When the tank interval spreadsheet stops being reproducible

A terminal's next inspection date should be an output, not an entry. The engine holds each course's measured thickness, the API 653 t-min for the tank's current fill height and product gravity, and both long- and short-term corrosion rates, then derives the external, UT and internal dates the code allows. Change the service and every date recomputes.

API 653 does not yield one date per tank. Routine external inspection by owner personnel runs on a monthly cycle. External inspection by an authorised inspector is bounded by the lesser of five years and RCA/4N, where RCA is remaining corrosion allowance in mils and N the shell corrosion rate in mils per year. External UT thickness measurement, where a corrosion rate is established, is bounded by the lesser of fifteen years and RCA/2N. The internal interval is driven by the bottom rather than the shell and carries a twenty-year default ceiling that only a documented risk-based assessment under API 580/581 can extend. Each of those is a minimum taken over a code cap and an arithmetic result. A workbook that collapses them into one column called next due destroys the distinction that tells a terminal where to spend money: capped tanks need scheduling, rate-bound tanks need measurement.

Source: Written against API 653 (Tank Inspection, Repair, Alteration and Reconstruction of Aboveground Storage Tanks), API 575 (Inspection Practices for Atmospheric and Low-Pressure Storage Tanks), API 570 (Piping Inspection Code), API 510 (Pressure Vessel Inspection Code), API 571 (Damage Mechanisms Affecting Fixed Equipment), API 580 and API 581 (Risk-Based Inspection), API 651 (Cathodic Protection of Aboveground Petroleum Storage Tanks), API 652 (Lining of Aboveground Petroleum Storage Tank Bottoms), ASME Section VIII Division 1, ASME B31.3, and ASNT SNT-TC-1A.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What an interval engine must derive separately across a terminal's asset classes
Asset classGoverning ruleWhat the derived interval is bounded byInput that fails first in a spreadsheet
Tank shell, external inspection by authorised inspectorAPI 653Lesser of the code cap and RCA/4N from the shell corrosion rateCorrosion rate silently switched between long-term and short-term basis
Tank shell, external UT thickness measurementAPI 653Lesser of the code cap and RCA/2N where a rate is establishedt-min stored as a constant after the tank changed product or fill height
Tank bottom, internal inspectionAPI 653Minimum remaining thickness against code minimum, divided by topside plus underside corrosion rateUnderside rate assumed in an unlabelled cell with no basis recorded
Critical zone and annular ringAPI 653Tighter minimum thickness than the general floor, evaluated separatelyOne site-wide bottom t-min applied to tanks with different RPB and leak-detection provisions
Transfer lines, manifold and rack pipingAPI 570 with ASME B31.3Circuit class interval and thickness against B31.3 required thicknessInjection points and dead legs carried as ordinary circuits
Vapour recovery knockout drums, receivers, LPG bulletsAPI 510 with ASME Section VIII Div 1Internal or on-stream and external intervals from vessel remaining lifeVessels tracked in a second workbook and reconciled by hand
Interval formulas and code caps are stated as API 653 and API 570 define them. Site-specific application belongs to the owner-user's inspection programme and the authorised inspector.

Why the workbook stopped being trustworthy

Nothing dramatic happens when a tank inspection workbook fails. There is no error message. A planner opens it in March, sorts the sheet by next-due date to build the outage list, and the sort moves the values while leaving a block of formulas pointing at the rows they used to sit beside. Every remaining-life figure below a certain row is now computed from a different tank's readings. The file still looks right, still prints, still gets emailed to the terminal manager. It is discovered eighteen months later when a tank the sheet credited with eleven years of life comes up short on a lower course.

The second failure is quieter. Two people maintain the workbook. One treats the corrosion rate column as the long-term rate measured from original thickness; the other has been overwriting it with the rate between the last two inspections whenever those two look worse. Both practices are defensible — API 570 defines long-term and short-term rates precisely and expects the governing one to be selected with engineering judgement, and API 653 applies the same logic to shell and bottom. What is not defensible is a column where you cannot tell, row by row, which of the two you are looking at.

The moment this stops being an annoyance and becomes a project is usually external: a new terminal manager, an insurer's engineering survey, an acquisition, or an API 653 evaluation an authorised inspector has to put a stamp on. Someone asks a question the workbook cannot answer. Not what is the next date, but show me how you got it. Reproducing a number requires the inputs as they stood when it was computed, and a spreadsheet only ever holds the inputs as they stand now.

What API 653 actually asks the engine to compute

The code produces a family of dates on different clocks from different evidence. Routine external inspection by owner personnel is a short-cycle visual activity. External inspection by an authorised inspector is bounded by the lesser of the code cap and RCA divided by four times the shell corrosion rate. External ultrasonic thickness measurement, where a corrosion rate is established, is bounded by the lesser of a longer cap and RCA divided by twice that rate. Internal inspection is driven by the bottom and carries a twenty-year default ceiling that only a documented risk-based assessment can extend.

Every one of those is a minimum taken over a code cap and an arithmetic result, and each arithmetic result depends on a remaining allowance and a corrosion rate that are themselves derived from readings. A spreadsheet almost always collapses this into one column. That collapse destroys the single most useful distinction in the whole calculation: which term bound the answer.

If a tank's UT interval landed on the code cap because RCA/2N came out at twenty-two years, the corrosion rate is currently not interesting and the tank is a scheduling problem. If RCA/2N came out at nine years, the corrosion rate is the entire story, the next reading set is consequential, and the CML coverage on that course deserves review. Terminals with a hundred tanks and a small integrity team live or die on that sorting. An engine that shows the binding term turns an undifferentiated due-date list into a work plan.

t-min is not a constant at a terminal

API 653 computes the minimum acceptable shell thickness for each course from tank diameter, the height from the bottom of the course under consideration to the maximum design liquid level, the specific gravity of the stored product, the allowable stress and the joint efficiency. Two of those inputs describe the service rather than the steel. In a refinery, service rarely changes for decades. In a third-party terminal, service changes with the lease.

A tank that held distillate and then takes on a customer storing a heavier additive package has a higher t-min in every course from the day the product changes, and less remaining corrosion allowance than the sheet claims. The reverse costs money in the other direction: a tank formally derated to a lower maximum fill height genuinely has a lower t-min, more allowance, and a longer legitimate interval — potentially a tank that comes out of an outage year on real evidence rather than being cleaned and entered because the workbook said so. Terminals leave that value unclaimed because recomputing t-min across every course of every tank by hand is a week of work nobody schedules.

This is the argument for deriving rather than typing, in its sharpest form. When t-min is a stored constant, a commercial decision made in the front office silently invalidates an engineering conclusion in the back, and neither side finds out. When t-min is a function of the current service record, a product change recomputes the affected dates the same afternoon, the change is attributed to whoever edited the service record, and it can be inspected and reversed.

The bottom is where the arithmetic gets uncomfortable

Shell corrosion is measurable. Bottom corrosion is half-measurable. The internal interval works from the minimum remaining bottom thickness against the minimum the code will accept, divided by the sum of the topside and underside corrosion rates. A floor scan gives the topside rate with reasonable confidence and gives underside metal loss as it stands at the time of the scan. It does not give an underside rate, because a rate needs two observations at the same location and there is only one.

So the underside rate is an assumption, built from soil resistivity, the cathodic protection record kept under API 651, whether the tank sits on a release prevention barrier, the age and condition of any liner installed under API 652, and how similar tanks on the same pad have behaved. Assumptions are legitimate and unavoidable. Undocumented assumptions buried in a spreadsheet cell are not. A tank whose interval rests on an assumed three mils per year is a different risk proposition from one resting on eight, and in a workbook that shows only the answer the two are indistinguishable.

The critical zone needs its own handling. The band of bottom plate immediately adjacent to the inside of the shell carries a tighter minimum than the rest of the floor, and the acceptable minimum elsewhere depends on whether the tank has a release prevention barrier and leak detection beneath it. A terminal with mixed-vintage tankage on one pad will have three or four different acceptance bases sitting side by side. Any engine that holds a single site-wide bottom t-min is wrong for most of them, and wrong in the unconservative direction for the oldest ones.

The rack and the manifold are not on the tank's clock

A terminal is not a tank farm with some pipe attached to it. Transfer lines, the loading rack, meter runs, the manifold, pumps and vapour recovery equipment fall under API 570, and the pressure vessels among them — knockout drums, air receivers, LPG bullets — fall under API 510 with required thickness evaluated against ASME B31.3 or Section VIII rather than against the API 653 shell formula. Three rule sets, one site, one due-date list.

The mixing points are where terminals get hurt. Additive and dye injection at the rack creates injection-point circuits that API 570 treats distinctly, with a shorter default interval and a defined upstream and downstream extent for the CML set. Seasonal and customer-specific lines produce dead legs that corrode faster than the live circuits on either side of them, and a dead leg is the most common location for a loss of containment at a terminal that has otherwise inspected diligently. Both are classification problems before they are measurement problems: if the circuit is typed as ordinary, the engine will derive a comfortable and wrong date.

The buying implication follows directly. An engine that only implements API 653 solves part of the terminal's scheduling problem and leaves the rest in the workbook you were trying to retire. Tanks, circuits and vessels have to live in one asset register with one derivation layer and several rule sets, or you end up running two systems and reconciling them by hand — which is the failure mode you started with, wearing better software.

