The remaining-life record an NDT service provider can hand to an auditor

For an NDT service provider the remaining-life number is a deliverable, not an internal note. An auditor will not argue about the arithmetic; they will ask which corrosion rate you used, which minimum thickness it was measured against, which certified technician took the readings on which verified instrument, and whether the next-due date follows from those inputs without anyone retyping it.

API 510 sets the internal or on-stream interval at the lesser of one-half the remaining life or ten years. API 570 caps piping thickness intervals by class — five years for Class 1, ten for Class 2 and Class 3 — with the half-remaining-life rule underneath and a tighter three-year or half-life rule at injection points. API 653 caps the tank internal interval at twenty years, extendable only under a documented risk-based assessment. Every one of those rules is a two-input calculation: a corrosion rate and a minimum thickness. The audit exposure is almost never the rule. It is that the corrosion rate came from two readings whose difference sits inside the instrument's stated accuracy, or from a nominal thickness that was never measured, or from a reading taken at 260 degrees Celsius with no temperature correction applied. The engine's job is to make each of those choices explicit, attributable and re-runnable.

Source: Sources: API 510 (Pressure Vessel Inspection Code), API 570 (Piping Inspection Code), API 653 (Tank Inspection, Repair, Alteration, and Reconstruction), API 574 (Inspection Practices for Piping System Components), API 580 and API 581 (Risk-Based Inspection); ASME Boiler and Pressure Vessel Code Section V, including Article 5 and Article 23 for ultrasonic thickness practice; ASME B31.3 and ASME Section VIII Division 1 for design minimum thickness; ASNT SNT-TC-1A and ANSI/ASNT CP-189; ISO 9712; ISO/IEC 17020 (inspection bodies) and ISO/IEC 17025 (testing laboratories); NAS 410 for aerospace personnel; OSHA 29 CFR 1910.119(j) for mechanical integrity contractor documentation.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What an auditor asks about a remaining-life number, and the record that has to answer it
Audit questionGoverning referenceEvidence the record must produceWhere a spreadsheet fails
Which corrosion rate did you use, short-term or long-term?API 510, API 570, API 574Both rates, the readings behind each, and the documented basis for the one carried into the intervalThe sheet holds one rate in one cell with no trace of the alternative or the decision
What minimum thickness did you compare against?ASME B31.3, ASME Section VIII Div 1, API 510, API 653The t-min value, its derivation (pressure design, structural, or owner-specified), and who set itA constant typed once per line and copied down, with no derivation and no owner
Who took the reading, and were they certified for it?ASNT SNT-TC-1A or CP-189, ISO 9712, NAS 410Certification level and method, currency, near-vision examination date, employer annual evaluationTechnician initials in a column, with certification status held in a separate HR file
Was the instrument verified, and against what?ASME Section V, written procedureCalibration and in-service verification records, the block used, its traceability, verification at shift start and endNo link at all between a reading and the instrument that produced it
Was the reading corrected for temperature?Written procedure, instrument manualSurface temperature at the time of reading and the correction appliedTemperature is not captured, so hot readings silently read thin and inflate the corrosion rate
Does the next-due date follow from the inputs?API 510 section on inspection intervals, API 570 class table, API 653A derivation showing rule, rate, t-min, current thickness, resulting remaining life and intervalA date typed by a planner, defensible only by the memory of whoever typed it
The specific interval rule and minimum thickness basis for any given item are determined by the applicable code edition and the owner-user's inspection programme. This table describes what the record has to be able to show, not a substitute for that determination.

What the auditor is actually testing

An audit of a remaining-life deliverable is almost never a technical dispute about API arithmetic. The rules are short and unambiguous, and competent auditors assume you can divide. What they test is whether the number in front of them can be traced backwards to physical evidence, and whether the same inputs would produce the same number if someone else ran it. That is a records question wearing an engineering costume.

The specific mechanism is a vertical trace. An auditor picks one line item from a report you issued — one circuit, one shell course, one nozzle — and walks it down. Where did this thickness come from? Who took it? Under which procedure, at which revision? On which instrument, verified when, against which block? What corrosion rate did that produce, over what baseline? Against what minimum thickness? And therefore why is the next inspection due on this date? A trace that survives all seven questions passes. A trace that dies at question four fails regardless of how correct the arithmetic was.

Providers usually fail at the joins rather than at any single record. The certifications exist, in the training folder. The calibration records exist, in the equipment binder. The readings exist, in the field sheets. Nothing links them to the specific number under examination, so reconstructing the trace becomes a multi-day archaeology exercise performed in front of the auditor. That reconstruction is the finding, even when it eventually succeeds.

