Trusting thickness data you did not collect yourself

A CML and TML registry for a nuclear station has to be a boundary, not a bucket. Contractor datasets arrive at outage speed from multiple crews, and the registry must reject unknown point IDs, require declared units and grid datums, hold the full point set rather than a bare minimum, and record who reviewed and accepted each file before it becomes plant record.

Wall thinning data at a nuclear plant is overwhelmingly collected by people who do not work for the plant. Vendor crews arrive for a refueling outage, take tens of thousands of ultrasonic readings across the flow-accelerated corrosion programme in under three weeks, and hand back files. Each crew has its own naming habits, its own grid conventions and sometimes its own units. The station then has to treat that output as quality records under the plant quality assurance programme, defend the wear rates derived from it, and use those rates to justify what gets replaced this outage and what waits for the next one. Nothing about that chain tolerates ambiguity. A registry designed for this environment enforces its rules at the point of import rather than during review, because review capacity during an outage is the scarcest resource on site and errors caught two weeks after turnover have already influenced scope decisions that cost real money to reverse.

Source: Written against ASME Section XI including the IWA general requirements for personnel qualification and records, 10 CFR 50.55a, the quality assurance criteria of 10 CFR Part 50 Appendix B, ASME NQA-1, EPRI NSAC-202L for flow-accelerated corrosion programme management, NRC Bulletin 87-01 and Generic Letter 89-08 on erosion and corrosion induced pipe wall thinning, ASME B31.1 for balance-of-plant piping, and 10 CFR Part 21 for reporting of defects.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Contractor dataset defects seen at outage turnover, and the control that catches each before acceptance
Defect in the delivered datasetHow it reaches the permanent recordControl at the registry boundary
Point identifiers invented by the crewImport creates new locations that look like additional CMLs, and next outage the trend has no history to attach toA closed point catalogue: an import referencing an unknown location is rejected rather than auto-created, with the unknown IDs listed back to the vendor
Grid origin and orientation not declaredSquare A1 sits at a different corner than last outage, so squares are compared against the wrong squares and false wear appearsMandatory datum fields for reference weld, flow direction and the twelve o'clock reference, with a marked-up photograph attached to the grid
Units mixed between crews or between filesMils entered where inches are expected, so a 0.375 inch wall is stored as 375 or as 0.000375 and the trend becomes nonsenseUnit of measure declared per file at import, with range validation of every value against the component nominal wall before acceptance
Only the grid minimum reportedThe distribution is discarded, so wear cannot be treated statistically and a single outlier drives the whole decisionFull point set required; a minimum submitted without its supporting grid is quarantined pending resubmission rather than accepted with a note
Re-measurement taken from a different datumApparent wear appears where none exists, or genuine wear is measured on unaffected metal and disappearsPrior datum re-issued to the contractor inside the work package, and the returned dataset checked against it before the readings are trended
Personnel certification or equipment calibration lapsed mid-outageDiscovered at audit, after the affected data has already supported a scope or operability decisionValidity evaluated at capture against the examination date, with affected readings flagged and routed into the corrective action process
Every control listed is applied at import. Controls applied during later review consume outage review capacity that does not exist.

The outage compresses a year of data collection into nineteen days

A flow-accelerated corrosion programme at a large station may carry several thousand monitoring locations, many of them gridded, and the majority can only be examined when the plant is shut down and the systems are drained, cooled and scaffolded. That means a year of examination happens inside a refueling window, executed by vendor crews assembled for the outage, working around every other trade competing for the same scaffold and the same containment access. The volume arrives in days, not months, and it arrives as files rather than as entries.

Under those conditions, quality problems are not the exception. Two crews from the same supplier will name points differently if the naming rule is not specified. A crew that finds a location inaccessible will improvise a nearby point and give it a plausible identifier. Someone will report in mils because that is what their instrument displayed. Someone will submit only the minimum for each grid because that is what the previous station they worked at asked for. None of this reflects poor technicians. It reflects conventions that were assumed rather than specified, at a moment when nobody has time to ask.

