Midstream API 653 Program Audits: What an Outsourced Level III Actually Checks
An outsourced ASNT Level III doesn't re-inspect your tanks, they audit the program that inspects them. Here's exactly what a midstream API 653 program audit covers.
Why Midstream Operators Bring in an Outside Level III
A midstream terminal or pipeline operator running an internal API 653 tank inspection program usually has competent people running it — a staff inspector or two, sometimes an in-house Level II, occasionally a Level III on payroll if the tank count justifies it. What that internal team almost never has is distance from its own work. The person who wrote the inspection procedure, scheduled the intervals, and reviewed the reports for the last five years is structurally the wrong person to catch the drift that's crept into that same program over those five years — not because they're careless, but because familiarity is exactly what makes small, compounding deviations invisible from the inside. That's the gap an outsourced ASNT Level III program audit is built to close, and it's a distinct engagement from routine third-party inspection: the Level III isn't there to inspect a tank, they're there to inspect the program that inspects the tanks.
Midstream operators — terminal companies, pipeline operators with tank farms at pump stations and delivery points, gathering and processing companies with produced-water and condensate storage — have a specific version of this problem. Their tank populations are often smaller and more geographically scattered than a refinery's, which means the internal inspection function is thinner, procedures get written once and rarely revisited, and the operator's own quality assurance oversight of the tank program is often folded into a broader HSE or reliability role rather than staffed by a dedicated API 653 program owner. A periodic outsourced Level III audit is how a midstream operator gets an honest read on program health without carrying that overhead full-time.
What "Auditing the Program" Actually Means
An API 653 program audit is not a re-inspection of tanks. It's a structured review of the system that produces inspections, and it breaks down into five areas an outsourced Level III will methodically work through.
1. Written Inspection Procedures Against Current Code Edition
API 653 has gone through multiple editions and addenda, and a program's written procedures need to reflect the edition the operator is actually committed to following — not the edition that was current when the procedure was first written. A Level III auditor checks whether internal procedures correctly reference current inspection interval formulas (which depend on corrosion rate, per Section 6), current minimum thickness calculation methods, and current out-of-service inspection triggers. It's common to find a midstream operator's internal procedure still citing interval logic or acceptance criteria from an edition two revisions old, quietly carried forward because nobody's job was to notice.
2. Interval Calculation and Scheduling Logic
API 653 external inspection intervals are capped based on tank design and corrosion allowance (with a maximum of five years absent a corrosion-rate-based justification for extending it, per the RCA — remaining corrosion allowance — calculation in Section 6.3.2), and internal inspection intervals are calculated from measured or estimated corrosion rates against the minimum required thickness. A program audit checks whether the operator's scheduling system is actually applying that formula correctly per tank, or whether intervals have calcified into a flat default (every tank inspected internally every ten years, for instance) that isn't individually justified by that tank's actual corrosion data. This is one of the most common findings in a midstream audit: a scheduling shortcut adopted years ago for administrative simplicity that no longer matches what the corrosion data on specific tanks actually supports.
3. Inspector Qualification Records
The audit verifies that every technician who performed inspection work credited in the operator's tank files actually held a current, applicable qualification at the time the work was done — API 653 certification for the certified inspector of record, and ASNT SNT-TC-1A qualification at the appropriate level for the NDT methods performed (UT thickness gauging, MFL floor scanning, PT or MT on repair welds). It's a records exercise as much as a technical one: a Level III auditor is checking dates on certificates against dates on inspection reports, looking for gaps where a technician's qualification lapsed between two inspection cycles without anyone catching it internally.
4. Report Quality and Traceability
A midstream operator with tanks at a dozen scattered sites, inspected over a decade by a rotating mix of internal staff and third-party contractors, frequently has an inconsistent report archive — different formats, different levels of detail, some findings documented thoroughly and others summarized in a paragraph with no supporting data attached. The audit checks whether reports contain enough raw data (thickness grid values, not just summary statements) to allow a future inspector to independently recalculate corrosion rates and remaining life, rather than having to trust a prior inspector's conclusion at face value. This traceability requirement is what makes a tank's inspection history defensible under a later regulatory review or, in a worse case, a legal discovery process following an incident.
