Signalling and train-control integration testing
The control system, the trains and the infrastructure proved together - and independently checked at every step.
Last updated 2026-09-05

What is Signalling and train-control integration testing?
Signalling and train-control integration testing is the most assurance-heavy activity on any railway project. Everything before it proved that individual parts worked. This proves that the control system, the trains and the infrastructure behave correctly as one, in every state the railway can be in - normal running, degraded operation, equipment failure, emergency, and the transitions between them. Because the signalling system is what keeps trains apart, an error here has a different order of consequence from an error anywhere else, and the entire process is structured around that fact.
The work is done under a regime of independent checking. The people who design the control data are not the people who check it, and the people who test it are not the people who accept it. Every function is traced from the requirement, through the design, through the data, to the test that demonstrates it, and back again. Independent checkers verify the correspondence at each step. Competence is formally recorded for every person involved. This is slower and more expensive than any other form of testing on the project, and it is the reason railway signalling has the safety record it does.
In practice the testing is layered. Laboratory and simulator testing proves the control logic and the data against a modelled railway long before anything is installed, and catches the great majority of errors where they are cheap to correct. Site testing then proves that the real equipment corresponds to what was tested - that the points on the ground are the points in the data, that the detection reports the state it should, that every route sets and locks as designed. Integration with the trains follows, proving the on-board equipment against the trackside and the control centre. The volume of this work is what makes it the item most likely to determine the opening date, and it is the reason projects invest heavily in simulation to take work off the critical path.
How does Signalling and train-control integration testing work, step by step?
- 1
Step 1: Establish the assurance regime before any data is written
The independent checking regime is defined at the outset: which roles exist, who is competent to hold them, how independence is maintained, what evidence each role produces and how it is recorded. Requirements are captured and made traceable so that every function can be followed from the operating concept through to the test that proves it. Nothing about this regime is created as the work proceeds - it is agreed with the operator, the infrastructure manager and the independent assurance parties first, because retrospective assurance is not assurance.
- 2
Step 2: Design and independently check the control data
The signalling design and the control data that implements it are produced from the scheme plan and then checked independently against it. The checker works from the same requirement and confirms correspondence rather than reviewing the designer's reasoning. Errors found are corrected and rechecked. Version control is absolute from this point onwards, because from here on every test result is only valid for the specific version of data it was carried out against.
- 3
Step 3: Prove the logic in the laboratory and on simulators
The control system is tested against a simulated railway before it reaches site. Every route, every signal aspect sequence, every point movement, every locking and every interlocking condition is exercised systematically, including the conditions that should be refused. Simulation makes it possible to test states that would be difficult, expensive or unsafe to create on the real railway, and to test them repeatedly. Most data errors are found here, which is exactly where they should be found.
- 4
Step 4: Prove correspondence between the data and the ground
Site testing establishes that the physical railway matches what was tested in the laboratory. Every point machine, every detection device, every signal and every piece of trackside equipment is proved to be the one the data believes it is, connected as designed, and reporting the state it actually has. This correspondence testing is painstaking and it is the step that catches installation and wiring errors that no amount of laboratory testing could reveal. It is witnessed and signed function by function.
- 5
Step 5: Integrate the on-board and trackside systems
The train-borne equipment is then proved against the trackside and the control centre together: the train receiving its movement authority, responding to it correctly, reporting its position and state, and behaving as designed at the boundaries between control areas or between different systems. Transitions are tested particularly hard, because handover between systems and between areas is where the interfaces are most complex and where most integration problems are found.
- 6
Step 6: Test degraded and failure conditions deliberately
Normal operation is the easy part. The testing that matters proves what happens when things go wrong: equipment failures, communication loss, power loss, a train stopped where it should not be, conflicting commands, and the recovery from each. Failure conditions are introduced deliberately and the response is observed and recorded. The operator's degraded-mode procedures are exercised alongside the technical response, because the safe outcome depends on the people as much as the system.
- 7
Step 7: Test with the operators who will use it
Signallers, controllers and drivers take part in the testing, using the real interfaces to carry out real operating tasks. This proves the human side of the system - whether the displays are legible under pressure, whether the alarms are manageable, whether the procedures make sense to the people executing them - and it builds the operational familiarity that trial running will later depend on. Comments from operators at this stage are treated as findings, not as preferences.
- 8
Step 8: Assemble the safety case evidence
The output of integration testing is the core of the evidence supporting entry into service: the traceability from requirement to test, the independent check records, the test results against a controlled data version, the competence records, and the disposition of every outstanding item. It is reviewed by the independent assurance parties and by the operator. Entry into service is a formal authorisation granted on the strength of this evidence, and no amount of programme pressure substitutes for it.
What are the benefits of Signalling and train-control integration testing?
- Proves the complete control system in the conditions that matter, including the ones that never occur in normal running
- Independent checking catches errors that the originating designer would not find in their own work
- Simulation removes a large proportion of the testing from the critical path and from the physical railway
- Full traceability from requirement to test result gives a defensible assurance case
- Deliberate failure testing proves the recovery paths before passengers depend on them
- Involving signallers, controllers and drivers builds operational competence during testing rather than after it
- Produces a controlled baseline against which every future modification will be assessed
What are the limitations of Signalling and train-control integration testing?
- The slowest and most expensive testing activity on a railway project, and usually the critical path to opening
- Depends on a small pool of formally competent signalling testers who are shared across the industry
- Any change to the control data invalidates completed testing and forces retesting to a defined extent
- Requires extensive access to the railway and to the trains, usually at night
- Laboratory testing can only prove what the simulation models, so site correspondence testing remains unavoidable
- Interfaces between systems from different suppliers are where most problems are found and are commercially difficult
- The documentation volume is enormous and its control is a project risk in itself
What is Signalling and train-control integration testing best suited for?
What plant does Signalling and train-control integration testing need?
- Signalling laboratory and simulation facilities modelling the control system and the railway
- Test equipment for interlocking, detection, point operation and signal proving
- Control centre workstations and replica operator interfaces for testing with staff
- Train-borne test equipment and data recorders
- Communications test and coverage equipment for the train-to-trackside links
- Configuration and version control systems for design data, software and test records
- Test trains and paths for the on-track integration stages
How is Signalling and train-control integration testing quality-checked?
- Independent checking regime defined, with roles, competence and independence recorded before work starts
- Full traceability maintained from requirement through design and data to test result
- Control data version recorded against every test, with no result accepted against a superseded version
- Correspondence between the data and the physical equipment proved and witnessed function by function
- Degraded and failure conditions tested deliberately, with results recorded and reviewed
- Competence records held for every person carrying out or witnessing signalling tests
- Change control applied rigorously, with the retest scope assessed and agreed for every change
- Evidence reviewed and accepted by the independent assurance parties and the operator before entry into service