Chasing Intermittent and Nuisance Faults on a Fire Alarm System
Every experienced fire alarm engineer knows the visit that ends with "it's not doing it now." The customer describes a fault that has occurred several times, the panel display shows nothing wrong, the log shows the fault cleared some time ago, and a straightforward test of the affected circuit passes without complaint. This is not a failed diagnosis so much as a different kind of problem: an intermittent fault cannot be found by testing a circuit that, at this exact moment, happens to be behaving.
The essential idea is this: constant faults are found by dividing a circuit and observing; intermittent faults are found by working out what condition makes the fault appear, then either reproducing that condition or reading the pattern it leaves behind in the log.
Who this is for
This is for fire alarm engineers investigating a fault reported as intermittent, recurring, or "gone by the time I arrived." Experience level: competent engineer, comfortable reading event log history over an extended period and applying provoking techniques within the manufacturer's stated limits. No default access codes or internal service routines are published here.
What counts as an intermittent fault
An intermittent fault is not a separate category of fault in itself — it can be an earth fault, an open circuit, a device fault, or a network fault — but one that appears and clears rather than persisting. What makes it distinct is the mechanism: a connection or component that is marginal under normal, stable conditions and only actually fails when something changes.
Thermally provoked conditions. A connection that loosens or a conductor that flexes as temperature rises and falls through a daily heating cycle.
Vibration provoked conditions. A loose terminal or connector affected by nearby machinery, lift motors, or vehicle movement.
Moisture provoked conditions. Condensation or water ingress that appears only in certain weather or at a low point in a cable route.
Interference provoked conditions. Electrical noise that only occurs when a specific piece of equipment elsewhere in the building switches on.
Telling an intermittent fault from a resolved one
The distinction matters because a clean test result today does not mean the fault is not real or not still there. A genuinely resolved fault has an identified and corrected cause behind it. An intermittent fault that has simply cleared on its own has neither, and testing the circuit in its current, stable state proves nothing either way about whether it will recur.
The event log is where the pattern usually emerges. Ask the customer, not just the panel log, when the fault has occurred — time of day, day of week, weather, and anything unusual happening in the building at the time, since customers often notice patterns an engineer visiting once would never see. Device compatibility rarely explains a genuinely intermittent fault, but it is worth ruling out early if the pattern does not otherwise fit environmental provocation.
On arrival and initial observations
Initial observations for a suspected intermittent fault differ from a normal fault call, because the fault itself is unlikely to be present. Check the panel's event log thoroughly, not just for the most recent occurrence, and note every timestamp if there is a history of repeat events. Resist the temptation to reset the fault and move on if a single visit does not reproduce it; closing the job at that point simply defers the same call-out to a later date.
Ask what has changed since the fault started — recent works, a new piece of equipment installed nearby, or a change in how a space is used — and get as full a history as possible before forming a theory.
Evidence gathering and site observations
Evidence gathering here means laying the occurrences against a timeline of what else was happening. A fault that recurs at a consistent time each day suggests a scheduled event — heating coming on, a piece of plant starting, a delivery vehicle reversing near a cable route. A fault that only appears in certain weather suggests moisture or thermal expansion. Site observations about environment are directly relevant: a suspect connection in a plant room, roof void, or external route deserves more weight than one in a stable internal environment.
This pattern-reading step often narrows the search dramatically before any physical testing begins, and it costs nothing but attention to the log and a few questions on site.
What you can safely establish on site
Where the pattern points to a likely cause, try to reproduce the condition rather than waiting for it to recur naturally. If thermal cycling is suspected, a heat gun or a can of freezer spray applied carefully to a suspect connection or device, well within the manufacturer's guidance and safe working limits, can reproduce a marginal contact failing under temperature change in seconds rather than waiting for the building's own heating cycle. If vibration is suspected, gently flexing a cable run or tapping a suspect junction box while watching the panel can reveal a connection that only fails under movement. If moisture is suspected, inspecting a cable route's low points and cable glands after checking the weather history, rather than only on a dry day, gives a fairer test.
Safety warning. Any deliberate provoking technique — heat, cold, flexing, or working near live circuits — must stay within the manufacturer's stated tolerances for the equipment and within your own safe working practice. Change one variable at a time and watch the panel closely, so the fault can be attributed to a specific trigger rather than several disturbed at once.
Investigation flowchart
Used as an investigation flowchart, the sequence runs:
- Review the full event log history, not just the most recent occurrence.
- Ask the customer for their own account of timing and pattern.
- Cross-reference occurrences against building schedules, weather and recent works.
- Form a theory about the likely provoking condition.
