Automation Glossary • No-effect / no-part failures

What Is a No-Effect Failure in Safety Systems?

Merobix Engineering • • 6 min read

The familiar split of failures into safe and dangerous is a simplification. A real failure modes, effects, and diagnostic analysis sorts a device's failures into a fuller set of categories, and two of the most misunderstood are no-effect failures and no-part failures. These are failures that either do not touch the safety function at all or are not even counted as failures of the safety element. Getting them right matters, because whether a failure lands in one of these buckets or in the safe or dangerous buckets directly changes the safe failure fraction and probability-of-failure numbers used to verify a loop.

Back to Blog

No-effect / no-part failures in one line: A no-effect failure is a component failure that does not affect the safety function and does not put the device in a degraded state relevant to safety. A no-part failure is a failure of a component that is not part of the safety function at all. Because neither influences the ability of the safety function to perform on demand, both are excluded from the safe failure fraction and probability-of-failure calculations.

The fuller FMEDA failure taxonomy

A safety element is made of many components, and not every component or every way it can fail is relevant to whether the safety function works. A detailed analysis therefore does not just ask whether a failure is safe or dangerous; it first asks whether the failure affects the safety function at all, and only then, for those that do, whether the effect is safe or dangerous and whether diagnostics would detect it. The result is a taxonomy with more than two boxes.

A no-effect failure is one where a component genuinely fails but the safety function is unaffected. Perhaps a redundant internal element takes over, or the failed component only participates in a non-safety feature, or the failure mode simply does not propagate to the function's behavior. The device is technically less than fully healthy, but its ability to detect a demand and act on it is intact, so the failure has no bearing on the safety claim. A no-part failure goes further: it is a failure of a component that is not part of the safety function's boundary in the first place, so it was never in scope.

Annunciation failures form a related category. These affect only the reporting or diagnostic annunciation, the ability to signal a status, without affecting the safety function itself. If a device fails in a way that stops it lighting an indicator or sending a diagnostic message, but it still performs its safety action correctly on demand, the failure sits apart from the safe and dangerous categories that govern the loop's integrity. Distinguishing all of these is the first, and most consequential, judgement in the analysis.

Why these categories are excluded from SFF and PFD

The safe failure fraction and the probability of failure on demand are both about the safety function's behavior on a real demand. Safe failures push the function toward its safe state or are detected; dangerous failures leave it unable to act when needed. No-effect, no-part, and annunciation failures do none of these things to the function, so including them would distort exactly the quantities those metrics are meant to capture. They are set aside, not because they are unimportant to the device, but because they are irrelevant to the specific question the safety math asks.

The exclusion has a real numerical consequence, and it is a place where analyses can be honestly done or quietly gamed. The safe failure fraction is the proportion of the relevant failure population that is safe or dangerous-detected. If a large number of no-effect failures were wrongly counted as safe failures, the safe failure fraction would look artificially high, making a device appear to need less redundancy than it truly does. The taxonomy exists partly to prevent that: no-effect and no-part failures are removed from the calculation base so they cannot inflate the fraction.

This is why correct categorization is the foundation the rest of the numbers stand on. Every failure mode a device can exhibit has to be examined and placed in the right bucket, and the safe failure fraction and probability figures are derived from how the population divides across those buckets. A sloppy taxonomy, one that miscategorizes to make a device look better, produces safe failure fraction and probability numbers that are wrong in a favorable direction, which is the worst direction for a safety claim to be wrong in.

Categorization, diagnostics, and the operating picture

The failure taxonomy that a manufacturer establishes in analysis has a counterpart in operation. A device continuously reports its state, and the diagnostics that a facility sees, healthy, warning, faulted, and the annunciations behind them, are the running expression of the same categories the analysis defined. An annunciation-only failure, for instance, is precisely the kind of subtle condition where a device may still be doing its safety job while having lost the ability to tell you so, which is exactly what makes it worth watching.

A cloud SCADA platform helps by surfacing the diagnostic and status signals that reveal where a device sits in that taxonomy day to day. Seeing that a device has raised a diagnostic warning, and understanding whether that warning corresponds to a safe-detected condition, a dangerous-detected condition, or merely a no-effect or annunciation issue, lets maintenance prioritize correctly rather than treat every fault as equally urgent or equally ignorable.

Because Merobix reads field devices and their diagnostic states into one browser-based view, it gives engineers the operating evidence to see which failure categories are actually occurring across a fleet. That real-world distribution can, over time, confirm or challenge the categorization assumed in the original analysis, and it keeps annunciation-only failures, the ones that hide precisely because the device seems fine, from going unnoticed until a demand exposes them.

Frequently Asked Questions

Why are no-effect failures left out of the safe failure fraction?

Because the safe failure fraction is about the safety function's behavior, and a no-effect failure does not affect that behavior. Including it would distort the metric. Counting no-effect failures as safe failures would artificially inflate the fraction and make a device look like it needs less redundancy than it really does, so they are removed from the calculation base entirely.

What is the difference between a no-effect and a no-part failure?

A no-effect failure is a failure of a component within the safety function's boundary that nonetheless does not affect the function, for example because a redundant element covers it. A no-part failure is a failure of a component that is not part of the safety function at all, so it was never in scope. Both are excluded from the safety calculations, but for slightly different reasons.

What is an annunciation failure?

An annunciation failure affects only a device's ability to report or signal a status or diagnostic, without affecting the safety action itself. The device still performs its safety function correctly on demand, but it may have lost the ability to tell you about a condition. Because it does not change whether the function works, it sits apart from the safe and dangerous categories used for integrity calculations.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
FMEDA  •  Fault-tolerant time interval (FTTI)  •  Fault reaction time  •  Demand rate estimation  •  Voting degradation  •  Profibus DP vs PA  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →