Turning third-party offshore UT into an interval you can defend

Offshore thickness data arrives from several contractors in several formats, and a single bad reading can move a due date in either direction. The engine has to ingest against a schema, quarantine readings that fail physical and provenance checks, keep the raw submission separate from the accepted value, and only then compute a corrosion rate and an API 570 interval.

On a platform, a wrong corrosion rate has an unusually direct cost. Shorten an interval on bad data and you spend a helicopter seat, a bed and a POB slot on an inspection that was not needed, in a schedule where those are the binding constraints. Extend it on bad data and you have accepted a mechanism you cannot see. Neither error is recoverable quickly, because remobilising a rope-access UT crew offshore is a matter of weeks and weather, not a phone call. That asymmetry is why the data quality layer belongs in front of the interval calculation rather than in a monthly review afterwards. The engine has to reject what is physically implausible, quarantine what is merely doubtful, and let the plan continue to run on the previous accepted values while a query is open, so a data problem never becomes a silent gap in the schedule.

Source: Interval logic follows API 570 and API 510 for topsides piping and pressure equipment, with API 571 for damage mechanism identification and API RP 580 and 581 where a risk basis applies. Contractor performance and qualification are assessed against ASNT SNT-TC-1A or ISO 9712 written practice. Sour service limits reference NACE MR0175 / ISO 15156, erosional velocity practice references API RP 14E with DNV RP-O501 for sand erosion, small-bore vibration references Energy Institute guidance, and the overarching safety and management system sits under 30 CFR Part 250 Subpart S and API RP 75 in US waters.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Contractor data defects, how they present, and what the ingest layer must do
DefectHow it presents in the dataRequired engine behaviour
Uncorrected hot readingWall appears thicker than the previous survey on a line in hot serviceFlag against recorded surface temperature; reject or apply a stated velocity correction, never accept silently
Coating included in the readingA step increase across a whole CML group after a recoat campaignCorrelate with coating history; quarantine the group and require confirmation of the measurement mode used
CML datum driftScatter within a CML far exceeding instrument repeatabilityHold the grid point identity, not just the CML; require photographic or scan evidence of location
Resolution lossValues reported to two decimals in millimetres across a five-year gapReject at schema validation; store raw submitted precision and refuse to derive a rate below resolvable change
Expired qualificationReport accepted, technician certification lapsed before the survey dateValidate qualification against the inspection date at ingest and block acceptance until resolved
Negative corrosion rateCurrent reading exceeds previous by more than repeatabilityDo not take zero; fall back to long-term rate on the earliest reliable reading and raise a data query

The problem is not the contractor, it is the absence of a schema

The usual framing is that contractor data quality is a vendor performance issue, to be handled with a stern conversation and a clause in the next contract. That framing is mostly wrong and it never fixes anything. Three vendors working on the same platform under three different scopes will produce three internally consistent, mutually incompatible datasets, and every one of them will believe they delivered what was asked for. What was asked for was a report. What the integrity engine needs is a record.

The difference is specific. A report is a document with a conclusion; a record is a structured set of measurements, each attributable to a location, an instrument, a procedure, a calibration and a qualified person, on a stated date, at a stated surface temperature. A PDF satisfies the first and destroys the second. So does a spreadsheet with a vendor-designed layout, because the meaning of each column exists only in the head of whoever built it.

Which is why the fix belongs at the interface rather than in the relationship. Publish a schema, make it part of the scope of work, validate against it at submission, and return failures to the contractor while the crew is still offshore. Vendors comply with a schema far more reliably than they comply with an instruction, because a schema tells them immediately and unambiguously whether they have complied.

What an unnecessary offshore inspection actually costs

Onshore, a suspect reading is cheap to resolve. Someone walks out with a gauge and settles it in twenty minutes. Offshore, that same resolution consumes a helicopter seat, a bed, and a POB slot on an installation where the total is fixed and already contested by drilling, projects and operations. A rope-access UT scope is planned months ahead, mobilised into a weather window, and demobilised on schedule regardless of what remains unresolved.

This changes the economics of the calculation in a way that most inspection software does not reflect. Onshore, when in doubt you re-measure. Offshore, when in doubt you either accept an unverified number into your integrity basis, or you carry a gap until the next campaign, which may be twelve months out. Both options are bad, and the choice between them is being made implicitly, usually by whoever is reconciling the spreadsheet weeks after the crew has gone home.

