Recommended practice establishing the methodology for risk-based inspection (RBI) of fixed equipment — defines PoF, CoF, and risk-based interval setting.
Scope
API 580 — Risk-Based Inspection — establishes the methodology for risk-based inspection (RBI) programs for fixed equipment in refining and petrochemical facilities. RBI is the alternative to prescriptive interval setting in API 510, API 570, and API 653 — instead of "5 years for Class 1 piping," RBI sets the interval based on the calculated risk and the operator's risk-tolerance threshold. API 580 defines the methodology framework. API 581 provides the quantitative methodology (specific calculation procedures, data tables, models) for those operators who choose a fully quantitative RBI. The current edition is the 3rd Edition (February 2016) — the standard establishes program requirements rather than specific calculation methods.
Code compliance is only demonstrable if the evidence behind it is: the procedure revision in force, the inspector's certification state and the instrument's calibration status at the time of test. Atlantis NDT provides ASNT Level III consulting for procedure and written-practice work against this code, training toward the certifications that reference it, and inspection management software that keeps that evidence recoverable years later. Request a consultation.
How a standard like this is applied in an inspection programme
A standard is only half of the requirement. It defines how an examination is performed and, in some cases, how results are classified — but the acceptance criteria that decide whether a component stays in service normally come from the construction or in-service code governing the item, not from the examination standard itself. Confusing the two is one of the more common findings in a procedure review: a procedure that correctly cites the examination standard but applies acceptance criteria from the wrong code or the wrong edition.
What has to be in place for compliance to be demonstrable
A written procedure qualified against this standard for the specific materials, thickness ranges and geometries in scope — not a generic procedure covering everything
Personnel certified for the method and level under ASNT SNT-TC-1A, ANSI/ASNT CP-189, NAS 410 or ISO 9712, current on the date the examination was performed
Equipment, probes and reference standards in calibration on that date, with traceability to a national standard under ISO 17025
The applicable edition of the standard recorded against the examination, so historical work stays assessed under the edition then in force
Technique sheets under the same revision control as the procedure above them — the most frequently uncontrolled document in an otherwise compliant quality system
Edition changes
When a new edition is issued, new work moves to it from a defined effective date that you set and record; work already performed stays assessed under the edition in force at the time. Retrospectively applying a new edition to historical dispositions invalidates the original acceptance decision and creates a substantially larger problem than the one being solved.
Where this usually goes wrong
Not in the technical content, but in reconstruction. An auditor picks an issued report and asks which procedure revision applied, who performed the work and whether they were qualified on that date, and whether the instrument and reference blocks were in calibration. Programmes that hold only current state can answer none of those. Binding the document revision, the qualification state and the calibration state to each inspection record as it is created turns that from an investigation into a lookup.
API RP 580 defines the minimum elements of a credible risk-based inspection programme: it requires that risk be assessed as probability of failure multiplied by consequence of failure, that assumptions and data quality be documented, and that inspection plans be driven by that risk. It is a planning framework, not a calculation method — the numbers live in API RP 581.
The document is a recommended practice, so it becomes mandatory only when a jurisdiction, an owner-user procedure or a referencing code invokes it. API 510, API 570 and API 653 each permit inspection intervals to be set by RBI, and each points at API RP 580 for what that assessment must contain. That is where the practice acquires teeth: once an owner-user extends a vessel interval beyond the default half-remaining-life or ten-year rule on the strength of an RBI, the assessment becomes an auditable engineering record. API 580 tells you the record must identify the damage mechanisms credible for each equipment item, the data used and its quality, the assumptions, the analyst competence, the risk target against which the result was judged, and the inspection actions the risk drives. It does not tell you how to compute a number. Auditors read the assumptions first, not the risk plot.
Source: Source: API RP 580, Risk-Based Inspection, 3rd edition (2016); API RP 581, Risk-Based Inspection Methodology, 3rd edition; API 510 Pressure Vessel Inspection Code; API 570 Piping Inspection Code; API 653 Tank Inspection, Repair, Alteration and Reconstruction; API RP 571 Damage Mechanisms Affecting Fixed Equipment in the Refining Industry; API RP 584 Integrity Operating Windows; ASME PCC-3 Inspection Planning Using Risk-Based Methods; 29 CFR 1910.119 Process Safety Management.
API RP 580 programme elements, what each requires, and the audit finding it generates when it is thin
Programme element
What API RP 580 requires
Typical audit finding
Damage mechanism screening
Every credible mechanism identified per equipment item, referencing API RP 571
Generic "general corrosion" applied plant-wide, with no screening for CUI, HTHA or chloride stress corrosion cracking
Data and data quality
The data used, its source and the confidence placed in it recorded alongside the assessment
Corrosion rates taken from a design corrosion allowance rather than from measured thickness history
Probability of failure
PoF derived from the mechanism, the rate and the inspection history — not from a show of hands
PoF scored in a workshop in which no thickness data was opened
Consequence of failure
Consequence assessed on the actual inventory, phase behaviour and isolation capability
Consequence lifted from a unit-level HAZOP with no reasoning recorded for isolation credit
Risk target
A tolerable risk criterion documented by the owner-user before results are judged against it
Target inferred backwards from the plotted results so that nothing lands in the red band
Inspection plan
Method, coverage, location and due date driven by the mechanism the risk was built on
Plan reads "UT thickness" with no CML count, no coverage percentage and no link to a mechanism
Reassessment and management of change
Reassessment triggered by process change, damage discovery or elapsed time per the referencing code
Assessment frozen at project handover; a feed change three years ago never triggered a review
Findings above are the recurring ones in owner-user RBI audits. None of them are failures of the software — every one is a failure to record why an input was chosen.
What API RP 580 covers, and what it deliberately does not
API RP 580 covers the design and management of a risk-based inspection programme for fixed equipment: pressure vessels, piping circuits, atmospheric and low-pressure storage tanks, heat exchangers, pressure relief devices and, where the owner-user chooses, associated components. Its subject is the programme, not the equipment. It tells you what the assessment must identify, what must be written down, who must be involved, when the work must be revisited, and how the result feeds an inspection plan. Everything in it is answerable to a single question: could someone else reconstruct why this interval was chosen?
What it does not cover is just as important, and is where most misapplication starts. It contains no calculation method — no failure frequencies, no damage factor tables, no consequence models. It does not set a tolerable risk criterion; that is the owner-user's to define and defend. It does not address fitness-for-service, which is API 579-1/ASME FFS-1. It does not cover rotating equipment, instrumented protective functions or structural steel, and it does not replace hazard analysis. An RBI study is not a HAZOP and will not find the scenarios a HAZOP finds.
The most common scope error is treating API RP 580 as a licence to reduce inspection. It is not a cost-reduction document. Applied properly it usually moves effort rather than removing it — pulling scope off low-consequence, low-rate circuits and pushing it onto the handful of components where a credible mechanism is active and the consequence is severe. If your first RBI cycle reduced total inspection hours across the board and moved nothing, the study did not discriminate, and that is a finding.
The requirements that actually bite
Three requirements produce almost all of the findings. The first is documented assumptions. API RP 580 requires that the basis for each input be recorded — where a corrosion rate came from, why a mechanism was screened out, what was assumed about isolation. In practice the assessment file contains a software export and a spreadsheet of scores, and no narrative at all. When the auditor asks why a circuit carrying wet H2S was not screened for hydrogen blistering or SOHIC, there is no record of the decision, only its absence.
The second is data quality. The practice expects data to be characterised, not merely used. A corrosion rate calculated from two thickness readings taken eleven years apart by different technicians on nominally the same CML, using different couplant and possibly different paint condition, is not the same input as a rate from a monitored series on a prepared location — even if both produce 0.08 mm/yr. Recording that difference is the whole point, and it is the single most valuable thing an inspection data management system does for an RBI programme.
The third is competence. API RP 580 expects the assessment team to have demonstrable capability in damage mechanisms, inspection methods and the RBI method itself, and expects that to be recorded. Where an owner-user has no in-house corrosion authority, the usual route is an external Level III or materials specialist retained for the assessment cycle. Atlantis supports this through ASNT Level III consulting on the NDE side — mechanism-to-method selection, procedure adequacy, and whether a proposed examination can actually detect what the study claims it detects.
How API RP 580 interacts with API 510, 570 and 653
The referencing code is what gives API RP 580 force, and each one applies it differently. API 510 permits the internal or on-stream inspection interval for a pressure vessel — otherwise the lesser of half the remaining corrosion life or ten years — to be set by RBI instead. API 570 permits piping thickness measurement and external visual intervals, which default by piping class with Class 1 thickness readings at five years, to be set by RBI. API 653 permits the tank internal inspection interval, otherwise capped at twenty years, to be extended by RBI, subject to the code's own absolute ceiling of thirty years.
This asymmetry matters when a single RBI study spans vessels, piping and tanks. The study will produce a risk-driven due date for each item, but the code the item is inspected under may refuse it. A tank whose RBI supports a thirty-five-year interval still gets thirty. A vessel whose RBI supports twenty-two years still needs the assessment to satisfy API 510's own requirements for RBI-based intervals, including reassessment. Software will happily emit the unconstrained date, and the constrained date is the one you are audited against.
The other interaction people miss is directional. RBI can extend an interval; it can also shorten it, and the referencing code does not protect you from that. If the assessment identifies an active mechanism the historic programme was not looking for — say ammonium chloride corrosion at a specific dew point location — the resulting plan may require an examination well inside the code default, at a location the old plan never had a CML on. Ignoring a risk-driven shortening while banking the extensions is indefensible, and it is visible in the data.
Damage mechanism identification decides the answer
Everything downstream in an RBI is a consequence of the mechanism list. If the mechanism is wrong, a rigorous calculation on a rigorous consequence model produces a confidently wrong number, and the inspection plan sends a technician to take thickness readings on a circuit that is going to crack rather than thin. API RP 580 points to API RP 571 for mechanism definitions and expects screening to be done per equipment item against actual process conditions, not per unit against a design basis.
The mechanisms that most often go missing are the ones that do not produce general wall loss: corrosion under insulation at the specific temperature bands and wet-dry cycling locations where it concentrates, high temperature hydrogen attack in hydrogen service above the Nelson curve threshold, chloride stress corrosion cracking on austenitic stainless under insulation or at the tube-to-tubesheet region, caustic embrittlement at weld heat-affected zones without post-weld heat treatment, and creep in fired heater tubes. Every one of these has a preferred location and a required examination method. None of them is found by routine spot thickness.
The screening step is also where integrity operating windows earn their place. API RP 584 windows define the process envelope inside which the assumed mechanism list holds. When a unit runs outside the window — a higher chloride feed, a lower overhead water wash rate, a temperature excursion — the mechanism list changes and the RBI assumptions expire. A programme that maintains windows and links excursions back to the assessment is the difference between an RBI that stays true and one that quietly stops describing the plant.
Risk targets and the trap of letting the matrix set them
API RP 580 requires a tolerable risk criterion, and requires that it be the owner-user's. This is the requirement most frequently skipped, because a risk matrix arrives with colour banding already applied and it is tempting to treat red, amber and green as the criterion. They are not. Banding on a five-by-five matrix is a display convention. Without a stated target — expressed as an area consequence per year, a financial exposure per year, or a defined position on the matrix that triggers mandatory action — the study produces a ranking with no threshold, and a ranking cannot justify an interval extension.
The failure this produces is subtle and consistent. Teams calibrate the matrix until the distribution looks reasonable, typically until roughly the same set of equipment lands in the high band as the experienced inspectors already worried about. That is not validation. It is the study reproducing the prior belief it was supposed to test, and it guarantees that the equipment nobody was worried about — which is where the surprise failures live — never surfaces.
A defensible target is set before results are seen, is written into the owner-user procedure, is applied uniformly across units, and is signed by someone with the authority to accept the residual risk. Where risk exceeds the target, API RP 580 expects mitigation: inspection to reduce uncertainty, a design or metallurgy change, a process change, or a documented acceptance. Inspection is only one of the four, and it is the only one that reduces uncertainty rather than risk itself — a distinction worth stating explicitly in the procedure.