5. Repair and Alteration Documentation
Any repair or alteration performed under API 653 has its own documentation requirements — welding procedure qualification, NDT of repair welds, and sign-off against the code's repair provisions. A program audit checks that repair records are complete and correctly filed against the specific tank and location, not just noted in passing in an inspection report's narrative summary. Missing or incomplete repair documentation is one of the more serious findings a Level III audit surfaces, because it directly affects whether a tank's current fitness-for-service status can be substantiated.
What a Typical Finding Set Looks Like
A representative midstream API 653 program audit across a modest tank population — say, twenty to forty tanks across several terminal sites — commonly surfaces a mix of findings like these:
- Two or three tanks where the internal inspection interval was calculated using an outdated corrosion rate that hasn't been updated since the last internal inspection, even though a more recent external inspection produced new relevant data.
- One or two technicians whose ASNT qualification records on file don't clearly establish current status for the specific method credited on a given report.
- Inconsistent settlement survey documentation — performed rigorously at some sites, done informally or skipped at others, with no documented justification for the difference.
- A handful of older reports lacking the raw thickness grid data needed to independently verify the stated corrosion rate, meaning the operator is trusting a conclusion it cannot re-derive.
- Repair records that reference a weld repair in the inspection narrative but lack the corresponding NDT report or welding procedure qualification record in the file.
None of these individually is catastrophic. Collectively, they represent exactly the kind of program drift that goes unnoticed under normal operating conditions and becomes a serious liability the moment a regulator, an insurer, or an incident investigation looks closely at the program's actual rigor rather than its reputation.
How the Engagement Is Scoped
A midstream program audit is typically scoped around three inputs: the operator's tank count and geographic spread, the number of years of inspection history under review, and whether the audit is a standalone health check or being performed ahead of a specific trigger — a merger or acquisition due diligence process, an insurer's request following a claim elsewhere in the industry, or a planned expansion of the tank farm that will bring new regulatory scrutiny. The Level III auditor typically starts with a document review — procedures, inspector qualification files, and a sample of inspection reports across the tank population — before determining whether field verification (a site visit to spot-check a subset of tanks against their documented condition) is warranted. Not every audit requires a field component; a document and records audit alone often surfaces the majority of program-level findings, since most of what's being evaluated is whether the paperwork and the process hold up, not whether any single tank has an undiscovered defect.
The deliverable is a findings report ranked by severity — distinguishing a genuine fitness-for-service concern from a documentation gap that's administratively serious but doesn't indicate an actual undetected integrity problem — along with specific, actionable recommendations: procedure language to update, records to reconstruct or supplement, and, where relevant, a recommendation for follow-up field verification on specific tanks where the document review couldn't resolve a question.
What's Driving the Timing of These Audits
API 653 itself isn't a federal regulation with a mandated third-party audit cadence for midstream tank farms the way, say, PHMSA pipeline integrity rules operate for transmission lines — it's an industry consensus standard that becomes binding through contract, insurance requirements, or state-level adoption. That means the trigger for a program audit is usually one of a few practical pressures rather than a fixed regulatory calendar. Insurers writing property and environmental liability coverage on tank farms increasingly send their own risk engineers to review a program's rigor before renewal, and a poor showing there can move a premium more than a single tank's condition would. Facilities operating under an EPA Spill Prevention, Control, and Countermeasure (SPCC) plan need their tank integrity program to hold up as part of that broader environmental compliance picture, since a tank failure is exactly the event an SPCC plan exists to prevent. And any merger, acquisition, or private equity transaction involving midstream tank assets brings a buyer's technical due diligence team through the inspection program's records looking for exactly the kind of gaps a Level III audit is designed to surface — finding them yourself, on your own timeline, is considerably better than having a buyer's consultant find them during a deal.
