The Short Answer
The fail-safe position is what the valve does when instrument air (or power) is lost — and it must be chosen from process safety, not convenience. An air-to-open (ATO) valve opens on air failure, so it fails open; an air-to-close (ATC) valve closes on air failure, so it fails closed. Choose the action that puts the process in its safest state on utility loss: cooling water and fuel valves usually fail open; isolation, feed, and vent valves usually fail closed (or per the hazard analysis). There is no universal right answer — the decision comes from the process hazard analysis and operating philosophy.
The Mechanics: How Fail-Safe Action Works
A spring-return pneumatic actuator has a spring that moves the valve to one end of travel when air pressure is removed:
| Actuator Action | Valve Action on Air Failure | On-Off / Control Convention |
|---|---|---|
| Air-to-open (ATO, fail closed) | Air pushes the valve open; loss of air lets the spring close it | Fails closed (FC) |
| Air-to-close (ATC, fail open) | Air pushes the valve closed; loss of air lets the spring open it | Fails open (FO) |
Important: the terms are about the air action, and the plant convention (“fail open”/”fail closed”) is about the result. When you specify, write the result: “This valve must fail closed on loss of air.” Then the actuator supplier picks ATO (spring closes it).
For electric actuators, the same fail-safe goal is achieved differently:
- A spring-return module (mechanical) drives the valve to the fail position on power loss.
- A battery backup unit (DCU) holds the electronics and drives the motor to the fail position.
- Electric valves without these modules hold position on power loss — which may or may not be acceptable.
How to Choose the Fail-Safe Position
There is no universal rule, but these questions guide the decision:
Question 1: What is the safe state of the process on utility loss?
- Cooling water / cooling medium valves: usually fail open — keep cooling flowing on an upset.
- Fuel gas / fuel valves to fired equipment: usually fail closed — cut fuel on loss of control or utilities (with the burner management system adding independent shutdown).
- Feed valves (reactant feed to reactors): usually fail closed — stop feeding on upset.
- Block/isolating valves in hazardous service: usually fail closed — contain the hazard.
- Pressure-relief and vent valves: usually fail open (where relief is needed on upset) — but relief systems are normally independent of utility air.
- Steam letdown / heat exchanger steam valves: often fail closed on the steam side to avoid overpressure/overheating, but analyze per service.
Question 2: What does the hazard analysis say?
If a formal process hazard analysis (HAZOP/LOPA) exists, the fail-safe position is typically specified there — follow it. If not, run a simple analysis: “Air fails. What is the worst that can happen if this valve is open vs. closed?” The state that avoids the worst consequence is the fail-safe position.
Question 3: Is there a plant operating philosophy?
Many plants standardize: “fail closed unless the hazard analysis says otherwise.” Others mandate specific actions for specific valve functions (e.g., all cooling water fails open). Follow the plant standard; consistency matters for operator training.
Common Choices by Service
| Valve Service | Typical Fail Position | Reason |
|---|---|---|
| Cooling water supply | Fail open (FO) | Keep cooling on upset |
| Fuel gas to furnace/boiler | Fail closed (FC) | Cut fuel on loss of utilities |
| Reactant feed to reactor | Fail closed (FC) | Stop the reaction feed |
| Steam supply to reboiler | Fail closed (FC) | Avoid overpressure/overheating (analyze) |
| Product letdown (pressure control) | Often fail closed | Contain pressure (analyze) |
| Block valve on hazardous line | Fail closed (FC) | Contain the hazard |
| Compressor recycle valve | Fail open (FO) | Avoid surge on trip |
| Blowdown / vent valve | Fail open (FO) | Relieve on upset (where appropriate) |
| Boiler feedwater | Fail closed (FC) | Avoid flooding/overfilling |
These are starting points only — each application must be verified against the hazard analysis.
Specification Pitfalls
- Saying “air-to-open” when you mean “fail closed.” The plant talks in result terms; the supplier talks in air terms. Write both: “Fail closed on loss of air; actuator to be air-to-open (spring closes).”
- Choosing by convenience (“it was cheaper that way”). Fail-safe action is a safety function; cost is not the deciding factor.
- Forgetting the intermediate positions. Some processes need a fail-last-position or a fail-to-specified-position (e.g., fail to 50% open). Specify it explicitly; it affects the actuator and the positioner hardware.
- Ignoring the time to reach the fail position. An ESD valve that takes 30 seconds to close fails its purpose; specify the required stroke time and verify it.
- Assuming electric valves fail safe. Without a spring module or battery backup, an electric actuator holds position on power loss — confirm this is acceptable, or add the fail-safe hardware.
- Not testing the fail-safe action. Spring-return actuators must be stroke-tested periodically (partial stroke or full stroke) to confirm the spring still drives the valve reliably after years of service.
Partial Stroke Testing — A Related Safety Practice
For critical fail-closed valves, partial stroke testing (PST) moves the valve partway (e.g., 10–20%) to prove it moves, then returns it — without disrupting the process. Smart positioners automate PST and log the results. This is a recognized way to increase the reliability of fail-safe valves between full stroke tests. Consider it for high-integrity pressure protection (SIL-rated) valves.
Documentation — What to Write on the Data Sheet
On the valve/actuator data sheet, state clearly:
- Fail-safe action on loss of air: FAIL CLOSED / FAIL OPEN / FAIL LAST POSITION
- Fail-safe action on loss of electrical power: (for electric: with/without backup)
- Time to reach fail position: ___ seconds (if safety-critical)
- Stroke test requirement: full stroke every ___ / partial stroke (PST) via positioner
- Actuator action: air-to-open or air-to-close (to confirm the spring direction)
Conclusion
The fail-safe position is a process-safety decision made from the hazard analysis, not an actuator preference. Decide what the process needs on air loss, write it in result terms (fail open / fail closed / fail last), confirm the spring direction on the actuator, and verify the action by periodic stroke testing. When in doubt, ask the process safety engineer — the cost of the wrong fail-safe direction can be an uncontrolled incident, not just a maintenance call.
