grokkingstuff Home Blog Projects Wiki Calculators About

Corrosion Monitoring as Feedback

date2026-07-24tags:ele: :control:

The thesis

Corrosion is an electrochemical process — anodic dissolution, cathodic reduction, electrons exchanged at a metal-electrolyte interface — and this fact, almost trivial in retrospect, is what makes it tractable to control theory in a way that, say, mechanical wear is not. If corrosion is electrochemical, then it is observable through electrochemical sensors (EIS, LPR, OCP, ER probes) and controllable through electrochemical or chemical actuators (cathodic protection, inhibitor dosing, coatings). We have a measured variable, a manipulated variable, a setpoint, a plant, disturbances: a feedback loop. This is the loop where control theory and corrosion science meet, and it is underdeveloped in both fields, because corrosion engineers treat monitoring as passive (the probe is there to log, to alarm, to appear in the monthly report) and control engineers treat corrosion as "someone else's problem" — a chemical curiosity that lives outside the P&ID, downstream of the real process. The result is a loop that exists in principle but is rarely closed in practice, and when it is closed, it is closed badly, by a chemist with a pump and a hunch instead of by someone who has heard of Bode plots.

[fn:: There is a deeper reason the loop stays open beyond mere disciplinary neglect: corrosion is one of the few industrial processes where the "plant" actively changes its own dynamics over the measurement horizon. The inhibitor film is a state variable with memory; the metal surface roughens and repassivates; microbial colonies establish and die back. A loop tuned on Tuesday's plant may be mistuned on Thursday's, and the mistuning is not a small perturbation but a change in sign of the effective gain under some transients. This is not the kind of plant that lends itself to a one-time commissioning and walk-away.]

What follows is an attempt to lay out the sensor layer, the actuator layer, the loop that joins them, two worked industrial examples, and the honest accounting of why the loop so often stays open.

The sensor layer

LPR — the rate, directly

Linear polarization resistance (LPR) gives the corrosion rate directly via the Stern-Geary relation:

$$I_{\text{corr}} = \frac{B}{R_p}, \quad \text{where } R_p = \left(\frac{dE}{di}\right)_{E=E_{\text{corr}}}$$

Here $B$ is the Stern-Geary coefficient (typically 26 mV for active systems, 52 mV for passive — a value that itself depends on the Tafel slopes, which you usually have not measured), and $R_p$ is the polarization resistance in $\Omega \cdot \text{cm}^2$, obtained by perturbing the working electrode ±10 mV around the open-circuit potential and measuring the slope. Divide by equivalent weight and density and you get a corrosion rate in mm/yr that is good to within a factor of roughly two, which is either appalling or remarkably good depending on whether you are used to chemical sensors or to thermocouples. See Linear Polarization Resistance and Open Circuit Potential.

[fn:: The ±10 mV perturbation is small enough that the current-potential relationship is approximately linear (hence "linear" polarization), which is what licenses the Stern-Geary simplification. Push harder and you leave the linear regime; the full Butler-Volmer equation takes over, and you are now doing potentiodynamic polarization, which gives more information (Tafel slopes, pitting potential) but takes longer and damages the surface. There is no free lunch: the faster and less destructive the measurement, the more model-dependent the interpretation.]

A worked number: suppose $R_p = 250\;\Omega \cdot \text{cm}^2$ and $B = 26$ mV. Then $I_{\text{corr}} = 0.026/250 = 1.04 \times 10^{-4}\;\text{A/cm}^2 = 104\;\mu\text{A/cm}^2$. For iron (equivalent weight 27.9 g/eq, density 7.87 g/cm³), the conversion factor is roughly $3.27 \times 10^{-3}\;\text{mm/yr per }\mu\text{A/cm}^2$, giving a rate of $0.34$ mm/yr — aggressive but not catastrophic for a mild-steel cooling-water loop, and well above the 0.075 mm/yr target that most refinery specs demand.

