Building a CML Registry That Survives a Tank Out-of-Service Window
A tank terminal CML registry stores every shell, floor, roof and nozzle monitoring location as a persistent record with its own course, elevation, access method, nominal and retirement thickness, and full reading history. That structure lets you freeze an API 653 out-of-service scope weeks before degassing, because the registry already tells you how many locations exist, where they sit, and what it takes to reach them.
Terminals are not refineries. There is no unit-wide turnaround; there is a single tank pulled from service while the rest of the facility keeps moving product, and the window is set by lease commitments and seasonal demand rather than by a maintenance calendar. Degassing, cleaning and sludge disposal consume the front of that window, so the inspection scope has to be frozen before anyone can see the metal. That is only possible if last campaign's registry survived intact: every shell CML tied to its course and elevation, every floor grid point tied to a plate number, every prior indication recorded with its disposition, and every location carrying the access method needed to reach it. API 653 sets the evaluation rules and the twenty-year ceiling on internal intervals, but it does not tell you how to keep 300 monitoring locations re-findable across two decades and three inspection contractors. That is the registry's job.
Source: Sources: API 653 Tank Inspection, Repair, Alteration and Reconstruction (shell, bottom and roof evaluation in Section 4; inspection intervals in Section 6, including the twenty-year ceiling on internal inspection); API 575 Inspection Practices for Atmospheric and Low-Pressure Storage Tanks; API 570 for terminal transfer piping; API RP 580 and API RP 581 for risk-based interval setting; ASME Section V for ultrasonic and magnetic flux leakage examination requirements; EPA SPCC rule 40 CFR 112.8(c)(6) integrity testing and 40 CFR 112.20 facility response plans; STI SP001 for shop-fabricated tanks; API 939-E for ethanol service considerations.
| Location class | Minimum record fields | Why the terminal case differs | Governing evaluation |
|---|---|---|---|
| Shell course CML | Course number, elevation, clock position, nominal wall, course-specific t-min, joint efficiency, access class | Required thickness changes with course, fill height and product specific gravity, so a stored number goes stale after any service or level change | API 653 Section 4 shell evaluation |
| Annular ring and critical zone | Plate identifier, radial offset from the shell, weld seam reference, coating condition, prior repair history | The critical zone next to the shell is frequently the governing find and drives bottom-course decisions | API 653 bottom and annular plate evaluation |
| Floor plate grid point | Plate number, grid coordinate, MFL coverage percentage and reporting threshold, prove-up method, topside or underside attribution | MFL screens and UT proves up; without the scan parameters recorded, two campaigns are not comparable | API 653 bottom evaluation using minimum remaining thickness |
| Floating roof deck and pontoon | Deck panel identifier, pontoon compartment number, leg setting at inspection, seal condition, vacuum box or penetrant result | Reachability depends on roof position, leg landing and vapour clearance rather than on scaffold alone | API 653 roof evaluation with API 575 practice |
| Nozzle, manway and shell penetration | Nozzle tag, size and schedule, reinforcing pad test result, link to the adjacent shell CML | Nozzle necks and repads concentrate settlement damage and product-change effects | API 653 evaluation against the original ASME Section VIII design basis |
| Terminal transfer piping circuit | Circuit identifier, component type, clock position, injection point or dead-leg flag, circuit classification | Transfer piping sits under API 570 while the tank sits under API 653, and the two intervals rarely align | API 570 piping circuit rules |
A terminal window is one tank, not a unit turnaround
In a refinery the turnaround is a coordinated shutdown of an entire unit, and every discipline queues for the same window. A terminal works the opposite way. The facility never stops. One tank comes out of service while product keeps moving through the rest of the tankage, and the window that tank gets is negotiated against throughput commitments, lease agreements with the customers who own the product, and the seasonal shape of demand. A gasoline tank that has to be back in service before a seasonal volatility transition, or a distillate tank that has to be full before winter, carries a return date that no inspection finding is going to move.
That constraint has a direct consequence for the registry. Degassing, washing, sludge removal and waste disposal consume the front of the window, and nobody enters the tank until they are finished. Scaffold contracts, rope access teams, vacuum trucks, long-lead plate material and the authorised inspector are all committed before anyone sees bare metal. The scope therefore has to be built entirely from what you already know: which monitoring locations exist, where they sit, what they read last campaign, and what it costs to reach them. If that information is spread across three PDF reports from three different contractors, the scope is a guess, and the guess is reliably low.
