Pipeline Integrity RBI Consulting: Building an API 1160/1163-Aligned Program
How midstream and pipeline operators build a defensible RBI program that survives a PHMSA audit — API 1160 risk modeling paired with API 1163 ILI tool qualification.
Why Pipeline Operators Are Rebuilding Their RBI Programs Around API 1160 and API 1163
A hazardous liquid pipeline operator running 900 miles of 16-inch and 20-inch line across three states does not fail an integrity audit because nobody ran an inline inspection tool. It fails because the risk model behind the inspection schedule cannot be defended in front of a PHMSA auditor, and because the ILI data validation trail does not connect cleanly to the written practice that says who reviewed it and when. Risk-based inspection consulting for pipelines is not about telling an operator to run more smart pigs. It is about building a defensible, auditable program that ties API 1160 risk assessment methodology to API 1163 inline inspection qualification, and then proving — with document control, not with a binder of PDFs — that the program was actually followed.
Atlantis NDT's ASNT Level III consulting engagements in this space typically start the same way: an operator has an RBI framework on paper, built by a consultant or an in-house engineer who has since left, and nobody currently on staff can explain why a given segment is inspected every 5 years instead of every 7. That gap is the actual finding, more often than any specific wall-loss anomaly.
What API 1160 Actually Requires From a Risk Assessment
API RP 1160, "Managing System Integrity for Hazardous Liquid Pipelines," does not hand operators a single risk formula. It requires a documented, repeatable process that identifies threats — external corrosion, internal corrosion, stress corrosion cracking, third-party damage, manufacturing and construction defects, equipment failures, incorrect operations, and weather-related or outside-force events — and assigns likelihood and consequence to each pipeline segment. The consequence side has to account for High Consequence Areas (HCAs) as defined by 49 CFR Part 195: populated areas, commercially navigable waterways, and unusually sensitive areas (USAs) for drinking water or ecological resources.
Where operators get into trouble is in the likelihood modeling. A defensible RBI program under API 1160 needs segment-level data on pipe age, coating type and condition, cathodic protection history, soil corrosivity, depth of cover, crossing density, and prior inspection findings — not a single corporate-wide corrosion rate applied uniformly across dissimilar segments. When Atlantis Level III consultants review an existing program, the most common finding is a risk model that was built once, five to eight years ago, and never re-calibrated against actual ILI results. API 1160 explicitly calls for the risk assessment to be a living document, reassessed whenever new inspection data, incident history, or changed operating conditions warrant it — and PHMSA inspectors know to ask for the re-assessment date.
API 1163: Where Most ILI Programs Actually Break Down
API 1163, "In-line Inspection Systems Qualification," governs the tool run itself — not just whether a smart pig went through the line, but whether the vendor's tool was qualified for the specific defect types the operator needs to find, and whether the post-run data validation followed a documented process. Three areas cause the most rework on audit:
- Tool performance specification mismatch. A magnetic flux leakage (MFL) tool qualified for metal loss detection is not automatically qualified for axial or circumferential SCC detection, which typically requires an EMAT (electromagnetic acoustic transducer) or ultrasonic crack-detection tool. Operators sometimes run the wrong tool class for the threat identified in their own API 1160 risk assessment — for example, running an MFL caliper run on a segment flagged for SCC susceptibility near a compressor station discharge, where the threat is cracking, not metal loss.
- Unvalidated tolerance claims. API 1163 requires the ILI vendor's stated tolerances (depth, length, width sizing accuracy) to be validated against field data — dig verifications, not just the vendor's factory calibration sheet. Operators who skip the dig-validation step and accept vendor tool-spec sheets at face value cannot defend their reported repair criteria if an auditor asks for the correlation between reported and actual defect dimensions.
- Data integration into the risk model. ILI results need to feed back into the API 1160 risk assessment as new likelihood data, not sit in a separate report that engineering reviews once and files. Atlantis consultants frequently find that a pipeline's GIS-based risk model and its ILI anomaly database are maintained by different departments on different update cycles, so the "current" risk ranking used to schedule the next inspection is actually 18-24 months stale relative to the most recent tool run.
Building the RBI Program: A Practical Sequence
A pipeline integrity RBI consulting engagement that holds up under a PHMSA or state pipeline safety audit generally follows this sequence, whether the operator is a midstream gathering system, a long-haul crude line, or a refined products pipeline subject to 49 CFR Part 195 integrity management (or Part 192 for gas transmission, where API 1160 principles are commonly adapted alongside ASME B31.8S):
1. Segment the system by threat, not just by milepost
Segmentation should follow changes in threat exposure — coating type transitions, soil resistivity changes, HCA boundaries, crossing density, and known incident or repair history — rather than administrative boundaries like station-to-station mileposts. A 40-mile segment with uniform 1970s coal-tar enamel coating and consistent soil chemistry can often be treated as one risk unit; a segment that crosses from clay soil to sandy, more corrosive soil at mile 12 should be split there.
