The next article of the MI series focuses on piping systems.
Piping systems act as the lifelines of an industrial facility, enabling the continuous movement of hydrocarbons, chemicals, steam and utilities between units. Their extensive and interconnected nature means they operate across diverse conditions, often spanning large areas and multiple process environments.
While individual piping failures may be localised, they frequently represent one of the most common sources of loss events that appear across industrial facilities. Due to the sheer length, complexity and variability of service conditions, piping systems are inherently more vulnerable to degradation.
Failures in piping systems are often:
- Frequently compared to static equipment
- Difficult to predict without structured inspection programs
- Capable of triggering fires, explosions or unit-wide shutdowns
From an insurance perspective, piping failures are a major contributor to both attritional losses and, in some cases, large loss events when escalation occurs.
Why piping integrity requires special attention
Piping presents unique integrity challenges:
- Large total asset footprint (kilometres of piping vs discrete pressure vessels)
- Multiple damage mechanisms acting simultaneously
- High number of fittings, welds, branches and small-bore connections
- Exposure to external conditions (corrosion under insulation, marine environments, vibration)
- Frequent modifications and tie-ins over the asset lifecycle
Unlike pressure vessels, where inspection scope is often more clearly defined, piping systems require a structured approach involving corrosion circuit identification, risk-based prioritisation and ongoing integrity management to effectively control risk.
A practical self-check: Is your piping integrity program truly robust?
1. Is your piping program built around circuits and damage mechanisms?
Effective piping inspection starts with proper "circuitization" (organising groups or circuits of piping that share similar operating conditions, process parameters and levels of risk) and identification of credible damage mechanisms. Without this, inspection becomes reactive and inefficient.
Ask yourself:
- Are piping circuits clearly defined based on process conditions and materials?
- Are damage mechanisms identified for each circuit (e.g., corrosion, erosion, cracking)?
- Are relevant inspection techniques used to target the expected damage mechanism?
- Are the monitoring locations strategically selected by a specialist/authorised representative?
2. Are you managing dead legs, small-bore connections (SBCs) and low-flow areas effectively?
Dead legs are one of the most common sources of accelerated corrosion due to stagnant conditions. These areas are often overlooked or underestimated.
Ask yourself:
- Have all dead legs and SBCs been identified, categorised, risk-ranked and documented?
- Are inspection frequencies higher for dead legs compared to active lines?
- Are dead legs minimized or eliminated where possible?
- Are vibration-prone areas assessed and monitored?

3. Are changes/modifications integrated within Management of Change (MoC)?
Changes will happen during the life of an asset, and new risks will be introduced if they aren't managed effectively.
Ask yourself:
- Are changes to metallurgy managed through a MoC? Has a material selection study been performed? (e.g., change of Stainless Steel 316 to SS304 reduces resistance to chloride stress corrosion cracking).
- Are changes to process conditions performed through a MoC? (e.g. changes in feedstock).
4. Are you addressing Corrosion Under Insulation (CUI) proactively?
CUI remains one of the leading causes of unexpected piping failures, particularly in carbon steel systems operating between −4°C and 175°C.
Ask yourself:
- Is there a defined CUI risk-based inspection program?
- Are susceptible temperature ranges and insulation types identified?
- Are screening techniques (e.g., visual, thermography, radiography) used effectively?

5. Are inspection deferrals and overdue items tightly controlled?
Given the extent of piping systems, deferrals can be a relatively common occurrence, and if not controlled, they can significantly increase risk exposure.
Ask yourself:
- Are all deferrals approved before the inspection due date?
- Are they reviewed and authorised by competent personnel?
- Does the deferral include an assessment of risks?
- Does the deferral require a review of the inspection history?
What industry losses continue to show
Piping failures often follow a similar pattern:
- Localized degradation develops in a specific area
- Standard inspection coverage doesn't identify this
- Failure occurs suddenly, often during normal operation
Chevron Richmond refinery accident (2012)
The Chevron Richmond refinery incident occurred on August 6, 2012, when a section of piping carrying hot gas oil in the crude distillation unit ruptured due to severe thinning caused by high-temperature sulfidation corrosion. This led to the release of flammable vapor, which ignited, causing a significant fire. The incident resulted in a large cloud of smoke that affected nearby communities, with approximately 15,000 people seeking medical treatment for respiratory issues and other health problems.
Key findings
The root cause of the incident was identified as the failure of a carbon steel pipe with low silicon content, which had corroded at an accelerated rate. The corrosion wasn't adequately detected due to insufficient monitoring and inspection practices.
This directly reinforces the first self-check question: Is your piping program built around circuits and damage mechanisms?
These failures reinforce a key principle: Integrity risk in piping can be highly localised, not uniform.
Final thoughts
Piping systems represent one of the most extensive and failure-prone asset classes in industrial facilities. While individual failures may appear minor, they are a leading driver of fires, leaks and unplanned shutdowns.
Across higher-performing sites, we typically observe:
- Clearly defined circuits aligned with process conditions
- Explicit linkage between damage mechanisms and inspection methods
- Focus on high-risk areas such as dead legs, SBCs and injection/mixing points
- Changes are managed through a robust MoC process
- Strong control over inspection deferrals and backlog
Our next article explores how inadequate risk management of storage tanks can result in high-consequence incidents.
Gallagher is the third largest broker in the world and is committed to supporting risk management best practice across the Energy Industry. For more information about our in-house risk engineering and risk advisory services and how we can support you, please reach out to our team.