The second consequence is that scope growth is unusually expensive here. In a large turnaround a discovered problem competes for shared resources and can often be absorbed. At a terminal there is one tank, one crew and one dike. An unplanned floor repair does not get absorbed; it extends the outage day for day against a contractual return date, and in a leased tank it may trigger commercial consequences that dwarf the cost of the repair itself. A registry earns its keep by shrinking discovery, not by documenting it afterwards.
A monitoring location and an indication are not the same record
Most thickness software models exactly one thing: a location that receives a reading every campaign, indefinitely. Terminal tanks generate two other kinds of record that do not fit that shape, and forcing them into it is how history gets lost. A shell CML is genuinely persistent, because you intend to return to the same point on the same course for two decades. A floor indication is not persistent at all. It is a discrete feature found during a magnetic flux leakage scan, proved up with ultrasonics or a pit depth gauge, dispositioned by the evaluator, and very often removed from existence by a patch plate before the tank returns to service.
If that indication is stored as a CML, it pollutes every trend it touches, sitting in the corrosion rate calculation as a location with one reading and no future. If it is stored only in the report narrative, it effectively disappears, and the next campaign cannot answer the question the inspector will certainly ask, which is what was at this coordinate last time and what was done about it. The registry needs three distinct classes: recurring monitoring locations, indications with a found date and a disposition, and repairs with their own installation date, material and baseline.
Repairs deserve particular attention because they reset the arithmetic. A patch plate installed in one campaign has that campaign's baseline and its own corrosion rate from that point forward. Averaging its readings with the surrounding original floor understates loss on the old plate and overstates it on the new one. A registry that cannot represent a repair as a new component with a new baseline will quietly corrupt the bottom evaluation on every tank that has ever been repaired, which at a working terminal is most of them.
One t-min across all shell courses is the most common arithmetic error
API 653 evaluates shell thickness course by course, because the hydrostatic head acting on a course depends on how much product sits above it. The bottom course carries the largest head and the largest required thickness; the top course carries almost none. The required minimum is a function of tank diameter, the height of product above the course, the specific gravity of the stored product, the allowable stress for the shell material, and the joint efficiency of the original construction. None of those are constant across a tank, and at least two of them are not constant across a tank's life.
The failure mode is banal and widespread. Somebody computes a required thickness once, types the number into a spreadsheet column, and it propagates through every subsequent report. Applied to the upper courses it condemns steel that is entirely serviceable and generates repair scope nobody needed, which at a terminal means scaffold time and plate that were bought against a fixed window. Applied to the bottom course it does the opposite, and that is the direction that matters.
Product service is the change that catches people out. Moving a tank from gasoline at roughly 0.74 specific gravity to a denser product raises the required thickness on every course without a single thousandth of an inch of metal being lost. Reducing the maximum operating level after a settlement survey lowers it. In both cases, every historical evaluation on that tank is now computed against the wrong denominator. A registry that derives required thickness from a stored design basis can re-evaluate the entire reading history the moment the basis changes. One that stores a typed number cannot, and nobody notices for a decade.
Floor grids, MFL screening and the prove-up problem
The tank bottom usually governs the internal inspection interval, and the bottom is measured differently from everything else on the tank. Magnetic flux leakage scanning is a screening technique. It detects volumetric metal loss and estimates it as a percentage of wall, with an accuracy that depends on plate thickness, coating thickness, sensor lift-off, scan speed and the calibration plate used. It does not produce a thickness. Prove-up with ultrasonics or a pit depth gauge produces the number that goes into the evaluation, and only the proved-up value belongs in the arithmetic.
A floor campaign therefore generates two data sets that must both be recorded and must never be confused. The first is coverage: which plates were scanned, at what percentage, with what reporting threshold, using what equipment and calibration. The second is the proved-up measurements at specific coordinates. If the coverage parameters are not stored, the next campaign cannot compare like with like. A full scan reported at a twenty per cent threshold and a partial scan reported at a forty per cent threshold will produce very different indication counts on a floor that has not changed at all, and somebody will read the difference as deterioration and buy a floor.
