Migrating Years of Thickness History Into a Food Plant Registry

A food and beverage CML registry covers the regulated utility side of the plant: anhydrous ammonia refrigeration, steam and condensate, CIP chemical lines, CO2 and brine systems, and pressure vessels. Migrating legacy history into it means re-deriving minimum thicknesses, recomputing corrosion rates from readings rather than importing stored ones, and preserving every legacy location description as a searchable alias.

Food plants arrive at this problem from a particular direction. The thickness history exists, sometimes twenty years of it, but it lives in a per-plant spreadsheet, in an ageing thickness data package, or in the inspection contractor's own database. Because procurement rotates contractors every few years, the history has usually been rebuilt more than once, and each rebuild reset the location numbering. Meanwhile the ammonia refrigeration system sits under process safety management, so this data is compliance evidence with an audit cycle attached, and the migration cannot end with a system nobody can reconcile against the old records. The work that decides success is unglamorous: unit detection, date parsing, minimum thickness re-derivation, alias preservation and a reconciliation report. Everything that goes wrong in these projects goes wrong in those five areas, and every one of them is cheap to fix before go-live and expensive afterwards.

Source: Sources: OSHA 29 CFR 1910.119 process safety management, including the mechanical integrity requirements at 1910.119(j) and the three-year compliance audit cycle at 1910.119(o); EPA Risk Management Program 40 CFR Part 68; ANSI/IIAR 2 and ANSI/IIAR 6 for closed-circuit ammonia refrigeration design and for inspection, testing and maintenance; API 570 piping inspection methodology and API 510 for pressure vessels where adopted as recognised practice; ASME B31.5 refrigeration piping; ASME Section VIII Division 1 and NBIC NB-23 for repairs and alterations; ASTM A269 and A270 for stainless tubing; 3-A Sanitary Standards and ASME BPE for product-contact equipment; ASME Section V for ultrasonic examination.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Legacy field mapping traps in a food and beverage thickness migration
Legacy fieldHow it usually arrivesWhat it becomes if imported as-isCorrect handling
Wall thickness unitsMixed mils, inches and millimetres inside one workbook, sometimes inside one columnA 0.065 inch sanitary tube wall stored as 0.065 millimetres, or 65 mils read as 65 inchesDetect per sheet and per column, convert on import, retain the original string in an audit field
Reading dateExported CSV with ambiguous day and month orderingTwo readings dated 03/04 and 04/03 invert the interval and produce a negative or absurd corrosion rateParse against the export locale, then reject any computed interval under thirty days or longer than the asset's life
Stored corrosion rateA single number the old system computed under its own short-term or long-term ruleTwo different next-due dates for the same location once the new system recomputes from readingsImport as a reference value only, always recompute from readings, and report every disagreement above ten per cent
Minimum thicknessA company alert threshold typed into the retirement thickness field years agoA large share of the plant reads as condemned on day one and the due list loses all credibilityRe-derive from design basis and code, and flag every location whose legacy value differs materially
CML identifierPlant-local sequences that collide the moment workbooks merge, such as CML-001 at four sitesReadings silently attach to the wrong plant's location and two histories interleaveNamespace by site and system, and keep the legacy identifier as a permanent searchable alias
Location descriptionFree text such as elbow east of pump 3, second floor, syrup lineStructured location fields left empty and the point becomes unfindable within one crew rotationPreserve the string verbatim, build structured fields alongside it, and never overwrite the original
Each of these is inexpensive to resolve before go-live and expensive to resolve afterwards, because after go-live the corrupted values have already been used to issue work. The migration plan should name an owner and a specific test for every row.

Decide what belongs in the registry before you move anything

The most expensive mistake in a food and beverage migration is made in the first week, when somebody decides that everything in the legacy workbook should come across. Food plants contain two entirely different inspection worlds, and only one of them is a thickness monitoring domain. The product-contact side, the sanitary tube, the fillers, the pasteurisers, the tanks with polished internals, is governed by 3-A Sanitary Standards and, in the more pharmaceutical-adjacent plants, ASME BPE. Its integrity questions are surface finish, drainability, gasket crevices, weld heat tint and cleaning validation. It is monitored by swab, by riboflavin coverage test, by ATP, by borescope. It is not monitored by trending wall loss.

