Moving Years of Offshore Thickness History Into a New Registry Without Inventing Corrosion

A CML and TML registry holds every thickness monitoring location's identity, position and reading history. Migrating an upstream or offshore programme into one is dangerous because legacy records mix measured and nominal values, computed and observed quantities, and inconsistent units. Import them uncritically and the new system produces a remaining life distribution that is confidently wrong on day one.

Offshore integrity data is usually older than the systems holding it. A twenty-year-old platform has passed through a proprietary contractor database, one or two commercial integrity applications, and long stretches of spreadsheet maintenance, with scanned handwritten field sheets underneath all of it. Each transition lost something. Baselines were entered as nominal wall rather than measured. Corrosion rates were stored as computed values and then re-imported as if they were observations. Locations were deleted rather than retired when a spool was replaced, taking their history with them. Readings arrived in millimetres from one contractor and inches from another. None of this is visible in a summary report. It becomes visible the moment a new system recomputes remaining life from first principles and produces a different answer than the old one for several hundred circuits. The migration protocol, not the software, decides whether that difference is a discovery or a disaster.

Source: Written against API 570 and API 574 for condition monitoring practice, API 510 for pressure vessels, API 571 for damage mechanism definitions including CO2 corrosion, erosion-corrosion and microbiologically influenced corrosion, ANSI/NACE MR0175 with ISO 15156 for sour service materials, API RP 14E for erosional velocity practice and its limits, ASTM A106 and A312 for permitted mill wall tolerance, ASME B31.3, 30 CFR Part 250 for United States outer continental shelf operations, and the United Kingdom Offshore Installations (Offshore Safety Directive) Safety Case Regulations 2015 verification requirements.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Legacy record conditions and the migration rule each one demands
Legacy fieldHow it was typically recordedMigration failure it causesRule for the new registry
Baseline thicknessNominal pipe schedule entered at commissioning, never measuredFirst real reading appears as up to 12.5 percent loss overnight because mill under-tolerance is permitted on seamless pipeImport as nominal, flag as unmeasured, and exclude from any corrosion rate until a measured baseline exists
Corrosion rateStored as a computed number in the legacy tableCannot be re-derived, cannot be audited, and silently overrides the new system's own calculationNever import. Import readings only, recompute, and reconcile the result against the legacy value
UnitsMillimetres from one contractor era, inches from another, sometimes mixed within a circuitA 0.375 value interpreted in the wrong unit passes every range check and corrupts one circuit invisiblyStore a canonical unit with the as-recorded unit and value preserved alongside it
Retired locationsDeleted when the spool was replacedHistory vanishes, and the circuit appears to have started life at the last turnaroundRetire with a reason and a date, never delete, and keep the retired history queryable
Non-numeric entriesNR, NA, blocked, 0.000 and free text in a numeric columnZeros treated as readings drive remaining life to zero, or the whole record is discardedMap each code to an explicit not-taken reason with the obstruction recorded
Location descriptionA line number and a sequence integer with no datumTwo crews cannot converge on the same steel, so scatter is read as corrosionRequire a physical datum, offset and clock convention before the location is considered migrated
Reading metadataProbe, couplant, temperature and surface condition absentHigh-temperature readings not velocity-corrected are pooled with ambient onesCarry metadata where it exists, and mark readings without it as lower confidence rather than equal
The reconciliation step is the whole protocol. Every circuit where the recomputed remaining life differs from the legacy value by more than an agreed tolerance is investigated individually before go-live, and the explanation is recorded. A migration that reports zero differences has almost certainly imported the old conclusions rather than recomputing them.

What is actually inside the legacy system

The tidy version of an offshore integrity migration is a table of locations with a table of readings hanging off it. The real version is layered. There is a core register created when the platform was commissioned, using a numbering scheme that encoded the line number and a sequence integer. There is a second layer from a re-lining or a project that renumbered part of the topsides and never fully propagated. There is a contractor-maintained database covering a period when inspection was outsourced. And underneath, boxes of scanned field sheets covering the years before any of it.

Each layer has its own conventions and its own gaps, and the seams between them are where the damage sits. A location that changed identity during a renumbering typically appears as two records, each holding half the history, and the corrosion rate computed on either half understates the total. Nobody notices, because the summary report only ever shows the current record.

Before any technical migration work begins, the single most valuable exercise is a census: how many locations, how many readings, across how many source systems and eras, in what units, and how many have a physical description good enough to re-find them. That census usually reframes the project. Teams that expected a data transfer discover they have a data reconstruction with a data transfer at the end of it.

