The Failure Position and Why It Was Chosen
Why this matters
Every modulating device on a system has a position it goes to when something is taken away from it, and somebody chose that position on purpose, years ago, by asking which outcome they could least afford. A tech who does not know which loss the position was chosen against will read a device sitting wide open on a dead system as a fault, or worse, will replace a spring-return actuator with a non-spring model because it was what was on the truck, and remove a protection nobody will notice is gone until the night it was needed.
This card is mostly about what a failure position does not cover. The list of things it does cover is short and widely understood. The list of things it silently does not cover is where the callbacks live.
What "fail" actually means, and it is not one thing
"Fail-closed" is an incomplete sentence until you say what was lost.
- Loss of control signal, with power and the plant still running. The actuator is alive and knows it has no command.
- Loss of actuator power, with the plant otherwise running. The actuator is dead and only stored energy can move it.
- Loss of motive medium on a pneumatic device, meaning instrument air. Same shape as power loss.
- Plant-wide loss of power. Everything is dead, including the pumps and fans that would make the position mean something.
A spring-return device covers the second and third of those, and covers the first only if the control interface is designed to release it on signal loss rather than hold last value. A device with an internal capacitor or battery drive covers power loss for as long as its stored charge lasts and no longer. A "fail-in-place" or "last position" device covers none of them. It is not a failure position in the protective sense, it is the deliberate absence of one, chosen where the risk of moving is greater than the risk of staying put.
How the position gets chosen
The rule is the worst outcome of the loss, not the most convenient outcome for operations.
| Device | Common failure position | The outcome it was chosen against |
|---|---|---|
| Outside air damper | Closed | Freezing a wet coil with unconditioned air |
| Preheat or heating coil valve | Open | Freezing the coil with no flow through it |
| Cooling coil valve | Closed | Overcooling and condensation, and wasted plant capacity |
| Combustion fuel valve | Closed | Fuel released with no supervised ignition |
| Isolation damper on a smoke or fire path | Per the listed assembly | Life safety, and it is not a control decision at all |
| Process valve on a batch or fill path | Closed | Overfill or overflow |
Two rows on that table are not design preferences. A fuel valve closing on any loss and a listed fire or smoke damper going to its listed position are requirements of the listed assemblies and the codes that adopt them, and neither is available for a field substitution decision. Everything else is an engineering choice made against a specific hazard, which means it can be a wrong choice on a system that was later modified.
The five things a failure position does not protect against
This is the substance of the card.
A jammed driven element. A return spring is sized to overcome the device's normal operating torque plus a margin. It is not sized to overcome a seized stem, a blade frozen to its frame, a linkage bound on debris, or a valve with scale on the seat. The actuator goes home. The thing it drives does not, and no signal anywhere says so.
A broken or fatigued spring. A return spring that has cracked or lost tension gives no indication in normal service, because normal service is the motor driving against the spring, and a weak spring makes that easier rather than harder. The device operates perfectly right up until the day it is asked to do the one job the spring exists for.
A slipped coupling. Same shape. The actuator returns to its rest position and the blade or stem stays wherever it was. A sibling card covers finding this, and the finding matters here because a coupling that is loose enough to slip under motor torque will certainly slip under spring torque.
A loop that is intact and wrong. A failure position acts on loss. It has nothing to say about a controller acting confidently on a drifted sensor, a mis-scaled input or a bad sequence. The system is not failed, so nothing fails safe. This is the largest gap and the least intuitive one.
A loss bigger than the one it was designed against. The next section is this case worked through, because it is the one that surprises people who understand the other four.
Worked case: the fail-open valve that protected nothing
A hydronic preheat coil on an outside air intake. Design intent as installed: outside air damper fails closed on power loss, preheat valve fails open on power loss. The reasoning is standard and correct as far as it goes - a wet coil with no flow, exposed to freezing air, will freeze, so the valve goes open to keep water moving through the tubes.
Now take the loss the building actually had: a utility outage on a 10 degree night, three hours.
Walk it through. Control power is gone, so the damper spring drives it closed, and that part works. The valve spring drives it open, and that part works too. But the circulating pump is on the same dead building power. An open valve with a dead pump passes nothing. The protection that was supposed to keep water moving through the coil delivered a valve in the correct position and zero flow through it.
