Oil & gas
IBM Maximo for oil and gas: integrity, inspection and turnaround
A verification body asks about one safety-critical element and expects the trail in an afternoon. Whether that is a query or a fortnight was decided by a taxonomy call taken years earlier.
Who keeps score
Six scorekeepers, and the evidence each one turns down
A standard body wants comparability and a safety regulator wants demonstrable control. One configuration serves both, with no translation layer between them.
| Ref | Scorekeeper | Asks for | Will not accept |
|---|---|---|---|
| O1 | ISO 14224, the standard that makes reliability data comparable | Consistent equipment class, failure mode and failure mechanism coding, captured where the work is done. | Free-text failure descriptions. A comment field is a story, and stories do not aggregate. |
| O2 | The offshore safety regulator, with an independent competent person running the written scheme of verification | Per safety-critical element: the performance standard, the verification activity, when it was done, what was found, how it was closed. | Evidence reconstructed from general maintenance history. |
| O3 | API RP 580 and 581, adopted by operators and scrutinised by insurers | An inspection plan derived from assessed probability and consequence of failure, with results feeding the next assessment. | A risk-based inspection study sitting in a report while the system still raises the old calendar routine. |
| O4 | The Health and Safety Executive, under the Pressure Systems Safety Regulations 2000 | A written scheme of examination, examinations carried out to it by a competent person, defects acted upon. | An examination recorded without the scheme it satisfies. |
| O5 | API RP 14C, applied to offshore production systems | Protection devices identified against the process components they protect, and maintained. | A device register held apart from the asset hierarchy, so protection and protected are never seen together. |
| O6 | The COMAH competent authority: the HSE with the environmental regulator | Evidence that major accident prevention measures are in place, maintained and tested. | A maintenance backlog on a prevention measure with no risk assessment behind the deferral. |
Codes are stable. O2 and O4 are the rows that decide how a Maximo estate is structured.
In conversation with Jonathan
Jonathan Heward
Head of Account Management · 25+ years in IBM Maximo
Jonathan on the one decision that outlives the programme
- You spent a decade on data standards at BP. What did that settle?
-
That asset data either supports the way the business is run or it gets worked around. A coding scheme that makes a technician harder work at three in the morning is complied with for about six weeks, and then the reliability data you believed you were collecting stops existing. The standard has to be applied where the work is done, in a form the technician can complete honestly.
- Why is ISO 14224 the first decision rather than a later one?
-
Because it is the only part of the configuration that is expensive to change afterwards. Screens, workflows and reports can be revisited. Equipment class, failure mode and mechanism cannot: once two years of work is coded one way, the choice is between rewriting history and living with the split.
- What does a safety case demand of a maintenance system?
-
That the safety-critical element is a structure in the record rather than a label on a report. The verification body asks about a specific element and expects five things back. Modelled properly that is a query; modelled as a report over general maintenance history it is a fortnight of assembly, and what comes out is an argument.
- What will you not promise an operator?
-
Predict on an estate without the failure history to support it. No configuration raises the personnel-on-board limit or improves the weather, so our plans hold both fixed.
Jonathan led ISO 14224, API RP 14C and ISO 15926 alignment across BP's global Maximo estate, then spent sixteen years as a principal Maximo consultant.
One work order
The same pump failure, coded two ways
Illustrative, from what we find where the taxonomy was never set. The left column is complete, tidy and aggregates to nothing.
WO-118432 / asset PU-4021, centrifugal pump
5 of 7 fields changed
| Field | Before | After | Set by |
|---|---|---|---|
| EQUIPMENT_CLASS | PUMP | Centrifugal pump, ISO 14224 class | Taxonomy set at configuration |
| FAILURE_MODE | Free text: tripped again | FTS, fails to start on demand | Technician, from the domain on the work order |
| FAILURE_MECHANISM | Blank | Bearing failure, vibration confirmed | Technician, at the asset |
| DETECTION_METHOD | Blank | Periodic condition monitoring | Defaulted from the job plan |
| MAINTAINABLE_ITEM | Not recorded | Bearing, drive end | Technician, at the asset |
| DOWNTIME_HOURS | 14 | 14 | Unchanged. Operations always recorded this. |
| LABOUR_COST | Recorded | Recorded | Unchanged. Finance always had this. |
Applied to new work from go-live, the taxonomy produces comparable data after one maintenance cycle (O1).
Terms as we use them
Three words the safety case uses precisely
- Safety-critical element
- A part of the installation whose failure would cause or contribute to a major accident, or whose purpose is to prevent one. In Maximo it carries its performance standard, its verification activity and its findings.
- Often read as A criticality rating. A rating sorts a backlog; it does not answer a verification body.
- Written scheme of examination
- The document stating what will be examined on a pressure system, how, at what interval and by whom (O4). The examination is evidence against the scheme, so the scheme is held on the asset.
- Often read as The inspection history. A completed examination with no scheme behind it satisfies nothing.
- Anomaly
- A recorded departure from expected condition, raised at the equipment and linked to the inspection plan that found it and the work that closes it.
- Often read as A finding held in the integrity system, tied to maintenance by a reference number somebody types.
Demonstrated, not described
Four things we demonstrate before an integrity programme is signed off
Run on your own data in a lower environment, with your people watching.
- V1
A safety-critical element evidence pack produced live
- Passes when
- Performance standard, verification activity, date, finding and close-out returned for a named element in one session.
- Witnessed by
- Your technical authority, and the independent competent person where they attend.
- V2
Failure data aggregating across sites
- Passes when
- One equipment class reports failure modes on the same taxonomy from every site, with no manual mapping.
- Witnessed by
- Your reliability engineering lead.
- V3
Risk-based inspection driving the work plan
- Passes when
- A changed assessment moves the next inspection date and technique, and the superseded routine stops being raised.
- Witnessed by
- Your integrity engineer and maintenance planner, together.
- V4
Isolation state readable from one place
- Passes when
- What is isolated, what is being worked on and who is in the field return one answer.
- Witnessed by
- Your offshore installation manager or site authority.
Scope and boundaries
Four disclosures we make before scoping
Each lands better now than in month four.
Historical re-coding is a programme of its own
ISO 14224 on new work from go-live is routine. Re-coding a decade of history recorded by people who have left, on equipment classes named differently at each site, carries its own scope and cost. We quote them separately.
Predict needs a population and a history
Large populations of similar rotating equipment with years of consistent coding are where predictive maintenance pays back. Bespoke high-value assets with thin history take a different route.
Permit and personnel limits set the ceiling
Better planning raises the proportion of planned work that starts on the day. The personnel-on-board limit, simultaneous operations restrictions and the weather window do not move.
The verification body reaches its own verdict
We make the safety-critical element trail complete and quick to produce. Whether the independent competent person accepts the state of your assurance is settled between you and them.
Maximo for oil and gas, frequently asked questions
- Can Maximo take integrity scope off SAP PM?
- Often. Where SAP PM has been stretched to cover inspection, integrity and rotating-equipment maintenance, moving that scope to Maximo brings integrity engineers and maintenance planners onto one record, usually with SAP retained as the finance and procurement spine.
- How does Maximo support permit-to-work and isolation management?
- Either through integration with a dedicated permit system or through Maximo-native configuration. We design for one answer to what is isolated, what is being worked on and who is in the field. The boundary patterns are on Maximo integrations.
- Do you support offshore and remote operations?
- Yes. IBM Maximo Mobile works in low-bandwidth and intermittently connected conditions, and we design planning around the permit meeting that gates every shift. See Maximo Mobile.
- What is the honest prerequisite for predictive maintenance upstream?
- A large enough population of similar rotating equipment, and years of failure history coded consistently. Estates with disciplined ISO 14224 coding produce models reliability engineers trust; estates without it need the coding work first. We say which one you are before anything is scoped.
Bring one equipment class and one verification finding.
The equipment class tells us whether your failure data is comparable. The finding tells us how long your evidence chain takes to assemble.
Bring this to the first call
- The failure history for one equipment class, exactly as coded today
- One safety-critical element and the evidence pack you last produced for it
- The scope document from your last turnaround, with growth work identified
- The systems that currently hold part of the integrity record