Turning corrosion rates into a frozen outage scope for a combined-cycle plant

A combined-cycle plant gets one access window every year or two, and scope must be frozen weeks before it opens. Short-term and long-term corrosion rates are computed separately with the higher governing, but flow-accelerated corrosion does not behave like uniform corrosion and a cycling unit does not age by calendar year. Both facts change what the rate must be built from.

Power generation sits outside API 510 jurisdiction. Boilers and their integral piping fall under ASME Section I and are inspected in service under the National Board Inspection Code, with a jurisdictional inspector rather than an API-certified vessel inspector, while balance-of-plant steam and feedwater piping falls under ASME B31.1 and its covered piping systems requirements. Neither document hands you the short-term and long-term rate formulas that API 510 spells out, so most well-run plants adopt that logic voluntarily inside their own written program. The dominant mechanism is flow-accelerated corrosion, which is controlled by water chemistry, temperature, geometry, two-phase quality and the residual chromium content of the individual pipe heat. Two identical elbows in the same header can thin at rates differing several-fold. Pooling them into a component-class rate destroys the only signal worth having.

Source: In-service inspection follows the National Board Inspection Code NB-23. Boiler construction follows ASME Boiler and Pressure Vessel Code Section I; power piping follows ASME B31.1 including its covered piping systems requirements. Fitness-for-service assessment follows API 579-1 / ASME FFS-1, Part 4 for general metal loss and Part 5 for local metal loss. Damage mechanism definitions follow API RP 571. Flow-accelerated corrosion program practice follows EPRI guidance. Welding qualification follows ASME Section IX. Personnel qualification follows ASNT SNT-TC-1A, ASNT CP-189 or ISO 9712.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Circuits competing for a fixed outage window, and what has to be settled before it opens
Circuit or componentDominant mechanismWhy a calendar-year rate misleadsWhat must be settled before the window
LP economizer and feedwater heater drainsSingle-phase flow-accelerated corrosionRate tracks operating hours in the FAC temperature band, not elapsed yearsScaffold and insulation removal at the elbows and downstream straights
LP evaporator risers and drum internalsTwo-phase FAC and under-deposit attackDamage responds to steam quality and cycling, which vary year to yearAccess through drum manways, confined space plan, internal lighting
HP economizer inlet header and tube stubsThermal fatigue plus localised thinningLoss concentrates at a few tubes; averaged rates read as benignTube sample selection, boroscope or IRIS access, spare tube stock
Attemperator and desuperheater downstream pipingThermal fatigue and erosion from spray waterDamage accumulates per start and per spray event, not per yearWeld inspection technique agreed, crew certified for the method
Extraction, drain and bypass linesTwo-phase FAC at low-flow and intermittent serviceIntermittent service means the operating hours are far below calendar hoursLine list agreed with operations; isolation and drain plan
Cold-end duct, stack and SCR regionAcid dew point corrosion and ammonium salt depositionDepends on fuel sulfur, load profile and ammonia slip, all variableDuct entry, cleaning of deposits before measurement, coating repair materials
Fuel gas piping and heaters upstream of the turbineInternal corrosion from moisture and contaminantsLong intervals give a short-term rate indistinguishable from the long-termIsolation with the gas supplier, purge plan, hot work permits

Why the power turnaround inverts the corrosion rate problem

In a refinery, a corrosion rate mostly answers a monitoring question: is this line degrading faster than expected, and does the interval need to shorten. In a combined-cycle plant, the question is scheduling. The unit will be offline for a fixed number of days, at a date set by market conditions, gas turbine equivalent operating hours and the seasonal shoulder when the plant can be spared. Scaffold, insulation removal, crews, cranes and long-lead materials all have to be committed before anyone can see inside. The rate has to support a decision made in advance of the evidence.

That inverts the usual sequence. Instead of measuring and then deciding, you forecast, commit, and then measure to confirm. A rate that is merely accurate about the past is not useful; what is needed is a projection of thickness at the window opening date, and a second projection at the following window, because the real question for most components is not whether they will survive this outage but whether they will survive to the next one. Deferring a component to the next window and being wrong is the most expensive error available in this environment.

The second inversion is consequence. In process plant, an unplanned shutdown is lost production. In merchant power, an unplanned outage may be a forced outage against a capacity obligation with contractual penalties, and it may fall in a period of high market prices precisely because the grid is stressed. The asymmetry between a slightly over-scoped outage and a forced outage two months later is large enough that plants will routinely add scope on a marginal rate — provided the rate is credible enough to justify the spend.

This is National Board and ASME territory, not API 510

Getting the jurisdiction right matters more than it sounds. A power boiler is constructed to ASME Section I and inspected in service under the National Board Inspection Code NB-23, with the jurisdiction's commissioned inspector involved and repairs and alterations handled by an organisation holding the appropriate National Board stamp with procedures qualified to ASME Section IX. Balance-of-plant steam, feedwater and condensate piping falls under ASME B31.1, which carries its own operation and maintenance expectations including a covered piping systems program identifying which lines get systematic inspection attention.

None of those documents hands you the neat short-term and long-term rate formulas that API 510 and API 570 specify. That is a real practical gap: a plant integrity engineer inherits an obligation to manage thinning without a prescribed arithmetic for doing it. Most competent programs close the gap by adopting API-style two-rate logic voluntarily and writing it into their own procedure, sometimes alongside EPRI-derived flow-accelerated corrosion methodology for the circuits where FAC dominates.

The implication for software is that it cannot assume the code. A system hard-wired to API 510 intervals will produce inspection dates that mean nothing in a jurisdiction that sets its own boiler inspection frequency, and it will fail to model a covered piping systems program at all. What a power plant needs is a configurable rule set: define your own governing rate logic, your own interval basis, your own equipment classes, and record which code or program each one is being managed under, so that an audit sees the plant's written procedure reflected exactly in the system's behaviour.

Flow-accelerated corrosion does not behave like corrosion

Flow-accelerated corrosion is the dissolution of the protective magnetite layer into flowing water or wet steam. It is not an electrochemical pitting process and it responds to a different set of variables: temperature, with a susceptibility peak in the mid range rather than a monotonic increase; pH and reducing versus oxidising chemistry; mass transfer, which means geometry, velocity and upstream disturbance; steam quality in two-phase lines; and the alloy content of the steel, where even a modest chromium residual suppresses the mechanism dramatically.

That last variable is the one that breaks conventional rate management. Carbon steel piping to a single specification carries chromium as a residual, not a controlled addition, and it varies heat to heat. Two elbows of the same size, schedule and specification, installed in the same header on the same day, can thin at rates that differ by a factor of several purely because they came from different heats. Pooling them into a component-class average rate produces a number that is wrong for both, and specifically it produces a number that is comfortably low for the one you needed to worry about.

This has a direct consequence for how a rate module should be built. Component-level identity is mandatory; class averages are for screening only. Where material test reports or in-situ alloy verification give chromium content, it belongs on the component record as an attribute the engineer can sort by. And the population of rates within a circuit is itself informative: a circuit where every component thins at a similar rate is behaving predictably, while a circuit with a wide spread is telling you that heat-to-heat variation dominates and that your worst component may not yet have been measured.

Calendar years are the wrong denominator for a cycling unit

The gas fleet has changed duty profoundly. Units built for baseload now cycle daily to follow renewable output, with hundreds of starts a year, extended low-load operation, and long periods offline. Damage accumulation follows operation, not the calendar. A plant that ran 8,000 hours a year for six years and then 2,500 hours a year for three accumulated its flow-accelerated corrosion overwhelmingly in the first period, but a calendar-based long-term rate spreads it evenly and will systematically over-predict future loss in the new regime.

The fix is not complicated but it does require the data. Store operating hours and start counts against the plant and, where the circuits differ, against the circuit. Compute the long-term rate on the exposure basis appropriate to the mechanism: hours in the susceptible regime for FAC, starts for thermal fatigue and attemperator damage, and calendar time only where the mechanism genuinely proceeds while the unit is shut down, such as offline corrosion in poorly laid-up circuits. Present both bases, because a planner arguing for scope needs the number a manager will recognise as well as the one that is technically correct.

Layup deserves its own note. Damage during shutdown is real and under-recorded. A unit that sits wet without nitrogen blanketing or a dehumidified air system can accumulate meaningful offline corrosion in circuits that are dormant, and cycling units sit idle far more than baseload ones ever did. A rate computed on operating hours will attribute that loss to operation and inflate the operating-hour rate; a rate computed on calendar time will blur it. The honest treatment is to record layup practice and treat poorly laid-up periods as exposure of a different kind.

Forecasting to the outage after next

The planning question is a projection, not a measurement. For each candidate component, project thickness at the opening of the next window and at the opening of the one after, using the governing rate on the appropriate exposure basis and an assumed forward duty profile. Compare both projections against the required minimum thickness plus whatever margin your program demands. That produces three populations: components that must be addressed this window, components that will not survive to the following one and should therefore be addressed now while access exists, and components that can genuinely wait.

The middle population is where the money is, and it is the one a purely reactive program never sees. A component with two years of remaining life going into a three-year window interval is a forced outage waiting to happen, but it will pass every present-tense screening because it is above minimum thickness today. Making that population visible, sorted and costed is the single highest-value output a corrosion rate module can produce for a plant on a fixed outage cycle.

The forecast needs honest uncertainty attached. A projection built on two readings separated by one interval, on a mechanism as variable as FAC, carries wide error bars. A projection built on four readings over three intervals with a consistent technique is considerably tighter. Presenting the projection with a confidence indication lets the outage manager triage properly: high-consequence components with low-confidence projections are candidates for early inspection or for an online screening technique before the freeze date, rather than for a coin-flip decision at scope review.

Chemistry changes and the governed exception to conservatism

The rule that the higher of the short-term and long-term rate governs is sound, and in one specific power scenario it is perverse. A plant that has run reducing all-volatile treatment for years, accumulated significant flow-accelerated corrosion, and then converted its chemistry regime — to an oxidising treatment or to oxygenated treatment where the cycle design permits — will often see FAC rates fall substantially and quickly. The long-term rate, dominated by the pre-conversion period, will continue to govern for years and will keep pulling components into scope that are no longer degrading.

The correct handling is a governed reset rather than a quiet override. The engineer establishes a new datum at the conversion date, records the chemistry evidence — the treatment change, the date, and the sustained chemistry results supporting it — and computes the forward long-term rate from that datum. The pre-conversion history is retained and remains visible. Critically, the reset should not take effect on assertion alone; it should require confirmation readings on the new basis before the system will use the reduced rate for interval setting.

This is a good test of whether an inspection management system is engineering software or a database with charts. The behaviour required is a controlled exception path: a defined justification type, mandatory evidence attachment, a named approver with authority recorded, an effective date, and a permanent audit trail showing both the pre-reset and post-reset rates. Systems that offer either no override or an unrestricted one both fail, in opposite directions. The first drives engineers to keep their real numbers in a spreadsheet; the second makes the whole dataset unauditable.

Turning a rate into a frozen scope, a scaffold list and a crew plan

A projection only becomes useful when it converts into work packages. Each component flagged for this window generates a set of dependencies: what has to be removed to reach it, what technique will be used, who is certified for that technique, what the acceptance criteria are, what materials are required if the finding is negative, and how long the whole sequence takes. Insulation removal and scaffold are usually the binding constraints, not the inspection itself, and both are ordered from a list that has to be complete before the freeze date.

This is where the arithmetic and the schedule finally meet. Two components with similar remaining life are not equally urgent if one requires a single ladder and the other requires a hundred cubic metres of scaffold and a confined space entry. Ranking scope by risk alone produces a plan that cannot be executed in the window; ranking by risk divided by access cost produces one that can. A rate module that carries access and technique attributes on the location can produce that ranking directly, which is exactly the artefact an outage manager needs at scope review.

The same structure serves the post-outage side. Every finding needs to close the loop: what was measured, what was repaired, whether a fitness-for-service assessment under API 579-1 / ASME FFS-1 was used to justify continued service, what the new baseline thickness is, and when the component is next due. Components repaired or replaced start fresh baselines. Components accepted on assessment carry the assessment's conditions and expiry into the next planning cycle, so the constraint does not get lost between outages.

