engineering

Failure sequences for critical-environment HVAC: fan failure, door openings, fire alarm, and power loss

Written sequences of operation for cleanroom and containment HVAC faults: supply and exhaust fan failure, door events, fire alarm shutdown, power loss, and restart order.

Editorial reviewBy Mukarram Haroon
Direct answer

What this means

A critical-environment failure sequence states, for each fault, how the system moves from normal operation through detection, alarm, a defined safe state, and recovery. Every sequence follows from one decision per room: which way air must never flow. A positive product-protection room must never draw air in, and a negative containment room must never push air out, so in a containment room supply stops first and exhaust stops last, and after an outage exhaust starts and proves airflow before supply is allowed to run. That order, dampers with known fail positions, and controls on uninterruptible power stop airflow reversing when power returns and fans restart out of order.

Equipment and model context

  • Positive cleanroom suites and negative containment rooms with supply, exhaust, and makeup air systems under a building automation system
  • Sequences are templates to adapt; delays, setpoints, and fail positions are placeholders settled at design review and commissioning

These are sequence templates that show structure and order, not a sequence for a particular facility. Fire alarm responses are set with the fire protection engineer and the authority having jurisdiction under NFPA 90A and the local code, and containment responses in nuclear or high-hazard facilities follow that facility's safety basis.

What this covers

  • The five stages every failure sequence should state, from normal operation to recovery.
  • Written sequences for supply fan failure, exhaust fan failure, a door held open, and a fire alarm.
  • Why fans restart out of order after power returns, and the restart order that prevents reversal.
  • How to test each sequence during commissioning so it is proven before the room is used.

What changes the result

  • Whether a room protects its product, its surroundings, or both, which decides the forbidden airflow direction.
  • Drive restart settings, generator transfer time, and which fans share a power source.
  • Damper fail positions and whether the controls and monitors stay powered through an outage.
  • The fire and life safety strategy agreed with the authority having jurisdiction.

What a failure sequence has to state

A sequence of operations that covers failures well describes five stages for each event. Normal operation says what is running and at what setpoints. Detection names the measured signal, its threshold, and the time it must persist. The alarm says who is told, where, and at what priority. The safe state says exactly which fans, dampers, and valves go where. Recovery says what must be proven, in what order, before normal operation resumes.

Writing the stages separately exposes gaps that a single sentence hides. "On exhaust fan failure, alarm" says nothing about the supply fan, which is still running and is the reason the room goes positive. The general structure of a sequence is covered in the article on how to write a sequence of operations; this page applies it to the events that decide whether a critical room keeps its product or its containment.

First decide which way air must never flow

Every room gets one priority statement before any sequence is written. A positive room protects what is inside it, so the forbidden direction is inward: the room must never fall below the less clean space beside it. A negative room protects what is outside it, so the forbidden direction is outward. A room that does both, such as a negative cleanroom holding sterile hazardous drugs or the cleanroom around a hot cell, is written with containment first, because product can be discarded and a release cannot be recalled.

The DOE handbook for nuclear air cleaning puts the containment case plainly: pressure differentials between confinement zones should prevent backflow even under upset conditions. Upset conditions are the failures on this page. The priority statement tells every later sequence which fan stops first, which starts first, and which damper position is safe.

Supply fan failure in a positive cleanroom

In normal operation the supply fan holds its airflow setpoint, the return or exhaust tracks it at the design offset, and the room sits above its neighbors. The fault is detected when supply airflow stays below a set share of setpoint for a set time, or the drive reports a fault; both values are chosen at commissioning from trended data, so a brief dip during a filter-loading step change does not trigger it.

On detection, a standby fan or the remaining fans in an array are commanded to carry design airflow. Where no standby exists, the return or exhaust is reduced in proportion, so the room loses airflow without losing its pressure direction, and the room alarm tells operators to stop exposing product. A room without any standby cannot hold its class on reduced airflow for long, and the sequence should say that production stops.

Recovery starts when supply airflow is proven at setpoint. Return and exhaust are restored to their tracking offset, the pressure cascade is confirmed, and the room is held for a recovery period or a particle count before product is exposed again, since the room spent the event at reduced dilution.

