IOW and the technological card
≈ 25 min read · 5,006 words
A car’s rev counter has three ranges, even though only one needle moves across it. There is an economical band where the engine carries the car on the least fuel. There is a range where you can drive smoothly, but if you keep it there for long, the machine ages faster. And there is the red zone, where something can be destroyed within minutes. A process plant works exactly like this, only there it is not one needle but several hundred: temperature, pressure, flow, hydrogen partial pressure. The technical name of that “red zone” is the Integrity Operating Window (IOW), and the document listing the parameters and their limits is the technological card. Let’s look at what the two concepts mean in practice, how the limits are set, and what happens if a parameter does slip out anyway.
The Integrity Operating Window (IOW) is the upper and lower limit of the process parameters whose exceedance endangers the integrity of the equipment.
The parameters and their limits are recorded by the technological card in the process documentation; the IOW is the integrity-critical part of that card, covering the most hazardous process points (corrosion, high temperature hydrogen attack and similar damage mechanisms). If the plant stays within the established limits, degradation is predictable and reasonably low, which improves reliability. A limit is complete only when a predefined action and response time go with it.
Figure 1 — the three limit levels for one parameter: the optimal band, where energy consumption is lower and product yield is better; the standard (technological card) level, where the product is still within specification; and the critical (IOW) limit, whose crossing can lead to rapid failure of the equipment.
Who is this for?
Section titled “Who is this for?”This article is for those whose daily work touches operational limits: operator · shift supervisor and plant manager · process engineer · inspector · corrosion specialist · reliability engineer · process safety (PSM) specialist · asset team leader. Keeping to the limit is in the hands of those working in the shift; setting the limit, maintaining it and investigating an exceedance belong to the engineering and management roles.
Learning objectives
Section titled “Learning objectives”After reading this article you will be able to:
- distinguish the operational limit, the technological card and the IOW
- explain the meaning of the three limit levels (optimal, standard, critical) and the duty to act that goes with each
- contrast the operating envelope and the integrity window on the basis of their focus
- walk through the IOW-setting process according to API RP 584 and name the roles on the team
- describe what happens on a sustained deviation: alarm, log entry, investigation, MOC
- draw the line where the IOW does NOT replace a certified safety function
What are the Integrity Operating Window (IOW) and the technological card?
Section titled “What are the Integrity Operating Window (IOW) and the technological card?”Operational limits are the ranges of process variables within which the operator must control the process to achieve the desired result: product specification, safe and reliable operation, low corrosion rate. The limits are set by experts: the licensor, the equipment manufacturer and the local engineers. The technological card is the part of the process documentation that describes these parameters and their limits. The IOW is the integrity-critical intersection of the card: it sets limits on those parameters that affect the integrity of the equipment if the plant deviates from them for a predetermined amount of time.
The three concepts are therefore nested: the operational limit is the general category, the technological card is the document, and the IOW is the part of the card that protects the service life of the equipment.
The technological card is not a separate world: the process operating instruction must in any case contain the range, the maximum and the minimum values of the parameters of normal operation, and typically it is the technological card that carries them. The basic condition of process control is that the technical documents (process operating instruction, technological card, P&ID, PFD) are available and up to date; the plant process engineer assigned to the asset team is accountable for this.
In brief
Section titled “In brief”- Operational limit: the range of the parameter within which you must operate (product, safety, low corrosion). Set by experts: licensor, manufacturer, local engineer.
- Technological card: the part of the process documentation that describes the parameters and their operational limits.
- IOW: the limits of the integrity-critical parameters (corrosion, HTHA, temperature) that protect the integrity of the equipment. The relevant standard is API RP 584.
- Three levels on the card: optimal (more favourable energy and yield), standard (safe operation to specification), critical or IOW (rapid failure, immediate action).
- Limit = parameter + action + response time: the bare number does not protect; a predefined intervention and response time belong to every limit.
- Deviation monitoring: the plant information system watches the limits, and on a sustained deviation it automatically raises an alarm and creates an entry in the electronic log.
- MOC is mandatory: the IOW includes management of change, so that the integrity impact of every process or hardware modification is identified.
- Cross-functional ownership: the IOW is built and maintained jointly by inspection, the corrosion specialist, operations, the process engineer, the reliability engineer and the asset leader, with a facilitator.