The station is where the consequences land. The data becomes a quality record, the wear rates derived from it drive replacement scope, and the whole set has to withstand review by the plant quality organisation, by industry peer evaluation and eventually by the regulator. The only place to intervene without adding review workload during the outage is the boundary: the moment a file is imported. Rules enforced there cost nothing to apply and catch the defect while the crew is still on site to fix it, which is a window measured in days and never reopens.

Where nuclear CMLs actually live: the FAC programme, not Section XI

It is easy to assume that all nuclear inspection sits under ASME Section XI, and for the reactor coolant pressure boundary and the Class 2 and Class 3 systems that is broadly true. Wall thinning monitoring is different. The large populations of gridded thickness locations at a station are on secondary side and balance-of-plant piping: feedwater and condensate, extraction steam, moisture separator reheater drains, heater drains and vents, and the associated valve and orifice geometry. Much of that is designed to ASME B31.1 rather than Section III, and it is managed under the station's flow-accelerated corrosion programme.

That programme follows EPRI NSAC-202L, which sets out how susceptible lines are identified, how components are selected for examination, how wear rates are calculated and how inspection scope is planned outage to outage. Predictive modelling with tools such as CHECWORKS ranks components by predicted wear so that finite outage hours go to the components most likely to need them. The programme is a licensee commitment, described in station documents and, for a plant in extended operation, tied to the aging management commitments made in the license renewal application.

The practical consequence for a registry is that it must serve two regimes with different rules on the same site, and must not blur them. Section XI examinations carry their own personnel qualification requirements under the IWA general requirements, their own record and report obligations, and for certain examinations a performance demonstration qualification under Mandatory Appendix VIII administered through the industry programme. FAC programme examinations carry the plant's own procedures and the NSAC-202L methodology. Storing both without distinguishing them produces a dataset that satisfies neither reviewer, and an engineer who has to explain the difference verbally every time it is questioned.

Surry, and why wall thinning carries a different burden of proof

In December 1986 an eighteen-inch elbow in the suction piping to a main feedwater pump at Surry Unit 2 ruptured while the unit was at power. Four workers died from the steam release. The pipe wall in the failed region had thinned dramatically from its original thickness by a mechanism that had not been systematically monitored, and the failure was not preceded by leakage or by any indication that a periodic walkdown would have caught.

The industry response is why the programme exists in its present form. NRC Bulletin 87-01 asked licensees to report what they knew about pipe wall thinning in single-phase and two-phase systems. Generic Letter 89-08 followed, addressing erosion and corrosion induced wall thinning and the adequacy of licensee programmes to find it. EPRI's NSAC-202L guidance consolidated the methodology, and predictive modelling gave stations a way to aim limited outage hours at the components most likely to be thinning. Every element of a modern FAC programme traces back to a failure that thickness data, properly collected and properly compared, would have anticipated.

That history shapes how the data is treated. A wear rate at a nuclear station is not a maintenance planning input; it is the technical basis for deciding that a component can safely run another cycle, and it is expected to withstand hostile review. Consequently the standard applied to the underlying measurements is higher than in most industries: not just accurate, but traceable to a qualified person, a controlled procedure, a calibrated instrument and a defined physical location, with the raw data retained rather than summarised. A registry built on the assumption that a stored number is self-evidently sufficient cannot support that standard.

Appendix B does not care that the technician worked for someone else

When a station procures examination services, the quality assurance programme extends to the work rather than stopping at the fence. The criteria in 10 CFR Part 50 Appendix B address control of purchased material, equipment and services, control of special processes, inspection, corrective action and quality assurance records, and none of them contain an exemption for work that a supplier performed. In practice that means the supplier is evaluated and qualified, their procedures are reviewed and accepted by the station, and their deliverable is accepted through a documented review rather than simply received.

