Building a CML Register That Is Still Trustworthy in Ten Years
A corrosion rate computed from two readings that were not taken at the same place is not a corrosion rate. It is a number with a unit.
The corrosion monitoring location register is the foundation every integrity decision rests on, and it is almost always the weakest part of the programme. Locations get added inconsistently by successive contractors, identifiers get reused, physical marking fades, and within a few inspection cycles the thickness history is a set of readings that cannot be proven to share a location. Everything downstream — corrosion rates, remaining life, next inspection interval, fitness-for-service — inherits that uncertainty.
Identity is the property that matters most
A CML identifier has to be unique, permanent and never reused. That sounds trivial and is routinely violated: identifiers get renumbered when a circuit is re-drawn, reused after a component is replaced, or duplicated across units because the numbering restarts per drawing. Once identity is ambiguous, the time series is broken and no amount of software fixes it retrospectively.
Practical rules that hold up: allocate identifiers centrally rather than per contractor, never renumber, retire rather than reuse when a component is replaced, and record the physical location precisely enough that a different technician can find the same spot without the previous one present — which usually means a description plus a measured offset from a permanent feature, not just a paint mark.
Placement should follow the damage mechanism
- Assign the credible damage mechanisms per API RP 571 for the circuit before placing locations, not after.
- Place against mechanism-specific susceptibility: elbows and tees for erosion-corrosion, dead legs and low points for under-deposit and MIC, insulation penetrations and terminations for CUI, hot zones for sulfidation and HTHA.
- Distinguish CMLs intended for trending from examination points used for one-off condition assessment; mixing them corrupts the trend.
- Record the measurement grid at each location, not just a single reading, where the mechanism is localised.
- Revisit placement when process service changes — a circuit that changed feedstock has different credible mechanisms.
Surviving contractor turnover
Most CML registers degrade at contractor handover. The incoming contractor cannot find the locations, so they place new ones nearby, and the register grows a parallel set of near-duplicates. Preventing that requires the register to belong to the asset owner rather than to whoever holds the inspection contract, with location descriptions good enough to be found by someone who has never been on the site.
Where a register has already degraded, the honest fix is a documented re-baseline: identify which historical readings can be confidently attributed, retire the ambiguous ones, and record the decision and its date. That is defensible. Continuing to compute corrosion rates across ambiguous locations is not.
Keeping it trustworthy
- Store readings against the CML, never against a report file or a drawing revision.
- Compute corrosion rates from the full time series with outlier flagging, not from first and last readings.
- Flag statistically implausible readings for review rather than silently averaging them away.
- Retain the instrument, technician and procedure provenance per reading so a suspect trend can be investigated.
- Audit the register annually — a percentage of locations physically re-found and verified, not just reviewed on screen.
Frequently Asked Questions
How many CMLs should a circuit have?
Enough to represent the credible damage mechanisms, which is a technical judgement rather than a formula. What consistently goes wrong is uniform placement — the same number of locations per circuit regardless of susceptibility — which over-inspects benign circuits and under-inspects the ones that will actually fail. Placement driven by API RP 571 mechanism assignment gives better coverage for the same or less effort.
What do we do with a register we no longer trust?
Re-baseline deliberately and document it. Identify which historical readings can be confidently attributed to a specific physical location, retire ambiguous identifiers rather than reusing them, and record the date and rationale for the baseline. Auditors accept a documented re-baseline; they do not accept corrosion rates computed across locations that may not be the same place.
Should CML data live with the contractor or the owner?
With the owner, always. The register outlives any inspection contract, and registers that live with successive contractors are how near-duplicate locations and broken time series get created. Contractors should read from and write to the owner's register rather than maintaining their own copy.
How does the register relate to a digital twin?
The twin is what makes the register spatial rather than tabular: each CML sits at a location on the asset model with its thickness history, computed corrosion rate and governing damage mechanism attached. That changes both trend interpretation and inspection planning, because clustering and spatial pattern become visible in a way a spreadsheet of identifiers never shows.
See it running on your own workflow
Thirty minutes, your job types and your reporting formats, co-presented by an ASNT NDT Level III. Affordable, accessible, fully customizable — request a demo and a tailored quote.
Related: Asset integrity management software · Atlantis Digital Twin platform · Corrosion tracking module · API 570 certification guide