Two corrosion rates, and the problem of trusting the readings behind them
Compute the long-term rate from the earliest reliable reading and the short-term rate from the previous inspection, keep them as separate stored values, and let the higher of the two govern remaining life unless a corrosion specialist documents why it should not. In a refinery the harder question is whether a contractor's step change is corrosion at all.
API 570 defines both formulas and leaves selection of the governing rate to the inspector or corrosion specialist; most owner specifications resolve that by taking the more conservative value. The trap is that the short-term rate is the noisier of the two by construction, because the same measurement uncertainty is divided by a shorter interval. A digital thickness gauge quoting 0.001 in resolution has a field repeatability closer to plus or minus 0.004 in once couplant, surface preparation and operator technique are included. Divide that by a one-year interval and the short-term rate carries an 8 mpy noise band before any metal has been lost. On a six-month interval the band doubles again. A refinery running tens of thousands of CMLs through several inspection contractors will therefore manufacture hundreds of false short-term rates every year unless the calculation is gated on interval length and measurement uncertainty.
Source: Written against API 570 and API 510 for corrosion rate calculation, remaining life and inspection intervals; API RP 571 for refining damage mechanisms; API RP 580 and API RP 581 for risk-based inspection and inspection effectiveness; API RP 584 for integrity operating windows; ASME BPVC Section V, Article 23 (SE-797); OSHA 29 CFR 1910.119 mechanical integrity.
| What arrives in the data | How it appears in the rate | Detection rule the system can apply | Correct disposition |
|---|---|---|---|
| Reading taken 75 mm from the actual CML | Step change of a few thousandths that reverses at the next survey | Flag any single-interval change exceeding four times the CML's long-term rate | Hold, re-shoot the point, exclude with reason 'location not repeatable' |
| Uncompensated reading at 315 C (600 F) | Wall appears to grow by roughly one percent per 100 F above ambient | Compare recorded surface temperature against the correction factor applied | Apply temperature compensation, then recompute both rates from the corrected value |
| Dual-element probe replacing single-element mid-history | A systematic offset across an entire circuit appearing in one campaign | Detect circuit-wide, same-sign shifts coincident with an instrument change | Treat the instrument change as a baseline reset for short-term rate only |
| Velocity left on the previous job's material setting | Every reading in one report biased by the velocity error percentage | Compare reported velocity or material against the circuit's material of construction | Rescale the report or reject it outright; never average it into the history |
| Missing reading entered as 0.000 | Apparent complete wall loss and an immediate escalation | Reject any non-null value below the smallest physically plausible thickness | Return to the contractor; store as null with an exclusion reason recorded |
| Insulation jacket or coating included in the measurement | Wall appears thicker than nominal, suppressing the long-term rate | Flag any reading exceeding nominal plus mill tolerance | Exclude and re-measure with the coating removed or accounted for |
| A two-point interval of five months | Short-term rate dominated by gauge repeatability rather than metal loss | Suppress short-term governance below a minimum interval gate | Report the rate with its uncertainty band and require documented acceptance |
Two rates, computed separately, and why refining cannot collapse them into one
API 570 sets out both calculations plainly. The long-term rate uses the initial thickness and the most recent measurement across the full elapsed period. The short-term rate uses the previous measurement and the most recent one across the interval between them. They answer different questions. The long-term rate describes the circuit's life; the short-term rate describes what the process is doing now.
Refining is the industry where those two answers diverge most violently, because the process itself changes. A crude unit that switches to an opportunity crude with a higher total acid number can see naphthenic acid attack appear in high-velocity zones of the vacuum transfer line within one campaign, while the long-term rate, averaged over fifteen years of sweet operation, is still reporting three mils per year. A hydroprocessing reactor effluent air cooler whose wash water rate has been trimmed can move from negligible loss to aggressive ammonium bisulfide attack without disturbing the long-term trend for years.
That is why the two values are stored separately and why the more conservative normally governs. It is also why the standard keeps a person in the loop. API 570 expects the inspector or corrosion specialist to select the rate that best reflects current conditions, and a system that simply takes the maximum without recording who accepted it has automated a judgement it was never entitled to make.
The noise floor: what a short-term rate can and cannot resolve
The short-term rate is the difference of two numbers divided by a small number, and that structure amplifies error. If your field repeatability on a coated, hot, moderately rough carbon steel surface is about plus or minus 0.004 in, which is realistic once couplant, surface preparation and operator technique are included, then two surveys twelve months apart can differ by 0.008 in with no metal lost at all. Expressed as a rate, that is an 8 mpy band centred on zero.
