Bringing a legacy pipeline corrosion history into a system that can recompute it
In midstream, corrosion rate calculation has to reconcile two incompatible evidence streams: fixed measurement locations on station piping and tanks, where API 570 and API 653 short-term and long-term rates apply directly, and in-line inspection run comparisons on the line pipe, where growth is inferred from two tool readings each carrying roughly ten percent wall tolerance. A migration succeeds when both streams land with their provenance intact.
A legacy midstream corrosion history is rarely one dataset. It is a thickness database for station piping, twenty years of in-line inspection deliverables in successive vendor formats, a folder of scanned dig sheets, an alignment sheet set, a pipe tally, and a spreadsheet of corrosion rates that nobody can trace back to a reading. The new system expects an asset, a measurement location, a dated thickness and a baseline. Half of that history has no measurement location, because an in-line inspection feature is not a fixed point — it is an object whose identity between runs is inferred from a girth weld count that repairs have changed. So the migration is not a column-mapping exercise. It is a reconstruction of identity, of the joint-level wall thickness each depth percentage refers to, and of the provenance of every rate you intend to keep. Decide the provenance rule before the first record loads, because it cannot be reconstructed afterwards.
Source: Basis: 49 CFR Part 192 Subpart O and 49 CFR 195.452 integrity management, including their condition-response and reassessment-interval requirements; 49 CFR 195.432, which directs aboveground breakout tank inspection to API 653; API 570 §7.1.1 for station piping corrosion rate and remaining life; ASME B31.8S and API 1160 for integrity management methodology; ASME B31G, modified B31G and API 579-1/ASME FFS-1 Part 5 for remaining strength of corroded pipe; AMPP/NACE SP0206, SP0208 and SP0110 for internal corrosion direct assessment; API 5L and ASTM A106 wall thickness tolerances.
| Evidence source | What it actually measures | Dominant uncertainty | Interval before growth beats the noise | Migration hazard |
|---|---|---|---|---|
| Fixed UT locations on station piping | Wall thickness at a repeatable point | Probe, couplant, surface, temperature and technician, around ±0.005 in | Two to four years at typical station corrosion rates | Location identifiers reused after a spool replacement, so the long-term rate is computed across a new weld |
| Magnetic flux leakage in-line run pair | Depth of a metal-loss feature as a percentage of assumed nominal wall | Commonly ±10% of wall at 80% certainty per run | Five to ten years unless features are individually re-analysed | Feature identity between runs rests on a girth weld count that repairs and tie-ins have altered |
| Ultrasonic in-line inspection | Remaining wall directly, in engineering units | Tighter than MFL but sensitive to cleanliness and coupling | Four to seven years | Depth convention flips between remaining wall and loss depth across vendors and file generations |
| Direct examination at an excavation | True remaining wall over a mapped area | Small, provided the grid is dense and properly referenced | Immediate, but only for that one location | Dig reports survive as scanned PDFs with no structured depth values to import |
| Electrical resistance probes and coupons | Corrosivity of the fluid at one point in the system | Placement; a probe at twelve o'clock never sees water-line attack | Weeks to months for corrosivity trend | Legacy corrosivity values imported into the same field as measured wall loss |
| Cathodic protection and coating surveys | Likelihood of external attack, not a rate at all | Interference currents and IR drop | Not a thickness rate under any interval | Survey findings mapped into the corrosion rate field because the column existed |
The job: a history in a shape the new system was not built for
Nobody migrates a corrosion history because they want to. The trigger is a vendor sunsetting a product, an Access database that no longer opens on a supported operating system, or the retirement of the one person who understood how the workbook joined the thickness table to the anomaly list. The deadline is external, the scope is discovered rather than specified, and the data turns out to be five datasets wearing one name.
What you actually hold is a thickness database for station piping with location identifiers, a shelf of in-line inspection deliverables spanning three file formats and two vendors across twenty years, a folder of scanned dig sheets, a set of alignment sheets, a pipe tally of uncertain completeness, and a spreadsheet of corrosion rates that no longer connects to anything. The new system expects a clean shape: an asset, a measurement location, a dated reading, a baseline, a rate. Roughly half a midstream history does not have that shape and cannot be forced into it without losing the thing that made it evidence.
The decision that governs the whole project is what to do with rates that have no readings behind them, and it has to be made before the first record loads. Import them as locked legacy values with an explicit provenance flag, or discard them and restart the long-term clock at the first migrated reading. Either is defensible. A register in which some rates are recomputable and others are not, with nothing recorded to tell them apart, is what an integrity audit finds three years later and what an engineer discovers the week they need to justify a reassessment interval.
Two evidence streams, two different meanings of the phrase corrosion rate
Station piping, meter runs, pig traps, filter vessels and breakout tanks live in the familiar world. API 570 governs the in-plant piping, aboveground breakout tanks are inspected to API 653 by direct regulatory reference, and both produce short-term and long-term thinning rates from repeatable fixed locations against a minimum required thickness. An inspector who has worked in a refinery recognises this instantly, and it is the part of the migration that behaves.
