Making Every Thickness Location Re-Findable Before a Midstream Outage Window Opens

A CML and TML registry gives every condition monitoring location a permanent identity, a physical description precise enough for a stranger to re-find it, and a reading history that survives spool replacement. In midstream the payoff is scheduling. Station and terminal outages are short and infrequent, so scope, access, insulation removal and crew loading must all be settled before the window opens.

Midstream runs two rulebooks over the same steel. The regulated line sits under 49 CFR Part 192 or Part 195 and is largely assessed by in-line inspection. The station, terminal and manifold piping around it is assessed under API 570 at fixed condition monitoring locations, and breakout tanks fall to API 653 by direct reference from 195.432. API 570 caps thickness measurement intervals at five years for Class 1 piping and ten years for Class 2 and Class 3, or half the remaining life if that is shorter, with injection points at three years or half remaining life. Those intervals rarely align with the outage calendar. A pump station comes down for seventy-two hours once every three or four years, and every location needing insulation removal, scaffold or a line break must fall inside that window. The registry exists to make the window plannable rather than discovered.

Source: Written against API 570 (Piping Inspection Code) for condition monitoring locations and inspection intervals, API 574 (Inspection Practices for Piping System Components) for CML selection and placement, API 653 for breakout tanks as invoked by 49 CFR 195.432, API 571 for damage mechanism definitions, ASME B31.4 and B31.8 for design basis, and 49 CFR Parts 192 and 195 for the PHMSA integrity management obligations that sit alongside them.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What a midstream CML registry has to carry, by location type
Location typeDominant damage mechanismReadable on stream?What the registry must store beyond the reading
Chemical or methanol injection point, downstream quillLocalised injection point corrosion and impingementUsually yes, if lagging is already openCircuit extent from the quill to the second change in flow direction, plus the 12 in beyond it, and every point inside that extent as one governed set
Meter run and control valve downstream elbowErosion and erosion-corrosionYesFlow direction, extrados versus intrados position, and the clock position of each point so the eroded side is read again, not the shadow side
Bypass loop, relief header dead leg, idle pig trap barrelUnder-deposit corrosion and MIC at the water drop-out low pointOften not, isolation requiredLow-point elevation, the reason the leg is dead, and a flag that it cannot be read without a line break
Heat-traced crude or condensate line under insulationCorrosion under insulation at the traced band and at supportsNo, requires an inspection port or lagging removalInsulation type, port location, whether a plug exists, and the cost or trade needed to reopen it
Terminal breakout tank shell course and critical zoneGeneral shell corrosion and soil-side floor lossTank must be out of service for internal workAPI 653 due dates carried in the same register as the piping so both compete for one outage calendar
Buried-to-above-ground transition at a valve stationSoil-to-air interface corrosion under the coating shieldExternally, yes, once excavatedExcavation depth, coating condition at last exposure, and the CP test point that shares the location
Read on stream means the reading can be taken with product moving and no permit for a line break. It does not mean access is free, only that the constraint is scaffold and lagging rather than the outage calendar.

The midstream failure is not missing data, it is data nobody can act on

Almost every midstream operator already has thickness readings. They exist in a contractor's report from the last campaign, in a spreadsheet maintained by an integrity engineer who has since moved on, and in scanned field sheets filed by job number rather than by location. The data is not lost. It is simply unaddressable, because the identity of the location lives in whatever naming convention the crew used that week.

The consequence shows up at exactly the wrong moment. Four days before a station outage, someone asks which locations are due and what access each one needs. The answer takes a week to assemble, because it requires reconciling three sources that use different identifiers for the same steel. By the time it exists, the scaffold order is late and the insulation contractor is booked elsewhere.

A registry solves a narrower problem than most vendors claim. It does not predict corrosion. It guarantees that a location has one identity for its entire life, that every reading ever taken against that identity is attached to it, and that the physical description is good enough for a crew who has never been on that site to stand in the right place on the first attempt.

The outage window, not the inspection interval, is the binding constraint

API 570 tells you the latest date by which a thickness measurement must be taken. It says nothing about whether the plant will be available on that date. In refining, the two roughly converge because turnarounds run on a published multi-year cycle. In midstream they do not. A pump station comes down when nominations allow, a terminal tank comes out of service when tankage elsewhere can absorb the movement, and a compressor station outage is bounded by contractual delivery obligations rather than by an integrity calendar.

