Corrosion management is one of those disciplines that everyone agrees is important and comparatively few organizations can describe in structural terms. Most operators can point to inspection data, a risk-based inspection program, and a set of intervals, but far fewer can set out the sequence of work that produced them and explain how each step depends on the one before it.
In a recent Cenosco webinar, Amit Singh, our domain expert for pressure equipment integrity, worked through that sequence from the beginning. What follows is a summary of the structure he described, which is worth reading as a checklist against your own program.
The dependency that decides everything else
Mechanical integrity exists to keep fluid inside the boundary built to hold it, and corrosion is the mechanism that gradually removes that boundary. Because corrosion progresses during every hour a plant is in service and is widely cited as the largest degradation-driven contributor to loss of containment, the quality of your corrosion knowledge sets a ceiling on the quality of everything built on top of it.
Risk-based inspection is the clearest example. It does not generate knowledge about how a plant degrades; it consumes that knowledge and converts it into a plan, which means generic inputs still produce a complete and confident-looking inspection schedule.
“I have seen operators that have jumped directly into performing the RBI by identifying generic degradation mechanisms like internal corrosion and external corrosion, just to satisfy themselves with the need to perform RBI. But for RBI assessments to be effective, there is a need for investing time and effort into performing a good quality corrosion study.” – Amit Singh
A complete corrosion management program has five components, and they have to be built in order
1. Corrosion loops
A process unit is not assessed as a single object. It is divided into corrosion loops, each grouping components that will share similar degradation mechanisms, and the parameters decide whether they do: the same fluid and composition, including contaminants and corrodents, the same operating conditions of temperature, pressure, and velocity, and the same material of construction. Where those align, common degradation mechanisms follow, because susceptibility is a function of fluid, condition, and metallurgy.
This is the step most often compressed, and the one whose consequences reach furthest, since every later activity inherits the quality of the loop definitions it was handed.
2. Degradation mechanism identification
For each loop, the task is to identify every mechanism that could credibly occur over its remaining life, including mechanisms that would only become active under process excursions you can reasonably anticipate. Historical damage is an input to that judgment, not the answer to it.
The assessment draws on process conditions, then materials and metallurgy, including heat treatment, weld types, and hardness, then operating and inspection history, and only then on industry standards such as API 571 and the relevant equipment manuals. The output is the credible mechanism list for the loop, which becomes the core of your corrosion control document.
Most degradation in oil and gas falls into three categories. Internal corrosion is age-related wall loss from the process fluid, which means a rate can be established and a timeline estimated. External corrosion is driven by the outside environment, dominated by corrosion under insulation, which is the mechanism that most often reaches failure undetected because it occurs where nobody can see it. Environmental cracking requires a specific pairing of susceptible material, tensile stress, and corrosive environment, and no meaningful rate can be assigned to it at all, which is why prevention matters more than detection in that category.
3. Risk-based inspection
With mechanisms and rates established, risk assessment can be performed at whatever level of rigor suits the organization, from qualitative through quantitative using API 581, to dynamic models in which risk updates as new data arrives rather than waiting for a reassessment campaign.
The payoff is in resource allocation. Time-based inspection spreads effort evenly regardless of what equipment is actually likely to do, whereas risk-based inspection concentrates it where consequence and probability are highest. That reallocation is only as trustworthy as the corrosion study behind it.
4. Integrity operating windows
This is the component most often missing entirely. Operators invest in the corrosion study, invest again in good risk-based inspection, and then have no integrity operating window program at all. The reason that matters is that inspection does not mitigate every mechanism. Creep, thermal fatigue and stress corrosion cracking are managed by knowing when the process has moved outside the envelope in which the material stays stable, and an inspection interval carries no information about that. Integrity operating window monitoring does, which makes it a coverage gap rather than a documentation gap.
5. The corrosion control document
Everything above consolidates into a corrosion control document containing the loops and their components, every credible mechanism with its probability and consequence assessment, the monitoring and inspection strategy, and the integrity operating windows. It should tell anyone who reads it how the equipment in that unit corrodes. Its value depends entirely on being current. It is not unusual to find documents that were built properly and then left untouched for ten, fifteen or twenty years while the plant changed feedstock, throughput and metallurgy around them. When the risk based inspection assessment is updated, time to update the corrosion study alongside it needs to be planned for rather than found.
Where AI fits, and where it does not
Degradation mechanism identification is heavily labor-intensive. Two of its three steps are now realistically automatable. Input data collection is one, since drawings, piping, and instrumentation diagrams can be read by tools that extract tags, build a hierarchy, and pull design and operating details, work Cenosco has completed for a customer in Southeast Asia. The assessment step is the other, because the logic determining susceptibility is already written down in API 571 and API 581, and can be encoded into models that propose mechanisms against a given set of conditions and materials. The third step stays with the engineer. What a model produces is a suggestion with an indication of confidence, which the corrosion engineer then accepts, edits, or rejects.
“AI here is just a supplement that makes the work of a corrosion engineer more efficient. Ultimately, it will be the judgment of a corrosion engineer, and we need to ensure there is a human factor in place before accepting the suggestions.” – Amit Singh
The gain is that the engineer spends their time on decisions rather than on data entry and standards lookup, which is what makes a properly detailed study affordable in the first place.
Checking your own program
The chain runs in one direction. Loops determine what is studied, mechanism identification determines what risk assessment can see, risk assessment determines where inspection effort goes, integrity operating windows cover what inspection cannot, and the corrosion control document holds it together for as long as it stays current. Breaking one link does not stop the links downstream from producing output, which is what makes a weak corrosion study so hard to spot. It generates an inspection plan that looks exactly like a strong one.
准备好演示了吗?
Are you ready to see the IMS in action? Fill out the form below to book a demo!