Why it matters (the stakes)
Section titled “Why it matters (the stakes)”The business logic of the IOW answers three questions. Why do we do it? So that we can exploit market volatility. How? By staying flexible in production. What do we do for that? We understand how changing process variables affect the physical assets, and we prevent unexpected or rapid degradation. The price of flexibility is precisely that the equipment sees operating states it was not originally designed for.
The benefit side is correspondingly fourfold: enforcing mechanical integrity, improving availability, driving maintenance to be more effective, and reducing non-value-adding activities. If we know how far a parameter may go and for how long, then the deterioration of the equipment becomes calculable and unexpected failure becomes preventable.
The stakes are not theoretical. In a publicly investigated plant accident in 2010 a heat exchanger in hydrogen service exploded, causing the death of seven people; the root cause was high temperature hydrogen attack (HTHA). This kind of damage mechanism works slowly and silently, and that is exactly why it needs a limit that has been set in advance and is monitored.
What does each level mean, and when is action mandatory?
Section titled “What does each level mean, and when is action mandatory?”The limit card brings together those more important operating and laboratory parameters of the plant that affect its optimal, trouble-free running and the long-term preservation of the condition of the equipment. It distinguishes three levels:
| Level | What does it mean? | Consequence of exceeding it | Mandatory action |
|---|---|---|---|
| Optimal | within this operating range lower energy consumption and/or better product yield can be achieved | the economic optimum is missed | no action prescribed |
| Standard (technological card) | safe operation, the products meet the specification; for laboratory parameters the limits are identical with those set in the process operating instruction | product quality may slip out of specification; for operating parameters a process upset, and in the long run equipment failure | action required |
| Critical (IOW) | the boundary of integrity | rapid failure of the equipment | immediate action required |
It matters what the green band does not mean: degradation goes on there too. Operating within the established limits does not stop the damage, it only makes it predictable and reasonably low. This difference is the whole point of the IOW: it does not abolish wear, it makes it plannable.
Operating envelope or integrity window? (separating the two frames)
Section titled “Operating envelope or integrity window? (separating the two frames)”The two concepts are related but not the same, and mixing them up is a typical mistake. The operating envelope is the envelope of performance, the IOW is that of integrity:
| Aspect | Operating Envelope | Integrity Operating Window (IOW) |
|---|---|---|
| Focus | conversion, yield, energy, quality | damage mechanisms |
| What it watches | performance indicators | chemical and physical parameters |
| Typical question | is the plant running well and economically? | will the equipment stay intact? |
In practical implementation the two can meet on the same surface: the parameters and limits of the technological card appear visualized in the plant information system, so that a deviation is visible at a glance. The underlying logic nevertheless stays twofold, and when the limits are set the two aspects have to be thought through separately.
Within this, API RP 584 distinguishes three types of IOW: informational, standard and critical. This typology belongs to the standard, and it is not to be confused with the local, three-level limit card above (optimal / standard / critical): the two are separate frames that happen to use similar words.
How are IOW limits established? (the API RP 584 process)
Section titled “How are IOW limits established? (the API RP 584 process)”IOW limits are not born from estimation but from an eight-step process closed by a decision gate. The logic: first we understand what damages the equipment, and only then do we draw a number.
Figure 2 — the eight steps of the IOW process according to API RP 584 and the built-in decision gate.
- Define the design and the prior operating conditions.
- Define the operating conditions and premises belonging to the IOW limits.
- Identify the potential and active damage mechanisms (DM).
- List all process parameters that can affect each damage mechanism.
- Set or adjust the upper and lower limits so that unacceptable damage can be avoided.
- Risk rank each and every limit.
- Check at the gate: do the limits and the risk fit within the premises? If not, back to rethinking the premises.
- Determine the type of IOW, then define the action and the response time for the case of an exceedance.
The process needs inputs: the list of business critical and process safety critical equipment, the design and operating parameters, the corrosion loop and material diagram, the PFDs and P&IDs, the company risk matrix, the catalogue of damage mechanisms (API RP 571), the risk-based inspection toolkit (API RP 580 and 581), and the IOW standard itself (API RP 584). Two decisions have to be made in advance: which future operating conditions we are preparing for (for example an alternative crude), and how much future run time we expect from the equipment.
How can it be introduced? (team, scope, deliverables)
Section titled “How can it be introduced? (team, scope, deliverables)”An IOW program is not the task of one engineer and not the work of one quarter. In its first phase it covers the process safety critical pressurised equipment of business critical production units, and in its second phase all further such equipment. The method is API RP 584, the time requirement is of the order of three to four years, and the responsibility is shared between inspection, process technology, and the process information and automation organization.
The composition of the IOW team (the roles are needed for creating, implementing, monitoring and maintaining it):
- corrosion specialist: brings the material and corrosion degradation information;
- unit process engineer: the process design and engineering data;
- inspector: the inspection data, and aligns the inspection plan to it;
- experienced operations representative: the current operating practice;
- maintenance or reliability engineer: ad hoc, the failure history;
- licensor technology specialist and process chemical treatment vendor: ad hoc, where the technology or the chemical treatment warrants it;
- facilitator: someone knowledgeable in the IOW work process itself, who carries the team through it;
- asset team leader: accountable for making sure the process is properly staffed with experienced experts and closes on time.
What has to be put on the table at the end of the work: (1) the parameters defined and the limits set; (2) the list of developments required to measure the critical parameters and indicate them on the DCS; (3) the actions and response times in case of deviations; (4) the reporting scheme of deviations. The objective of the program is accordingly not the number of limits but the coverage: for every process parameter defined on the technological cards it must be prescribed what is to be done when the limit is exceeded, and the same applies to the parameters defined through the IOW.
The second deliverable is the one most often forgotten: if a critical parameter is not measured, or does not appear on the operator’s screen, the limit belonging to it stays on paper. IOW work therefore always produces an instrumentation and display development list as well.
What happens if a parameter drifts out?
Section titled “What happens if a parameter drifts out?”The card in itself is a static document. The value is delivered by deviation monitoring: the plant information system gathers the relevant process data and the plant status, computes dynamic limits, and passes the result on to the electronic log system. From there the escalation ladder starts, whose thresholds are site- and procedure-specific settings, not universal rules.
Figure 3 — the chain of deviation monitoring and the escalation ladder: alarm, automatic log entry, then mandatory investigation.
- Alarm (typically on a deviation lasting beyond 24 hours): the system sends an alarm message to the log, which creates an entry, and notifies the process engineers and the members of the shift by e-mail.
- Automatic entry (in another established practice, on a deviation exceeding 72 hours): the system automatically creates an entry in the electronic shift log, where the plant staff have to describe briefly the cause of the deviation.
- Mandatory investigation (typically on a deviation persisting for at least 7 days): the investigation is carried out jointly by plant process technology and the process operations manager of the plant, involving as needed process safety, production and energy management, reliability engineering, operational maintenance and business excellence. The result of the investigation and the corrective proposals have to be recorded in the corporate event register, and the owner of the event approves them.
- Periodic review: a quarterly report to the business team on how often and why there were deviations from the cards (with reference to the shift log entries), how they were eliminated, and further on the interlock overrides (among them those beyond 24 hours) and on the trend of corrosion monitoring and of the IOW parameters.
It is wired into the shift routine as well: a mandatory agenda item of the shift handover and the shift review is the handing over of the exceeded limits of the technological cards, alongside the interlock and ESD changes and the APC status. This way the deviation does not remain an alarm somewhere in the system, but information handed over from shift to shift.
How can a limit be changed?
Section titled “How can a limit be changed?”A limit is not eternal: if the feed, the temperature profile or the material quality changes, the IOW has to be re-evaluated. The change, however, is not a matter of individual judgement but a governed workflow:
- Submit the request for the data change or for adding a new parameter to the process technology manager.
- After approval the process engineer concerned is accountable for the implementation and for keeping the measurement points, target values and limits up to date.
- Carry it through in both places: on the visualization surface and in the process operating instruction concerned as well. The laboratory specialist engineers concerned are informed.
- Launch an MOC process for modifying the technological card or for adding a new card. This is not a formality: by definition the IOW contains an effective management of change process that identifies every change in the process or in the physical equipment that may affect the integrity of the pressurised equipment.
- Check the end points: the prescribed parameter has to be entered into the plant information system, and it has to be verified whether it has also been carried through on the DCS screen.
