Thickness and condition monitoring locations in a GMP plant, after the spreadsheet

A pharmaceutical CML and TML registry stores every monitoring location as a controlled record: its position, nominal and retirement thickness, the mechanism it watches, and every reading with the technician, gauge and calibration behind it. In a GMP plant it must also hold non-thickness condition locations — glass lining, rouge grade, passivation — and carry a Part 11 audit trail no workbook can produce.

The constraint that changes everything in pharmaceutical service is that true metal loss is close to zero. A 316L sanitary line to ASME BPE at 2 in OD by 0.065 in wall carries about 1.65 mm of metal, and a hand-held pulse-echo gauge repeats to roughly two hundredths of a millimetre at best on a clean electropolished surface, worse across operators, couplant and probe pressure. Subtract two campaigns' readings taken 40 mm apart and you manufacture a corrosion rate out of nothing. What the register actually has to guarantee is that the second reading came from the same square centimetre as the first, that the retirement thickness on file was set by a named engineer under change control, and that both the reading and any later correction survive in a 21 CFR Part 11 audit trail. Section VIII pressure math is rarely the governing limit; cleanability under 21 CFR 211.65 often is.

Source: Sources relied on: 21 CFR Part 11 electronic records and electronic signatures, in particular 11.10(e) on audit trails; 21 CFR Part 211 subparts C and D, notably 211.63, 211.65 and 211.67 on equipment construction, surfaces and maintenance; EU GMP Annex 11 (computerised systems) and Annex 15 (qualification and validation); ASME BPVC Section VIII Division 1 and Section V; ASME BPE for hygienic tubing dimensions and surface finish; ASTM E797/E797M for manual pulse-echo thickness measurement; ASTM A967/A967M for stainless steel passivation; ISPE GAMP 5 for computerised system categorisation; ASNT SNT-TC-1A and ISO 9712 for personnel qualification.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Monitoring locations in a GMP plant: what each one records, and why a thickness-only spreadsheet drops it
Location typeDamage mechanism watchedWhat is measured or observedRecord the registry must hold
Sanitary tube weld and heat-affected zone in a CIP/SIP loopChloride pitting and crevice attack from residual rinse water and heat tintPulse-echo thickness plus borescope inspection of the weld inside diameterThickness to 0.01 mm, orbital weld coupon reference, internal image, heat-tint and ferrite note
WFI and clean steam distributionRouging, graded Class I to Class III, and progressive loss of the passive layerVisual rouge classification, swab results, derouging and repassivation historyA graded condition rather than a number, with the date and method of the last repassivation to ASTM A967
Glass-lined reactor shell, nozzle and agitator zoneCrazing, spalling and pinholes at the nozzle radius and impeller shadowHigh-voltage spark test at a stated kV, lining thickness by eddy currentSpark test voltage, defect map, tantalum plug repair history — no wall thickness at all
Reactor jacket and half-pipe coilExternal corrosion and attack under insulation on the service sideUT thickness at the jacket weld toe after insulation removalInsulation removal window identity, jacket MAWP basis, reading with surface temperature at capture
Solvent and product transfer line elbows and teesErosion-corrosion and flow-induced thinning downstream of control valvesGrid UT, typically five fixed points across the elbow extradosGrid geometry anchored to a named datum weld so the same five points repeat every campaign
Hastelloy or duplex acid and halide serviceLocalised pitting and end-grain attack at weld ends and cut edgesPit depth gauging and liquid penetrant examination rather than general thicknessPit depth distribution and count against a stated acceptance limit, with the PT technique sheet
A register organised around a single thickness column cannot hold rows two, three or six. In practice those locations migrate to a separate file, and the separate file is the one that never gets reviewed.

The workbook did not fail all at once

It started as a good spreadsheet. One tab per vessel, a column for nominal thickness, a column for retirement, dated columns for each campaign, and a rate formula at the bottom. Then the site added a second suite. A contract inspector took a copy into the field. Someone sorted a column without extending the selection. A reviewer inserted rows in the middle. Now there are two files with the same name, a rate formula pointing at a deleted sheet, and no way to say which number the last periodic review actually approved. Nobody was careless. The workbook outgrew the assumption it was built on, which is that one person holds the whole thing in their head.

