Proving every LNG inspection date, on the day the auditor asks for it
In LNG the auditor is not checking the date, they are checking its basis. An interval engine derives each due date from a stated rule — API 510 or 570 remaining life, a cycle count, or a fixed code maximum where cryogenic service makes corrosion rate meaningless — and stores the inputs, the approver and the rule version, so the record reconstructs itself under questioning.
An LNG facility fails audits on documentation long before it fails on metal. The findings that recur are procedural: an interval extended without a recorded technical basis, a deficiency identified and not tracked to correction, an inspection performed to a superseded procedure, and a due date whose derivation nobody present can explain. None of those are engineering failures. They are failures of the record. The complication specific to LNG is that most of the plant does not corrode in any measurable way. Wall loss on a cryogenic line in continuous service is effectively zero, so the remaining-life formula that anchors API 510 and 570 intervals divides by nothing. A spreadsheet returns an error, a planner types a number, and that typed number is now the only basis on file. The interval engine has to make the correct answer — a code-maximum default under a stated rule — the easiest one, and record it as a rule rather than as a keystroke.
Source: Governed by 49 CFR Part 193 for US LNG facility siting, design and operations, which incorporates NFPA 59A; 33 CFR Part 127 for waterfront LNG facilities; OSHA 29 CFR 1910.119 for process safety management, including the mechanical integrity and compliance audit elements; API 620 Annex Q and API 625 for refrigerated storage tank systems, with EEMUA 147 for in-service inspection guidance; API 510 and API 570 for ambient-service vessels and piping; and API 571 for damage mechanism identification.
| Audit question | Weak record | Record the engine must hold |
|---|---|---|
| Why is this interval ten years? | "That's what the code allows" | The rule applied, the mechanism assessment behind it, the version of the rule in force, and the approver |
| Why is remaining life blank? | A spreadsheet error, then a typed date | An explicit no-credible-thinning determination, the code maximum applied as default, and the review date for that determination |
| Who extended this by twelve months? | An email thread | A deferral record with requester, technical justification, approver, expiry date and the mitigations imposed |
| Was this done to the current procedure? | The report PDF names a procedure | The procedure revision in force on the inspection date, linked to the result and to the technician's qualification at that date |
| Was the deficiency corrected? | A punch item on a closed list | A tracked deficiency with the interim measure, the corrective action, the completion evidence and the date |
| What did the plan look like last year? | Overwritten | The plan as of any past date, reconstructable from versioned data and rules |
The auditor is testing the basis, not the date
Everyone preparing for an audit optimises the wrong thing. Effort goes into making sure nothing is overdue, because overdue items are visible and embarrassing. But a plan with nothing overdue and no derivation behind it is weaker than a plan with three tracked exceptions and a defensible method. Auditors know that a clean date column is easy to produce and tells them almost nothing about whether the programme is real.
The line of questioning is predictable because it is the same everywhere. Pick an asset. What is its next inspection date. How was that date arrived at. Show me the previous inspection that fed it. Show me the procedure that was in force when that inspection was done, and the qualification of the person who performed it. Show me the finding that was raised and what happened to it. Each question moves one step further from the date and one step deeper into the record, and the programme fails at whichever step the evidence stops.
This is why the interval engine matters more in LNG than the raw calculation would suggest. The calculation is often trivially simple. The chain of custody around it is not, and that chain is what is under examination. A system that derives dates but cannot show the derivation has automated the part that was never the problem.
Why the corrosion-rate model does not describe an LNG plant
The remaining-life logic in API 510 and API 570 assumes a wall that is thinning at a rate you can measure and extrapolate. That assumption holds in a crude unit and does not hold across most of an LNG train. Below the freezing point of water there is no electrolyte and no aqueous corrosion; a nine percent nickel inner tank, a cold box, a main cryogenic heat exchanger and the lines in continuous cold service simply do not lose metal in any way that thickness monitoring will resolve.
What happens next in a spreadsheet is entirely mechanical. Current thickness minus t-min divided by a corrosion rate of zero returns a division error. The planner cannot leave an error in a plan, so they type a date, usually ten years out, because that is roughly what the code caps at anyway. The date they typed is probably correct. The problem is that the only thing on file is the keystroke, and under questioning nobody can distinguish it from a guess.
The engine's job is to make the honest version of that answer the default. Where no credible thinning mechanism is active, the asset carries an explicit determination to that effect, with a named basis and a review date, and the interval defaults to the code maximum under a stated rule. The date is identical. The difference is that it now has a derivation, and the derivation is what the auditor asked for.