2. Assign quantitative likelihood scores per threat category
External corrosion likelihood should be driven by coating condition survey data (close-interval survey, DCVG, or ACVG results), cathodic protection rectifier readings, and pipe-to-soil potential trends over time — not a single "medium" rating assigned by engineering judgment alone. Internal corrosion likelihood needs product characterization: water cut, CO2/H2S partial pressures, flow velocity relative to erosional velocity limits, and any history of pigging for solids removal.
3. Select the ILI tool class against the dominant threat, and document the selection logic
This is the step API 1163 audits most directly. The written justification for tool selection — why MFL versus ultrasonic wall measurement versus EMAT crack detection — needs to reference the specific threat identified in step 2, not a default "we always run MFL" policy inherited from a prior operator.
4. Validate tool results against dig data before updating the risk model
API 1163 unity plots (predicted versus actual defect depth) should be generated and retained for every dig program, and the resulting confirmed tolerance should be the number that feeds repair criteria — not the vendor's marketing spec sheet.
5. Re-run the risk assessment with new data and reset the reassessment interval
The reassessment interval itself should be justified — API 1160 does not mandate a fixed number, but it does require the operator to show the basis for whatever interval is chosen, tied to the confidence level of the risk data.
Where Multi-Method NDT Fits Inside the RBI Framework
ILI is the backbone of most liquid pipeline integrity programs, but RBI-driven direct examination still relies on conventional and advanced NDT methods at dig sites and above-ground facilities: phased array ultrasonic testing (PAUT) for girth weld and seam weld verification, time-of-flight diffraction (TOFD) for crack sizing on suspected SCC colonies, magnetic particle testing (MT) for surface-breaking indications on exposed pipe, and guided wave ultrasonic testing (GWUT) for screening inaccessible or insulated segments such as road and rail crossings and pipe supports at pump stations. A risk-based program should specify which method applies to which finding type — GWUT as a screening tool to prioritize excavation, not as a replacement for direct PAUT sizing once a segment is exposed.
Procedure qualification matters here as much as tool selection. Personnel performing PAUT sizing on ILI-flagged anomalies should hold ASNT Level II or III qualification specific to the PAUT technique per the operator's written practice, and the written practice itself should map to SNT-TC-1A with employer-specific qualification requirements — not a generic template. This is where a lot of midstream and gathering-system operators, who may have a smaller integrity staff than a major interstate carrier, benefit from bringing in outside ASNT Level III consulting support to review or author the written practice rather than trying to adapt a template built for a different operator's threat profile.
Documentation: The Difference Between Passing and Failing an Audit
PHMSA integrity management audits under Part 195.452 (and analogous state pipeline safety programs for intrastate lines) focus heavily on whether the operator can produce, on request, the specific records that show the risk assessment, the inspection method selection rationale, the tool qualification records, the dig verification data, and the repair prioritization logic — all cross-referenced to each other. A common failure mode: the risk assessment says segment 14 is high-risk for external corrosion, the ILI report shows several metal-loss anomalies in that segment, but the dig program record does not show which anomalies were excavated, and the repair log does not tie back to the ILI anomaly IDs. Each document may be individually correct, but the chain between them is broken.
This is precisely the kind of cross-referencing problem that inspection management software is built to solve. An NDT and integrity management ERP that ties inspection work orders, personnel qualification records, and NDT reports to specific asset IDs and anomaly IDs eliminates the spreadsheet-and-shared-drive fragmentation that shows up as findings in almost every PHMSA audit report. Pairing that with a digital twin platform that visualizes the pipeline route with anomaly locations, repair history, and current risk ranking overlaid on the actual GIS alignment gives integrity engineers and auditors a single source of truth instead of reconciling four disconnected systems.
Scoping an RBI Consulting Engagement: What to Ask For
Owner-operators and EPC integrity teams evaluating outside Level III support for an RBI program build-out or gap assessment should expect a scope that includes: a review of the existing risk methodology against API 1160 current edition requirements; a gap analysis of ILI tool qualification records against API 1163; a sample audit of dig verification data and unity plot generation; a review of the written practice governing direct-examination NDT personnel qualification; and a documented recommendation set prioritized by audit exposure, not just technical elegance. A Level III consultant should be able to walk into an existing program, identify which of the five sequence steps above is weakest, and scope a fix that the operator's own staff can maintain going forward — the goal of good consulting is a program the operator owns, not a permanent dependency.
