Oil and gas, Predict
A prediction on a safety-critical pump, and the person who is allowed to act on it
Upstream holds deep failure history and written accountability for acting on it. This page walks IBM Maximo Predict through the three gates that decide whether a model earns its place, and what it is permitted to write on a safety-critical element. The general capability sits on our Predict page, and the sector on Maximo for oil and gas.
Prerequisites
What standing Predict up on an upstream estate requires
Failure history
- Taxonomy
- ISO 14224 coding on the candidate class, comparable across platforms and years
- First test
- A sampled year of coded failures, read as an engineer would read it
- When coding is thin
- ISO 14224 alignment is the first phase, scoped and priced on its own
- Signal sources
- Historian and condition monitoring on the class, typically after Monitor
The two registers
- Safety-critical elements
- Performance standards and a written scheme of verification under the accepted safety case
- Production-critical only
- Maintenance criticality for planning; handled on a separate route from SCE output
- Standards beside it
- API RP 14C for the SCE analysis; API 580 and 581 for RBI on fixed equipment
- Regulator frame
- UKCS duty holders under the Offshore Safety Directive Regulator (HSE and OPRED)
The run state
- Output route
- Reliability engineer first; technical authority on every SCE
- What the model may add
- Inspection or condition work inside the existing routine
- What stays fixed
- Verification intervals, performance standards and examination scope
- Platform
- MAS on Red Hat OpenShift, run as MaxIron-managed hosting
Unit counts and durations for a first class are set in scoping against your coding sample.
The gates
Three gates before a prediction may change the plan
Each gate has a named signer. On several estates the right outcome of the first gate has been a coding programme and no model that year.
-
Gate 1 Coding readiness
Signed by Your reliability lead
Passes
A class whose failure codes carry a signal a reliability engineer recognises as the fault, not the shift pattern.
Held back
A class where the nearest available code is the habit. Alignment runs first; the model waits.
-
Gate 2 Register separation
Signed by Your asset integrity lead
Passes
Candidate assets labelled SCE or production-critical before scoping, with different output routes from that point.
Held back
A single criticality list used for both planning and the safety case. The registers stay apart.
-
Gate 3 Technical authority on an SCE
Signed by The named technical authority
Passes
Additional functional or condition work inside the existing routine, with the model version and features cited on the job card.
Held back
Any change to a verification interval, performance standard or examination scope. Those stay with the safety case.
The worked scene
One fire water pump, and five things written
Fire water pumps test the design: a population a model can learn from, and a safety-critical element nobody may quietly reschedule. Illustrative composite of patterns on upstream estates.
-
Signal
Across the diesel-driven fire water pumps, one unit sits above the population for failure inside the next maintenance window: start reliability drift, cranking away from peers, two coded failures on the same sub-unit inside a year.
Written Predict score and feature set against the pump asset, with model version.
-
Engineer
The reliability engineer reads the features, checks the two coded failures against the job cards, and confirms the same fault rather than a coding duplicate.
Written Judgement on the prediction record: signal accepted, with the job-card check cited.
-
Authority
The technical authority holds the decision because the pump is a safety-critical element. He adds a functional test and a condition check inside the existing routine.
Written Decision record naming the authority, the added scope, and the model output as the reason.
-
Manage
Work is raised against that pump as additional scope, tagged to the SCE, carrying the model version and the features cited.
Written Work order on the asset. Nothing existing is deferred, shortened or removed.
-
Scheme
The independent competent person examines to the same written scheme on the same schedule. The extra work is evidence available to that examination.
Written Verification scheme untouched. Examination interval unchanged.
Predict proposes an asset. A reliability engineer judges it. On a safety-critical element the technical authority decides, and Maximo records which of them did what.
Boundaries
Three boundaries on Predict in an upstream estate
Each one changes what a first phase should contain, so each is stated before scoping.
Performance standards and verification stay with the safety case
They are set through that process and examined independently. Predict adds work and evidence; every route we build keeps examinations, intervals and scopes where the safety case put them.
The model learns from the failure coding you hold
Where history on a class is thin or inconsistently coded, ISO 14224 alignment is the first phase. Predict follows once the coding carries a signal. The programme we ran for a North Sea operator is in the ISO 14224 and API RP 14C standards case study.
Single bespoke machines belong on a condition-monitoring route
One high-value unit with no population and no comparable history is served by condition monitoring, vendor engineering and human judgement. We name those classes before any licence conversation.
IBM Maximo Predict for upstream oil and gas, questions we are asked first
- Is upstream oil and gas a credible candidate for IBM Maximo Predict?
- For specific asset classes, yes. Large populations of rotating equipment with years of ISO 14224-coded failure history, where unplanned failure is expensive and safety-critical, are the conditions Predict pays back on. Bespoke high-value assets with thin history are called out before scoping.
- Does Predict change our written scheme of verification?
- No part of our delivery is designed to. Predict output can justify additional condition or functional work and becomes evidence for the independent examination. Any change to the scheme itself runs through the safety case process and the duty holder’s technical authority.
- What about ISO 14224 failure-coding discipline?
- It is the strongest determinant of whether a model is worth building. Estates without disciplined coding usually need a cleanup before the model build is funded. We have led ISO 14224 alignment on operator estates and approach the readiness assessment from that work.
- Do we need Monitor in place first?
- For most upstream rotating equipment, yes. Vibration, pressure and temperature signal materially improves the model. The natural sequence is Monitor on the class, then Predict, argued in sequencing Monitor and Predict after Manage.
Where this sits
Read next
- Capability IBM Maximo Predict, how we deliver it
The model lifecycle, validation against belief, and the route from score to work order.
- Capability IBM Maximo Monitor
The usual prerequisite on rotating equipment before Predict pays back.
- Capability IBM Maximo Health
Integrity-critical fixed assets beside Predict on rotating classes.
-
Why programmes stall at the first gate on this page.
- Case study ISO 14224 and API RP 14C standards programme
Where the coding discipline on this page was built inside Maximo.
Bring one asset class and a year of its failure history.
We read the coding the way a model would read it and say what it would learn. If that answer is coding habit rather than failure mode, you hear it on the first call.
Bring this to the first call
- The asset class you have in mind, and roughly how many units you run
- A year of coded failure history for that class, however untidy
- Whether any of those units are safety-critical elements, and who the technical authority is
- What an unplanned failure on one of them costs in production deferral or HSE exposure