Reproducibility is the actual deliverable

Reproducing a five-year-old interval means holding four things a spreadsheet does not hold. The readings as they stood then, including ones later superseded or excluded and the reason for the exclusion. The calculation basis in force then, including the fill height and product gravity the tank was operating on. The code edition and the owner-user's own written procedure as they then stood. And the identity of the person who accepted the result, with the date they accepted it.

Practically that means readings are immutable records and a correction is a new record that supersedes rather than an edit that overwrites; that the engine can be asked to recompute as of a date and will use the inputs valid on that date; and that every field carries who changed it, when, and from what. This is unglamorous plumbing and it is the whole point of moving off Excel. A dashboard is easy to build. An answer to why did this date move is not.

The test to run during evaluation is simple. Pick a tank whose next date has moved in the last two years. Ask the system to explain the movement without anyone opening a document. A serious engine returns the before and after values, the input that changed, the person who changed it, and whether the binding term switched from the code cap to the arithmetic bound. Anything that returns only the new date is a prettier spreadsheet.

How to evaluate this on your own tanks, not on a demo dataset

Bring three real tanks to the evaluation: one on the code cap, one bound by shell corrosion rate, one whose internal interval is driven by an assumed underside rate. Load their actual reading history with its actual gaps. Demo data is uniform and complete, which is exactly why it proves nothing about a system that has to cope with a course inspected in 2011, replated in 2016 and scanned by two different contractors since.

Then run four specific probes. Change the product gravity on the first tank and confirm every affected course's t-min and date recompute without anyone editing a date field. Enter a thickness reading that is greater than the previous one and confirm the system flags a non-physical rate rather than quietly returning an infinite remaining life. Ask which term bound each interval. And ask for the exclusion record on a scattered pit that was deliberately not used to drive the rate — API 653 permits ignoring certain isolated pitting under stated conditions, and the record of that decision is precisely what an auditor will want.

Finally, ask what the system does with the rack. If piping circuits and vessels have to be handled in a separate module with a separate register and no shared derivation, price the reconciliation effort into your comparison, because it will recur every quarter. For a scoped walkthrough against your own tank and circuit data, request a consultation at info@atlantisndt.com.

Why does the same tank produce three different due dates?

Because API 653 governs three different activities with three different evidence bases. The routine external walkdown looks for visible condition. The authorised inspector's external inspection is bounded by the shell corrosion rate through RCA/4N. External UT is bounded by RCA/2N against a longer cap. The internal inspection is driven almost entirely by bottom-plate condition, which the shell readings say nothing about. Merging them into one date loses the reason each one exists.

What actually changes when a terminal tank changes product?

The minimum acceptable shell thickness changes. API 653 computes t-min from diameter, the height to the maximum design liquid level, the specific gravity of the stored product, allowable stress and joint efficiency. Gravity and fill height are properties of the service, not the steel. A tank moving from 0.85 gravity distillate to a 1.05 gravity additive has a higher t-min in every course from that day, and a shorter remaining life nobody recalculated.

How is the underside corrosion rate on a tank bottom justified?

It is inferred, not measured. One MFL or UT campaign from inside the tank gives underside metal loss at a moment in time, but a rate needs two observations at the same location. The assumption is built from soil resistivity, the cathodic protection record under API 651, whether a release prevention barrier exists, liner age under API 652, and behaviour of similar tanks on the same pad. The assumption is legitimate; leaving it undocumented in a cell is not.

Can a derated tank legitimately earn a longer interval?

Yes, and terminals routinely leave that value unclaimed. Lowering the maximum design liquid level reduces the height term in the t-min calculation for every course below it, which increases remaining corrosion allowance and lengthens the arithmetic bound on the interval. The constraint is that the derate must be a controlled, documented change to the tank's service record, reflected in the calculation basis, not a note in an email about how the tank is being operated.

Does this replace the authorised inspector's judgement?

No. The engine computes the arithmetic the code defines and shows which term bound the result, so the inspector spends time on the parts that need judgement: whether a rate is credible, whether pitting should be excluded under the scattered-pit provisions, whether a mechanism from API 571 makes a linear extrapolation unsafe, and whether an RBI assessment supports extension. The output is a defensible proposal with its working shown, for a certified individual to accept or override.

Is API 510, 570 or 653 inspector training part of this offer?

No. Those certifications are issued by API through its Individual Certification Programs, and preparation for them sits outside what is described here. Atlantis provides inspection management and reporting software, digital twins, 3D laser scanning and report validation, plus NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, and ASNT Level III consulting. For scope questions, contact info@atlantisndt.com.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.