Glossary · Fault behavior and system states
Fail-safe behavior
Also known as: fail-safe, fail-safe design
In functional safety, fail-safe behavior is behavior in which a fault causes or maintains a safe state. The design ensures that the expected failure modes lead toward safety rather than away from it.
- Functional safety
- Systems engineering
In one sentence
Fail-safe behavior means a fault leads to or keeps a safe state, such as de-energizing to stop, provided the safe state is correctly defined.
Example
A spring-applied brake holds the ram of a press when power fails, and a broken wire in a guard interlock circuit removes the enabling signal, so both faults stop hazardous motion.
How it applies
- Machine safety: The classic principle is de-energize to stop: loss of power or a broken wire removes the enabling signal. Safe Torque Off (STO) applies this principle to drives.
- Functional safety: Fail-safe works only for the failure modes considered, and only where de-energizing really is safe. Vertical axes, clamping devices and vacuum grippers may need energy or brakes to stay safe. The defined safe state must come from the risk assessment.
- Evidence: Document the assumed failure modes and show by analysis or test, for example fault injection, that each leads to the safe state.
Fail-safe vs. fail-operational behavior
Fail-safe stops or holds; fail-operational behavior keeps running. Many systems combine both: fail-operational for a limited time, then fail-safe.