Turning an RBI Study Into a Picture of Your Plant
RBI visualisation places each API 571 damage mechanism on the equipment it affects in a 3D model, shades equipment by risk tier, and shows where inspection effort is currently allocated against where risk actually sits. The RBI study is unchanged. What changes is that its conclusions become visible to planners, operators and management instead of living in a spreadsheet.
API RP 580, now in its fourth edition of August 2023 and titled Elements of a Risk-Based Inspection Program, sets what an RBI programme must contain without prescribing the calculation. API RP 581, fourth edition February 2025, supplies one quantitative route: probability of failure combined with consequence of failure, across five parts including a reorganised inspection-planning part. API RP 571, third edition March 2020, describes more than sixty damage mechanisms with susceptible materials, critical factors, inspection method guidance and control measures. Together they produce a risk ranking and an inspection plan. Neither produces a picture. The output of a competent RBI study is a table of equipment items with risk categories and recommended examinations, and the people who most need to act on it, meaning turnaround planners, unit engineers and contractors bidding scope, read tables poorly and geometry well. Mapping the mechanisms onto the asset is a translation problem, not an analysis problem.
Source: API RP 580, 4th edition, August 2023, Elements of a Risk-Based Inspection Program, now an ANSI/API standard (framework; accepts qualitative, semi-quantitative and quantitative approaches); API RP 581, 4th edition, February 2025, Risk-Based Inspection Methodology (quantitative POF and COF procedures across five parts, including a reorganised Part 4 on inspection planning); API RP 571, 3rd edition, March 2020 (more than sixty damage mechanisms, each with description, susceptible materials, critical factors, inspection method guidance and control measures; CUI in carbon and low-alloy steels between 10 °F and 350 °F); API RP 941 Nelson curves (high-temperature hydrogen attack operating limits); API 579-1/ASME FFS-1 (fitness-for-service assessment methodology); U.S. Chemical Safety and Hazard Investigation Board, Final Investigation Report on the Chevron Richmond Refinery pipe rupture and fire of 6 August 2012, published January 2015 (sulfidation accelerated by low silicon content in an individual carbon steel component, corroding faster than adjacent components and not readily detectable by multiple corrosion monitoring locations; recommendation to revise API RP 939-C).
| API 571 damage mechanism | Where it concentrates on the geometry | Why a uniform inspection grid misses it | What the twin makes visible |
|---|---|---|---|
| Corrosion under insulation | Insulation penetrations, supports, damaged jacketing and low points, on surfaces held between 10 °F and 350 °F | CMLs get placed on straight runs for convenience, while CUI concentrates at fittings and interfaces | Every insulated component inside the susceptible band, shaded, with the inspected fraction distinguished |
| High-temperature sulfidation | Hot crude and vacuum unit piping, and individual components with low silicon content | Adjacent components corrode at different rates, so a monitoring grid samples the wrong ones | Component-level thickness against immediate neighbours, so a divergent component stands out |
| Erosion-corrosion | Downstream of control valves, orifices, elbows and tees where flow changes direction | Damage is directional and local, so outer and inner radius readings differ sharply | Flow-path geometry alongside reading positions, exposing untouched impingement zones |
| Wet H2S damage: blistering, HIC, SOHIC, SSC | Weld seams and heat-affected zones in sour service vessels and lines | Thickness monitoring does not detect cracking, so the plan needs a different method entirely | Which welds sit in sour service and which have had a crack-detection method applied |
| Amine stress corrosion cracking | Non-PWHT welds in lean and rich amine service | Risk follows fabrication history rather than position in the process | PWHT status per weld, overlaid on the amine circuit |
| Chloride stress corrosion cracking | Austenitic stainless steel above roughly 140 °F, and under insulation where chlorides concentrate | Cracking initiates without measurable general wall loss | Stainless components inside the susceptible band separated visually from carbon steel |
| High-temperature hydrogen attack | Hydrogen-service equipment operating near the API 941 Nelson curve limits for its material | Damage is subsurface, so conventional UT thickness gives no warning | Material and operating condition per component, checked against the curve |
The RBI study already knows; the plant cannot see it
A completed RBI study is a substantial piece of engineering. Damage mechanisms identified per API RP 571, probability and consequence assessed under the framework of API RP 580 or the quantitative procedures of API RP 581, equipment ranked, inspection plans written. The document runs to hundreds of pages and its operative content is a table. That table then has to survive contact with everyone who was not in the study room.
It rarely does. The turnaround planner receives an extract. The unit engineer remembers the top ten items. The inspection contractor bidding the scope sees a work list with no risk context attached at all. Within two years the study is a file that gets revalidated on schedule and consulted rarely, while inspection continues on the intervals people are used to running.