The design consequence is that validation has to happen at the moment of capture, not at the moment of analysis. If the ingest layer can tell the technician on the deck that a reading has failed a plausibility check against its own history, the correction costs an hour. If the same failure surfaces in a desktop review in the following month, the correction costs a mobilisation, and in practice it does not happen at all: the number gets accepted with a note, and the note is forgotten.

The specific ways third-party UT goes wrong

Temperature is the most consequential and the least visible. Ultrasonic thickness gauges compute from an assumed sound velocity, and velocity in steel falls as temperature rises. Measure a hot line with an ambient velocity setting and the reading comes back thicker than the metal actually there, by roughly one percent per fifty-five degrees Celsius as a working rule. That error is non-conservative, it looks like healthy pipe, and it is undetectable unless surface temperature was recorded alongside the reading. If your data schema has no temperature field, you cannot audit for it at all.

Location is the second. A CML is a defined area, but corrosion offshore is rarely uniform across it; the loss is at the six o'clock position, in the crevice at a support, or in a band at a splash-zone transition. A technician who lands the probe fifty millimetres from where the last one did is not making a mistake by their own standards, and the resulting scatter reads as corrosion or as recovery depending on which way it falls. Holding grid-point identity below the CML, with photographic or scan evidence, is the only way to distinguish real change from relocation.

Then there is everything that comes from how the data was written down rather than how it was taken. Coating included because the instrument was in the wrong measurement mode. Precision destroyed by rounding to two decimals in millimetres, which cannot resolve a low corrosion rate over any realistic interval. A CML numbering scheme that follows the vendor's job rather than your asset register. And, quietly, work performed by a technician whose qualification had expired before the survey date, which nobody checks because the certificate was valid when the contract was signed.

Offshore damage mechanisms the rate model has to respect

Upstream production fluids are aggressive and variable in ways that make a single general corrosion rate per circuit close to meaningless. Carbon dioxide drives sweet corrosion whose rate depends on partial pressure, temperature and water wetting. Hydrogen sulphide brings sulphide stress cracking and hydrogen-induced cracking, governed by material selection under NACE MR0175 and ISO 15156 rather than by any thinning trend. Water injection and produced water systems support microbiologically influenced corrosion, which pits aggressively and locally and is often first found by a leak.

Sand is the mechanism most badly served by conventional interval logic. Erosion concentrates at bends, tees, chokes and downstream of any restriction, and it scales with production rate and solids loading, neither of which appears anywhere in a thickness history. The routine error is to treat the erosional velocity constant from API RP 14E as though it predicted erosion; it does not, it was never derived for solids-bearing service, and treating a circuit as safe because it sits below that velocity is unjustified. Sand-prone circuits need CMLs placed where the impingement is and a rate that responds to production data.

Topsides adds mechanisms that thickness monitoring will never see. Corrosion under insulation is severe in a salt-laden marine atmosphere, concentrating at supports and penetrations. The splash zone attacks structure and caissons under conditions no gauge reaches on a routine campaign. And small-bore connections on vibrating lines fail by fatigue, where the governing variables are excitation and geometry rather than wall loss. An interval engine has to let a circuit's basis be set by its actual mechanism, because a fatigue-driven small-bore tee and a CO2-driven flowline share nothing but a plant number.

Quarantine, not rejection

The instinct when data fails validation is to reject it. In practice, wholesale rejection is what makes people stop using the system, because a rejected dataset means an asset with no current reading, a plan with a hole in it, and a planner who now maintains a private spreadsheet to work around the gap. Within two campaigns the integrity record has forked, and the shadow spreadsheet is the one people actually use.

Quarantine behaves better. The submission is accepted and stored intact, exactly as the contractor sent it. Readings that fail plausibility or provenance checks are marked and held out of the calculation. The asset continues to run on its previous accepted values and its existing interval, so the plan stays whole. The quarantined readings appear in a data-quality queue with the reason for the hold, and each one is eventually accepted, corrected with a recorded basis, or formally rejected with a reason.

This distinction between the raw submission and the accepted value is the structural feature that makes the record defensible later. When a corrosion rate is disputed two years on, you can show what was submitted, what was accepted, what was changed and by whom, and why. A system that normalises data on import and stores only the cleaned result has destroyed the evidence needed to defend its own numbers, and it will not be able to reconstruct them when the dispute is with the contractor who supplied them.

Attribution is what makes a third-party reading usable

A thickness value on its own is not evidence, it is a number someone typed. What makes it usable in an integrity basis is everything attached to it: the exact location including grid point, the date and surface temperature, the instrument and its serial number, the probe type and frequency, the calibration block and the calibration record covering that date, the procedure and its revision, and the technician with their method, level and qualification status on that date under a named written practice.

