Back to Blog
RiskFinanceHealthcare

Fail-Closed Is a Governance Decision, Not an Engineering One

July 2026·5 min read

When a system fails, does it protect the person or the process? That decision is made long before anyone writes code, and it is precisely what a supervisor asks about afterwards.


'Fail open' or 'fail closed' sounds like an engineering choice. It is not. It is a decision about which party absorbs the cost when something goes wrong, and it belongs to whoever owns the risk, not to whoever happens to be writing the code that week.

What the terms mean A system that fails open keeps working when a check cannot be completed: the transaction proceeds, the content is served, the access is granted. A system that fails closed stops. The first protects availability. The second protects the person the check was originally meant to protect.

Why governance owns this question The answer depends on consequences, not on uptime targets. If the check exists to prevent harm to a customer or a patient, failing open means the harm proceeds whenever the check is unavailable. In a bank that is a conduct issue. In a hospital it can be a clinical one.

The testable form Ask, for each control: under what circumstances would this fail, and who is exposed during that window? If nobody can answer without opening the code, the decision was never really made, it was inherited by default.

Conclusion Write the answer down. A supervisor asking why a system failed open is asking a governance question, and 'the engineers decided' is not a response that survives contact with a regulator.

Facing One of These Deadlines?

We start with a gap analysis, the fastest route to knowing exactly what you need.