The responsibilities are cleanly divided: the decision belongs to the process technology manager, the execution to the process engineers, the production and energy controller and the operations manager contribute, and the laboratory specialist engineer is informed.
Case study: a minor change, a major risk
Section titled “Case study: a minor change, a major risk”In a hydrogen plant purge gas was introduced into the feed with the aim of reducing costs. The change went through the standard MOC procedure, but that prescribed no action. A later test run showed that the hydrogen partial pressure was higher than acceptable, which meant a danger of HTHA on the carbon steel equipment. At that point a new MOC was launched, within which the IOW limits were defined, set and monitored on the DCS. No degradation was found in the end, but the review made action necessary at further equipment in hydrogen service as well.
Among the preventive barriers in the bow-tie analysis of the investigation there is exactly what this article is about: setting and regularly checking the IOW limits and the actions in case of exceeding them, keeping the variables within the IOW, and reporting the excursions to maintenance. The Nelson diagram (API 941) provided the filter for identifying the hydrogen service equipment.
The one-sentence lesson of the investigation: a minor change can cause huge damage, and the MOC is the key to keeping modifications under control. The risk of operation after the change must not be higher than it was before.
Process-industry and safety context
Section titled “Process-industry and safety context”The IOW is the intersection of mechanical integrity and process safety. The critical IOW limits are directly connected to the layers of protection: operational control, that is, staying within the IOW, is the first layer of protection, which prevents a corrosion or HTHA scenario uncovered in the HAZOP from developing at all. If the operator disregards the limit because “the yield is higher this way”, degradation accelerates and the equipment fails prematurely. In a Seveso plant the end of this can be a loss of primary containment, fire or a toxic release. The IOW is therefore not a production constraint but the protection of service life and of lives.
What must the operator know? (the competency ladder)
Section titled “What must the operator know? (the competency ladder)”A limit protects only if the operator understands what the deviation means and what has to be done. Operator training is therefore an important part of the IOW introduction, not an afterthought. The competency connected to the safe operating envelope is built on three levels:
| Level | What they know |
|---|---|
| 1. Awareness | is aware that safe operating envelopes exist; is aware of the process and of what can go wrong; is aware of what is required to keep the process under control and what to do in an abnormal situation |
| 2. Fundamental | is able to operate the facility safely within the safe operating envelope and to maintain a shift log; recognizes how to recover from an abnormal situation; manages start-up and shutdown |
| 3. Skilled | is able to interpret weak signals (for example shift log details), to conduct an effective shift handover and to mentor new operators |
The third level is the essence from the viewpoint of this article: recognizing the weak signal is what makes the slow, creeping deviation visible before it turns into an exceeded limit.
Common mistakes
Section titled “Common mistakes”- The card stays on paper. Why it’s a problem: without deviation monitoring the limit warns no one. Instead: take the parameters and their limits into the plant information system, visualized.
- There is no action alongside the limit. Why it’s a problem: the alarm in itself is not an intervention; the operator does not know what to do and how much time there is for it. Instead: every limit should have a defined action and response time (this is the last step of API RP 584).
- The critical parameter is not measured or not indicated. Why it’s a problem: you cannot react to a parameter that is not visible. Instead: the list of measurement and DCS display developments is part of the IOW work.
- Blurred levels. Why it’s a problem: if the standard and the critical level are not separated, it is not visible what is dangerous “on a sustained exceedance” and what is dangerous “immediately”. Instead: separate reporting and a separate duty to act for each level.
- No MOC. Why it’s a problem: a change in the feed or in the material quality is not carried through into the IOW, and the limit becomes obsolete. The case study failed on exactly this point. Instead: every card modification and new card goes through management of change.
- The alarm passes without a response. Why it’s a problem: if there is no documented operator action and investigation for a sustained deviation, the IOW is mere decoration. Instead: an escalation ladder with a logged entry, an investigation and an approved closure.
- The operator was not trained. Why it’s a problem: they do not understand why crossing the limit is dangerous, so they “reset” it. Instead: training according to the competency ladder, all the way to reading weak signals.
When NOT to use it (the limits of the method)
Section titled “When NOT to use it (the limits of the method)”The IOW is a strong tool, but it is not for everything, and there are things that must not be entrusted to it:
- It is not a certified safety function. An IOW limit is an operational control, not a SIF: it does not replace the ESD system, and it is not the layer for which LOPA gives risk reduction credit as a certified independent protection layer.
- It does not handle an unknown damage mechanism. The third step of the process is the identification of the mechanisms; whatever is left out here will have no limit. With a new feedstock or a new operating mode the identification therefore has to be re-run, rather than the old limit being nudged.
- It does not substitute for inspection. Operation within the limit gives predictable degradation, not zero degradation; wall thickness measurement and risk-based inspection are needed regardless.
- It is not a production optimization tool. Yield and energy optimization is the business of the operating envelope; if the IOW is used for this, the two logics get mixed up and the integrity limit becomes negotiable.
- It does not work without measurement. If the parameter is not measured and not displayed, the limit stays formal. In that case the task is instrumentation first, not the limit number.
Take it home (keys)
Section titled “Take it home (keys)”- Connect the three: the operational limit is the concept, the technological card is the document, the IOW is the integrity-critical part of the card.
- Ask about the action: when you see a limit, ask what is to be done when it is exceeded and within how much time. If there is no answer, the limit is not complete.
- Separate the two envelopes: the yield and energy optimum is a different question from the integrity of the equipment; do not let the same trade-off decide both.
- Build an escalation ladder: alarm, automatic log entry, mandatory investigation. The thresholds are set by your own procedure, but every one of the three levels should have an owner.
- Every modification through MOC: changing the card or the IOW is management of change, and it has to be carried through on the DCS as well.
- Train the operator up to weak signals: knowing the envelope is the entry ticket, reading the log details is mastery.
Self-test
Section titled “Self-test”- What exactly does it mean that in the green (optimal) band degradation is “predictable and reasonably low”? Why is this not the same as there being no degradation?
- How does the focus of the operating envelope differ from that of the integrity window, and why is it important to separate them?
- What are the two things that, in the API RP 584 process, make a limit “complete” beyond the bare number?
Answer key: 1) That the damage goes on within the limits too, but at a calculable rate, so inspection and replacement can be planned; zero degradation is neither the goal nor realistic. · 2) The operating envelope focuses on conversion, yield, energy and quality with performance indicators, the IOW on damage mechanisms with chemical and physical parameters; if they blur together, the integrity limit becomes the subject of a production trade-off. · 3) The action in case of an exceedance and the response time belonging to it (and that the parameter is measurable and appears on the operator’s screen).
How does this show up in digital practice?
Section titled “How does this show up in digital practice?”The principle of the operating limit does not stop at the paper card: the same logic is recorded automatically and becomes trackable in a digital operation. The mechanism differs, the principle is the same.
| Element | Digital implementation | Value |
|---|---|---|
| Parameter and limit | Central parameter register extending to the operator interface and to the historian | One source of truth, no two kinds of “valid” limit |
| Plant-status-dependent limit | Dynamic limit computation based on the current plant status | The limit follows reality, it does not alarm during start-up as well |
| Detecting the deviation | Automatic deviation monitoring with configurable time thresholds | The deviation does not depend on human noticing |
| Operator response | Mandatory log entry on the cause of the deviation, with owner and status | Instead of “an alarm went off”, a documented action that can be closed |
| Extended deviation | Automatic launch of an investigation and task tracking | The creeping deviation does not become the new normal |
| Changing the limit | Management of change workflow with approval and verification of the carry-through | An unassessed limit change cannot get through |
Modern digital operating systems implement the same principles as the paper technological card: recording the limit, detecting the deviation and documenting the response, only faster, retrievably and with an audit trail.
Connection to OPEREX (shift log)
Section titled “Connection to OPEREX (shift log)”The decisive point of how the IOW works is not the calculation of the limit but that a documented, trackable operator response is produced for the deviation, and the place of that is the shift log. In established solutions a sustained deviation creates an automatic entry and a notification in the log for the process engineer and the shift crew, and an extended deviation triggers an investigation. The OPEREX shift log records exactly this deviation → entry → action chain in an auditable way: who saw the deviation, what they did, and whether it was closed. On top of that, a mandatory agenda item of the shift handover is the handing over of the exceeded card limits, which is likewise log content. This way the IOW is not a static table but a live control followed shift by shift, and the asset leader can also see retrospectively how many deviations there were and how they were handled.
