Making an offshore corrosion rate defensible before the auditor arrives

Offshore and upstream corrosion rates must be computed twice: a long-term rate from the earliest reliable thickness and a short-term rate from the previous inspection. The higher rate governs remaining life unless an engineer documents otherwise. Audits fail not on the arithmetic but on the chain behind it — CML identity, probe temperature, and who was qualified to take the reading.

API 510 and API 570 both define the long-term rate as the earliest reliable thickness minus the current thickness, divided by the years between them, and the short-term rate as the previous thickness minus the current thickness over that shorter interval. The larger of the two governs remaining life unless a corrosion specialist documents a technical reason to use the smaller. Offshore, that rule collides with data that is expensive and irregular to collect. A CML on a splash-zone riser may be read by rope access once every three years; a wet gas line may be read hot at 180F on one campaign and cold on the next; a sour line may return a mid-wall blister that reads as fifty percent metal loss. A system that stores only the final number cannot survive an auditor asking how that number was produced.

Source: Rate methodology and interval logic follow API 510 (Pressure Vessel Inspection Code) and API 570 (Piping Inspection Code). Damage mechanism identification follows API RP 571. Risk ranking follows API RP 580 and API RP 581. Sour service material limits follow NACE MR0175 / ISO 15156. Erosional velocity guidance follows API RP 14E. Offshore safety and environmental management program expectations follow API RP 75 and 30 CFR Part 250 Subpart S. Personnel qualification follows ASNT SNT-TC-1A, ASNT CP-189 or ISO 9712.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What an offshore audit pulls at a single CML, and where the record usually fails
Record requestedWhat it has to proveWhere offshore records break
Raw thickness reading and instrument recordThe number was measured, not typed or estimatedDigital gauge log absent; only a transcribed spreadsheet value survives the campaign
CML identity and datum sketchThis year's reading and last year's came from the same steelGrid re-established from different scaffold; a 6 o'clock point read at 5 o'clock under an insulation band
Metal temperature and gauge mode at time of readingThe reading needs no correction, or the correction was appliedHot reading on a producing flowline recorded with no temperature; single-echo through-paint mixed with echo-to-echo
Technician certification and method scopeThe reader was qualified for the method and thickness rangeCertification expired mid-campaign, or the certificate is for UT thickness while the scan was a corrosion map
Calibration block and traceability certificateThe instrument was verified against a known standardBlock serial number recorded but no traceable certificate; velocity setting never documented
Rate calculation, remaining life and next inspection dateThe interval was set from the governing rate, not the convenient oneShort-term rate suppressed with no engineering justification, or a negative rate silently clamped to zero
Deferral assessment and management of changeAn overdue inspection was assessed, not just postponedWeather-window deferral recorded in an email thread; no risk assessment attached to the equipment record

Why offshore changes the corrosion rate question

Onshore, a condition monitoring location is a painted circle you can walk to in ten minutes. Offshore, every reading carries a cost structure: a helicopter seat, a bed on the platform, a permit to work, a rope access team or a diver, and a weather window that may close before the scope is finished. That cost pushes frequency down and interval length up, and the rate arithmetic is exquisitely sensitive to interval length. A 0.004 in disagreement between two readings is 4 mpy across a one-year interval and 1 mpy across a four-year interval. The same instrument error produces a rate that differs fourfold purely because of when the boat could sail.

The damage mechanisms differ too. Sweet CO2 corrosion in wet gas gathering, top-of-line corrosion where condensation forms at twelve o'clock on a cooled flowline, under-deposit attack beneath solids in a low spot, microbiologically influenced corrosion in produced water and seawater injection systems, sand erosion at chokes and the first bend downstream, and corrosion under insulation aggravated by marine air and by passive fire protection that nobody wants to cut. Each has a different time signature, and several are step functions rather than slopes. A single averaged rate per line flattens all of them into a number that describes none of them.

Then there is the question of who owns the record. On most offshore assets the operator owns the integrity management system, an NDT contractor takes the readings, an engineering consultancy runs the fitness-for-service work, and a certifying authority, client or regulator audits all three. The corrosion rate is the number where those four parties meet, and it is invariably the number they disagree about first.

The two rates, and what the code actually requires

The long-term rate takes the earliest reliable thickness for a location, subtracts the current thickness, and divides by the elapsed years. The short-term rate does the same using the previous inspection instead of the earliest. Remaining life is the current thickness minus the required minimum thickness, divided by the governing rate. The next inspection interval is the lesser of half that remaining life and the maximum the code allows for the equipment class. The governing rate is the larger of the two unless a corrosion specialist documents a technical reason for using the smaller.

The asymmetry is deliberate. A long-term rate damps measurement noise and gives a stable planning number, but it is blind to change. A short-term rate is noisy but sees acceleration. By making the larger one govern, the code accepts a certain rate of false alarms in exchange for not missing a genuine step change. Software that computes only one rate, or averages the two, has quietly removed the safety behaviour the code was built around, and no auditor who understands the method will let that pass.

The rule also has a legitimate exit, and a good system makes that exit expensive rather than easy. A specialist may justify using the lower rate — for example when a short-term spike is traced to a demonstrated measurement artefact rather than metal loss. That justification is an engineering record: the mechanism, the evidence, a named individual, a date, and enough reasoning to stand up after that individual has left the company. If a planner can suppress a short-term rate with a dropdown and no artefact, the audit finding writes itself.

CML identity is the first thing an audit breaks

The formula assumes that both thickness values came from the same piece of steel. Offshore, that assumption is fragile in ways that rarely get written down. Grids are re-established from scaffold that was not in the same place last campaign. A rope technician reads what can physically be reached. A six o'clock location under an insulation band gets read at five o'clock because the band would not move. A spool is replaced during a shutdown and the old CML number is carried forward onto new pipe, so the next long-term rate is computed across a component boundary.

The observable symptom is the negative corrosion rate: this year's reading is thicker than last year's. Most systems either clamp the value to zero or drop the point from the trend. Both responses hide the real finding. A negative rate is not noise to be filtered — it is a measurement telling you that the two numbers came from different places, different temperatures, different transducers or different surface conditions. On a well-run offshore dataset, negative rates cluster around exactly the locations where access is hardest, which is precisely where you least want your data to be wrong.

A defensible system does the opposite of filtering. It keeps negative rates visible and demands a disposition. It stores photographs and a datum sketch against the CML rather than against the line, so the next technician can find the same spot. It versions the location when a component is replaced, starting a fresh long-term baseline and refusing to compute a long-term rate across the replacement. And it records who established the grid, because grid establishment is an engineering act, not a clerical one.

Readings taken hot, cold, and through coating

Ultrasonic velocity in carbon steel falls as temperature rises, roughly one percent per 100F. A gauge calibrated at ambient and used on a producing line therefore over-reads. On a 0.600 in riser wall read at 200F with no correction, that is about 0.006 in of metal that is not there. Across a one-year interval, 0.006 in is 6 mpy — comparable to the actual CO2 corrosion rate on many wet gas lines. If one campaign is taken on a running line and the next during shutdown, the correction error changes sign and the trend inverts.

Coating introduces a second systematic offset. A single-echo gauge measuring through paint includes the paint in the reading. Echo-to-echo mode removes it, but needs adequate back-wall signal and may fail on rough or heavily corroded surfaces. Offshore coating systems are thick, and passive fire protection thicker still. A contractor who switches from through-paint single-echo to echo-to-echo between campaigns generates an apparent step loss of ten to twenty thousandths across hundreds of CMLs simultaneously. That produces a fleet-wide short-term rate alarm from a method change, and an integrity engineer who cannot explain it will either ignore the whole dataset or spend a shutdown chasing corrosion that does not exist.