What to test in a demonstration when your window is fixed

Bring one HRSG circuit with real history, including at least one component where two adjacent items of identical specification thinned at very different rates, and if you have had a chemistry conversion, bring data spanning it. Ask the vendor to produce a projected thickness at your next two window dates, on an operating-hours basis rather than calendar years, with the governing rate identified for each component and the confidence in each projection made explicit. That single exercise separates products that model your problem from products that plot your data.

Then test the mechanics that determine whether anyone will actually use it. Can the code or program basis be configured per equipment class, so boilers under the National Board Inspection Code and piping under B31.1 coexist without one pretending to be the other? Is there a governed datum reset with mandatory evidence and an approver? Can operating hours and starts be imported from the plant historian rather than typed? Can a location carry access and technique attributes so scope can be ranked by risk against access cost? Does the export produce something an outage planner can work from directly?

Atlantis builds inspection management, reporting and digital twin software for exactly this pattern of work, configured to the plant's own written program rather than to a generic code assumption, and integrated with the access and scope planning side rather than stopping at the trend chart. The positioning is affordable, accessible and fully customizable. To see a projection run against your own HRSG history ahead of your next window, request a demonstration or a technical consultation at info@atlantisndt.com.

Why is API 510 the wrong code for a power boiler?

Because jurisdiction differs. API 510 governs in-service inspection of pressure vessels built largely to ASME Section VIII and operating in the process industries under an owner-user program. A power boiler is built to ASME Section I, inspected in service under the National Board Inspection Code, and is subject to a jurisdictional authority and its commissioned inspector. Balance-of-plant piping follows ASME B31.1. The distinction matters at audit, because citing the wrong code in a written program is a straightforward finding even when the engineering behind it was sound.

How do you set the right denominator for a cycling unit?

Use exposure, not calendar time. A combined-cycle plant that ran baseload for a decade and now performs two hundred starts a year accumulates damage on a completely different schedule from before. For flow-accelerated corrosion, hours within the susceptible temperature and chemistry regime are the meaningful denominator. For thermal fatigue and attemperator damage, starts and spray events matter. Storing operating hours and start counts against each location, and letting the rate be computed on either basis, is what turns a trend into a forecast you can plan an outage around.

Why do two identical elbows thin at different rates in an HRSG?

Because flow-accelerated corrosion is exquisitely sensitive to alloy chemistry, and residual chromium in carbon steel varies from heat to heat. Two elbows to the same specification, installed on the same day, may carry very different chromium residuals, and even small differences suppress FAC substantially. Add local geometry, upstream disturbance and two-phase quality, and the spread widens further. This is why component-class average rates are actively misleading here: the number you need is the rate at the specific component, and the population variance is the finding.

When can a plant reset the long-term rate datum?

When a documented, physical change to the driving conditions has occurred — most commonly a water chemistry conversion, such as moving from a reducing all-volatile treatment to an oxidising regime, which can cut flow-accelerated corrosion sharply. The rule that the higher rate governs would otherwise punish a plant indefinitely for damage that predates the fix. The reset must be a governed exception: engineering justification, chemistry records showing the change and its date, an approver, and confirmation readings on the new basis before the reset takes effect.

How far ahead must a turnaround scope be frozen?

Long enough to procure long-lead items, engineer repairs, contract crews and build the scaffold plan — commonly several months for major replacements and at least six to eight weeks for anything requiring engineered access. This is the constraint that shapes everything upstream. The corrosion rate module is not being asked what condition a component is in today; it is being asked what condition it will be in when the window opens, and whether it will survive to the window after that.

What happens if a component is found below minimum thickness mid-outage?

You are choosing between replacement inside a schedule that has no float, a code repair, or a documented fitness-for-service assessment under API 579-1 / ASME FFS-1 that justifies continued operation to the next opportunity. All three need engineering input under time pressure. The value of a good rate forecast is that it converts that emergency into a pre-planned decision: the components at risk were identified before the window, the assessment basis was prepared, and the materials were on site rather than being expedited.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.