The storage tank is not an API 653 tank
This is the single most common technical documentation error in LNG integrity records, and it is introduced by software as often as by people. Inspection management systems are overwhelmingly built for refineries and terminals, where every tank is an API 650 tank inspected under API 653. Load a refrigerated LNG tank into such a system and it will happily accept it, apply API 653 external and internal interval logic, and produce a plausible schedule with a completely wrong basis.
A full-containment or double-containment LNG tank is a different object. It is a system of an inner tank in nine percent nickel or austenitic stainless, an outer concrete or steel containment, a suspended deck, perlite insulation, a bottom heating system and a foundation, designed under API 620 Annex Q or specified as a system under API 625. It is not opened on a routine cycle; a decade-plus of continuous service is normal, and taking one out of service is a project measured in months, not a scheduled internal inspection.
That reality has to be modelled, not worked around. The interval regime is built from continuous and periodic external evidence: settlement surveys, annular space and vapour barrier condition, bottom heating system performance, boil-off rate trending, insulation integrity, and instrumentation on the tank itself. Out-of-service windows are planned events constrained by the facility's commercial calendar, and the system must let a long-cycle asset live in the plan with the correct basis rather than being forced into a tank template it does not belong to.
Where the damage actually is
Because the cold core is stable, an LNG integrity programme spends most of its attention on the parts of the plant that are ambient, intermittent or cycling. Corrosion under insulation is the dominant thickness-loss mechanism, and it concentrates exactly where the vapour barrier is penetrated: at supports, hangers, nozzles, valve boxes and instrument tapping points, where moisture enters, cycles through the temperature band that supports corrosion, and cannot escape. It is invisible from outside and it is not found by a routine external visual.
Austenitic stainless steel in intermittent or ambient service is exposed to chloride stress corrosion cracking under insulation, which produces cracking rather than thinning and therefore does not register on any thickness trend at all. Aluminium brazed plate-fin exchangers in the cold box are vulnerable to mercury attack if the mercury guard bed is not performing, a mechanism with essentially no warning in wall thickness data. Boil-off gas compressor discharge piping and its small-bore connections accumulate vibration-induced fatigue, where the relevant counter is cycles and excitation, not corrosion.
An interval engine that only knows how to divide thickness by rate has nothing to say about any of these. What it needs is the ability to carry a damage mechanism per asset or per circuit, and to select the interval basis from that mechanism: thickness-driven where thinning is credible, cycle-driven where fatigue governs, condition-driven where a coating or insulation system is the barrier, and code-maximum where no mechanism is active. The mechanism assessment then becomes the thing that gets reviewed and re-approved, which is the correct place for the engineering judgement to sit.
PSM, 49 CFR 193 and what "good engineering practice" obliges you to show
A US LNG facility sits under several overlapping regimes and each of them asks for the same evidence in a different vocabulary. PHMSA regulates siting, design and operations under 49 CFR Part 193, which incorporates NFPA 59A. Waterfront facilities handling LNG add 33 CFR Part 127 and Coast Guard oversight. Over the top of both, the process is covered by OSHA process safety management under 29 CFR 1910.119, and it is the mechanical integrity element there that governs inspection frequency directly.
The mechanical integrity requirement is deliberately non-prescriptive. It asks for inspection and testing that follows recognised and generally accepted good engineering practice, at a frequency consistent with manufacturer recommendations and operating experience, with each inspection documented and each deficiency corrected before further use unless the safety of continued operation is assured. Note what is being demanded: not a specific interval, but a written and defensible reason for the interval you chose, and a closed loop on everything you found.
This is why the deficiency loop belongs inside the same system as the interval. In practice, findings drift out of the integrity record and into maintenance work management, where they lose their link to the asset and the mechanism that produced them. The auditor then finds an inspection report identifying a coating breach on an insulated line, and no evidence that anything followed. The interval was fine. The programme still fails, because the correction of the finding is an explicit regulatory requirement and the evidence for it does not exist in a retrievable form.
Deferrals and extensions, the finding that recurs
Every operating facility defers inspections. Turnaround scope gets cut, a crew is unavailable, an outage window slips, a unit cannot be isolated. Deferral is not itself a finding. Undocumented deferral is, and so is deferral that quietly becomes permanent because the mechanism used to record it was simply editing the date.
