One rule set, five sites, one overdue number

Across a mine, an extraction plant, an upgrader and SAGD central facilities, overdue means whatever each site decided it means. A scheduling module standardises the calculation, not the spreadsheet: one interval rule, one remaining-life convention, one definition of complete, plus duty-based due dates for slurry and froth lines that wear by tonnage rather than by calendar.

In Alberta the roll-up is not a management preference, it is a regulatory artefact. An owner-user runs a quality management system accepted by ABSA under the Pressure Equipment Safety Regulation, and that document states how intervals are set. If the mine site computes remaining life on the long-term corrosion rate, the upgrader uses the short-term rate and a SAGD plant takes the lesser of the two, the same wall loss produces three different due dates and the corporate compliance number is arithmetic fiction. The minimum thickness convention does the same damage: design minimum from the original code calculation versus structural minimum thickness can move a circuit from routine to a fitness-for-service assessment on identical readings. Hydrotransport makes it worse, because slurry elbows lose wall in millimetres per month against tonnes moved, so a calendar interval is the wrong unit entirely.

Source: Sources: Alberta Safety Codes Act and the Pressure Equipment Safety Regulation as administered by the Alberta Boilers Safety Association, including owner-user pressure equipment integrity management and quality management system acceptance; CSA B51; Alberta Energy Regulator Directive 055 and Directive 077; API 510, API 570 and API 653 for interval and remaining-life rules; API RP 571 for damage mechanisms including naphthenic acid corrosion, sulfidation and ammonium bisulfide corrosion; API RP 939-C for sulfidation of carbon steel piping; API 941 for hydrogen attack; API 579-1/ASME FFS-1 for fitness-for-service; API RP 580 and 581 for risk-based inspection; ASME Section VIII Division 1 and ASME B31.3 for design minimum thickness.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
One circuit, three sites, three due dates: where the conventions diverge and what it does to the roll-up
ConventionMine and extraction siteUpgraderSAGD central facilityEffect on the corporate number
Governing corrosion rateLong-term rate over full historyGreater of short-term and long-termShort-term rate over last two surveysThe same readings yield three remaining lives; a fleet backlog figure mixes them without saying so
Minimum thickness sourceStructural minimum thicknessDesign minimum from the original code calculationNominal less a fixed corrosion allowanceA circuit is routine at one site and a fitness-for-service case at another on identical data
Interval ruleFixed five-year cycle aligned to shutdownHalf remaining life, capped at the code maximumRisk-based, from a separate assessment toolOverdue counts are not comparable, so no site can be ranked against another
Definition of completeField data uploadedReport reviewed and signedRecommendations dispositionedBacklog looks smallest where the bar is lowest, which inverts the management signal
Due date basis for slurry serviceTonnes through the line since last inspectionCalendar monthsCalendar months with ad hoc pull-forwardCalendar-based due dates on hydrotransport are unrelated to the wear that actually happened
None of these conventions is wrong on its own. All of them are defensible locally. The failure is that the corporate roll-up adds them together and presents the sum as a single compliance position.

Five sites, five definitions, one number that means nothing

An oil sands operator does not run a plant, it runs a portfolio: a mine and extraction plant, a froth treatment facility, an upgrader with hydroprocessing and vacuum units, one or more SAGD central processing facilities with once-through steam generators, plus tailings and utilities, often separated by hundreds of kilometres and acquired at different times from different owners. Each arrived with its own inspection practice, its own historical database and its own experienced people who have good reasons for doing it their way.

The trouble appears when the corporate integrity report asks a simple question. How many circuits are overdue across the business? Every site can answer for itself with confidence. The sum of those answers is not a number, because overdue is calculated, not observed, and the calculation differs. One site counts a circuit overdue when the field data has not been collected. Another counts it complete when data is uploaded but the recommendations sit undispositioned. A third does not count risk-based deferrals at all because they are managed in a separate tool.

This is not a reporting problem to be fixed with a better dashboard. Aggregating incompatible calculations produces a figure that is precise, auditable and wrong, and the more polished the presentation the longer it takes anyone to notice. The remedy is to standardise the calculation and let the sites keep their local vocabulary above it.

The interval calculation is the standard; everything else is formatting

When people say they want to standardise inspection across sites, they usually mean forms, templates and naming. Those matter least. What determines a due date is a short chain of arithmetic: measured wall, minimum thickness, corrosion rate, remaining life, interval rule. Standardise that chain and the sites can keep almost every other habit they have. Leave it unstandardised and matching templates produce beautifully consistent documents containing incomparable numbers.

Consider the rate choice alone. API 510 and API 570 contemplate both long-term and short-term corrosion rates, and a programme must state which governs. A site using the long-term rate smooths out a recent acceleration and issues a comfortable date. A site using the short-term rate reacts to the last two surveys, including any measurement scatter. A site taking the greater of the two is conservative and generates work. All three are defensible. Applied across one portfolio without a stated rule, they make the fleet-level backlog uninterpretable and make site comparison meaningless, which in turn makes resourcing decisions arbitrary.