The requirement follows directly. The record must carry the instrument and firmware, the measurement mode, the transducer type and frequency, the couplant, the calibration block and its traceability, the surface preparation, and the metal temperature at the moment of reading. With those fields, a step change can be attributed to a method change in an afternoon. Without them, it cannot be attributed at all, and the honest engineering answer is that the previous decade of trend is unusable.

Sour service produces rates that are not corrosion

In H2S service governed by NACE MR0175 / ISO 15156, hydrogen-induced cracking and blistering create planar features inside the wall. An ultrasonic thickness gauge reading a mid-wall blister returns the echo from the blister, not the back wall, and reports roughly half the nominal thickness. Loaded as a thickness value, that produces a short-term rate in the hundreds of mils per year and a remaining life measured in weeks. The number is physically impossible for uniform corrosion, and the correct response is not to compute a rate at all but to reclassify the indication.

This is why a rate module has to be mechanism-aware rather than purely arithmetic. A location tagged for wet H2S damage — HIC, SOHIC, stepwise cracking, sulfide stress cracking — should route to an evaluation workflow requiring A-scan or full waveform review, not to a trend line. API RP 571 gives the mechanism definitions; the software's job is to make the tag consequential, so that tagging a CML changes what the system does with its data rather than adding a label nobody reads.

The same principle covers other non-thinning mechanisms present offshore: chloride stress corrosion cracking in austenitic stainless under insulation, fatigue at small-bore connections on vibrating lines, and preferential weld corrosion where the weld metal chemistry differs from the parent. None of these are described by a thickness slope. A rate engine that treats all metal loss as uniform corrosion will convert a cracking finding into a thinning statistic, and the statistic will look reassuringly ordinary right up until it is not.

Weather windows, deferrals, and the interval that quietly expired

An offshore inspection plan is a set of dates that the weather negotiates with. When a campaign slips, the equipment does not become safer; the interval simply gets longer. Audits check two things here: whether any next-inspection date was exceeded, and whether an exceedance was formally assessed and approved rather than absorbed. A deferral captured in an email thread and a spreadsheet cell is the single most common integrity documentation finding on offshore assets, and it is entirely a systems problem rather than an engineering one.

There is a subtler failure underneath it. Stretching the interval also stretches the denominator of the short-term rate. A location read at twelve months, then at thirty-six, has a short-term rate computed over three years — which mathematically converges toward the long-term rate. The system's own early-warning mechanism goes quiet at exactly the moment the asset has gone longest without being looked at. Nobody suppressed the alarm; the arithmetic did it for them.

The countermeasure is to track the interval clock as a separate object from the rate. The system should know the due date, the actual date, the deferral request, the risk assessment that supported it, the approver, and the expiry of that approval. It should flag rates computed across unusually long intervals as lower confidence, so a planner reading a trend chart can see that a flat-looking line is flat because it is under-sampled rather than because the corrosion stopped.

Sand, chokes, and the step change a long-term rate will not show

API RP 14E gives the familiar erosional velocity relationship, with the fluid velocity limit inversely proportional to the square root of mixture density and scaled by an empirical C-factor. It is a screening tool rather than a prediction, but it captures the essential point: velocity and solids together drive a loss mechanism that has nothing to do with electrochemistry and does not respond to inhibitor. A sanding well can put an order of magnitude more metal loss into the first bend downstream of a choke than the underlying CO2 corrosion rate would ever produce.

Run the arithmetic on a real shape of failure. A bend has lost 0.180 in over twelve years of service: a long-term rate of 15 mpy. If 0.120 in of that loss occurred in the last fourteen months after a workover, the short-term rate is roughly 103 mpy. With 0.140 in of wall available above the required minimum, remaining life is 9.3 years on the long-term rate and 1.4 years on the short-term rate. One number puts the component in the next five-year plan; the other puts it in the next shutdown. This single divergence is the entire justification for computing both.

What makes the short-term number credible to an auditor is a cause. If the system links condition monitoring locations to process and well events — sand detector alarms, choke position changes, a new tie-in, gas lift startup, a change in water cut — then the spike arrives with an explanation attached. Without that linkage, an engineer facing a hundred-mpy short-term rate has only two options: believe it and spend money, or disbelieve it and write a justification that will not survive review.

How to evaluate a system before the audit, not during it

The most informative demonstration you can ask for takes twenty minutes and uses your own data. Bring five real condition monitoring locations from your least tidy dataset, including at least one that has produced a negative rate and one where a spool was replaced. Ask the vendor to load them and reproduce your published remaining life and next inspection date, then ask to see the evidence chain behind one of those numbers — reading, datum, temperature, mode, technician certification valid on that date, calibration traceability. Most systems can show a chart. Fewer can show a chain.

Then test the behaviours that matter under audit rather than under demonstration. How does the system handle a negative rate — does it hide it, or force a disposition? What does it require before a short-term rate can be set aside? Does replacing a component start a new baseline automatically? Can a damage mechanism tag change how a location is processed rather than just how it is labelled? Are technician certifications live objects that expire and block, or are they scanned PDFs in a folder? Can you export the full audit trail for one location without a support ticket?

Atlantis builds inspection management, reporting and digital twin software around exactly this chain, configured to the way an offshore operator or an NDT service provider already works rather than forcing a rewrite of the procedure. The positioning is affordable, accessible and fully customizable. If you want to see the negative-rate workflow and the evidence chain run against your own CML history, request a demonstration or a consultation at info@atlantisndt.com and bring the messy data — it is more useful than the clean data.

What does an offshore auditor actually check on a corrosion rate?

Rarely the division itself. An auditor picks three to five CMLs and asks you to reproduce the number from source records: the raw gauge reading, the CML datum, the metal temperature, the technician's certification valid on that date, the calibration block traceability, and the engineering disposition if the short-term rate was set aside. Any link that cannot be produced within a few minutes becomes the finding, regardless of whether the rate was correct.

Why does the short-term rate matter more on a sand-producing well?

Because erosion is a step function and a long-term rate is an average. When a well starts producing sand, or a choke is changed, or a new tie-in shifts velocity above the API RP 14E erosional threshold, metal loss at the first bend downstream can jump by an order of magnitude in months. Averaged across a decade of service that spike disappears. The short-term rate is the only calculation that sees it, which is exactly why the code makes the higher rate govern.

Can a corrosion rate be negative, and what does it mean?

Arithmetically yes, and it is one of the most useful signals in the dataset. Steel does not grow. A negative rate means the two thickness values did not come from the same conditions: a different point on the grid, a different temperature, a different gauge mode, a spool that was replaced, or a transcription error. Systems that clamp negatives to zero or discard them destroy the evidence that CML identity has broken, which is the finding that actually matters.

How does splash zone and CUI inspection change the calculation?

Both produce sparse, irregular data. Splash-zone access depends on sea state and often yields readings only in fair-weather windows, so intervals stretch unevenly. Corrosion under insulation offshore is aggravated by salt-laden air and by passive fire protection that cannot be stripped casually, so inspection is frequently partial or by screening technique. Rates built on partial coverage need a confidence attribute stored alongside them, or a planner will treat a single opportunistic reading as a fleet baseline.

Does 30 CFR 250 or API RP 75 tell you how to compute a corrosion rate?

No, and that distinction matters in an audit. API RP 75 and the SEMS requirements in 30 CFR Part 250 Subpart S govern the management system: mechanical integrity procedures, documentation, competency, management of change, and audit. They require that you have a defensible method and follow it. The arithmetic itself comes from API 510 and API 570. An audit therefore tests whether your written procedure and your software agree, not whether the formula is right.

Is API 510, 570 or 653 inspector certification training part of this offer?

No. Atlantis does not deliver API inspector certification programs. What Atlantis provides is NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, ASNT Level III consulting, inspection management and reporting software, digital twins, 3D laser scanning, and independent report validation. API inspector certification is administered separately by API, and the software simply stores and expires those credentials alongside NDT qualifications.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.