1. Introduction
A subsea processing system is a system in which separation, boosting and injection of the well stream are performed at the seabed instead of topside. It has become a key technology for deep- and ultra-deep-water field development, improving recovery, reducing topside production liabilities and mitigating flow assurance risk [
1,
2].
Placing key equipment of a subsea separation system, such as the separator, at water depths of around 3000 m, however, exposes it to extreme external hydrostatic pressure, low temperature and severely restricted intervention access. Failures under these conditions carry large production, environmental and intervention-cost consequences [
3,
4]. Quantitative reliability assessment is therefore central to the design and integrity management of subsea separation systems. Research in this context strives to address two qualitatively different questions: how often the equipment fails to perform its function, and how likely it is to collapse structurally.
The first question is traditionally answered with reliability methods based on generic failure-rate databases such as OREDA [
5]. Because field experience for novel subsea equipment is scarce, several authors have proposed adjusting topside-derived failure rates through risk influencing factors (RIFs) [
6], and Rahimi and Rausand formalized a practical procedure for predicting failure rates of new subsea systems from such factors [
7]. Bayesian networks (BNs) have proven particularly attractive for propagating the associated uncertainties and for diagnostic reasoning, with obvious advantages over static fault trees [
8,
9], and they have been applied to subsea blowout preventer control systems [
10], subsea X-mas trees [
11], subsea control modules coupled with digital twins [
12] and general system-level evaluation combined with machine learning [
13]. Fault-tree-based treatments of subsea production systems, including fuzzy extensions and system optimization, complement this research work in the present context [
14,
15,
16]. Within this line of research, and in the author’s own earlier work, a Bayesian framework was developed for the reliability prediction of subsea processing systems, quantifying the influence of nine RIFs on the failure rates of a five-equipment subsea separation system (SSS) and reporting a year-one system failure probability of 0.4195 with an approximately ±15% failure-rate envelope across RIF states [
17]. A recent study illustrates the trend towards physics-informed condition monitoring of subsea safety systems [
18].
The collapse or local buckling of tubular structures such as subsea cylindrical equipment is a classical problem of instability [
19], for which Windenburg and Trilling derived a widely used finite-length elastic collapse equation [
20], and modern research work combines elastic and plastic collapse and geometric imperfections through interaction equations of the type adopted in offshore design codes [
21,
22,
23]. Corrosion-induced wall loss is a dominant degradation mechanism for such components: it reduces collapse capacity [
24], drives the time-variant reliability of pipelines [
25] and introduces substantial model uncertainty into strength predictions [
26]. Accurate capacity evaluation for realistic geometries generally requires nonlinear finite element analysis (FEA), whose computational cost is prohibitive for the limit-state evaluations required by sampling-based reliability methods. This computational burden has recently motivated the use of machine-learning models for predicting burst and collapse failure in subsea pipeline systems [
27].
Surrogate modelling is considered to bridge this gap. Response surfaces were introduced for structural reliability by Bucher and Bourgund [
28], and Gaussian process (Kriging) surrogates [
29] have since become the reference approach. These methods have demonstrated efficiency for marine structural reliability problems [
30], active-learning variants such as AK-MCS that adaptively enrich the design of experiments near the limit state [
31], and a mature body of survey literature [
32]. Meta-model-driven reliability analyses are now also being applied to complete offshore systems, such as floating wind turbines [
33]. Nevertheless, in the subsea processing literature, the surrogate-based structural strand and the BN-based functional strand have evolved essentially independently of each other.
This study examines the feasibility of combining the aforementioned approaches. Straub and Der Kiureghian showed that structural reliability methods can be embedded within enhanced Bayesian networks [
34,
35], and that the integration of heterogeneous failure modes on a common probabilistic basis is recognized as one of the persistent challenges of reliability engineering [
36] and a prerequisite for credible digital twins of subsea assets [
37]. Yet, to the author’s knowledge, no published study couples a physics-based, time-variant structural reliability of a subsea separator, represented by a trained surrogate model, into a system-level BN. Existing SSS assessments treat the separator as a purely functional item with a constant failure rate [
17], so the influence of external-pressure collapse, its degradation due to corrosion, and its interaction with system-level RIF uncertainty remain unquantified.