The gap is not analytical. It is that risk expressed as rows resists being held in mind across a unit with several hundred equipment items and thousands of circuits. Geometry does not have that problem. A person who has walked a unit can hold its layout, and a picture of that layout shaded by risk is legible to them in seconds rather than in an afternoon of cross-referencing.
What mapping API 571 onto geometry means in practice
Mapping starts with the mechanism assignments the study already produced. Each equipment item and corrosion circuit carries one or more API 571 mechanisms: sulfidation on the hot crude circuit, CUI on the insulated cold lines, amine cracking on the non-post-weld-heat-treated welds in the treating unit. Those assignments are attached to components in the model. Nothing is recalculated. The assignment is simply given a position in space.
Position immediately does work the table could not. API 571 places CUI in carbon and low-alloy steels between 10 °F and 350 °F, most severe between 212 °F and 350 °F. On a model, that stops being a sentence in a document and becomes a set of highlighted lines: every insulated component inside the susceptible band, with the ones actually inspected in the last cycle distinguished from the ones nobody has opened.
The same applies to mechanisms thickness monitoring cannot detect. Wet H2S cracking, amine cracking and chloride stress corrosion cracking initiate without measurable general wall loss, which means a component covered by dense UT coverage can be entirely uninspected for its governing mechanism. Displaying mechanism against method applied makes that mismatch obvious, and it is common enough that most first mapping exercises find several examples.
Risk tiers as a plant view rather than a matrix
Risk tiers rendered on geometry answer a question the matrix cannot: what does the high-risk equipment in this unit look like as a group? Sometimes it is scattered, and the inspection plan is necessarily distributed. Often it clusters, around a hot section, a sour service circuit, or a set of exchangers sharing a service, and the clustering is itself a finding worth acting on.
Clusters change plans. Four high-risk items on the same structure share access, which means one scaffold and one shutdown window rather than four separate access packages. That connection is invisible in a ranked list sorted by risk score, because the list has no concept of proximity. It is the same argument that makes turnaround access planning worth doing in the model rather than on paper.
The view also survives handover. A contractor bidding turnaround inspection scope who can see risk tier per item bids differently from one working off a line list. Operators new to the unit learn where the consequential equipment is in an afternoon. The RBI study stops being a document owned by one engineer and becomes shared knowledge, which is the outcome API RP 580 asks a programme to achieve and no standard can enforce.
Reallocating effort from uniform coverage to where the risk sits
Uniform inspection is the default that RBI exists to replace, and it persists because it is administratively simple. Everything on the same interval, the same number of CMLs per circuit, the same coverage everywhere. The result is well documented: substantial effort spent on equipment where failure would be inconvenient, and thin coverage on equipment where failure would be serious. RBI identifies that imbalance. Visualising it is what gets it corrected.
The mechanism is comparison. Put risk tier and current inspection effort on the same geometry as two overlays and the disagreements are visible without analysis. A low-risk circuit with forty CMLs sitting next to a high-risk vessel with a general visual is a picture anyone can interpret, including the manager who approves the inspection budget. That audience matters, because reallocation is a budget decision before it is a technical one.
The reallocation itself is engineering work and belongs with people qualified to do it. Reducing coverage on equipment is a decision with consequences, and it needs the study's assumptions verified rather than assumed, particularly the mechanism assignments and the inspection effectiveness credited to past examinations. Where a site lacks that capability internally, it is precisely what RBI programme design exists to supply. The picture builds the case; a qualified engineer signs the change.
Corrosion circuits, CMLs and the mapping problem underneath
Underneath the visualisation sits a reconciliation problem that determines whether the project works at all. RBI operates on equipment items and corrosion circuits. Thickness monitoring operates on CMLs. The model operates on geometric components. These three schemes were built by different people at different times and rarely align cleanly. A circuit in the RBI study may span components the model treats as separate items, and CMLs may sit on components the circuit definition never named.
The reconciliation is manual and it is the schedule. Circuit boundaries have to be drawn on the model. CMLs have to be placed on components. Equipment tags have to match model objects one for one. Doing this at circuit level first produces something usable quickly, while insisting on point-level completeness before anything is visible produces a project that stalls. Partial completeness, honestly marked, beats false completeness every time.
This is also where a site discovers the true state of its data. Circuits with no documented boundary, equipment tags that appear twice, drawings that do not match the plant as built. Those findings are uncomfortable and valuable, and they are the same findings that surface in an NDT programme audit. The mapping exercise simply makes them impossible to defer any longer.
When the picture sends you to fitness-for-service
Mapped thickness against mechanism produces a specific trigger. When a component's measured thickness reaches or drops below the minimum required by the design code, continued operation stops being an inspection question and becomes an assessment question governed by API 579-1/ASME FFS-1. The twin's role is to raise the flag with the surrounding context attached: which component, what mechanism, what the neighbouring readings show, and what the thickness profile looks like across the affected area.