ASME NQA-1 gives the structure for that supplier control, including the audit and surveillance expectations and the treatment of commercial grade items and services where dedication is required. Where an examination result will support a decision on a safety-related component and the supplier is not qualified to the station's programme, the path is dedication rather than assumption. Separately, 10 CFR Part 21 sits behind the whole arrangement as the reporting obligation when a defect or noncompliance in a basic component or associated service is discovered. A contractor dataset that turns out to be systematically wrong is not merely a commercial problem.

What this asks of a registry is concrete. Acceptance has to be an explicit, recorded act performed by a named station reviewer, not an implicit consequence of a file having been uploaded. Rejected datasets need a state of their own, quarantined and visible, with the reason recorded and communicated back to the supplier. A dataset that fails review has to be routable into the corrective action programme so that the condition is evaluated rather than solved informally. And the audit trail has to survive personnel turnover at both the station and the supplier, because the review that matters is the one being questioned four years later.

Repeatability is the floor under every wear rate you report

Contact ultrasonic thickness measurement is more variable than its display precision suggests. A gauge reading to three decimal places on painted, scaled or roughly ground carbon steel is influenced by couplant film, contact pressure, probe wear, surface preparation, temperature, and the operator's technique in seeking a stable reading. Dual-element probes, which are standard for corrosion measurement, introduce V-path error that varies with the wall thickness being measured, and different probes with different delay line wear behave differently on the same square.

Add the contractor dimension and the variation compounds. Two crews in consecutive outages may use different probe frequencies, different instruments, different surface preparation practice and different judgement about what constitutes a valid reading on a rough surface. Field experience across many stations puts realistic operator-to-operator repeatability at several thousandths of an inch on typical secondary side surfaces. When the genuine wear over a two-year cycle is of the same order, subtracting one crew's number from another crew's number and dividing by elapsed time is not a measurement. It is noise with units attached.

The methodology that survives review compares populations rather than points. Grid statistics from one outage are compared against grid statistics from the next, the difference is evaluated against a stated uncertainty band, and a wear rate is only asserted where the change exceeds what measurement variation alone could produce. That requires the registry to hold every point rather than the minimum, to hold the instrument and probe used, and to make the uncertainty basis an explicit stored assumption rather than a convention held in an engineer's head. It also means the system must be able to say that no wear rate can yet be established, which is a genuinely useful answer that spreadsheets almost never give.

Re-registering a grid to the same physical squares, outage after outage

Everything above depends on measuring the same metal twice. A grid laid out on an elbow has an origin, an orientation and a spacing, and those three things are the difference between a comparable dataset and an expensive one. If the origin was two inches from the upstream weld toe last outage and is measured from the downstream toe this outage, the squares no longer correspond. If the previous crew laid the grid looking downstream and the new crew laid it looking upstream, the columns are mirrored. If twelve o'clock was referenced to the pipe support last time and to true vertical this time, the rows are rotated.

None of those mistakes announce themselves. They present as wear appearing in a square that was previously thick, or as wear vanishing from a square that was previously thin, and the natural first interpretation is that something changed in the plant. Engineers then spend review time during an outage arguing about whether a scallop moved, when the answer is that the grid did. The cost is not just the time; it is the erosion of confidence in the dataset as a whole, which pushes decisions back toward conservatism and unnecessary replacement.

The remedy is to treat the datum as data. Store the permanent physical reference used, the flow direction the layout assumed, the angular reference for twelve o'clock, the spacing, the number of rows and columns, and a marked-up photograph of the grid as laid out. Then issue that package back to the contractor as part of the next work order, so the crew arrives knowing exactly where the grid goes rather than reconstructing it from a report. Verification at import can compare the returned grid geometry against the stored geometry and flag any mismatch before the readings are trended. This single discipline removes more spurious wear findings than any other change a station can make.

Evaluating a registry that must accept data it did not create

The evaluation question for a nuclear station is different from the one an operating company asks. The system is not primarily a place where your own inspectors record findings; it is a controlled boundary through which other organisations' data becomes plant record. So test it as a boundary. Hand a vendor file with three unknown point IDs and confirm the import is rejected with those IDs named, rather than silently creating three new locations. Submit a grid minimum with no supporting points and confirm it is quarantined. Submit a file in mils where the catalogue expects inches and confirm the range validation catches it before acceptance.

