Shutdown Valve: Fail Action Is Not the Shutdown Command

Ryan Tanaka6 min read
Other ManufacturerSafety SystemsTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

After you separate the power-failure response from the shutdown command, the valve can hold its last position when actuator power is lost and still close when the shutdown system issues a valid trip. The two actions are independent only if the actuator, solenoid, energy source, and shutdown logic can physically produce both states.

Stop Trying the Wrong Fixes

The panel symptom is usually simple: the shutdown indication changes state, but the valve remains where it was. Or you change the documented power-failure action to “fail in last position” and then assume every loss of signal must produce the same response. Start here: separate the initiating event from the required valve action.

Symptom Likely cause
Valve holds position after total power loss The actuator traps pressure, has no stored closing energy, or is mechanically designed to fail in place.
Shutdown indication appears, but the valve does not close The trip did not operate the final control element, the closing energy is unavailable, or the shutdown path was configured around the actuator’s physical capability.
Changing the controller output does not change power-loss behavior Controller logic cannot override the actuator after its control power or motive energy is gone.
Valve closes on a shutdown test but holds during a real power failure The shutdown test retained the energy or electrical supply needed to drive the valve closed.

Changing only the output polarity wastes time if the solenoid or actuator cannot move without power. Reversing an indication tag also wastes time; it changes what the panel displays, not what the valve does. Replacing the position feedback device is not the first fix unless local observation proves that the valve moved and only the displayed position is wrong.

Separate Fail Action from Shutdown Action

Fail-safe action describes the valve assembly’s response to a defined failure. You must name that failure: loss of electrical control power, loss of instrument air, loss of hydraulic pressure, loss of command signal, or failure of a control component. Those events are not interchangeable.

A shutdown signal is an intentional command from the shutdown system. For a shutdown valve intended to stop flow, that command normally requests the closed state. A functioning shutdown path may de-energize a solenoid, energize a trip device, vent an actuator chamber, or command a powered actuator. The selected method depends on the installed hardware.

“Fail in last position” therefore does not automatically mean “ignore shutdown.” It means the valve stays near its existing position for the particular failure covered by that description. The valve can still close on a shutdown command when a separate control path and enough motive energy remain available.

Trace the Energy That Moves the Valve

The shutdown system supplies information. The actuator supplies motion. Treat those as separate paths.

  • Command path: shutdown input, shutdown logic, output channel, interposing devices, solenoid or actuator input.
  • Energy path: instrument air, hydraulic pressure, electrical actuator supply, spring force, accumulator, or another stored-energy mechanism.
  • Mechanical path: actuator linkage, stem, valve closure member, and seating force.
  • Feedback path: open and closed limit switches, position transmitter, and panel indication.

A fail-in-place pneumatic arrangement may trap pressure on the actuator when control power disappears. If the shutdown command uses the same solenoid and the same loss of power, it may produce the same hold response. Separate behavior requires a deliberate way to release, redirect, or retain motive energy during shutdown while preserving the chosen response to a general power failure.

The phrase “power failure” also needs a boundary. Loss of the controller output supply is different from loss of all site electrical power. A shutdown output backed by an independent supply may remain operational during one event but not the other. Mark those boundaries on the loop drawing before changing logic.

Define the Cause-and-Effect Before Configuring

Write the required final state for each initiating condition. Do not use one broad “signal failure” row for physically different events.

  1. Identify the process-safe position for a shutdown demand. For the case described, that state is closed to stop flow.
  2. List each credible loss separately: shutdown command, controller power, solenoid power, instrument air, hydraulic pressure, actuator power, and communications loss where applicable.
  3. Record the required valve response to each event: close, open, hold, or transfer to another control mode.
  4. Compare each required response with the actuator’s stored energy and mechanical fail action.
  5. Trace which supplies remain available during every event. Include control power and motive power.
  6. Resolve conflicting requirements before programming. If the same de-energized solenoid state is expected both to trap the actuator and to vent it closed, logic alone cannot satisfy both requirements.

This cause-and-effect definition is the design basis. “Close on shutdown, hold on loss of normal power” is a valid functional requirement, but the final element must have a shutdown path that survives the specified power-loss event. That may require segregated power, stored motive energy, or different final-element architecture. Select the arrangement through the site’s safety review and approved design process.

Test the Two Functions Independently

Use controlled functional tests. Watching the output bit change is not proof that the valve reached its required state.

  1. Place the process in an approved test condition and establish the valve at an intermediate position.
  2. Issue a shutdown demand while normal utilities are available. Confirm the command reaches the final control element and the valve travels to the required closed state.
  3. Reset through the approved sequence. Confirm that reset does not cause an unintended valve movement.
  4. Re-establish the intermediate position, then simulate the specifically defined power failure without accidentally removing unrelated supplies.
  5. Confirm that the valve holds its last position for that failure case.
  6. Repeat for each separately defined utility loss. Test electrical power loss and motive-power loss as different cases.
  7. Compare local mechanical position with shutdown-system feedback. Investigate any disagreement before returning the loop to service.

Record the initiating condition, output state, solenoid state, available motive energy, observed valve movement, and final feedback. A test that leaves normal actuator energy available proves shutdown logic only; it does not prove behavior during a total loss of utilities.

Avoid Recurring Design and Test Traps

  • Undefined failure boundary: “Power loss” is too vague. Name the lost supply and the supplies that remain.
  • Logic-only correction: Software cannot move an actuator after its required energy disappears.
  • Confusing command with confirmation: An output state proves a command was issued. Closed feedback or direct observation proves valve position.
  • Testing one event as another: Forcing a shutdown input is not the same as removing solenoid power, actuator power, or instrument air.
  • Ignoring shared components: A common solenoid, supply, or relay can make independent actions impossible even when the logic uses separate commands.
  • Uncontrolled reset behavior: Check what happens when power returns, pressure returns, or the shutdown latch resets. Restoration must not create an unreviewed opening command.

FAQ

Can a shutdown valve hold position on power failure and close on shutdown?

Yes, if the shutdown path retains the command capability and motive energy needed to close the valve. Verify the behavior separately for loss of control power, solenoid power, and actuator energy.

Does fail in last position override a shutdown signal?

No. It defines the response to a named failure, not the response to every shutdown demand. It overrides effective closure only when the failure also removes or blocks the command or energy needed to close.

Can PLC logic make a fail-in-place valve close after total power loss?

No. Logic cannot operate without its supply or move a final element without motive energy. The hardware architecture must retain or store the energy required for the closing stroke.

Does a de-energized shutdown output always close the valve?

No. The result depends on solenoid plumbing or wiring, actuator construction, available energy, and mechanical fail action. Trace the final element from output channel to valve stem.

Can I change this behavior without modifying the valve hardware?

Only when the installed actuator and solenoid arrangement already supports both actions and the problem is limited to configuration. Stop testing if drawings, observed motion, and the cause-and-effect requirement disagree; escalate to the valve or actuator manufacturer’s official support channel and the site safety authority before altering the final-element design.

Back to blog