Migrating Off a Legacy IDMS Without Corrupting Your Turnaround Calendar

In a petrochemical unit, inspection scheduling is really turnaround planning. Most vessel internals, furnace tube sampling and exchanger bundle work can only happen inside a shutdown window that comes around every four to six years, so the plant runs two clocks at once: on-stream due dates and the turnaround work list. A scheduling module has to reconcile them, and a migration has to preserve the arithmetic that sets them.

The complication is that a petrochemical due date is not a date the software owns - it is a calculation. Under API 510 the next internal inspection falls at the lesser of one-half remaining life or ten years, and remaining life is (t actual minus t required) divided by a corrosion rate that itself depends on the first thickness reading ever taken at that CML. Migrate the readings without the nominal thickness, the required minimum, the CML identity and the true reading dates, and the long-term corrosion rate collapses into the short-term rate. Every interval derived from it moves, usually outward, and the schedule looks healthier than the plant is. On a unit that opens once every five years, an interval that drifts eight months past the turnaround is not an eight-month problem - it is a five-year problem, closed only by a fitness-for-service assessment or an interval extension you have to justify in writing.

Source: Written against API 510 (Pressure Vessel Inspection Code), API 570 (Piping Inspection Code), API 571 (Damage Mechanisms Affecting Fixed Equipment), API 579-1/ASME FFS-1 (Fitness-For-Service), API 580 and 581 (Risk-Based Inspection), API 941 (steels for hydrogen service), AMPP/NACE SP0170 (protection of austenitic stainless steels during shutdown), ASME Boiler and Pressure Vessel Code Sections V and VIII, ASNT SNT-TC-1A, and OSHA 29 CFR 1910.119.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What a legacy record has to carry across for a petrochemical due date to survive the migration
Legacy fieldWhy the due date depends on itWhat happens if it is dropped or mangled
CML / TML identity and its position on the drawingLong-term corrosion rate is computed from readings taken at the same physical point over timeTwo decades of readings become an unrelated pile; long-term rate defaults to the short-term rate from the last two surveys
Original nominal thickness and the date of the first readingNumerator and start of the clock in the long-term rate formula in API 570 7.1.1Long-term rate cannot be computed at all, so the more volatile short-term rate silently sets every interval
Required minimum thickness and its basis (design calculation, structural minimum, or code case)Remaining life is (t actual - t required) / corrosion rate; the basis decides which t required appliesRemaining life is computed against the wrong floor - typically the structural minimum, which is optimistic for pressure retention
Reading date versus report issue dateIntervals in API 510 and API 570 run from when the examination was performedEvery interval shifts by the report lag, commonly four to ten weeks, and a task that belonged in the last turnaround now looks compliant
Damage mechanism assignment per API 571 and the credited inspection methodDetermines whether the task is on-stream capable or shutdown-only, and whether UT is even a valid detection methodHTHA, creep and cracking mechanisms get scheduled as thickness surveys and are never actually looked for
Interval basis: prescriptive, RBI per API 580/581, or an owner-user justified extensionSets whether the ten-year cap or an RBI-derived interval governsRBI-derived intervals are re-imposed as prescriptive dates, mass-shifting thousands of tasks into the next turnaround
Field names differ between legacy systems; the test is whether the destination can reproduce the old due date from the migrated data before you cut over.

A petrochemical plant runs two calendars, and only one of them is yours

The on-stream calendar is dense and unglamorous. External visual inspection of pressure vessels at intervals not exceeding five years under API 510, thickness measurement on Class 1 piping circuits at intervals not exceeding five years under API 570, injection point circuits on a much shorter cycle - not exceeding three years or half the remaining life, whichever is less - corrosion under insulation surveys targeted at the temperature bands where water sits, infrared on furnace casings and refractory, and pressure relief device testing. All of it happens while the unit makes product, which means it competes with operations for access, permits, scaffold and manpower every single week.

The shutdown calendar is sparse and brutal. Once every four to six years the unit comes down and the entire backlog of internal work lands inside a window measured in weeks: vessel entries, tray and internals inspection, exchanger bundle pulls and eddy current tube testing, cracking furnace tube sampling and replacement, and the repairs that come out of all of it. The window is fully subscribed before inspection asks for anything. Every hour of critical-path inspection has to be argued for against mechanical, and the argument is only winnable with a defensible due date behind it.

A scheduling module that models only one of these calendars is useless in this industry. What it has to do is hold a due date and an execution constraint as two separate facts, then show you where they collide - which tasks are due before the next shutdown and cannot be done before it, which can be converted to an on-stream method, and which are going to need a documented interval extension. That collision report is the actual deliverable. Everything else is a work order list.

