Skip to main content
Engineering leaders reviewing schedules and maintenance dashboards in a refinery planning room at dawn

Asset Advisory

Criticality Is Not Priority: How Engineering Leaders Decide What Work Comes First

Turning asset consequence, physical degradation, regulatory deadlines, document readiness, spares and resource constraints into an executable work plan, with the enterprise toolchain that carries each decision.

UEI
ZR3PJZEA7A21
CAGE
174X8
Independence
Findings challenged before release
Deployment
Remote response within 24 hours

Every asset-intensive organization eventually reaches the same Monday morning: hundreds of notifications coded Priority 1, a turnaround window that is already over-subscribed, and a planning meeting that defaults to whoever argues loudest. The cause is rarely a missing criticality ranking. It is the belief that a criticality ranking is a priority list. This article sets out how BlackOut Power Group separates the two, and how engineering leaders combine consequence, condition, compliance, document readiness, materials, schedule float and people into a decision about what work actually happens next.

01

The Monday morning backlog trap

A mid-size refinery or power station can carry ten to twenty thousand open notifications in its CMMS. When a large share of them are coded Priority 1, the code carries no information. Planners then fall back on proximity, seniority and noise: the operator who calls twice gets the crew, and the slow-developing failure on an unspared machine waits.

The ranking is usually not wrong. It is being asked to answer a question it was never designed for. A criticality register describes potential consequence. It says nothing about whether the asset is degrading this week, whether a regulator expects closure by the 30th, whether the drawings are current, whether the parts are in the storeroom, or whether a certified millwright is available on Thursday.

  • Symptom: priority codes inflate until P1 means nothing.
  • Symptom: turnaround scope grows until the window cannot hold it.
  • Symptom: crews mobilize to work that stops for paperwork or parts.
  • Symptom: compliance actions age quietly in a separate system.
Criticality tells you what would hurt most if it failed. Priority tells you what must be worked on now. Readiness tells you whether it can be. A plant that confuses the three is not prioritizing; it is queuing.

02

Asset criticality is foundational, but it is not priority

Asset criticality is the intrinsic potential consequence of losing a function: life safety, environment, production, cost and the system dependency that makes one failure cascade into many. It is a stable baseline, revisited at management of change, after turnarounds and when bad-actor reviews show the consequence model was wrong. BPG Criticality (criticality.blackoutpowergroup.com) structures exactly this baseline, with weighted dimensions and a dependency multiplier, as a decision-support input.

Task priority is time-bound. It answers how quickly risk is moving toward an unacceptable outcome and how much time remains to act. A Tier 1 compressor running smoothly may rightly sit at routine priority. A Tier 2 pump whose vibration has doubled in ten days may need to be worked first. The decision requires both: consequence sets the stakes, risk velocity sets the clock.

Consequence sets the stakes, velocity sets the clock

High criticality, low velocity

Plan deliberately

Protect with monitoring and schedule into the next suitable window.

High criticality, high velocity

Act now

Confirmed degradation on a high-consequence function. P0 or P1 triage.

Low criticality, low velocity

Defer or batch

Backlog candidate. Bundle with nearby work or retire.

Low criticality, high velocity

Contain

Routine order or accepted run-to-failure under the FMECA logic.

Horizontal axis: asset criticality. Vertical axis: risk velocity. Quadrant outcomes are illustrative and remain subject to compliance overrides and readiness.
The three questions engineering leaders must keep separate
DimensionQuestion it answersTypical sourceChanges how often
Asset criticalityHow bad is it if this function is lost?BPG Criticality, FMECA, ISO 14224 registerAt MOC, turnaround review, bad-actor audit
Task priorityHow soon must we act on this specific condition?Condition data, inspection findings, compliance datesDaily to weekly
Execution readinessCan the work be done safely and correctly now?Documents, materials, permits, people, scheduleDaily

03

P0 non-negotiables: statutory, safety and environmental overrides

Some work does not compete. A mechanical integrity deficiency under a process safety program, an overdue relief device inspection, an environmental permit exceedance or a consent-decree milestone is not ranked against production optimization. It enters above the economic queue, and the only legitimate debate is the least-cost, lowest-risk way to comply.

These overrides are typically governed in an EHS and process safety platform such as Enablon or Sphera, while the physical work lives in SAP or Maximo. The common failure is that the two never meet: the audit action shows as open in one system while no work order, crew hours or materials exist in the other. Each P0 action needs a linked work order, an owner, a due date and a closure evidence requirement.

  • Statutory or code inspection deadlines (pressure equipment, relief devices, fired equipment).
  • Process safety actions from PHA, HAZOP, LOPA, incident investigation and MI audits.
  • Environmental permit limits and regulatory commitments.
  • Imminent life-safety hazards identified in the field.

04

Dynamic modifiers: condition and P-F acceleration

Condition data is what turns a static score into a live risk position. Bently Nevada System 1 for rotating machinery protection and diagnostics, and the AVEVA PI System for process history, are the plant-standard sources most engineering leaders already trust. Inspection findings from thickness surveys, thermography and oil analysis belong in the same picture.

The governing concept is the P-F interval from the FMECA. If a detected degradation mechanism typically progresses to functional failure in weeks, discovery itself raises priority regardless of the next planned outage. If the mechanism is slow and well-monitored, the work can wait for the window. The FMECA Criticality Guardian carries these intervals so the triage meeting is arguing about evidence, not intuition.

05

Document management as an execution gate

Document control is usually treated as back-office closeout. In practice it is one of the hardest constraints on execution. Work on a pressure boundary, a protection system or a control loop cannot safely or legally proceed if the P&ID is not current, the MOC is not approved, the isolation list does not match the field, or the weld procedure is not qualified for the material and thickness.

Mature organizations therefore treat document readiness as a gate with the same standing as material readiness. A work order is not released until the engineering package is current and approved. Engineering document platforms such as Hexagon SmartPlant Foundation and Autodesk Vault hold revision control; the CMMS references the governed revision; the planner confirms it before release. After execution, redlines and as-built records return to the master so the next crew does not inherit a stale drawing.

Execution readiness gates

  1. 01

    Triage and priority set

  2. 02

    Document package current and approved

  3. 03

    MOC authorized

  4. 04

    Materials staged

  5. 05

    Crew and discipline available

  6. 06

    Permit and isolation verified

  7. 07

    Released for execution

Priority does not equal readiness. Work is released only when every gate, including the document package, is satisfied.
Minimum document package before releasing higher-consequence work
DocumentWhy it gates executionTypical owner
Current P&ID and isolation / blind listSafe isolation and line-break depend on drawings that match the fieldOperations and process engineering
Approved MOC with redlinesChanges to design, chemistry or control logic require authorized review before workMOC coordinator and Responsible Engineer
Issued-for-construction drawings and isometricsFabrication and installation must match a governed revisionEngineering / document control
WPS, PQR and welder qualificationsCode repairs require qualified procedures before the first arcQA/QC and welding engineering
Inspection and Test Plan with hold pointsDefines what must be witnessed and accepted, and by whomQA/QC and inspection
OEM manuals, clearances and torque dataMachine-specific limits govern assembly and acceptanceReliability / machinery engineering

06

Spares and supply chain: the unspared single point of failure

Inventory status changes priority. An unspared duty pump with a rotor in the storeroom is a manageable risk; the same pump with a rotor quoted at an extended OEM lead time is a different risk, even though nothing physical has changed. When the spare is consumed, criticality has not moved but exposure has.

Long-lead procurement also inverts the calendar. If installation is six months away but the component lead time exceeds that, the procurement task is urgent now. SAP Materials Management and SAP Ariba, or the Maximo inventory equivalent, should flag critical-spare reservations, purchase order release dates and promised delivery against the planned execution date. Where long-term service agreements govern parts and field service, their mobilization terms belong in the same view.

07

Outage windows and schedule-critical float

Turnarounds create a category that ranking alone misses: schedule-critical work. An item can be moderate in consequence but must be engineered, approved and procured before a fixed window, or it slips by years. Its priority is driven by the float remaining between today and the last responsible date to be ready.

Oracle Primavera P6 carries the logic network, manning histograms and the outage critical path. Deltek Acumen Fuse checks whether that schedule is mechanically sound: open ends, hard constraints, out-of-sequence logic and false float. Where confidence matters, schedule risk analysis tests whether the window is achievable. A schedule that has not passed these checks should not be used to defend scope decisions.

08

The hardened industrial toolchain

No single platform resolves priority. Each tool owns one kind of evidence, and the value comes from disciplined handoffs between them. The list below is deliberately limited to platforms that plant managers, reliability leaders and turnaround superintendents recognize as industry baseline. Equivalent systems can fill the same roles.

Integrated enterprise toolchain

  1. ConsequenceBPG Criticality, FMECA Criticality Guardian
  2. ConditionBently Nevada System 1, AVEVA PI System
  3. ComplianceEnablon, Sphera
  4. DocumentsHexagon SmartPlant Foundation, Autodesk Vault
  5. Work and materialsSAP S/4HANA PM and MM, IBM Maximo
  6. ScheduleOracle Primavera P6, Deltek Acumen Fuse
  7. Decision boardMicrosoft Power BI exception view
Each layer owns one kind of evidence. Decisions are made at the board, by accountable people, not inside any single platform.
Enterprise toolchain: role, output and the common failure
LayerTypical platformsPrimary outputCommon failure
Consequence and criticalityBPG Criticality, GE Vernova APM (Meridium)Baseline consequence score per functionScored once and never revisited
Failure modes and strategyFMECA Criticality Guardian, ReliaSoft XFMEAFailure modes, P-F intervals, task logicFMECA never reaches the CMMS
Condition and telemetryBently Nevada System 1, AVEVA PI SystemDegradation trends and alertsAlerts not linked to notifications
Safety and complianceEnablon, SpheraP0 actions, deadlines, closure evidenceActions tracked apart from work orders
Document controlHexagon SmartPlant Foundation, Autodesk VaultGoverned revisions, MOC packagesWork released against stale drawings
Work managementSAP S/4HANA Asset Management (PM), IBM MaximoNotifications, orders, task lists, historyInflated priority codes
Materials and sparesSAP MM, SAP AribaStock, reservations, PO and delivery datesCrews mobilized before parts arrive
Scheduling and manningOracle Primavera P6Logic network, critical path, manningUnconstrained wish-list schedule
Schedule integrityDeltek Acumen FuseSchedule health and float validationFalse float accepted as real
Cross-system triageMicrosoft Power BIException board for weekly decisionsDashboards without decision rights

