Remaining life and inspection intervals in oil sands, when the turnaround window will not move
In oil sands service the interval engine has to do two things a refinery engine does not. It must compute metal loss against throughput and velocity rather than elapsed calendar time, because erosion in slurry and froth service stops when the line stops. And it must reconcile every derived date against a turnaround window that will not move.
API 510 sets the internal inspection interval at the lesser of half the remaining life or ten years, and API 570 sets thickness measurement for Class 1 piping at the lesser of half remaining life or five years. Both formulas divide a wall-loss allowance by a corrosion rate expressed in mils per year. That denominator is the problem. On a hydrotransport line carrying quartz-laden bitumen froth, wall loss is a function of tonnes moved and slurry velocity, and a four-month outage or a throughput cut of thirty percent changes the rate without changing anything about the metal. An engine that computes rate as thickness difference over elapsed years will report a longer remaining life after a slow year and a shorter one after a strong year. In an Alberta upgrader, where the coker turnaround cycle is now measured in years rather than months, that error compounds directly into scope.
Source: Interval rules referenced here come from API 510 (Pressure Vessel Inspection Code), API 570 (Piping Inspection Code) including its structural minimum thickness provisions, API 653 (Tank Inspection, Repair, Alteration and Reconstruction), API RP 571 for damage mechanism definitions covering erosion and erosion-corrosion, naphthenic acid corrosion and high-temperature sulfidation, API RP 574 for piping inspection practice, and API 579-1/ASME FFS-1 for fitness-for-service. Canadian owner-user obligations follow CSA B51, the Alberta Safety Codes Act and the Pressure Equipment Safety Regulation, administered through ABSA's pressure equipment integrity management requirements.
| Circuit or asset | Dominant damage mechanism (API RP 571) | What the rate should be measured against | Governing interval rule |
|---|---|---|---|
| Hydrotransport and tailings slurry lines | Erosion and erosion-corrosion from entrained quartz | Tonnes conveyed and time above a velocity threshold, not elapsed months | API 570 thickness measurement; structural minimum usually governs t-required |
| Froth treatment and diluent recovery towers | Naphthenic acid corrosion, high-temperature sulfidation | Operating hours above the NAC threshold temperature at the measured TAN | API 510 internal at the lesser of half remaining life or ten years |
| Delayed coker heater, transfer line and overhead | Sulfidation, coke deposition, thermal fatigue, creep | Fired hours and decoke cycles between turnarounds | API 510 and API 570 with the derived date snapped to the outage window |
| SAGD steam generation and steam distribution | Under-deposit corrosion, wet CO2 corrosion in produced fluid return | Steam hours and recorded water chemistry excursions | Owner-user programme accepted by the provincial regulator, not API 510 by default |
| Tailings, product and slop storage tanks | Soil-side bottom corrosion, erosion at inlet nozzles and sumps | Bottom plate corrosion rate from the last floor scan campaign | API 653 internal interval from measured bottom rate; external capped at five years |
The turnaround window is the real constraint, not the due date
A derived inspection date is only useful if a crew can reach the item on that date. In an oil sands upgrader the coker, the hydrotreaters and the froth treatment trains are opened on a fixed cycle, and once that window closes the equipment is not accessible again for years. The engine's output therefore has to be read against the outage calendar rather than against a wall planner. The question a turnaround team actually asks is not when an item is due, but whether its due date falls inside the window about to open, inside the one after it, or in the gap between them.
Items that fall in the gap consume the planning cycle. A vessel whose API 510 internal comes due fourteen months after the window closes cannot simply wait twenty-six months for the next one. Somebody has to build a defensible basis: an on-stream examination substituting for the internal where the code permits it, a shorter-interval on-stream programme, a mid-cycle opportunity outage, or a fitness-for-service assessment supporting operation to the next window. Each of those is engineering work with a lead time, and the only way to schedule that work is to know in month one which items are orphans, not in month twenty.
That is the most useful thing an interval engine does for a turnaround organisation in this industry. It converts a list of dates into a list of exceptions against a known window, months ahead, with the reason each item is an exception attached. Scope, scaffold tonnage, insulation removal and crew loading all follow from that list. Building it by hand from a spreadsheet of due dates is how items get discovered during the outage, at the worst possible cost.
Erosion does not run on a calendar
General corrosion is reasonably well behaved against time. A carbon steel line in wet sour service loses wall at a rate that, averaged over a few years, is close enough to linear that mils per year is a fair unit. Erosion in slurry is not that. Wall loss in a hydrotransport line, a cyclofeed spool or a tailings pump discharge is driven by particle impingement: it scales with velocity to a power well above one, with solids loading, with particle size distribution and with local geometry. Two identical elbows at the same station, one on a line that ran at design rate and one on a swing line that ran at forty percent, will show very different loss over the same twelve months.
So the denominator matters. If the engine computes rate as the thickness difference divided by the years between readings, a period of reduced throughput inflates remaining life. Run that number through the API 570 half-life rule and the interval extends, precisely for a line that will return to full rate next quarter. The correction is to allow the rate to be normalised against a duty variable — tonnes conveyed, hours above a velocity threshold, or hours in service — and to record for each circuit which variable was used and who chose it.
