Author Name: Bruce Zheng
Author Role: Co-Founder and Valve Engineer at NTGD Valve
Author Bio: Bruce Zheng is Co-Founder and Valve Engineer at NTGD Valve, focusing on industrial valve selection, application, and technical content for global B2B buyers.
Last Updated: July 22, 2026
Quick Answer: A pneumatic diaphragm valve fail-safe position is the intended final valve position after a specified failure event. The required position may be open, closed, or retained by an engineered arrangement.
Air-to-open, air-to-close, normally open and normally closed do not independently define that result. Each label describes only one part of the operating logic.
The fail-safe position is therefore a property of the complete pneumatic diaphragm valve package—the valve, actuator, spring where fitted, pneumatic circuit, solenoid, positioner, feedback devices and any stored-energy or lock-up arrangement—not of one actuator label.
A reliable specification must answer three separate questions:
- What failure event is being considered?
- What final position is required under that event?
- How will the complete package achieve and verify that position?
This guide concerns industrial pneumatic diaphragm valves in which an actuator moves a stem and compressor, and the compressor raises or presses the valve sealing diaphragm against the weir or sealing surface. It does not describe a globe control valve merely fitted with a diaphragm actuator.
For the broader choice between manual, pneumatic and electric operation, review our diaphragm valve actuation selection guide; this article focuses on the deeper failure-state logic of pneumatic packages.
What Is a Pneumatic Diaphragm Valve Fail-Safe Position?
A fail-safe position is the position that the complete valve assembly is intended to reach after a defined loss condition or trip.
Common designations are:
- Fail-open (FO)
- Fail-closed (FC)
- Fail-in-place or fail-lock (FL)
The word intended is important. A project may specify that a valve must close when instrument air is lost, but that designation does not prove the valve will close during every possible control, pneumatic or mechanical failure.
A complete requirement therefore needs both:
- a defined failure trigger; and
- a required final valve position.
A Fail-Safe Position Must Be Tied to a Defined Failure Event
“Valve fails closed” is incomplete unless the specification states what has failed.
Relevant events may include:
- total loss of instrument-air supply;
- gradual reduction of actuator-air pressure;
- loss of the controller output signal;
- positioner failure or loss of positioner power;
- solenoid de-energisation during a trip;
- loss of electrical power to the solenoid or control accessories;
- mechanical obstruction within the valve or actuator;
- loss of position feedback while the valve remains mechanically operable.
These events can produce different responses.
A signal may disappear while full instrument air remains available. A de-energised solenoid may vent one actuator chamber, supply another chamber, block the pneumatic ports or redirect stored air. A mechanical obstruction may prevent movement even when the control package commands the correct direction.
The datasheet, pneumatic schematic and shutdown documentation should identify the specific event instead of relying on the phrase “on failure.”
Fail-Safe Position Is Not the Same as Normal Position or Air Action
The following terms describe different aspects of the package:
- Air action describes the direction of valve movement as actuator pressure increases.
- Normal or deactivated position describes the state under a stated normal reference condition.
- Spring direction describes the mechanical return direction of a single-acting actuator.
- Fail position describes the intended final position after a defined failure.
- Process-safe state describes the position that produces the lower overall process risk.
These fields often align in a simple spring-return package, but they should still be specified separately.
Intended Position Does Not Guarantee Shutoff Under Every Fault
A fail-closed diaphragm valve is intended to reach the closed position after the stated trip. That designation does not independently guarantee:
A CCPS Process Safety Beacon case study documents a fail-open valve that remained closed after a mechanical linkage failure, illustrating why the designed utility-failure position and the actual field position must be verified separately.
- zero leakage;
- bubble-tight isolation;
- full diaphragm travel at every differential pressure;
- closure through solids, deposits or crystallised media;
- movement through a seized stem or compressor;
- correct position feedback;
- successful operation under every mechanical fault.
Leakage and isolation acceptance must be specified separately.
A valve may reach its indicated closed position and still fail the project shutoff requirement because of diaphragm condition, incomplete compressor travel, deposits at the sealing surface, insufficient actuator force, incorrect adjustment or another mechanical condition.
Fail-safe position defines the intended response. Shutoff performance confirms whether the required process isolation was actually achieved.
Air-to-Open, Air-to-Close, Normally Open and Normally Closed
Air-to-open, air-to-close, normally open, normally closed, fail-open and fail-closed are frequently used together, but they are not interchangeable.
| Term | What It Describes | Typical Interpretation | What It Does Not Prove |
|---|---|---|---|
| Air-to-open (ATO) | Direction of complete-valve movement as pneumatic pressure increases | Increasing actuator pressure moves the valve toward open | The required final position after every failure |
| Air-to-close (ATC) | Direction of complete-valve movement as pneumatic pressure increases | Increasing actuator pressure moves the valve toward closed | The required final position after every failure |
| Normally open (NO) | Normal or deactivated state under a stated reference condition | Valve is open without the stated actuating command | That the valve will remain open during all failures |
| Normally closed (NC) | Normal or deactivated state under a stated reference condition | Valve is closed without the stated actuating command | That the valve will close during all failures |
| Fail-open (FO) | Intended final open position after a defined failure | Valve moves to or remains open after the specified event | Which energy source produces the movement |
| Fail-closed (FC) | Required or intended final closed position after a defined failure | Valve moves to or remains closed after the specified event | Bubble-tight shutoff or zero leakage |
| Fail-in-place / fail-lock (FL) | Intended retention near the last position after a defined failure | An engineered arrangement attempts to hold position | That a basic double-acting actuator will remain fixed indefinitely |

What Air-to-Open and Air-to-Close Actually Describe
An air-to-open diaphragm valve moves toward the open position as pneumatic pressure applied to its actuator increases.
An air-to-close diaphragm valve moves toward the closed position as actuator pressure increases.
These terms should describe the movement of the complete valve assembly, not only the motion of an internal actuator component.
For an industrial diaphragm valve, the movement chain is:
Actuator pressure changes → actuator piston or actuator diaphragm moves → stem and compressor move → valve sealing diaphragm lifts or presses down → the process flow path opens or closes
The actuator diaphragm, where used, converts pneumatic pressure into force. The valve sealing diaphragm directly controls and isolates the process medium. They are separate components with different functions.
What Normally Open and Normally Closed Describe
Normally open and normally closed are meaningful only when the reference condition is stated.
That condition may be:
- no actuator air;
- solenoid de-energised;
- no control command;
- normal operating command absent;
- actuator at its spring-return position.
Without the reference condition, a normally open or normally closed label can be ambiguous.
For a datasheet or RFQ, “normally closed” should not replace a trigger-and-response statement such as:
Upon total loss of instrument air, the valve shall move to the closed position.
This statement defines both the event and the required response.
Why ATO Does Not Automatically Mean Fail-Closed
In a typical single-acting, spring-to-close arrangement:
Air pressure applied → valve opens Actuator air removed and vented → spring drives the valve closed
That package may correctly be described as:
- air-to-open;
- spring-to-close;
- fail-closed on total actuator-air loss.
The ATO label alone does not establish the response to:
- loss of signal while actuator air remains available;
- solenoid de-energisation;
- electrical power failure;
- trapped pressure in the actuator;
- a lock-up device;
- an alternate pneumatic supply;
- mechanical obstruction.
A standard spring-to-close ATO package commonly provides FC during actuator-air loss. A modified package that retains pressure, uses alternate stored energy or applies different trip logic may respond differently.
ATO describes commanded movement as pressure increases. Fail-closed describes the intended result after a defined event.
Why ATC Does Not Automatically Mean Fail-Open
In a typical single-acting, spring-to-open arrangement:
Air pressure applied → valve closes Actuator air removed and vented → spring drives the valve open
That package may be described as:
- air-to-close;
- spring-to-open;
- fail-open on total actuator-air loss.
ATC still does not define every signal, power or mechanical failure response. Solenoid porting, retained actuator pressure, stored-energy devices or other control arrangements may prevent the expected spring-return movement.
A standard spring-to-open ATC package commonly provides FO during actuator-air loss. It should not be specified as fail-open until the complete package and relevant failure event have been confirmed.
Fail-Open, Fail-Closed and Fail-in-Place Explained
The required failure position should be selected from process consequences, not from a preference for one actuator arrangement.
| Failure State | Intended Final Position | Typical Means of Achieving It | Main Process Consequence | Key Limitation |
|---|---|---|---|---|
| Fail-open (FO) | Valve moves to or remains open | Spring-to-open actuator or another stored-energy arrangement | Continued flow can create uncontrolled feed, drainage, cross-flow, cross-contamination or continued transfer | FO may preserve a required flow but can also continue an unwanted release or process feed |
| Fail-closed (FC) | Valve moves to or remains closed | Spring-to-close actuator or another stored-energy arrangement | Blocked flow can cause pressure buildup, pump deadheading, loss of cooling or circulation, and interruption of discharge or downstream operation | FC defines position, not leakage performance or successful isolation under every condition |
| Fail-in-place / fail-lock (FL) | Valve is retained near its last position | Lock-up device, controlled port blocking, stored pneumatic energy or another engineered arrangement | An intermediate retained position can create insufficient flow, excessive residual flow or an unstable process condition | Short-term trapped position is not the same as reliable long-duration position retention |
Fail-Open: Flow Continues After the Defined Failure
A fail-open diaphragm valve is intended to open or remain open after the defined trip.