Attribution is the third thing to record. API 653's bottom evaluation projects a minimum remaining thickness forward using corrosion rates, and topside and underside loss behave differently. Topside loss follows water bottoms, sediment and product chemistry. Underside loss follows soil-side conditions, the release prevention barrier and the state of cathodic protection, and only one of those is affected by a new internal coating. A grid point recorded without stating which side the loss was on gives the evaluator no defensible basis for choosing a rate, so the evaluator chooses conservatively, and conservative on a tank bottom means an earlier and far more expensive next outage.
Access class is the real cost driver, not the CML count
Estimators are handed a location count and multiply it by a blended rate per reading. On a storage tank that method is wrong by a factor of two or three, because the cost of a shell reading is almost entirely the cost of getting a qualified technician to the metal. Courses one and two are typically reachable from grade or a small manlift. Above that you are into elevated work: a manlift with the reach and the ground bearing pressure to be positioned inside a diked area, a swing stage, erected scaffold, or a rope access team working to a recognised rope access scheme.
The productivity difference is not marginal. A technician working from grade can take a hundred or more thickness points in a shift. The same technician on rope, in a team that cannot be smaller than two working technicians plus a supervisor, covers a fraction of that, and every reposition is a rigging change with its own hold points. Add the containment dike, whose wall and slope block wheeled access to a substantial arc of the circumference on many terminal tanks, and the reachable-from-grade fraction is considerably smaller than the plot plan suggests.
The fix is to make access a first-class field on every location rather than a sentence in a report. Each CML carries an access class: grade, manlift, scaffold, rope, roof, or confined space entry. The registry can then produce a scope that reads as hours and crew composition rather than as a count of readings. That is the number you can sign a scaffold contract against and book a rope crew against before the tank is degassed, which is the entire reason for building the registry before the window opens.
Service changes break the corrosion rate, not just the required thickness
Terminals change what they store, sometimes several times in a tank's life. A tank runs gasoline, then a ten per cent ethanol blend, then a renewable diesel or fatty acid methyl ester blend, then perhaps jet. Each service brings its own mechanism. Ethanol and biodiesel blends hold and release water differently and support microbiologically influenced corrosion at the water interface and in the floor sump region. Heated products cycle the shell thermally and introduce the possibility of heating coil leaks. Jet fuel makes coating and lining condition more commercially consequential than a few thousandths of shell loss, because the product specification is unforgiving about particulate and free water.
A corrosion rate computed straight across a service change is a blended fiction. Six years in a benign service averaged with three years in an aggressive one produces a number that describes neither period and systematically understates the mechanism currently running. Terminal registries should carry service history as a timeline on the tank, compute rates within a service epoch, and flag any location whose reading span crosses a change so that a human decides how to treat it rather than an average deciding silently.
The same timeline earns its keep a second time during outage planning. Knowing that a tank has been in a water-bearing blend since the last internal tells the planner to expect floor and sump scope, to book more prove-up capacity than the location count implies, and to hold a coating contractor provisionally. That is a scope decision made from stored data weeks before anyone opens a manway, and it is precisely the difference between a planned outage and a discovered one.
The registry is an SPCC record whether or not you designed it as one
Petroleum storage terminals in the United States sit under the EPA's Spill Prevention, Control and Countermeasure rule, and the integrity testing provision at 40 CFR 112.8(c)(6) requires testing on a regular schedule combined with visual inspection, in accordance with recognised industry standards. The facility's professional-engineer-certified SPCC plan names the standard it follows, commonly API 653 for field-erected tanks or STI SP001 for shop-fabricated ones, and the intervals stated in that plan become the facility's own commitment. Facilities that could reasonably be expected to discharge into navigable waters carry facility response plan obligations under 40 CFR 112.20 in addition.
The practical consequence is that the thickness registry is evidence, not merely a maintenance convenience. When a regulator or an auditor asks how the interval on a particular tank was set, the answer has to be reconstructable in full: which readings, taken by whom, under which written procedure, with instruments calibrated when, evaluated against which required thickness and which fill height. Data that lives in a contractor's proprietary system, or in a spreadsheet that has been edited in place for a decade with no version history, cannot answer that question in a form anyone will accept.
