On this page
When a fluid heater loses its intended heat-removal path, the heater surface can warm much faster than the useful fluid temperature suggests. Dry-run detection should therefore be based on how the actual assembly behaves during abnormal loss of fluid contact or flow. Temperature, rate of rise and process-state signals can contribute, but their meaning depends on sensor location, delay and the failure being detected. Normal temperature control and protective shutdown require separate review.
Key design decisions
- Define the abnormal boundary: absent fluid, low flow, trapped gas or partial wetting.
- Measure heater-side signals that can reveal loss of heat removal before a delayed load sensor does.
- Review independent interruption and fault behavior with the responsible equipment safety engineer.
Distinguish the dry-run scenarios
An empty vessel, a blocked flow path, a gas pocket and partial wetting do not produce identical temperature fields. Some remove cooling from the whole heater, while others create a small local hot region beside normally cooled material. The fault definition should identify where heat transfer is lost and which signals are expected to change.
Include plausible startup and shutdown states. A legitimate filling sequence may temporarily resemble an abnormal condition, and residual fluid after shutdown may cool one region but not another. Detection logic needs the process context without allowing an uncontrolled heating interval. The equipment design should establish which states permit power and which require inhibition or interruption.
Relate the temperature rise to lost heat removal
At a given electrical input, reducing useful heat removal leaves more energy in the heater and nearby structure. The initial rate of temperature rise depends on the participating thermal capacity and remaining losses. A thin local region can heat quickly even while the bulk assembly changes slowly.
Use this energy balance to decide where fast observations are needed. It does not provide a universal dry-run threshold because contact, fluid properties, heater construction and operating temperature all affect the response. Characterize the actual assembly under an approved, controlled fault-test plan with suitable protection. Do not infer safe fault duration from a nominal power rating or a normal steady-state thermal map.
Choose signals that observe the vulnerable region
A fluid outlet sensor may remain cool after flow stops, while the heater beneath it becomes hot. A sensor on a massive support may respond slowly, and a sensor far from a gas pocket may not see the local peak. Select locations from the heat-transfer and fault map, not only from wiring convenience.
Temperature measurements can be supplemented by flow, level or other process-state observations where appropriate. These signals answer different questions and have their own failure modes. A flow indication does not necessarily prove full wetting of every heated surface, while a temperature rise alone may also occur during normal startup. The design review should describe what each signal can and cannot distinguish.
Evaluate rate of rise without amplifying noise into a fault
Temperature rate can reveal loss of cooling earlier than an absolute threshold in some systems, but differentiation magnifies noise and depends on sampling and filtering. Specify the time interval used to calculate the rate and examine both genuine faults and the fastest normal transient.
A long filter can reduce nuisance trips while delaying detection. A short interval can respond rapidly but produce false triggers from noise, sensor contact changes or switching interference. Characterize that trade from recorded data. Threshold selection should include sensor uncertainty, process variation and the consequences of missed or delayed detection rather than being chosen from a single particularly clear test trace.
| Signal | Potential value | Limitation to address |
|---|---|---|
| Heater-side absolute temperature | Directly observes excessive temperature near the chosen location. | A remote or poorly attached sensor can miss a local hot region or respond too slowly. |
| Temperature rate of rise | Can identify a rapid change in heat removal before a high absolute temperature is reached. | Noise, filtering and normal startup behavior can overlap the proposed trigger. |
| Flow or level state | Can inhibit heating when a required process condition is absent. | One measurement may not prove complete wetting or detect a trapped local gas pocket. |
| Electrical power and current | Confirms whether heat input continues after a command or fault indication. | Electrical input alone does not reveal where cooling has been lost. |
Separate protective interruption from normal control
The normal controller regulates a process temperature. A protective function must address relevant failures that could prevent that controller from acting correctly, including sensor faults or a switching device that remains on. The appropriate degree of independence and the required interruption architecture belong to the equipment safety assessment.
Document the complete chain from detection through power removal, including delays and the behavior after a fault. A software command to stop heating is not the same as verified interruption of electrical energy. Consider whether the protective sensing path shares a vulnerable location, supply or device with the normal loop. Avoid assuming that two labels on one controller establish independent protection.
Compare abnormal traces with the full normal envelope
The test program should include relevant normal extremes such as cold startup, maximum intended input, low permitted flow and changes in load. Compare these with the defined abnormal conditions using synchronized temperature, process-state and electrical records. The fault-test procedure must be approved and executed with suitable safeguards and interruption limits.
Preserve the time between the physical loss of cooling, the detected condition, the interruption command and the actual cessation of power. These are distinct events. Temperature can continue rising after power is removed because heat remains stored in adjacent regions. Record that residual rise rather than ending the trace at the control signal.
Investigate partial faults and sensor failures
A whole-heater dry test may be easier to interpret than a small partially dry region, but it may not be the most demanding detectable fault. Review partial wetting, localized scale and gas pockets where the application makes them credible. Spatial observations can show whether the selected sensors see those regions.
Also examine the protective system’s response to open, shorted, detached or implausible sensor signals using the approved equipment procedure. A detached sensor may continue reporting a plausible cool temperature, making simple electrical continuity checks insufficient. The final protection claim should be tied to the actual faults covered, not a broad label that conceals untested local or sensing conditions.
Provide a fault-detection evidence package
A completed review contains a fault map, normal and abnormal time traces, sensor positions, detection timing and confirmed power-interruption behavior. It identifies who owns threshold selection, safety validation and changes to the control architecture. The heater supplier can provide construction and thermal observations while the equipment integrator validates the complete protective system.
Revisit the detection basis after changes in power, mounting, fluid path, sensor attachment or thermal mass. These changes can alter both normal transients and fault speed. A threshold that worked for one assembly should not be copied to another merely because the nominal heater resistance or target fluid temperature is unchanged.
Send the fluid path and fault scenarios
A dry-run review needs a physical description of lost cooling and a clear division between normal control and protective shutdown.
- Heater and fluid-path drawings showing wetted areas, possible gas pockets, supports and the regions most vulnerable to local overheating.
- Normal voltage, current, flow, fill sequence, fluid properties and operating temperature range with expected startup transients.
- Sensor types, attachment and coordinates, sampling and filtering, proposed process-state inputs and the power-interruption architecture.
- Approved fault-test records with synchronized physical event, detection, command, actual power removal and residual-temperature observations.
The drawing-upload form loads as you reach this section.