You compute it, someone else owns it — and impartiality is in scope

A service provider occupies an awkward position in the integrity chain. The owner-user's authorised inspector makes the determination under API 510, 570 or 653. The provider supplies the measurements and, increasingly, the calculation as a contracted engineering service. That arrangement is entirely normal and entirely auditable, but only if the record states clearly which party did what.

Where this becomes sharp is under ISO/IEC 17020. An accredited inspection body is assessed on impartiality, and the independence type it holds constrains what it can do for a client whose asset it also inspects. A provider that measures, calculates, recommends the interval and then wins the follow-up inspection work is describing a conflict that has to be actively managed and documented, not one that can be ignored because it is common. Laboratories operating under ISO/IEC 17025 face an equivalent question about the boundary between test results and interpretation.

The practical consequence for software is that the record must carry roles, not just users. Who measured, who calculated, who reviewed, who approved, who is the client's accepting authority, and whether any of those are the same person. An engine that stores a single 'created by' field cannot answer an impartiality question at all, which means the answer gets assembled by hand and asserted verbally.

The corrosion rate is where the audit goes

Every interval rule in the API codes reduces to a corrosion rate and a minimum thickness, so the corrosion rate is where a competent auditor spends their time. The first question is short-term versus long-term. API practice is to evaluate both and to be deliberate about which governs, because they diverge for real reasons: a process change, a chemical injection upset, a new dew point. A provider reporting one rate with no evidence the other was considered has skipped the step the code cares about.

The second question is measurement uncertainty, and it is the one that catches most providers off guard. A gauge that displays to 0.001 inch may be specified to an accuracy several times that. Two surveys four years apart on a slowly corroding circuit can produce a difference entirely inside the instrument's own band. Divide that difference by four and you have a corrosion rate that is arithmetically impeccable and physically meaningless. The honest system flags it: this rate rests on a difference smaller than the stated accuracy of the instrument that produced it.

The third question is repeatability of the location itself. A condition monitoring location is only a trend if the probe lands in the same place each time. Move fifteen millimetres onto a weld cap, a grind mark or a different pipe schedule and the trend records wall loss that never occurred. This is why CML definition — photograph, dimension from a datum, surface preparation — belongs in the record next to the reading and not in a technician's memory.

Minimum thickness: the input most often wrong

If corrosion rate is where auditors look, minimum thickness is where the errors actually are. There is no single t-min. There is a pressure design minimum from the construction code, a structural minimum that can govern on large-diameter thin-wall piping regardless of pressure, and an owner-user specified value that may be more conservative than either. Choosing among them is an engineering decision that has to have an owner and a date. In most spreadsheets it is a constant typed once and copied down a column.

The second recurring error is the baseline. Corrosion rate needs a starting thickness, and using nominal wall as that baseline fabricates loss that never happened. Seamless pipe is manufactured to a wall tolerance that permits it to be meaningfully thinner than nominal from the mill. Plate can be thicker. Subtracting today's measured wall from a nominal value therefore produces a rate composed partly of manufacturing tolerance. The correct baseline is the first measured thickness, and the record has to be able to say which one it used.

Temperature is the third. Ultrasonic velocity in steel falls as temperature rises, so an uncorrected reading taken on hot service reads thin. Take a baseline cold and a follow-up hot and you manufacture a corrosion rate out of thermodynamics. Capturing surface temperature with every reading, and applying and recording a correction, costs a field second and closes an entire category of audit finding.

The evidence chain behind one date

Assemble the chain deliberately and it is short. A next-due date rests on a remaining life. A remaining life rests on a current thickness, a corrosion rate and a minimum thickness. Each thickness rests on a reading. Each reading rests on a technician, a procedure, an instrument, a calibration block, a couplant, a temperature and a location definition. Each technician rests on a certification under the applicable scheme — SNT-TC-1A or CP-189 in a written practice, ISO 9712 under a certification body, NAS 410 in aerospace — plus current vision examination and, where the written practice requires it, a documented annual evaluation by the employer.

In a compliant system these are foreign keys. In a spreadsheet they are conventions, which means they are only as good as the person who maintains them. The difference shows up the first time a technician's certification lapses mid-campaign. In a linked system, every reading taken after the lapse date is flagged automatically and the exposure is a report you run in a minute. In a workbook, nobody notices until an auditor cross-references the training folder against the field sheets, and then the exposure is however many reports were issued in the interim.

There is a second-order benefit worth naming. Once the chain exists, the corrective action after a finding is bounded. You can state exactly which deliverables are affected, notify exactly those clients, and re-issue. Without the chain, the only honest answer to 'which reports are affected?' is 'we will have to check all of them', which is what turns a minor finding into a major one.