Most of those fields already exist somewhere in the contractor's paperwork; they are simply not carried through into anything structured. Requiring them in the schema costs the vendor very little, because they are recording the information already, and it changes what you can do with the result entirely. You can then answer questions no PDF-based record can answer: which readings on this platform were taken with an instrument that was subsequently found out of calibration, or which results were produced under a procedure revision that has since been superseded.

Qualification validity against the inspection date deserves particular attention, because it is checked almost nowhere and found in audits routinely. The relevant test is not whether the technician holds a current certificate today; it is whether they held a valid certificate, in the right method and level, on the day the work was done. Storing qualifications with effective and expiry dates and validating at ingest turns that from a retrospective discovery into a submission-time block.

How data quality feeds back into the interval itself

Once readings carry a quality state, the interval logic can use it. A corrosion rate computed entirely from validated readings is treated as accepted. A rate that depends on a quarantined reading is provisional, and the engine should behave conservatively while it is provisional: keep the shorter of the derived and the previous interval, and mark the asset as awaiting data resolution rather than presenting a confident date it cannot support.

This also gives you a genuine measure of contractor performance that survives contract negotiation, because it is derived from data rather than opinion. First-pass acceptance rate by vendor. Median time to resolve a query. Proportion of readings rejected for temperature, location or provenance defects. Those figures are far more useful in a vendor review than the general impression that a particular crew is careless, and they identify systematic problems, such as a single instrument producing anomalies across every campaign it appeared in.

The last piece is bidirectional traceability. From any due date, you should be able to reach the corrosion rate, the readings behind it, the submission file each arrived in, the technician and the procedure. From any submission, you should be able to reach every interval it currently influences. That second direction is the one systems omit, and it is the one you need on the day a calibration failure or a qualification lapse is discovered, when the only question that matters is which of your inspection dates are now unsupported.

Why does an uncorrected hot UT reading read thick rather than thin?

Because the instrument computes thickness from a velocity constant set at ambient, while the actual sound velocity in steel falls as temperature rises. With the assumed velocity higher than the true one, the calculated thickness comes out greater than the metal actually present. The commonly used rule of thumb is roughly a one percent shift per fifty-five degrees Celsius. That is non-conservative in the worst possible direction: it hides wall loss and extends the interval.

What is the correct handling for a reading thicker than the last survey?

Never silent acceptance of a zero corrosion rate. A thickness increase is physically impossible on a corroding component, so the reading, the previous reading, or the location is wrong. The engine should compare the increase against instrument repeatability, hold the pair as a data query, revert to the long-term rate anchored on the earliest reliable measurement, and mark the CML for confirmation on the next campaign. Recording that fallback is what makes the resulting interval defensible.

Why does offshore mobilisation cost change how strict the ingest should be?

Because a rejected dataset cannot be re-collected the same week. Persons on board, bed space, helicopter seats and weather windows are all hard constraints, and an inspection campaign is planned months out. If bad data is only discovered during a desktop review after demobilisation, the correction waits for the next campaign. Validation therefore has to run at submission, while the crew is still on the asset and a re-measurement costs an hour instead of a mobilisation.

How should sand erosion change the interval basis on a flowline?

By moving it off pure general-corrosion logic. Erosion concentrates at bends, tees, chokes and downstream of restrictions, and it scales with production rate, sand rate and velocity, none of which appear in a thickness trend until the metal is gone. The classic trap is treating the API RP 14E erosional velocity constant as an erosion prediction; it was never derived for solids-bearing service. Sand-prone circuits need targeted CML placement and a rate tied to production data.

Should quarantined data block the inspection plan?

No. A plan that stalls whenever a submission fails validation will be bypassed within a month. The correct behaviour is that the asset keeps its previous accepted interval while the query is open, the quarantined reading is visible on the asset and in a data-quality queue, and the interval only moves when the reading is accepted, corrected or formally rejected. Every one of those outcomes is recorded with an author and a reason.

Is API 510, 570 or 653 inspector training part of this offer?

No. Atlantis does not deliver API inspector certification training. Atlantis provides NDT training to ASNT SNT-TC-1A and ISO 9712 across Level I, II and III in UT, RT, MT, PT, ET, VT, PAUT and TOFD, together with ASNT Level III consulting, inspection management and reporting software, digital twins, 3D laser scanning and independent third-party report validation. API inspector certification remains with an accredited API training provider.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.