Automation Glossary • 1oo2 Voting

What Is 1oo2 Voting Architecture?

Merobix Engineering • • 5 min read

1oo2 voting, read as "one out of two," is a redundant safety architecture in which either of two channels can trip the process to its safe state on its own. It is one of the simplest ways to improve the probability that a safety function acts when it is genuinely needed. The design deliberately trades a higher chance of nuisance shutdowns for a lower chance of a dangerous failure to trip. That single tradeoff is what makes 1oo2 the right choice in some plants and the wrong choice in others.

Back to Blog

1oo2 Voting in one line: 1oo2 (one out of two) is a voting architecture built from two redundant channels where a trip signal from just one channel is enough to drive the process to its safe state. Because only one of the two channels has to detect the hazard, 1oo2 lowers the chance of a dangerous undetected failure but increases the rate of spurious trips compared with a single channel or a 2oo2 arrangement.

How 1oo2 Voting Works

In a 1oo2 arrangement you install two independent measurement and logic paths, each capable of initiating the same shutdown. The voting rule is biased toward safety: if either channel calls for a trip, the final element de-energizes and the process moves to its safe state. Only when both channels agree there is no demand does the process keep running. This is the mirror image of a 2oo2 arrangement, where both channels must agree before a trip occurs.

The practical benefit is redundancy against a stuck or blind channel. If one transmitter fails in a way that hides a real hazard, the second channel still sees the deviation and trips. That is why 1oo2 is described as fault tolerant to dangerous failures: a single dangerous failure in one channel does not defeat the safety function, because the surviving channel can still act on its own.

The cost of that benefit is exposure to spurious trips. Any single channel that trips by mistake, whether from noise, drift, a failed transmitter that fails toward the trip direction, or a wiring fault, will shut the process down even though no real hazard exists. With two channels each able to trip alone, the plant sees roughly twice the nuisance trip rate of a comparable single channel.

The Safety Versus Availability Tradeoff

Every voting architecture sits on a spectrum between two competing goals: making sure the safety function trips when it must, and making sure it does not trip when it must not. 1oo2 pushes hard toward the first goal. It maximizes the chance of a safe trip on a genuine demand, which is exactly what you want when the consequence of failing to trip is catastrophic and the consequence of an occasional false trip is merely lost production.

The reliability math reflects this. In low-demand terms, 1oo2 roughly halves the probability of failure on demand relative to a single channel, because both channels would have to be in a dangerous undetected state at the same time for the function to fail. That improvement in dangerous performance is the headline reason engineers reach for 1oo2 when a single channel cannot meet the required integrity target.

At the same time, the spurious trip rate roughly doubles, so 1oo2 is a poor fit where an unplanned shutdown is itself hazardous or extremely expensive. In those situations designers move to architectures like 2oo3, which recover much of the availability while keeping strong dangerous-failure performance. Choosing 1oo2 is therefore an explicit statement that avoiding a missed trip matters more than avoiding a false one.

1oo2 in Field Operations and SCADA Monitoring

On a real site, a 1oo2 function usually appears as two transmitters on the same process point, feeding a safety logic solver that trips a shutdown valve if either reading crosses the trip setpoint. Because both channels are live and independent, operators need clear visibility into which channel initiated a trip and whether the two channels are tracking each other. A slow divergence between the two often signals a failing transmitter before it causes an unexpected shutdown.

This is where continuous monitoring earns its place. A cloud SCADA platform that trends both channels side by side lets an operations team spot a drifting or noisy sensor and schedule maintenance before it causes a spurious trip. Deviation alarms between the redundant channels turn a hidden reliability problem into an actionable maintenance item, which directly reduces the nuisance-trip penalty that comes with 1oo2.

For remote and unmanned assets, that same visibility shortens the response loop after any 1oo2 trip. Knowing instantly which channel fired, what the process was doing, and how the two channels compared helps a technician distinguish a real demand from a false one without a long site visit. Good telemetry does not change the voting logic, but it makes living with a spurious-trip-prone architecture far more manageable.

Frequently Asked Questions

Why does 1oo2 increase spurious trips?

Because each of the two channels can trip the process on its own, any single false trip in either channel shuts the process down. With two channels each capable of an independent nuisance trip, the overall rate of unwanted shutdowns is roughly double that of a single channel. This is the direct cost of the architecture favoring safe action over uninterrupted production.

When should I choose 1oo2 over a single channel?

Choose 1oo2 when a single channel cannot meet the required probability of failure on demand and when a missed trip would be far more damaging than an occasional false trip. It is common on hazards where failing to shut down risks people or major assets, and where the plant can tolerate the extra spurious shutdowns. If unwanted trips are themselves dangerous or unacceptably costly, a 2oo3 architecture is usually a better fit.

What is the difference between 1oo2 and 2oo2?

In 1oo2, either channel can trip the process alone, so it favors safety and produces more spurious trips. In 2oo2, both channels must agree before a trip, so it favors availability and resists nuisance trips but is weaker against a dangerous failure that blinds one channel. They are opposite ends of the two-channel tradeoff, and 2oo3 exists partly to blend their strengths.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
2oo3 Voting  •  Proof Test  •  Proof Test Coverage  •  Safe State  •  Demand Mode  •  Process Safety Time  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →