The refinery thickness workbook nobody can reproduce
A CML and TML registry gives every monitoring location on a refinery circuit a permanent identity, a physical position, and a reading history that recomputes rather than stores its corrosion rate. Because the calculation is derived from the raw readings and their metadata, any remaining-life number can be traced back to the exact shot, instrument and technician that produced it.
The workbook fails for a structural reason, not a discipline reason. A spreadsheet stores an answer where a register should store an argument. When the 2019 column holds 0.412 and nobody recorded whether that was a five-point grid minimum or a single shot, whether the gauge was zeroed on a step wedge or a rat-tail, or whether the 0.500 baseline was nominal or measured, the long-term corrosion rate in the next cell cannot be defended. API 570 asks for short-term and long-term rates computed from actual measurements; API 574 treats an apparent thickness increase as measurement variability rather than metal growth. A register that holds readings as immutable observations and derives rates on demand answers both. It also lets you change a retirement thickness after a re-rate and watch every affected remaining life recalculate, instead of hunting for the six worksheets that hard-coded the old number.
Source: Written against API 570 (Piping Inspection Code), API 574 (Inspection Practices for Piping System Components), API 510, API 571 (Damage Mechanisms Affecting Fixed Equipment in the Refining Industry), API RP 580 and 581 (Risk-Based Inspection), API RP 584 (Integrity Operating Windows), API RP 932-B (reactor effluent air cooler corrosion control), API RP 941 (Nelson curves for high-temperature hydrogen attack), and ASME B31.3 for pressure design and retirement thickness.
| Workbook symptom | Root cause | Effect on the calculated rate | What the register holds |
|---|---|---|---|
| Corrosion rate hard-typed into the cell | Someone computed it once and pasted the value | Rate never moves when an earlier reading is corrected | Readings only; rates derived at query time |
| Metal appears to have grown since last campaign | New shot taken 200 mm from the old point, or a grid minimum compared against a single point | Negative rate, usually zeroed by hand with no note | Position, grid pattern and point index bound to each reading |
| Baseline of 0.500 in with no provenance | Nominal wall used as t-initial instead of a measured baseline | Long-term rate inflated by up to the 12.5 percent mill tolerance | Baseline flagged nominal or measured, with its source and date |
| Two engineers saved the same file | Last write wins; one crew's field results vanish silently | History has a hole nobody can see | Append-only rows with author, timestamp and no overwrite |
| Retirement thickness changed after a re-rate | Old t-min still embedded in six downstream sheets | Remaining life overstated on every affected circuit | t-min as a versioned attribute; recalculation cascades |
| Reading with no instrument or technician recorded | Field sheet transcribed as bare numbers | Number cannot be defended in an incident review or RBI study | Instrument serial, calibration block, procedure, surface temperature, technician and certification on every reading |
Why the workbook broke when the second editor arrived
A thickness workbook survives exactly as long as one person owns it. That person carries the undocumented rules in their head: that the 2017 column for the twelve-inch overhead line is a grid minimum while the 2019 column is a single shot, that the vacuum transfer line baseline was measured after the 2015 spool replacement rather than taken from the spec sheet, that three locations on the reboiler return were quietly retired when the piping was renewed. None of that is in the file. When a second engineer opens it, those rules do not transfer, and the first irreproducible number appears inside a week.
The failure is not carelessness. It is that a spreadsheet stores results while integrity work needs to store observations. A corrosion rate is not data; it is a conclusion drawn from two measurements, an elapsed interval, and a set of assumptions about whether those two measurements describe the same piece of metal. Excel has nowhere to put the assumptions, so they end up in a cell comment, a fill colour, or nowhere at all, and the conclusion outlives the reasoning that produced it.
The practical test is simple and most refineries fail it. Pick any remaining-life figure in the current inspection plan and ask the engineer to rebuild it from raw field records without calling anyone. If that takes more than ten minutes, the workbook has stopped being an integrity record and become a summary of one.
A CML is a physical place, not a spreadsheet row
The central design decision in a registry is that a condition monitoring location is an object with persistent identity, and a thickness reading is an event attached to it. The location carries the isometric reference, the line number, the circuit, the component type — elbow extrados, tee, reducer, straight run — the clock position, the distance from a named weld or flange face, the nominal and measured baselines, the material specification, the design conditions, and the retirement thickness together with its basis. The reading carries the date, the value or grid of values, the instrument, the calibration block, the procedure revision, the surface temperature and the technician.
That separation is what makes correction safe. If a 2021 reading is later found to have been taken on the wrong elbow, you void that observation and the rates recompute; you do not edit history into a shape that hides the error. If a location is retired because the spool was replaced, it is retired with a date and a reason, and its old readings stay attached to it instead of being deleted or, far worse, silently reused as the baseline for new metal.
It also solves re-findability, which is the quiet cause of most spurious refinery data. A location described as "12-CW-104 elbow" is not a place. A location described as "12-CW-104, elbow EL-07, extrados, six o'clock, 150 mm downstream of weld FW-12, five-point grid at 25 mm spacing, photograph attached" is one a different contractor can hit within a centimetre five years later.
Refinery circuits change when the crude slate changes
Refining is the one industry where the corrosion model is partly a function of a commercial decision taken this quarter. An opportunity crude with a higher total acid number changes naphthenic acid attack in the vacuum transfer line and the hot side of the tower. A higher chloride load moves the salt point in the atmospheric overhead and shifts where ammonium chloride deposits and hydrolyses. A change in hydrotreater severity changes ammonium bisulfide concentration in the reactor effluent air cooler, which API RP 932-B treats as a governing variable alongside velocity.
The consequence for a CML register is that circuit boundaries are not permanent. A corrosion circuit groups components expected to corrode at the same rate for the same reason. When the reason changes, the grouping is wrong, and every rate computed across the boundary is a blend of two different regimes. The register has to support redrawing a circuit without orphaning readings taken under the old definition, and without pretending pre-change history predicts post-change behaviour.
This is where integrity operating windows earn their place. API RP 584 asks for defined process limits whose exceedance triggers an integrity response. The register should be where an excursion is recorded against the affected circuits — a week inside the salt-point margin, a TAN spike, an overhead water pH dip, a wash water rate shortfall — so the next thickness campaign is planned against what the unit actually did rather than what it was designed to do.
The arithmetic traps that make a rate irreproducible
Long-term rate uses the original or a defensible baseline; short-term rate uses the most recent pair. Both are trivial arithmetic and both go wrong for the same handful of reasons. The most common is a baseline that was never a measurement. Seamless pipe is commonly supplied to a minus 12.5 percent mill tolerance, so a nominal 0.500 inch wall may have left the mill at 0.437. Using 0.500 as t-initial manufactures roughly 0.06 inch of corrosion that never happened, and the long-term rate that follows is fiction dressed as engineering.
The second trap is the apparent increase. When this campaign reads thicker than the last, the metal did not grow. Either the point moved, a grid minimum was compared against a different point in the grid, surface preparation or couplant differed, a temperature correction was applied on one campaign and not the other, or the earlier reading was a doubling error on thin wall. API 574 treats such increases as measurement variability, and a register should raise them as a data-quality exception rather than let an engineer overwrite the negative rate with a silent zero.
The third is a change of reporting convention mid-history. A five-point grid reported as a single minimum is a different quantity from one repeated point, and trending across the switch produces a rate that describes the paperwork rather than the pipe. The register must record which convention produced each number and refuse to trend across a change in convention without an explicit, logged acknowledgement by a named engineer.
Injection points, mix points and deadlegs need their own rules
API 570 singles out injection points because that is exactly where the general corrosion model stops applying. Wash water, corrosion inhibitor, neutralising amine and caustic all create a short zone of accelerated, highly localised attack that a circuit-average rate will never see. The conventional treatment is to bound the injection point circuit upstream by a short distance — commonly the greater of about 300 mm or three pipe diameters — and downstream through to the second change of flow direction, with tighter CML spacing and a shorter interval than the parent line.
A spreadsheet almost always loses this distinction. The injection point locations get filed with the line they sit on, inherit the line's interval, and quietly stop being inspected on the schedule that justified creating them in the first place. A register that treats an injection point as its own circuit type, with its own interval rule and its own location density, removes the failure by construction rather than by reminder emails before each turnaround.
Deadlegs and soil-to-air interfaces need the same treatment for the opposite reason. They are low-flow, stagnant or buried, so the process model does not predict them and the parent circuit rate under-reads them. Both belong in the register as named location classes with their own inspection logic, so that a decision to extend the parent circuit interval does not silently drag them along behind it.
What a turnaround does to a register
A refinery turnaround compresses several years of inspection into a few weeks, executed largely by contract crews who were not there last time, working from scaffolding that will be dismantled before anyone reviews the data. It is the single largest injection of readings the register will ever receive and the moment when data quality is most at risk, because the cost of a re-shoot rises by orders of magnitude the day access is removed.
The register earns its keep here by being the work list rather than the archive. Every location due in the turnaround is issued with its position description, its prior readings, its retirement thickness and an expected value band derived from its own history. A reading that lands outside that band is flagged while the scaffold is still standing. A location that cannot be reached is closed as a documented no-read with a reason code, never left blank, because a blank is indistinguishable from a missed inspection at the next audit.
Afterwards, the register is what turns tens of thousands of readings into a defensible next-inspection date for every circuit. That only works if ingestion was disciplined at the time. Reconstructing metadata from a contractor's PDF three months after the unit is back on line is precisely how a refinery ends up with the workbook problem again, at greater scale and with less memory of how the numbers were produced.
Feeding RBI: the register is the input, not the output
Risk-based inspection under API RP 580 and 581 consumes the thickness history rather than replacing it. The probability side depends on measured corrosion rate, the uncertainty around that rate, the effectiveness of past examinations, and the damage mechanisms credible for the circuit under API 571. Every one of those is an attribute of the CML record. A spreadsheet supplies a number; it cannot supply coverage, technique or inspection effectiveness, because it was never asked to hold them.
This is the concrete reason many refineries outgrow workbooks at one identifiable moment: the first RBI study. The analyst asks for extent and effectiveness per examination and discovers the plant holds thickness values stripped of the context that would make them evidence. The study then runs on assumed effectiveness, produces intervals the inspection group does not trust, and gets rerun three years later at full cost.
A register designed for this stores each examination with its extent — spot, grid, scan, full corrosion map — its technique, and its coverage as a proportion of the component. That is what allows an RBI model to distinguish a five-point spot check from a mapped weld band, and it is also what lets an owner argue for a longer interval on evidence rather than defend a shortened one on suspicion.
How to evaluate a CML registry when reproducibility is the requirement
Bring one of your own irreproducible numbers to the demonstration. Ask the vendor to load the raw readings behind it and show, on screen, every input to the remaining-life figure: which readings were used, why others were excluded, what retirement thickness applied on that date, and who approved the result. A system that stores rates rather than deriving them cannot do this, and the difference is completely invisible in a slide deck.
Then ask three questions that separate genuine registers from formatted spreadsheets. Can you correct a historical reading without destroying the audit trail, and does everything downstream recompute? Can you change a retirement thickness once and have every affected circuit reflect it immediately? Can two inspectors work the same circuit at the same time without either of them losing work?
Finally, test the exit. Ask for a complete export — locations, readings, metadata, attachments, calculation basis — in an open format, and confirm you can reload it somewhere else. An integrity record that exists only inside one vendor's product has reintroduced the original problem with better styling. Atlantis builds this module on an open, fully customisable Odoo-based platform, and a working demonstration against your own circuit data is available on request through info@atlantisndt.com.
Can a CML register reproduce a corrosion rate calculated five years ago?
It can if it derives rates instead of storing them. Reproduction means pulling the two readings used, showing why any others were excluded, showing the retirement thickness in force on that date, and showing who approved the result. A register that keeps readings as immutable observations, versions t-min, and logs every correction can rebuild the figure on demand. One that saved the answer into a field cannot, no matter how the screen is laid out.
Should the baseline thickness be nominal wall or the first measurement?
Use a measured baseline wherever one exists. Seamless pipe is routinely supplied to a minus 12.5 percent tolerance, so a 0.500 inch nominal wall may have left the mill at 0.437. Trending from nominal invents roughly 0.06 inch of corrosion that never occurred and inflates the long-term rate accordingly. Where no measured baseline exists, record that fact explicitly on the CML so the resulting rate is read as an upper bound rather than a fact.
How many CMLs does a refinery piping circuit actually need?
Enough to represent every distinct corrosion condition in the circuit, not a fixed count per line. A circuit that shares one damage mechanism and one flow regime may be well characterised by a handful of locations biased toward elbows, tees, reducers and downstream of flow disturbances. Injection points, mix points, deadlegs and soil-to-air interfaces do not belong to that population at all and need their own locations, spacing and interval.
What happens to the register when the crude slate changes?
Circuit boundaries stop being valid. A corrosion circuit groups components expected to corrode at the same rate for the same reason, and a higher total acid number or a shifted chloride load changes the reason. The register must let you redraw circuits and revise damage mechanisms without orphaning readings taken under the old definition, and must mark the changeover so nobody trends a pre-change rate straight through into post-change remaining life.
Does a thickness register replace an RBI study?
No. It supplies the study. API RP 580 and 581 need measured rate, rate confidence, the damage mechanisms credible for the circuit under API 571, and the effectiveness of past examinations. Effectiveness depends on technique, extent and coverage, which are attributes of the examination record, not of the thickness number. Plants that hold values without that context end up running RBI on assumed effectiveness and producing intervals their own engineers do not believe.
Is API 510, 570 or 653 inspector training part of this offer?
No. Those are API individual certification programmes and this module does not deliver or prepare candidates for them. Atlantis provides NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, ASNT Level III consulting, report validation, inspection management and reporting software, digital twins and 3D laser scanning. The registry is software for holding and defending inspection data, not a certification course.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.