- Attempt to reproduce that condition using an appropriate, manufacturer-safe technique.
- Change one variable at a time and observe the panel closely.
- Isolate the specific connection, device or cable length that fails under the trigger.
- Confirm the finding by removing the trigger and seeing the fault clear.
- Repair the identified cause.
- Agree a monitoring period with the responsible person if the cause cannot be fully confirmed.
Repair, verification and testing after repair
An intermittent fault is only genuinely closed out when the cause has been identified and corrected, and ideally confirmed by successfully reproducing the trigger condition afterward and seeing the fault no longer occur. Verification here needs to be broader than a single clean test, because that is exactly the false confidence that let the fault go unresolved before.
A short repair checklist for this class of work: full event log history reviewed; likely trigger condition identified and, where safe, reproduced; specific cause isolated and corrected; fix confirmed by reproducing the original trigger and observing no recurrence; monitoring period agreed if the cause cannot be fully confirmed; logbook updated with the pattern found and action taken.
Escalation and spares
Escalate to the manufacturer's technical support when a suspected device or card shows intermittent behaviour under provoking techniques but the exact internal cause cannot be confirmed on site. A good escalation includes the full pattern of occurrences, what provoking technique was tried, and the result.
Spares are rarely the bottleneck for this class of fault, since the fix is usually a connection, a cable, or occasionally a single device rather than a major component. Estimated repair time is genuinely unpredictable: a marginal connection found and reseated is minutes, while a fault that resists reproduction over several visits can take considerably longer to close out properly.
Common engineer mistakes
Testing a circuit once, finding it healthy, and closing the job without reviewing the full log history. Disturbing several things at once while trying to provoke a fault, then being unable to say which change actually mattered. Assuming an intermittent fault has "gone away" because it has not recurred during a single visit. Applying heat, cold or force to a connection or device beyond the manufacturer's stated tolerances. And failing to record the pattern found, leaving the next engineer to start the correlation work from scratch.
Telling the responsible person
There is a legal dimension worth being clear about. In England and Wales the Regulatory Reform (Fire Safety) Order 2005 places duties on the responsible person, including a maintenance duty in respect of the fire safety equipment provided in the premises. BS 5839-1 is a code of practice containing recommendations on investigating and remedying faults promptly; it makes no distinction between a constant and an intermittent one, and it is not itself legislation.
What that means in practice is straightforward. An intermittent fault that clears itself before you arrive is not evidence that nothing is wrong, and the responsible person needs that explained plainly rather than being told the system "tested fine."
Report example
A workable report example: "Investigated recurring fault reported on Zone 6, occurring on four occasions over the past three weeks per event log, each between 06:00 and 07:30. Pattern correlates with the building's heating system starting. Attended during a cold start and used controlled heat-gun testing on suspect terminations in the roof void; reproduced the fault at a specific junction box terminal that had loosened. Terminal re-made and secured; fault not reproduced on repeat testing over three heating cycles. Recommend continued monitoring via event log at next visit."
Related faults
Related faults worth reading alongside this: using the fire panel event log for diagnosis for reading fault history, how to find an earth fault on a fire alarm system for the constant-fault method this guide contrasts with, and reducing fire alarm false alarms for a related class of hard-to-pin-down problems.
When not to rely on this alone
When not to use this article: do not use it to justify applying heat, cold or force beyond the manufacturer's stated tolerances, to close out a fault as resolved without genuine confirmation, or as a substitute for competent training. Provoking a fault deliberately must be done within the manufacturer's guidance and by a competent person.
Relevant standards
Recommendations for investigating and remedying faults on fire detection and fire alarm systems, without distinction between constant and intermittent defects, are given in BS 5839-1, current edition. This is a standard, not law; the statutory duty in England and Wales rests with the responsible person under the Regulatory Reform (Fire Safety) Order 2005. Work to the current edition in every case and verify device-specific tolerances against the manufacturer's manual before applying any provoking technique.
Professional disclaimer
This is an educational resource for competent engineers. It does not replace the current British Standards, the manufacturer's documentation, safe working practice or professional judgement. Work within BS 5839-1 and verify device-specific tolerances against the manufacturer's manual before applying any provoking technique.
Related documentation
Read this with using the fire panel event log for diagnosis and fire alarm cable segregation and EMC. Recording intermittent fault patterns and their resolution is easier with the fault database and the digital logbook.
References
- BS 5839-1 (current edition), BSI
- The Regulatory Reform (Fire Safety) Order 2005 — legislation.gov.uk
- Panel manufacturer installation and commissioning manuals for the equipment on site