That inverts the planning logic. Instead of asking what is due, the integrity engineer has to ask what will be reachable in the next window and what the consequence is of deferring everything else. A location due in fourteen months, sitting on a circuit that will not be isolated again for four years, has to be caught in the window that is about to open or accepted as a deferral with a documented technical justification.

The registry has to answer that question directly. Every location needs an access class, not just a due date: readable on stream, readable with lagging removal, readable with scaffold, readable only with the line isolated. Sorting due dates against access class is what converts a due list into a scope, and it is the single most useful query a midstream integrity engineer runs all year.

Where midstream corrosion concentrates, and why generic grids miss it

Midstream damage is overwhelmingly localised and geometry-driven. Water drops out at low points and under-deposit corrosion or microbially influenced corrosion attacks the six o'clock position of a sagging run. Chemical injection quills produce impingement and localised attack for a short distance downstream. Meter runs and the elbows immediately downstream of control valves erode on the extrados where the flow impinges. Heat-traced lines corrode under insulation in a band along the tracer and at every pipe support that breaks the vapour barrier.

A uniform grid laid across a circuit is a poor match for all of these. It reads the six o'clock and twelve o'clock positions of a straight run and reports healthy steel, while the elbow ten feet away thins on a face nobody selected. API 574 exists precisely to push CML selection toward the features that fail, and the registry has to preserve the reasoning, not just the coordinate.

This is why the registry needs a damage mechanism field tied to API 571 terminology on each location rather than on the circuit as a whole. A circuit can carry three mechanisms at once. When the next engineer inherits the program, the mechanism recorded at the location tells them why that point was chosen and whether a different NDT method, such as corrosion mapping rather than spot ultrasonic, is now the right call.

The arithmetic trap: a relocated CML manufactures a corrosion rate

Here is the failure that quietly corrupts more midstream integrity data than any other. A crew arrives, cannot find the marked location because the paint has weathered off, and takes a reading a hand's width away on the same fitting. The number goes into the system against the original identity. It reads 0.031 inches thinner than last campaign, not because the pipe corroded, but because pipe wall varies that much across a single elbow from the forming process alone.

The system then computes a short-term corrosion rate over the interval between campaigns. With a three-year interval, thirty-one mils of apparent loss becomes roughly ten mils per year, which on a circuit with modest corrosion allowance can collapse the calculated remaining life from decades to a handful of years. Someone now has to explain an emergency scope addition that was created by a measurement error.

The inverse is worse. A relocation onto a thicker spot produces apparent wall gain, the system discards it as noise or clamps the rate to zero, and a genuinely corroding circuit gets its interval extended. The defence is not better statistics. It is a registry that stores a re-findability description strong enough that the second reading lands on the first reading's steel, plus an explicit as-found flag when the technician knows they could not.

Two rulebooks on one site, and the register has to see both

At a liquids terminal, the piping inside the fence is inspected under API 570, the breakout tanks are inspected under API 653 because 49 CFR 195.432 says so, and the regulated line beyond the block valve is managed under the Part 195 integrity management program with its own high consequence area logic and reassessment intervals. Three programs, three vocabularies, one set of crews and one outage calendar.

Operators routinely run these in separate systems, and the collision is discovered during planning. The tank internal inspection and the manifold piping scope both need the same window, the same confined space attendants and the same rope access team, and nobody realises until the schedule is built. Worse, when PHMSA or a state agency audits, the evidence trail has to be assembled by hand from systems that do not share an asset identity.

A registry does not need to replace the ILI data management or the tank inspection reports. It needs to hold one asset hierarchy that all three attach to, so that a query for everything due at a site in a given window returns piping locations, tank due dates and planned digs together. That single query is usually what justifies the project internally.

Building the scope pack the window actually consumes

A turnaround scope for midstream station work is not a list of locations. It is a bundle of dependent orders. Lagging removal has to be ordered against a list of locations, scaffold has to be designed against elevations, confined space entries need attendants scheduled, hot work permits need to be sequenced against purging, and the ultrasonic crew has to be sized against the number of readings and the travel between them.

The registry supplies the spine for all of it if the location records carry the right attributes. Elevation and access class drive the scaffold list. Insulation type and port availability drive the lagging order. Surface condition from the last campaign drives whether grinding and surface preparation time has to be budgeted, which is routinely underestimated on external coated piping in coastal terminals.