The utility side is where thickness monitoring belongs, and it is a substantial scope in its own right: anhydrous ammonia refrigeration piping and vessels, steam and condensate, boiler external surfaces and supports, CIP caustic and acid circuits, CO2, glycol and brine, compressed air receivers, and often a wastewater pretreatment plant with its own vessels and chemical feed. That inventory is genuinely at risk of wall loss and, in the case of ammonia, sits under process safety regulation.

Migrating the sanitary side into a thickness registry does not merely waste effort. It creates thousands of locations that will never be read, which permanently distorts every coverage and completion metric the system produces. A due list that is ninety per cent theoretical is a due list the plant learns to ignore, and once that habit forms it applies to the ammonia locations as well. Scope the migration to what will actually be measured, and record the rest in the asset register without monitoring locations.

Ammonia refrigeration is the regulated core of the migration

In most food and beverage plants the reason a formal mechanical integrity programme exists at all is anhydrous ammonia. Above the threshold quantity, the system falls under OSHA's process safety management standard at 29 CFR 1910.119 and the EPA's risk management programme at 40 CFR Part 68. The mechanical integrity element at 1910.119(j) requires written procedures, trained personnel, and inspection and testing that follows recognised and generally accepted good engineering practice, with documentation of each inspection including the date, the person, the equipment identifier, the technique and the results.

For closed-circuit ammonia refrigeration, the recognised practice is ANSI/IIAR 6, with IIAR 2 governing design. IIAR 6 sets out inspection, testing and maintenance tasks and their frequencies, but it does not hand you a condition monitoring location grid the way API 570 does for process piping. In practice, operators adopt API methodology for the thickness element of the programme and run it alongside the IIAR task schedule. That hybrid is where migration errors hide, because legacy spreadsheets frequently carry an API piping class that a contractor assigned years ago and that was never reconciled against the IIAR programme the plant actually runs.

The dominant damage mechanism also shapes what the registry has to hold. On a cold ammonia system, the threat is external: corrosion under insulation on low-temperature lines where vapour drive and cyclic operation keep the insulation wet, concentrated at penetrations, valve boxes, hangers and pipe supports. That means many monitoring locations are at supports and at insulation breaches, that inspection frequently requires insulation removal and reinstatement, and that profile radiography may be the measurement rather than contact ultrasonics. A registry that cannot record inspection method, insulation removal requirement and support detail per location cannot plan this work at all.

Sanitary tube is not schedule pipe, and the mapping error is silent

Where the migration does legitimately touch stainless tube, on a CIP circuit or a utility line built from sanitary components, there is a specific and very common mapping failure. Process pipe is specified by nominal pipe size and schedule. Sanitary tube is specified by outside diameter and gauge. A two inch outside diameter sixteen gauge tube has a wall of roughly 0.065 inches. Two inch schedule 10S pipe is around 0.109 inches and schedule 40 is thicker still.

A migration script that recognises the string two inch and looks up a schedule table therefore assigns a baseline the tube never had and a minimum thickness that is thicker than the tube's original wall. Every location on that line immediately reads as being below retirement thickness. If the exception is investigated, the migration loses a week. If it is not, the plant either issues replacement work it does not need or, more commonly, learns to dismiss alarms from that system, which is the worse outcome.

The thin wall also changes measurement practice in a way the registry should capture. On 0.065 inch material, a measurement uncertainty of a few thousandths is a meaningful fraction of the wall, so probe type, calibration block and whether the reading was taken through a coating matter more than they do on quarter-inch carbon steel. Requiring method and probe on the reading record is not administrative overhead here. It is the difference between a trend and a scatter plot.

The legacy shapes you will meet, and who actually owns them

Four legacy shapes account for most food and beverage migrations. The first is a workbook per plant, maintained by a corporate reliability engineer, with a tab per system and a growing column per campaign. The second is an ageing thickness data management package installed a decade ago, still running, with an export that produces a wide format nobody has parsed since the vendor's last support engineer retired. The third is the inspection contractor's own database, where the plant sees results as PDF reports and never sees the underlying table. The fourth is no system at all: the history exists as a stack of report PDFs on a shared drive.