The moment that assumption breaks, the question stops being what the thickness is and becomes whether you can reproduce the calculation. In a GMP plant that question carries a weight it does not carry elsewhere. A thickness record used to justify continued use of product-contact equipment is a GMP record. If two people can edit it, if there is no trail showing what changed and who changed it, and if the previous value is overwritten rather than preserved, it does not satisfy 21 CFR 11.10(e), which asks for a secure, computer-generated, time-stamped audit trail that does not obscure previously recorded information.

The practical consequence is that a better spreadsheet is not the fix. Under GAMP 5 categorisation, a workbook carrying its own calculations behaves as a bespoke application and inherits the validation burden of one: a specification, testing evidence, change control, a named owner and periodic review. Sites that reach this point usually find it is cheaper to move the register into a system designed to hold controlled records than to validate, and keep revalidating, the workbook they already have.

Why near-zero corrosion makes the location harder, not easier

In a refinery, a carbon steel line losing 0.15 mm a year produces a signal that outruns measurement error within two campaigns. A pharmaceutical plant has the opposite problem. Product-contact 316L in ambient or moderate service may show no measurable general loss for a decade. A hand-held gauge on a clean electropolished surface repeats to roughly two hundredths of a millimetre under good conditions and considerably worse across different operators, couplants, probe pressures and surface temperatures. When the true rate is smaller than the noise, every difference you compute between campaigns is measurement error wearing a corrosion rate's clothing.

That inverts what the register is for. It does not exist to produce a rate. It exists to make the comparison legitimate: to guarantee the second reading came from the same square centimetre as the first, taken the same way, by someone qualified to take it. A short-term corrosion rate derived from two campaigns on 1.65 mm of tubing is arithmetic performed on noise. In a system that will happily do the arithmetic anyway, the honest output is a flag reading below the resolution of the method, not a tidy number that will be quoted in a review three years from now.

Re-finding the point is also physically harder here. You cannot centre-punch a hygienic surface. You cannot leave a permanent mechanical marker on a product-contact line. Much of the system is jacketed, insulated, or inside a classified area with a gowning step between the technician and the point. The location record therefore has to carry the things that survive all of that: a named weld or fitting as datum, an offset in millimetres, a clock position referenced to a fixed external feature, and a photograph taken from a stance a different technician can reproduce next year.

Half your monitoring locations are not thickness locations

A glass-lined reactor is the clearest case. Nothing about its condition is a wall thickness. The relevant record is a high-voltage spark test at a stated voltage, a map of the pinholes and crazing found at the nozzle radius and in the impeller shadow, and the history of tantalum plug repairs. A site can run a dozen glass-lined vessels and have not one meaningful number to put in a thickness column, while the failure that actually stops production is a lining defect that exposes carbon steel to the batch.

Clean utilities behave the same way. Rouging in WFI and clean steam distribution is graded, not measured: Class I migratory particulate, Class II in-situ oxidation of the surface itself, Class III high-temperature oxide in pure steam service. The meaningful record is the grade, the extent, the date and method of the last derouging, and the repassivation performed afterwards to ASTM A967. Elastomer diaphragms in sanitary valves, gasket condition at ferrule joints and passivation state on newly installed spool pieces all fall into the same category.

This is where a thickness-shaped spreadsheet actually breaks. These locations end up in a comments column, a photo folder, or a second workbook owned by a different department, and the second workbook is the one that never gets reviewed. A registry that treats condition monitoring locations as first-class records — with their own location type, their own acceptance basis and their own due dates — keeps the whole population on a single schedule instead of splitting it across systems that only one person knows how to reconcile.

