This is Article 6 in an ongoing series examining America's abandoned and orphaned well problem.

Article 5 showed why financial assurance for abandoned oil and gas wells was never designed to survive time. Bonding systems were calibrated around short operational horizons and assumed closure, not decades of material degradation, deferred failure, and long-tail liability.

A reasonable question follows. If the mismatch is so structural, why does the system continue to operate as if it were under control? The answer isn't denial or negligence. It's triage.

Across virtually all oil and gas producing jurisdictions, abandoned and orphaned wells are managed using risk-based prioritization frameworks. These frameworks determine which wells get inspected, monitored, or plugged first when funding, staffing, and data are limited. They're sometimes referred to informally as "BESSY," though no single formal model exists. What matters isn't the name but the logic, because that logic explains how bonding levels can appear defensible even as long-term liability continues to accumulate.

The logic of regulatory triage

Risk-based prioritization frameworks are designed to answer a narrow, operational question. If a well is leaking or fails tomorrow, where would harm be most immediate and visible? To answer that, regulators typically evaluate evidence of active leakage in the form of oil, gas, brine, or pressure; proximity to people, buildings, and drinking-water sources; land use and population density; well age, construction era, and record completeness; and the anticipated severity of consequences if failure is confirmed. The result is a ranked list of wells for inspection or plugging.

While details vary by jurisdiction, the pattern is remarkably consistent. Texas uses a published weighted scoring system that heavily emphasizes groundwater protection and active leaks. New Mexico scores wells across more than twenty criteria, automatically elevating any active leaker to the highest tier. California explicitly adds points for proximity to homes and disadvantaged communities. On federal lands, the Bureau of Land Management applies a numerical risk matrix to prioritize orphan wells for plugging. There's no national standard, but the convergence is clear.

This approach is rational. It allows agencies to allocate scarce funds defensibly, respond to complaints, and demonstrate risk-based oversight to legislatures and auditors, even when records are incomplete or decades old. Used as intended, triage works. The trouble starts when we expect it to answer questions it was never built to address.

Triage versus reliability: snapshot risk and time-dependent failure

Risk-based triage evaluates present exposure. Reliability engineering evaluates future failure. That distinction isn't semantic; it's structural.

Anyone who has re-entered older wells knows they aren't static assets. They're degrading systems governed by time-dependent processes: cement carbonation, sulfate attack, and micro-annulus development; casing corrosion driven by fluid chemistry, pressure, and electrochemistry; progressive loss of zonal isolation; and delayed pressure migration following barrier compromise. These mechanisms don't produce steady-state risk. They produce increasing failure probability over time.

In reliability terms, abandoned wells exhibit long wear-out tails. The most serious failures are often hidden, slow, quiet, and invisible until they intersect with a pathway or receptor. Triage frameworks don't model this behavior. They implicitly assume that the absence of surface evidence implies lower risk. That assumption makes sense for emergency response, but it doesn't hold for lifecycle analysis. Triage asks where harm would show up today. Reliability asks which assets will fail given enough time. Those are different questions, with different answers.

Why triage can't support bonding adequacy

Bonding systems exist to answer a fundamentally actuarial question. What is the expected future cost of managing this well or portfolio over its remaining life? Risk-based triage can't answer that, for three reasons.

First, triage ignores time. Bonding is a multi-decade obligation, while triage is a moment-in-time ranking. A well that appears quiet today may represent a near-certainty of future cost, but it won't score high until failure becomes visible.

Second, triage underweights invisible degradation. Cement degradation and casing corrosion have no reliable surface signal, and pressure migration can remain confined for decades. These processes continue whether or not a well is prioritized.

Third, triage biases toward proximity rather than inevitability. Remote wells score low until failure is obvious. Those same wells dominate future orphan inventories once operators exit and liabilities mature.

The outcome is predictable. Bonds appear sufficient when assessed against current risk screens, actual future costs diverge as degradation accumulates, and the shortfall emerges after operators are gone. That isn't a flaw in triage itself. It's a mismatch between what the tool does and what it's quietly expected to do.

Risk-based oversight and the quiet deferral of liability

Regulators often describe their programs as risk-based, and within the limits of triage, that's accurate. Wells posing immediate threats to people or water are prioritized, and visible hazards are addressed. What triage doesn't do is eliminate long-term failure. It defers it. In practice, this shows up as annual plugging lists that look reasonable on paper but age poorly once operators exit.

Across states and federal programs alike, the same pattern emerges. Near-term hazards are managed credibly, quiet wells continue to degrade unattended, bonding levels remain static while risk grows, and liability migrates forward in time. No single decision causes this outcome. It's what happens when tools designed for prioritization are treated, implicitly or explicitly, as proxies for lifecycle risk. From the outside, the system appears controlled, and that appearance is itself part of the problem.

From governance back to physics

Risk-based prioritization determines which wells receive attention. It doesn't determine which wells leak. Subsurface fluids don't respond to inspection schedules, funding cycles, or scoring frameworks. Migration is governed by pressure, permeability, chemistry, and time.

The next article examines what moves through these systems during that deferral, namely methane, benzene, and radium, and why their behavior is dictated by physics rather than prioritization.

About this article in the series

This article doesn't argue that risk-based triage is wrong. It argues that triage is insufficient when extended beyond its design envelope. Understanding that distinction is essential to understanding why the bonding gap persists and why long-term liability continues to grow even under risk-based oversight.


Next in the series: Article 7: "Methane, Benzene, and Radium: What's Actually Leaking from Abandoned Wells"


Sources and Further Reading