Shorten the interval and it worsens in direct proportion. At six months the same repeatability produces a 16 mpy band. Most refinery carbon steel circuits corrode at single-digit mils per year, so a six-month short-term rate on a healthy circuit is close to a random number, and a rule that says the more conservative rate governs will faithfully promote that random number to the governing value and set an inspection interval on it.
The fix is not to abandon the rule but to gate it. Suppress short-term governance below a minimum interval. Publish the rate with its uncertainty band rather than as a bare number. Require documented specialist acceptance before a short-term rate that exceeds the long-term rate by less than the band is allowed to change a remaining life. And when a short-term rate is genuinely alarming, the correct first action is a repeat measurement, not a recalculation.
Refining damage mechanisms that break a single-rate model
API RP 571 catalogues the mechanisms, and their spatial behaviour is what determines whether a rate means anything. High-temperature sulfidation is broadly uniform, so a grid average tracks it well and a long-term rate predicts it reasonably. Naphthenic acid corrosion is not uniform at all: it concentrates where wall shear is highest, at elbows, reducers and the outlet of a transfer line, and a CML sitting on a straight run will report nothing while the elbow thins.
Ammonium bisulfide corrosion in hydroprocessing effluent behaves similarly, governed by the Kp parameter and velocity, and it is capable of rates that make a five-year interval reckless. Overhead systems present a different problem again: hydrochloric acid corrosion at the water dew point follows operating conditions, so the location of the damage migrates with the process and a fixed CML grid can lose it entirely between surveys.
Then there are mechanisms that produce no wall loss whatsoever. High-temperature hydrogen attack, chloride stress corrosion cracking in austenitic stainless steel and creep are not detected by a thickness trend, and a rate of zero on those circuits is not reassurance. A corrosion rate module that reports remaining life without carrying the circuit's credible damage mechanisms alongside it invites exactly that misreading, which is why the mechanism list belongs on the circuit record next to the number.
Where third-party data goes wrong, mechanically
Contractor error is rarely careless work. It is usually a settings problem or a locating problem, and both leave signatures. The most common is location repeatability: a CML marked in paint that has weathered off, re-established by a different technician a few inches away. In grid-averaged data this reads as a step change that reverses at the next survey. The signature is oscillation, and no genuine corrosion mechanism oscillates.
Temperature is the second. Ultrasonic velocity in carbon steel falls as temperature rises, so a reading taken hot with a room-temperature velocity setting reads thicker than the metal is. The customary field correction subtracts about one percent of indicated thickness per 100 F above ambient. On a 0.500 in wall at 600 F that is roughly 0.027 in of phantom metal, several years of a typical rate. If one contractor compensates and the next does not, you get a fabricated step in one direction and then the other.
The third is instrument and setup change. Dual-element probes have a V-path characteristic that single-element probes do not, and switching probe type mid-history offsets an entire circuit at once. So does a velocity or material setting carried over from the previous job. The tell for all three is that the shift is circuit-wide, same-signed and coincident with a report boundary, which is a pattern software detects easily and a human reviewing one CML at a time will never see.
Making an incoming contractor file auditable before it touches the history
Treat contractor submissions as a staged import with an explicit acceptance step, not as a direct write. The staging layer validates before anything reaches the trend: is every CML in the file on the circuit's register; does every reading carry a technician, instrument, method and surface temperature; was the instrument's calibration valid on the reading date; is any value above nominal plus mill tolerance or below a physically plausible floor; is any value exactly zero.
Then run the comparative checks that require history: single-interval change against the CML's established rate, circuit-wide same-sign shifts, and interval length against the uncertainty gate. Each exception carries a disposition, which is accept, hold for re-shoot, exclude with reason, or return to the contractor, and each disposition carries a name and a date. Nothing is corrected invisibly, because the correction is itself a record.
The commercial benefit is that contractor quality becomes measurable. Exception rate per submission, per contractor and per crew is a number you can put in a quarterly performance review and into the next tender. Most refineries have a firm opinion about which of their inspection contractors is more reliable and no evidence for it; this produces the evidence as a by-product of checks you needed to run anyway.