FO may be considered when interruption of a required flow creates the greater process hazard. Relevant functions can include:
- equipment cooling;
- protective circulation;
- dilution;
- flushing;
- essential discharge.
The opposite consequence must also be reviewed. Continued flow can cause uncontrolled chemical feed, vessel drainage, cross-contamination, transfer into unavailable equipment or release to an unintended destination.
The decision question is:
What happens to the process, upstream equipment and downstream destination if this valve remains open after the specified failure?
Fail-Closed: Flow Is Stopped After the Defined Failure
A fail-closed diaphragm valve is intended to close or remain closed after the specified event.
FC may reduce risk where continued flow could cause:
- uncontrolled chemical addition;
- vessel overfill;
- contamination;
- cross-flow between process streams;
- unwanted drain-down;
- continued transfer after downstream equipment has stopped.
Isolation of the risk source is only one side of the decision. The project must also confirm that closure will not create unacceptable upstream pressure, trapped fluid, pump deadheading, loss of cooling, loss of circulation or blockage of an essential discharge path.
The selection question is:
Does stopping this flow create a lower total process risk than allowing it to continue?
Fail-in-Place or Fail-Lock: Position Is Retained by an Engineered Arrangement
Fail-in-place means the package is intended to retain the valve near its last position after a defined failure.
This response may be considered when an abrupt move fully open or fully closed would cause:
- a severe process disturbance;
- an excessive pressure or flow change;
- unstable equipment operation;
- damage caused by sudden interruption or full flow.
Reliable fail-in-place behavior normally requires a deliberately engineered arrangement, such as:
- pneumatic lock-up;
- controlled port blocking;
- stored-air devices;
- dedicated reservoirs;
- pilot logic;
- another verified position-holding system.
A basic double-acting actuator has no spring-defined fail position. Closing or blocking its air ports may temporarily trap pressure, but that is not proof of reliable long-duration position retention.
Position can drift as trapped pressure changes because of internal or external leakage, process differential pressure, diaphragm and stem friction, valve orientation or external mechanical loads.
A reliable FL specification should define:
- the triggering failure event;
- allowable position deviation;
- required hold duration;
- devices used to retain or replenish pneumatic energy;
- the test used to verify performance.
Why None of the Three Positions Is Universally Safer
The same valve position can eliminate one hazard and create another:
- closing stops feed but may block cooling or create pressure buildup;
- opening preserves circulation but may continue uncontrolled transfer;
- holding position avoids an immediate full stroke but may leave unstable residual flow.
The correct choice is the position that produces the lower overall process risk for the specific failure event and for the connected upstream and downstream equipment.
That decision must then be converted into a verifiable valve-package requirement.
How a Pneumatic Diaphragm Valve Reaches Its Failure Position
The final position is created by the interaction of the actuator, valve operating mechanism, pneumatic circuit, control accessories and available stored energy.
From Actuator Pressure to Stem, Compressor and Valve Diaphragm Movement
In an industrial pneumatic diaphragm valve, actuator force is transmitted through the valve operating mechanism.
The movement sequence is:
- Pneumatic pressure acts on an actuator piston or actuator diaphragm.
- The actuator converts pressure into linear force and travel.
- The stem transfers the movement into the valve upper assembly.
- The compressor raises or presses the valve sealing diaphragm.
- The valve diaphragm moves away from or against the weir or sealing surface.
- The process flow path opens or closes.
A correct actuator label does not prove that the required valve position has been achieved.
Travel can be limited by:
- incorrect adjustment;
- inadequate actuator pressure;
- insufficient force under the actual differential pressure;
- stem or diaphragm resistance;
- deposits or obstruction;
- damaged components;
- incorrect actuator-to-valve assembly.
The fail position is physically achieved only when the compressor drives the valve sealing diaphragm through the intended travel and produces the required flow opening or contact with the weir or sealing surface.

