Computing a Defensible Corrosion Rate From Third-Party Inspection Data
Two rates per monitoring location, a long-term rate from the baseline and a short-term rate from the last inspection, with the more conservative one governing remaining life. In a cGMP plant the difficulty sits upstream of the arithmetic. Readings arrive from contractors, and a rate is only defensible if every input is attributable, contemporaneous, original, and traceable to the same physical point.
The single most common error in contractor-fed corrosion data is comparing this year's grid minimum with last year's grid minimum. Those are two different points on the vessel. A twenty-five point grid on a 4.0 mm wall with 0.08 mm of measurement scatter will produce a minimum roughly 0.15 to 0.20 mm below the grid mean by chance alone, and the location of that minimum wanders from visit to visit. Subtract one from the other across a two-year interval and you have manufactured a corrosion rate near 0.05 mm per year on a circuit that has not corroded at all. The remedy is structural, not procedural. Rates are computed point to point at a fixed, physically re-locatable CML, and grid minima are treated as a screening statistic that triggers investigation, never as a term in a subtraction. Any system that permits a minimum thickness field to be trended across inspections will eventually publish a false remaining life.
Source: Sources: API 510 and API 570 corrosion rate and remaining-life provisions; API RP 571 for chloride stress corrosion cracking, caustic corrosion and corrosion under insulation; ASME Section VIII Division 1 for vessel minimum thickness; ASME Section V Article 23 for ultrasonic thickness measurement; ASME BPE for bioprocessing equipment materials and surface finish; FDA 21 CFR Parts 210 and 211 current good manufacturing practice; 21 CFR Part 11 electronic records and electronic signatures; EU GMP Annex 11 computerised systems and Annex 15 qualification and validation; MHRA and FDA data integrity guidance and the ALCOA+ attributes; ISPE GAMP 5 for computerised system validation; ASNT SNT-TC-1A and ISO 9712 for examiner qualification.
| Defect in the incoming data | How it presents in the report | Effect on the computed rate | Control that prevents it |
|---|---|---|---|
| Grid minimum supplied instead of point readings | One value per CML, labelled minimum or lowest | Manufactures loss from extreme-value scatter, typically 0.03 to 0.06 mm/yr of pure fiction | Reject single-value grids at ingestion; require the full point set with point identifiers |
| CML re-gridded without notice | Same CML number, a new sketch and a different point count | Subtracts two thicknesses from different metal; the sign of the answer is arbitrary | Lock CML identity to a photograph, a weld or nozzle datum, and an offset dimension |
| Sound velocity left at instrument default | No velocity field anywhere in the report | A systematic bias of roughly 0.3 to 0.5 per cent that reads as a real trend over four years | Require velocity, calibration block identity and block temperature on every data set |
| No A-scan or waveform retained | Digital thickness values only, tabulated | A suspect reading can never be re-adjudicated, so the whole interval is unusable | Require waveform capture at every CML used for rate calculation, not just at anomalies |
| Examiner certification expired at the date of work | Certificate attached, but issued after the survey date | Every reading in the set becomes inadmissible in an inspection or audit | Validate certification against the reading date, not the upload date, and block on failure |
| Values transcribed from field notebook into a spreadsheet | Clean workbook, no instrument file, no source reference | Fails the original attribute under ALCOA+, and carries a real transcription error rate | Ingest the instrument file itself, keep it immutable, and derive the tabulated value from it |
The arithmetic is trivial; the provenance is where pharmaceutical programmes fail
The long-term rate is baseline thickness minus current thickness, divided by the years since the baseline was established. The short-term rate is the previous thickness minus the current thickness, divided by the interval between them. The more conservative result governs remaining life unless an engineer documents a specific reason to set it aside. That is the entirety of the calculation, and no pharmaceutical site has ever failed an inspection because someone divided incorrectly.
Sites fail on inputs. In a pharmaceutical plant almost none of the thickness data is generated in house. It arrives from a third-party inspection contractor, sometimes several across the life of an asset, in whatever format that contractor's reporting habit produces. One sends a bound PDF with a hand-drawn sketch. Another sends a spreadsheet exported from a data logger. A third sends the raw instrument file plus a summary. The engineering group retypes whichever it received into a maintenance system, and the moment that retyping happens the record has lost its claim to being original.
This is not a pedantic distinction in a cGMP environment. Where a computerised record supports a decision about equipment condition, the expectations under 21 CFR Part 11 and EU GMP Annex 11 apply, and the ALCOA+ attributes are what an inspector will use as the lens. A thickness value that cannot be attributed to a named, qualified individual, that was not captured contemporaneously, that is a transcription rather than the original, and that carries no audit trail for subsequent change, is a weak foundation for a remaining-life statement that governs whether a reactor stays in service.
CML identity is the whole problem
A corrosion rate is a subtraction between two thicknesses. That subtraction is only meaningful if both numbers came from the same piece of metal. In a plant where surveys are performed by rotating contractors over a decade, the single most fragile element of the entire record is the assertion that CML 12 in 2020 and CML 12 in 2026 are the same physical spot. Nothing in a spreadsheet enforces that. A new technician arrives, cannot find the paint mark, and establishes a location that is reasonable, documented, and three hundred millimetres downstream of the original.
The consequence is silent. The reading is perfectly good. The rate derived from it is nonsense, and its sign depends on which side of a weld the two points fell. On a vessel with a slightly heavier shell course below the weld, the new location will appear thicker and the system will report negative corrosion. On the thinner course it will report a step change and generate an investigation that consumes a fortnight before someone walks down the vessel with both sketches.
Fixing this requires identity to be anchored to something that survives personnel change. A CML record should carry a photograph showing the location in context, a permanent datum such as a nozzle centreline or a specific weld, an offset dimension and orientation from that datum, an elevation, and the physical marking method used. The system should require those fields before a CML can be used for rate calculation, and should surface them to the technician in the field, not just store them for the office.
Order statistics: why a bigger grid makes the trend worse
Once a grid minimum enters a trend, adding readings actively damages the result. The expected minimum of a sample falls as the sample grows, purely from the statistics of extremes and independent of any real corrosion. A contractor who takes twenty-five points this visit where the previous contractor took forty-nine will report a higher minimum on identical metal. Reverse the counts and the apparent loss appears from nowhere. The plant then holds a corrosion rate that is a function of how thorough its vendor was, which is not a property of the equipment.
This interacts badly with a well-intentioned improvement. Sites that expand their grids to improve coverage frequently see their computed rates jump in the year the expansion happens, conclude the process has become more corrosive, and shorten intervals or launch a materials review. The cause is a change in sample size, and the only way to see that is if the point count and the point identifiers were captured alongside the values, which is exactly what a single minimum field discards.
The correct architecture separates two uses of the same survey. Point-to-point comparison at identified locations produces the corrosion rate and drives remaining life. The grid as a whole produces a screening statistic, and a minimum falling below a defined threshold triggers an investigation, an extent-of-condition survey, or a fitness-for-service assessment. The screening statistic never enters a subtraction. A system that offers a minimum thickness column and allows it to be charted over time is inviting the error rather than preventing it.
Applying Part 11 and ALCOA+ to a thickness reading
Take the attributes one at a time against a real record. Attributable means the reading resolves to a named examiner whose qualification level and written practice were valid on the date of work, not on the date the report was compiled. Legible and enduring mean the record remains readable and retrievable for the retention period, which for a long-lived vessel outlasts several software generations, so export format matters as much as storage. Contemporaneous means captured at the time of examination, which argues strongly for instrument capture over evening transcription in a site office.
Original means the first capture, retained as such. For ultrasonic thickness that is the instrument file. The tabulated value in the database should be derived from it and linked to it, not a substitute for it. Accurate means the measurement conditions are known well enough to bound the error, which is why sound velocity, calibration block identity, block temperature, surface condition and probe type are not administrative clutter. Complete means nothing was dropped, including readings the technician considered anomalous. Consistent means the sequence of events is unambiguous. Available means an inspector can be shown it within the visit.
Practically, this dictates the ingestion design. A contractor submission becomes a record set with an immutable original file, a parsed data table linked to it, an examiner and qualification check performed against the work date, an instrument calibration check performed against the same date, and an audit trail on every subsequent change. Where a field is missing, the record is accepted with an explicit deficiency flag rather than being rejected outright or, far worse, quietly completed with a default.
What actually corrodes in a pharmaceutical plant
The clean utility side is largely a surface story rather than a thickness story. Water for injection and purified water loops in electropolished 316L, distribution at elevated temperature, clean steam generators and their distribution: the degradation of interest is rouging. Particulate iron oxide migrating from upstream, in-situ attack on the passive film where halides are present, and the dark magnetite film characteristic of pure steam service all change surface condition, particulate burden and cleanability without measurably changing wall. Ultrasonic thickness measurement will not detect any of it, and a corrosion rate programme that reports these loops as healthy is technically correct and practically incomplete.
The API and chemical synthesis side is where wall loss lives. Solvent recovery columns and reboilers, halogenated intermediates, hydrochloric and hydrobromic acid service in Hastelloy or glass-lined equipment, caustic in cleaning and neutralisation duties, and chloride-bearing cooling water on the utility side of exchangers. Glass-lined reactors are their own category: the vessel's protection is the glass, its integrity is assessed by spark testing and visual examination, and a shell thickness trend tells you nothing about the condition that will actually take it out of service.
Then there is the mechanism that quietly destroys austenitic equipment in warm, insulated, chloride-exposed locations: external chloride stress corrosion cracking under insulation. It requires no measurable thinning, it initiates at temperatures readily reached by jacketed vessels and steam-traced lines, and chloride can be delivered by insulation leachate or by wash-down water. A programme built solely on thickness trending will show a flawless record on a vessel that is cracking beneath its cladding, which is why CML type and inspection method have to be selected against the credible mechanism rather than by default.
