Standardising deficiency tracking across an offshore portfolio

Offshore deficiency tracking fails at fleet level when each installation keeps its own severity words and its own closure habits. A module that works stores one fleet severity value behind each site's local label, computes due dates from that value instead of accepting typed ones, carries engineered temporary repairs as dated objects with an expiry, and normalises open-finding counts by inspection coverage rather than by site.

Offshore constraints change the shape of the problem. Bed space and helicopter seats ration repair execution, so a finding's real cost is a manifest slot rather than a labour hour. Weather windows push work into campaigns, which makes the register a planning input months before it is a closure record. A large share of offshore defects are carried on engineered temporary repairs, composite wraps and clamps under ASME PCC-2, justified by a fitness-for-service assessment to API 579-1/ASME FFS-1, each with an expiry date and a re-inspection obligation that a plain status field cannot hold. Under a SEMS programme built to API RP 75 and 30 CFR Part 250 Subpart S, and under safety case regimes elsewhere, a defect against a safety and environmental critical element answers to a written performance standard rather than to a supervisor's sense of urgency. The module has to separate those from a corroded handrail on the first screen, not in a report.

Source: Written against 30 CFR Part 250 Subpart S (SEMS) and API RP 75, API 510 and API 570 in-service inspection, API RP 580 and RP 581 risk-based inspection, API RP 2SIM structural integrity management, API RP 571 damage mechanisms, API 579-1/ASME FFS-1 fitness-for-service, ASME PCC-2 repair of pressure equipment, and NACE MR0175/ISO 15156 for sour service materials.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Harmonising local severity labels into one fleet class
Fleet classLocal labels commonly inheritedWhat earns the classDue-date rule the system stores
F1 — critical element impairmentCat A, Priority 1, Red, ImmediateLoss or degradation of a safety or environmental critical element, or a loss of containmentMitigation same shift; permanent close date taken from the element's performance standard
F2 — fitness-for-service dependentCat B, P2, Amber, Engineer to assessMeasured wall below t-min, or a flaw requiring an API 579 Level 1 or Level 2 assessment to keep operatingComputed from the assessment's remaining-life date, never typed by a user
F3 — campaign scopeCat C, P3, Yellow, Next POBDegradation with margin remaining, but execution needs a vessel, crane, diver or rope-access spreadNext scheduled campaign date for that installation, shifted automatically if the campaign moves
F4 — non-criticalCat D, P4, Green, Punch listNo integrity, safety-system or environmental consequence; access, coating or housekeepingRolling twelve months, no escalation path
T — temporary repair in serviceTR, clamp, wrap, often recorded as a closed Cat BDefect contained by a PCC-2 repair with an engineered design lifeExpiry date from the engineering case, plus a re-inspection date that is independent of expiry
Sites keep their own words on the entry form. The fleet class is what the roll-up counts, and it is never editable from the field.

The roll-up fails before the data does

The request that sends people looking is nearly always the same. Someone at group level asks how many open high-severity findings the portfolio is carrying. Seven installations return seven numbers, the numbers are added, and the total is quietly meaningless, because high was defined seven times by seven different people over twenty years and nobody wrote the definitions down.

The reflex is to call it a data quality problem and commission a cleanup. It usually is not. Each site's data is internally consistent, defensible and understood by the people who produced it. What is missing sits above the data: a shared statement of what a class means in consequence terms, and a mechanism that keeps the local meaning and the fleet meaning attached to the same record instead of forcing a choice between them.

That is why the first hour of this work is not software configuration. It is deciding, in writing, that a fleet class is defined by consequence and by the presence or absence of a critical element, not by how soon somebody wants the job done. Everything else in the module follows from that sentence.

Severity means something different on every installation

A typical portfolio inherits at least three vocabularies. A fixed platform commissioned in the 1990s still runs Cat A through D from its original commissioning punch list. A floating production unit uses the shipyard's snag categories, which were designed to close out construction defects and have no concept of in-service degradation at all. An acquired asset arrives with P1 to P4 from the seller's CMMS, where P1 was defined by a maintenance planner rather than an integrity engineer.

Those three scales do not disagree at the extremes. Everyone agrees that a live hydrocarbon leak is the top class. They disagree in the middle, which is where almost all the population sits: wall loss with margin remaining, a cracked support, a failed coating over a splash-zone weld, a gas detector out of calibration. One scale sorts the middle by how soon the job can be done, another by how bad it would be if nothing were done, and the two orderings are not the same list.