For a complete sectional explanation of the stem, compressor, sealing diaphragm and shut-off interface, see the diaphragm valve diagram and working-principle guide.
The full valve construction and working principle belong to a broader mechanism guide. For fail-safe evaluation, the key issue is whether the actuator’s return or emergency movement produces the required valve-diaphragm position.
Single-Acting Spring-to-Close and Spring-to-Open Arrangements
A single-acting actuator uses pneumatic pressure for one direction and stored spring energy for the return direction.
| Arrangement | Air-Driven Movement | Spring-Driven Movement | Common Air-Loss Result | Specification Caution |
|---|---|---|---|---|
| Air-to-open / spring-to-close | Toward open | Toward closed | Often fail-closed after total actuator-air loss and effective venting | Confirm solenoid porting, trapped air, spring force, full travel and required shutoff |
| Air-to-close / spring-to-open | Toward closed | Toward open | Often fail-open after total actuator-air loss and effective venting | Confirm full opening travel under the actual process condition |

Spring return provides an internal source of mechanical energy. It does not remove the need to confirm:
- spring direction;
- actuator sizing for the approved valve;
- available air pressure;
- full stroke;
- process differential pressure;
- pneumatic porting;
- final valve position;
- shutoff or flow acceptance.
Double-Acting Actuation and the Limits of Inherent Fail-Safe Action
A double-acting pneumatic actuator uses air pressure to drive both opening and closing strokes.
Because it normally has no internal return spring, it does not possess an inherent spring-defined fail-open or fail-closed position.
After total air loss, possible behavior includes:
- temporary position retention;
- gradual drift;
- movement caused by process forces;
- movement caused by unequal trapped pressure;
- response controlled by stored air or an accessory;
- no predictable final position.
A double-acting pneumatic diaphragm valve should not be assumed to fail in place merely because both actuator ports lose their supply.
A defined FO, FC or FL response requires an engineered arrangement capable of producing or retaining the required force under the stated failure condition.
Stored Air, Lock-Up and Other Engineered Arrangements
Spring return is not the only method of producing a defined failure response.
A package may use:
- an air reservoir;
- a pneumatic accumulator;
- a lock-up valve;
- pilot-operated logic;
- a dedicated emergency-air source;
- another stored-energy device.
These arrangements introduce additional questions:
- Is enough usable energy available to complete the required travel?
- What event activates the emergency arrangement?
- Does the solenoid vent, supply, block or redirect the actuator ports?
- What happens when electrical power and instrument air are both lost?
- How long must a retained position remain within tolerance?
- How will the stored-energy system be inspected and functionally tested?
Such features are engineered package configurations, not assumed characteristics of a standard pneumatic diaphragm valve.
Why Loss of Air, Signal and Electrical Power May Produce Different Results
“Fail-safe” is incomplete until the triggering event is identified.
| Failure Event | What Changes | What Controls the Valve Response | What Must Be Verified |
|---|---|---|---|
| Total loss of instrument air | Pneumatic supply falls to zero | Spring direction, stored energy, trapped air and process forces | Actual final position, full stroke and achieved flow or shutoff |
| Partial air-pressure decay | Available actuator force decreases | Actuator force margin, spring force, friction and differential pressure | Whether the valve moves fully, slowly, partially or not at all |
| Loss of control signal | Command information disappears or changes | Controller fail output, positioner configuration and solenoid logic | Whether actuator pressure is maintained, increased, reduced, vented or redirected |
| Solenoid de-energisation | Solenoid shifts to its de-energised state | Solenoid type and pneumatic porting | Which actuator chamber is supplied, vented or blocked |
| Loss of electrical power | Positioner, solenoid and feedback may be affected independently | Electrical architecture and de-energised states | Combined physical response and feedback availability |
| Positioner failure | Actuator output pressure may hold, increase, decrease or vent | Positioner design and configured failure behavior | Physical valve position rather than displayed command alone |
| Mechanical obstruction | The movement path is physically restricted | Valve condition, deposits, travel setting and damaged components | Whether the intended movement can actually occur |

Loss of Instrument Air
For a basic spring-return actuator, total loss of actuator air normally permits the spring to move the valve toward its return position, provided the actuator chamber can vent.
The project should confirm:
- the correct chamber is vented;
- no retained pressure opposes the spring;
- spring direction matches the required final position;
- the spring can complete the stroke under the process condition;
- the valve sealing diaphragm reaches the required position.
A double-acting actuator has no inherent final position after total supply-air loss unless an additional arrangement defines it.
