify detection but omit the shutdown threshold or delay, stop configuration and obtain a design decision.
  • If the alarm value is defined but no trip value is given, do not silently use the alarm value as the shutdown value.
  • If no mandate applies, complete a hazard assessment before adding an interlock. An improvised shutdown can create process hazards or conflict with the burner safety sequence.

The term setpoint here means the concentration at which a defined detector output changes state. The term delay means the approved persistence time before that state initiates an action. A displayed concentration, an alarm setpoint, and an exposure limit serve different purposes; one must not be substituted for another without an approved engineering basis.

Checks 2 and 3: Detector and shutdown path

Check 2: inspect the detector data, installation, and live diagnostics. Expect the detector to be suitable for the environment, within its documented service and calibration status, powered normally, free of fault indication, and installed at the approved locations.

  • If the detector reports normal status and its calibration check passes, continue to Check 3.
  • If it reports fault, expired service status, loss of power, or failed calibration, repair or replace it before testing shutdown logic.
  • If location differs from the approved plan or installation instructions, correct the placement before accepting concentration readings.

Check 3: trace the complete trip path from detector output to burner permissive. Expect the electrical drawings, terminal identification, relay state, controller indication, and field wiring to agree. Confirm which boilers and auxiliary devices the interlock controls.

  • If the trip output reaches the designated safety input and the logic matches the cause-and-effect record, continue to the resolving procedure.
  • If the signal reaches only a building-management or operator-display input, the installation has monitoring but no proven shutdown path.
  • If a general-purpose controller performs an assigned safety function without approval in the design, refer the architecture for engineering review.
  • If bypasses exist, identify their authorization, indication, time control, and restoration method. An undocumented jumper defeats the safety function.

Resolving procedure

  1. Record the jurisdictional decision and approved alarm, trip, delay, latching, reset, fault, and power-loss requirements.
  2. Select and locate the detector according to its instructions and the approved room assessment. Include every sensing point required to represent the occupied and combustion-equipment areas.
  3. Connect the detector’s defined output to the burner or boiler safety input identified by the equipment design. Preserve separation between routine control, warning alarm, high-CO trip, and detector fault.
  4. Configure the alarm and shutdown functions with the approved values. Where the design requires a latched trip, require a deliberate reset after the initiating condition clears.
  5. Make reset conditional on a normal detector state and satisfaction of the boiler’s normal restart permissives. A reset must not bypass purge, flame supervision, fuel safety, or other burner sequencing.
  6. Update wiring drawings, the cause-and-effect record, setpoint register, calibration record, test method, and bypass-control procedure.

Do not prove the function by exposing personnel to combustion products or creating uncontrolled CO. Use the detector manufacturer’s approved test method or a controlled input simulation identified in the commissioning procedure. Coordinate any burner trip with operations because removing heat or fuel can affect the process.

Numbered verification checks

  1. Normal-state check: expect no detector fault, no CO alarm, the intended interlock relay state, and a valid burner permissive when every other boiler condition is normal.
  2. Alarm check: apply the approved test stimulus and expect the local and remote alarm outputs to change at the configured alarm criterion.
  3. Trip check: advance the approved simulation to the shutdown criterion and expect the burner permissive to be removed after the configured delay. Confirm every boiler assigned to the cause is affected.
  4. Latched-state check: remove the stimulus and expect the shutdown to remain latched if manual reset is specified.
  5. Reset check: restore a normal detector state, perform the authorized reset, and expect the permissive to return only after all normal boiler restart conditions are satisfied.
  6. Fault-path check: simulate the approved detector fault or signal-circuit failure and expect the specified fault indication and protective response.
  7. Power-loss check: use the approved isolation method and expect the documented loss-of-power response; restoration must not cause an uncontrolled burner restart.

Frequently asked questions

How do I determine whether a boiler room CO interlock is required?

Ask the authority having jurisdiction for the current requirement applicable to the site, then compare it with the boiler, detector, and approved design documents. Record whether CO detection must provide an alarm, shutdown, fault response, or some combination.

How do I choose the boiler room CO shutdown setpoint?

Use the value and delay accepted for the installation by the authority having jurisdiction and the responsible engineer. Do not substitute an exposure limit, detector default, or alarm setpoint for a shutdown criterion.

How do I wire a CO detector to stop a boiler?

Route the detector’s defined trip output through the approved interlock architecture to the burner’s designated safety input. Verify that loss of power, detector fault, alarm, and trip each produce the documented response.

How do I complete the final CO interlock verification?

Apply the approved controlled test stimulus, expect the configured alarm and trip sequence, clear the stimulus, test the specified reset, and record the detector reading, output state, burner-permissive state, delay, and test result.

Back to blog