The way through is aliasing rather than replacement. The entry form keeps the local words; the database stores one fleet value. Historic records are mapped through the same table, with a named owner per site signing off the mapping, so that when the numbers change on the first roll-up after go-live, everyone can see exactly which mapping decision moved them.

Due dates must be computed, not typed

A free-text due date field turns the register into a negotiation. Offshore, the negotiation has a specific shape: the supervisor knows there is no walk-to-work vessel until the second quarter, so the date typed is in the second quarter, and the overdue report never shows the eight-month exposure that actually exists. The metric has absorbed the problem it was built to expose.

Computed dates fix this by separating two facts that a typed date fuses together. The required date comes from the fleet class and, for engineering-limited findings, from the remaining-life date in the fitness-for-service case. The achievable date comes from the campaign plan. When they diverge, the gap is visible, and the gap is the thing worth reporting to a duty holder. An extension is then a first-class event with an approver, a reason and the original date retained, rather than an edit that leaves no trace.

There is a companion trap worth designing against. On sites where the clock is the only metric, findings get closed and immediately re-raised under a new number, which resets ageing to zero. The register should carry lineage, so a re-raise inherits the original raised date and the fleet ageing chart tells the truth even when local behaviour does not.

Safety and environmental critical elements need their own clock

Offshore is one of the few sectors where the regulatory framework itself names a subset of equipment and attaches a written performance standard to it. Under a SEMS programme built to API RP 75, and under the safety case regimes that govern other basins, the elements whose failure would cause or fail to prevent a major accident are identified in advance, and their required performance is documented before anything goes wrong.

That changes what a deficiency record has to know. When a finding lands on a tag inside that set, the acceptable response is not a manager's judgement of urgency; it is whatever the performance standard says, and if the element cannot meet it, the operation runs on a documented deviation with compensating measures and a time limit. A register that cannot tell the two populations apart forces someone to make that call from memory, at the worst possible moment.

Most generic systems will let you tick a critical box on the finding. That is not the same thing. The criticality belongs to the tag, it is inherited by every finding raised against that tag, and it should drive the workflow automatically, including who is notified, which approvals are required to defer, and whether a deviation record is mandatory rather than optional.

Temporary repairs are the register's largest hidden liability

Offshore carries more engineered temporary repairs than any other sector, for a simple reason: replacing a spool means a shutdown, a lift and often a vessel, while fitting a clamp or a composite wrap means a rope-access team and a permit. Done properly, under ASME PCC-2 and supported by an API 579 assessment, these are legitimate engineering, not a shortcut. Done in a register that has no place to put them, they become invisible debt.

The failure mode is precise. The finding is marked closed when the wrap goes on, because the leak stopped and the immediate risk went away. The open count improves, the ageing chart improves, and the fact that forty-one wraps across the portfolio reach the end of their engineered life within eighteen months exists nowhere except in the heads of three corrosion engineers, one of whom is about to retire.

Model the repair as its own object. Install date, engineered design life, expiry, the assessment that justified it, the re-inspection interval, and a link back to the underlying finding which stays open in a state of its own. The fleet report then answers a question no spreadsheet was answering: which contained defects expire inside the next year, and which of those need marine support to resolve permanently.

Bed space, weather and vessels decide when a finding closes

Onshore, execution capacity is roughly elastic; you can add a crew. Offshore it is hard-capped by persons on board and by the flight schedule that feeds them. A finding that needs two technicians for three days is not competing for budget, it is competing for bunks against a drilling campaign, a shutdown crew and a class survey. That is why days-open, taken alone, is an unfair measure of an offshore integrity team.

The register should therefore carry an execution constraint on every finding: rope access, scaffold, diver or ROV, crane lift, hot work, isolation or full shutdown. Once that attribute exists, the backlog sorts itself into campaign scopes without anyone building a spreadsheet, and the annual planning conversation changes from arguing about priority to sizing the spreads needed to clear a defined population.

It also makes the portfolio comparison honest. A platform whose backlog is dominated by shutdown-only items and a platform whose backlog is rope-access work are not performing differently; they are constrained differently. Reporting them against the same ageing target guarantees that one team spends every review defending arithmetic instead of discussing risk.

Normalise by coverage, or the least-inspected asset wins

Any ranking built on raw open-finding counts rewards not looking. The installation that completed sixty per cent of its examination plan raises fewer findings than the one that completed all of it, and appears at the top of the league table for it. Over two or three reporting cycles, that incentive is strong enough to change behaviour without anyone deciding to change behaviour.