Then test the record it produces. Can a reviewer see the raw file as delivered, alongside the parsed result, and confirm they agree? Are waveform or scan files retained as attachments so an anomalous reading can be re-examined rather than re-argued? Is acceptance an act with a named person and a timestamp, and is rejection a state with a reason that can be reported back to the supplier and, where warranted, into the corrective action programme? Can you reconstruct exactly what the system asserted about a component on a date three years ago, including the assumptions in force at that time?

Finally, evaluate the things that are unique to this sector and easy to defer. Role-based access down to the system and document level. Where data physically resides and who at the vendor can reach it. How access is revoked the day a contractor demobilises. What an export contains and what it deliberately omits. These are technical evaluation criteria at a nuclear station, not procurement afterthoughts, and a system that cannot answer them clearly will not be deployed no matter how well it models a grid. Atlantis NDT will run a sample contractor dataset through the import controls as part of a working demonstration, using your point catalogue and your conventions. Write to info@atlantisndt.com to arrange a consultation or request a quote.

Why is contractor data quality a structural problem rather than a vendor problem?

Because the volume and the schedule guarantee it. A refueling outage compresses a year of examination into a few weeks, using crews assembled for the window from several suppliers, working shifts around other trades. Even excellent contractors produce inconsistent output under those conditions, because consistency depends on conventions being specified rather than assumed. The station owns the specification. If the point catalogue, units, datums and required fields are not defined in the work package and enforced at import, variation enters regardless of who was hired.

Where do nuclear CMLs actually live in the plant programme?

Mostly outside the Section XI inservice inspection programme. Wall thinning monitoring concentrates on secondary side and balance-of-plant piping such as feedwater, condensate, extraction steam, moisture separator reheater drains and heater drains, managed under the station's flow-accelerated corrosion programme following NSAC-202L. Section XI governs the Class 1, 2 and 3 pressure boundary examinations with their own rules. Both feed the same integrity picture and both are audited, but they have different scoping rules, different qualification expectations and different record requirements.

Why does a single reading difference not establish a wear rate?

Because the difference is often smaller than the measurement uncertainty. Contact ultrasonic thickness measurement on painted or scaled carbon steel carries operator-to-operator variation of several thousandths of an inch, and dual-element probes add V-path error that varies with wall thickness. Two crews measuring the same square in consecutive outages can differ by more than the real annual loss. Defensible wear rates come from comparing grid populations and treating the result against a stated uncertainty band, not from subtracting two individual numbers.

What does Appendix B expect when the examination is performed by a supplier?

The same standard the station applies to itself. The quality assurance criteria address control of purchased services, control of special processes, inspection, corrective action and records, and none of them relax because a contractor performed the work. In practice that means a qualified supplier, procedures reviewed and accepted by the station, personnel qualification verified against the examination date, documented acceptance of the deliverable, and a route into the corrective action programme when a dataset fails review.

How is a grid re-registered to the same physical squares outage after outage?

By storing the datum with the grid rather than in someone's memory. The record needs a permanent physical reference such as an upstream weld toe or a flange face, the direction the grid was laid out relative to flow, the angular reference used for twelve o'clock, the grid spacing, and a marked-up photograph. That package goes out with the next work order so the incoming crew measures the same metal. Without it, comparison across outages is measuring different squares and calling the difference wear.

What access and data handling questions belong in a nuclear evaluation?

More than in any other sector. Detailed configuration and degradation data for a nuclear station can attract controlled information handling requirements, so evaluation has to cover role-based access, where data is stored, who at the vendor can see it, how access is revoked when a contractor demobilises, and what the export and audit trail look like. These questions belong in the technical evaluation alongside the functional ones, because a system that fails them cannot be deployed regardless of how well it models a grid.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.