One inspection calendar for every refinery in the network
Scheduling across a refining network fails on definitions before it fails on software. One site counts a circuit as one due item, another counts every condition monitoring location; one closes an inspection when readings are taken, another when the deficiency is dispositioned. A shared calendar has to fix those definitions first, then model scaffold, insulation, entry permits and turnaround gates as real constraints.
In a refinery the inspection itself is rarely the long pole. Scaffold erection, insulation removal and reinstatement, confined space entry under 29 CFR 1910.146, hot work permits and lockout under 1910.147 consume most of the elapsed time, and a stainless austenitic system in sulphur service cannot be opened for internal inspection until it has been neutralised and purged against polythionic acid stress corrosion cracking, which places the work in a fixed position within the shutdown sequence rather than on a date the planner chooses. Meanwhile mechanical integrity frequencies under 29 CFR 1910.119(j) must follow recognised and generally accepted good engineering practice, and if three sites cite different practices for the same equipment class, the inconsistency itself becomes the finding. A network calendar has to hold the due date, the access path that makes the date reachable, and the justification for the frequency, in one place, for every site.
Source: Sources: OSHA 29 CFR 1910.119 (Process Safety Management of Highly Hazardous Chemicals), 29 CFR 1910.146 (Permit-Required Confined Spaces), 29 CFR 1910.147 (The Control of Hazardous Energy); API 510, API 570, API 653, API 571 (Damage Mechanisms Affecting Fixed Equipment in the Refining Industry), API 572, API 573, API 574, API 576 (Inspection of Pressure-Relieving Devices), API 580 and API 581 (Risk-Based Inspection), API 583 (Corrosion Under Insulation), API 941 (Steels for Hydrogen Service, Nelson curves), API 579-1/ASME FFS-1 (Fitness-For-Service); ASME Boiler and Pressure Vessel Code Sections V and VIII; NACE/AMPP SP0170 on protection of austenitic stainless steels during shutdown.
| Scheduling element | Typical divergence between sites | Common definition that makes it comparable | Refining constraint behind it |
|---|---|---|---|
| The unit of work | One site schedules by circuit, another by individual CML | Schedule at circuit level, roll CMLs up as scope within the circuit | A circuit is what a scaffold and an isolation serve; a CML is not independently accessible |
| Completion | Readings taken, report issued, or deficiency dispositioned | Completion is report issued and accepted; deficiency closure tracked as a separate clock | API 510 and 570 intervals run from inspection; PSM deficiency correction is a separate obligation |
| Overdue | Measured at month end at one site, at report approval at another | Overdue measured daily against the assigned due date plus any documented deferral | A monthly snapshot hides items that went overdue and were closed inside the month |
| Criticality | Local three-tier scale versus a five-tier RBI ranking | One network criticality mapped from the RBI output where RBI exists | API 580/581 outputs are not interchangeable with a locally invented A/B/C scale |
| Access cost | Scaffold booked as a separate work order or buried in the inspection cost | Access modelled as its own schedulable resource linked to the inspections it serves | Scaffold and insulation frequently exceed the inspection labour they enable |
| Deferral | Verbal approval by the local inspector at one site, MOC at another | A single deferral workflow with a defined approval authority and a technical basis | Extending an interval beyond code is an engineering decision, not a planning one |
Sites diverge under a single corporate procedure
Every multi-site refiner has a corporate mechanical integrity procedure, and every one of them has sites that execute it differently. This is not usually indiscipline. It is the accumulated result of different unit configurations, different histories, different regulators, different contractor markets and, most often, different people solving the same problem independently over fifteen years. One site built its programme around a legacy inspection database and thinks in circuits. Another grew out of a turnaround planning group and thinks in work orders. A third was acquired and still carries the previous owner's criticality scale.
The divergence is invisible while each site reports on itself. It becomes acute the moment a corporate integrity function asks for a network view, because the metrics arrive in incompatible units and the natural response is to normalise them in a spreadsheet. That spreadsheet becomes the corporate number, it is rebuilt monthly by whoever is available, and nobody can explain in a review why a site's compliance moved four points.
The instinct at that point is to buy a system and impose it. That usually fails, because the divergence being solved is definitional rather than technical, and a new system with the old definitions produces the same incomparable numbers faster. The sequence that works is the reverse: agree the definitions that must be common, agree explicitly what stays local, then implement.
The denominators that stop the numbers rolling up
Start with the unit of work. If site A schedules an inspection per piping circuit and site B schedules one per condition monitoring location, a circuit with forty CMLs is one item at A and forty at B. Both sites can be at ninety per cent complete and be doing wildly different amounts of work. The physically defensible unit is the circuit, because a circuit is what an isolation, a scaffold and an insulation removal actually serve. CMLs are scope within that item, not independent items.
Then completion. Three definitions circulate in every refiner: readings taken, report issued, and deficiency dispositioned. They can be months apart. Under API 510 and 570 the interval clock runs from the inspection, so completion for interval purposes has to be tied to the inspection and its accepted report. Deficiency correction is a separate and equally important obligation under the process safety mechanical integrity provisions, and it needs its own clock rather than being folded into the completion percentage where it distorts both numbers.
Then overdue. Measuring overdue at month end rather than daily hides every item that went past due and was closed within the same month, which is precisely the population most worth seeing. And finally criticality: a locally invented A/B/C scale cannot be mapped onto an API 580/581 risk ranking by assertion. Where risk-based inspection exists, the network scale should derive from its output; where it does not, the site should say so rather than supply a number that looks like the others.
The calendar has to schedule access, not just inspections
The cost and duration of a refinery inspection are usually dominated by everything that is not the inspection. Erecting scaffold to reach a vessel nozzle, stripping and reinstating insulation on a hot line, permitting a confined space entry under 29 CFR 1910.146 with attendant and atmospheric monitoring, isolating and locking out under 1910.147 — these consume the schedule. The ultrasonic technician's time on the item can be minutes.
This inverts the design of the calendar. Scheduling inspections and treating access as an administrative consequence produces a plan that is unbuildable and a scaffold bill that dwarfs the inspection budget. Scheduling access as a resource, and bundling every inspection that shares that access into one campaign, is where the recoverable cost lives. It also changes the scheduling question from 'when is this CML due' to 'what else should we look at while this scaffold is standing', which is a question a planner can only answer if every due date within reach of that access point is visible at once.
Corrosion under insulation makes this concrete. API 583 addresses inspection of insulated systems, where the damage is hidden and the inspection requires the same insulation removal whichever technique is used. The economics of a CUI programme are almost entirely an access-planning problem, and a scheduling engine that cannot group by access point cannot support one.
Unit damage mechanisms decide what can be scheduled at all
A refinery is not one plant with one damage profile. It is a dozen units with distinct mechanisms, and those mechanisms determine whether an item can be inspected on-stream or only during a shutdown. Sulphidation in crude and vacuum heater transfer lines is a thinning mechanism, amenable to external thickness survey while running. High temperature hydrogen attack in hydroprocessing, assessed against the Nelson curves in API 941, is a subsurface material degradation that requires specialised techniques and a very different inspection plan. Ammonium bisulphide corrosion in a hydrotreater reactor effluent air cooler is velocity and concentration dependent, localised, and often only accessible internally.
Naphthenic acid corrosion in high-TAN crude service is velocity-dependent and concentrates in specific geometries — elbows, reducers, downstream of control valves — so the inspection plan is geometry-driven rather than uniform. Wet hydrogen sulphide cracking in amine and sour water systems is a cracking mechanism requiring different methods and, frequently, internal access. Creep in fired heater tubes brings its own techniques and its own inspection cycle tied to the heater's own outage rather than the unit turnaround.
The scheduling consequence is that 'due' does not mean 'schedulable'. An item whose mechanism can only be assessed internally is constrained to a shutdown window, and its due date has to be reconciled against a turnaround cycle that may be four to six years long. This is the mechanism by which deferrals get created, and a calendar that does not distinguish on-stream-capable from shutdown-only items will generate a plan that quietly assumes the impossible.
Turnaround gates and the price of discovery scope
Refining turnarounds run to a gated schedule, and the gate that matters for inspection is scope freeze, typically set many months ahead of execution. After the freeze, adding scope is expensive: materials are not procured, contractor manning is set, the critical path is built, and late additions land as discovery work at premium rates and premium schedule risk. Everyone in a refinery knows this. What is surprisingly hard is answering, on the freeze date, which inspection items will become due before the following turnaround.
That question requires a forward projection across every clock at the site — vessel internal intervals under API 510, piping thickness intervals under API 570, tank internal intervals under API 653, pressure-relieving device test intervals under API 576 and the site's own practice, heater tube cycles, and any risk-based intervals with their own expiry. It is a projection, not a status report, and it has to include items that are currently comfortably in date but will not be by the time the next window comes round.
Sites that build this projection by hand build it inconsistently, which is one of the clearest expressions of the standardisation problem. One site projects to the next turnaround, another to the next plus a margin, a third only to the end of the fiscal year. The result is that some sites systematically carry more discovery scope than others, and the corporate view cannot see why. A shared engine that runs the same projection at every site with the same horizon turns that into a comparable, reviewable number.
