Field note, first posted on LinkedIn.
Redundancy hides failures. That is what it is designed to do.
A dual or TMR turbine control keeps running with one channel down. So a failed module, a dead power supply or a drifting input can sit there for months. The second fault is the one that can trip the unit.
What I look at in a controls health check:
- 1.Diagnostics on every controller and I/O module, not only the alarms on the HMI.
- 2.All controllers online and in sync, standby ready to take over.
- 3.Voting: redundant inputs that no longer agree.
- 4.Electrical health: feeds, supplies, ground faults, loose wiring, blown fuses.
- 5.Every network path up.
- 6.Same application and firmware everywhere, backup current.
How often do you check your redundant controls, and what is on your list?