Exhaust fan failure in a negative containment room

In normal operation the exhaust fan holds its airflow and supply tracks below it at the design offset, keeping the room negative. The fault is detected when exhaust airflow stays below its threshold for a short delay, measured at an airflow station rather than inferred from fan status, since a running fan with a broken belt or a closed damper moves no air.

On detection, a standby exhaust fan starts, with an isolation damper on each fan so air cannot recirculate backward through the failed one. Where no standby exists, supply stops or drops to a minimum immediately, because supply without exhaust turns the room positive, and the local alarm tells workers to secure open containers and stop work. The sequence names the delay and the order: supply off within the detection delay, not after an operator acknowledges the alarm.

Recovery follows the power-return order in the first figure. Exhaust runs and is proven first, supply is released and ramped, and normal operation is declared only after room pressure has held negative for a set period. The USP 800 ventilation requirements set the pressure band a hazardous drug room must return to.

Door openings and doors held open

A door opening is a normal event, not a failure, and the sequence treats it that way until time runs out. When a door contact opens, pressure-driven control loops are frozen at their current output so they do not chase the collapsed differential, and a door timer starts. When the door closes, the loops resume.

If the door stays open past its delay, a local alarm sounds at the door. A second, longer delay escalates to the monitoring system. Pressure alarms for rooms with a door open are suppressed for the same window, so operators receive one clear message about the door rather than a pressure alarm that trains them to ignore alarms. The pressure cascade design page shows why no airflow can hold pressure across an open doorway, which is the reason this sequence manages time instead of airflow.

Fire alarm response

NFPA 90A requires duct smoke detectors downstream of the filters in supply systems above 2,000 cfm, and at each story in return systems above 15,000 cfm serving more than one story, and requires the air handling unit to stop on detection. A fire alarm system signal can also command shutdown or a smoke control mode. Local mechanical codes can place the detectors differently, so the fire protection engineer and the authority having jurisdiction fix the exact requirement.

Containment is where the fire response needs a deliberate decision. Stopping a containment exhaust during a fire removes the negative pressure that keeps contamination inside, while running it can move smoke and heat into filters and ductwork. The approved strategy states which fans stop, which run, which smoke or fire dampers close, and whether containment exhaust continues on a protected path. The DOE handbook recommends that filters exposed to smoke from a fire be leak tested in place promptly and replaced if they fail, so the recovery stage includes that test before the room is declared safe.

Recovery after a fire alarm is manual: the fire alarm system is cleared and reset, a person confirms the rooms are safe to restart, and the automation system then runs the same ordered startup used after power loss.

Power loss and the restart that reverses airflow

Power loss stops every fan at once, and while everything is off no fan pushes air the wrong way. The danger comes at restart. Fans on the generator return within the transfer time, which NFPA 110 caps at 10 seconds for a Type 10 system, while fans on normal power return only when the utility does. Drives with automatic restart enabled start on their own timers, and a supply drive with a short delay can be running before an exhaust drive that is still waiting out its own.

Prevent it at several layers. Keep controllers, pressure monitors, and alarms on uninterruptible power so the automation system is awake before any fan is. Disable automatic restart on the drives whose premature start would reverse airflow, which for a containment room is supply, and let the automation system start them only after a permissive. Give each damper a fail position chosen from the priority statement, such as supply isolation dampers that close on loss of power. Put the fans that protect containment on standby power, as the DOE handbook asks for fans, dampers, and controls where the safety documentation requires backup power.

Then write the restart as the figures show: in a containment room exhaust first, proven, then supply; in a positive suite supply first, proven, then return and exhaust, with rooms verified from the cleanest outward. A room that spent the outage with no airflow is not released on pressure alone; a recovery hold or particle count confirms the air is clean again.

Testing the sequences before handover

A failure sequence that has never been run is a hypothesis. During functional performance testing under ASHRAE Guideline 0, each event is created for real: a fan is stopped at its disconnect, a door is propped open, a fire alarm input is simulated with the fire protection contractor present, and normal power is removed so the generator transfer and restart run end to end.

