Fail-Safe or Fail-Secure? Choosing the Right Locking Logic for Access-Controlled Doors
| Power-loss behavior, free egress and fire-alarm response are separate decisions that must be coordinated at each opening.
For: access-control integrators, security consultants, door-hardware specifiers and electrical contractors | Technical review: TOPTEK Access Fail-safe and fail-secure describe the lock’s state when control power is removed; they do not by themselves define safe egress.
The quick answerThe phrase “fail safe” sounds universally safer, but uncontrolled unlocking during every power interruption can create a serious security problem. “Fail secure” sounds more secure, but it is unacceptable where power removal is required to unlock the means of egress. The correct answer depends on the opening’s code path and operating intent. Document three states: normal power, loss of lock power and emergency-system activation. For each state, show who can enter, who can exit, which signals are monitored and how staff regain control. Separate entry security from egress behaviorFail-safe and fail-secure normally describe the electrically controlled side—often the outside lever or locking element—when power is removed. Free egress describes what an occupant can do from the egress side. A properly selected mortise lock may keep the outside secure during power loss while the inside lever remains mechanically free, but that must be verified for the exact function. Do not use the electrical label as a substitute for a function description. State whether the inside lever retracts the latch at all times, whether a deadbolt is present, and whether any credential, sensor, key or special knowledge is required to exit.
When fail-safe may be requiredFail-safe behavior is common where the applicable code or approved design requires the lock to release upon loss of power, activation of the fire-alarm system or another life-safety event. Electromagnetic locks and certain special locking arrangements often use this logic. The exact release path matters. Removing controller data while lock power remains present is not the same as removing lock power. The design should identify the listed power supply, relay logic, fire-alarm interface and any local release device required by the authority having jurisdiction. When fail-secure protects the openingFail-secure logic keeps the controlled side locked during power loss. It can be appropriate for perimeter, storage or other security-sensitive openings when code-compliant mechanical egress remains available. The mechanical key override and emergency access plan become especially important during a prolonged outage. Security teams should decide whether the goal is to preserve perimeter security, protect assets, prevent re-entry or maintain compartmentation. Those goals may lead to different functions at doors that look identical. Test more failures than a power switchCommissioning should include normal credential grant, denied credential, loss of mains power, loss of lock power, controller reboot, network loss, broken communication, fire-alarm input, request-to-exit action and mechanical key operation. Confirm both the physical door state and the event reported to the access-control system. UL Solutions notes that access and egress locking configurations can require integration with fire detection or suppression systems, fail-safe or fail-secure features, and other code provisions. The project’s code analysis and listed product configuration—not a generic diagram—should control the final circuit. State-by-state approval matrix
Electrified mortise-lock example: the exact mechanical function and powered state must be read together. Fail-mode selection checklist▪ Identify the applicable building, fire, accessibility and security requirements. ▪ Describe entry and egress separately for normal, power-loss and emergency states. ▪ Confirm the exact lock function, handing and inside-lever behavior. ▪ Define which circuit loses power and which controller/fire-alarm relay initiates it. ▪ Check voltage, current, inrush/holding load and listed power-supply capacity. ▪ Specify mechanical key override and emergency access responsibility. ▪ Monitor physical door/lock condition where required—not just relay command. ▪ Witness and record every scenario at the completed opening. What a capable manufacturing partner should provideTOPTEK’s electronic locks and access-control devices include ANSI and EN mortise-lock formats. Selection should be made by exact function, voltage and operating logic rather than by appearance or a generic “electric lock” description. For a new platform, use a joint hardware-and-electrical review. TOPTEK’s electronic engineering capabilities can support interface confirmation, prototype operation and controller-side questions before site deployment. Frequently asked questionsDoes fail-secure mean occupants are locked inside during power loss?Not necessarily. Many mortise-lock functions preserve mechanical free egress from inside while the outside remains secure. Verify the exact lock and code path. Does a fire alarm always need to remove lock power?Requirements depend on the locking arrangement and jurisdiction. The approved code sequence and authority having jurisdiction should determine the interface. Is relay status proof that the door unlocked?No. A controller command confirms intended state, not necessarily physical bolt or lever condition. Use appropriate monitoring where the risk requires it.
|
||||||||||||||||||||||||