Rebuilding Wall Loss History When a Mill Leaves Its Legacy System
A migration must reconstruct two rates for every thickness location: a short-term rate from the last two readings and a long-term rate from the original baseline, with the higher governing. In a pulp mill the long-term rate spans decades of liquor chemistry changes and undocumented tube panel replacements, so the migration has to carry reset events, not just numbers.
The failure mode of a pulp and paper migration is not lost data. It is data that arrives intact and computes a confident, wrong answer. A recovery boiler generating bank panel replaced in a 2011 outage leaves forty years of readings on a location that is now fourteen years old; carried across without a reset event, the long-term rate comes out negative and the system reports the tube as gaining wall. A digester shell whose nominal thickness lived on a 1971 drawing arrives with no baseline, so the long-term rate silently defaults to the short-term one. Readings from an early digital meter recorded to ten thousandths of an inch arrive stored to three decimals, implying a precision they never had, and put a noise floor of about 0.010 inch on every annual outage interval. None of these produce an import error. All of them produce a remaining life that a jurisdictional inspector will eventually ask you to defend.
Source: Written against ASME Section I for power and recovery boilers, ASME Section VIII Division 1 for digesters and pressure vessels, ASME Section V and Section IX, the National Board Inspection Code NB-23 Parts 2 and 3, BLRBAC recommended good practice for black liquor recovery boilers including the emergency shutdown procedure, TAPPI technical information papers on continuous digester and impregnation vessel inspection, and API 579-1/ASME FFS-1 Part 4 for general metal loss.
| Defect in the legacy record | How it looks after migration | Rate error it produces | What the new record needs instead |
|---|---|---|---|
| Tube panel or spool replacement never recorded | An unbroken reading history across a component that is physically new | Negative long-term rate, or a rate an order of magnitude too low | A dated reset event on the same location, with prior history retained but excluded |
| Nominal thickness held only on the drawing | Thickness values arrive with an empty baseline field | Long-term rate cannot compute and silently defaults to short-term | Baseline thickness with its source: mill certificate, drawing revision, or as-built UT |
| Point IDs reused after a renumbering project | Two physical locations merged under one identifier | A step change of 0.100 inch or more read as a single interval of wear | Legacy identifier kept as an alias, with the renumber date and the mapping |
| Readings taken on a 0.010 inch resolution meter | Values stored to three decimals, implying 0.001 inch | A 0.010 inch noise floor on every annual short-term rate | Instrument resolution carried per reading, not assumed from the stored format |
| Metric conversion project in the 1990s | 0.250 inch stored as 6.35 mm, re-imported and rounded to 6.4 mm | A phantom 0.002 inch wall gain dated to the conversion | Raw source value and unit preserved beside the converted value |
| Probe velocity set for carbon steel on clad tube | Readings biased relative to the rest of the circuit | Apparent wear or gain concentrated at each material transition | Material and sound velocity stored with the reading |
The job: decades of readings in a shape the new system will not accept
The migration usually starts because the legacy tool has become unsupportable — a vendor discontinued the product, the mill's server is running an operating system corporate IT will no longer permit, or the one person who understood the schema retired. The reliability engineer inherits a dataset of tens of thousands of thickness readings covering a recovery boiler, a power boiler, two digesters, the causticizing area, the bleach plant and several kilometres of liquor and process piping, some of it dating to commissioning.
The trap is that the export runs cleanly. Thickness values, dates and location identifiers all move across. What does not move is everything that was never a field in the old system: which drawing the nominal came from, that the floor tubes were replaced in 2011, that points were renumbered in 1998, that readings before 1994 came off a meter that displayed two decimal places, that the mill went metric and then partly back. Those facts lived in the heads of two people and in the margins of a set of drawings.
The consequence is a system that computes a rate for every location on day one and is wrong on a meaningful fraction of them, with no signal to say which. That is worse than the legacy system, because the legacy system was known to be untrustworthy and this one looks authoritative. The whole migration should be organised around a single principle: refuse to compute rather than compute without provenance.
What is actually corroding in a kraft mill, and why that shapes the migration
The damage mechanisms in a pulp mill are not a single family. The recovery boiler lower furnace sees fireside corrosion from molten alkali and, historically, cracking of co-extruded 304L composite tubes in the floor and around primary air ports, which drove a generation of replacements into alloy 825 and other materials. Generating bank and superheater tubes see sootblower erosion and fireside attack. The economizer and cold end see dew-point corrosion. Every one of those has a different rate signature and a different reset history.
Elsewhere, continuous digesters and impregnation vessels see caustic stress corrosion cracking at liquor and vapour interfaces, which is why so many shells carry stainless weld overlay — an overlay that changes what a thickness reading means at that location forever. The bleach plant is a chloride environment where 304 and 316 are at risk of chloride stress corrosion cracking and where titanium, duplex and FRP are common, so entire circuits have no meaningful uniform corrosion rate at all. White water systems bring microbiologically influenced corrosion. Liquor pumps and lines bring erosion-corrosion at bends and downstream of throttling.
This diversity is the migration problem in one sentence: a mill's inspection history is not one dataset with one convention, it is eight datasets that happen to share a database. A migration that applies one baseline rule and one rate rule across all of them will produce numbers that are right for the power boiler and meaningless for the bleach plant.
The jurisdiction is the National Board, not API
Teams coming from oil and gas assume the fitness-for-service frame they know. In a pulp mill, the recovery boiler and power boiler were built to ASME Section I and the digesters and larger vessels to ASME Section VIII Division 1. In-service inspection, repair and alteration are governed by the National Board Inspection Code, and the person who signs is a National Board commissioned inspector working for the jurisdiction or the insurer, not an API 510 inspector working for the owner.
That changes what the record has to contain. Repairs and alterations flow through NBIC Part 3 with the associated documentation and stamping, and a wall thickness history is evidence in that process. The recovery boiler carries an additional layer: BLRBAC recommended good practice, which shapes pressure part inspection frequency and the emergency shutdown procedure, because the failure mode being defended against is a smelt-water explosion rather than a loss of containment to atmosphere. Property insurers hold their own expectations on top.
Practically, the migrated system must be able to produce, per component, a defensible chain from raw readings to a governing rate to a remaining life, addressed to that audience. If the tool can only emit an API-style circuit report, the mill will keep a parallel document set for the jurisdictional inspector, which is precisely the fragmentation the migration was supposed to end.
Replacement events are the most damaging thing a migration can lose
Take a generating bank panel replaced during a 2011 shutdown. The location identifier survives, because the mill kept the same tube numbering. Readings from 1978 through 2010 sit in the record, then readings from 2012 onwards on new tube. Migrate that as a continuous series and the long-term rate is computed from a 1978 baseline to a 2025 reading on metal that has been in service for fourteen years. If the new tube is thicker than the old tube was in 2010, the long-term rate goes negative. If it is similar, the rate simply reads far too low and looks entirely normal.
The negative case is survivable because it is visible. The plausible case is the one that hurts, and it is the more common one after partial replacements, where a panel is renewed in sections across three consecutive outages. The rate stays positive throughout and drifts downward, and the natural interpretation is that a chemistry improvement is working.
The fix is structural rather than analytical. The data model needs a first-class event on the location — replacement, weld overlay, partial renewal, material change — with a date, a description and a new baseline. Prior readings stay attached and visible, because they are still the record of the original component and may be needed for a repair history, but they are excluded from the rate. Building this after the migration is far harder than building it during, because by then nobody remembers which of the 40,000 locations need one.
Identity: reused point numbers and the silent merge
Almost every mill has had a renumbering project. Points laid out by one contractor in the 1980s get renumbered when a new inspection contractor takes over, or when a drawing set is redrawn, or when a database migration happened once before. The old identifiers are frequently reused, because the new scheme is tidier and starts at one.
When a migration keys on identifier alone, two physically different locations collide into one series. The symptom is an abrupt step in the thickness trend at the renumber date, which the rate engine reads as a single interval of enormous wear or gain. On a boiler tube circuit where nominal wall differences between locations are a tenth of an inch, that step produces a short-term rate large enough to condemn the component, or a negative rate large enough to make the long-term rate meaningless.
The discipline that prevents it is to treat the legacy identifier as an alias rather than a key. Each location in the new system gets a stable internal identity, carries every historical identifier it has ever had with the date range each was valid, and refuses to accept a reading whose identifier maps ambiguously. That last point is the one people negotiate away under schedule pressure, and it is the one worth defending: a quarantine queue of two thousand ambiguous readings is a week of work, while two thousand silently merged series is a permanent defect.
Resolution, units and the quantisation floor
A mill's reading history spans instrument generations. Early digital meters displayed to 0.01 inch. Later meters display to 0.001 inch, and modern equipment with an A-scan and a documented procedure can be better than that on a prepared surface. Legacy databases usually stored everything in one column format, so a 0.01 inch reading and a 0.001 inch reading are indistinguishable after the fact unless the reading date and the instrument record are preserved.
This matters because quantisation sets a floor on the short-term rate. With annual cold outages and 0.01 inch resolution, the short-term rate cannot resolve anything finer than about 0.01 inch per year, and a great many mill locations corrode at a fraction of that. The result is a short-term rate that oscillates between zero and 0.01 inch per year depending on which side of the rounding the reading fell, and a governing rate that alternates between benign and alarming with no physical change at all.
Unit conversion compounds it. A mill that converted to millimetres, and a system that re-rounds on import, can manufacture a wall gain of a couple of thousandths of an inch dated exactly to the conversion. The safeguard is to store the raw source value with its original unit and precision alongside the converted working value, and to derive the noise band for each rate from the coarser of the two readings that produced it. A rate whose magnitude is inside its own noise band should be presented that way, not as a number.