Terminology (HU / EN / JP)
Section titled “Terminology (HU / EN / JP)”| Hungarian | English (canonical) | 日本語 (JP) | Note |
|---|---|---|---|
| operatív határérték | operational limit | — | the range of the parameter |
| technológiai kártya | technological card | — | part of the documentation |
| üzemeltetési boríték | operating envelope | — | the performance-focused frame |
| integritás-üzemeltetési ablak | Integrity Operating Window (IOW) | — | the integrity-critical part (API RP 584) |
| károsodási mechanizmus | damage mechanism (DM) | — | what the IOW limit holds back (API RP 571) |
| eltérés-monitorozás | deviation monitoring | — | watching the deviation from the limit |
| magas hőm. hidrogénkorrózió | high temperature hydrogen attack (HTHA) | — | a typical IOW hazard (API 941) |
| változáskezelés | MOC (Management of Change) | — | part of the IOW |
The concept is not of Japanese origin, so the JP column is empty; the canonical technical term is the English one, aligned to the terminology of the API standards.
What is the difference between the technological card and the IOW?
The technological card describes all the operational limits (product specification, safety, corrosion). The IOW is its integrity-critical part: it focuses specifically on those parameters that endanger the integrity of the equipment (corrosion, HTHA) if they are exceeded for a predetermined amount of time.
What do the three limit levels mean?
Within the optimal level lower energy consumption and/or better product yield can be achieved. Within the standard (technological card) level operation is safe and the product is within specification; exceeding it can lead to off-specification quality, a process upset and in the long run equipment failure, so action is required. Exceeding the critical (IOW) limit can lead to rapid failure of the equipment, and there immediate action is needed.
What is the difference between the operating envelope and the IOW?
The focus of the operating envelope is conversion, yield, energy and quality, that is, it watches performance indicators. The focus of the IOW is damage mechanisms, that is, it sets limits on chemical and physical parameters. The two may appear on the same surface, but they answer different questions.
How does the system notice when a parameter leaves the window?
Deviation monitoring runs in the plant information system: it gathers the process data and the plant status, computes a dynamic limit, and if the deviation persists beyond the configured time threshold, it sends an alarm and an automatic entry to the electronic log for the process engineer and the shift crew. The typical thresholds (for example 24 or 72 hours for the alarm and the entry, one week for the mandatory investigation) are procedure-specific settings.
Why does the IOW need MOC?
Because a limit is valid only for a given process and equipment state. If the feed, the temperature profile or the material quality changes, the old limit may be misleading. The MOC ensures that the integrity impact of every such change is assessed, that the IOW is updated, and that the modification is carried through on the operator interface as well.
Related concepts
Section titled “Related concepts”production reliability program · management of change · LOPA and SIL · HAZOP · alarm management · ESD systems · the standard operator round · operational risk assessment
Next step
Section titled “Next step”- Tie it to change: management of change, because it is change management that keeps the IOW valid, and the case study failed here too.
- Look at the layer-of-protection logic: LOPA and SIL, to see where operational control ends and where the certified safety function begins.
- Take it into the shift: alarm management and the standard operator round, because the limit protects where the operator notices and reports the deviation.
References / further reading
Section titled “References / further reading”- API RP 584 — Integrity Operating Windows. The canonical recommended practice for establishing, typing and maintaining IOW limits.
- API RP 571 — Damage Mechanisms Affecting Fixed Equipment. The catalogue of damage mechanisms; the input to the third step of the IOW process.
- API RP 580 / API RP 581 — Risk-Based Inspection. The framework and the quantitative methodology of risk-based inspection, on which the risk ranking of the IOW limits relies.
- API 941 — Steels for Hydrogen Service at Elevated Temperatures and Pressures. The source of the Nelson diagram, with which HTHA-prone equipment can be identified.
In practice
The deviation from operational limits is computed by the plant information system, but the place of the alarm and the operator response is the shift log: beyond the configured threshold an automatic entry and a notification are created for the process engineer and the shift crew, and an extended deviation triggers a mandatory investigation. The OPEREX shift log records exactly this deviation → entry → action chain in an auditable way, so the IOW is not merely a limit that has been set, but a live control followed shift by shift.
Learn more: Shift log →