Signal aspect verification is the feedback loop that closes the gap between what a traffic signal controller commands and what road users actually see. A controller can issue a green phase with complete timing precision. If the lamp driver circuit has failed silently, or a lamp has blown without tripping a fuse, the intersection shows darkness where drivers expect a green. Verification circuitry exists to catch exactly that condition, in real time, before it becomes a safety incident.
What signal aspect verification actually does
The controller sends a voltage signal to each lamp circuit. Verification monitors the return path: typically current sensing, voltage sensing, or both. If the measured output doesn't match the commanded state within a defined tolerance window, the controller flags a fault. Depending on configuration and jurisdiction, it then either enters a fallback flash mode or de-energises the head entirely and triggers an alarm.
There are two distinct failure modes the system targets. The first is a dark aspect: a commanded ON lamp that is not illuminating. The second is a spurious aspect: a lamp that is illuminating when it was commanded OFF. The second failure is generally treated as the more critical, because a spurious green or spurious walk signal creates a direct conflict risk. Current sensing alone can detect the dark case easily. Detecting a spurious aspect requires voltage sensing or dedicated monitoring of the switched side of the circuit.
Current sensing versus voltage sensing
Current sensing uses a low-value shunt resistor or Hall-effect sensor in series with the lamp circuit. When current flows, the lamp is on. When it doesn't, the lamp is off or open-circuit. This approach is simple, low cost, and reliable for detecting blown lamps. Its limitation: it tells the controller that current is flowing, not that the light is actually visible to a driver. A partially failed LED module that draws normal current but emits negligible luminous output can fool a current-based system entirely.
Voltage sensing monitors the circuit at the lamp terminals. It checks whether voltage is present or absent relative to the controller's switch state. This catches a broader range of faults, including welded relay contacts that hold a circuit live after the controller commands off. For LED signal heads, which typically use constant-current drivers rather than simple switched loads, the monitoring architecture needs to account for the driver's own internal regulation. A failed LED string within a module may not shift the terminal voltage detectably unless the driver itself faults.
Modern signal controllers often combine both methods. Current sensing catches open-circuit lamp failures. Voltage sensing catches stuck-on conditions from contact welding or driver faults. Together, they cover the failure matrix that either method alone misses.
LED modules and the limits of indirect verification
Incandescent lamps failed in ways that were straightforward to detect. A blown filament broke the circuit. The current dropped to zero. The monitoring circuit responded instantly. LED signal modules introduced a different failure profile. An LED string can degrade gradually, losing luminous efficacy over thousands of hours without ever fully opening the circuit. The driver continues supplying current. Verification sees a normal current draw. The aspect appears to function. A field inspection at night reveals a dim signal that falls below the minimum luminance requirements set under Austroads traffic signal standards.
This is why photometric verification is gaining traction as a supplementary method in high-criticality installations. A small photodiode or lux sensor embedded behind the lens can confirm actual light output rather than just electrical continuity. It's not yet standard across Australian deployments, but the failure modes of LED modules make it a rational extension of the verification architecture, particularly on arterial intersections with high pedestrian volumes.
The relationship between verification and fail-safe design is direct. Signal aspect verification is one of the sensing inputs that allows fail-safe design in traffic signal systems to function as intended. A fail-safe architecture can only default to a safe state when it knows that a failure has occurred. Verification provides that knowledge.
Watchdog interaction and fault escalation
Signal aspect verification faults feed into the controller's fault escalation logic. Minor faults, typically a single lamp failure in a non-conflicting position, may trigger a maintenance alert while the intersection continues operating. A verification fault on a primary signal head, or a spurious aspect detected on any output, typically triggers an immediate transition to all-way flash or full shutdown depending on the site's configured fault response.
The watchdog timer in the controller interacts with this process. If the verification monitoring firmware itself stops reporting, the watchdog treats that silence as a fault and resets the controller. This prevents a scenario where the monitoring system fails silently and leaves the controller operating without oversight. The layering of watchdog supervision over the verification subsystem is part of what makes modern signal controllers genuinely fault-tolerant rather than simply fault-reporting. The specific mechanics of that interaction are covered in detail in the article on watchdog timers in traffic signal controllers.
Fault logs generated by aspect verification events are operationally valuable beyond the immediate safety response. Repeated single-lamp faults on a specific head, logged over weeks, can indicate a wiring fault, a connector degrading under thermal cycling, or a batch of LED modules from the same production run approaching end of life simultaneously. Maintenance teams that read verification logs prospectively can schedule replacements before a fault escalates to an unplanned outage.
Configuration tolerances and calibration
Verification thresholds require calibration at commissioning. The acceptable current window for a given lamp type needs to be set correctly. Too tight, and the system generates nuisance faults on normal lamp variation or cold-start current transients. Too wide, and it misses partial failures. LED modules complicate this further because their driver circuits often present a substantially different electrical profile from the lamps originally specified for the controller's factory settings.
At commissioning, the technician measures baseline current for each circuit under normal operating conditions and sets the monitoring window accordingly. For multi-lamp heads where LEDs have replaced incandescents, this calibration step is critical. A controller still configured with incandescent current thresholds will either fail to detect LED lamp faults or generate constant false alarms, neither of which is acceptable on a live intersection. Documenting the calibration settings in the site's as-built records is a minimum requirement. It lets maintenance staff re-calibrate correctly after any hardware change without relying on field memory.
Signal aspect verification is not a diagnostic add-on. It's a core safety function that sits between the controller's software logic and the physical world that drivers and pedestrians navigate. Treating it as a commissioning checkbox rather than an ongoing maintenance discipline is the fastest way to lose confidence in the data it generates.