Clad, overlaid and composite surfaces: what the reading measures
A co-extruded composite tube, a stainless weld overlay on a digester shell, and a rubber or brick lining all break the assumption that a thickness reading is a single wall. On composite tube the ultrasonic response depends on how the instrument is set up and what the technician chose to gate; different crews across different decades have made different choices, and the legacy record rarely says which.
The practical consequence during a migration is a circuit where the readings look internally consistent within each contractor's era and step at every handover. Attributing that step to corrosion is wrong, and attributing it to nothing is also wrong, because a genuine mechanism may be hiding under it. The only recoverable position is to record what is known about each era — instrument, velocity setting, material assumption, procedure — and to segment the trend accordingly rather than fitting one line through all of it.
For overlaid digester shells the question is sharper still: the overlay was applied to arrest cracking, not to add pressure-retaining wall, and whether it counts toward the thickness used in an evaluation is an engineering decision recorded in a specific document. That decision must live with the location in the new system. If it lives only in a report from 2004, the next analyst will make a different one and the long-term rate will change without a single new reading being taken.
Evaluating a corrosion rate module for a migration
Run the evaluation on your worst data, not your best. Extract three hundred locations that include a known replacement, a known renumber, a metric-era gap and a composite tube circuit, and give the same file to each vendor. The question is not whether the system imports it. The question is what it does with the parts that are wrong.
Specifically: does it refuse to compute a long-term rate when there is no baseline, or does it substitute the earliest reading without saying so? Does a negative long-term rate raise an exception, or does it display as a negative number in a grid? Can you attach a dated reset event and see the rate change accordingly, without deleting prior readings? Does it retain the legacy identifier as an alias and reject ambiguous mappings into a queue? Does it store the raw source value and unit? Can you open any rate and see the exact two readings, the exposure period, and the procedure behind it?
Then test the output side, because the mill still has to satisfy a jurisdictional inspector and an insurer. Can it emit a component-level record that a National Board commissioned inspector will accept, showing readings, governing rate, remaining life and the basis for each? Can it segment a trend at a documented chemistry or firing change? Can a technician working an annual outage enter data offline in the field and reconcile later? A migration is judged years afterwards by whether anyone still keeps a private workbook. If the answer to any of the questions above is no, that workbook is already being created.
Why is a pulp mill's corrosion history harder to migrate than a refinery's?
Because it is older, longer and less continuously governed. A kraft mill may hold sixty years of readings taken under four different inspection contractors, two numbering schemes and one metric conversion, on assets whose materials have changed underneath the record. Refinery circuits usually sit inside an API 510 or 570 programme with a defined baseline and a data owner. Mill records often live half in a database and half on marked-up drawings in the boiler shop.
What single migration error causes the most damage to a corrosion rate?
An unrecorded replacement. When a generating bank panel, a floor tube section or a liquor line spool is replaced and the reading history continues on the same location identifier, the long-term rate is computed across a physical discontinuity. The usual symptom is a negative long-term rate, which is at least visible. The dangerous symptom is a positive rate that is far too low, because a partial replacement leaves the trend plausible and nobody investigates.
Should the long-term rate span a change in liquor chemistry or firing solids?
It will, unless you stop it. A mill that moved to higher dry-solids firing, changed sulfidity, or converted a bleach sequence has stepped the corrosion rate on affected assets. The long-term rate then averages a regime that no longer exists with the one that does, and reads low. This is exactly why the governing rate is the higher of short-term and long-term, and why the change date needs to be in the record so an analyst can see why the two diverge.
Who has jurisdiction over the remaining life numbers in a mill?
For boilers and pressure vessels it is the state or provincial jurisdiction and a National Board commissioned inspector, working to NBIC NB-23 for inspection, repair and alteration, with the original construction under ASME Section I or Section VIII. Recovery boiler practice is further shaped by BLRBAC recommended good practice and by the property insurer. This is a different regulatory frame from API 510 or 570, and a system configured only for the API path will not produce the right record.
Why does old data with coarse resolution give a better long-term rate than short-term?
Because quantisation error divides by time. A reading pair from a meter with 0.010 inch resolution, taken twelve months apart, carries roughly 0.010 inch per year of pure noise in the short-term rate. The same 0.010 inch spread over a forty-year baseline is about 0.00025 inch per year. Coarse legacy readings are therefore nearly useless for short-term rates and perfectly serviceable for long-term ones, which is the opposite of what most people assume when they triage a migration.
Is API 510, 570 or 653 inspector training part of this offer?
No. This page is about inspection data and rate calculation software. Atlantis NDT provides NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, ASNT Level III consulting, inspection management and reporting software, digital twins, 3D laser scanning and report validation. API inspector certification is administered by the American Petroleum Institute; mills needing it engage that programme directly.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.