TL;DR
Unplanned switchover means the primary controller faulted and transferred to the secondary. Review the event log to identify the fault type before restoring the secondary as hot standby.
What you might see
- primary controller changed to secondary without operator action
- redundancy status alarm on workstation
- event log shows controller fault at switchover time
- process holds or brief output bump at switchover
Likely causes
Power supply fault on the primary controller carrier
Processor module memory error or watchdog timeout
I/O network communication failure causing the controller to declare a fault
Firmware corruption or software exception on the primary module
Required tools
- Laptop with DeltaV Diagnostics software
- Multimeter (for power supply voltage check)
- LOTO kit (if re-seating modules requires isolation)
- Anti-static wrist strap
Safety first
- Removing a primary controller module while the system is live will transfer control to the secondary. Coordinate with operations before pulling any module.
- DCS cabinet contains live 24 VDC and 120 VAC circuits. Use insulated tools and appropriate PPE.
- Pharmaceuitcal batch processes may need to be placed in a hold state before a controller module change to prevent a CIP / SIP sequence from aborting unexpectedly.
Procedure
- 1
Check the DeltaV Diagnostics dashboard for the exact controller fault code and the switchover timestamp.[1]
- 2
Open the controller cabinet and inspect the primary controller module LEDs. Compare the LED pattern to the general indicator guide.[1]
- 3
Check the power supply module status indicators. A power supply fault can cause the controller to reload.
- 4
Inspect the I/O network cables and connectors on the primary carrier for loose connections or damage.
- 5
Pull the event chronicle for the 5 minutes before the switchover. Look for communication alarms, I/O card faults, or any watchdog messages.
- 6
If no hardware fault is found, reseat the primary controller module (with a planned outage or in a maintenance window) and monitor for recurrence.
- 7
After the root cause is resolved, re-synchronize the secondary module to restore full redundancy.
Sources
Emerson Emerson DeltaV DCS (Distributed Control) general technical documentation, Emerson
Emerson DeltaV DCS general controller diagnostics and redundancy procedures (general)
More guides for Emerson Emerson DeltaV
How to fix an I/O card communication fault on an Emerson DeltaV DCS
A BAD I/O card status means field signals are not reaching the controller. Identify whether the fault is the card, the carrier backplane, or the fieldbus wiring.
How to fix workstation communication loss on an Emerson DeltaV DCS
A single workstation losing communication is almost always a network issue: cable, switch port, NIC, or IP conflict. Check hardware first, then software.
Stop fixing the same fault twice.
Dovient turns guides like this into your team's shared playbook, with AI that catches recurring issues before they break the line.