EIS — the mechanism

Electrochemical impedance spectroscopy (EIS) gives the mechanism, not just the rate: by sweeping frequency (typically 100 kHz down to 1 mHz or lower) and measuring the complex impedance, you can separate charge-transfer resistance $R_{ct}$ (the kinetic term, the corrosion rate) from diffusion-controlled Warburg impedance (the mass-transport term, which tells you whether the rate is limited by the reaction or by getting reactant to the surface). The Randles circuit interpretation — $R_s$ in series with $(R_{ct} \parallel C_{dl})$, with a Warburg element appended for diffusion — is the workhorse model, and like all workhorses it is wrong in detail and useful in aggregate. See Electrochemical Impedance Spectroscopy.

[fn:: The measurement time-scale problem is the central obstacle to closing a fast loop. A single EIS spectrum down to 1 mHz takes on the order of $1/(0.001) = 1000$ seconds per low-frequency point alone — realistically 20–40 minutes for a full spectrum, longer if you want low-frequency resolution. This bounds the achievable loop bandwidth to roughly $1/(2\pi \cdot 1200\,\text{s}) \approx 0.13$ mHz, or a period of ~2 hours. LPR is faster (seconds to minutes) but gives only the scalar $R_p$, losing the mechanistic decomposition. The trade-off between information content and bandwidth is fundamental: you cannot simultaneously know what the corrosion is doing and respond to it quickly, unless you accept LPR's lossy summary and reserve EIS for periodic diagnostic sweeps.]

OCP — the thermodynamic state

Open-circuit potential (OCP) gives the thermodynamic state — where the metal sits on the Pourbaix diagram, whether it is in the immune, passive, or corroding regime. OCP is cheap (a high-impedance voltmeter and a reference electrode), continuous, and almost useless on its own: a stable OCP tells you nothing about the rate, only the tendency. But as a feedforward signal — "the potential has drifted 200 mV in the noble direction, something has changed, wake up the LPR loop" — it has value.

ER probes — the blunt instrument

Electrical resistance (ER) probes measure metal loss directly: a thin element of known cross-section is exposed to the environment, and its electrical resistance increases as it thins. The measurement is in mm/yr (averaged since probe installation), it requires no electrolyte contact beyond that of the process itself, and it works in non-aqueous environments (oil, gas, even soil) where electrochemical methods fail. The price is that it is an integral measurement — it reports cumulative loss, not instantaneous rate — so its bandwidth is days to weeks, and it cannot see transients. ER probes are the fallback when you cannot do LPR, and they are the cross-check when you can.

[fn:: There is a subtle epistemological gap between ER and LPR worth flagging. LPR measures an electrochemical rate — the faradaic current — and assumes all of it produces metal loss. ER measures an actual metal loss — by geometry and resistance — and is agnostic to mechanism. The two can disagree when, for example, a fraction of the anodic current goes into forming a passivating oxide (which LPR counts as "corrosion current" but ER correctly does not count as "metal loss"), or when localized pitting thins a small area that ER averages over but that is far more damaging than the average rate suggests. LPR is biased toward uniform corrosion; ER is biased toward nothing in particular but is too slow to catch anything fast. Neither sees pitting well, and pitting is the failure mode that actually kills equipment.]

The actuator layer

There are three actuators, in decreasing order of how much they resemble a control-system actuator:

Cathodic protection

Impress a current (either sacrificial anode or impressed-current rectifier) that pushes the structure's potential below the corrosion potential $E_{\text{corr}}$, into the immune or kinetically-suppressed regime. The actuator is an electrode (or a rectifier driving one); the manipulated variable is current. There is an elegant circularity here: the plant is the sensor. The pipeline whose potential you are controlling is also the working electrode whose potential you are measuring against a reference cell. You are not measuring a separate proxy; you are measuring the thing you are controlling, which is good for observability but means sensor failure and actuator failure are the same failure mode — a dangerous coupling.