There is also a change-control point that operators tend to discover late. Moving from a calendar-based interval to a risk-based interval, or extending an interval on the strength of a release prevention barrier and a supporting evaluation, changes the basis stated in the SPCC plan and is therefore a plan amendment requiring professional engineer certification. A registry that timestamps interval changes, records the justification and retains the superseded basis makes that amendment a short piece of paperwork. One that simply overwrites a next-due date makes it an archaeology project conducted under time pressure.
What to ask a vendor before the scope freeze date
The questions that separate systems are narrow. Can required thickness be derived from the tank's design record rather than typed in, and does the system re-evaluate history when the design basis changes? Can it hold indications and repairs as record types distinct from monitoring locations, each with its own dates and dispositions? Does every location carry an access class, and can the system produce a scope expressed in crew hours by access class rather than in counts? Can it store MFL coverage parameters alongside proved-up measurements, and will it refuse to compute a rate from a screening estimate?
A second set of questions concerns handover, because terminals change inspection contractors and contractors change software. Can the full registry, including reading history, procedures, calibration references and inspector credentials, be exported in an open format at any time without vendor assistance? Is the export complete enough that a different system could rebuild the trend? Who holds the data if the contract ends mid-campaign? Terminals that have lived through one contractor transition without a clean export rarely need this explained twice.
Finally, ask to see the system fail. Load a real tank from your own history, including the messy parts: a service change, a patch plate, a course where the required thickness was revised, a floor campaign with partial coverage. A demonstration built on clean synthetic data proves nothing, because clean data is not the problem you are buying a solution to. Atlantis will run that exercise against your own records as part of a scoping consultation, and the output should be a scope you could hand to a scaffold contractor before the tank is degassed.
How many CMLs should a 120-foot storage tank actually carry?
There is no correct count, only a defensible basis. Shell CMLs are normally set per course with enough circumferential spread to catch preferential wetting and dead bands, floor coverage is set by the MFL scan plan rather than by discrete points, and nozzles and repads are treated individually. What matters far more than the number is that each location has a course, an elevation, a clock position and an access class, because a location you cannot re-find contributes nothing to a corrosion rate.
Can one t-min be applied across all shell courses?
No, and doing it is the most common arithmetic error on tank data. API 653 evaluates each course against the hydrostatic head above it, so required thickness falls as you move up the shell. Applying the bottom-course value everywhere condemns sound upper-course steel and manufactures repair scope; applying an upper-course value low down is the dangerous direction. Derive t-min from diameter, fill height, specific gravity, allowable stress and joint efficiency, and recompute it whenever any of those change.
How do you keep a floor indication findable after the plate is patched?
Store it as an indication record, not as a CML. It needs a found date, plate number, coordinate, the MFL amplitude or estimated wall loss, the proved-up measurement, and a disposition. When a patch plate is installed, the registry should create a new component with its own installation date, material and baseline thickness, and link it to the indication that caused it. The next campaign can then answer what was here, what was done, and what has happened since the repair.
What happens to corrosion rate history when a tank changes product service?
The rate becomes a blend of two different mechanisms and describes neither. Gasoline, ethanol blends, fatty acid methyl ester blends, jet and heated products carry different water behaviour, different microbiological risk and different thermal cycling. A registry should hold service history as a timeline on the tank and compute rates within a service epoch, flagging any location whose reading span crosses a change rather than quietly averaging across it. The same timeline predicts where the next campaign's scope will land.
Does the registry need to record how each CML is reached?
Yes, because access dominates cost. A technician working from grade takes many times the readings per shift that the same technician takes on rope, where the team cannot be smaller than two working technicians plus a supervisor and every move is a rigging change. Containment dike geometry also blocks wheeled access to a large arc of many tanks. Without an access class on each location, an estimate built by multiplying CML count by a blended rate is wrong by a large factor.
Is API 510, 570 or 653 inspector training part of this offer?
No. API 510, 570 and 653 inspector certification is administered by API through its own examination programme, and Atlantis is not an API certification training provider. What Atlantis does deliver is NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, ASNT Level III consulting, third-party report validation, 3D laser scanning, and the inspection management software described on this page. Demonstrations and scoping consultations are available on request.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.