The same applies to the interval rule itself. Half remaining life capped at a code maximum, a fixed cycle aligned to the site shutdown, and a risk-based interval from an assessment are three different answers from the same corrosion data. The scheduling module should hold one configured rule set for the business, with any site-level variation existing as a recorded, approved exception rather than as an undocumented local habit.

Erosion changes the unit of time

Most inspection scheduling assumes damage accumulates with the calendar. In oil sands hydrotransport that assumption is simply false. Slurry lines carrying oil sand and water at high velocity lose wall as a function of tonnage moved, solids loading, particle character and geometry, and the loss concentrates brutally at elbows, tees, spool transitions and downstream of any flow disturbance. Wear is measured in millimetres per month on the worst geometries, and it stops when the line stops.

A calendar due date on such a line inspects the wrong pipe at the wrong time in both directions. A line that ran at reduced rate through a quarter gets inspected as though it had run flat out. A line that ran hard through an unplanned production push gets inspected on the same date as always, after the damage occurred. Operators know this, which is why the discipline in practice runs on spreadsheets kept by a few experienced people who watch throughput and call the inspection when the number looks right. That knowledge does not roll up and it leaves with the person.

A scheduling module that supports duty-based due dates fixes this properly. The due date is expressed in tonnes through the line, operating hours, or another counter fed from the historian, and the calendar date is derived from the current rate rather than fixed. The same mechanism handles rotation strategies for spools and elbow change-outs, where the practical question is not whether an inspection is due but which spool comes out at the next opportunity and what the replacement inventory should be.

Different sites, different mechanisms, same rule set

Standardising the calculation does not mean pretending the assets are alike. The mine and extraction side is dominated by erosion and abrasion, with slurry, froth and tailings service and large amounts of non-pressure equipment. The upgrader is a refinery in all but name, with high total acid number feed driving naphthenic acid corrosion in the vacuum unit, sulfidation of carbon steel piping where silicon content varies spool to spool, ammonium bisulfide corrosion in hydrotreater effluent air coolers, and hydrogen attack considerations in hydroprocessing. SAGD facilities bring once-through steam generator tube damage, produced water treatment, and de-oiling equipment with their own scaling and corrosion behaviour.

These mechanisms determine which methods are credible, which locations matter and how often data is worth collecting. They do not determine the arithmetic of remaining life. That distinction is the design principle: the damage mechanism drives the inspection plan, and the rule set drives the date arithmetic. A system that conflates them ends up with per-site logic that cannot be reconciled, which is exactly the condition the standardisation effort was meant to end.

Sulfidation illustrates why local knowledge must still be captured. Where carbon steel piping was fabricated before silicon content was controlled, individual spools within one circuit can corrode at very different rates, and the recognised practice in API RP 939-C is to treat component-level variability as real rather than averaging it away. That is a plan-level decision about how many condition monitoring locations a circuit needs. The interval arithmetic applied to each of those locations should still be the corporate one.

Winter and the shared turnaround market

Alberta compresses maintenance into narrow seasons. Turnaround work concentrates in spring and autumn, and every operator in the region draws from the same pool of certified technicians, scaffolders, rope access crews and inspection contractors during the same weeks. Within a single company, sites planning independently will bid against each other for the same people, sometimes without knowing it, and will pay for the privilege in schedule risk rather than only in rate.

Levelling requires one calendar and one skill taxonomy. If the mine site records a requirement as ultrasonic technician and the upgrader records phased array Level II with a specific procedure qualification, no system can tell you that one site's shoulder week could cover the other's peak. Standardising the way competency is expressed is unglamorous work that unlocks the only real capacity gain available, which is moving people between sites rather than hiring in a seller's market.

Winter adds its own constraints that belong in the plan rather than in folklore. Couplant behaviour and instrument performance at deep cold, insulation and heat tracing that must be reinstated correctly after removal, scaffold erection times that stretch, and daylight hours that shorten the practical shift for external work. A scheduling module that carries seasonal productivity factors per site produces plans that survive contact with February. One that assumes a uniform hour produces a plan that is quietly forty per cent optimistic for four months of the year.

Deviation as a recorded exception, not a local habit

The goal is not uniformity for its own sake. Sites differ legitimately, and a rigid corporate rule applied without exception will be worked around within a month by people who need to get the job done. The workable arrangement is that the rule set is corporate, deviations are permitted, and every deviation exists as a record with a scope, a reason, an approver and a review date. That way the roll-up can present a clean figure with a stated set of exceptions, rather than a dirty figure presented as clean.

This is also what an owner-user quality management system accepted by ABSA effectively expects. The programme document says how intervals are established and who may change them. A deviation that is written down, approved and reviewed is compliance. The same deviation existing only as local practice is a non-conformance against the operator's own accepted document, and it is a more uncomfortable finding than a technical one because it goes to whether the management system is real.