What a controlled CML record actually contains

A defensible location record carries far more than a number. It needs a permanent identifier that never gets reused, the parent equipment and its unique identity, the location type, the damage mechanism being watched, the datum and offset that fix its position, the method and technique required, the required surface preparation, the interval and its basis, the nominal and as-built thickness, the retirement thickness with the calculation that produced it, and the name and date of the engineer who set it. Every reading then inherits its own metadata: instrument, calibration status on the day, reference block, couplant, surface temperature, technician certification level and expiry as they stood at capture.

Two of those fields cause more trouble than the rest combined. Nominal is not as-built. Plate and tubing arrive with mill tolerance, welded fittings are thinner at the forming radius, and a location baselined against a catalogue number rather than a measured value will read as having already lost metal on day one. The register should hold both values and be explicit about which one the trend runs from.

The second is retirement thickness. On a pressure boundary it comes from a Section VIII calculation, but in a hygienic system the governing limit is often not pressure at all. A line that has been repolished several times to remove rouge or weld discolouration may reach a point where surface finish and cleanability under 21 CFR 211.65 fail before the pressure calculation does. If the register stores only the pressure-derived number, it is measuring against the wrong limit and will report comfortable margin on a line that should already have been replaced.

The GMP layer a spreadsheet cannot reach

Once the register is the record that justifies continued use of GMP equipment, Part 11 applies to it in full. That means unique user accounts with no shared logins, authority checks so that only permitted roles can approve a reading or change a retirement thickness, electronic signatures that carry the signer's printed name, date, time and the meaning of the signature, and an audit trail that captures the old value, the new value, the actor, the timestamp and a reason. The audit trail must not be disableable by the people using the system.

EU GMP Annex 11 adds an expectation many sites overlook until an inspection: audit trails are not just retained, they are reviewed. Somebody has to look at what changed, on a defined frequency, with the review itself recorded. A registry that stores a trail but offers no way to review it efficiently pushes that obligation back onto a person with a raw export, and the review quietly stops happening. Ask to see the review view, not the trail.

The rest of the layer is unglamorous and equally load-bearing: qualified backup and restore, defined retention that matches the equipment's life rather than the software contract, controlled export that cannot silently drop a decimal, and a documented position on what happens to the data if the system is retired. These are the questions that show up in a supplier audit, and they are far easier to answer for a system built for controlled records than for a network share holding twelve years of workbooks.

Change control on the register itself

Most sites apply change control to equipment and procedures and forget that the register is itself a controlled artefact. Adding a location, moving one, retiring one, changing a retirement thickness, changing an interval, or reassigning a location to different equipment are all changes that alter what the integrity record says. Each should require a reason, an authorised approver appropriate to the change, and preservation of the prior state. The system should make a silent edit impossible rather than merely discouraged.

The scenario that goes badly in an inspection is specific and common. An investigator notices that a retirement thickness on a transfer line differs from the value in the qualification package, asks when it changed and on what basis, and the answer is that nobody knows, because a cell was edited at some point between 2019 and now. The finding is not that the number is wrong. The finding is that the quality system cannot tell whether it is right, which is a data integrity observation and considerably harder to close.

Periodic review closes the loop. Once a year, or on the site's own cycle, the register should be reviewed as a document: locations that have never been read, locations whose parent equipment has been decommissioned, intervals that keep being extended, retirement thicknesses whose basis predates a change in service, and any location where the reading population is too small to support the conclusion drawn from it. That review is far more valuable than the corrosion rates it sits next to.

Migrating years of spreadsheet history without inventing data

The temptation when moving off a workbook is to import everything and let the new system compute rates over the full history. Resist it. Old readings usually have no recorded instrument, no calibration reference, no technician identity and no proof the point was the same point. Loading them as though they were equivalent to a controlled reading fabricates provenance the data never had, which is precisely the problem you are migrating to escape.

A defensible approach tiers the history. Readings with full metadata come across as verified. Readings with partial metadata come across flagged, visible in the trend but excluded from any calculation that drives a due date. Readings with no metadata come across as historical context only. The original workbook is frozen, versioned and attached to the equipment record as a controlled document, so nothing is lost and nothing is dressed up as more than it is.