The damage mechanism decides which calendar a task belongs to

Thickness loss is the easy case, and it is the case every generic maintenance system is built for. Petrochemical service is full of mechanisms that thickness measurement cannot see. High temperature hydrogen attack, governed by the Nelson curves in API 941, produces fissuring and decarburisation with no wall loss until very late; detecting it means advanced ultrasonic backscatter or TOFD on a targeted set of welds, planned as a campaign, not as a survey. Creep and carburisation in cracking furnace tubes are assessed by diameter growth, replication and sampling, and they are shutdown-only by definition.

Environmental cracking changes the shape of the schedule again. Chloride stress corrosion cracking of austenitic stainless under wet insulation, caustic cracking in adjacent utility systems, amine cracking in treating loops - each has its own detection method, its own susceptible temperature and concentration window, and its own trigger conditions. API 571 is the reference that maps service to mechanism, and the assignment has to travel with the asset record, because it determines whether an inspection task is credible at all. A UT thickness grid scheduled against a cracking mechanism is a compliance record of an examination that could not have found the damage.

There is also the category where the inspection itself introduces the hazard. Sensitised austenitic stainless steel that has run in sulphidic service will crack from polythionic acid once oxygen and moisture reach it during shutdown. AMPP/NACE SP0170 exists precisely for this, and the neutralisation wash or nitrogen purge that prevents it is a predecessor to every entry on that circuit. In a scheduling module that means a real dependency with a crew, a duration and a chemical, sequenced ahead of the inspection - not a warning buried in a procedure attachment.

What a legacy IDMS actually loses on the way out

Extracts from an ageing inspection data management system come out cleaner than they are. Thickness readings export readily, because they are numbers in a column. What does not export readily is everything that makes those numbers mean something: which physical point the reading came from, what the nominal wall was, what minimum thickness the equipment is being judged against and on what basis, when the examination was actually performed as opposed to when the report was issued, who performed it and under what certification, and which damage mechanism the reading was supposed to be watching. Those fields are frequently in free text, in a scanned attachment, or in the head of an inspector who retired.

Unit handling is the quiet destroyer. Legacy datasets accumulate mixed inches, mils and millimetres, sometimes within a single circuit, because two contractors reported differently in 2011 and someone normalised the display without normalising the store. A silent conversion error of 25.4 does not produce an obvious wrong answer; it produces a corrosion rate that looks plausible and a remaining life that is off by more than an order of magnitude. The only defence is a reconciliation pass that recomputes every remaining life in the destination and diffs it against the legacy value, asset by asset, before cutover.

Then there is the repair history. A vessel that was weld overlaid in 2014, or a piping spool replaced under an approved repair procedure, has a step change in its thickness record. If the migration imports readings as a continuous series without the repair event, the software sees wall thickness increasing, computes a negative corrosion rate, and either errors out or, worse, clamps the rate to zero and reports infinite remaining life. Repair, alteration and re-rating events are not history; they are boundary conditions on the calculation.

The arithmetic trap hiding inside a migrated corrosion rate

API 570 defines two rates for a reason. The long-term rate uses the original or earliest reading and spans the full service history; the short-term rate uses the previous reading and spans one interval. The code direction is to compare them and apply judgement, ordinarily using the one that produces the shorter remaining life, and to investigate when they diverge - divergence is usually a signal that process conditions changed, not that the metal changed its mind. A migration that carries only the two most recent readings can compute only the short-term rate. It has structurally lost the ability to do the comparison the code asks for.

The effect propagates into the interval, and it propagates in the dangerous direction. Suppose a circuit has a genuine long-term rate of 8 mils per year and a short-term rate of 3 mils per year because the last campaign ran a cleaner feed. With 200 mils above the required minimum, remaining life is 25 years on the long-term rate and 67 years on the short-term. API 510 caps the interval at the lesser of half remaining life or ten years, so both hit the ten-year cap - and the schedule looks identical. Three surveys later, after a feed change puts the rate back where it was, the plant is working from a baseline that no longer contains the evidence of the higher rate.

There is a second, subtler trap in how a CML is summarised. Some legacy systems store the average of the readings in a grid; some store the minimum; some store both and display whichever the report template asked for. Remaining life must be computed on the governing thickness, and if the migration maps an averaged value into a field the new system treats as minimum, every remaining life on the site is optimistic by whatever the scatter happens to be. Ask the vendor to state, in writing, which value drives the calculation and how it handles a grid where one point is an outlier.

Scheduling against a turnaround date that has not been fixed yet

The next shutdown date is a business decision, not an engineering one, and it moves. Margins, feedstock contracts, a sister plant's outage, catalyst life and a licensor's recommendation all pull on it, and a six-month shift eighteen months out is unremarkable. Every task placed relative to that shutdown has to move with it. If the schedule stores absolute dates for shutdown work, a slip means a manual re-plan of hundreds or thousands of records, done under time pressure, and the errors introduced there are exactly the ones nobody catches until an auditor samples them.