Practically, the exception register becomes a useful management artefact in its own right. When forty circuits at one site are on an approved deviation from the corporate rate convention, that is a visible fact with an owner and a review date. When the same forty circuits are simply calculated differently by a local spreadsheet, nobody outside that site knows, including the person who signs the integrity report.

Getting from five practices to one without breaking history

The instinct on a standardisation programme is to renumber everything into a clean scheme. Resist it. Condition monitoring location identifiers are painted on pipe, written in old reports, referenced in drawings and known by name to the people who take the readings. A renumbering campaign breaks the link between the new identity and the historical readings, and the usual outcome is that a fifteen-year thickness history splits into two shorter histories that each look reassuringly flat.

The safer route is an identity layer. One canonical location per physical point, with every local alias mapped to it and retained. Field crews keep using the identifiers on the pipe. Reports from contractors keep arriving in the vocabulary they know. The system resolves the alias on submission, and a reading whose alias cannot be resolved is held rather than silently creating a new location, which is the mechanism by which duplicate points appear in every register that has ever been migrated.

Sequence the rest by leverage. Fix the rate convention and the minimum thickness source first, because they change every due date. Fix the definition of complete second, because it changes every backlog number. Introduce duty-based due dates on slurry and froth service third, because that is where the calendar is doing the most damage. Templates, forms and report layouts come last, when they are cosmetic rather than structural. Atlantis will walk an integrity team through that sequencing against their own register as a consulting engagement; the contact is info@atlantisndt.com.

What to test before you commit

Bring three real circuits from three different sites, with their full reading history, and ask the vendor to compute due dates under each site's current convention and then under a single proposed convention. The output should show how many circuits change state and in which direction. Any product that cannot do this is not calculating due dates, it is storing them, and storing them is what the spreadsheets already do.

Then test the duty-based path. Ask for a hydrotransport line with a due date expressed in tonnes, fed by a throughput tag, and see whether the projected calendar date updates as the rate changes. Ask what happens when the historian feed is unavailable for a week. A product that silently falls back to a calendar date without saying so has reintroduced the original problem in a place nobody will look.

Finally, test the exception mechanism. Configure a site deviation from the corporate rule, and check that the roll-up reports the fleet figure and the exception simultaneously rather than burying one in the other. Then ask the vendor to reproduce the fleet overdue number as it stood six months ago. If the system cannot reconstruct a past position, it cannot be used to defend a past decision, and defending past decisions is a substantial part of what an integrity programme is for.

Why do two sites report different overdue counts from the same data?

Because overdue is a calculated state, not a recorded fact, and the calculation has at least four inputs each site sets independently: which corrosion rate governs, where minimum thickness comes from, which interval rule applies, and what counts as complete. Change any one and the due date moves. Two sites with identical equipment, identical readings and identical diligence can differ by years, and neither is making an error against its own procedure.

Should slurry line inspections be scheduled by calendar or by tonnage?

By duty, in almost every case. Hydrotransport, froth and tailings lines wear as a function of throughput, solids content, velocity and slurry character, and a line that ran at half rate for a quarter has not worn like one that ran full. Expressing the due date in tonnes moved or operating hours since last inspection produces a date that tracks the damage. Calendar intervals on these circuits systematically inspect the wrong pipe at the wrong time.

What does an ABSA-accepted owner-user QMS require of a scheduling system?

That the system does what the document says, and can show it. The quality management system describes how inspection intervals are established, who is competent to set and change them, how deviations are approved and how records are retained. A scheduling module is the operational expression of that text. When site practice drifts from the written programme, the non-conformance is against the owner-user's own accepted document, which is the awkward finding to receive.

How do you standardise CML naming across sites without renumbering everything?

You do not renumber. You add a governed identity layer above the local identifiers, so each site keeps the tags painted on its pipe while the system holds one canonical location with the local aliases mapped to it. Renumbering campaigns break the link to fifteen years of history and to field markings, which is how a long thickness record silently splits into two short ones that both look healthy.

Why does the minimum thickness convention change the due date?

Because remaining life is measured from wherever you place the floor. Structural minimum thickness, design minimum from the original code calculation and nominal less a fixed corrosion allowance can differ by more than a millimetre on the same spool. On a circuit corroding slowly, that difference is years of interval. On a slurry line losing wall quickly, it is the difference between a planned change-out and an unplanned one.

How do multiple oil sands sites share the same turnaround labour pool?

Badly, unless someone levels it. Alberta's turnaround season concentrates demand into narrow spring and autumn periods, and every operator draws on the same certified technicians, scaffolders and rope access crews. Sites planning independently bid against each other for the same people, at the same weeks, sometimes inside the same company. One calendar with one skill taxonomy is the precondition for moving a crew from one site's shoulder week to another's peak.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.