[fn:: The circularity is not purely cosmetic. Because the CP current polarizes the structure, any potential measured while CP is on includes an $IR$ drop through the soil or electrolyte, which is an artifact of the actuator itself, not a property of the plant. This is the corrosion-control analogue of measuring a process variable that is contaminated by the actuator's own action — the classic problem of sensor-actuator coupling. The "instant off" technique (interrupt the current, measure within a second, before depolarization) is the engineering workaround, but it means the sensor cannot see the controlled state continuously, only in snapshots. A loop that must turn its actuator off to measure accurately is a loop with a structurally limited bandwidth.]

Inhibitor dosing

Add a chemical (phosphate, zinc, molybdate, azole, a film-forming amine) that adsorbs or precipitates on the metal surface, forming a diffusion barrier that lowers $I_{\text{corr}}$. The actuator is a metering pump, not an electrode; the manipulated variable is mass flow rate (mg/L of inhibitor in the bulk fluid). The plant here is genuinely nonlinear and slow: the inhibitor film builds up over hours to days and wears off over a comparable timescale, so the gain and time constant are both state-dependent. This is not a valve on a tank; it is a valve on a surface chemistry that you cannot observe directly.

Coating selection

Choose a barrier coating (epoxy, polyurethane, fusion-bonded epoxy for pipelines). This is open-loop: you select it at design time, it degrades over years, and there is no real-time manipulated variable. It is an actuator only in the sense that a building's foundation is an actuator against gravity — technically true, but not in the spirit of the word. I mention it for completeness and to flag that most "corrosion control" is, in control-theory terms, not control at all but design-time robustness.

[fn:: Coatings and CP are not independent — they are coupled through the "coating holiday," the defect in the coating that exposes bare metal. A 99.9%-intact coating still leaves 0.1% of the surface exposed, and on a large structure that exposed area concentrates all the CP current demand onto a few square centimeters, driving local current densities orders of magnitude higher than the design assumption. The classic failure is "cathodic disbondment": the over-polarized holiday region evolves hydrogen, the coating lifts at the edge, the holiday grows, the current demand grows, the cycle accelerates. This is a positive-feedback path between the open-loop actuator (coating) and the closed-loop actuator (CP) that nobody models as a coupled system because they belong to different engineering disciplines — the coating is a materials-science decision, the CP is an electrical one.]

The loop

Close the loop: $R_p$ (or the derived corrosion rate in mm/yr) is the measured variable; inhibitor dosing rate or CP current is the manipulated variable; the corrosion-rate target (e.g. < 0.1 mm/yr for a cooling-water system, or $E < -850$ mV vs Cu/CuSO$_4$ for a cathodically protected pipeline) is the setpoint. This is a slow loop — hours to days — with a highly nonlinear, time-varying plant: the inhibitor film accumulates and depletes, the surface roughness changes with exposure, temperature and flow rate couple in as load disturbances, and seasonal chemistry swings (chloride, sulfate, hardness) shift the gain by factors of two or more.

[fn:: Why PID is the default here, and why more sophisticated control is usually not worth it: the plant is too poorly modeled for MPC or LQR (you would need a validated film-formation kinetics model, which most facilities do not have), the bandwidth is so low that PID's robustness margins are more than sufficient (a loop with a 6-hour period does not need $\mu$-synthesis), and the operators understand PID, which matters more than control theorists like to admit. The honest failure mode of PID in this application is not poor tracking but integrator windup during inhibitor starvation or pump failure — the standard anti-windup fixes apply, but they require someone to have configured them, which they usually have not. See PID Control: Theory & Tuning.]

The dominant dead time in most inhibitor loops is not the transport delay (the pump-to-probe travel time, often minutes) but the film kinetics — the time for the inhibitor to reach the surface, adsorb, and form a barrier. This is a distributed, surface-limited process with a time constant of hours, and it is the reason the loop is fundamentally slow regardless of how fast the sensor polls.