Gradual or Partial Air-Pressure Decay
A gradual pressure reduction is not equivalent to a clean, instantaneous trip.
As pressure falls, actuator force may become insufficient to:
- oppose the spring;
- overcome stem and diaphragm resistance;
- overcome process differential pressure;
- complete the full travel.
The valve may begin moving early, move slowly, stop partway or remain at an intermediate position until the force balance changes.
This incomplete movement can be a difficult field fault to identify. The valve may appear responsive while failing to reach full open or full closed, leaving insufficient protective flow, unwanted residual flow or unacceptable isolation.
Actual behavior should be checked against the approved actuator data and the specified test condition rather than inferred from the nominal air-failure label.
Loss of Control Signal or Positioner Output
Loss of a control signal does not necessarily remove instrument air.
Depending on the control architecture, a controller or positioner may:
- drive its output low;
- drive its output high;
- hold its last output;
- generate a configured fail output;
- become inactive while a separate solenoid determines the actuator state.
Signal-failure response must therefore be specified separately from air-failure response.
The relevant question is not merely whether the signal disappears, but what pneumatic pressure is then delivered to each actuator chamber.
Solenoid De-Energisation and Fail Porting
A solenoid valve determines the pneumatic connections in its energised and de-energised states.
When de-energised, it may:
- vent an actuator chamber;
- supply an actuator chamber;
- block one or more ports;
- redirect stored air;
- initiate a spring-return stroke.
Labels such as “de-energise to trip” or “solenoid fail-close” do not fully define the valve response.
The project should verify the actual chamber behavior:
Which port is supplied? Which port is vented? Which port is blocked? What pressure remains in the actuator?
The resulting stem, compressor and valve-diaphragm movement must then be confirmed.
Loss of Electrical Power
Electrical power loss may simultaneously affect:
- the solenoid;
- the positioner;
- controller output;
- limit switches;
- the position transmitter;
- local indication;
- remote feedback.
The mechanical valve may move correctly while its feedback becomes unavailable. Conversely, the control system may continue to display a commanded or inferred position that the valve has not physically achieved.
Physical position and feedback status should be verified separately.
Mechanical Obstruction Is a Different Failure Category
A fail-safe designation describes a designed response to a defined utility or control failure. It does not guarantee movement through a mechanical obstruction.
Possible mechanical causes include:
- deposits beneath the valve diaphragm;
- a damaged diaphragm or compressor;
- stem seizure;
- incorrect travel adjustment;
- actuator linkage damage;
- internal obstruction;
- external interference.
These conditions belong to maintenance and troubleshooting. They should not be treated as evidence that the intended fail-position specification itself was correctly or incorrectly defined.
Rupture, sticking, leakage and failure-to-operate symptoms should be assessed through a separate diaphragm valve troubleshooting guide, not treated as proof of the intended fail position.
Failure Events Must Be Specified Separately
Air failure, signal failure, electrical-power failure and emergency solenoid trip should not be grouped under one unspecified “fail-safe” condition.
A project may require different responses for each event. Each trigger should therefore have its own required final position, control-path description and verification method.
How to Select the Required Safe Position from Process Consequences
The required safe position should be selected by comparing the consequences of the valve being open, closed or retained after the specified failure.
A useful review asks:
- What continues to flow if the valve remains open?
- What stops flowing if the valve closes?
- What pressure, temperature, concentration or level change follows?
- Which upstream and downstream equipment remains in operation?
- Does the event affect one valve or the wider utility system?
- Is the required state different for normal shutdown, air failure and emergency trip?
| Process Question | If the Valve Fails Open | If the Valve Fails Closed | Selection Implication |
|---|---|---|---|
| Does the line feed material into a vessel or process unit? | Chemical or liquid feed may continue after downstream shutdown | Feed is isolated | FC may reduce overfeed or contamination risk, but upstream pressure and pump consequences must be reviewed |
| Does the line provide cooling, dilution or protective circulation? | Protective flow may continue | Cooling or circulation is lost | FO may reduce loss-of-cooling risk, but continued supply to a damaged system must also be assessed |
| Is the line an essential discharge or pressure-relief path? | Discharge remains available | Pressure or level may rise | FO may be preferred where blockage creates the greater hazard |
| Can continued flow cause cross-contamination or unwanted transfer? | Transfer may continue | Transfer is stopped | FC may reduce contamination risk if closure does not create a larger upstream hazard |
| Can closure deadhead a pump or trap pressure? | A flow path remains available | Pump discharge or trapped volume may be blocked | FO or another engineered response may be required |
| Would a sudden full stroke destabilise the process? | Full flow may be excessive | Complete flow loss may be excessive | Engineered position retention or a controlled sequence may require separate review |
The table is a decision framework, not a universal recommendation.