This paper develops and demonstrates a component-to-system, multi-scale reliability framework for deep-water subsea separation systems (SSS). The main contributions are fourfold. First, a GPR surrogate of the separator collapse pressure is trained on a 474-sample collapse dataset spanning six design variables and is verified against the analytical capacity model from which that dataset is generated; the reliability model adds the internal operating pressure and a capacity-model uncertainty factor, so that eight random variables enter the limit state. Second, the surrogate model is combined with FORM and MCS analyses to produce intact and corroded structural failure probabilities, converted to annual failure rates. Third, the structural failure rate is combined with the RIF-adjusted functional failure rates of the five SSS equipment items in a Bayesian network (BN). The BN provides time-dependent system reliability, failure attribution, and diagnostic posteriors. The integrated model is then validated against the author’s previous assessment of the same system [
17]. Fourth, a sensitivity study translates the results into fabrication (ovality), inspection and monitoring priorities for the assumed design and degradation scenarios. The remainder of the paper is organized as follows:
Section 2 presents the framework and its component- and system-level models;
Section 3 reports the numerical results;
Section 4 is devoted to verification and consistency checks;
Section 5 discusses sensitivities, engineering implications and limitations; and
Section 6 concludes.
5. Discussion
A one-at-a-time sensitivity analysis was performed to identify the key engineering parameters affecting system reliability.
Figure 9 and
Table 7 present the changes in the annual structural failure rate at year 20, using the baseline value of 6.29 × 10
−5 yr
−1 for the moderate corrosion scenario. The analysis considers variations in fabrication, degradation, and operational parameters to evaluate their individual influence on failure probability. Changing the mean initial ovality from 0.5% to 0.75% is by far the most detrimental change, raising the rate twenty-fold to 1.26 × 10
−3 yr
−1, while tightening it to 0.35% suppresses the rate to 3.2 × 10
−6 yr
−1, below even the intact baseline of
Table 5. Doubling the corrosion rate is the second-ranked driver, followed by the width of the capacity-model uncertainty; the demand frequency scales the rate linearly, and delaying the corrosion onset by five years (an effective coating) is equivalent to shifting the whole degradation trajectory accordingly. Two internal consistencies corroborate the tornado sensitivity (
Figure 9) results: halving the corrosion rate at year 20 reproduces exactly the year-10 rate of the baseline scenario, and the five-year onset delay reproduces the year-15 rate, as the thinning model of Equation (15) requires.
Three important implications can be drawn for integrity management. First, ovality is the most important factor controlling structural reliability. The high influence of initial ovality, shown by both the FORM importance factor (αi2 = 50.6%) and the tornado ranking, indicates that ensuring accurate manufacturing tolerances can improve reliability more effectively than later operational measures. Therefore, dimensional inspection of the as-built shell, to confirm that the measured out-of-roundness does not exceed the value assumed in design, is essential.
Second, the DNV target-rate crossings presented in
Section 3.3 illustrate how an inspection strategy can be derived from reliability limits. For the corrosion scenarios assumed here, a baseline ultrasonic wall-thickness inspection within the first three to five years would be sufficient to distinguish the moderate from the severe scenario while the system is still within the high-safety-class reliability limit, and requalification would be indicated before year 12 for the severe scenario and before approximately year 24 for the moderate one. These years follow directly from the deterministic corrosion rates of 0.2 and 0.4 mm/yr, from the assumed protection-breakdown time and from the assumed demand frequency; they are illustrative results for the assumed cases rather than general inspection recommendations, and they would move with any change in those assumptions or in the target safety class.
Because subsea inspection campaigns are costly, their timing should be linked to predicted reliability-limit crossings rather than based on fixed inspection intervals. This provides a more effective risk-based inspection strategy [
44,
45]. Third, since the frequency has a direct linear effect on structural reliability, the number of depressurization events can serve as a simple and measurable reliability indicator. Operational practices that avoid unnecessary full depressurization (zero internal pressure) events can reduce the structural failure rate by half without additional capital investment.
The system-level results should be interpreted carefully. From a frequency perspective, structural failure is a very small contributor: it accounts for less than 0.001% of failure attribution for an intact shell and increases to only 0.33% after 25 years under severe corrosion. Therefore, availability improvement efforts should focus primarily on functional failure modes, following the priority ranking in
Table 6, with attention first given to the separator internals and coalescer.
This ranking is expressed in failure frequency alone. The framework quantifies probabilities and frequencies of failure and contains no consequence model, so the quantities reported in this paper are reliability measures rather than risk measures. The distinction matters because the consequences of the two failure classes differ in kind: functional failures generally result in recoverable module intervention and temporary production loss, whereas collapse of the separator shell at 3000 m water depth is a loss-of-containment event with potential equipment replacement and environmental consequences. Converting the present results into risk would require an explicit consequence assessment, for example a frequency–consequence matrix or an expected-loss model. Such an assessment would be expected to weigh the structural branch more heavily than its frequency contribution alone suggests, but that expectation is not quantified here and no risk-based conclusion is drawn from it.
The main advantage of the proposed multi-scale framework is its ability to represent both functional and structural failure mechanisms within a single probabilistic model, instead of treating them separately through independent structural reliability and reliability–availability–maintainability (RAM) analyses. Furthermore, the diagnostic results presented in
Section 3.4 provide an operational benefit: early-life system failures contain valuable information about the underlying RIF conditions and should trigger a reassessment of the assumed environmental and maintenance states [
9].
The limitations of this study should be considered when interpreting the results, and are listed individually below.
- (i)
The training data are generated by the physics-based interaction model of Equations (1)–(5) with calibrated noise rather than by an independent nonlinear finite element campaign. This is sufficient to demonstrate the framework and to quantify the cost saved by the surrogate step, but it means that the accuracy figures of
Section 3.1 measure emulation error rather than physical accuracy. Geometry-specific finite element results and, ultimately, experimental collapse data should be incorporated before the method is used for design decisions; such an improvement would change only the input data, while the surrogate, reliability and system-integration steps would remain unchanged.
- (ii)
The capacity model represents an unstiffened cylindrical shell course under uniform external pressure. A practical separator additionally contains end closures, nozzles, supports, internal weirs and plates and, in some designs, ring stiffeners. These features change the effective length between restraints, introduce local stress concentrations and can shift the governing buckling mode, and their net effect on the collapse pressure may be favourable through added restraint or unfavourable through local imperfection and residual stress. The present results therefore apply to the governing shell course, and a component-specific finite element model would be needed to confirm that this is the critical location for a given design.
- (iii)
The surrogate is trained over the ranges of
Table 2. Thickness, diameter, length, stiffness and yield stress remain inside those ranges for every corrosion year considered, but the upper tail of the ovality distribution and the FORM design point lie slightly outside the sampled interval, so the model is mildly extrapolated there. The comparison with the analytical capacity model in
Section 4.2 indicates that the resulting error is small, but an extended design of experiments in
f0 is recommended for design application.
- (iv)
Only the separator carries a structural failure branch. The hydrocyclone, the coalescer and the two pumps enter the network through functional failure rates alone, although they are also pressure-containing or pressure-exposed items with their own ultimate limit states. The framework extends to them without modification, but each would require its own capacity model and design of experiments, which was outside the scope of this study.
- (v)
The system model is simplified in three respects: the series representation and the conditional independence assumption exclude redundancy and common-cause failures beyond the shared RIF state, and the two-state node S captures the published uncertainty range but not the full nine-factor RIF network of [
17].
- (vi)
Functional failure rates are assumed constant in time, whereas the structural failure rate varies with ageing. This difference follows the OREDA data basis [
5]; incorporating time-dependent functional degradation models would improve predictions for late-life operation.
- (vii)
Corrosion is simplified as uniform wall thinning of an initially defect-free shell. More realistic corrosion patterns, such as localized pitting or grooving, would require defect-specific capacity models [
24,
26] combined with inspection-based reliability updating.
- (viii)
The demand frequency
νd is an operational assumption rather than a measured quantity; its influence is linear and is quantified in
Table 7.
- (ix)
FORM underestimates the failure probability relative to MCS by 16–19% at the higher probability levels, as discussed in
Section 4.2. This is relevant mainly for component-level predictions close to the end of service life and does not affect the system-level results.
- (x)
Epistemic and aleatory uncertainties are not separated, particularly for
f0 and
Xm. A nested uncertainty framework would allow reducible uncertainty to be distinguished from inherent variability and would give a more informative uncertainty representation [
46].
6. Conclusions
A component-to-system multi-scale reliability framework has been developed for a deep-water subsea separation system operating at 3000 m water depth. A Gaussian process regression surrogate of the collapse pressure of the vertical gravity separator shell, trained on a 474-sample design of experiments, was embedded in FORM and Monte Carlo reliability analyses and coupled, through a time-variant structural failure rate, to a Bayesian network of the five-equipment separation train. The following conclusions are drawn.
The surrogate reproduces the capacity model it emulates with R2 = 0.996 and a relative RMSE of 2.1% on held-out samples, and its posterior standard deviation at the FORM design points remains below 0.4% of the predicted capacity. Replacing the analytical capacity model by the surrogate changes the reliability index by 0.5% for the intact vessel and by 0.04% at the verification point, so the surrogate is reliability-equivalent to the capacity model at a negligible fraction of its evaluation cost. This equivalence is numerical: the physical adequacy of the capacity model itself is not established by the present dataset and remains to be demonstrated against independent finite element and experimental results.
For the intact, code-compliant shell the reliability index is β = 4.55, corresponding to an annual structural failure rate of 5.3 × 10−6 per year. This satisfies the DNV high-safety-class target for ultimate limit states and amounts to 0.0034% of the functional failure rate of the separator, so structural collapse is negligible in frequency terms for a new vessel.
Uniform corrosion changes this picture progressively. At 0.2 and 0.4 mm/yr the reliability index falls to 3.86 and 3.12 after 25 years and the annual structural failure rate increases by factors of 21 and 350, respectively, crossing the medium-safety-class target of 10−4 per year at years 24 and 12. The cumulative structural collapse probability over 25 years reaches 9.2 × 10−3 for the severe scenario, and the structural share of system-level failure attribution rises from below 0.001% to 0.33%.
At system level the year-one failure probability of 0.4334 agrees within 3.3% with the previously published assessment of the same system, confirming that the contracted two-state RIF network reproduces that earlier result. Adding the structural branch changes the system failure probability by less than 10−5, so the value of the integration lies in consistent attribution and diagnostics across failure classes rather than in the headline reliability figure. Diagnostic inference illustrates this: an observed first-year system failure raises the posterior probability of the severe RIF state from 0.50 to 0.556.
The sensitivity study identifies fabrication quality as the controlling factor for structural reliability. The initial ovality carries a FORM importance factor of 50.6%, and relaxing its mean from 0.5% to 0.75% raises the year-20 annual failure rate twenty-fold, whereas doubling the corrosion rate raises it by a factor of ten. Dimensional control of the as-built shell is therefore a more effective reliability measure than any of the operational parameters examined.
Two developments are required before the framework is applied to design. First, the collapse dataset should be regenerated from independent nonlinear finite element analyses of the specific vessel geometry, including end closures, nozzles and internals, and validated against experimental collapse data. Second, an explicit consequence model is needed if the frequency results reported here are to be interpreted as risk. Extending the structural branch to the remaining pressure-containing items and replacing the deterministic corrosion scenarios by inspection-updated degradation models are natural further steps.