[fn:: The setpoint itself is rarely a hard physical threshold but an economic-optimization compromise. A refinery might specify 0.075 mm/yr not because 0.076 mm/yr is dangerous — a 6 mm wall at 0.075 mm/yr lasts 80 years, and at 0.15 mm/yr still 40 years, both beyond the asset's design life — but because the incremental inhibitor cost of holding 0.075 is judged cheaper than the discounted risk-weighted cost of a heat-exchanger tube leak at year 15. The "controller" is thus tracking an economically derived reference, which drifts with chemical prices and risk appetite, not a fixed engineering limit. This makes the loop's objective function itself time-varying, a wrinkle that classical PID handles gracefully (the operator just changes the setpoint dial) but that any formal optimal-control formulation would have to model explicitly.]

The disturbance spectrum in these loops is wide: fast (seconds — a pump trip, a valve slam), medium (hours — a heat-load swing, a makeup-water change), and slow (seasonal — temperature, biocide demand, chloride ingress from a brackish source). The loop can only really attack the medium band; fast disturbances must be caught by alarms and manual intervention, and slow ones by periodic retuning. This separation of timescales is what makes the slow PID tolerable — it does not need to be fast, because the disturbances that matter to cumulative metal loss are themselves slow.

The pipeline CP example

Consider impressed-current cathodic protection on a buried steel pipeline. The rectifier is the actuator (it drives DC current through groundbed anodes into the soil and onto the pipe), the reference electrode at a test station at the soil interface is the sensor (it measures pipe-to-soil potential), and the target is $-850$ mV vs a Cu/CuSO$_4$ reference electrode — the NACE/SP0169 criterion, which is a regulatory setpoint as much as a technical one. The loop is: measure $E_{\text{pipe-to-soil}}$, compare to $-850$ mV, adjust rectifier output voltage.

[fn:: The $-850$ mV criterion is itself contested. It derives from empirical pipeline experience and a thermodynamic argument that below this potential the iron is in the immune region of the Pourbaix diagram at near-neutral pH. But the criterion can be over-conservative (wasting power and risking coating disbondment from hydrogen evolution at negative potentials) or under-conservative (in high-chloride or microbial soils where the threshold shifts). There is an "instant off" variant (measure the potential 0.5–3 s after interrupting the CP current, to remove the $IR$ drop in the soil) that is more accurate but cannot be done continuously, and a "true off" criterion that is more accurate still but requires full interruption, which defeats the purpose of protection. Every measurement is a compromise with the actuator being on.]

The distributed nature of the plant is the real difficulty: the pipeline is kilometers long, and the potential varies along it — close to the rectifier (over-potential, wasted), far from it (under-protection, corroding), and sensitive to soil resistivity, coating holidays, and stray currents from nearby railways or other CP systems. This is a distributed-parameter system, and the "one sensor, one actuator" architecture is fundamentally mismatched to it. The practical answer is multiple rectifier stations along the route, each with its own reference electrode, forming a set of loosely-coupled SISO loops instead of a true MIMO controller — a pragmatic decomposition that works because the coupling between stations is weak but that no control theorist would have designed from first principles.

A worked pipeline number: a 50 km buried steel pipeline (wall thickness 7.9 mm, diameter 610 mm) protected by one impressed-current rectifier with a groundbed delivering 8 A. The attenuation coefficient along a coated pipeline is small — call it $\alpha \approx 0.01$ km$^{-1}$ for a well-coated line with high-resistivity soil — so the potential at distance $x$ from the drain point follows roughly $E(x) \approx E_0 \exp(-\alpha x)$, and at 50 km the protection has decayed by $1 - \exp(-0.5) \approx 39\%$. If the drain point sits at $-1100$ mV (well-protected, arguably over-polarized and risking disbondment), the far end sees roughly $-670$ mV — above the $-850$ mV criterion and actively corroding. The fix is not a bigger rectifier (which only deepens the over-polarization near the drain point) but a second station at roughly the midpoint, splitting the line into two half-length segments each with acceptable attenuation. This is a spatial control problem solved by spatial actuator placement, not by tuning a single loop's gain.

