Automation Glossary • Flame failure response time (FFRT)

What is flame failure response time (FFRT) and how is it set?

Merobix Engineering • • 6 min read

Flame failure response time, or FFRT, is the maximum time allowed between the actual loss of a burner's flame and the moment the fuel safety shutoff valves are de-energized to cut off fuel. It is one of the defining safety parameters of a flame safeguard system, because it governs how quickly the system reacts when a flame goes out. A short, well-controlled response time limits the amount of unburned fuel that can enter the furnace during the gap between flame loss and fuel shutoff. Codes place upper limits on this time precisely because a slow response lets a dangerous quantity of fuel accumulate.

Back to Blog

Flame failure response time (FFRT) in one line: Flame failure response time is the maximum time from actual flame loss to de-energizing the fuel safety shutoff valves. Codes cap it, commonly at a few seconds and tighter for large furnaces, to limit unburned fuel accumulation, and it is verified during commissioning by removing the flame signal and timing the trip.

Why codes cap the flame failure response time

When a flame is lost but fuel keeps flowing, unburned fuel enters the furnace and mixes with air. If that fuel later reaches an ignition source, the accumulated mixture can ignite all at once, producing an explosion capable of severe damage and injury. The amount of fuel that accumulates is proportional to how long fuel keeps flowing after the flame is gone, so the response time directly determines how large that potential explosive charge can grow.

This is why standards impose an upper limit on flame failure response time. A commonly cited maximum is on the order of a few seconds for many burners, with tighter limits applied to larger furnaces where even a short delay admits a substantial mass of fuel. The exact limit depends on the application and the governing standard, but the principle is constant: the bigger the potential fuel accumulation, the tighter the response time must be.

It is important to understand that FFRT is a maximum, not a target to approach. The goal is to shut off fuel as promptly as the equipment reliably allows while staying comfortably within the code limit. A response time that meets the cap keeps the accumulated fuel below the threshold at which a re-ignition would be destructive, which is the entire safety rationale for the parameter.

What counts toward the response time

The flame failure response time is not just the reaction speed of one component; it is the total elapsed time from real flame loss to fuel actually stopping. That total includes the time the flame detector and flame safeguard take to recognize that the flame is gone and to command a trip, plus the time the fuel safety shutoff valves take to physically close once they are de-energized. Both the detection delay and the valve closure stroke count.

This matters because a fast flame detector paired with slow-closing valves may still exceed the limit, and vice versa. The scanner or flame rod response contributes the sensing and logic portion, while the valves contribute a mechanical closure time that depends on their size and design. Achieving a compliant overall FFRT means the detection and the valve action together must fit within the allowed window, so both parts of the chain are considered when specifying equipment.

Because the parameter spans the whole chain, verifying it requires measuring the real end-to-end behavior rather than trusting individual component ratings. The interaction between detection speed and valve stroke is what the system actually delivers, and that combined figure is what must satisfy the code limit for the installation.

Verifying FFRT at commissioning and monitoring it in service

The practical way to confirm flame failure response time is to test the whole chain during commissioning. A technician removes or interrupts the flame signal, simulating a sudden flame loss, and times how long it takes for the fuel safety shutoff valves to close and cut off fuel. This end-to-end measurement captures both the detection delay and the valve closure, giving the true response time as installed rather than a calculated estimate from datasheets.

Recording the measured response time and the conditions under which it was verified provides a baseline for the safety system. If the burner or its components are later modified, or if maintenance replaces a valve or a scanner, the test is repeated to confirm the response time still meets the limit. This discipline keeps the flame failure response function trustworthy over the life of the equipment rather than only at initial startup.

In service, a SCADA or monitoring system supports this by time-stamping flame-loss and trip events, so that when a real or test flame loss occurs, the interval between the loss of flame signal and the valve trip is captured in the record. Trending these events across a fleet lets a reliability team spot a burner whose response is drifting, perhaps due to a sluggish valve or a slowing scanner, and schedule attention before the response time approaches the code limit. The commissioning test proves the value once; continuous monitoring helps ensure it stays valid.

Frequently Asked Questions

Why is flame failure response time limited to just a few seconds?

Because unburned fuel keeps entering the furnace for as long as fuel flows after the flame is lost, and that accumulated fuel can explode if it re-ignites. The amount that builds up grows with time, so a short response time keeps the accumulation below a dangerous level. Codes cap the time, often at a few seconds and tighter for large furnaces, to bound the potential explosive charge.

Does the fuel valve closing time count toward FFRT?

Yes. Flame failure response time is the total time from actual flame loss to fuel actually being shut off, so it includes both the detection and logic delay of the flame safeguard and the mechanical time the fuel safety shutoff valves take to close after being de-energized. A fast detector cannot compensate for slow valves; the whole chain must fit within the allowed window.

How is flame failure response time verified?

It is verified end to end, usually at commissioning, by deliberately removing or interrupting the flame signal to simulate a flame loss and timing how long it takes the fuel safety shutoff valves to close. This measures the real installed response, including detection delay and valve closure, and the test is repeated after modifications or component replacements to confirm the response still meets the code limit.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Forced vs induced draft fans  •  Balanced draft & implosion protection  •  Hot surface vs direct spark ignition  •  Windbox  •  Pump Shutoff Head  •  Pump Runout  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →