Thirty Years of Tank History, and the Records That Do Not Import

A tank terminal computes corrosion rates separately for shell courses, the annular ring and the floor, because API 653 applies a different minimum-thickness criterion to each and the floor carries both a topside and an underside rate. Migrating legacy history fails not on the thickness column but on the timeline: repair dates, cathodic protection changes and product reassignments left behind in the PDFs.

Terminals rarely lack data. They have twenty-five years of API 653 out-of-service reports, shell ultrasonic readings by course, floor magnetic flux leakage runs in three vendors' formats, and settlement surveys — all correct, all in shapes the new system was never designed for. What fails on import is not the numbers. It is the timeline: a shell course patched in 2011, cathodic protection energised in 2004, a change from gasoline to a heavier product that moved required thickness without moving a single reading. A long-term rate computed across any of those events describes metal that did not exist for part of the interval. A corrosion-rate module for terminals has to hold rate epochs rather than one continuous series per location, keep topside and underside floor rates as distinct fields with distinct evidence, and carry the interval logic that API 653 and 49 CFR 195.432 both key back to the calculated rate.

Source: Written against API 653 (Tank Inspection, Repair, Alteration and Reconstruction), including its shell minimum-thickness provisions and its bottom minimum-remaining-thickness treatment with separate topside and underside corrosion rates; API 650 for original construction; API 575 for inspection of atmospheric and low-pressure storage tanks; API 651 for cathodic protection of aboveground petroleum storage tanks; 40 CFR 112 (SPCC) integrity testing requirements; 49 CFR 195.432 for breakout tanks on regulated pipelines; ASME Section V, Article 23 (SE-797) for ultrasonic thickness measurement; ASNT SNT-TC-1A for personnel qualification.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What migrates from a legacy tank-inspection archive, and what breaks if it is skipped
Legacy recordTypical formatMigrates cleanly?What breaks if it is skipped
Shell UT readings by courseReport tables or a per-tank spreadsheetYes, once course and orientation are mappedRates evaluated against the wrong course minimum thickness
Repair and alteration historyNarrative text in the API 653 report; paper forms in a filing cabinetNo — must be re-keyed as dated events before any readings loadLong-term rates computed straight through replaced metal
Floor MFL scansVendor proprietary file, often only a PDF colour mapPartly — indications and the report, not a thickness gridSynthetic grids that will look measured to whoever reads them in 2032
Prove-up UT at MFL indicationsAppendix table in the inspection reportYes, if the indication location IDs surviveUnderside rates with no directly measured basis
Cathodic protection historyAPI 651 survey records and rectifier logs, a separate archiveNo — usually held by a different department entirelyUnderside rates averaged straight across a regime change
Minimum-thickness inputsHardcoded constant per course in the old workbookNo — the inputs must be recovered, not the resultRemaining life that cannot be recomputed after a product change
Settlement surveysSurvey contractor reports, sometimes drawings onlyAs dated attachments and eventsLoss of the explanation for localised annular and shell-to-bottom corrosion
Load the event timeline first and the thickness readings second. Rates computed afterwards will respect the events automatically.

Three assets in one tank, three corrosion rates

A field-erected storage tank is not one asset for corrosion-rate purposes. It is at least three, and API 653 handles them separately because they fail differently and answer to different minimum thicknesses. The shell is a hoop-stress problem, and required thickness varies by course because the bottom course carries the full product head while the top course carries almost nothing. The floor is not a pressure boundary at all — it is a containment membrane whose criterion is a minimum remaining thickness before a leak, not before a rupture. The annular ring sits between the two and inherits the worst characteristics of both.

The consequence for a corrosion-rate module is that a single tank-level corrosion rate is meaningless. A tank can be losing 0.004 in/yr on the underside of the floor while the upper shell courses lose effectively nothing, and the number that sets the next internal inspection is the floor rate. Terminals that report one rate per tank almost invariably report the shell rate, because the shell is what external ultrasonic surveys see between internals — and the shell is the component least likely to be the constraint.

Required thickness itself varies by course and must be stored per course, together with the product specific gravity, design liquid level, course geometry and joint efficiency it was derived from. A remaining-life number that does not carry its own inputs cannot be re-derived when any of them change, and at a terminal at least one of them changes every few years. This single design decision — store the inputs, not the answer — separates systems that survive five years from systems that are quietly replaced by a spreadsheet.

Why the floor needs two rates and the shell needs one

API 653 addresses bottom plate remaining life using separate topside and underside corrosion rates evaluated against a minimum remaining thickness. This is not a bookkeeping formality. Topside corrosion is product-side and is driven by water bottoms, settled sediment, microbially influenced attack under sludge and sulfur species in the stored product. Underside corrosion is soil-side and is driven by moisture in the pad, soil chemistry and resistivity, the condition of any release prevention barrier, and whether cathodic protection is actually polarising the steel.

The two rates have almost nothing in common and respond to entirely different spending. Improving water draw-off practice and tank cleaning frequency moves the topside rate. Repairing a rectifier or extending the anode ground bed moves the underside rate. A system that stores one floor rate makes both interventions invisible, and terminals routinely fund one while the other is the binding constraint. Merging the two is the most common modelling error in tank integrity software.

They are also measured with very different confidence. Topside loss is directly measurable during an internal — a gauge on clean steel. Underside loss is inferred, usually from MFL indications sized against a limited set of verification ultrasonic readings. That difference belongs in the record. A topside rate built from forty direct readings and an underside rate inferred from twelve prove-up points are not the same class of number, and a system that renders them identically invites a decision the data does not support.

What actually breaks when you import thirty years of tank history

The import that fails on a terminal migration is not the thickness column. Thickness readings are numbers with dates and they move cleanly. What fails is everything that happened to the metal between them. A tank whose second and third shell courses were patched in 2011, whose annular ring was partially replaced in 2016, and whose floor was lined in 2004 has three discontinuities in its history, and a long-term rate computed straight through any of them is arithmetic performed on metal that was not there for part of the interval.

Legacy systems almost never carry this in machine-readable form. It sits in the repair narrative of an API 653 report, on a paper form in a filing cabinet, or in the recollection of an inspector who has retired. Recovering it is genuine work, and it is the work that determines whether the migration produces a usable system or an expensive copy of the old one. The pragmatic order is to pull every out-of-service report, extract repair scope and date only, and load those as dated events before a single thickness reading is imported.

The test for whether a candidate system understands this is short. Load a repair event into the middle of a history and ask for the long-term rate at an affected location. The correct behaviour is to compute from the repair date, label the output as a post-repair rate, and keep the pre-repair series intact as a separate epoch. Silent continuity is the failure mode, and it is silent by definition — nobody discovers it until an auditor asks how a 2011 plate accumulated seventeen years of loss.

Cathodic protection creates a step change, not a slope

Cathodic protection does not slow soil-side corrosion gradually. It changes the regime. Before the rectifiers were energised, the underside of a tank floor may have been losing 0.008 in/yr. Afterwards, with adequate polarisation and a functioning ground bed, it may be losing an order of magnitude less. A long-term rate averaged across that transition reports a figure somewhere in between, which accurately describes no period of the tank's actual life and understates the risk in the years before commissioning while overstating it in every year since.

For a terminal migrating history, the CP retrofit date is often the single most valuable piece of metadata in the entire archive — and it is almost never in the thickness data. It lives in the API 651 survey records, usually held by a different department, sometimes by a contractor. Annual survey results, rectifier readings and any documented interruption periods belong on the same timeline as the thickness readings, because a rectifier that was off for eighteen months created a corrosion-rate epoch whether or not anyone recorded it as one.

The output this makes possible is a rate an integrity engineer can defend in a sentence: underside rate 0.0009 in/yr since CP commissioning in 2004, prior-epoch rate 0.0071 in/yr, next internal driven by the post-CP rate with a documented basis. That statement is worth doing the migration properly for. Its opposite — one blended rate with no epochs — cannot survive a single question from an auditor who happens to know when the rectifiers went in.

A product change moves required thickness without moving a reading

Terminals reassign tanks, and they do it more often than the integrity records suggest. A tank moved from gasoline to a heavier product experiences greater hydrostatic head at every shell course, which raises the required minimum thickness at every course, which reduces remaining life at every CML — without a single new thickness reading being taken. Legacy spreadsheets almost universally hold required thickness as a hardcoded constant per course, entered once during the original build and never revisited.

A corrosion-rate module for terminals therefore has to store the inputs rather than the result: specific gravity, design liquid level, course height and position, joint efficiency and corrosion allowance. It recomputes on change, retains the previous values with their effective dates, and keeps every historic remaining-life figure reproducible in the context in which it was originally issued. Without effective dating, recomputation silently rewrites history and the archive stops matching the reports that were sent to regulators.

This is also the most common reason a newly migrated terminal system disagrees with the old spreadsheets on day one. The spreadsheet was right for the service the tank had in 2014. The new system is right for the service it has now. Both numbers are correct and only one is current. Teams briefed to expect the disagreement resolve it in an afternoon. Teams that are not spend a quarter arguing about whether the software works.

MFL is not a thickness gauge, and the rate it feeds is different

Magnetic flux leakage floor scanning locates and ranks indications. It does not measure wall thickness. The output is a percentage of nominal loss carrying an accuracy band that varies with plate thickness, coating thickness, scan speed and the calibration plate used. Treating an MFL percentage as though it were an ultrasonic reading imports the tool's uncertainty directly into a number that will decide whether a tank comes out of service, and the uncertainty disappears from the record the moment it is stored as a thickness.

The defensible workflow is MFL for coverage, prove-up ultrasonic readings for measurement, and a corrosion rate computed from the prove-up readings with the MFL result retained as the coverage evidence. The system should hold both, linked to the same locations, and should be able to state which of the two produced any given rate. Terminals that merge them lose the ability to answer the question every auditor eventually asks, which is not what the rate is but how you know it.

On migration, historic MFL data is typically the least portable asset in the archive — vendor-specific formats, and in older files often nothing but a PDF colour map. Accept that limitation rather than engineering around it. Migrate the prove-up ultrasonic readings, the indication counts and severity distribution, and the report itself as an attachment. Do not reconstruct a synthetic thickness grid from a scanned image, because a grid you invented is indistinguishable from a grid you measured once six years have passed.

The interval is the deliverable, not the rate

For most terminals the corrosion rate is an intermediate value. The deliverable is the inspection interval. API 653 caps the external inspection interval and drives the internal interval from the calculated bottom corrosion rate and remaining thickness, so the rate is the input to a scheduling decision with substantial cost attached on both sides. An error in the conservative direction pulls a revenue tank out of service early. An error in the other direction is considerably worse.

The regulatory frame at a terminal is denser than most operators expect it to be. SPCC under 40 CFR 112 requires integrity testing on a schedule consistent with industry standards, which for large field-erected tanks means API 653. Breakout tanks associated with regulated pipelines fall under 49 CFR 195.432, which points to API 653 directly. State programmes and, at some sites, consent-decree schedules layer on top. The same tank can owe its inspection to two federal citations and a state permit, and every one of them derives from the same calculated rate.

A module that produces a rate but not the interval — with its basis, its code cap, its next-due date and the evidence trail behind it — leaves the highest-consequence step of the process in a spreadsheet. That is precisely the step the migration was supposed to remove from the spreadsheet, and it is the step most likely to be examined.

How to evaluate a corrosion-rate module during a migration

Evaluate with your own worst tank rather than a demonstration dataset. Choose the one with the most repairs, the CP retrofit, the product reassignment and the missing 2009 report, and ask the vendor to load it in front of you. What you are watching is not whether it loads — everything loads — but what the system does with the gaps. Quarantined and visible is the right answer. Defaulted and hidden is a system that will produce confident numbers built on assumptions nobody wrote down.

Three questions separate candidates quickly. Can it hold more than one corrosion-rate epoch per location, and explain which epoch produced the rate it is showing? Does it keep topside and underside floor rates as distinct fields with distinct evidence and distinct confidence? Can it recompute every historic remaining-life figure after a required-thickness input changes, while still showing what the number was when it was issued? A no to any of the three means the spreadsheet returns within a year, running alongside the software.

Finally, ask what happens the day an inspector disagrees with the calculation. The right answer is an override that demands a reason, an owner, a date and a permanent trace — not an editable cell. In a terminal the override is frequently correct; experienced inspectors know things the model does not. It is the absence of a record of the override, not the override itself, that fails an audit.

Why does API 653 need two corrosion rates for a tank floor?

Because the two sides of a bottom plate corrode for unrelated reasons and respond to unrelated interventions. API 653 treats bottom remaining life with separate topside and underside corrosion rates against a minimum remaining thickness criterion. Topside loss is product-side — water bottoms, sediment, microbial activity under sludge. Underside loss is soil-side — pad moisture, soil chemistry, release-prevention barrier condition and cathodic protection status. Improving water draw-off moves one; fixing a rectifier moves the other.

What happens to a long-term rate when a shell course was patched?

It becomes arithmetic on metal that was not present for part of the interval. A course patched in 2011 has an installation date that resets the baseline at those locations only. Computing from a 1998 original baseline to a 2026 reading on 2011 plate yields a number that describes nothing physical. The correct behaviour is to compute from the repair date forward, label the result as a post-repair rate, and retain the pre-repair series as a separate epoch rather than deleting it.

Can MFL scan results be used directly as corrosion-rate input?

No. Magnetic flux leakage finds and ranks indications; it does not measure wall thickness. Its output is a percentage of nominal loss with an accuracy band that depends on plate thickness, coating thickness, scan speed and the calibration plate. Feeding that percentage into a rate calculation imports the tool's uncertainty into a decision worth an out-of-service outage. Use MFL for coverage, prove-up ultrasonic readings for measurement, and record which of the two produced the rate.

Does changing the stored product change the corrosion rate or the remaining life?

The remaining life, immediately and at every course, without a single new reading being taken. Moving a tank to a heavier product raises the hydrostatic head, which raises required thickness course by course. Legacy workbooks store that required thickness as a hardcoded constant, so the change is invisible. A system must store the inputs — specific gravity, design liquid level, course geometry, joint efficiency — and recompute, keeping the previous values with their effective dates.

How should cathodic protection history be reflected in the rate?

As an epoch boundary, not as a gradual improvement. Cathodic protection changes the soil-side regime rather than slowing it smoothly, so an underside rate averaged across commissioning describes no actual period of the tank's life. Carry the energisation date, annual API 651 survey results and any documented interruption periods on the same timeline as the thickness readings. A rectifier that was off for eighteen months is a corrosion-rate epoch whether or not anyone logged it as one.

Is API 510, 570 or 653 inspector training part of this offer?

No. API inspector certification runs through API's own Individual Certification Programs and is outside the scope of this software. What Atlantis provides here is the inspection management system that holds the readings, rates, repair events and interval logic. Separately, Atlantis delivers NDT training to ASNT SNT-TC-1A and ISO 9712 at Levels I, II and III, including the ultrasonic thickness work that feeds every shell and prove-up rate in the system.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.