[fn:: Stray current from DC traction systems (railways, trams) is the disturbance that keeps pipeline CP engineers awake. A DC railway a kilometer away can inject tens of amperes into a pipeline intermittently, driving the local potential hundreds of millivolts in either direction on a timescale of seconds — far faster than the CP rectifier's response. The defense is typically not feedback but rather drainage bonds (low-resistance connections that shunt stray current back to its source) combined with insulating joints to limit the affected length. This is feedforward / open-loop mitigation of a disturbance that feedback is too slow to catch.]

Storage tank bottoms

Aboveground storage tanks (ASTs) holding crude oil, refined product, or produced water present a variant: the floor is a thin (6–8 mm) steel plate in contact with soil or water on the underside and product on the upper side, and the corrosion of interest is on the soil side, which you cannot reach with a probe. The sensor here is indirect — either external CP reference electrodes measuring tank-to-soil potential around the periphery, or, increasingly, permanently installed sensor cables / mats beneath the floor that report a spatially averaged corrosion signal. The actuator is an impressed-current system with anodes buried in a ring around the tank or in a deep-well groundbed.

[fn:: The telluric-current problem applies here too but in a different register: large tank networks are effectively antennas, and geomagnetic disturbances (the same phenomenon that drives GIC risk in power grids) induce telluric currents in long tank farms that perturb CP readings over hours. The loop bandwidth needed to reject this is hours to days, which happens to be achievable — one of the few cases where the disturbance timescale matches the actuator's reach. Most CP systems ride through telluric events passively; active rejection is rare and arguably unnecessary given the slow plant dynamics.]

The fundamental difficulty is observability: you are protecting and measuring a surface you cannot directly inspect, and the only ground truth comes from internal inspections (MFL scanning of the floor) every 5–10 years, which is a calibration interval measured in half-decades. A CP loop that has drifted out of tune may not be discovered until the tank is opened for inspection — at which point the floor is already thinned.

[fn:: This is the corrosion-control equivalent of an open-loop observer with a 5-year correction step. No control theorist would accept a Kalman filter whose measurement update arrives once per half-decade, yet this is the operational reality for buried and hidden surfaces, and it is why "risk-based inspection" (RBI) is the dominant corrosion-management paradigm instead of "closed-loop control." RBI is, in essence, an open-loop scheduling framework that treats the inspection as the measurement and the repair/retubing as the actuator — a loop with a bandwidth of years. It is the honest admission that for hidden surfaces, you cannot close a fast loop, so you structure the slow one explicitly.]

Loop integrity and failure modes

A closed-loop corrosion system fails in characteristic ways that are distinct from process-control failures, and worth enumerating because they shape what "closed loop" can realistically mean here:

[fn:: The unifying theme is that every component in this loop is itself a corrosion-prone electrochemical device. The sensor corrodes, the reference electrode polarizes, the groundbed anode consumes itself. There is no vantage point outside the chemistry from which to observe it cleanly — the measuring instrument is made of the same stuff as the thing it measures. This is not unique to corrosion (it is true of any in-situ chemical sensor) but it is unusually severe here because the environment is the corrosive process itself. A thermocouple in a furnace is at least made of a noble alloy; an LPR probe is mild steel in the same water it is measuring.]

Cooling water treatment

The most common industrial corrosion loop, by sheer count of installations, is cooling water treatment: an inhibitor (phosphate, zinc, azole for copper, phosphonate for scale) dosed into the circulating cooling water, monitored either by coupon weight loss (mounted coupons removed and weighed monthly — open-loop, retrospective, a lagging indicator closer to a post-mortem than a measurement) or by online LPR (a probe in a bypass stream, polling every 15–60 minutes — closed-loop, current, but giving you the rate at the probe location, not at the heat exchanger tubes where it matters).

