Automation Glossary • Thermocouple Burnout Detection

What Is Thermocouple Burnout Detection?

Merobix Engineering • • 7 min read

A thermocouple is a fragile thing: two dissimilar wires joined at a junction, exposed to heat, vibration, and corrosion, and eventually one of them breaks. The dangerous moment is not the break itself but what the input module reports when it happens. Without a deliberate detection scheme, an open thermocouple can read as an ambiguous or even plausible temperature, so a control system might keep heating a process that has actually lost its temperature feedback. Burnout detection forces a broken sensor to read in a known, safe direction instead. This guide explains how modules detect an open thermocouple, why the burnout direction matters for safety, and how to configure it so a failed sensor triggers the right alarm.

Back to Blog

Thermocouple Burnout Detection in one line: Thermocouple burnout detection is a feature on a thermocouple input module that senses when the sensor has gone open-circuit - a broken wire or a failed junction - and drives the reading to a known extreme rather than letting it float to a misleading value. It is configured for upscale burnout, which forces the reading to full-scale high (indicating maximum temperature), or downscale, which forces it to full-scale low. The direction is chosen so the resulting reading pushes the process into its safe state: upscale for a heater trip so a broken sensor shuts the heat off.

How a Module Detects an Open Thermocouple

A thermocouple produces a tiny voltage that varies with the temperature difference between its measuring junction and the module's reference, and it does so only while the loop is intact. When a wire breaks or a junction fails, the circuit goes open, and the module's high-impedance input is no longer looking at the sensor's millivolt signal but at an undefined, floating node. Left undetected, that floating input can drift to any value, and the reading it produces may be wildly wrong or, worse, land somewhere that looks like a believable temperature. Burnout detection exists to catch this condition explicitly rather than trusting whatever the open input happens to read.

The common detection method is for the module to inject a very small sense current, or bias, into the thermocouple loop. While the sensor is intact and its resistance is low, that tiny current develops a negligible voltage and does not disturb the measurement. When the loop opens, that same current now flows into an effectively infinite resistance, so the input voltage is driven hard to one rail - which is precisely how the module knows the sensor is open and which is what pins the reading to full scale in the configured direction. Because thermocouples are low-resistance devices, a well-designed sense current is small enough not to corrupt a good reading but decisive enough to slam the input to the rail the instant the circuit breaks.

Why Burnout Direction Matters for Safety

The entire point of choosing upscale versus downscale is to make a sensor failure produce the safe outcome for that specific application, and the right choice depends on what the control system does with a high reading. Consider a heater controlled to a setpoint: if the temperature reads high, the controller cuts power to the heat; if it reads low, the controller adds heat. Now imagine the thermocouple breaks while the heater is running. If you configured downscale burnout, the broken sensor reads full-scale low, the controller concludes the process is cold, and it drives the heater to maximum with no working feedback - a runaway. If instead you configured upscale burnout, the broken sensor reads full-scale high, the controller concludes it is too hot, and it shuts the heat off. For a heater, upscale is the fail-safe choice: a broken sensor fails hot, which shuts the heat down.

The logic flips in other applications. Where a high reading would trigger an unsafe or costly action - say, a temperature that opens a cooling valve, dumps product, or trips equipment on a high alarm - you may want downscale burnout so a broken sensor does not cause that action falsely, and instead announces itself as an obviously low, out-of-range reading that no plausible process would produce. The unifying rule is to reason through the failure: decide which direction the reading must go so that a sensor break drives the process toward safety, then configure that direction deliberately. A default left unconsidered is how a broken sensor ends up producing a false-safe reading that hides the failure instead of exposing it, and that is exactly the outcome burnout detection is meant to prevent.

Configuring the Right Alarm, and Remote Sensor-Health Visibility

Getting value from burnout detection means configuring both the drive direction and the alarming that sits on top of it. Set the module's burnout direction per application - upscale where a break must trip the heat off, downscale where a false high would be dangerous. Then make sure the reading a break produces actually raises a distinct alarm rather than quietly parking at the rail. A well-set-up system does not just pin the value; it flags a sensor-fault or out-of-range condition so operators know the reading is a burnout indication, not a real temperature. Some modules expose a dedicated open-thermocouple fault bit alongside the pinned value, which is the cleanest signal to alarm on because it says unambiguously that the sensor is broken rather than that the process is genuinely at an extreme.

For remote and unmanned sites the difference between a pinned value and an explicit fault flag is the difference between a clear failure and a confusing one, and this is where cloud SCADA closes the loop. A platform such as Merobix can bring both the temperature and the module's open-sensor fault status up to operators anywhere, so a broken thermocouple at a remote heater treater or a wellhead reboiler raises a specific sensor-fault alarm instead of a puzzling temperature that a night-shift operator has to interpret. Historizing the reading also helps distinguish a slow sensor failure from a real process event, because a genuine burnout typically slams to the rail instantly while a real excursion ramps. Seeing that signature remotely lets someone dispatch a technician for a sensor replacement with confidence that the problem is the thermocouple, not the process it was watching.

Frequently Asked Questions

Should I use upscale or downscale thermocouple burnout?

It depends on what the control system does with a high reading. For a heater, use upscale: a broken sensor reads full-scale high, the controller thinks it is too hot, and it shuts the heat off - failing safe. Use downscale where a false high reading would trigger something unsafe or costly, so a break instead reads obviously low. The rule is to pick whichever direction drives the process toward its safe state when the sensor fails.

How does a module detect that a thermocouple has burned out?

Most thermocouple modules inject a very small sense current into the loop. While the thermocouple is intact its low resistance means that current develops a negligible voltage and does not affect the reading. When the sensor goes open-circuit, that same tiny current flows into an effectively infinite resistance and drives the input hard to one rail, which the module interprets as an open thermocouple and uses to pin the reading full-scale in the configured burnout direction.

Why does my thermocouple suddenly read maximum temperature?

A reading that jumps instantly to full scale is the classic signature of a burned-out thermocouple on a module configured for upscale burnout - the wire or junction has broken and the module has pinned the value high to indicate the fault. A real temperature excursion normally ramps up rather than slamming to the rail in one step. Check for an accompanying sensor-fault or open-circuit flag, and inspect the thermocouple and its wiring for a break before assuming the process actually reached that temperature.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Field Power vs Logic Power  •  Backplane Current Budget  •  Bus Coupler  •  Output Snubber  •  2-Wire vs 4-Wire Wiring  •  Conformal Coating  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →