Bad PV Handling: 7 Essential DCS Rules for Safe Loop Control

Share:
DCS
Bad PV Handling: 7 Essential DCS Rules for Safe Loop Control

A controller acting on a broken measurement can drive a valve fully open in seconds and push a unit into a trip or worse. Every DCS therefore checks the quality of each process value and decides what the loop, the alarm and the interlock should do when that value cannot be trusted.

Signal Status NAMUR NE 43 Mode Shedding Hold Last Value Voting

A failed transmitter does not just give a wrong number, it can mislead a control loop and an interlock at the same time. Learn how a DCS detects a bad process value and how loops, alarms and voting logic should respond.

Hello everyone, today we are going to learn what bad PV handling means in a DCS, how signal status is decided, how NAMUR NE 43 limits help, and how loops, alarms and interlocks should respond to a failed measurement.
Bad PV

What Is Bad PV Handling?

Bad PV handling is the set of DCS rules that detect when a process variable can no longer be trusted and then decide how control loops, alarms and interlocks react to it. It starts at the input card, where a broken wire or a failed transmitter on a 4 to 20 mA current loop first shows up.

Every value in a modern DCS carries a status along with its number. The status flows through the function blocks described in DCS function block programming, so a downstream PID block knows whether its input is healthy.

FOUNDATION Fieldbus function block connections

The Control.com fieldbus textbook explains that blocks can be programmed to switch mode when a Bad or Uncertain input status is detected. The same source notes that a Bad status propagates downstream, so no block acts on data it should not trust.

Advertisement

Good, Uncertain and Bad Signal Status

Good

The value is valid and within its configured range, and the device reports no fault.

Best for: normal automatic control
Use
Uncertain

The value may be usable but has lower confidence, such as a reading beyond range or a sensor near its limits.

Best for: display, cautious control
Review
Bad

The device, wiring or card has a detected fault, so the number must not drive control.

Best for: alarm and safe action
Reject

FOUNDATION Fieldbus, HART devices and OPC servers all use this three level idea, with substatus codes such as sensor failure, device failure, out of service or last usable value. The KMITL fieldbus paper states that devices separate serious problems as Bad and less serious ones as Uncertain, a scheme also used in FOUNDATION Fieldbus.

For plain analog signals, bad PV handling begins at the DCS input card, which assigns the status itself from the current level and its own diagnostics. HART devices add more detail through device status bits, as explained in how the HART protocol works.

Do You Know?

NAMUR NE 107 groups device diagnostics into four signals: Failure, Function Check, Out of Specification and Maintenance Required. A DCS can map Failure to Bad and Out of Specification to Uncertain for each process value.

NAMUR NE 43 Limits for 4 to 20 mA

NAMUR NE 43 lets the input card tell a real measurement from a failure signal. A transmitter keeps its measuring signal between 3.8 and 20.5 mA, and drives 3.6 mA or less, or 21 mA or more, when it detects an internal fault, as covered in NAMUR NE 43 standard explained.

Loop CurrentMeaningStatus in DCS
3.6 mA or lessTransmitter failure, downscaleBad
3.6 to 3.8 mABelow measuring range, not yet failureUncertain
3.8 to 20.5 mAValid measurement including slight over rangeGood
20.5 to 21 mAAbove saturation, not yet failureUncertain
21 mA or moreTransmitter failure, upscaleBad
Near 0 mAOpen wire or lost loop powerBad

Whether a transmitter fails high or low is a configuration choice. Temperature transmitters call this burnout direction, described in burnout function in temperature transmitters, and it should match what makes the process safer.

Quick Tip

During loop checks, use a HART communicator to force 3.5 mA and 22 mA from the transmitter. Confirm the DCS shows Bad status and raises the right alarm before you sign the loop sheet.

NE 43 Status and PV Calculator

This calculator converts a loop current into engineering units and classifies its status using the NE 43 bands. It helps when deciding which band a reading falls in during loop checks or troubleshooting.

PV = LRV + (mA minus 4) ÷ 16 × (URV minus LRV)
Percent of span = (mA minus 4) ÷ 16 × 100

Example: 20.8 mA on a 0 to 200 °C range
PV = 0 + 16.8 ÷ 16 × 200 = 210.00 °C
Percent = 16.8 ÷ 16 × 100 = 105.0 %
20.8 mA lies between 20.5 and 21 mA, so status is Uncertain
Loop Current to PV and NE 43 Status
Result
Status Uncertain, PV 210.00 at 105.0 % of span

At 3.7 mA the same range gives minus 3.75 °C with Uncertain status, a common sign of a drifting transmitter or a leaking cable. Values outside the measuring band should be investigated even when they are not yet marked Bad.

Advertisement

How a PID Loop Reacts: Mode Shedding

When the PV of a PID block turns Bad, the usual bad PV handling action on most DCS platforms is to shed the loop from AUTO or CASCADE to MANUAL, or to an initialisation manual mode, and freeze the output. The available modes are explained in DCS control modes.

Input FaultWire break or NE 43 failure current
Status BadCard or block marks the PV
Mode ShedPID moves from AUTO to MAN
Output HeldLast output kept or safe value applied
AlarmOperator told which tag failed
RecoveryPV good again, operator returns to AUTO

In a cascade, a Bad secondary PV also breaks the outer loop, which must stop integrating and track its output. The structure of such loops is described in cascade control.

The KMITL paper on FOUNDATION Fieldbus cascade control describes a further option, where the PID passes a Bad status to the AO block. That forces the AO fault state and drives the valve to its configured safe position because control cannot continue without a measurement.

Do You Know?

Writing in Control magazine, John Rezabek describes a refinery fired heater startup where a temperature loop did not shed to manual as expected. The case shows that status options must be tested, never assumed.

Hold Last Value or Go to a Safe Output?

Hold Last Value
  • Process stays where it was, no sudden valve movement.
  • Suits slow, stable loops such as tank levels.
  • Gives operators time to switch to a backup measurement.
  • Avoids nuisance trips from short glitches.
Drive to a Safe Output
  • Removes risk when holding could overfill or overheat.
  • Matches the valve fail position for the hazard.
  • Needed when the loop protects equipment directly.
  • Can upset the unit, so use with care.

In bad PV handling, the choice should follow the process hazard, not a default setting. For final elements, align it with the valve fail action covered in fail safe valve positions.

7 Essential Bad PV Handling Rules

1
Configure NE 43
Set transmitters and cards to the same failure current and direction.
2
Map Status
Map card, HART and fieldbus diagnostics to Good, Uncertain and Bad.
3
Decide Uncertain
Choose per loop whether Uncertain is treated as good or causes shedding.
4
Set Shed Mode
Define the mode and output action for every loop on Bad PV.
5
Alarm Once
Raise one clear bad PV alarm per failed tag, not a flood.
6
Vote Safely
Decide how a Bad input counts in every voting interlock.
7
Test It
Simulate failures during FAT, SAT and after every change.

Rule three is where many surprises hide. Rezabek reports that a default option, use uncertain as good, left unchecked made PID blocks shed to manual whenever the measurement went beyond its configured full scale, even though the signal was accurate.

Advertisement

Bad PV Handling for Alarms

A bad PV alarm, often called input open or IOP, tells the operator that a measurement has failed, not that the process has changed. Its priority should follow the rationalisation rules of ISA 18.2 alarm management.

When a value goes Bad, process alarms on that tag such as high and low should be suppressed, since they are now meaningless. Without this, one failed transmitter can produce several alarms, a problem tools in alarm shelving cannot fully solve.

Quick Tip

Add a short delay of a few seconds to bad PV alarms on noisy analog points. It stops one momentary spike from creating an alarm and then a return to normal message.

Bad PV Handling in Interlocks and Voting

In a 2oo3 trip, a Bad input is commonly configured to vote as tripped, so the logic degrades to 1oo2 and still protects the plant. The voting logic itself is explained in 2oo3 voting logic.

Other plants vote a Bad input as healthy and raise a high priority alarm, which avoids spurious trips but reduces protection until repair. The trade off between safety and availability is covered in voting architectures in safety systems.

Myth: A frozen PV is a good PV.
Fact: A stuck value can still carry Good status, so add rate of change or deviation checks between redundant transmitters.
Myth: Mode shedding makes the loop safe.
Fact: It only stops the PID, and the held output may still be unsafe for the process.
Myth: Uncertain always means faulty.
Fact: Uncertain values are often usable, so treat them per loop rather than one global rule.
Myth: The SIS will handle any bad measurement.
Fact: The control system must handle it too, since the SIS acts only at the trip point.

Troubleshooting Bad PV Handling in the Field

  • Read the loop current at the marshalling terminals with a clamp meter.
  • Check the status and diagnostics on the transmitter or HART communicator.
  • Look for open wires, loose terminals and water in junction boxes.
  • Confirm loop supply voltage and fuse at the card.
  • Check card and channel diagnostics in the DCS.
  • Verify ranges match between transmitter and DCS tag.
  • Return the loop to AUTO only after the PV is Good.

If several tags go Bad together, suspect a common cause such as a card, power supply or remote I/O node, as listed in remote I/O failure modes. Single tags usually point to field wiring or the transmitter, explained in analog input problems and solutions.

Fieldbus Cascade Control Safety Paper

PDF
How to Fully Benefit from Function Blocks of Foundation Fieldbus for Digital Cascade Control with High System Safety
KMITL paper on status, fault state and safe cascade loops

NAMUR NE 43 Explained in Video

Bad PV Handling FAQ

What is bad PV handling in a DCS?

It is the set of rules that detect an untrustworthy process variable and define the response. The response covers the control loop, the alarm system and any interlock using that signal.

Typical actions are mode shedding, holding the last output and raising a clear alarm. Voting logic must also define how a failed input counts toward a trip.

What do Good, Uncertain and Bad mean?

Good means the value is valid and the device reports no fault at all. Uncertain means the value may be usable but carries less confidence, such as a slight over range.

Bad means a detected fault, so the value must not drive control or a trip directly. Substatus codes explain the reason, for example a sensor failure or an out of service device.

How does NAMUR NE 43 help?

It supports bad PV handling by reserving 3.8 to 20.5 mA for real measurement and uses 3.6 mA or less, or 21 mA or more, for failure. The input card can then tell a real process value from a transmitter fault.

Values between the two bands are usually given an Uncertain status by the input card. Set the transmitter burnout direction to the side that is safer for the process.

What is controller mode shedding?

It is the automatic change of a PID block from AUTO or CASCADE to a manual mode when its PV becomes Bad. The output is frozen so the loop stops reacting to a wrong number.

Some systems instead send a fault state to the output block to move the valve to a safe position. The right choice depends on the process hazard.

Should the output hold or go to a safe value?

In bad PV handling, holding the last output avoids upsets and suits slow, stable loops such as tank levels. It gives the operator time to switch to a backup measurement while the fault is repaired.

A safe output is better when holding could overfill, overheat or overpressure equipment. Align that output with the valve fail position chosen during hazard reviews.

How should voting logic treat a Bad input?

Many plants vote a Bad input as tripped, so a 2oo3 function degrades to 1oo2 and stays protective. That approach favours safety over availability.

Others vote it as healthy and raise a high priority alarm to avoid a spurious trip of the unit. Whichever rule is chosen must be documented in the safety requirements and tested.

How do I test bad PV handling?

Force failure currents of about 3.5 mA and 22 mA from the transmitter or a loop calibrator during checks. Then confirm the status, the alarm and the controller mode change on the DCS screen.

Repeat the test for cascade loops and voting interlocks during factory and site acceptance tests. Retest after every DCS upgrade, since default options can change between versions.

Advertisement

Related Articles

External References

What We Learn Today

  • Bad PV handling starts with status, where every DCS value is marked Good, Uncertain or Bad from card diagnostics, HART data or fieldbus substatus.
  • NAMUR NE 43 keeps measurement between 3.8 and 20.5 mA and signals failure at 3.6 mA or less, or 21 mA or more.
  • On a Bad PV, loops shed to manual or a safe output, one clear alarm is raised and voting logic follows a documented, tested rule.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *