Back to articles

Automation & Instrumentation

Loop Break Alarms: When the Thermocouple Isn't Where You Think It Is

How loop break alarms detect heater output without the expected temperature response, and how they complement sensor-break alarms and independent high-limits.

Heater controller showing an alarm beside a heated reactor, with the control thermocouple lifted out of its well. Technical illustration · Displaced control thermocouple

A loop break alarm catches the failure your temperature sensor can’t report on its own: a thermocouple that works perfectly but is no longer measuring the thing your heater is heating.

Most people configuring a heater controller know to watch for a broken thermocouple. An open circuit is easy to detect, and every decent controller does it. The harder case is a thermocouple that was left out after maintenance, never pushed all the way back into its well, or pulled loose during work nearby. The signal is clean and the reading is believable. It’s just reading the wrong place, and the PID loop will keep driving the heater harder trying to fix a temperature it can’t actually change.

How a heater loop normally behaves

A heater control loop has two numbers worth watching: the process value (PV) from the thermocouple, and the output the controller sends to the heater, expressed as a percentage of full power.

You enter a setpoint. If the PV is below it, the PID raises the output. As the heater warms the process, the PV climbs toward setpoint and the PID backs the output off until it settles at whatever percentage holds the temperature steady. The key relationship is cause and effect: more output should produce a rising temperature, within a time that depends on the thermal mass and how tightly the thermocouple is coupled to the heater.

When that relationship breaks, the PID has no way of knowing. If the PV drops or refuses to rise, the controller does exactly what it was designed to do. It raises the output, and keeps raising it until it hits 100% or whatever output limit you’ve clamped it to.

What a loop break alarm actually checks

A loop break alarm watches for output without response. The most common way it’s built is an AND condition feeding a delay timer:

  1. The heater output is above a threshold, and
  2. The PV’s rate of rise is below a threshold.

When both are true, the AND starts the timer. If both are still true when the timer runs out, the alarm trips. If either clears first, because the output backs off or the temperature starts climbing, the timer resets.

A simpler variant replaces the rate check with an absolute temperature: by the end of the delay, the PV must be above a fixed value, usually 10 to 15 degrees over ambient. That reliably catches a thermocouple sitting in open air, which is the most common version of the problem. Its blind spot is a thermocouple reading somewhere warm but wrong, like the insulation around a heated line. That reading clears the threshold easily, so the alarm stays quiet while the heater runs at full output.

Many controllers have a built-in version of the same logic, usually set as a loop break time and a band the PV must move within that time while the output is high. The parameter names differ, but the logic is the same.

Many implementations also check the opposite direction. If the output is at 0% and the temperature keeps rising, something is heating the process that the controller isn’t commanding, such as a solid state relay that has failed shorted.

Because the alarm is watching the whole loop rather than the sensor, it catches more than a displaced thermocouple:

  • A thermocouple left out, not fully inserted, or pulled out of its well
  • A heater element that has burned out
  • A blown fuse, tripped breaker, or open contactor in the heater circuit
  • A solid state relay failed open (no heat) or shorted (heat it can’t stop)
  • A thermocouple wired with reversed polarity, so the reading moves the wrong way as the heater warms
Three-panel comparison of normal heating, overheating with a thermocouple left out of its well, and a loop break alarm detecting too little temperature change despite rising heater output.

Loop break is not sensor break

A sensor break alarm detects a failed signal. A loop break alarm detects a healthy signal that has stopped meaning anything. You want both, because neither covers the other.

Sensor break works at the input. The controller drives a tiny current through the thermocouple circuit; if the wire breaks or a junction opens, the input reads as out of range and the controller flags it, usually forcing the output to a safe value immediately. It’s fast and reliable, but it only knows whether the circuit is intact.

A thermocouple sitting in ambient air or wedged in pipe insulation has an intact circuit. Sensor break sees nothing wrong. Only the loop break alarm, which compares what the controller is asking for against what the temperature actually does, has a chance of noticing.

What it looks like on a real reactor

I’ve seen this firsthand on a reactor. A thermocouple gets left out after something is taken apart and reassembled, or it doesn’t get pushed all the way back in and ends up sitting in the insulation around a line instead of against the part it’s supposed to measure.

When the system heats back up, the reading starts low and climbs slowly, if at all. The PID sees a large error and drives the output up. Without a loop break alarm, the output goes to 100% or wherever it’s clamped and stays there.

The misleading part is that the temperature may still rise. A thermocouple stuck in nearby insulation picks up some heat from the heater, so the trend isn’t flat and nothing looks obviously broken. But the rate of rise at full output is far below what the system should produce, and the real metal temperature is running well ahead of the reading. Left alone, that ends with overheated heater elements, damaged seals and fittings, or a reactor body taken past what it was designed for.

Setting it up

There are three settings: the output threshold, the rate threshold (or absolute temperature), and the delay. Get any one of them wrong and the alarm either trips on every cold start or never trips at all.

Size all three from a measured response. Run the heater at full output from cold and record two things: how long it takes the PV to start climbing steadily, and how fast it climbs once it does. Use the slowest normal case, such as a cold start at maximum flow or low ambient.

The delay should comfortably exceed the time before the PV starts climbing. Too short and a heavy block or a cold vessel trips it every startup. Too long and the heater has done its damage before the alarm says anything. Some controllers calculate a loop break time during autotune, and a commonly cited starting point is about twice the integral time. Treat either as a value to verify, not an answer.

Set the rate threshold well below the rate you measured, low enough that a working heater always clears it but high enough that a thermocouple warming slowly from stray heat doesn’t. Calculate the rate over a window of several seconds or filter the PV first. A raw derivative of a thermocouple signal is noisy, and every noise spike that drops the AND condition resets the timer.

Set the output threshold to arm before the output reaches its clamp. If you’ve limited a heater to 70% output, a 90% threshold will never arm, and the alarm is effectively disabled without anyone noticing.

Then decide what the alarm does. On many controllers the loop break alarm is only an alarm: it lights an indicator and nothing else. For it to protect anything, it has to be configured to force the output off, or mapped to a relay that drops the heater contactor and latches until someone resets it. Check this on the bench by pulling the thermocouple out of its well and confirming the heater actually de-energizes.

Loop break and the high-limit

Loop break alarms and high-limit controllers catch different failures, and a heated reactor is better off with both.

A high-limit uses its own thermocouple, usually at the heater sheath, wired to a separate limit controller that cuts power and latches until someone resets it. It covers failures in the control loop itself: a controller that fails with its output on, a solid state relay that fails shorted, a wrong setpoint. Loop break can’t be relied on for those, because it runs on the same controller and thermocouple that failed.

What a high-limit can’t catch is its own thermocouple in the wrong place. If a job means pulling both thermocouples, both can be left out the same way, and a high-limit thermocouple sitting in open air reads low and never trips. Loop break is the only one of the two that checks whether the heater’s output is actually producing heat at the sensor. Configured to cut the output, it doesn’t just warn you about a displaced thermocouple. It stops the damage.

Neither one is the backup for the other. Each covers the other’s blind spot. The high-limit is blind when its own thermocouple is out of place, and loop break is the only check for that. Loop break is blind when the controller or output hardware fails, and the high-limit catches that as long as its thermocouple is where it belongs.