The trap that fabricates twelve percent of corrosion

Seamless pipe manufactured to ASTM A106 may be supplied up to 12.5 percent under the nominal wall thickness, and this is entirely permissible. On a nominal 0.280 inch wall, that permits a genuine as-delivered thickness of 0.245 inches with no corrosion whatsoever. Legacy registers routinely recorded the nominal value as the baseline, because at commissioning nobody had measured anything and the schedule value was what was available.

When the first real ultrasonic reading arrives years later at 0.248 inches, the system sees 0.032 inches of loss. If that is spread over the elapsed years since commissioning it may look benign, but if the baseline date and the first reading date are close together, or if the interval was recorded incorrectly during a previous migration, the computed rate can be extreme. Offshore, where circuits are numerous and review time is scarce, these propagate straight into the remaining life ranking that drives scope.

The rule is simple to state and requires discipline to apply. A baseline that was never measured is not a reading. Import it, mark it as nominal, display it, and refuse to let it anchor a corrosion rate calculation. The first genuine measurement becomes the baseline, and the circuit carries a documented note that its early history is nominal. This costs the programme some apparent history and saves it from confidently wrong numbers.

Migrate observations, never conclusions

Legacy integrity tables are full of derived quantities: short-term rate, long-term rate, remaining life, next due date, sometimes a risk rank. Every one of them is a conclusion drawn by a previous system under assumptions nobody wrote down. Importing them feels efficient and it is the most common way a migration goes wrong, because it makes the new system's own calculations decorative.

The alternative is to import only what was observed: this thickness, at this location, on this date, by this technician, with this equipment, under these conditions. Everything else the new system computes. That has an immediate and uncomfortable consequence, which is the point of the exercise. The recomputed remaining life will disagree with the legacy value on a meaningful fraction of circuits.

Those disagreements are the deliverable. Each one is either a legacy error, a new configuration error, or a genuine difference in engineering basis, and all three need to be known before anyone plans a campaign against the new numbers. A migration that produces no disagreements has not recomputed anything. It has copied the old answers into a new interface and inherited every mistake in them without inheriting the ability to find them.

Offshore damage mechanisms the old identifiers were never built to carry

Upstream fluids are aggressive in ways the original register often did not describe. Carbon dioxide in produced fluids drives sweet corrosion whose rate is strongly dependent on temperature, partial pressure and water wetting, so two circuits on the same platform can differ by an order of magnitude. Where hydrogen sulphide is present, materials selection falls under ANSI/NACE MR0175 and ISO 15156 and the concern shifts partly from wall loss to cracking. Sand production drives erosion and erosion-corrosion at chokes, at the first bends downstream and at any geometry that turns the flow.

Water injection systems add microbiologically influenced corrosion and under-deposit attack at low points and dead legs. Wet gas lines can suffer preferential weld corrosion, which is invisible to a grid that reads parent metal either side of the weld and never the weld itself. Externally, the splash zone and the underside of topsides piping in a marine atmosphere corrode on a schedule of their own, and corrosion under insulation on heated lines does the rest.

A legacy identifier encoding only a line number and a sequence integer cannot express any of this. Part of the migration is therefore enrichment, not transfer: attaching an API 571 mechanism to each location, recording whether the point was chosen for a geometric reason such as an elbow extrados, and flagging the locations where the correct method is now corrosion mapping or weld-specific inspection rather than a spot reading. Skipping the enrichment produces a faster migration and the same blind spots in a newer database.

A missed location offshore costs more than the reading

Onshore, a location missed during a campaign is recovered with a truck and a technician. Offshore it is recovered with a helicopter seat, a bed, a weather window and, on a busy installation, a bump of somebody else's scope. Persons on board is a hard constraint, and inspection competes for it with drilling support, projects and maintenance. That economics is why offshore integrity teams care disproportionately about first-pass completion rate.

The registry is what makes first-pass completion achievable. A crew arriving with the previous readings, the datum description, the photograph, the access requirement and the surface preparation expected can work through a scope without returning to the office for clarification. A crew arriving with a list of identifiers spends its first day rediscovering the platform.

It also changes what belongs in the record. Scaffold requirement, rope access requirement, whether the point sits inside a hazardous area requiring a specific permit, and whether the last crew found it obstructed by a later piping modification are all things that cost a return trip if they are unknown and cost nothing to record. An obstructed location noted once and never resolved is a standing item that should surface every planning cycle rather than being rediscovered by each new crew.

Three audiences read the same history and want different things

An offshore operator's thickness history is read by more parties than a refinery's. The regulator wants evidence of a controlled system, whether that is a safety and environmental management system under 30 CFR Part 250 on the United States outer continental shelf or a safety case with a verification scheme under the United Kingdom regulations. In the latter case an independent competent person examines safety critical elements against a written scheme, and the inspection evidence has to be traceable and contemporaneous.

