Automation Glossary • Dangerous Undetected Failure

What Is a Dangerous Undetected Failure?

Merobix Engineering • • 6 min read

Of all the ways a safety system can fail, one category is uniquely troublesome: the failure that both prevents the system from doing its job and gives no sign that it has happened. It sits silently in a valve or sensor, doing no harm until the day a real demand arrives and the protection does not respond. This is the dangerous undetected failure, and it is the failure class that drives most of the effort in safety design. This guide explains what a DU failure is, how it sits among the other failure categories, why it dominates the failure-probability calculation, and how it is shrunk.

Back to Blog

Dangerous Undetected Failure in one line: A dangerous undetected failure, often written DU and represented by the rate lambda-DU, is a failure that would prevent a safety function from acting on demand and that the system's own diagnostics do not detect. Because nothing reveals it, it stays hidden until a proof test finds it or a real demand exposes it. Dangerous undetected failures accumulate between proof tests and are the main contributor to a safety function's average probability of failure on demand.

The Failure Quadrant: Where DU Sits

Every failure of a safety device can be sorted along two questions, and the two together make a quadrant. The first question is whether the failure is dangerous or safe: a dangerous failure tends to prevent the safety function from acting when needed, while a safe failure tends toward the safe state, at worst causing a spurious trip. The second question is whether the failure is detected or undetected: a detected failure is revealed by the system's automatic diagnostics, while an undetected one is not. Combining them gives four classes - safe detected, safe undetected, dangerous detected, and dangerous undetected.

Three of the four are, in their own way, manageable. Safe failures do not compromise protection. A dangerous detected failure is dangerous, but because diagnostics reveal it, someone can be alerted and the fault repaired - or the system can take a defined action - before a demand arrives. The dangerous undetected failure is the one that combines the worst of both axes: it defeats the safety function, and nothing tells you it has happened. It is the category that requires the most care precisely because it is silent.

Placing a failure in the DU quadrant is the heart of a device's failure analysis. When reliability engineers characterise a valve, sensor, or logic solver, splitting the total failure rate into these categories - and especially estimating the dangerous undetected rate - is what determines how safe the device really is in service. A device with a low DU rate is one whose dangerous failures are mostly caught by diagnostics rather than left to hide.

Why Lambda-DU Dominates the Probability of Failure

The reason dangerous undetected failures matter so much is arithmetic. A safety function's average probability of failure on demand depends heavily on how long a dangerous failure can sit hidden before it is found. A dangerous detected failure is found almost immediately by diagnostics, so it contributes little. A dangerous undetected failure is found only at the next proof test, so on average it lies dormant for a large fraction of the interval between tests. That long dormancy is what makes lambda-DU the dominant term in the calculation.

The consequence is that the probability of failure on demand is driven largely by the dangerous undetected failure rate multiplied by how long, on average, such a failure goes unrevealed - which is roughly half the proof-test interval. Lengthen the interval between proof tests and you let dangerous undetected failures accumulate for longer, pushing the probability up. Shorten it and you catch them sooner, pulling the probability down. This is why the proof-test interval is such a powerful lever, and why it is fundamentally a lever on the DU failure class.

It also explains why the final element, usually a shutdown valve, so often dominates a loop's failure probability. Valves sit idle for long periods and carry a high proportion of dangerous undetected failure modes - a stuck stem, a degraded actuator, a seat that will not seal - none of which announce themselves during normal operation. The whole discipline of stroke testing exists to attack exactly this: the dangerous undetected failures hiding in the valve between full proof tests.

Shrinking DU With Diagnostics, Testing, and Monitoring

There are two main ways to reduce the impact of dangerous undetected failures, and they attack different parts of the problem. The first is diagnostic coverage: the more of a device's dangerous failures its automatic diagnostics can detect, the more of them move from the undetected quadrant into the detected quadrant, where they are revealed at once rather than lying hidden. Better diagnostics literally convert dangerous undetected failures into dangerous detected ones, shrinking lambda-DU directly.

The second is testing. The proof test is the manual sweep that finds the dangerous undetected failures diagnostics missed - it is the reason a plant proof-tests its safety functions at all. Shortening the proof-test interval reduces the average time a DU failure stays hidden, and techniques like partial and full stroke testing add intermediate tests that catch some dangerous undetected failures in the final element between full proof tests. Every test that reveals a hidden fault is a dangerous undetected failure caught before it could matter.

Continuous monitoring supports both. When device diagnostics, valve position, stroke times, and proof-test results are surfaced as SCADA tags, the failures diagnostics can detect are seen the moment they occur, and the schedule of proof tests that catch the rest can be tracked and enforced. A cloud platform such as Merobix reads those diagnostics and status tags from the controllers and presents them in a browser, so a dangerous detected failure raises an alarm an engineer sees immediately, and an overdue proof test - the thing that would otherwise let dangerous undetected failures pile up unchecked - becomes visible instead of forgotten.

Frequently Asked Questions

What does DU stand for in functional safety?

DU stands for dangerous undetected. It describes a failure that would prevent a safety function from acting on demand and that the system's automatic diagnostics do not reveal. The rate at which such failures occur is written lambda-DU. Because these failures are both dangerous and hidden, they only come to light at a proof test or when a real demand exposes them.

Why do dangerous undetected failures dominate PFDavg?

Because a dangerous undetected failure stays hidden until the next proof test, it lies dormant on average for roughly half the proof-test interval, and that long dormancy makes it the largest term in the failure-probability calculation. Dangerous detected failures, by contrast, are caught by diagnostics almost immediately and contribute little. Lengthening the test interval lets dangerous undetected failures accumulate longer and raises the probability of failure on demand.

How do you reduce dangerous undetected failures?

Two levers dominate. Better diagnostic coverage moves dangerous failures from the undetected category into the detected one, where they are revealed immediately rather than left hidden. Shorter proof-test intervals, together with partial and full stroke testing of valves, reduce how long the remaining dangerous undetected failures stay hidden before a test finds them. Both approaches shrink the effect of lambda-DU on the safety function's reliability.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Safety Function Boundary  •  Revealed vs Unrevealed Failure  •  Across-the-Line Starting  •  Autotransformer Starting  •  Part-Winding Starting  •  Primary Resistance Starting  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →