Reproducible Corrosion Rates When the Workbook Has Outgrown One Owner
Two rates are computed for every condition monitoring location: a short-term rate across the last interval and a long-term rate from the baseline, with the more conservative governing. For an NDT service provider the hard part is not the arithmetic but the audit trail — who read it, on what instrument, at which point, under whose procedure.
A service provider's spreadsheet starts as one technician's tool and ends as a shared liability. Three people edit it, one adds a column, another hard-codes a nominal thickness where the drawing was missing, a third pastes values over formulas after a site visit, and six months later nobody can say which cell produced the remaining life on a signed report. The exposure is asymmetric: the client's authorised inspector signs the interval, but the number came from you. Reproducing a rate means reproducing everything upstream of it — the technician's certification level under SNT-TC-1A or ISO 9712, the instrument and its verification, the calibration block and velocity setting, the surface temperature and any correction applied, and the exact condition monitoring location the probe sat on. A rate whose provenance stops at a cell reference is not evidence, and it will not survive a client audit.
Source: Method basis: API 510, API 570 and API 653 corrosion-rate and remaining-life practice, in which short-term and long-term rates are determined separately and the more conservative governs; API 579-1/ASME FFS-1 Part 4 for general metal loss and thickness averaging where a client's procedure invokes it; ASNT SNT-TC-1A and ANSI/ASNT CP-189 and ISO 9712 for personnel qualification, certification and currency records; ASTM E797 for standard practice in measuring thickness by manual ultrasonic pulse-echo contact method; ISO 9001:2015 clause 7.1.5 for measurement traceability and equipment verification records.
| What the workbook does today | How it fails under two or more editors | What a client audit asks for | Control in the module |
|---|---|---|---|
| Nominal thickness typed into a cell when the drawing is missing | A second technician types a different nominal for the same component on a later job | The source of the baseline for every monitoring location | Baseline held once on the asset record with a source field; individual readings cannot carry their own nominal |
| Values pasted over formulas after a site visit | The formula is gone, the sheet still looks correct, and nothing flags it | Recalculation of any published number on demand | Readings are immutable inputs and every rate is derived at read time; a rate can never be typed in |
| Negative rates deleted or zeroed by hand | The edit leaves no trace and the anomaly is never investigated | Why a thicker reading appeared and what was done about it | Negative and zero rates are retained, flagged for disposition, and require a recorded reason before a report can clear |
| Rate rule hard-coded into the sheet | One client wants greater-of, another wants long-term only, so the sheet gets copied and the copies drift | Evidence your calculation matched their written procedure | Rate rule is a per-client profile applied to the same data set, and the profile name prints on the deliverable |
| Technician identity in a header cell | The header travels with the file to the next job and the next client | Certification method, level and currency for the person who took each reading | Reading-level attribution to a qualified individual, drawn from the certification register rather than typed |
| High-temperature readings entered raw | Some jobs applied a velocity correction, some did not, and nobody can tell which | The correction applied and the surface temperature at the time of reading | Surface temperature is a required field; the correction is applied and displayed rather than assumed |
| Grid data kept in a separate tab per vessel | Tabs are duplicated for the next campaign and diverge from the original | One continuous history per monitoring location across all campaigns | Locations are permanent objects on the asset; campaigns add readings to them rather than creating new sheets |
What a shared workbook loses that a service provider cannot afford to lose
Almost every NDT service company's thickness calculation started as one competent technician's spreadsheet. It worked, because one person held the whole model in their head: which tab was current, which nominal came from a drawing and which was assumed, why row 47 was manually overridden after the January survey. The workbook did not become dangerous when it got large. It became dangerous the day a second person had edit rights, because the model in one person's head stopped being the system of record and nothing replaced it.
The specific losses are all the same kind. Formulas get overwritten by pasted values after a site visit, which is invisible because the sheet still displays a plausible number. Baselines get edited in place rather than versioned, so last quarter's report can no longer be regenerated. Technician identity lives in a header cell that travels with the copied file to the next client. Rate rules get hard-coded, then the file is duplicated for a client with a different procedure and the two copies drift. None of these is a calculation error. Every one of them is a reproducibility failure.
The reason this matters more for a service provider than for an asset owner is the shape of the liability. The owner's authorised inspector signs the inspection interval and carries the regulatory responsibility, but the thickness and often the rate came from your crew and your workbook. If the interval turns out to be wrong, the first document requested is the one showing how your number was produced. A workbook cannot produce that document, and the absence is not read as a filing problem. It is read as an absence of control.
Reproducibility starts at the probe, not at the formula
It is tempting to treat this as a software problem about calculation transparency, and to stop once every rate can be traced to a formula. That is only the last few inches of the chain. A corrosion rate is a difference between two measurements, and every source of variance in those measurements propagates directly into it. Over a short interval where real metal loss may be a few tenths of a millimetre, measurement variance is frequently the larger term.
The variables that need to be captured with the reading are unglamorous and specific. Which instrument, and when was its performance last verified. Which transducer, which frequency, and was it a dual element on a corroded surface or a single element on a machined one. Which calibration block and which velocity setting — a velocity set for carbon steel and used on a stainless component produces a systematic error that looks exactly like corrosion. Surface condition and preparation. Surface temperature, because sound velocity in steel falls as temperature rises and an uncorrected reading on a line at operating temperature reads thin by a percentage that grows with the temperature difference. And whether the reading was a single point, the minimum of a small cluster, or a grid average, because those three are different quantities.
Then there is location. A monitoring location on a corroded surface is a physical spot, not a description. Thickness on a pitted plate can vary substantially over a few centimetres, so a probe placed a little differently from the previous campaign generates an apparent rate that is pure geometry. Permanent marking, a photograph, a dimensioned sketch from a datum, and a location identifier that belongs to the asset rather than to the job number are what make the second reading comparable to the first. Without that, you do not have a trend. You have two unrelated numbers subtracted.
You serve several procedures at once, and the client's governs
An asset owner needs one rate rule. A service provider needs several, simultaneously, and must never let them blur. One client's written procedure calls for the greater of the short-term and long-term rates, straightforwardly following API 510 practice. Another specifies the long-term rate only, because their engineering group considers short-term rates over their inspection intervals to be noise-dominated. A third computes the short-term rate over the last three intervals and takes the most conservative of those. A fourth supplies statistically treated rates from their own integrity software and wants you to supply readings and nothing else.
All four are legitimate positions. The failure mode is the workbook approach of copying the sheet per client, because the copies then drift as improvements get made to one and not the others, and eventually a technician grabs the wrong template under time pressure. What is needed instead is a single data model — readings, locations, assets, baselines — with the rate rule expressed as a client profile applied at calculation time, so all four clients are served from one set of controlled inputs and the differences exist only in the rule.
The deliverable has to state which profile was used. This sounds like a small reporting detail and it is actually the core of the defence. A report that shows a rate of 0.18 mm per year says almost nothing about how it was produced. A report that shows the same rate, names the client procedure revision it was computed under, states that the long-term rate governed, and prints the short-term rate alongside for comparison is a document that answers the audit question before it is asked. It also protects you when a client changes their procedure, because the older reports remain readable against the rule that was actually in force at the time.
Negative and zero rates are data, not errors to be cleaned
Every thickness campaign of any size produces readings thicker than the last ones. In a spreadsheet the almost universal response is to zero the rate, or to quietly delete the row, because a negative remaining life breaks the report. That edit is invisible, unattributed and unrecoverable, and it destroys the only signal that would have told you something systematic was wrong.
Work through the causes, because they have very different consequences. Probe repositioning on an uneven surface is benign and common, and the fix is better location control. A wrong baseline — a nominal typed in where a measured value existed, or a mill plate running at the high end of tolerance — means every long-term rate on that component is wrong, not just this one. Coating or scale included in the reading means the technique needs correction across the campaign. A replaced component with no record means the asset register is stale. An instrument velocity set for the wrong material means every reading that day is systematically off. One of those is a rounding matter and four of them invalidate a batch.
The behaviour that serves a service provider is to retain the reading, flag the location, and require a recorded disposition with a reason before the report clears. That turns an embarrassment into a controlled finding, gives the technician a defined path rather than an improvisation, and creates exactly the record a client wants to see when they ask what your quality control actually does. It also builds a dataset over time: a location that produces a negative apparent rate every campaign is telling you its monitoring point is badly chosen.
The highest rate is not the shortest remaining life
This is the arithmetic trap that catches experienced people, and it is worth stating plainly because reports built on a spreadsheet almost always sort by rate. Remaining life is the current thickness minus the required thickness, divided by the governing rate. It is a function of two independent quantities, and ranking on one of them produces the wrong ordering whenever the other varies, which it always does.
Take a vessel with two monitoring locations. The shell course location is corroding at 0.30 mm per year and currently sits 6 mm above required thickness: twenty years. A nozzle location is corroding at 0.10 mm per year and sits 1 mm above required thickness: ten years. Sorting by rate puts the shell at the top of the exception report, and the shell is not the problem. Under API 510 practice the equipment's next inspection due date is driven by the shortest remaining life among its monitoring locations, which is the nozzle, and the nozzle is the location whose reading interval and repeat-measurement discipline actually matter.
The consequence for a service provider is in scope definition, not only in reporting. If your survey plan allocates effort by rate, you spend the crew's time on the fastest-corroding locations rather than on the ones nearest their limit. The system should rank by remaining life, present rate alongside as a supporting figure, and let the ranking drive which locations get repeat readings for confidence. Where the client has not supplied a required thickness, remaining life cannot be computed at all, and the honest output is a rate with an explicit note that remaining life awaits the owner's required thickness rather than a silently assumed one.
