Given. A population of >150 tanks, 75 miles of pipe, and >2000 valves, and a single working day (roughly 8 hours) available for field inspection — a 100% physical inspection of every asset is not possible in the time available.
Find. A defensible sampling plan — not a full census — that concentrates the available inspection time where it is most likely to detect a real release risk.
Approach. Combine a desk-based risk stratification (using existing records) with a risk-weighted field sample, rather than either a purely random sample (which wastes time on low-risk assets) or a purely judgmental walk-through (which is not statistically defensible).
Part 1 — Desk review and risk stratification (before going to the field). Compile existing records for every tank, pipe segment, and valve: age, material of construction, corrosion-monitoring/thickness data, prior leak or repair history, secondary containment status, and service (corrosivity of the contained product). Rank each asset into a small number of risk tiers (e.g. High/Medium/Low) using a simple weighted score combining LIKELIHOOD factors (age, corrosion rate, material, containment/service history) and CONSEQUENCE factors (proximity to a waterway or property line, tank/segment size, product volatility/toxicity) — the standard risk = likelihood × consequence framework used in API 580/653-style risk-based inspection (RBI) programs.
Part 2 — Field time budget. Estimate a realistic per-asset inspection rate (e.g. ∼20–30 min for an external tank walk-down, ∼2–5 min for a valve visual/leak check, a pipe segment inspected by walking an accessible run and checking flanges/supports/coating condition at a set pace) and divide the ∼8-hour day across the three asset classes in proportion to both population size and risk-tier weighting, so the day's schedule is fixed BEFORE entering the field (prevents the audit drifting toward whichever asset type is easiest to reach).
Part 3 — Sample selection within each tier. Inspect 100% of the HIGH-risk tier (this is usually a small fraction of the population — the assets a release would matter most from, or that the desk review flags as most likely to fail) plus a randomly- or systematically-selected statistical sample of the Medium- and Low-risk tiers (e.g. every Nth asset, or a simple random sample sized to give reasonable confidence that the tier's true condition distribution is represented) — concentrating certainty where consequence is highest while still giving every asset a nonzero chance of being checked.
Part 4 — Field inspection method. Use rapid, non-intrusive techniques suited to a one-day walk-down: visual inspection for external corrosion, coating failure, staining, vegetation stress (a classic indicator of a slow leak), and valve-packing weeps; a handheld combustible-gas/VOC meter or acoustic leak detector at flanges and valve stems for a fast go/no-go screen; and spot ultrasonic thickness readings only on the highest-risk tanks/pipe runs where time allows. Full internal tank inspections (API 653) and complete pipe wall-thickness surveys are explicitly OUT of scope for a one-day audit and are flagged as follow-up work.
Part 5 — Documentation and follow-up. Record every inspected asset's condition against a standard checklist, and treat any anomaly found in the Medium/Low sample as a signal to escalate — a single unexpected finding in a "low-risk" tier justifies expanding that tier's sample in a follow-up visit, since it suggests the desk-review risk ranking may be missing a real condition issue.
Sampling plan summary
Asset class
High-risk tier
Medium/low-risk tier
Method
Tanks (>150)
100% inspected
Statistical sample
External visual + spot UT thickness
Pipes (75 mi)
100% of flagged segments
Systematic walk-down sample
Visual + acoustic/VOC leak screen
Valves (>2000)
100% of flagged valves
Random sample
Visual + packing/stem leak check
Check: the exact time budget per asset (Part 2) and sample fraction for the Medium/Low tiers (Part 3) are reasonable engineering estimates the audit team would refine on-site once actual walking distances and access constraints are known — the risk-based stratification structure, not these specific numbers, is the substance of the answer.