None of this is exotic. The plant already meters ore throughput and line running hours; the gap is almost always that the integrity system has no field to receive them and no way to express a rate in anything but mils per year. During an evaluation, ask to see a corrosion rate expressed per million tonnes conveyed, and then ask to see the interval that was derived from it. If the demonstration cannot produce that, the engine is a refinery engine with an oil sands label on it.
The spool rotation problem, and other events that break a long-term rate
Slurry lines in oil sands are maintained by rotating them. A spool showing preferential loss at the invert is unbolted and reinstalled rotated a third of a turn, presenting unworn wall to the abrasive path. This is deliberate, sound life extension. It also destroys the arithmetic of a long-term corrosion rate, because the next reading at that physical CML is now taken on metal with a different service history than the reading it is being compared against.
An engine that computes long-term rate from the original thickness to the current reading will, after a rotation, calculate a negative or near-zero rate and report a remaining life measured in decades. Some systems silently suppress negative rates, which is worse: the trend resets and nobody records why. The correct behaviour is an explicit event on the CML — rotation, spool replacement, weld overlay, internal lining, hardfacing — that closes the previous series, starts a new baseline, and retains the event, its date, its author and the as-installed thickness.
The same logic applies to any intervention that changes the metal being measured. The test for a candidate system is easy to run in a demonstration: enter a rotation event and then ask for the long-term rate. A defensible system reports the rate since the event, or refuses to compute one until two post-event readings exist. A system that averages across the discontinuity has just handed you an interval that no reviewer should sign.
Which minimum thickness the remaining life divides down to
Remaining life is the measured wall above a limit, divided by a rate. The limit is the part buyers examine least and get wrong most often. For a pressure-retaining vessel the required thickness comes from the design code calculation at the MAWP being maintained, with corrosion allowance excluded. For piping it may come from the pressure design formula, or from the structural minimum thickness for that pipe size, whichever is greater — and API 570 exists partly because the second one is so often forgotten.
In slurry service the structural minimum usually governs. A large-bore hydrotransport line at modest pressure has a pressure-design thickness that is trivially small; what actually retires the pipe is the wall needed to carry its own weight, the slurry inventory, the support spans, and Alberta wind and snow loading, plus a margin for handling during a rotation. If the engine divides down to a pressure-design thickness, the remaining life is fiction and the line reaches a structural limit long before it reaches a pressure limit.
So the engine has to carry a required thickness per CML with a stated source: pressure design, structural minimum table, an owner-set retirement thickness, or an assessed minimum from an API 579 evaluation. That source has to be visible on the same screen as the derived date, because the first question a reviewer asks about any generous remaining life is what it was divided down to. A system that stores one t-min number with no provenance cannot answer that question two years later, and a reviewer who cannot answer it will not sign the deferral.
The provincial owner-user obligation sits on top of the API formula
Most oil sands pressure equipment in Alberta is registered under the Safety Codes Act and the Pressure Equipment Safety Regulation, with the province's delegated authority administering the pressure equipment programme. An owner-user running its own in-service inspection programme does so under a quality management system that the regulator has accepted, and that programme — not a bare reading of API 510 — is the document defining how intervals are set, who may set them, and what evidence supports an extension.
Practically, the interval engine has to be configurable to the accepted programme rather than hard-coded to an API formula. If the programme commits to an on-stream interval shorter than API 510's ten-year cap for a class of equipment, the engine must apply the shorter cap and show that it did. If the programme requires a named individual holding a specific qualification to approve any interval beyond a threshold, that approval has to exist as a record in the system with the qualification attached, not as an email in someone's mailbox.
This is where a system bought for a Gulf Coast refinery tends to fail a Canadian site. It will produce an API 510 date without complaint. It will not necessarily let you express a provincial commitment as a rule, and it will not assemble the evidence package a programme audit expects: which rule applied, the data behind it, the qualification of the approver, and the version of the programme in force on the date the decision was made.
Building turnaround scope from derived dates rather than from last time's list
The default scope-building method in most organisations is to take the previous turnaround's work list, delete what was completed, add what broke, and negotiate the remainder. It is fast, and it is the reason scope grows every cycle. An interval engine that is trusted changes the starting point: the scope begins as the set of items whose derived date falls inside the window, plus the orphans that must be handled because they fall outside it, plus the deferrals from last cycle that are now expiring.
For that to work the engine has to know more than the date. It needs to know whether the examination requires the equipment open or can be done on-stream, whether it needs scaffold or rope access, whether insulation must be stripped and reinstated, whether the item sits in a confined space, and whether the technique requires a certified Level II in a method the site does not keep on staff. Those attributes turn a due date into a resource requirement, which is the output a turnaround planner can actually use.