Who is allowed to set the required thickness, and why it is not you
Sooner or later a client asks the crew on site to just work out the minimum thickness so the report is complete. It is a friendly request and it should be declined. Required thickness on pressure equipment follows from the original design calculation, the code of construction, the current service conditions, any fitness-for-service assessment already performed, and the owner-user's inspection programme. Under API 510 and API 570 that determination sits with the owner-user and its engineering function, with the authorised inspector working inside that programme.
A service provider who calculates and publishes a required thickness has moved from measurement into engineering determination. The commercial exposure follows immediately: your professional indemnity cover is almost certainly written for inspection services, your quotation was priced for inspection services, and the client's own management of change process was never applied to the number you produced. If the vessel is later found to have operated below its true required thickness, the document with your logo on it is the one that stated the limit.
The right posture in the software is to make required thickness a client-supplied input on the asset record, with a source and a date, that your organisation can read and use but not author. Where it is absent, the system computes and reports rates and withholds remaining life rather than substituting a default such as a fixed percentage of nominal. This is not a limitation to apologise for. It is a boundary that experienced clients recognise and respect, and stating it clearly in a proposal frequently distinguishes a serious provider from one that will write any number asked for.
Evaluating the module as a deliverable engine, not a database
A service provider is not buying a place to keep data. You are buying the machine that produces the document you hand to a client and the evidence that stands behind it. Evaluate it that way. Load one real campaign — a vessel with a grid, a piping circuit with single-point locations, at least one negative apparent rate, and one component whose baseline you had to assume. Then ask to see the deliverable, and check whether it names the governing rate, the client procedure profile, the technician and level for each reading, the instrument and its verification date, and the source of every baseline.
Next, test reproducibility directly. Ask the vendor to regenerate the report as it stood before a correction was made, and confirm the earlier version is retrievable rather than overwritten. Ask what happens when a technician's certification lapses between the reading and the report — the reading should remain valid as of its date, with currency visible, rather than either vanishing or silently passing. Ask whether a rate can be typed. If any field in the system accepts a hand-entered corrosion rate, every control above it is optional in practice.
Finally, test the multi-client dimension, because it is the one that generic inspection software handles worst. Configure two clients with genuinely different governing rules against the same underlying readings and confirm both produce correct, distinctly labelled outputs without duplicating the data. Confirm that export matches what each client's own system expects, since a large part of your value is that the client's integrity software ingests your file without rework. Confirm that field capture works offline, because the tank farm has no signal and a synchronisation model that assumes connectivity will be defeated on day one. For a walkthrough against one of your own campaigns, or a scoped quote, contact info@atlantisndt.com.
Why can nobody reproduce a corrosion rate from a shared workbook?
Because a spreadsheet stores results, not derivations. Once someone pastes a value over a formula, or edits a baseline in place, the calculation that produced last quarter's report no longer exists anywhere. There is no version of the cell, no record of who changed it, and no link from the number to the reading, the technician or the instrument. The rate can still be right. It simply cannot be shown to be right, which is the part a client audit tests.
What should the system do with a negative corrosion rate?
Keep it and force a disposition. A reading thicker than the previous one almost always means one of five things: the probe sat on a different spot, the baseline was wrong, coating or scale was included, the component was replaced without a record, or the instrument was not calibrated to the right velocity. Each has a different consequence. Deleting the reading destroys the evidence needed to tell them apart and hides a possible systematic error across the whole campaign.
Is the highest corrosion rate the same as the shortest remaining life?
No, and conflating them is a common and consequential error. Remaining life is the distance from current thickness to required thickness divided by the governing rate. A location corroding at 0.30 mm per year with 6 mm of margin has twenty years. A location at 0.10 mm per year with 1 mm of margin has ten. Ranking a vessel's locations by rate puts the wrong one at the top; the equipment's interval is driven by the shortest remaining life.
Should an NDT contractor calculate the required thickness?
It is not the contractor's call to make. Under API 510 and API 570 the required thickness follows from design calculations and the owner-user's inspection programme, and the authorised inspector works within that programme. A service provider that derives and publishes a required thickness is performing an engineering determination it was not contracted for and is generally not insured for. Supply measured thickness, rates and the calculation on the client's supplied required thickness, clearly attributed.
How much does probe repositioning affect a short-term rate?
On a pitted or unevenly corroded surface, enough to dominate it. Thickness can vary by several tenths of a millimetre over a couple of centimetres, which on a two-year interval can exceed the entire real metal loss. That is why a monitoring location has to be a physical, marked, photographed point rather than a description, and why grid readings and single-point readings should never be silently mixed into the same trend series.
Is API 510, 570 or 653 inspector certification training part of this offer?
No. This page is about inspection management software for computing and evidencing corrosion rates. Atlantis NDT does deliver NDT method training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, along with ASNT Level III consulting and independent report validation, but API inspector certification programmes sit outside that scope. Demonstrations, consultations and quotes are arranged on request at info@atlantisndt.com.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.