The right structure is a dependency: shutdown work is scheduled against a named event, and the event carries the date. Move the event, and the work list moves as one object. That also gives you the freeze date - the point past which nothing new enters the work list without a change control - which is the single most useful control in turnaround inspection planning. Everything discovered after the freeze either goes into the discovery budget or waits for the next window, and having that boundary in the system rather than in a project manager's spreadsheet is what makes the decision reviewable afterwards.

Access predecessors deserve the same treatment. Scaffold erection, insulation removal and reinstatement, blinding, cleaning and gas freeing, and confined space permitting each consume days and crews, and they are shared across dozens of inspection tasks. A module that treats scaffold as a resource with a lead time will show you that seventeen thickness surveys share one scaffold and should be sequenced together. A module that treats it as a checkbox will let you plan the same scaffold three times and then wonder why the critical path slipped.

How to evaluate a scheduling module while the migration is still running

The only evaluation that matters is a replay. Take twenty assets that span your worst cases - a circuit with thirty years of readings, one that was weld overlaid, one on an RBI-derived interval, one with an injection point, one where the units changed contractors mid-history - and ask the vendor to load them and reproduce the current due date and remaining life from your legacy system. Not approximately. Exactly, or with a written explanation of every difference. A vendor who cannot do this on twenty assets will not do it on four thousand.

Then test the failure paths deliberately. Feed in a reading that implies negative corrosion without a repair record and see whether the system flags it or swallows it. Feed in a reading dated after the report issue date. Feed in a CML with a single reading and ask what long-term rate it computes. Ask it to show every asset whose interval basis changed as a result of the import, with the before and after. If the answer to any of these is a silent default, you have found where your future audit finding lives.

Finally, insist on running parallel for at least one inspection cycle. Keep the legacy system read-only as the record of truth while the new module produces the schedule, and reconcile monthly. It is slower and it is worth it, because the alternative is discovering the discrepancy during a turnaround when the vessel is open and the decision window is hours. Atlantis builds inspection scheduling on Odoo so the same records carry the crew, the certification, the equipment calibration and the work order, and the migration is scoped as a defined project with a reconciliation deliverable rather than a file drop. Request a consultation at info@atlantisndt.com.

Why can a petrochemical schedule not just use calendar recurrence?

Because the unit does not open on a calendar. An ethylene plant or a polymer train may run four to six years between shutdowns, and vessel internals, tray inspections, exchanger bundle pulls and furnace tube sampling are physically impossible while it runs. Calendar recurrence generates a due date that nobody can execute, then an overdue flag nobody can clear. The schedule has to model the shutdown as the constraint and place tasks relative to it.

What is the single most damaging thing a migration gets wrong?

Losing CML identity. If the destination cannot prove that the reading taken in 2009 and the reading taken last quarter came from the same physical point on the same circuit, it cannot compute a long-term corrosion rate. It falls back to the short-term rate from the two most recent surveys, which is noisy, sensitive to probe placement and operator, and usually lower. Intervals extend, and the extension is invisible.

How should tasks that fall due between turnarounds be handled?

Three legitimate routes exist and the system should record which one was used. Pull the task forward into the current shutdown; convert it to an on-stream method that credibly detects the governing damage mechanism; or extend the interval on a documented basis, typically a fitness-for-service assessment under API 579-1/ASME FFS-1 or a risk assessment under API 580. The fourth route - letting it drift - is what audits find.

Does risk-based inspection make the migration easier or harder?

Harder, and worth doing anyway. An RBI-derived interval carries a probability and consequence assessment behind it, an assumed inspection effectiveness, and a reassessment date for the analysis itself. If the migration imports only the resulting date, you inherit the number without its justification, and at the next reassessment nobody can reconstruct why the interval was set where it was. Import the assessment inputs or plan to redo the analysis.

What does the module have to know about shutdown-specific damage mechanisms?

That some inspection work creates hazard rather than only finding it. Sensitised austenitic stainless steel in sulphidic service is vulnerable to polythionic acid stress corrosion cracking once air and moisture reach it, which is why AMPP/NACE SP0170 neutralisation or nitrogen blanketing has to precede opening. The scheduler needs those as predecessor tasks with their own crews and durations, not as a note in a procedure nobody reads on shutdown day.

Is API 510, 570 or 653 inspector training part of this offer?

No. Those are American Petroleum Institute certifications, examined and issued by API through its Individual Certification Programs, and Atlantis has no role in them. Atlantis does provide NDT method training to ASNT SNT-TC-1A and ISO 9712 - Level I, II and III in UT, RT, MT, PT, ET, VT, PAUT and TOFD - along with ASNT Level III consulting, written practice development and report validation. Those are different qualifications serving different roles.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.