Define the failure you intend to survive
A provider outage, local internet failure, PBX failure and a single unreachable destination need different responses. A second trunk on the same PBX and internet circuit does not remove those shared dependencies.
New-call recovery and active-call survival are different tests. Inbound number failover needs a provider-side routing plan.
Design outbound behavior
Specify which failures should trigger an alternate route. An authorization denial or invalid destination may require correction rather than another attempt. Limit retries and verify number formatting, caller identity and permissions on each trunk. Prevent loops between alternate paths.
Design inbound behavior separately
Inbound failover depends on control of the called number and the provider's routing options. Ask where calls go when the primary PBX cannot be reached and whether that behavior uses a timeout or a health signal. A second outbound account alone does not redirect inbound calls to your number.
Test recovery as well as failure
Use an agreed maintenance exercise. Confirm new calls on the backup path, expected handling of active calls and return to the primary route. Check capacity, billing assumptions and emergency-calling arrangements for the backup. Record the observed recovery time instead of describing the design as seamless without evidence.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.