Three contractors, one interval
A vessel installed in 2008 may have been surveyed by three or four different inspection companies. Each brought a different instrument, a different probe, possibly a different velocity setting, its own grid philosophy and its own report format. The long-term rate computed across that history is arithmetic performed on measurements that were never intended to be compared. Nobody did anything wrong; the incompatibility is structural.
The controls are practical. Require a bridging survey at every vendor transition, in which the incoming contractor reads the incumbent's identified CMLs using the incumbent's grid before proposing any change. That one visit preserves the continuity of a decade of data. Where a new grid is genuinely necessary, re-baseline explicitly, record the reason, and start a fresh long-term series rather than splicing incompatible data and hoping.
The module should then make provenance visible in the output rather than burying it. A rate computed across a vendor change, a method change or a velocity-unverified data set should carry a confidence indicator that follows it into the remaining-life figure and onto the report. Engineers make good decisions with an uncertain number that is labelled uncertain. They make poor decisions with an uncertain number that is presented as precise, and an inspector reading a remaining-life table has no way to tell the two apart unless the system says so.
Evaluate the system on ingestion, not on reporting
Every corrosion module demos well, because every vendor demos the reporting layer: the trend chart, the heat map of a vessel, the remaining-life table sorted by urgency. Those views are the easy part and they are largely interchangeable between products. The differentiator sits at the other end of the pipeline, where a contractor's data enters the system, and that is the part rarely shown unless you ask.
Ask for the demonstration in that direction. Bring a genuine contractor deliverable, ideally a messy one, and have it loaded live. Watch whether the system parses the instrument file or asks someone to retype. Watch whether it requires point identifiers or accepts a lone minimum. Watch whether it checks examiner certification against the work date. Watch what it does with a missing sound velocity, with a duplicate CML identifier, with a reading that increased since last time, and with a survey where the point count changed. Every one of those is a real Tuesday, not an edge case.
Then ask what happens afterward. Can a historic value be corrected, and does the correction propagate through every derived rate with both versions retained and a reason recorded. Can a CML be retired, split or superseded without orphaning its history. Does the audit trail capture reads as well as writes where that is expected. Can the whole chain for one CML be exported as a single packet for an inspector. If the answer to those is yes, the reporting layer will take care of itself; if it is no, no dashboard will rescue the record.
How should the system handle readings from a contractor who did not record sound velocity?
Accept them, flag them, and do not let them set a baseline. Without a stated velocity and calibration block, a systematic bias of a few tenths of a per cent cannot be excluded, and on a 3 mm wall across four years that bias is indistinguishable from 0.01 mm per year of real loss. Mark the data set as velocity-unverified, exclude it from long-term rate derivation, and make the missing field a contractual finding for the next survey.
What does an original record mean when a contractor emails a PDF?
The PDF is a report, not the original. Under ALCOA+ the original is the first capture of the data, which for ultrasonic thickness is the instrument file containing the readings and, ideally, the waveforms. A PDF is a rendering downstream of that. Accept it as a supporting document, record that the original was not supplied, and specify instrument file delivery in the inspection scope so future surveys close the gap rather than repeating it.
Is API 510, 570 or 653 inspector training part of this offer?
No. Those inspector certifications and their examinations are administered by API under its Individual Certification Programs, and they sit outside the Atlantis scope of supply. Atlantis delivers NDT training to ASNT SNT-TC-1A and ISO 9712 at Levels I, II and III across UT, RT, MT, PT, ET, VT, PAUT and TOFD, together with ASNT Level III consulting, inspection management and reporting software, digital twins, 3D laser scanning, and independent report validation.
Should a corrosion rate be recalculated when an older reading is later corrected?
Yes, and the recalculation itself must be a recorded event. Correcting a historic value changes every rate and remaining life derived from it, so the system needs to identify the affected calculations, recompute them, and retain both the previous and revised results with the reason for change and the person who authorised it. Silently overwriting a value and republishing a new remaining life is the behaviour that turns a data error into a data integrity finding.
Does rouging in a WFI loop show up as a corrosion rate?
No, and expecting it to is a common misunderstanding. Rouging is an iron oxide film, whether migrated particulate, in-situ chloride-influenced attack on the passive layer, or the black magnetite that forms in pure steam service. It affects surface condition, cleanability and particulate burden rather than wall thickness, and ultrasonic measurement will not resolve it. It belongs in the same integrity programme, tracked by visual, borescopic and swab evidence, not by thickness trending.
How many contractors' data sets can safely be combined into one long-term rate?
As many as you like, provided each survey re-reads the same physically identified points and the provenance of every reading is retained. The risk is not the number of vendors, it is an undeclared change of grid or method between them. When a new contractor takes over, run one bridging survey where they read the incumbent's CMLs before proposing any new layout, so the transition costs one visit rather than the whole history.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.