What the inspection plan has to say beyond a date
An RBI that produces a due date and nothing else has done half the job. API RP 580 expects the plan to specify what will be examined, by which method, over what coverage, at which locations, and why that combination addresses the mechanism the risk was built on. A plan that says "internal visual, 2029" cannot be graded for effectiveness later, and effectiveness grading is what allows the next cycle to credit the examination and lengthen the interval.
Coverage is where plans are weakest. Ten CMLs on a forty-metre circuit is a sampling scheme, and its ability to find localised attack depends entirely on whether the CMLs sit where the mechanism concentrates — injection points, downstream of mixing tees, at dead legs, at the six o'clock position on a line carrying wet gas. The plan should say so. Where the mechanism is cracking rather than thinning, the plan must name a method capable of detecting it — shear wave, phased array, TOFD, ACFM, or WFMT after paint removal — because thickness readings will not.
The plan also has to survive contact with execution. Scope written in a study and then handed to a contractor as a line on a work order routinely loses the coverage and location detail that made it credible. Carrying the plan through to execution and back as a completed record is a workflow problem as much as an engineering one, and it is what an inspection management platform is for: the plan, the work order, the technician's certification, the equipment calibration, the result and the deviation all attached to the same equipment item.
Reassessment, management of change, and programme drift
An RBI assessment describes a plant at a moment. Plants move. API RP 580 requires reassessment, and the triggers that matter are the process ones: a change in feedstock or its contaminants, a change in operating temperature or pressure, a change in an overhead water wash or inhibitor injection rate, a repair or alteration, a change in service, and any inspection finding that contradicts the assumed rate or reveals an unexpected mechanism. Elapsed time is a backstop, not the primary trigger.
Drift is the failure mode nobody sees happening. A study is completed during a turnaround, endorsed, and becomes the basis for the next decade of intervals. Over that decade the crude slate changes twice, a heat exchanger is retubed in a different alloy, an injection quill is relocated, and three circuits are re-rated. None of these individually feels like an RBI trigger to the person making the change, and collectively they invalidate the assessment. The defence is a management-of-change route that names the RBI assessment as an affected document.
For sites operating under OSHA process safety management, this is not merely good practice. The mechanical integrity element requires inspection and testing procedures that follow recognised and generally accepted good engineering practice, and requires that the deficiencies found are corrected. Where RBI sets those intervals, the assessment and its currency become part of the mechanical integrity record — which is why owner-users increasingly hold the whole chain in mechanical integrity software rather than in a study report on a shared drive. Atlantis supports the owner-user's programme in this space; it is not a PSM auditor and is not the authorised inspector of record.
The misreadings that produce audit findings
The first is treating RBI output as an inspection result. Risk ranking tells you where to look; it does not tell you the condition of anything. Equipment that scores low risk has not been inspected by scoring low risk, and equipment that scores high has not thereby been found defective. Written the wrong way round in a plan, this produces the statement auditors seize on: that inspection was deferred because the risk was low, with no record of what evidence made it low.
The second is the inherited corrosion rate. Rates propagate through RBI databases by circuit similarity, and after a few cycles a substantial fraction of the plant carries a rate that was measured somewhere else, on different metallurgy, in a different service. This is legitimate as an initial estimate and indefensible as a long-term basis. API RP 580 expects the assessment to record which rates are measured and which are estimated, and expects the estimated ones to be replaced as data arrives.
The third is uncredited inspection quality. An examination only reduces uncertainty if it was capable of finding the damage, was performed to a qualified procedure by a certified technician, and covered the location where the mechanism concentrates. Reports that record a method and a result but not the coverage, the surface condition, the calibration or the technician's certification cannot support an effectiveness grade — which is why independent inspection report validation has become a normal step in owner-user RBI programmes before an examination is credited in the next assessment cycle.
Is API RP 580 mandatory?
Not by itself. It is a recommended practice, and it carries no legal force until something invokes it. That happens routinely: API 510, API 570 and API 653 all allow inspection intervals to be established by RBI and point to API RP 580 for what the assessment must contain, and many owner-user mechanical integrity procedures adopt it directly. Once your own procedure names it, an auditor will hold you to it exactly as if it were a code.
What is the difference between API 580 and API 581?
API RP 580 says what a risk-based inspection programme must contain and how it must be governed — mechanisms, data, assumptions, competence, targets, plans, reassessment. API RP 581 supplies one specific quantitative method for producing the numbers, with generic failure frequencies, damage factor tables and consequence models. You can be fully compliant with API 580 using a qualitative matrix and never touch API 581. You cannot use API 581 sensibly without the governance API 580 describes.
Can RBI extend an API 510 vessel inspection interval past 10 years?
API 510 sets the default internal or on-stream inspection interval at the lesser of one-half the remaining corrosion life or ten years, and permits that interval to be established instead by an RBI assessment meeting API RP 580. The extension is not automatic. It has to be supported by identified mechanisms, defensible rates, an inspection history that actually looked for the mechanism, and a documented risk target. The vessel's authorised API inspector remains the inspector of record.
Who is qualified to lead an RBI assessment under API RP 580?
API RP 580 describes a team rather than an individual, and expects competence to be documented. The typical composition is a materials or corrosion engineer who owns the damage mechanisms, an inspector who owns the examination history and its real coverage, a process engineer who owns operating conditions and upset scenarios, an operations representative, and a facilitator who owns the method itself. Where a mechanism is contested, the assessment should record who made the call and on what evidence.
Does API RP 580 require a quantitative risk analysis?
No. It explicitly accommodates qualitative, semi-quantitative and fully quantitative approaches, and it is indifferent to which you choose provided the method is documented, applied consistently, and capable of discriminating between equipment items. The practical failure is not choosing the wrong tier — it is choosing a qualitative method and then treating its output as if it were a calculated number, so that a five-by-five box becomes an acceptance criterion rather than a ranking device.
How often must an RBI assessment be reassessed?
API RP 580 requires reassessment but leaves the maximum interval to the referencing code and the owner-user procedure, so check API 510, API 570 or API 653 for the ceiling that applies to your equipment. Elapsed time is the weakest of the triggers. The ones that matter are a change in feed, operating temperature or pressure, a repair or alteration, discovery of an unexpected damage mechanism, and any inspection result that contradicts the assumed corrosion rate.
Frequently asked
Does API RP 580 replace API 510, 570 or 653?
No. It operates inside them. Those codes remain the inspection codes; API RP 580 supplies an alternative basis for setting some of the intervals within them, and each code states which intervals may be set that way and what ceiling still applies. The authorised inspector, the repair and alteration rules, the rating calculations and the record requirements are all unchanged.
What does API RP 580 say about using a risk matrix?
It permits one and shows an example, commonly a five-by-five arrangement of probability against consequence categories. What it does not do is supply the banding as an acceptance criterion. The matrix is a display and ranking device; the tolerable risk target is a separate, owner-user decision that must be documented before results are judged against it.
Can RBI be used to eliminate an internal inspection entirely?
It can substitute an on-stream examination for an internal one where the referencing code allows and the assessment supports it, but eliminating examination altogether is a different claim. If no credible damage mechanism is active, the assessment must show how that was established, including the process conditions screened and the data relied on. Absence of past findings is not evidence of absence of mechanism.
What documentation does an auditor expect from an RBI programme?
The owner-user procedure that adopts API RP 580, the risk target and who approved it, the team and their recorded competence, per-item mechanism screening referencing API RP 571, the data used with its source and quality, the assumptions and their basis, the resulting inspection plans with method and coverage, the reassessment triggers, and the management-of-change link that keeps it current.
Does API RP 580 cover pressure relief devices?
Owner-users commonly bring relief devices into the RBI scope, and API RP 581 provides a specific methodology for them, but the probability model is different in kind — it concerns failure to open on demand and leakage, not wall loss. Treating a relief valve like a piping circuit in the same study is a recurring error; the mechanism set, the consequence logic and the test interval basis are all distinct.
How does Atlantis support an RBI programme without being the inspector of record?
Atlantis works the NDE side of the assessment: whether the proposed method can detect the mechanism the study names, whether the procedure and personnel qualifications support the effectiveness grade being claimed, whether coverage and CML placement match where the damage concentrates, and whether the resulting records are complete enough to credit in the next cycle. Consultation requests go to info@atlantisndt.com.