Process Safety · Lesson 7 · 7 min read
Normal Operation Does Not Prove Mechanical Integrity

Stable readings and an absence of visible leakage cannot confirm that pressure equipment, piping and protective devices remain fit for service. Learn why inspection evidence, defect control and disciplined escalation are essential barriers against loss of containment.
A quiet plant can still contain an active degradation mechanism
Mechanical integrity is the continuing assurance that equipment which contains, controls or protects a hazardous process remains suitable for its intended service. Offshore, that assurance includes pressure vessels, storage systems, piping, relief and vent systems, emergency shutdown equipment, controls, pumps and other critical items. It is built through correct design, fabrication, installation, inspection, testing, preventive maintenance and competent defect management—not through the absence of an alarm or leak.
Normal pressure, temperature and flow indicate how the process is behaving at that moment. They do not directly reveal local wall loss beneath insulation, internal erosion, fatigue cracking, a weakened small-bore connection, a relief device that will not operate on demand or deterioration hidden inside equipment. Stable production is therefore operational information, not proof of equipment condition.
Inspection evidence must remain connected to the actual service
OSHA's Process Safety Management standard requires written procedures to maintain the ongoing integrity of process equipment. It calls for inspection and testing to follow recognised and generally accepted good engineering practices, with frequency based on manufacturers' recommendations and good engineering practice—and more often where prior operating experience indicates. The standard also requires documentation of inspections and tests, including the results.
That framework highlights an important operational principle: an inspection interval is not merely a date on a schedule. Its adequacy depends on the degradation mechanisms, materials, process chemistry, operating history and consequences associated with the equipment. If service conditions change, corrosion or erosion accelerates, monitoring becomes unreliable, or new damage is discovered, the integrity basis may need competent reassessment through the site's approved process.
Hypothetical example: a thinning indication on a process line
Consider a hypothetical offshore inspection campaign that identifies a local thinning indication on a hydrocarbon line. The line is not leaking, control-room trends remain normal and the next production activity is commercially important. Someone suggests continuing operation because the measured point has not yet produced any visible symptom.
This is an illustrative scenario, not a documented incident. No numerical acceptance criterion or remaining-life judgment is implied. The correct decision depends on verified measurements, the applicable code and design basis, the credible damage mechanism, uncertainty, operating conditions and assessment by authorised competent personnel.
The disciplined response is to record and protect the finding, confirm its location and quality, apply the approved fitness-for-service or defect-assessment process, define any operating restrictions and escalation requirements, and ensure the resulting actions are tracked to closure. Production stability cannot close an integrity question.
Deferral is a risk decision, not an administrative convenience
Inspection, testing or maintenance that becomes overdue creates uncertainty about a barrier's condition. Any proposed deferral should follow the installation's authorised process and be supported by a competent technical basis, current equipment condition, credible failure modes, interim monitoring, defined operating limits, an accountable owner and a firm completion date. A new date in a register does not by itself control degradation.
Repeated deferrals deserve additional scrutiny because assumptions may become stale while the physical condition continues to change. Teams should also examine linked barriers. If a relief device is awaiting test, a corrosion monitor is unavailable or a shutdown valve is degraded, another impairment may reduce the remaining protection. The combined risk must be understood rather than treating each item as an isolated work order.
Repair the defect—and the system that allowed it to persist
OSHA requires equipment deficiencies outside acceptable limits to be corrected before further use or in a safe and timely manner when other necessary steps are taken to assure safe operation. The exact decision and controls are site-specific, but the principle is clear: a known deficiency needs an authorised disposition. Informal observation, operator vigilance or familiarity with a long-standing defect is not an engineering resolution.
A repair should address more than the visible damage. Ask why the degradation developed, whether similar equipment shares the same mechanism, whether inspection locations and intervals remain suitable, and whether process conditions have moved away from the assumptions used in the integrity programme. Update drawings, registers, inspection plans, operating guidance and handover information where required. If a temporary repair is used, control it through approved engineering, management-of-change and monitoring arrangements.
Operations is an essential source of integrity information
Inspectors and engineers provide specialist assessment, but operators often see the earliest weak signals: unusual vibration, changing pump performance, recurrent seal leakage, staining, damaged insulation, abnormal temperature, unstable control or a new sound. These observations should enter the approved defect-reporting system with enough detail to support evaluation. A small anomaly may be the visible part of a wider degradation mechanism.
Handovers should identify significant equipment defects, overdue or deferred work, temporary repairs, unavailable monitoring and operating restrictions. The incoming team should understand what is known, what remains uncertain, who owns the action and which change in condition requires escalation or shutdown. Mechanical integrity weakens when important knowledge remains in one person's memory.
Three practical actions for today's shift
First, select one safety-critical item with an open integrity concern and confirm the approved disposition, responsible owner, monitoring requirements, due date and operating restrictions. Second, report any new leak, vibration, corrosion indication, damaged support or other abnormal condition through the authorised defect process; do not wait for it to become an alarm. Third, review overdue work and temporary repairs at handover, and escalate any case whose technical basis, validity or field condition cannot be confirmed.
Discussion question: Which item on our installation appears healthy mainly because it is still operating—and what current inspection or test evidence actually demonstrates its integrity?
This article provides general process-safety learning. Inspection methods, acceptance criteria, fitness-for-service decisions, repairs, deferrals and operating restrictions must follow the installation's approved procedures, engineering standards and escalation process.
Sources
- OSHA — 29 CFR 1910.119(j): Mechanical integrityPublished Accessed 19 September 2026
- UK HSE — Maintenance of work equipmentPublished Accessed 19 September 2026
Daily HSSE updates
Subscribe for practical HSSE updates.
Subscribe for the daily message, selected HSSE news and occasional new-resource alerts from Worksite Safety Hub.