OK, I see your point, I missed that one in the your message since it was very long post, I apologize (it was mixed message about standards and description of your system).
Well, safety is about calculating the percentage of risk, and as you know, it can never be zero. If it would have to be zero, e.g. cars would not be manufactured because they can kill humans (you cannot say there is 0% risk that car will kill a human). Therefore, the logic is what is the highest percantage of killed humans by car to be acceptable by the society. It sounds awful, but that is how the metrics can be given to safety risk calculation when you design the specific system. Now how low number is acceptable is not always the same for everyone/every society (different apporaches/politics/laws/cultures).
So, one can add the safety feature to the system (i.e. boat AC electrical installation), e.g. to prevent human death in case system (AC boat electrical installation) fails. For some that is sufficient. For others, they probably wanted to also add additional safety in case primary safety mechanism fails (they wanted to increase the safety or i.e. to decrease the safety risk probability).
So primary safety feature for the boat electrical system, in case AC system fails is ELCI/GFCI/RCD. Additional safety mechanism can be added to the system in case ELCI/GFCI/RCD fails (and it is plausable on boats, due to unfriendly environment, especially if houshold equipment is used, which often is in case of AC systems on boats => often without required IP protection for the given conditions).
Theoretically, if you have RCD, as soon as current difference between hot AC wires i.e. leakage is detected, it will trip and prevent the presence of AC on the affected component and protect your life. In case RCD fails, then at least, the circuit breaker/fuse will react and prevent fire in addition (fuse most often has too high current rating to protect human life). Now, where you could go into philosophy is if RCD fails, is it the higher probability that circuit breaker/fuse will be activated first or human will be killed first. And the question can extend do you want to protect the person or also the asset? Then you come to the discussions about the law, insurance, etc. By reading different materials, I have a feeling that USA is much more stringent than EU regarding insurance and asset protection in general and that could also be the reason for more stringent rule(s).
Mind that adding more and more features is rising the costs, not only by adding equipment, but also by doing the math about these probabilities. Of course, in this case where safety feature is adding simple connection between AC and DC, I personally am for more conservative US approach (also I do consider that it is higher probability that fuse will trip before I would be killed - most often when you arrive on the boat, you first enable something/whatever by the means of an insulated switch). But, if you ask manufacturer who needs to manufacture e.g. milion pieces of something, this additional task is really adding to the costs (the labor, the materials, etc.), therefore, manufacturers would probably select ISO if possible.
Oh, and let's not forget the interpretation of sentences in the standards, because they can have legal consequences - e.g. in case of ABYC
it is required so if you do not add it you are legally responsible if the second mechanism was lacking or fails, while in case of ISO it says
not required, but you are allowed to add it and you will not be legally responsible even if the second machanism fails, but still your reputation could be on the stake. It could be a million dollar question for some or one hour of easy work for one private person, do you agree? So, what to do becomes a very specific question for the person who is asking that question.
And yes, have a great day!