A Representative Audit Timeline
For a midstream operator with tanks spread across four or five terminal sites, a document-and-records-phase audit typically runs on a timeline like this: an initial one- to two-week document collection period where the operator gathers procedures, inspector qualification files, and a representative sample of inspection reports spanning at least one full inspection cycle per tank class; a review period where the Level III works through that documentation against current code requirements and flags questions; a short follow-up window for the operator to supply any missing records or clarify ambiguous entries; and a findings report with a severity-ranked list of gaps and recommended corrective actions. If field verification is warranted based on what the document review surfaces, that gets scoped as a separate, targeted site visit rather than blanket re-inspection of the entire tank population — keeping the engagement focused on the specific tanks or specific questions the records review couldn't resolve on its own.
Why This Works Better as an Outsourced Engagement
The value of bringing in an outside ASNT Level III consulting engagement specifically for this work, rather than asking an internal Level III (where one exists) to self-audit, comes down to independence and current exposure. An outside Level III auditor who works across multiple operators' tank programs sees a wider range of how procedures drift, where documentation gaps commonly hide, and how other operators have structured defensible interval justifications — pattern recognition an internal inspector, however skilled, doesn't get from working one company's program in isolation for years. That external perspective is also what carries weight with a regulator, an insurer, or an acquiring company's due diligence team: an audit performed by the same people who run the program day to day doesn't carry the same evidentiary weight as an independent review.
For midstream operators building out this function for the first time, pairing a program audit with a broader look at how inspection records are managed is often worthwhile — a program that's currently held together with spreadsheets and a shared drive benefits from moving to Atlantis NDT ERP for ongoing certification tracking, scheduling, and report archiving, and from digital twin visualization of tank inspection history for sites with enough asset complexity to justify it. But the audit itself should come first — you want to know exactly what's wrong with the current program before deciding what to replace it with.
The Cost of Skipping This Step
The operators who skip periodic program audits almost never do so out of a considered risk decision — it's more often an assumption that "the inspections are getting done, so the program must be fine." That assumption conflates two different things: whether individual inspections are being performed, and whether the program that schedules, qualifies, and documents those inspections is structurally sound. A tank can be inspected on schedule by a qualified technician and still sit inside a program with weak documentation traceability, inconsistent interval justification, or gaps in repair records — none of which show up until someone with a program-level view goes looking. By the time that someone is a regulator following an incident, an insurer denying a claim over a documentation gap, or a buyer's due diligence consultant during a deal, the cost of the original gap has multiplied well beyond what a periodic audit would have cost to catch it early.
Getting Started
If your tank inspection program has grown organically over several years, been managed by a rotating cast of internal staff, or simply hasn't had an outside set of eyes on it since it was first stood up, a program audit is a relatively low-cost way to find out where you actually stand before a regulator, insurer, or acquisition due diligence process finds out for you. Atlantis NDT's ASNT Level III consulting is affordable, accessible, and fully customizable to the size of your tank population — contact us for a tailored quote and scope discussion.
Atlantis NDT Products & Services
Atlantis NDT pairs field expertise with software: NDT inspection management software — Atlantis ERP, a digital twin platform for asset integrity, and NDT reporting software. Build your team with NDT training & certification (ASNT SNT-TC-1A) and ASNT certification pathways, or bring in ASNT Level III consulting. Affordable, accessible, fully customizable — book a free consultation.
Running this as a programme, not a one-off
If you are responsible for an inspection programme rather than a single job, the recurring problem is rarely the code — it is keeping measured thickness, damage-mechanism assignment and next-inspection dates in one defensible place. Asset integrity management software covers keeping measured thickness readings per CML in one place, so the RBI (API 580/581) and fitness-for-service (API 579) work your integrity team or its specialists carry out starts from measured data rather than default rates. Atlantis supplies the NDT data and the software to hold it; it does not perform RBI or FFS assessments.
Atlantis NDT Products & Services
Atlantis NDT pairs field expertise with software: NDT inspection management software — Atlantis ERP (certification tracking, work orders, method-specific reporting on every business app you need), a digital twin platform for asset integrity (3D corrosion mapping and inspection-data overlay), and NDT reporting software. Build your team with NDT training & certification (ASNT SNT-TC-1A) and ASNT certification pathways, or bring in ASNT Level III consulting for written practices, procedures and audits — plus independent inspection data review on API 510/570/653-governed assets. Capture as-built reality with 3D laser scanning services. Affordable, accessible, fully customizable — book a free consultation.