![]()
DEGRADED VOTING IN ESD SYSTEM: What Happens When One Voting Channel Fails? ![]()
![]()
Imagine an ESD system uses 3 pressure transmitters with a 2oo3 voting architecture.
Normally:
PT-1 β ![]()
PT-2 β ![]()
PT-3 β ![]()
The ESD trips when 2 out of 3 transmitters indicate the defined trip condition.
But what happens if one transmitter becomes faulty or is taken out for maintenance?
The system may enter a degraded voting state, depending on the approved SIS/ESD design.
What is Degraded Voting?
Degraded voting is a condition in which the normal voting architecture of a redundant ESD/SIS function is reduced or changed because one or more channels are unavailable, faulty, or intentionally taken out of service.
In simple terms:
Normal redundancy β One channel unavailable β Reduced voting capability
The exact degraded behavior is system- and application-specific.
Example: Normal 2oo3 Voting
Suppose three pressure transmitters protect a process:
PT-1 + PT-2 + PT-3 β 2oo3 Logic β ESD Trip
Normal operation:
| PT-1 | PT-2 | PT-3 | Result |
|---|---|---|---|
| Normal | Normal | Normal | No Trip |
| Trip | Normal | Normal | No Trip |
| Trip | Trip | Normal | |
| Trip | Trip | Trip |
This provides redundancy while reducing the possibility of a single transmitter causing an unwanted shutdown.
One Transmitter Becomes Unavailable
Suppose:
PT-3 = Fault / Maintenance
The system now has only:
PT-1
PT-2
The approved degraded-state logic might require both remaining channels to agree before initiating the trip.
For example:
2oo3 β degraded 1oo2
Then:
PT-1 Normal
PT-2 Normal
No Trip
But:
PT-1 Trip
PT-2 Trip
ESD Trip
However, 1oo2 is only an example. Some systems may use a different degraded strategy, inhibit the affected channel, generate a maintenance alarm, or require a controlled shutdown depending on the safety requirements.
Why Is Degraded Voting Important?
When redundancy is lost:
Fault tolerance may be reduced
Diagnostic capability may change
Spurious-trip probability may increase
The probability of failing to respond to a genuine demand may increase
Additional operational restrictions may be required
Therefore:
A degraded voting state should be treated as a temporary impairment of the designed redundancyβnot as normal operation.
Example During Maintenance
Suppose PT-2 requires calibration.
Before removing it:
Approved procedure
![]()
Risk assessment
![]()
Controlled bypass/inhibit or degraded voting arrangement
![]()
PT-2 maintenance
![]()
Testing
![]()
PT-2 restored
![]()
Normal voting restored
The exact procedure must follow the SIS philosophy, Cause & Effect, operating procedure, and vendor implementation.
Normal vs Degraded Voting
Normal:
PT-1
PT-2
PT-3
![]()
2oo3
![]()
ESD action
Degraded:
PT-1
PT-2
PT-3 unavailable
![]()
Approved degraded logic
![]()
ESD action if the defined degraded trip condition is met
Important Point
Degraded voting does not mean simply changing 2oo3 to 1oo2 whenever an instrument fails.
The degraded architecture must be defined and engineered in advance.
The safety analysis should consider:
Safe failure
Dangerous failure
Common-cause failure
Spurious trips
Diagnostic coverage
Proof-test requirements
Bypass/inhibit philosophy
Maximum permitted time in degraded state
Interview Question
What is degraded voting in an ESD system?
Degraded voting is the controlled reduction or modification of a redundant voting architecture when one or more voting channels become unavailable or faulty, while maintaining the specified safety function as far as permitted by the approved safety design.
Remember:
2oo3 = Normal redundancy
One channel unavailable = Degraded condition
Restore the failed channel = Return to normal voting
The goal of degraded voting is not simply to keep the plant runningβit is to manage reduced redundancy without compromising the required safety integrity.
#DegradedVoting #ESD #SIS #2oo3 #1oo2 #FunctionalSafety #SafetyInstrumentedSystem #IEC61511 #ProcessSafety #SafetyPLC #Instrumentation #IndustrialAutomation #CauseAndEffect #ESDSystem #InstrumentationEngineer ![]()
![]()
![]()