Then run one re-baseline campaign. Walk the population, confirm each location physically exists and is accessible, photograph it from the stance the record will specify, capture a reading with complete metadata, and mark that as the verified baseline. It costs one campaign. Everything downstream — every rate, every due date, every remaining-life statement — inherits its credibility from that campaign, and for the first time the register can say honestly which of its locations it actually knows something about.

How to evaluate a registry before it becomes a GMP record

Evaluate on four questions, in order. Can it hold a location that has no thickness, as a first-class record with its own schedule and acceptance basis? Can it bind technician certification, instrument identity and calibration status to a reading at the moment of capture, rather than recomputing them later from a current list? Can it show you the audit trail for a change you make in front of the vendor, including the prior value and the reason? And can it refuse a change that lacks an approver, rather than merely logging that it happened?

Then test it with your own difficult cases. A glass-lined reactor with a spark test result and no thickness. A WFI loop with a rouge grade. A location whose retirement thickness is governed by cleanability rather than pressure. A reading taken by a technician whose certification expired the week before. A vendor demonstration built on carbon steel piping in refinery service will sail through all of these on paper and fail every one of them on your site.

Atlantis NDT builds inspection management software around exactly this record structure, with the condition monitoring and thickness monitoring locations, evidence binding and controlled change history described above, configured to the site's own procedures rather than a generic template. It is affordable, accessible and fully customisable. For a walkthrough against your own equipment list, or a scoped quote, contact info@atlantisndt.com and ask for a demonstration using your data.

Why does a validated spreadsheet still fail once two people edit it?

Validation covers the file you tested, not every copy of it. The moment a second editor opens a second copy you have an unvalidated instance with no audit trail: sorted columns, inserted rows, a formula pointing at a deleted sheet. 21 CFR 11.10(e) asks for a secure, computer-generated, time-stamped audit trail that does not obscure the previous value. A workbook overwrites instead of preserving, so the record cannot show what a number used to be.

What makes CML re-findability harder on thin-wall stainless than on carbon steel?

Two things. The wall is thin, around 1.65 mm on 2 in hygienic tubing, so a repeatability error of a few hundredths of a millimetre is a large fraction of the remaining margin. And you cannot centre-punch a product-contact surface to mark the spot. The location has to be fixed by an external datum instead: a named weld or fitting, a measured offset, a clock position against a fixed feature, and a photograph taken from a repeatable stance.

How do you register a monitoring location that has no thickness at all?

You store an observation instead of a number. A glass-lined reactor location holds a spark test voltage, a defect map and a repair plug history. A WFI loop location holds a rouge classification and the date of the last derouge and repassivation to ASTM A967. The registry needs a location type that accepts an ordinal grade or an image set and still schedules, trends and escalates the way a thickness location does.

Does a pharmaceutical site need an API 510 or 570 program to justify a CML register?

No, and most do not run one. Pressure equipment is built and stamped to ASME Section VIII, but in-service inspection is usually driven by the jurisdiction, the insurer and the site's own maintenance procedure rather than an API program. That is exactly why the register matters: with no external code cadence forcing structure on it, the spreadsheet is often the only integrity record the plant has, and its weaknesses go unchallenged for years.

What should change control look like when someone moves or retires a CML?

Treat the register as a controlled document. Adding, relocating or retiring a location, changing a retirement thickness, or extending an interval should each require a stated reason, an authorised approver and a preserved prior value. The system should refuse a silent edit. Auditors rarely dispute a change that was justified and approved; they dispute one that simply appears in the data with no explanation and no name attached to it.

What do you ask a vendor to prove before their registry becomes a GMP record?

Ask for a live demonstration, not a document. Have them change a reading in front of you and show the resulting audit trail entry, the prior value and the reason field. Ask how routine audit trail review is performed, as EU GMP Annex 11 expects. Ask for the validation package and supplier quality questionnaire, and whether a non-thickness condition location is a first-class record or a comment field.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.