Why RBI Programmes Drift, and How to Tell Early
By Yuki Nakamura, PhD, P.Eng · 16 July 2026
An RBI programme almost never announces its own failure. It degrades, and the degradation is invisible from the ranking output — the dashboard still produces a ranked list, the intervals still get set, and the audit still passes. What changes is that the ranking gradually stops reflecting the actual condition of the plant.
The mechanism of drift
Probability of failure in API 581 is driven by corrosion rate. When measured rates are available for a circuit, the model reflects reality. When they are not, a default rate is substituted — legitimately, and usually with a note. The drift occurs because those substitutions accumulate silently: a CML that could not be accessed during one turnaround, a reading discarded as an outlier and never repeated, a circuit re-drawn so its history no longer joins up.
Five years later a meaningful share of the model runs on defaults, and defaults are by construction insensitive to what is actually happening in that circuit. The ranking then encodes assumptions rather than condition, which is the precise opposite of the reason RBI was adopted.
Six early indicators
- Rising proportion of circuits on default corrosion rates. Track it as a metric. If nobody knows the number, it is higher than anyone thinks.
- CML counts that change between campaigns without a documented reason. New locations appearing near old ones usually means the previous ones could not be found.
- Thickness readings with no instrument or technician attribution. An outlier you cannot investigate is an outlier you will eventually discard, and discarding data is how a time series becomes two points.
- Damage-mechanism assignments that have not been revisited after a feedstock or operating change. The mechanism drives the inspection technique; if the service changed and the assignment did not, the inspection is now looking for the wrong thing.
- Intervals extended more often than they are shortened. A model that only ever produces relief is not modelling.
- No record of integrity operating window excursions against the assessments that assumed them. The assessment presumed an envelope; nobody is checking whether operation stayed inside it.
What it costs
Two ways, in opposite directions. Under-inspection of a genuinely degrading circuit is the obvious one and the one everyone plans for. The quieter cost is over-inspection: circuits that have been demonstrably stable for a decade continue to consume turnaround scope because the model, running on defaults, cannot tell that they are stable. In most refineries the second cost is larger and is never attributed to the RBI programme at all.
The fix is upstream of the model
None of this is solved by better RBI software, because the defect is in the condition data feeding it. The corrective actions are unglamorous: reconcile the corrosion monitoring location register and stop reusing identifiers; capture instrument, technician and procedure provenance with every reading so outliers can be investigated rather than discarded; and re-run assessments when new data arrives instead of inheriting the previous interval by default.
Platforms built outward from the inspection data rather than from a maintenance or historian system handle this natively — asset integrity management software that computes RBI from measured thickness trends per CML rather than from tabulated defaults removes the substitution problem at source. The wider point stands regardless of vendor: a programme is only as defensible as the provenance of the readings underneath it.
A one-hour diagnostic
Pick three circuits. For each, try to produce the full thickness history at CML resolution, the instrument and technician behind each reading, the procedure revision in force, and the damage-mechanism assignment with its rationale. Whatever you cannot produce in an hour is the actual state of your programme — and it is considerably more informative than the ranking report.
Where the field-side capture is the gap rather than the modelling, the practical starting point is inspection management software that binds qualification, calibration and procedure revision to each record as it is created. Reconstructing that evidence afterwards is possible but expensive, and it is never complete.