For a floating production unit, a classification society adds a further cycle with its own survey periodicity, and reconciling class survey requirements with API 510 and API 570 intervals for the same equipment is a routine planning headache. The two schemes were not designed together, and an item can be current under one and overdue under the other.

The registry cannot resolve the regulatory overlap, but it can stop it from generating duplicate work. One location, one history, multiple obligations attached to it, each with its own due date and its own audience. What must be avoided is the common pattern where class-driven inspection and integrity-driven inspection maintain separate records of the same steel, because they will diverge and the divergence will be found by whichever auditor arrives first.

A migration protocol that will survive an audit

Start with the census and freeze the source. Take a dated, hashed extract of every source system and keep it unchanged for the duration, so that any question about what the legacy system said has a single answer. Continuing to edit the legacy data during migration is how teams end up unable to explain their own numbers.

Migrate in the order identity, position, observation, then enrichment. Establish the location identities and their aliases first, including retired ones. Attach the physical descriptions and flag every location that lacks a re-findable datum as incomplete rather than migrated. Then load readings as observations with their source document reference retained. Only then attach mechanisms, criticality and inspection strategy.

Run the reconciliation before go-live, not after. For every circuit, compare the recomputed remaining life against the legacy value, and investigate every difference beyond an agreed tolerance individually, recording the cause. Publish the resulting list. It is uncomfortable reading and it is also the single strongest piece of evidence that the new system is trustworthy, because it shows exactly where and why it disagrees with what came before.

How to test a vendor's migration claim before you sign

Hand over a deliberately ugly sample: a few hundred readings including nominal baselines, mixed units, a renumbering seam, some NR and 0.000 entries and a spool replacement. Ask for the loaded result and the exception report. A vendor whose loader accepts all of it cleanly has silently made decisions on your behalf, and every one of those decisions is now embedded in your remaining life numbers.

Ask specifically what the system does with a zero. A 0.000 entry in a legacy thickness column is almost never a measurement, and a loader that accepts it will produce a location with no remaining life and an emergency flag, or will discard the whole record and lose the surrounding readings. The correct behaviour is to quarantine it as a coded non-reading and ask.

Then ask to see the reconciliation report format before the project starts. If the vendor cannot show you what the disagreement report between legacy and recomputed values will look like, they are not planning to produce one, which means they are planning to import your old conclusions. Atlantis runs this exercise against a real extract during scoping, and the output of that exercise, the exception list and the reconciliation format, is usually more informative than any demonstration. Requests go through info@atlantisndt.com.

What is the mill tolerance trap and why does it wreck a migration?

Seamless pipe to ASTM A106 is permitted to be supplied up to 12.5 percent under nominal wall. If a legacy baseline was entered as the nominal schedule value rather than measured, the first genuine ultrasonic reading can appear as a large sudden loss that never happened. Migrate that pairing into a system that computes long-term corrosion rate from baseline to latest, and it will report a severe rate on steel that has barely corroded.

Why should computed corrosion rates never be imported?

Because a computed number carries no provenance. You cannot tell which readings produced it, whether the interval was right, whether an off-datum reading was included, or which convention for short-term and long-term rate was used. Importing it also means the new system's calculation is being overridden by an unauditable value. Import the observations, recompute everything, then treat every disagreement with the legacy figure as a question that needs an answer.

Is API 510, 570 or 653 inspector training part of this offer?

No. Those certifications are administered by API and sit entirely outside what Atlantis provides. Atlantis supplies inspection management software, reporting software, digital twin platforms, 3D laser scanning, report validation and ASNT Level III consulting, and delivers NDT method training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD. A data migration is an engineering and software exercise, not a certification pathway.

How do permanently installed thickness sensors change the registry design?

They create a second class of location that reports continuously rather than on a campaign. Offshore this is attractive because it removes readings from the scaffold and bed-space budget entirely. The registry has to model sensor-fed and manually read locations distinctly, because the sensor's repeatability characteristics, drift behaviour and temperature compensation differ from a hand-held probe, and pooling the two into one trend produces artefacts at every changeover point.

What should happen to readings that cannot be tied to a known location?

Retain them as unassigned rather than discarding or force-fitting them. Offshore migrations routinely surface field sheets from a campaign whose location register no longer exists. Those readings are still evidence, and a later isometric review often resolves them. Force-fitting them to the nearest plausible location is worse than leaving them unassigned, because it puts an unverifiable point into a corrosion trend that someone will later rely on.

How long should the old system be kept running after cutover?

Through at least one full inspection campaign, in read-only form, so that a disputed number can be traced to its original record without a restore. The parallel period also gives the reconciliation report a live test: when the new campaign's readings land, the recomputed rates should behave sensibly against the retained history. Decommissioning the legacy system before that point removes the only reference the migration can be checked against.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.