The third shape is the one that causes strategic trouble, because multi-plant food companies rotate inspection vendors on procurement cycles measured in a few years. When the vendor changes, the data leaves with them unless the contract says otherwise, and the incoming vendor establishes its own location numbering. Companies discover this at exactly the wrong moment, which is usually the first campaign under a new contract, when the new readings have nothing to trend against. The result is that history is not migrated once, it is rebuilt repeatedly, and each rebuild loses another few years of comparability.

The durable fix is contractual before it is technical. Master service agreements should require delivery of complete monitoring location and reading data, in an open and documented format, at the close of every campaign rather than at the end of the agreement. Once that clause exists, the registry stops being a project and becomes the plant's own record that vendors write into. Companies that put this clause in place typically find the next vendor transition costs a fortnight instead of a programme restart.

Six arithmetic traps that surface the day after go-live

Units come first because they are the most destructive and the easiest to miss. A single workbook maintained by several people over fifteen years commonly contains mils, decimal inches and millimetres, sometimes within one column, and the value 0.065 is a perfectly plausible number in two of those units. Detection has to run per sheet and per column with a plausibility check against the component's nominal wall, and the original string should be retained so a human can adjudicate the exceptions rather than trusting the converter.

Dates come second. An exported CSV with ambiguous day and month ordering will invert intervals on roughly a third of readings, which produces negative corrosion rates on some locations and enormous ones on others. Parsing against the known export locale fixes most of it, and rejecting any computed interval shorter than thirty days or longer than the asset's life catches the rest before the rate reaches anyone.

The remaining four are subtler. Stored corrosion rates were computed under the old system's convention and must be imported as reference only and recomputed from readings, with a disagreement report over a stated tolerance. Minimum thickness fields frequently contain a company alert threshold rather than a code-derived retirement thickness, so re-derivation from the design basis is mandatory or the plant condemns itself on day one. Location identifiers collide the moment plant workbooks merge, so namespacing by site is required before any consolidation. And legacy sheets are full of locations on lines that were replaced during a plant expansion years ago, which must arrive as retired with a retirement date rather than as active work waiting to be scheduled.

The location string is the only re-findability you inherited

Legacy thickness data in food plants rarely carries structured location fields. What it carries is a free text description written by a technician standing in front of the pipe: elbow east of pump three, second floor, syrup line, or six o'clock at the support after the header tee. Those strings look like noise in a migration and are routinely dropped in favour of a clean structured schema. Dropping them destroys the only information that makes the historical readings usable, because the structured fields are empty and nobody alive can say precisely where the old point was.

The rule is simple and absolute: preserve the string verbatim in a dedicated field, and build structured location fields alongside it as they are confirmed in the field. Never overwrite the original, and make it searchable, because for several years it will remain the way a technician actually finds the point. Structured data accumulates campaign by campaign as crews confirm locations, and eventually the string becomes redundant, but that transition takes cycles, not weeks.

Structured location on this equipment needs more than a line number. Clock position matters because corrosion under insulation concentrates at the six o'clock position where water collects, and erosion concentrates on the outer radius of bends. Support detail matters because contact points under insulation are where cold ammonia lines lose wall fastest. Elevation and access matter because a location reachable only from a lift inside a production hall can only be inspected when the line is down. A registry that captures these turns a list of locations into a workable inspection plan.

Reconciliation, parallel run and a field re-shoot

A migration is proven by reconciliation, not by opening records and looking at them. The baseline set of checks is mechanical: row counts by plant and by system compared against the source, a checksum on the last reading value and last reading date for every location, and a full recomputation of corrosion rates diffed against the legacy stored values with a declared tolerance. Every disagreement goes onto an exception report, and the exception report is signed by a named engineer before go-live rather than filed.

The check that finds what the mechanical checks cannot is a field re-shoot. Select twenty to thirty locations spread across plants, systems and data vintages, send a technician to take a reading at the location the migrated record describes, and compare. This catches the errors that matter most, which are location errors rather than value errors: a point that migrated with the wrong component, a duplicate that merged two histories, a description that no longer corresponds to anything because the line was rerouted in a plant expansion. No amount of desk checking finds these.