The distinction an auditor draws is between a decision and a change. A decision has an author with the authority to make it, a stated technical justification that names what risk is being accepted and against which mechanism, a bounded duration, and any compensating measures imposed in the meantime. A change is a new number in a cell. The first survives scrutiny. The second reads as a programme in which dates are advisory, and it invites the auditor to sample much more widely than they otherwise would.
The engine should therefore treat a deferral as a first-class object with an expiry, keep the originally derived date visible alongside it, and escalate automatically when the expiry passes. It should also make the aggregate visible: how many assets are currently running on deferral, for how long, and approved by whom. That number is one of the most useful internal health indicators a facility has, and in a spreadsheet-based programme it is usually unknowable.
Building the audit packet before anyone asks for it
The most useful thing an interval engine can do in an LNG facility is produce, per asset, the complete evidence chain on demand: the current interval and its basis, the mechanism assessment behind that basis, every inspection that fed it with the procedure revision and technician qualification in force on each date, every finding raised with its correction and completion evidence, and every deferral or extension with its approvals. Assembled by hand from a shared drive, that packet takes a day per asset. Derived from structured records, it is a query.
The other half is temporal. An audit routinely samples a period, not a moment, and asks what the programme looked like at some point in the past. A system that stores only current state answers with today's data and today's rules, which is not what was asked and is obvious to anyone experienced. The requirement is that the plan can be reconstructed as of any past date, from the data and the rule set that existed then.
Test this before you buy rather than during an audit. Take one asset with a real history, ask the system to produce its evidence packet, and read it as if you were hostile to it. Look for the gaps a reviewer would find: an inspection whose procedure revision is not recorded, a technician whose qualification expiry falls before the inspection date, a finding with no closure. If the packet exposes those, the system is doing its job. If it presents a tidy summary that quietly omits them, it is a reporting tool, not an integrity record.
Why does the standard remaining-life calculation break down on cryogenic service?
Because there is no measurable thinning to divide by. At roughly minus 162 degrees Celsius, aqueous corrosion mechanisms are inactive, so the corrosion rate on a continuously cold line trends to zero or to instrument noise. Remaining life becomes infinite or undefined, and the code's one-half-remaining-life instruction returns nothing usable. The correct treatment is a documented determination that no credible thinning mechanism is active, followed by application of the code maximum interval, not a number typed to clear an error.
Is an LNG storage tank inspected under API 653?
Generally not. API 653 addresses atmospheric storage tanks built to API 650. A double-containment or full-containment refrigerated tank is built to API 620 Annex Q or to API 625 as a system, and its in-service inspection regime comes from that lineage, from EEMUA 147 guidance and from the operator's own programme. Citing API 653 as the basis for a refrigerated tank interval is a documentation error an experienced auditor will find quickly.
Where does damage actually accumulate in an LNG facility?
Predominantly outside the cold, continuously operating core. Corrosion under insulation attacks carbon steel at vapour barrier penetrations, supports and lines that cycle through the wet ambient band. Austenitic stainless in intermittent or ambient service is exposed to chloride stress corrosion cracking under insulation. Aluminium brazed heat exchangers are vulnerable to mercury attack if the guard bed underperforms. Boil-off gas compressor piping and small-bore connections accumulate vibration-induced fatigue. None of these are thickness-loss problems, and none are found by a wall-thickness interval.
What does OSHA mechanical integrity require of an inspection interval?
That inspection and testing follow recognised and generally accepted good engineering practice, at a frequency consistent with manufacturer recommendations and the operating experience of the equipment, with each inspection documented and each identified deficiency corrected before further use or otherwise assured safe. The frequency itself is not prescribed, which is precisely why the basis has to be written down. "We do it every five years" is not a basis; the reasoning that produced five years is.
How should a deferral be modelled so it survives an audit?
As a bounded, expiring record rather than a changed date. The original derived date stays visible, the deferral carries a requester, a technical justification naming the mechanism it accepts risk against, an approver at the correct authority level, an expiry, and any interim mitigations such as increased monitoring. When the expiry passes without action, the asset escalates automatically. A deferral that quietly becomes the new plan is the finding that recurs across every LNG compliance audit.
Is API 510, 570 or 653 inspector training part of this offer?
No. Atlantis does not deliver API inspector certification training. Atlantis provides NDT training to ASNT SNT-TC-1A and ISO 9712, covering Level I, II and III in UT, RT, MT, PT, ET, VT, PAUT and TOFD, alongside ASNT Level III consulting, inspection management and reporting software, digital twin platforms, 3D laser scanning and independent report validation. The software implements API interval calculations; certifying your inspectors remains with an accredited API training provider.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.