> Needing (emphasis there) to fail over should be for emergencies, not standard operating procedure.
You should be failing testing failover regularly, just like you're testing backups and recovery, and other things that should not "need" to happen but have to actually work when they do.
A good time would be during your monthly/quarterly/(bi)annual/whatever patch cycle (and if there are no patches, then you should just test failover).
This is why you have failover for firewalls. The loss of any single device isn't that important.