When Stopping Flow Creates the Lower Risk
Fail-closed may be appropriate where continued flow could cause:
- uncontrolled chemical addition;
- vessel overfill;
- transfer into unavailable downstream equipment;
- contamination;
- cross-connection;
- unwanted drain-down.
A chemical-feed or vessel-filling line is a common example in which continued flow may be the dominant concern.
Closure must still be reviewed against the upstream system. Isolating the feed can create:
- pump deadheading;
- pressure buildup;
- trapped media;
- thermal expansion within a blocked section;
- loss of required circulation.
A fail-closed decision is complete only after both the benefit of isolation and the consequences of blocked flow have been evaluated.
When Maintaining Flow Creates the Lower Risk
Fail-open may be appropriate where flow performs a protective function, such as:
- equipment cooling;
- minimum circulation;
- flushing;
- dilution;
- essential discharge.
A cooling or protective-circulation line may need to remain available when control power is lost.
The project must also assess whether continued flow during the accident condition could cause:
- uncontrolled process feed;
- secondary leakage;
- discharge to an unavailable destination;
- environmental release;
- flooding or drain-down.
Fail-open is justified only when the risk of losing the required flow is greater than the risk of allowing it to continue.
When Holding Position Requires a Separate Engineered Solution
Fail-in-place may be considered when neither full opening nor full closure produces an acceptable immediate response.
The specification should define:
- the triggering failure event;
- the last valid position to be retained;
- allowable position deviation;
- required retention time;
- the devices used to trap or replenish energy;
- how drift and actual valve position will be verified.
“Double-acting” alone is not a position-holding specification.
Normal Shutdown and Emergency Trip May Require Different Definitions
Normal shutdown is a planned operating sequence. Instrument-air failure, electrical failure and emergency trip are separate events.
The same valve may therefore require:
- a commanded position during normal shutdown;
- a spring-return position after air failure;
- a different response when a solenoid is de-energised;
- an engineered sequence during an emergency trip.
Many projects define these conditions separately.
An RFQ should not contain one ambiguous “shutdown position” field when the required responses differ by event.
How to Verify the Complete Valve Package and Actual Shutdown Response
Fail-safe behavior should be confirmed from the approved package and its actual response, not inferred from a single label.
ISA’s partial-stroke testing scope for valve actuators defines the automated-valve boundary to include monitoring devices, air regulation, the actuator and the valve body, reinforcing package-level verification rather than reliance on one label.
Review the P&ID, Datasheet, Tag and Approved Configuration
The review should include:
- P&ID or process schematic;
- valve datasheet;
- valve tag;
- shutdown or cause-and-effect documentation where applicable;
- approved actuator configuration;
- pneumatic schematic;
- solenoid specification;
- positioner and feedback documentation.
For help reading the valve mark, actuator indication and tag context before moving to the datasheet, review the diaphragm valve symbol in P&ID drawings.
The documents should consistently identify:
- normal operating position;
- air action;
- required fail position;
- defined failure trigger;
- actuator type;
- spring direction;
- accessory behavior.
Where FO, FC, FL, NO, NC, ATO or ATC are used, the project legend should define their meaning.
Confirm Actuator Type, Spring Direction and Air Action
The physical package should be checked against the approved documents.
Confirm:
- single-acting or double-acting actuator;
- air-to-open or air-to-close movement;
- spring-to-open or spring-to-close direction;
- actuator connection to the stem and compressor;
- full intended valve travel;
- approved available-air range.

Visual similarity is not sufficient. Similar actuator housings may contain different spring arrangements, pneumatic connections or internal configurations.
Confirm Solenoid, Positioner and Feedback Behaviour
Verify:
- energised and de-energised solenoid porting;
- which chamber is vented, supplied or blocked;
- positioner output after signal or power loss;
- whether actuator air remains available after signal failure;
- whether the feedback device reports command, stem movement or confirmed end position.
A remote “open” or “closed” indication is not proof of the corresponding process-flow condition unless the feedback method and mechanical linkage are understood.
Separate Intended Fail Position from Achieved Shutoff
Verification should distinguish three results:
- The actuator moved in the intended direction.