For operators building this capability for the first time, NDT training aligned to ASNT SNT-TC-1A for in-house personnel, combined with a properly scoped written practice, is usually more cost-effective over a multi-year horizon than perpetually outsourcing direct-examination NDT. The consulting engagement and the training build-out are not competing options — the strongest programs use outside Level III expertise to build the framework and qualify the written practice, then train internal staff to execute against it year over year.
Common Findings From Gap Assessments
Across midstream and gathering-system RBI gap assessments, a handful of findings recur often enough to be worth naming explicitly, because each one is inexpensive to fix once identified but expensive to discover during a PHMSA enforcement action.
- Consequence data frozen at construction. HCA identification is sometimes performed once, at the time a segment is built or acquired, and never refreshed against current population growth data, updated National Hydrography Dataset waterway crossings, or newly designated unusually sensitive areas. A segment that was rural in 2010 may now cross a subdivision, and the risk consequence score needs to reflect that.
- Corrosion growth rates borrowed from industry defaults. Using a generic 5-10 mil-per-year external corrosion growth rate from an industry handbook, rather than the operator's own re-inspection interval data, understates or overstates risk depending on the actual soil and cathodic protection conditions on that specific segment. Two consecutive ILI runs on the same segment, properly aligned and compared feature-to-feature, give a far more defensible growth rate than any published default.
- Repair prioritization decoupled from the risk ranking. Some operators maintain a technically sound risk model but prioritize repairs purely by defect severity (percent wall loss) without weighting by the segment's HCA consequence score, which is backwards from what API 1160 intends — a moderate anomaly in a high-consequence area generally warrants faster action than a severe anomaly in a low-consequence rural segment with easy excavation access.
- No record of who qualified the ILI vendor's personnel. API 1163 places qualification obligations on both the pipeline operator and the ILI service provider. Audits increasingly ask operators to show how they verified that the vendor's data analysts and tool operators were qualified for the specific tool and defect type run — not just a general vendor approval letter from years earlier.
Aligning the Program With EPC and Construction-Phase NDT
For new pipeline construction or major looping projects, the RBI program should not start on the day the line goes into service — the baseline risk data begins with construction-phase NDT records: radiographic testing (RT) or automated ultrasonic testing (AUT) results on girth welds, coating holiday detection survey results, and as-built alignment sheets showing actual depth of cover and crossing locations. EPC contractors managing multi-site construction should hand over a digitized NDT record set, not boxes of film or disconnected PDF reports, so the operator's integrity team can load baseline weld quality and coating condition directly into the RBI model from day one rather than treating year-one data as unknown. Atlantis NDT's reporting software is built to produce that structured, exportable record set at the point of construction inspection, which materially shortens the time it takes to stand up a credible RBI baseline once the asset is placed in service.
Atlantis NDT Products & Services
Atlantis NDT pairs field expertise with software: NDT inspection management software — Atlantis ERP, a digital twin platform for asset integrity, and NDT reporting software. Build your team with NDT training & certification (ASNT SNT-TC-1A) and ASNT certification pathways, or bring in ASNT Level III consulting. Affordable, accessible, fully customizable — book a free consultation.
Running this as a programme, not a one-off
If you are responsible for an inspection programme rather than a single job, the recurring problem is rarely the code — it is keeping measured thickness, damage-mechanism assignment and next-inspection dates in one defensible place. Asset integrity management software covers keeping measured thickness readings per CML in one place, so the RBI (API 580/581) and fitness-for-service (API 579) work your integrity team or its specialists carry out starts from measured data rather than default rates. Atlantis supplies the NDT data and the software to hold it; it does not perform RBI or FFS assessments.
Atlantis NDT Products & Services
Atlantis NDT pairs field expertise with software: NDT inspection management software — Atlantis ERP (certification tracking, work orders, method-specific reporting on every business app you need), a digital twin platform for asset integrity (3D corrosion mapping and inspection-data overlay), and NDT reporting software. Build your team with NDT training & certification (ASNT SNT-TC-1A) and ASNT certification pathways, or bring in ASNT Level III consulting for written practices, procedures and audits — plus independent inspection data review on API 510/570/653-governed assets. Capture as-built reality with 3D laser scanning services. Affordable, accessible, fully customizable — book a free consultation.