[fn:: The coupon-versus-LPR debate is a measurement-bandwidth debate in disguise. Coupons integrate over 30–90 days and give a spatially and temporally averaged rate that is the ground truth for cumulative metal loss; LPR samples every 15 minutes and gives an instantaneous rate at one point that may or may not represent the exchanger. The two answer different questions — "how much metal did I lose this quarter?" versus "is the rate rising right now?" — and a mature program uses both, treating the coupon as the low-bandwidth calibration of the LPR's high-bandwidth signal. Closing the loop on LPR alone risks chasing transients; closing it on coupons alone means you react to a problem a month after it happened.]

Worked example: a cooling tower circulating 10,000 m³/h of water, with a corrosion-rate setpoint of 0.075 mm/yr and an LPR probe reading 0.12 mm/yr (the plant is corroding 60% above target). The inhibitor (say, a zinc-phosphate blend at 15 mg/L maintenance dose) is dosed by a metering pump with a range of 0–10 L/h of a 10% solution. At the maintenance dose the pump runs at roughly $10{,}000 \times 10^3 \times 15 \times 10^{-6} / (0.1 \times 10^3) = 1.5$ L/h — call it 2 L/h to account for bleed-off, so we have ample actuator headroom. The film-formation lag is roughly 4–8 hours: you dose, the inhibitor adsorbs, the rate drops — but not for half a shift. The bleed-off (blowdown) valve sets the concentration factor (cycles of concentration), which couples the corrosion loop to the scale-and-deposition loop, which has its own setpoint (the Langelier Saturation Index, or more crudely, a conductivity target). Disturbances: the makeup water hardness varies seasonally (higher in summer drawdown), the heat load varies with process demand, and a process leak (hydrocarbons into the cooling water, a tube rupture) can destroy the inhibitor film in minutes while the LPR loop takes an hour to notice. This is a loop that is closed, technically, but the disturbance rejection bandwidth is on the order of hours while the disturbance rise time can be minutes — a fundamental mismatch that explains why cooling-water failures are still common despite the instrumentation existing for decades.

[fn:: The coupling between corrosion control and scale control is a genuine MIMO problem masquerading as two SISO loops. Raising the inhibitor reduces corrosion but the same chemistry (phosphate, alkalinity) that passivates steel also precipitates calcium — so the actuator that helps one loop hurts the other. In practice operators run both loops conservatively and accept the inefficiency, because the cost of an extra mg/L of inhibitor is negligible next to the cost of a fouled exchanger bundle. The control-theoretic optimum is never pursued because the economic gradient is shallow.]

A second worked number for the dosing math: if the LPR reading climbs from 0.12 to 0.18 mm/yr after a heat-load excursion, and the empirically tuned loop gain is roughly $-0.3$ (mm/yr) per (L/h) of dosing above baseline (negative because more inhibitor lowers rate), then to return from 0.18 toward the 0.075 setpoint the controller commands an additional $(0.18 - 0.075) \times (1/0.3) \approx 0.35$ L/h — modest, well within the 10 L/h pump capacity, and delivered in seconds by the pump even though the effect will not register for 4–8 hours. This actuator-fast / plant-slow asymmetry is the defining feature of the loop and the reason derivative action is useless (it amplifies noise on a signal whose meaningful bandwidth is sub-millihertz) while integral action is essential (it accumulates the slow error that the plant takes hours to correct).

