Fail-Safe Position: Air-to-Open vs. Air-to-Close Explained

The Short Answer

The fail-safe position is what the valve does when instrument air (or power) is lost — and it must be chosen from process safety, not convenience. An air-to-open (ATO) valve opens on air failure, so it fails open; an air-to-close (ATC) valve closes on air failure, so it fails closed. Choose the action that puts the process in its safest state on utility loss: cooling water and fuel valves usually fail open; isolation, feed, and vent valves usually fail closed (or per the hazard analysis). There is no universal right answer — the decision comes from the process hazard analysis and operating philosophy.

The Mechanics: How Fail-Safe Action Works

A spring-return pneumatic actuator has a spring that moves the valve to one end of travel when air pressure is removed:

Actuator Action Valve Action on Air Failure On-Off / Control Convention
Air-to-open (ATO, fail closed) Air pushes the valve open; loss of air lets the spring close it Fails closed (FC)
Air-to-close (ATC, fail open) Air pushes the valve closed; loss of air lets the spring open it Fails open (FO)

Important: the terms are about the air action, and the plant convention (“fail open”/”fail closed”) is about the result. When you specify, write the result: “This valve must fail closed on loss of air.” Then the actuator supplier picks ATO (spring closes it).

For electric actuators, the same fail-safe goal is achieved differently:

  • A spring-return module (mechanical) drives the valve to the fail position on power loss.
  • A battery backup unit (DCU) holds the electronics and drives the motor to the fail position.
  • Electric valves without these modules hold position on power loss — which may or may not be acceptable.

How to Choose the Fail-Safe Position

There is no universal rule, but these questions guide the decision:

Question 1: What is the safe state of the process on utility loss?

  • Cooling water / cooling medium valves: usually fail open — keep cooling flowing on an upset.
  • Fuel gas / fuel valves to fired equipment: usually fail closed — cut fuel on loss of control or utilities (with the burner management system adding independent shutdown).
  • Feed valves (reactant feed to reactors): usually fail closed — stop feeding on upset.
  • Block/isolating valves in hazardous service: usually fail closed — contain the hazard.
  • Pressure-relief and vent valves: usually fail open (where relief is needed on upset) — but relief systems are normally independent of utility air.
  • Steam letdown / heat exchanger steam valves: often fail closed on the steam side to avoid overpressure/overheating, but analyze per service.

Question 2: What does the hazard analysis say?

If a formal process hazard analysis (HAZOP/LOPA) exists, the fail-safe position is typically specified there — follow it. If not, run a simple analysis: “Air fails. What is the worst that can happen if this valve is open vs. closed?” The state that avoids the worst consequence is the fail-safe position.

Question 3: Is there a plant operating philosophy?

Many plants standardize: “fail closed unless the hazard analysis says otherwise.” Others mandate specific actions for specific valve functions (e.g., all cooling water fails open). Follow the plant standard; consistency matters for operator training.

Common Choices by Service

Valve Service Typical Fail Position Reason
Cooling water supply Fail open (FO) Keep cooling on upset
Fuel gas to furnace/boiler Fail closed (FC) Cut fuel on loss of utilities
Reactant feed to reactor Fail closed (FC) Stop the reaction feed
Steam supply to reboiler Fail closed (FC) Avoid overpressure/overheating (analyze)
Product letdown (pressure control) Often fail closed Contain pressure (analyze)
Block valve on hazardous line Fail closed (FC) Contain the hazard
Compressor recycle valve Fail open (FO) Avoid surge on trip
Blowdown / vent valve Fail open (FO) Relieve on upset (where appropriate)
Boiler feedwater Fail closed (FC) Avoid flooding/overfilling

These are starting points only — each application must be verified against the hazard analysis.

Specification Pitfalls

  1. Saying “air-to-open” when you mean “fail closed.” The plant talks in result terms; the supplier talks in air terms. Write both: “Fail closed on loss of air; actuator to be air-to-open (spring closes).”
  2. Choosing by convenience (“it was cheaper that way”). Fail-safe action is a safety function; cost is not the deciding factor.
  3. Forgetting the intermediate positions. Some processes need a fail-last-position or a fail-to-specified-position (e.g., fail to 50% open). Specify it explicitly; it affects the actuator and the positioner hardware.
  4. Ignoring the time to reach the fail position. An ESD valve that takes 30 seconds to close fails its purpose; specify the required stroke time and verify it.
  5. Assuming electric valves fail safe. Without a spring module or battery backup, an electric actuator holds position on power loss — confirm this is acceptable, or add the fail-safe hardware.
  6. Not testing the fail-safe action. Spring-return actuators must be stroke-tested periodically (partial stroke or full stroke) to confirm the spring still drives the valve reliably after years of service.

Partial Stroke Testing — A Related Safety Practice

For critical fail-closed valves, partial stroke testing (PST) moves the valve partway (e.g., 10–20%) to prove it moves, then returns it — without disrupting the process. Smart positioners automate PST and log the results. This is a recognized way to increase the reliability of fail-safe valves between full stroke tests. Consider it for high-integrity pressure protection (SIL-rated) valves.

Documentation — What to Write on the Data Sheet

On the valve/actuator data sheet, state clearly:

  • Fail-safe action on loss of air: FAIL CLOSED / FAIL OPEN / FAIL LAST POSITION
  • Fail-safe action on loss of electrical power: (for electric: with/without backup)
  • Time to reach fail position: ___ seconds (if safety-critical)
  • Stroke test requirement: full stroke every ___ / partial stroke (PST) via positioner
  • Actuator action: air-to-open or air-to-close (to confirm the spring direction)

Conclusion

The fail-safe position is a process-safety decision made from the hazard analysis, not an actuator preference. Decide what the process needs on air loss, write it in result terms (fail open / fail closed / fail last), confirm the spring direction on the actuator, and verify the action by periodic stroke testing. When in doubt, ask the process safety engineer — the cost of the wrong fail-safe direction can be an uncontrolled incident, not just a maintenance call.

发表评论

您的邮箱地址不会被公开。 必填项已用 * 标注

滚动至顶部