What actually protected the coil that night was the damper closing, so that the only cold air reaching the coil was leakage past the closed blades and whatever the stack effect pulled through the intake. That is a real protection, and it is the one that carried the load, and it is not the one anybody would have named if asked.
Which means the fail-open valve on this system protects against a loss of control signal with the plant running, and against a loss of actuator power with the plant running. It does not protect against the plant-wide loss it is usually described as covering. The position was right. The claim made about it was wrong.
The protections that do survive a plant-wide loss are the ones that need no power at all: a tight and well-maintained outside air damper, a coil circuit charged with freeze-protected fluid, or a coil arranged to be drained. If the risk is real on your site, one of those has to be present, and the valve's failure position is not a substitute for it.
Freeze-protected fluid, stated carefully. A glycol charge is specified as a percent concentration, and by volume and by weight are different numbers for the same fluid, so read which basis the chart uses before you mix. Roughly 30 percent propylene glycol by volume puts the freeze point somewhere near the high single digits above zero, and ethylene glycol at the same concentration lower still, but take the actual value from the manufacturer's chart for the product in the loop rather than from any rule of thumb. Note also that freeze point and burst point are two different numbers: a properly inhibited glycol solution turns to slush at its freeze point without necessarily splitting a tube, and the burst protection extends further down than the freeze point does. Both numbers are on the chart. Use the one that matches the risk you are managing.
Glycol also costs capacity. A 30 percent charge carries less heat per unit of flow than water and pumps harder, and the penalty varies with temperature and coil geometry, so a coil retrofitted to glycol has to be re-checked against the manufacturer's correction factors rather than assumed equivalent. Handle it as the SDS directs: it is a skin and eye contact hazard, and ethylene glycol in particular is acutely toxic if swallowed, so keep it out of open containers that could be mistaken for anything else and wash exposed skin rather than wiping it.
A failure position is not a protective device
This distinction is worth stating flatly because the two get conflated constantly.
A failure position is part of the control system. It defines where a control element goes when it stops receiving direction. It is a graceful-degradation feature.
A limit, a freeze stat, a pressure switch, a rollout switch and an interlock are part of the safety system. They exist to stop the machine when a condition is reached, and they act on the condition itself rather than on the loss of a signal. They are wired to remove the hazard directly, usually independent of the controller.
The two are not interchangeable, and a system that has a good failure position is not thereby protected. If a protective device on the system has opened, that device found a condition. Establish what condition reached it, on evidence, before you treat the device as the fault: replacing a correctly-operating limit reaches the same end state as jumpering it, one step slower and with a part number on the invoice.
Finding out what a device actually does, without guessing
Read the device before you read the drawing. Spring return direction is marked on most actuator housings, along with the stroke and often an arrow. The drawing records the intent; the housing records what is installed, and on a system that has been serviced a few times those are not always the same thing.
Look at the mounting, not just the model. A spring-return actuator mounted with its rest position toward the wrong end of travel returns the device to the opposite of what was specified, and it will operate correctly in every normal sequence. Confirm the rest position against the driven element, not against the actuator's own label.
Observe it during a planned shutdown rather than creating one. Do not prove a failure position by pulling power on a running system. Removing power from a device that is holding a combustion path, a pressurized path or a refrigerant-bearing path in a particular state creates a real process event, not a test. Schedule the observation into a shutdown that is already happening, with the process off and the relevant path isolated per its own procedure, and confirm the driven element arrives, not just the actuator - which means having the marks on both shafts before power comes off, and keeping hands clear of the linkage sweep as the spring drives it, under 29 CFR 1910.147 for the stored mechanical energy the spring holds.
References
- 29 CFR 1910.147 - control of hazardous energy, covering stored mechanical energy in spring-return actuators and the isolation required before working on a linkage
- NFPA 70E-2021, 120.5 - process for establishing and verifying an electrically safe work condition, where a planned shutdown involves electrical isolation
- Manufacturer documentation for actuator spring-return direction, stroke and rest position, for listed fire and smoke damper assemblies, and for glycol freeze point, burst point and heat transfer correction factors
- Safety data sheet for the specific glycol product in the loop
- See related: What an Actuator Does and How Far It Actually Went; How to Verify an Actuator Reached Its Commanded Position