Reliabilityweb
What happened
A case study describes a gas-turbine generator trip that occurred when one of three safety controllers failed. It shows a 2-out-of-3 voting architecture did not prevent a process interruption, making the distinction between fault tolerance and fail-safe behavior operationally real. Watch whether suppliers publish retrofit plans, test reports, or formal fail-safe verification steps next
Why the category manager should care
Don't accept 'fault-tolerant' labels; demand supplier evidence of fail-safe outcomes and documented test results before approving control-logic changes
Key facts
- Case study of a gas-turbine generator trip after a single safety-controller failure
- Highlights limits of 2-out-of-3 (2oo3) voting architectures in preventing interruptions