Trend room pressure, airflow, and damper positions at a fast interval through each test, and compare the trend with the written sequence line by line. A containment room that goes positive for a few seconds during a restart has failed the test even if it settles correctly afterward. The commissioning tolerances article covers how acceptance bands for pressure and airflow are set before the tests begin.

Restart order after power returns: negative containment room

Steps from restored power to normal operation for a room that must never push air outward, with exhaust proven before supply is released.

  1. Controls on UPSControllers, pressure monitors, and alarms stayed powered through the outage
  2. Fail positions heldSupply isolation damper closed, exhaust path positioned by the safety basis
  3. Exhaust startsAutomation system starts the exhaust fan on a controlled ramp
  4. Exhaust provenAirflow station or flow switch confirms flow for a set period
  5. Supply releasedSupply ramps up while room pressure stays negative
  6. Normal declaredPressure inside its band for a set period, alarms cleared
Restart order after power returns: positive cleanroom suite

The ordered steps from restored power to production for a suite that must never draw unfiltered air inward, starting supply first and verifying rooms from the cleanest outward.

  1. Controls on UPSMonitoring history records how far each room fell during the outage
  2. Supply startsSupply fans or fan filter units start before any return or exhaust fan
  3. Return and exhaust followReleased once supply airflow is proven
  4. Cascade verifiedPressure checked from the cleanest room outward
  5. Room releasedHold period or particle count before production restarts
Failure events: detection, safe state, and recovery
EventDetected bySafe stateRecovery
Supply fan failure, positive cleanroomSupply airflow below setpoint or loss of fan statusStandby fan or remaining array fans pick up; without one, exhaust reduced so the room cannot go negative and production stopsAirflow restored, then pressure and particle recovery confirmed
Exhaust fan failure, negative containment roomExhaust airflow below setpointStandby exhaust starts; without one, supply stops so the room cannot go positive and work stopsExhaust proven first, then supply released
Door held openDoor contact open past its delayLocal door alarm; airflow held at setpoint rather than chasing pressureAlarm clears when the door closes and pressure returns to band
Fire alarmFire alarm signal or duct smoke detectorAir handlers stopped as NFPA 90A and the approved fire strategy require; containment exhaust handled as that strategy statesManual reset after the fire system clears, then the power-return startup order
Loss of normal powerPower loss at each drive and transfer switchDampers at fail positions, controls and monitors on UPS, standby-powered fans held for an ordered restartStaggered restart with exhaust before supply in containment rooms
Pressure sensor faultSignal out of range or disagreement with a second sensorLast good airflow setpoints held and alarm raised, no damper control from a bad signalSensor replaced or recalibrated, then pressure control restored

Questions people ask about this

Should cleanroom fans restart automatically after a power failure?

Fans should restart under the automation system's control, not on their own drive timers. The automation system releases each fan in a set order once controls are powered and dampers are in position, so a containment room's exhaust is proven before supply starts and a positive suite's supply runs before its return and exhaust.

Does a fire alarm have to shut down containment exhaust?

Not necessarily. NFPA 90A requires air handlers above its airflow thresholds to stop on duct smoke detection, but whether a containment exhaust keeps running during a fire is a decision for the approved fire and life safety strategy, which weighs smoke movement against loss of containment with the authority having jurisdiction.

What delay should a cleanroom pressure alarm use?

Long enough to ignore a normal door entry and short enough to catch a real loss of pressure, which depends on how long a door cycle takes in that room. Set it at commissioning from trended pressure during real door use, and add a separate door-held-open alarm so the pressure alarm is not the only warning.

Do room pressure monitors need uninterruptible power?

Monitors, controllers, and alarms should stay powered through an outage and the generator transfer, so the record shows what the rooms did and the restart has live readings to act on. A monitor that reboots with the fans cannot confirm that the restart order was followed.

Evidence record

Source verification pending

standards body publication, government guidance · editorial review

This page is awaiting source verification against the documentation in its evidence record: National Fire Protection Association, United States Department of Energy, ASHRAE, National Institutes of Health, Office of Research Facilities and United States Pharmacopeia technical literature. Its documentation class and intended scope are shown here while that check is pending.

Documentation class
standards body publication, government guidance
Scope of the definition
Confirm against the exact model manual