That context is exactly what a fitness-for-service assessment consumes. A Level 1 assessment needs flaw dimensions and a thickness profile. A Level 2 or Level 3 assessment needs geometry, loading and material data. A twin carrying a scanned profile of a corroded area supplies inputs that would otherwise be reconstructed from a report and a hand sketch, and reconstruction is where assessment schedules are lost.
Keep the boundary clean. The twin identifies candidates and packages data. The assessment is performed by a qualified engineer against the standard, and the result, whether run, repair, replace or run with a revised interval, is an engineering decision recorded outside the model. Our fitness-for-service assessments take the twin's output as input, not as a conclusion. A model that appears to decide is a model nobody should trust.
What the twin does not do to your RBI programme
It does not identify damage mechanisms. Mechanism identification is materials and corrosion engineering performed against API RP 571 and the actual process conditions, and it requires people who understand what the unit runs today rather than what it was designed for. A twin displays assignments made by those people. A mechanism nobody identified stays invisible, and the model's confident rendering can make that absence feel like coverage. Guard against that explicitly.
It does not calculate probability or consequence. The POF and COF work sits in the RBI methodology, whether the quantitative procedures of API RP 581 or whatever documented approach satisfies API RP 580 at your site. Importing risk scores into a model and re-rendering them is display, not analysis, and describing it as anything else misleads the people relying on the output to make spending decisions.
It does not revalidate itself. Risk changes when the process changes, when a mechanism is confirmed by inspection, when a repair is made, or when new data arrives. The revalidation cycle defined in your programme still governs. A twin showing risk tiers from a study that is four years old and two feed changes out of date is a confident picture of a plant that no longer exists.
Keeping the map alive between revalidations
Keeping the map current is a data-flow problem rather than a modelling problem. Inspection results have to reach the inspection data management system, mechanism confirmations have to reach the RBI study, and both have to reach the model. Where any of those hops is manual, the picture decays at the speed of the slowest hop. Sites underestimate this consistently, because the model looks identical whether the data behind it is current or two years stale.
The realistic architecture keeps the system of record where it already is. The IDMS holds thickness, calculations and history. The RBI study holds mechanisms and risk. The model reads both and owns neither. We set the division out on digital twin vs IDMS, because the alternative of migrating the record into the visualisation creates an audit problem that takes years to unwind.
Start where the mechanisms are concentrated and consequential: a hot crude circuit with sulfidation, an amine unit, a sour service network, or an insulated line network with CUI. One unit, one revalidation cycle, and a direct comparison of where inspection effort went before and after. Get in touch with the unit you would start on and the state of your current study, and we will scope it from there.
What is the difference between API 580 and API 581 in this context?
API RP 580, fourth edition August 2023, defines the elements a credible RBI programme must contain and permits qualitative, semi-quantitative or quantitative methods. API RP 581, fourth edition February 2025, supplies one detailed quantitative route with damage factor tables and consequence models. A twin visualises the output of either. Neither standard requires or mentions visualisation.
Does visualising risk change the risk ranking?
No, and any tool that changes the ranking during visualisation has a defect. The ranking comes from the RBI study and its documented assumptions. What visualisation changes is scrutiny: a high-risk item everyone can see gets questioned, and a low-risk item carrying heavy inspection spend gets questioned too. Both questions improve the next revalidation.
Why map damage mechanisms rather than just risk scores?
A risk score tells a planner how much to worry. A mechanism tells them what to do. API 571 pairs each mechanism with the inspection methods that detect it, so a component tagged with wet H2S cracking demands a crack-detection method rather than more thickness readings. Mapping mechanisms carries the method decision onto the geometry alongside the risk.
Can this find damage the RBI study missed?
Indirectly. Mapping forces every component into a mechanism assignment, and components that end up with none are visible as blanks on the model. Those blanks are usually small-bore connections, dead legs, vents and drains that the study covered only at circuit level. Finding them is a data-completeness benefit rather than an analytical one, and it is consistently the first thing a mapping exercise surfaces.
How does the twin connect to a fitness-for-service assessment?
It flags the trigger and hands over. When mapped thickness data shows a component below its minimum required thickness, the decision moves to API 579-1/ASME FFS-1 methodology and a qualified engineer. The twin supplies the flaw location, the surrounding geometry and the thickness profile that the assessment needs as input. Our fitness-for-service work starts from exactly that data.
What does a risk-weighted inspection plan look like on the geometry?
Two overlays compared side by side: risk tier per equipment item, and inspection hours or examinations currently assigned per item. Where the two overlays disagree, effort is misallocated. Low-risk equipment carrying heavy uniform coverage is where recoverable hours sit. High-risk equipment with thin coverage is where the next incident sits. The comparison is the deliverable.