How the governing rate feeds intervals, RBI and integrity operating windows
The governing rate is not an end product. API 510 sets internal or on-stream inspection intervals at the lesser of one-half the remaining life or a ceiling, and API 570 does the same for piping against class-based maxima. Halve a remaining life and you halve an interval, which is a budget line, a scaffold, a permit and a place in the turnaround schedule. The rate is where a great deal of downstream cost is determined.
Under API RP 580 and RP 581 the corrosion rate feeds probability of failure, and the quality of the inspection that produced it feeds the inspection effectiveness grading. That is the practical reason data provenance has financial value. The same reading, taken with documented technique by a certified technician on a calibrated instrument, earns a better effectiveness grade than an anonymous number in a spreadsheet, and a better grade supports a longer interval at the same risk.
API RP 584 closes the loop in the other direction. Integrity operating windows are set from the damage mechanisms and rates the inspection data supports, so a governing rate that moves should trigger a review of the window rather than only an interval change. A module that raises a notification when a governing rate crosses a threshold, and routes it to the corrosion specialist who owns that window, is doing what the recommended practice describes rather than filing a number.
How to evaluate a corrosion rate engine
Give the vendor a circuit with a known contractor problem in it and ask what the software says about it. The useful question is not whether it can compute two rates, because everything can, but whether it detects the oscillation, whether it flags the uncompensated hot reading, and whether it declines to let a five-month interval set a remaining life without a named person accepting it.
Ask how a rate is recomputed when history changes. Reinstating an excluded point, correcting a nominal thickness, or receiving a late-arriving report all change past rates, and a system that overwrites without versioning has destroyed the audit trail an auditor will ask for. Each computed rate should be reproducible: the same inputs, the same formula version and the same answer, with the inputs retained as they stood.
Finally, ask what happens on the exception path, because that is where the work actually is. If every flagged reading requires an engineer to open a record, read a trend and type a note, the checks will be switched off within a quarter. If exceptions are batched, pre-classified by signature and dispositioned in bulk with a reason, they get done. A demonstration on your own data, with your own exception volume, settles this in an hour; contact info@atlantisndt.com to arrange one.
Which corrosion rate should govern remaining life?
Both are computed and stored, and the more conservative normally governs. API 570 sets out both formulas and expects an inspector or corrosion specialist to select the rate that best reflects current process conditions, so the system should record who accepted the governing value rather than silently taking the maximum. In refining the short-term rate is usually the one that matters, because a process change shows up there first and is invisible in a long average.
How short an inspection interval is too short for a short-term rate?
Short enough that gauge repeatability dominates the difference. With a realistic field repeatability of about plus or minus 0.004 in, a twelve-month interval carries roughly an 8 mpy uncertainty band and a six-month interval doubles it. Most refinery carbon steel corrodes at single-digit mils per year, so short intervals produce apparent rates that are mostly noise. Publish the band with the rate and gate short-term governance below a minimum interval.
How do you detect that a contractor's step change is not real corrosion?
By signature. Location errors oscillate, and a step that reverses on the next survey is a repeatability problem, because no corrosion mechanism restores metal. Instrument, probe or velocity changes shift an entire circuit at once, same sign, coincident with a report boundary. Uncompensated high-temperature readings bias thick by roughly one percent per 100 F above ambient. Each of those is a rule an import stage can apply automatically before the data reaches a trend.
What does an uncompensated hot reading do to a corrosion rate?
It hides loss. Ultrasonic velocity in steel falls as temperature rises, so a hot reading taken with a room-temperature velocity setting reads thicker than the metal actually is. The customary field correction subtracts about one percent of indicated thickness per 100 F above ambient, roughly 0.027 in on a 0.500 in wall at 600 F. That is several years of a typical refinery rate, and the error flips sign the moment the next contractor does compensate.
Can the system take submissions from several inspection contractors at once?
Yes, through a staged import with an acceptance step rather than a direct write into the trend. Each submission is validated against the circuit register, personnel and calibration records, and physical plausibility limits, then checked against history for step changes and circuit-wide shifts. Every exception carries a disposition and a name. A useful by-product is a measurable exception rate per contractor and per crew that you can take into the next tender.
How does the governing rate affect inspection intervals and risk-based inspection?
Directly. API 510 sets internal or on-stream inspection intervals at the lesser of one-half the remaining life or a ceiling, and API 570 does the same for piping against class-based maxima, so halving a remaining life halves an interval. Under API RP 580 and RP 581 the rate feeds probability of failure while the quality of the inspection that produced it feeds effectiveness grading, which is why documented provenance is worth money in interval terms.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.