The measure of whether this works is simple and worth asking any vendor to demonstrate. Given a station and a window start date, can the system produce, in one pass, the list of locations to read, the access order for each, the crew hours implied and the deferral list with the technical justification for each deferral. If that takes a week of spreadsheet work, nothing has been solved.

Field capture at a valve station has no signal and no bench

Midstream inspection happens at unmanned sites at the end of a gravel road. There is frequently no cellular coverage, no power beyond a truck inverter and nowhere to set a laptop. Any capture approach that assumes connectivity produces the same outcome as paper: readings written down and transcribed later, with the transcription errors and the delay that implies.

Offline capture with deterministic sync is therefore not a nice feature, it is the whole difference between a live register and a retrospective one. The device has to carry the location list, the previous readings, the photographs and the datum descriptions down the road with it, and it has to reconcile cleanly when the truck reaches coverage, including when two crews touched adjacent locations on the same day.

There is a quality dividend that operators often miss. When the previous reading is visible on the device at the moment of measurement, the technician can challenge an anomalous result while still standing at the location. A twenty-mil discrepancy investigated on the spot is a two-minute recheck. The same discrepancy discovered three weeks later in the office is a mobilisation.

How to evaluate a registry before you commit an outage to it

Ask for a live demonstration of retirement rather than deletion. Replace a spool in the demo data, retire its locations, create the replacements, and then ask the system to show the circuit's full history including the retired points. Many systems either lose the old readings or, worse, carry the old identity onto new steel and produce a corrosion rate across the discontinuity.

Ask how the system handles a reading the technician flags as taken off-datum. It should accept the reading, mark it as not comparable, exclude it from the corrosion rate calculation by default and raise it for engineering review. A system that silently averages it into the trend is generating integrity numbers from measurement error.

Finally, ask it to fail. Give it a location with two campaigns of data and a three-year gap, and check whether it distinguishes short-term from long-term corrosion rate and shows both. API practice is to consider both, and a system that reports one number without saying which it is has removed the engineer's ability to notice that a mechanism recently accelerated. Atlantis will walk a midstream integrity team through each of these on their own data during a scoping consultation.

Why does a city or terminal name never define a midstream CML program?

Because the corrosion does not care where the station sits. What drives the inspection plan is service, flow regime, water content, temperature and the geometry immediately upstream of the point. Two stations three hundred miles apart on the same crude batch have near-identical CML strategies, while two circuits inside one terminal fence can differ completely because one carries dry gas and the other carries wet sour condensate.

How many condition monitoring locations should a midstream circuit carry?

API 574 gives selection guidance rather than a fixed count, and the honest answer is that the number follows the damage mechanism. A straight run of dry sales gas piping may justify a handful. A circuit with an injection quill, three elbows and a low point in wet sour service may need a dozen, because the mechanism is localised and a grid centred on the wrong feature returns comforting numbers from steel that was never at risk.

What makes a thickness location re-findable by a technician who has never seen it?

Three things together. A datum that is a physical feature rather than a coordinate, such as a named weld, a flange face or a support shoe, with a measured offset from it. A clock position referenced to a stated convention, usually top dead centre looking downstream. And a photograph taken from a repeatable standoff showing the surrounding fittings. GPS alone fails inside a manifold where forty points sit within ten metres.

Is API 510, 570 or 653 inspector training part of this offer?

No. API inspector certification is administered by API through its Individual Certification Programs, and the examinations and body-of-knowledge sit with them. Atlantis supplies inspection management software, reporting software, digital twins, report validation, ASNT Level III consulting and NDT method training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD. The registry described here is software, not a certification pathway.

Should in-line inspection results and station CML readings live in the same system?

They should share an asset hierarchy and a due-date calendar, but they are different evidence. ILI gives dense coverage of the regulated line with a tool tolerance measured in percentage of wall. CML readings give sparse coverage of station piping with a spot tolerance measured in thousandths. Merging them into one thickness trend produces nonsense. Linking them so a dig program and a station outage compete visibly for the same crews is the useful integration.

What does the registry have to do when a spool is replaced during the outage?

Retire the old locations with a reason and a date, keep every historical reading attached to the retired identity, and create new locations against the new component with a new baseline taken from the actual measured thickness rather than the nominal. If the system instead carries the old CML forward onto new steel, the next corrosion rate calculation spans a wall thickness discontinuity and silently reports negative loss.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.