The line pipe does not work that way at all. It is regulated as an integrity management programme, assessed by in-line inspection, pressure test or direct assessment, and its corrosion rate is a growth rate attached to a detected feature — a depth and a length that change between runs. It is not a thickness series at a fixed point, it has no minimum required thickness in the API 570 sense, and its consumer is a remaining-strength calculation rather than a remaining-life calculation. Two runs on the same segment do not even guarantee the same population of features, because detection thresholds and tool technology change.
The structural consequence for the data model is that one system must carry both without letting them merge. A great many legacy databases were built by someone who put both into a single rate column because a single column made the report easier, and the resulting asset-level corrosion rate is arithmetic performed on incommensurable quantities. Migration is the moment that gets fixed, or the moment it gets baked in for another twenty years.
Tool tolerance, not corrosion, dominates a short-interval growth rate
Magnetic flux leakage depth sizing is typically quoted at plus or minus ten percent of wall thickness at eighty percent certainty. On a 0.250 in wall that is plus or minus 0.025 in for a single run. Comparing two independent runs, the uncertainty on the difference is roughly the root-sum-square of the two, around 0.035 in. Spread across a five-year reassessment interval, that is about seven mils per year of apparent growth arising entirely from the measurement system, with no corrosion required.
The practical symptom is unmistakable once you look for it: a large fraction of matched features appear to have shrunk. Metal does not return, so negative growth is exactly the same species of evidence as a negative short-term rate on a fixed measurement location — it says the two measurements disagree, and it must be handled as a data-quality signal rather than credited as improvement or clamped silently to zero. A migration that imports negative growth as zero has destroyed the only visible indicator of how noisy the pair actually is.
Operators who need real growth numbers on a short interval get them by re-analysing the original signal data for matched features rather than differencing reported depths, because much of the quoted tolerance is sizing algorithm rather than sensor noise and cancels when the same analyst re-boxes both runs. Where that is not available, the honest approach is a conservative assumed growth rate applied by corrosion mechanism, clearly labelled as assumed. The system needs to be able to say, per feature, which of those three methods produced the number on the screen.
The baseline problem: nominal wall and mill under-tolerance
Pipe is purchased to a nominal wall, and nominal is a specification, not a measurement. API 5L and ASTM A106 permit seamless pipe an under-tolerance of twelve and a half percent, so a nominal 0.250 in joint can legitimately be 0.219 in as manufactured. Any long-term corrosion rate computed against nominal on such a joint begins with thirty-one thousandths of fictitious loss. On a twenty-year line corroding slowly, that fiction is larger than the real corrosion and completely governs the answer.
The same error propagates through in-line inspection, because feature depth is reported as a percentage of an assumed nominal wall. A feature called twenty percent of 0.250 in is 0.050 in of loss on paper; on a joint that was actually 0.222 in, the remaining wall is smaller than the report implies and the percentage is understated. This is why the pipe tally is not optional migration scope. Joint-level grade, wall, seam type, manufacturer and installation date have to arrive with the corrosion data, including the heavy-wall joints at road crossings and the replacement joints installed after past repairs.
A second, cruder trap catches almost every migration at least once. Some legacy records store remaining wall and some store loss depth, and the field names are frequently unhelpful. A sign or convention flip on import turns a benign twenty percent feature into an eighty percent feature, or worse, the reverse. The defence is an assertion at load time — no imported feature may exceed one hundred percent or fall below zero, and the distribution of depths in each run should be inspected against the distribution the vendor reported.
Identity is the hard part of the migration
A measurement location in a plant has a stable tag welded to a stable object. A pipeline anomaly has an address: a girth weld number, a distance downstream of that weld, and a clock orientation. That address is stable only while the weld sequence is stable, and it is not. Every sleeve installation, cut-out repair, tie-in, valve replacement and loop changes the count, so a feature referenced from weld 1,482 in one run is referenced from a different weld number in the next. Odometer distance drifts with wheel slip and pipe geometry, and the modern runs carry inertial and GPS references that the 1998 run simply does not have.
Rebuilding that join is the real work of the migration, and it produces artefacts that need a home in the new system: a per-run-pair offset table, an alignment method record, a matched-feature set and — critically — an unmatched bucket. Features that could not be matched are information, not waste. A cluster of unmatched features in one segment usually means either a repair that was never recorded or a run with a positioning problem, and both matter more than any individual growth rate.
The station side has its own identity failure, and migration is the one moment it can be caught. Measurement location identifiers get reused after a spool is replaced, so the thickness series runs continuously across a component that no longer exists, and the long-term rate is computed across a discontinuity. A single diagnostic finds most of them: list every location whose series contains a thickness increase larger than the measurement band. Almost every hit is either a replacement nobody recorded or a reading taken on the wrong component.