- The valve reached the intended physical position.
- The valve achieved the required shutoff or flow condition.
These are separate acceptance questions.

A valve may reach or indicate its fail-closed position and still fail the project shutoff requirement because of:
- diaphragm condition;
- incomplete compressor travel;
- deposits at the sealing surface;
- differential pressure;
- inadequate closing force;
- incorrect adjustment.
For a fail-closed valve, verification may need to include:
- full closed travel;
- physical end-position confirmation;
- feedback confirmation;
- specified isolation or leakage acceptance;
- response under the required differential-pressure condition.
For a fail-open valve, verification may need to include:
- full opening travel;
- adequate flow path;
- open-position indication;
- absence of mechanical interference.
Confirm the Response with a Controlled Functional Trip Test
A controlled trip test should simulate the specific event defined by the project.
Depending on the requirement, the test may include:
- removal of instrument air;
- gradual reduction of air pressure;
- loss of control signal;
- solenoid de-energisation;
- removal of electrical power;
- confirmation of physical valve movement;
- confirmation of end-position feedback;
- confirmation of the resulting shutoff or flow condition.
The detailed method, safety controls and acceptance criteria belong in the project commissioning or test procedure. This guide does not replace that procedure.
What to Specify in a Datasheet or RFQ
An RFQ should not request only “fail-open or fail-closed.” It should define the process requirement, failure trigger and complete package response.
| Information Group | Information to Specify | Why It Matters |
|---|---|---|
| Process conditions | Medium, operating and design pressure, temperature, differential pressure, solids, crystallisation, corrosion, normal and upset duty | Determines valve suitability and whether the actuator can complete the required movement under actual service conditions |
| Valve construction | Size, body, lining, valve diaphragm, connection and diaphragm-valve type | Defines the process valve that the actuator must operate |
| Actuator arrangement | Single-acting or double-acting, air-to-open or air-to-close, spring direction | Defines how pneumatic pressure and stored mechanical energy create movement |
| Available pneumatic supply | Available pressure, minimum dependable pressure, air quality requirements | Minimum reliable pressure affects actuator force, full travel and successful commanded operation |
| Normal state | Normal operating position and deactivated reference condition | Prevents NO / NC from being confused with the required fail position |
| Defined failure event | Loss of air, loss of signal, solenoid de-energisation, loss of electrical power or another trip | Separates different failure responses and prevents package-selection ambiguity |
| Required final position | FO, FC or engineered FL | Defines the intended result for the stated event |
| Solenoid data | Valve function, energised state, de-energised porting and applicable electrical data | Determines whether actuator chambers are supplied, vented or blocked |
| Positioner data | Control signal, output behavior and configured failure response | Determines pneumatic response after signal or power loss |
| Feedback | Open / closed switches, position transmitter and local indication | Confirms what physical or commanded state is being reported |
| Manual intervention | Manual override or emergency operating method where required | Defines local recovery and operating capability |
| Shutoff requirement | Required isolation or leakage acceptance, specified independently | Defines actual process isolation and prevents FC from being treated as a leakage guarantee |
| Verification requirement | Trip condition, physical-position confirmation, feedback confirmation and flow or shutoff acceptance | Confirms actual complete-package behavior |
Process and Valve Data
At minimum, provide:
- process medium;
- operating and design pressure;
- temperature;
- maximum expected differential pressure;
- solids, crystallisation or contamination;
- corrosion conditions;
- body and lining requirements;
- valve diaphragm material;
- nominal size;
- end connection;
- required flow duty.
These inputs do more than confirm general valve suitability.
Maximum differential pressure, deposits, solids and media condition can directly affect whether the spring, actuator, stem, compressor and valve diaphragm complete the required failure stroke.
For a deeper review of flow rate, differential pressure, media condition and RFQ inputs, use the diaphragm valve sizing guide.
Detailed size, body, lining, diaphragm, connection and actuator options should be confirmed against the approved pneumatic diaphragm valve product documentation and the project engineering review.
Actuator and Available-Air Data
Specify:
- single-acting or double-acting;
- air-to-open or air-to-close;
- spring-to-open or spring-to-close;
- available instrument-air pressure;
- minimum dependable pressure;
- required stroke and travel indication;
- project-specific operating-speed requirement where applicable.
The exact actuator size and pneumatic demand depend on the approved valve configuration and service conditions. They should be verified using manufacturer data rather than assumed from nominal valve size alone.
Defined Failure Event and Required Final Position
Use a trigger-and-response format.