Different audits ask different questions of the same record

A client audit is commercial and specific. The client's integrity engineer wants to know that the data feeding their mechanical integrity programme is sound, and they will usually pick items they already suspect. Expect questions about CML repeatability, about outliers you kept and outliers you discarded, and about whether your rate calculations match the ones their own system produces from your data.

An accreditation assessment under ISO/IEC 17020 or 17025 is systemic. The assessor cares less about any individual number and more about whether the management system controls the process: impartiality arrangements, personnel authorisation, procedure control, equipment records, review before issue, and the handling of nonconforming work. They will still trace one number end to end, but as a test of the system rather than of the number.

A process safety audit under 29 CFR 1910.119 arrives through the client and reaches you as a contractor. The mechanical integrity provisions require inspection and testing at frequencies following recognised and generally accepted good engineering practice, with results documented, and deficiencies corrected before further use or with a documented basis for safe continued operation. As the contractor supplying that documentation, you are expected to produce records that satisfy the operator's obligation, not merely your own. Aerospace work under NAS 410 and Nadcap adds a fourth and much more prescriptive personnel and process audit on top.

The eight weeks before an audit, and how to evaluate the engine

If an audit is scheduled, the highest-value preparation is not rewriting procedures. It is running the vertical trace yourself on a random sample before someone else does. Pick ten line items across different clients, methods and technicians, and walk each one down to physical evidence. Time it. Whatever breaks is what the auditor will find, and you now have weeks rather than minutes to fix it. Providers who do this routinely stop being surprised in audits, which is most of the benefit.

The second preparation is a lapse sweep: every certification, vision examination, annual evaluation, procedure revision and instrument verification against the date range of every report issued in the audit period. This is a query in a system and a week of manual cross-referencing in a folder structure, which is a reasonable way to decide whether the system is worth having.

Evaluate an interval engine on exactly these two capabilities. Ask a vendor to demonstrate a vertical trace from a due date down to a technician certification in under a minute. Ask them to show a report listing every deliverable affected by a hypothetical expired certification. Ask what happens when a corrosion rate rests on a difference inside instrument accuracy — silence is the wrong answer. Ask whether short-term and long-term rates are both retained. Ask who can override a derived date and whether the override survives forever on the record. To see this run against your own reports and audit history, request a working session at info@atlantisndt.com.

Who is accountable for the remaining-life number, the service provider or the owner?

The owner-user's authorised inspector owns the determination under the API codes. The service provider owns the data and, where contracted, the calculation as an engineering deliverable. That split matters during an audit because the questions differ. The owner is asked whether the interval is compliant; the provider is asked whether the inputs are traceable and the method was followed. A record that blurs the two — a provider asserting compliance it has no standing to assert — creates a finding for both parties.

Is API 510, 570 or 653 inspector training part of this offer?

No. API inspector certification is administered by API through its individual certification programmes, and preparation for it sits outside what is described here. What Atlantis provides is NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD at Levels I, II and III, ASNT Level III consulting, and the software that holds the inspection record. The distinction is worth being precise about in an audit context, because conflating the two is itself a finding.

How do you show an auditor that a corrosion rate is real and not instrument noise?

By stating the uncertainty alongside the rate. A digital thickness gauge displaying to a thousandth of an inch may carry a stated accuracy several times coarser than that. Subtract two readings four years apart whose difference is inside that band and the resulting rate is noise wearing a decimal point. The defensible practice is to record instrument accuracy, flag rates whose underlying difference falls within it, and require either a longer baseline or a repeat survey before that rate drives an interval.

What does an ISO/IEC 17020 assessor look for in an interval calculation?

Impartiality first, then competence and method control. If the same organisation takes the readings, performs the calculation and recommends the interval, the assessor will want to see how that is managed under the independence type the body is accredited to. They will then trace one number end to end: the procedure revision, the personnel authorisation for that method and technique, the equipment record, and the review before issue. The trace is the test, not the arithmetic.

How should short-term and long-term corrosion rates be reported to a client?

Report both, always, with the readings behind each and an explicit statement of which one was carried into the interval and why. Long-term rates smooth out real process upsets; short-term rates amplify measurement scatter. A provider who reports only the more comfortable of the two invites the obvious audit question and has no answer. Reporting both, with the selection documented, converts a vulnerability into evidence that the method was applied deliberately.

What has to be attached to a thickness reading for it to survive an audit?

At minimum: the condition monitoring location identifier and its physical definition, the date and surface temperature, the technician and their certification status on that date, the procedure and revision, the instrument serial number with its verification record, the calibration block used and its traceability, the couplant, and any correction applied. Detached from those, a number is an assertion. Attached to them, it is a measurement. The difference is the entire audit.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.