Deferrals, management of change, and what counts as good practice
Not every due date can be met, and pretending otherwise is what produces informal deferrals. The mechanical integrity provisions under 29 CFR 1910.119(j) require inspections and tests at a frequency consistent with manufacturer recommendations and good engineering practice, and require that equipment deficiencies be corrected before further use or that necessary means be taken to assure safe operation. Extending an interval is therefore an engineering decision with a documented basis — a fitness-for-service assessment under API 579-1/ASME FFS-1, a risk assessment under API 580/581, or a documented evaluation by the responsible engineer — not a planning convenience.
The recurring compliance exposure across a network is not that deferrals happen. It is that they happen differently. One site routes them through management of change with engineering approval. Another handles them by verbal agreement between the inspector and the unit engineer. A third does not record them at all, so items simply appear as overdue on a report and are closed retrospectively. All three sites believe they are compliant. Only one can demonstrate it.
There is a second dimension an auditor will probe. OSHA assesses mechanical integrity frequency against recognised and generally accepted good engineering practice, and if sites within one company cite different practices for identical equipment in identical service, the inconsistency invites the question of which one is right. Recording the basis for each frequency, and being able to show it is the same across the network for the same equipment class, closes that line of enquiry before it opens.
Standardising the definitions without flattening the sites
The standardisation that succeeds is narrow and deep. Make common the things that make numbers comparable: asset and circuit identification, criticality derivation, due-date rules and their basis, the completion definition, the overdue definition, the deferral workflow with its approval authority, and the forward projection horizon. Leave local the things that depend on local reality: crew assignment, daily sequencing, permit coordination, contractor call-off, scaffold vendors and the order in which a site works its units during a shutdown.
This division is not a compromise, it is the correct architecture. A corporate integrity function needs comparable numbers and consistent justification. It does not need to know which contractor is on which scaffold on Tuesday, and any attempt to centralise that will be routed around within a quarter by sites keeping their own real schedule in a spreadsheet — which reproduces the original problem with an expensive system on top of it.
Evaluate a scheduling engine against this division explicitly. Ask whether due-date rules are held centrally and versioned while execution stays local. Ask it to produce, for a chosen site, the list of items becoming due before the end of the next turnaround cycle. Ask how a scaffold or insulation-removal event is represented and whether inspections can be bundled to it. Ask how a deferral is created, who can approve it, what basis is compulsory, and whether it is visible on the corporate roll-up. Then ask for the same outputs from a second site and compare them line for line. To run that comparison against your own sites' data, request a working session at info@atlantisndt.com.
Why do site completion percentages disagree when every site uses the same procedure?
Because the procedure specifies what to inspect, not what to count. If one site's denominator is circuits and another's is condition monitoring locations, the same physical work produces completion figures that differ by an order of magnitude. Add a different closure definition — readings taken versus report accepted — and the numerator moves too. Standardising the procedure without standardising the counting rule produces the exact situation people describe as the numbers not rolling up.
How should scaffold and insulation work appear on the inspection calendar?
As first-class schedulable resources with their own lead times, not as a note on the inspection. In most refineries the access work costs more and takes longer than the NDT it enables, and it is the constraint that determines whether a date is achievable. Modelling it explicitly also enables campaign bundling: grouping inspections that share a scaffold or an insulation removal into one access event, which is the single largest recoverable cost in most on-stream programmes.
What does a turnaround scope freeze date require from the scheduling engine?
The ability to answer one question on the freeze date: which items will become due between now and the end of the following turnaround cycle, and therefore must be in scope now or carry a documented deferral. That is a forward projection across every clock at the site, not a list of what is currently overdue. An engine that can only report present status forces the scope team to build the projection manually, which is where items get missed and reappear as discovery work.
How are interval deferrals handled consistently across sites?
Through one workflow with a defined approval authority matrix and a compulsory technical basis — a fitness-for-service assessment under API 579-1/ASME FFS-1, a risk assessment, or a documented engineering evaluation. The failure pattern is deferral by absence: an item passes its due date, nobody records a decision, and the deferral becomes visible only when someone runs an overdue report. Making deferral an explicit, approved, dated object converts a compliance exposure into a managed one.
Which scheduling decisions should stay local to a site?
Crew assignment, daily sequencing, permit coordination and contractor call-off all belong to the site, because they depend on local labour, local access and local operations. What must be common is the definition layer: asset and circuit identification, criticality mapping, due-date derivation, completion and overdue definitions, and the deferral workflow. Centralising execution produces resistance and workarounds; centralising definitions produces comparable numbers without touching how a site runs its day.
How does the calendar handle inspections that can only happen at a point in the shutdown sequence?
By modelling them as sequence-dependent rather than date-dependent. Austenitic stainless equipment in sulphur service must be neutralised and protected before opening to avoid polythionic acid stress corrosion cracking, which fixes the inspection after specific operations steps. Similarly, entry cannot precede purge and gas test, and hot work cannot precede isolation. A calendar that holds only dates will schedule these correctly by luck; one that holds predecessors will schedule them correctly by construction.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.