What the rate is actually used for: pressure, not thickness
In a plant, the corrosion rate answers how many years remain until the wall reaches its minimum required thickness. On a regulated pipeline, it answers something structurally different. The rate projects a feature's depth and length forward to a chosen date, that projected geometry is fed into a remaining-strength calculation — ASME B31G, modified B31G, an effective-area method, or API 579-1/ASME FFS-1 Part 5 — and the resulting predicted failure pressure is compared against the maximum operating pressure and the applicable safety factor. The output is a condition classification and a response timeframe, not a remaining life in years.
This has a hard implication for the data model that legacy systems routinely got wrong. The rate must be attached to a feature geometry, not stored as a scalar against a segment, because the failure-pressure step needs both depth and length and is sensitive to length in a way that thickness-based thinking does not prepare you for. A legacy database that stored only a corrosion rate per segment cannot feed this calculation at all, which is a further argument for treating those rates as historical artefacts rather than live inputs.
It also explains why reassessment intervals are not simply half the remaining life. The regulatory ceilings apply regardless, the condition-response timeframes are triggered by predicted pressure rather than by predicted thickness, and a segment can require earlier reassessment because of feature length even where the depth growth rate is modest. Any system that reports a single years-to-failure number for a pipeline segment is compressing that logic into a number that will eventually be defended in a room where it does not hold up.
Evaluating a migration: the acceptance tests worth writing into the contract
Write the tests before the vendor writes the mapping. Count reconciliation first: feature counts per run and reading counts per station must match the source, with every discrepancy explained rather than tolerated. Then a recompute test — pick fifty measurement locations at random, recompute short-term and long-term rates from the migrated readings, and reconcile against the legacy report to the mil. Disagreements at this stage are worth more than any demonstration, because they expose the rounding, interval and baseline rules the legacy system applied silently.
Then the structural assertions. No imported feature depth outside zero to one hundred percent. Every joint's wall thickness sourced from the tally rather than a system default, with the count of joints that fell back to default reported explicitly. Every measurement series screened for a thickness increase beyond the measurement band, with the hits triaged rather than accepted. Every migrated corrosion rate able to answer three questions on demand: which two readings or which two runs produced it, what method was used, and whether it is measured, re-analysed or assumed. And the unmatched bucket visible on a report, with a number in it, because a migration that reports zero unmatched features has almost certainly matched them badly.
Atlantis builds these systems on Odoo 18 and treats the migration as the deliverable rather than an afterthought to a software install, with the alignment, tally reconstruction and provenance rules specified up front by an ASNT Level III who has worked both the station and the line-pipe side. It is affordable, accessible and fully customizable. If you are scoping a move off a legacy database, send a sample export and a couple of run deliverables to info@atlantisndt.com and ask for a migration assessment before you commit to a platform.
Can a corrosion growth rate be calculated from two in-line inspection runs?
It can, with care about what the number means. Each run reports depth with a tolerance around ten percent of wall at eighty percent certainty, so the difference between two runs carries the combined uncertainty of both. On a quarter-inch wall over five years that is several mils per year of apparent growth before any real corrosion occurs. Signal-level re-analysis of matched features is far more defensible than differencing two reported depths.
What happens to legacy corrosion rates that have no thickness history behind them?
You choose one rule and apply it universally. Either import them as locked historical values carrying an explicit provenance flag saying no readings support them, or discard them and start the long-term clock at the first migrated reading. Both are defensible to a regulator. What is not defensible is a register where some rates are recomputable and others are not, with nothing on the record to distinguish them.
Why is nominal wall a poor baseline for a pipeline long-term rate?
Because the pipe was never that thick. Seamless line pipe is permitted a wall under-tolerance of twelve and a half percent, so a nominal quarter-inch joint can legitimately have left the mill at 0.219 in. A long-term rate computed from nominal invents that difference as corrosion. In-line inspection depths expressed as a percentage of nominal inherit the same error, which is why a joint-level pipe tally has to migrate with the data.
How do station piping rates and line pipe rates coexist in one system?
They coexist by never being averaged. Station piping, meter runs and pig traps carry fixed measurement locations under API 570, with short-term and long-term thinning rates and a remaining life against minimum required thickness. Line pipe carries feature growth rates that feed a failure-pressure calculation. Both belong in one register with one reporting layer, but a single blended asset corrosion rate across the two is a number with no engineering meaning.
Does the corrosion rate drive the reassessment interval under Part 192 and Part 195?
It drives it indirectly, through predicted feature depth. The growth rate projects a feature forward, the projected geometry produces a predicted failure pressure, and that pressure against the maximum operating pressure determines whether a condition is immediate, scheduled or monitored, and when the segment must be reassessed within the regulatory ceiling. The rate is an input to a pressure decision, not a decision by itself.
How is feature identity preserved when the girth weld count changes?
Only by an explicit alignment step. Sleeve installations, cut-out repairs, tie-ins and loops all change the weld sequence, so a feature referenced as a distance downstream of weld 1,482 in a 2004 run may be downstream of weld 1,486 in a 2019 run. The migration needs a per-run-pair offset table, matched-feature records and a visible unmatched bucket that is counted rather than quietly dropped.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.