09

A five-band priority hierarchy

Priority bands only work if each band has criteria, a response expectation and a named approval, and if the share of work in the top bands is actively limited. When more than a small fraction of the backlog sits in P0 and P1, the bands are inflated and must be re-triaged, not expanded.

Five-band priority hierarchy

  1. P0Statutory, life-safety or environmental obligation
  2. P1High consequence with confirmed degradation
  3. P2Schedule-critical or long-lead for an approaching window
  4. P3Proactive reliability and routine engineering
  5. P4Discretionary or low-consequence improvement
Bands narrow toward the top by design. An inflated P0 or P1 population signals a triage failure.
Illustrative priority bands (set response windows by site procedure)
BandCriteriaIllustrative responseApproval
P0Imminent life-safety, environmental or statutory obligationImmediate to 24 hoursOperations lead and Responsible Engineer
P1High-consequence asset with confirmed degradation inside its P-F windowWithin daysResponsible Engineer
P2Schedule-critical or long-lead work for an approaching windowCurrent planning cyclePlanning and turnaround leads
P3Proactive reliability, PM and routine engineering30 to 90 daysMaintenance planning
P4Discretionary improvement or low-consequence workBacklog or opportunityArea owner

10

The governance rhythm and the Principal's questions

Prioritization is a cadence, not a calculation. A weekly triage brings the Responsible Engineer, maintenance planning, operations, EHS, supply chain and the turnaround coordinator to one exception board. They resolve new P0 and P1 entries, clear document and material blockers, confirm discipline loading, and freeze the next two-week schedule. Changes inside the frozen window require a stated reason.

Tools and AI-assisted analytics can surface exceptions faster, but they do not accept risk. The Responsible Engineer and operations leadership remain accountable for deferral decisions, and each deferral should record its basis and review date. Quarterly, the criticality baseline itself is reviewed against failures, MOCs and bad actors.

  • What is the failure mechanism, and how fast does it progress?
  • What happens to the system, not just the asset, if it fails before we act?
  • Is the spare physically in the storeroom, and what is the real lead time?
  • Is the document package current and approved for this exact work?
  • Which discipline is the bottleneck, and what else does this displace?
  • If we defer, who accepts the risk, on what evidence, until when?

Weekly engineering triage cadence

  1. 01

    Collect new findings and alerts

  2. 02

    Re-triage against criticality and velocity

  3. 03

    Clear document and material blockers

  4. 04

    Level discipline loading

  5. 05

    Freeze two-week schedule

  6. 06

    Execute and close with evidence

  7. 07

    Review deferrals and baseline

A closed loop run by accountable people. Tools surface exceptions; the Responsible Engineer and operations accept risk.

Technical References

Standards basis and scope references.

  1. 01 ISO 14224 for equipment taxonomy and boundary definitions that anchor a consistent criticality register.
  2. 02 ISO 55000 series for asset management system principles, including risk-based decision making and alignment of work to organizational objectives.
  3. 03 SAE JA1011 and JA1012 for reliability-centered maintenance logic and P-F interval principles.
  4. 04 OSHA 29 CFR 1910.119 (Process Safety Management), including mechanical integrity and management of change elements, where applicable.
  5. 05 ISO 9001 clause 7.5 and ISO 15489 principles for controlled documented information and records; API 510, API 570 and API 653 for in-service inspection and repair records where adopted.
  6. 06 ASME Boiler and Pressure Vessel Code Section IX and ASME B31.3 for welding procedure qualification and repair documentation, as adopted by the jurisdiction and owner.
  7. 07 AACE International recommended practices for planning, scheduling and schedule risk analysis; DCMA 14-point assessment as a widely used schedule health heuristic.
  8. 08 Platform roles described here reflect typical industry use. Each organization's configuration, procedures and Responsible Engineer govern actual decisions. Priority bands, response windows and examples are illustrative.

Applicability and adopted editions must be confirmed against the governing contract, authority, location, cable construction, and manufacturer requirements.

Move from an asset ranking to a work plan that holds.

BlackOut Power Group builds criticality baselines, priority governance, readiness gates and triage cadences that connect your existing enterprise systems to the decisions engineering leaders actually have to make.

Discuss engineering work prioritization