How do fitness-for-service assessment and integrity management differ?
Fitness-for-service assessment answers a question about one flaw at one moment, while integrity management answers a program question about which threats apply to an asset, what inspection addresses each, how often, and what response is triggered by a finding. Fitness-for-service assessment asks, given the flaw’s size, the material and the stress, whether continued operation is acceptable and on what basis.
A rupture usually implicates both fitness-for-service assessment and integrity management. The flaw that failed was either never found, found and assessed as acceptable, or found and not acted on, and each of those routes leads to a different set of documents.
How is the API 579-1/ASME FFS-1 fitness-for-service standard structured?
API 579-1/ASME FFS-1 organizes fitness-for-service assessment into tiers of increasing rigor, from conservative screening rules through more detailed analysis to numerical modeling, with separate parts for general and local metal loss, pitting, crack-like flaws, creep, fire damage and other damage classes.
The tiered structure of API 579-1/ASME FFS-1 matters forensically because it records the level of analysis actually performed. A screening-level acceptance and a detailed crack-like flaw assessment carry very different assumptions, and the inputs used at the chosen level are recoverable and checkable.
How is a fitness-for-service assessment run backward after a rupture?
After a rupture, a fitness-for-service assessment is run backward by using measured flaw dimensions from the fracture surface, toughness from Charpy or CTOD testing of the failed material, and stress from the reconstructed operating pressure to produce a critical flaw size, which can then be compared against what the flaw measured at each earlier inspection. In this way, the same fitness-for-service methodology used prospectively to justify continued service is used after the fact to explain why the flaw did not survive.
Running the fitness-for-service assessment backward is where an inspection history becomes analytically useful rather than merely suggestive. It converts the inspection record from a list of dates into a growth history.
How do detection threshold, sizing tolerance and probability of detection limit what an inspection can find?
An inspection tool is not a measuring device with unlimited resolution: every inspection method has a detection threshold, a sizing tolerance, a stated confidence level and a coverage limit, and in-line inspection performance is qualified against those declared specifications under API 1163.
The forensic comparison after a rupture is therefore not simply whether the flaw appeared in the inspection report. It is whether a flaw of that type, orientation and size at that location was within the capability of the inspection tool that was run, at the confidence the vendor specified, on the coverage that was actually achieved.
Why is the choice of inspection tool itself a finding?
The choice of inspection tool is itself a finding because metal-loss tools and crack-detection tools address different threats, and an inspection program that ran only one of them has answered only one question. A line inspected repeatedly and competently for wall loss may have no meaningful record at all regarding axial cracking.
Where the failure mechanism is one the selected inspection tools were not designed to find, the issue moves upstream to the threat assessment that chose those tools.
How short does a reassessment interval need to be relative to flaw growth?
A reassessment interval is defensible only if it is short relative to how fast the flaw grows. For gas transmission, ASME B31.8S sets out the integrity management approach and the basis for reassessment intervals, and the federal integrity management requirements in 49 CFR Part 192 and Part 195 impose their own timing obligations for covered segments.
Comparing the reassessment interval that was used against the growth rate derived from the failed flaw is often the single most probative calculation in a rupture case, and it is one the operator’s own data usually supports or undermines without outside assumption.
How do pressure limits and the operating record bear on a rupture?
Pressure limits and the operating record bear on a rupture in two ways: the record supporting maximum allowable operating pressure and maximum operating pressure can be as contested as the metallurgy, and cyclic severity matters as much as peak pressure. Maximum allowable operating pressure and maximum operating pressure are established from design, testing and regulatory history. Where establishment of those pressure limits relied on records that no longer exist or on a pressure test whose documentation is incomplete, that is an issue independent of the failure mechanism.
A line operating well within its pressure limit but cycling aggressively can drive fatigue growth that a static assessment never contemplated.
Which inspection codes govern pressure vessels, process piping and storage tanks?
Fixed equipment runs on its own inspection codes: API 510 for pressure vessels, API 570 for in-service piping and API 653 for aboveground storage tanks, each prescribing inspection types, interval-setting rules and the treatment of findings, often informed by risk-based inspection methodology.
API 510, API 570 and API 653 inspections generate dated, signed documents with named findings and recommendations. Whether a recommendation was closed, deferred or left open is frequently more decisive than the condition it described.
Does a clean prior inspection prove the flaw was not there?
A prior inspection reporting nothing reportable is not proof the flaw was absent. It establishes that nothing exceeding the reporting threshold was detected by that inspection tool, on that coverage, at that time. Whether the flaw was below threshold, outside coverage, or of a type the inspection method could not see are separate questions with separate answers.
Opinions on whether inspection should have found a flaw are challenged on exactly that gap. Work that states the tool specification, the coverage achieved, the reporting threshold, the growth rate assumed and its source will hold where a bare assertion that the flaw was or was not detectable will not.
This article is general technical orientation, not a failure analysis, an engineering opinion, or advice on any specific matter. Determining the cause of a particular incident requires hands-on examination by a credentialed expert.