Every control valve in a plant has a predetermined position it moves to when its power fails - when instrument air is lost or the control signal drops to zero. Choosing whether a valve should slam shut, swing wide open, or freeze in place is one of the most consequential decisions in process safety, and it is driven by what keeps the process safe, not by what is convenient. This guide explains fail-open, fail-closed, and fail-last actions, how spring direction and air action set the failure position, and how the safety case decides which one a given valve must have.
Fail-Open vs Fail-Closed Valve in one line: A fail-open (FO) valve moves fully open on loss of air or signal, a fail-closed (FC) valve moves fully shut, and a fail-last (FL) valve holds its last position. The failure position is set by the actuator's spring direction relative to the air action and is chosen by process-safety analysis so that the plant lands in its safest state when power is lost.
In a classic spring-and-diaphragm actuator, a return spring fights against air pressure on the diaphragm. When the air supply or control signal is lost, the diaphragm loses its force and the spring drives the valve to a known end position. If the spring pushes the stem down to seat the valve, the valve fails closed; if the spring pulls the stem up off the seat, the valve fails open. The mechanical arrangement of that spring, not the electronics, is what guarantees the safe position even when everything else is dead.
This is why fail-safe action and air action are linked but not identical. An air-to-open actuator uses air to move the valve open and a spring to close it, so it fails closed. An air-to-close actuator uses air to move the valve shut and a spring to open it, so it fails open. Reversing the spring, or ordering the actuator in the opposite configuration, flips the failure position - which is exactly why the desired failure direction is specified up front and built into the hardware.
Fail-last, sometimes called fail-in-place, behaves differently. It typically uses a double-acting piston actuator with air on both sides and no dominant return spring, or a lock-up valve that traps air pressure when supply is lost. On failure the valve simply stops moving and holds its last commanded position. Fail-last is chosen only where holding is genuinely safer than either extreme - for instance, on some large compressor recycle or blending duties where a sudden full stroke would upset the process worse than a frozen valve.
The rule of thumb is simple to state and central to plant safety: on loss of control, the valve should move to the position that leaves the process in its least hazardous state. A fuel-gas valve to a fired heater fails closed, because cutting fuel on any upset is far safer than continuing to feed a burner that may have lost its flame or its combustion air. A cooling-water or quench valve fails open, because losing cooling to a hot process is the dangerous event, so the safe reaction is to keep coolant flowing at maximum.
The same logic runs through separation and pressure control. A liquid dump valve on a separator often fails closed to avoid gas blowby into a downstream line, while a pressure-relief or blowdown path may be arranged to open on failure to prevent overpressure. There is no universal answer for a valve type; the same physical globe valve fails closed in one service and open in another. What matters is the consequence of loss of power on that specific stream, in that specific plant.
Because the failure position must be reasoned about rather than assumed, it is set during hazard analysis - a HAZOP or a layer-of-protection review - and recorded on the datasheet and the P&ID as a documented decision. Engineers deliberately resist choosing the failure direction for maintenance convenience or to match a neighboring valve, because a fail action selected for the wrong reason quietly removes a safeguard the safety case assumed was present. The failure position is a safety attribute of the loop, not a preference.
A fail action only protects the plant if the valve can actually reach its safe position, and that depends on hidden utilities and healthy hardware. Loss of instrument air, a stuck stem, a failed positioner, or a low supply-air header can all prevent a valve from stroking to safety when it is finally called on. Because these failures are silent until the demand arrives, operators watch the supporting conditions continuously rather than assuming the fail action will simply work.
A cloud SCADA platform gives the operations team a live window into those conditions across every site. Merobix reads the digitized tags from the PLC, RTU, or flow computer - instrument-air header pressure, valve position feedback, signal status, and positioner diagnostics - and trends and alarms them from a browser. An air header sagging toward the point where valves can no longer stroke, or a position readback that no longer follows command, surfaces as an alarm before it becomes an unsafe demand.
This visibility matters most across dispersed unmanned assets - wellpads, gathering stations, and remote separation packages - where no one is standing next to the valve. Trending the health of the fail-safe chain over time also feeds maintenance planning, so a slowly degrading air dryer or a drifting positioner is caught during routine work rather than discovered the moment a fail-closed valve is expected to protect the plant and cannot move.
A fail-open valve moves to its fully open position when instrument air or the control signal is lost, while a fail-closed valve moves fully shut under the same conditions. The failure position is fixed by the actuator's spring direction and is selected so that losing power leaves the process in its safest state, which differs from one service to another.
You decide by asking which position is safest if power is lost on that specific stream, and the answer comes from hazard analysis such as a HAZOP rather than from the valve type. Fuel-gas valves typically fail closed to stop feeding a burner, while cooling and quench valves typically fail open to keep coolant flowing. The choice is documented on the datasheet and P&ID as a safety decision.
Fail-last, also called fail-in-place, means the valve holds its last commanded position when air or signal is lost instead of driving fully open or closed. It usually uses a double-acting actuator with no dominant return spring or a lock-up device that traps air. It is chosen only where freezing the valve is genuinely safer than either full-stroke extreme.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.