Example:
Failure event: Total loss of instrument-air supply Required response: Valve shall move to the closed position
A separate event may require:
Failure event: Solenoid de-energisation during emergency trip Required response: Valve shall move to the open position
A project may need separate entries for:
- instrument-air failure;
- signal failure;
- electrical-power failure;
- solenoid trip;
- normal shutdown;
- emergency shutdown.
Solenoid, Positioner, Feedback and Manual-Override Data
Specify:
- solenoid function;
- energised and de-energised porting;
- positioner type and fail output;
- limit switches or position transmitter;
- local position indication;
- manual override;
- lock-up or stored-energy devices;
- required electrical state during a trip.
Accessory behavior should not be inferred from the ATO or ATC label.
Shutoff and Verification Requirements
State separately:
- required final valve position;
- required leakage or isolation performance;
- required physical and remote indication;
- functional test condition;
- test acceptance criteria;
- documentation to be supplied.
This separation allows the project to confirm not only that the actuator moved, but that the valve achieved the required process result.
Frequently Asked Questions About Pneumatic Diaphragm Valve Fail-Safe Positions
What happens to a pneumatic diaphragm valve when instrument air fails?
The result depends on the approved actuator and pneumatic package. A single-acting spring-return actuator normally moves in the spring direction when the correct chamber vents. A double-acting actuator may stop temporarily, drift or respond through a stored-energy or lock-up arrangement. The final position must be confirmed from the configuration and a functional test.
Is an air-to-open diaphragm valve always fail-closed?
No. Air-to-open describes movement toward open as actuator pressure increases. A typical single-acting spring-to-close package commonly moves closed after total actuator-air loss, but retained pressure, alternate air supply, solenoid logic or other engineered arrangements can change the response.
Is an air-to-close diaphragm valve always fail-open?
No. Air-to-close describes movement toward closed as actuator pressure increases. It commonly pairs with spring-to-open and fail-open during actuator-air loss, but the actual response still depends on the defined event, solenoid porting and complete package arrangement.
Should a diaphragm valve fail open or fail closed?
The choice should be based on process consequences.
The key question is:
Under the specified failure, is the greater risk the unexpected interruption of required flow, or the uncontrolled continuation of feed, discharge or transfer?
The upstream and downstream consequences must both be reviewed before FO or FC is specified.
Can a double-acting pneumatic diaphragm valve be fail-safe?
Yes, but double-acting operation alone does not create a defined fail position. FO, FC or reliable FL may require stored air, a reservoir, lock-up equipment, special pneumatic logic or another engineered arrangement. The required response must be specified and tested.
Does loss of signal cause the same valve action as loss of air?
Not necessarily. Instrument air may remain available after the control signal disappears. The controller, positioner and solenoid determine whether actuator pressure is maintained, increased, reduced, vented or redirected.
Does a fail-closed pneumatic diaphragm valve provide bubble-tight shutoff?
No. Fail-closed defines the intended final position after a specified failure. It does not independently guarantee bubble-tight or zero-leakage isolation.
Shutoff performance depends on the valve diaphragm, sealing surface, travel, actuator force, process differential pressure and valve condition. The project must define and verify leakage or functional acceptance separately under the applicable service or test condition.
Conclusion
A pneumatic diaphragm valve fail-safe position cannot be defined reliably by one actuator label.
Air-to-open and air-to-close describe movement as pneumatic pressure changes. Normally open and normally closed describe a stated normal or deactivated condition. Fail-open, fail-closed and fail-in-place describe intended final positions after a defined failure.
The complete response depends on the valve, actuator, spring, pneumatic circuit, solenoid, positioner, feedback and any stored-energy or lock-up arrangement.
Selection must begin with process consequences. The resulting requirement must then identify the failure trigger, required final position, package configuration and verification method.
Before the final datasheet or purchase document is approved, the specified failure event and required safe position should be checked line by line against the proposed actuator, solenoid, pneumatic circuit, feedback and valve configuration. That comparison is the most direct way to prevent an unexpected field response.
Application / Specification Support
NTGD Diaphragm Valve can review the process data, required failure event, safe-state requirement and proposed complete package configuration before a pneumatic diaphragm valve is specified.

A useful review package includes:
- process medium, pressure and temperature;
- expected differential pressure;
- valve construction;
- actuator arrangement and available air;
- required FO, FC or engineered FL response;
- solenoid and positioner logic;
- feedback method;
- shutoff requirement;
- proposed functional verification condition.