Comparison to battery management

The closest analog in electrical engineering is battery management (Battery Management System Control): there too you have an electrochemical plant (the cell) whose state of health you cannot measure directly, only infer from voltage, current, and temperature; there too the "actuator" is the charge/discharge current that is also the perturbation you are measuring; there too the dominant dynamics are slow (hours), nonlinear (the open-circuit-voltage curve), and state-dependent (capacity fades with cycles). Yet BMS control is a mature, actively-closed loop with sophisticated observers (Kalman filters on equivalent-circuit models), while corrosion control remains a chemist with a clipboard. The difference is not technological — the sensor and actuator primitives exist in both — but economic and institutional: a battery is a sealed, owned, warrantied unit whose failure is catastrophic and immediate, so the loop gets closed; a pipeline is a distributed, regulated asset whose failure is slow and statistical, so the loop stays open until a leak.

[fn:: One genuine transfer is the equivalent-circuit / impedance-modeling heritage. EIS on corroding electrodes and EIS on battery cells share the Randles-circuit lineage, the same Nyquist-plot interpretation, and broadly the same fitting machinery. A corrosion engineer and a battery engineer can read each other's impedance spectra. That the two communities do not talk to each other is, again, a sociological fact instead of a technical one — and it is the kind of gap that a well-placed review paper or a joint session at a conference could meaningfully narrow, though nobody has found it worth their career to do so.]

The contrarian case for corrosion remaining open-loop is worth steelmanning once more: battery cells are sealed and uniform, which licenses a lumped-parameter observer; corroding plant is open, distributed, and heterogeneous, which does not. A Kalman filter that works on a cell assumes the cell is the model; a corroding pipeline is emphatically not its model, and no amount of estimation finesse will conjure a state estimate for a surface you cannot see. The honest conclusion may be that corrosion control is inherently a semi-open loop — that the information-theoretic limits set by hidden surfaces and distributed states mean a fully closed loop is unattainable for much of the asset base, and that the field's inspection-centric culture is not backwardness but a grudging accommodation of those limits.

The honest gap

Most industrial corrosion "control" is, in truth, open-loop monitoring with periodic manual adjustment. An operator reads the LPR probe at the morning meeting, eyeballs whether the rate has crept up, and tells the chemical vendor to bump the dosing pump by 10%. The closed loop exists in principle — the sensors, actuators, and setpoints are all present — and in a handful of advanced installations (refineries with fully integrated cooling-water automation, some offshore platforms with closed-loop CP), but the field is culturally closer to inspection than to control. Corrosion management is organized around inspection intervals (NACE risk-based inspection, API 510/570), not around loop tuning.

[fn:: The economic argument for keeping the loop open is stronger than control engineers usually concede. A closed-loop corrosion controller that misbehaves can do real damage: a runaway integral term can over-dose inhibitor into a system, precipitating scale that fouls the heat exchangers the loop was meant to protect, or can drive CP current high enough to blister coatings. The failure mode of /over/-control is often more expensive than the failure mode of /under/-control, because under-control at least fails slowly and visibly. This asymmetry — catastrophic over-action versus gradual under-action — biases the whole field toward conservatism, manual oversight, and intentionally loose tuning. It is not irrational; it is a rational response to an asymmetric loss function that the formal control literature, with its symmetric quadratic costs, does not capture well.]

[fn:: The cultural argument, which I steelman because I think it is partially right: corrosion engineers are trained as chemists and materials scientists, not as control engineers, and the two communities rarely overlap at the level of shared vocabulary or professional societies. NACE (now AMPP) and ISA/IEEE are different worlds, different conferences, different journals. A corrosion engineer who reaches for a Bode plot is rare; a control engineer who reaches for a Pourbaix diagram is rarer. Each side has good reasons — the chemist knows that the plant is too nonlinear and poorly characterized for the control engineer's models, and the control engineer knows that the chemist's "control" is a dosing pump on a timer. Both are right, which is why the loop stays open. Bridging this requires someone bilingual, and such people are scarce and usually expensive enough that the open-loop status quo persists until a failure forces the issue. The adjacent case of battery management (Battery Management System Control) is instructive: there, the cell and the controller were developed by overlapping engineering communities, and closed-loop electrochemical control is the norm instead of the aspiration.]

Related