There is a number that tells you whether it is working: the proportion of executed turnaround scope that was on the list ninety days before the window opened. Sites that build scope from derived dates and access attributes routinely reach the high eighties. Sites that build it from last cycle's list and discover items during the outage live in the sixties, and the difference is paid in unplanned scaffold, mobilised crews standing by, and critical path.
Where the engine hands off to fitness-for-service
Erosion produces local metal loss with an extent and a profile, not a uniform thinning. When a reading falls below the required thickness the code answer is repair, replace, or run with an engineering basis, and the engineering basis is an API 579-1/ASME FFS-1 assessment. A Level 1 general metal loss assessment needs a thickness profile along a critical thickness line, not a single minimum point; a local thin area assessment needs the extent measured in both the longitudinal and circumferential directions.
The failure mode here is chronological rather than technical. The crew is on the line, the scaffold is up, the reading comes back thin — and if the field procedure captured one number, somebody has to go back for the profile after the scaffold is down and the window has closed. An interval engine coupled to the damage mechanism register can flag, before the campaign is planned, which CMLs are close enough to their limit that a profile should be taken as a matter of course rather than as a callback.
The evaluation question is whether assessment results feed back into the interval. An accepted API 579 assessment normally carries conditions: a re-inspection date, a monitoring requirement, an operating limit on temperature or velocity. Those conditions have to override the formula-derived date, and the override has to appear as an override with its basis attached, not as a silently rewritten number that nobody can trace back to the assessment that justified it.
What to test during an evaluation
Bring your own data, and bring the ugly parts. Take one hydrotransport circuit and one froth treatment vessel with the last three campaigns of readings, including a rotation event, a replaced spool, an outlier the previous inspector excluded, and a stretch of reduced throughput. Load them and ask the system for the derived date. Then ask it to explain the date: which rate governed, short-term or long-term, which readings were used and which excluded and on whose authority, what required thickness was applied and from which source, and which rule capped the interval.
Then move the window. Change the outage date by six months and see whether the exception list rebuilds itself, or whether the dates sit unchanged while a planner re-sorts a spreadsheet. Take one item out of the window and ask the system to record a deferral: it should demand a basis, an approver holding the right qualification, and an expiry date, and it should refuse a deferral that runs past the next window without a documented engineering evaluation behind it.
Finally, check the export. Turnaround scope leaves the integrity system and lands in the planning tool, then in a contractor's estimate, then in a work order. If the derived date exports but the reason for it does not, every downstream conversation restarts from zero and the planner rebuilds judgement that the engine already made. Ask for the exception list with the basis attached, and look hard at what actually comes out of the file.
Why does a calendar-based corrosion rate mislead in slurry service?
Because erosion is driven by particle impingement, and impingement scales with velocity and solids loading rather than with time. A line that ran at forty percent rate for eight months loses far less wall than the same line at design rate, but a rate computed as thickness change over elapsed years cannot tell the difference. Feed the inflated remaining life into the API 570 half-life rule and the interval extends for a circuit that is about to go back to full throughput.
How should the engine handle a rotated spool piece?
As an explicit event that closes the previous rate series and starts a new baseline. Rotating a slurry spool to present an unworn invert is deliberate life extension, but the next reading at that CML is on metal with a different history. A system that computes long-term rate from the original thickness will return a negative or near-zero rate and a remaining life measured in decades. Silently discarding negative rates is worse, because the trend resets with no record of why.
What happens when a derived due date falls between turnaround windows?
It becomes an exception that needs an engineering answer, and the value of the engine is finding it early. The available answers are an on-stream examination substituting for the internal where API 510 permits, a shorter-interval on-stream programme, a mid-cycle opportunity outage, or an API 579 assessment supporting operation to the next window. Every one of those has a lead time measured in months, so an orphan discovered in month one is a plan and an orphan discovered in month twenty is a schedule impact.
Does a provincial owner-user programme override the API interval formula?
In Alberta the accepted owner-user integrity management programme is the controlling document. It defines how intervals are set, who may approve an extension and what evidence supports it, and it can commit to caps shorter than API 510's ten years for a class of equipment. The engine therefore has to be configurable to the programme rather than hard-coded to the API formula, and it has to show which rule applied, with the programme version in force on that date.
Which minimum thickness should the remaining life divide down to?
Whichever is greater of the pressure design thickness at the maintained MAWP and the structural minimum for the pipe size, unless an owner retirement thickness or an assessed API 579 minimum is lower-bounded above them. In slurry service the structural minimum almost always governs: a large-bore, low-pressure hydrotransport line has a trivial pressure-design wall, but it still has to carry its own weight, its slurry inventory and its snow and wind load.
Is API 510, 570 or 653 inspector training part of this offer?
No. Atlantis NDT delivers NDT method training to ASNT SNT-TC-1A and ISO 9712, Level I, II and III across UT, RT, MT, PT, ET, VT, PAUT and TOFD, together with ASNT Level III consulting, inspection management software, reporting software, digital twins, 3D laser scanning and report validation. API inspector certification is administered by the American Petroleum Institute through its own individual certification programme. The software applies API interval rules; it does not certify the people who approve them.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.