The correction is to publish coverage beside condition. Findings per examination completed, findings per CML read, plan adherence as a percentage, and raise rate by discipline. When a site's raise rate falls while its coverage holds, that is a signal worth investigating, and it is invisible in absolute counts.

A related distortion appears in ageing. Mean age across the fleet is dragged around by a handful of very old records, and can be improved simply by closing the oldest items whatever their risk. Report the age distribution and the count of findings older than their required date by class, rather than a single average anyone can move by cherry-picking.

Offline capture and the conflicting-edit problem

Bandwidth offshore is rationed and prioritised, and during a shutdown it is prioritised away from inspection. Any module that assumes a live connection to save a record will be worked around within a week, usually by writing on paper and typing it up onshore, which quietly reintroduces every date and attribution error the system was bought to remove.

The requirement is full offline creation and editing, including records another person raised, with attachments captured at full resolution and queued separately for resumable upload. Reconciliation must be field-level. Last-writer-wins on the whole record means a thickness reading taken at height is silently replaced by an onshore edit to a description field, and nobody will ever find out.

This is easy to test and hard to fake. In the demo, put the tablet into airplane mode, edit a finding on it, edit the same finding from a desktop, then reconnect. Ask to see both versions, the merged result and the audit entry. A system that cannot show you all three is going to lose data on a platform.

How to evaluate the module before you commit

Bring your own mess. Take one real finding from each installation, in each site's own words, and ask to see them entered on their local forms and then counted correctly in a single fleet report. Ask what happens when you change one mapping decision, and whether the historic numbers move with it.

Then push on the three things that separate a register from a filing cabinet. Ask to see a due date that cannot be typed. Ask to see a temporary repair with an expiry that keeps its parent finding open. Ask to see a finding closed with evidence, and then ask how the closure would be demonstrated to an auditor three years later, after the inspector who closed it has left and the contractor has changed.

Atlantis configures this module from a working NDT and integrity practice rather than from a generic workflow template, and the fleet severity rubric is built with your inspection leads rather than delivered to them. Atlantis NDT is affordable, accessible and fully customisable; a walkthrough against your own data is available on request through info@atlantisndt.com.

Why do fleet open-finding counts flatter the least-inspected installation?

Because findings are an output of inspection, not of condition. Rank seven installations by raw open findings and the platform that completed sixty per cent of its examination plan will look like the best performer, while the one that completed all of it looks worst. Normalise by examinations completed or by CMLs read, and publish plan adherence next to the finding count so the two numbers are read together.

What goes wrong when each installation sets its own due dates?

The due date stops describing risk and starts describing workload. A supervisor with no vessel until the second quarter types a second-quarter date, and the metric that was meant to expose the gap absorbs it instead. Overdue counts then measure how honest each site is rather than how exposed it is. Compute the date from the fleet class, and make an extension an approved event with a reason, an approver and the original date preserved.

How should an engineered temporary repair sit in the register?

Not as a closure. Fitting a clamp or a composite wrap under ASME PCC-2 contains the defect for an engineered life; it does not remove it. The finding stays open in a distinct state, and the repair becomes its own record carrying install date, design life, expiry, the fitness-for-service case that justified it, and a re-inspection interval that is usually shorter than the life. The fleet question then becomes which repairs expire inside the next twelve months and which of those need a vessel.

Can a site keep its own severity words after harmonisation?

Yes, and it should. Local vocabulary carries years of tacit calibration, and taking it away is how standardisation projects lose the inspection leads who have to enter the data. The entry form shows Cat A to D on one installation and P1 to P4 on another; both write the same fleet class underneath. Historic records are mapped by the same table, so a report written in 2019 still reads the way its author wrote it.

How does the module behave on a platform with an intermittent satellite link?

Field capture has to work with no link at all, including creating findings, attaching photographs and thickness readings, and editing records raised by someone else. Reconciliation should be per field rather than last-writer-wins on the whole record, so a thickness entered offshore is not erased by an onshore edit to the description. Binaries queue separately and resume, because a scan will not clear a saturated link during a shutdown.

Is API 510, 570 or 653 inspector training part of this offer?

No. Atlantis delivers NDT method training to ASNT SNT-TC-1A and ISO 9712 at Levels I, II and III across UT, RT, MT, PT, ET, VT, PAUT and TOFD, along with ASNT Level III consulting and report validation. API inspector certification is administered by API through its Individual Certification Programs and is obtained directly from them. Where a deficiency workflow references API 510 or 570 practice, it is referencing the code, not offering the certification.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.