Finally, run one campaign in parallel. Let both the legacy sheet and the new registry produce the inspection due list, and diff them. Differences will be real, and each one is either a bug in the migration or an error in the legacy data that has been quietly driving the schedule for years. In practice both are found, and the exercise is what converts the engineering group from tolerating the new system to trusting it. For a plant under process safety management, that documented parallel run is also the cleanest evidence that mechanical integrity records were maintained continuously across the change.

Sequence the cutover against pack season and the audit clock

Food and beverage production is seasonal in a way that dominates every schedule. A cannery runs continuously through pack season and cannot host anything. A brewery peaks into summer. A dairy has no meaningful off-season at all but has weekly cleaning windows. The migration cutover has to land in the window where the plant can absorb a period of dual running and a field re-shoot, and that window is usually short and known a year in advance.

The second clock is regulatory. Process safety management requires a compliance audit at least every three years, and an auditor will ask to see mechanical integrity records for the ammonia system, including inspection dates, techniques, results and the qualifications of the people who performed them. Cutting over three weeks before that audit is a poor decision even if the migration is technically sound, because you will be explaining a data transformation instead of showing a record. Cutting over a year ahead means the registry has produced a full cycle of its own evidence by the time anyone asks.

For multi-plant operators, sequence rather than parallelise. Migrate one plant completely, including reconciliation, re-shoot and a parallel campaign, and let the exception patterns from that plant rewrite the mapping rules before the second one starts. The first plant always costs more than the plan says and the rest cost considerably less, because the traps are systematic and the same six will appear at every site. Atlantis runs the first-plant migration as a scoped exercise against your own extracts, and the deliverable that matters is the exception report, not the screenshot.

Which systems in a food plant belong in a TML registry?

The regulated and pressure-retaining utility side: anhydrous ammonia refrigeration piping and vessels, steam and condensate, boiler externals, CIP caustic and acid circuits, CO2 and glycol or brine systems, compressed air receivers, and wastewater pretreatment vessels. Product-contact sanitary piping is governed by cleaning validation, 3-A Sanitary Standards and ASME BPE rather than by thickness trending, and hauling all of it into the registry produces thousands of locations nobody inspects and a due list nobody trusts.

What breaks when sanitary tube is mapped to NPS schedule pipe?

Every derived number on that line. Sanitary tube is specified by outside diameter and gauge, so two inch sixteen gauge tube has a wall around 0.065 inches, while two inch schedule 10S pipe is roughly 0.109 inches and schedule 40 is thicker again. A migration that maps tube onto a schedule table assigns a minimum thickness the tube never had and a baseline it never had, and because the actual wall is thin, ordinary measurement uncertainty becomes a large percentage of it.

Should legacy corrosion rates be imported or recomputed?

Always recompute from the readings, and keep the legacy rate only as a reference value for comparison. The old system computed its rate under its own convention, which may have been short-term only, long-term only, or a manual override entered by an engineer during a review. Importing it produces two authorities for the same location and eventually two different next-due dates. The disagreement report between legacy and recomputed rates is one of the most useful artefacts a migration produces.

Who owns the thickness history when you change inspection contractors?

Whoever the contract says owns it, which in many food companies turns out to be the contractor. Multi-plant operators typically rotate inspection vendors on a procurement cycle, and if the data lives in the vendor's system the history leaves with them and the next vendor starts a new numbering scheme. The durable fix is contractual: require delivery of complete location and reading data in an open format at the close of every campaign, not only at the end of the agreement.

How do you prove a migration was correct before go-live?

With reconciliation rather than inspection of screens. Reconcile row counts by plant and system, checksum the last reading value and date for every location, recompute corrosion rates and diff them against the legacy values with a stated tolerance, and produce an exception report that a human signs. Then re-shoot twenty to thirty locations in the field across several plants and compare against what the migrated record says should be there. That last step is the one that catches location errors nothing else will.

Is API 510, 570 or 653 inspector training part of this offer?

No. API inspector certification is administered by API through its own examination programme, and Atlantis is not an API certification training provider. Atlantis provides NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, ASNT Level III consulting, independent report validation, 3D laser scanning, and the inspection management software described on this page. Food manufacturers most often engage the Level III consulting to write and audit the written procedures their mechanical integrity programme depends on.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.