A dual-input temperature transmitter accepts two independent sensor elements, then executes fail-over, average, differential, min/max, and drift-detection math in firmware, eliminating the duplicated transmitter pair that classic single-input designs required.
Production-grade units now cover -50 to +85°C ambient, hold 0.014% total accuracy, and ship with full assessment to IEC 61508:2010 for SIL 2 / SIL 3 loops, which is why the architecture is moving from specialty to default in chemical, food, and power projects [S3].
Operating modes a true dual-input device actually exposes
A "true" dual-input device reads both sensors independently, instead of hard-wiring sensor 1 and sensor 2 to the same analog-to-digital front end as a switchable pair [S1]. The host can then map any of four functions to the 4-20 mA primary variable: primary sensor, backup sensor, average of both, or differential (A-B or B-A) [S2]. High-select and low-select modes let the output track the hotter or colder of the two elements, which is the standard pattern for reactor skin-temperature limiters and bearing-temperature trips.
On a 2-wire HART 7 device such as the PR 5437, the calculated value plus raw input values are exposed as HART PV, SV, TV, and QV variables, so a single twisted pair carries the primary control value, the secondary reading, and a live deviation diagnostic at the same time [S2][S3].
Sensor redundancy vs transmitter redundancy: what you actually save
Classic single-input redundancy required two temperature sensors, two transmitters, two conduit runs, and a voter or selector in the DCS, plus double the calibration and proof-test work [S2][S4]. A dual-input transmitter collapses that to one head-mount transmitter and one pair of sensors wired into the same seven-terminal block, which removes the second analog loop, the second I/O card, and half the documentation burden.
Fail-over is automatic inside the device: when the primary element open-circuits, shorts, drifts past a user-defined band, or stops updating, the output commutates to the secondary element within the device's configured switch time, and the host sees a HART status flag rather than a 4 mA burnout [S2][S3][S6]. That single behaviour is what makes the architecture acceptable as a single-channel SIL 2 path on assessed devices, and as part of a SIL 3 voting pair where the second channel is a separate transmitter [S3].
Drift detection: the failure mode redundancy does not fix by itself

Redundancy only helps if a sensor fails hard. Slow Pt100 drift, creeping insulation resistance, or junction-box moisture will leave both sensors reading "in range" while the average silently moves away from the true process temperature, a mode redundancy cannot catch [S5][S6]. Drift-detection firmware closes that gap by continuously comparing the two element readings and raising a maintenance alarm when the absolute or normalized deviation exceeds a configured threshold, typically a few °C depending on the application.
A practical case: two Pt100 elements installed in the same thermowell of a reactor, evaluated by a dual-input transmitter, allow the operator to read each element, the deviation between them, and the running trend of that deviation through HART, so sensor replacement is scheduled on condition instead of on a calendar [S6]. The same math supports Callendar-Van Dusen sensor matching, which corrects individual element constants and tightens the accuracy budget on calibrated probes [S3].
Where a dual-input transmitter fits, and where it does not
The architecture is a strong fit for measurement points where a single lost reading stops a batch, trips a furnace, or invalidates a sterilization cycle, examples being chemical reactor temperature, food retort or autoclave, SIP/CIP loops, bearing housings on large motors, and power-plant steam-temperature limit loops [S2][S4]. It is also a good fit when the cost of a second conduit run and a second I/O card outweighs the cost of a slightly more expensive head-mount transmitter.
It is a weaker fit where the two measurement points are physically far apart, where a single transmitter failure must still be survived by a second independent device, or where the loop is already built around a multi-pair cable and dedicated differential pressure transmitter channels. In those cases two separate single-input devices on a hot-standby or voted pair remain the right answer, because the failure-mode coverage of dual-input and dual-transmitter is genuinely different [S5].
Specification comparison: typical 2026 dual-input transmitters

The table below lines up representative units on the parameters a process engineer actually compares at the desk. Values are taken from published OEM data, not marketing copy. [S1]
PR 5437 (PR Electronics): true dual inputs, HART 7, 0.014% total accuracy, -50 to +85°C ambient, 2.5 kVAC galvanic isolation, IEC 61508:2010 assessed for SIL 2/3, suitable for systems up to PL d per ISO 13849, NAMUR NE21/NE43/NE44/NE89/NE95/NE107 diagnostics, DIN form B head mount, 7-terminal design accepting RTD, thermocouple, linear resistance, potentiometer, and bipolar mV [S3].
THZ3 / TDZ3 (Moore Industries): dual sensor input with automatic fail-over to backup, HART 5/6 compatible, multidrop supports up to 16 transmitters on a single digital HART loop, average, differential, high-select, low-select modes, dynamic variable mapping to PV/SV/TV/QV, sensor drift and corrosion detect [S2].
Across those two designs the real differences are accuracy class (0.014% on the 5437 vs the broader accuracy class of the THZ3/TDZ3 family), SIL assessment depth (full IEC 61508:2010 SIL 2/3 plus PL d on the 5437, vs the application-level loop where the THZ3/TDZ3 is deployed), and ambient ceiling (-50 to +85°C on the 5437, narrower industrial range on the THZ3/TDZ3) [S2][S3].
Functional safety, EMC, and standards wiring to specify
For safety loops the specification should call out the IEC 61508:2010 assessment level, the applicable SIL target, and the proof-test interval assumed in the FMEDA, because those three numbers determine the achievable PFDavg and the safe-failure fraction [S3]. For mechanical integration, DIN form B head mounting is the de-facto pattern and the 7-terminal true-dual layout is the one to require if average and differential modes are wanted without external wiring tricks [S3].
EMC and diagnostic compliance should be named explicitly: NAMUR NE21 for industrial EMC, NE43 for the 4-20 mA signal-on-failure band, NE44 and NE89 for firmware/diagnostic content, and NE107 for status categories, all of which a SIL-assessed dual-input unit typically meets [S3]. For applications where the loop also drives a control valve or a pressure transmitter cascade, the same HART multidrop pattern lets multiple smart devices share one input card, with up to 16 transmitters daisychained on a single digital link in HART 5/6 networks [S2].
Failure modes the architecture does not cover

Dual-input redundancy inside one transmitter does not protect against a transmitter-internal failure, head-mount power loss, or a shorted sensor pair sharing the same wiring. For those failure modes, two physically separate transmitters on independent loops remain the only complete answer, which is why SIL 3 loops still call for a voted pair even when each leg uses a SIL 2/3 assessed dual-input device [S3][S5].
It also does not protect against a thermowell failure, a process tube pluggage, or a reference-junction error that affects both elements simultaneously, which is why the sensor-drift alarm should be wired as a separate HART diagnostic to the asset management system, not treated as a replacement for mechanical inspection on a calendar [S5][S6].
Related analysis: PPR vs PP-H Pressure Rating: PN Class, SDR, and Standards Compared.