The audit does not test your readings — it tests what they join to

For an audit, the reading itself is rarely the finding. Auditors test whether each thickness value joins to a technician certified for that method on that date, an instrument with a calibration record for that day, and a documented reason for every CML not measured. Oil sands records fail on the exclusions and the joins, not on the numbers.

Oil sands add a record-keeping requirement almost no other industry has: slurry spools are rotated on a maintenance schedule to redistribute erosion wear, and once a spool turns ninety degrees the metal at the twelve o'clock CML is not the metal measured last quarter. A history keyed only to a fixed clock position silently compares two different points and reports a corrosion rate that never happened. The record has to carry the rotation event, the new orientation and the re-mapping, or every rate across that spool is void. Hydrotransport and tailings lines also wear in millimetres per month rather than per year, so a system that stores an annualised rate rounded to two decimals loses the very resolution the integrity engineer needs. Auditors ask for the raw readings and the rotation log together, because either alone proves nothing.

Source: Sources: Alberta Safety Codes Act and the Pressure Equipment Safety Regulation (AR 49/2006), administered by ABSA, including the quality management system expected of an owner-user inspection organization; CSA B51 for boiler, pressure vessel and pressure piping code; CSA Z662 for oil and gas pipeline systems; API 510, API 570 and API 653 for in-service inspection; API RP 571 for damage mechanisms including erosion, erosion-corrosion, naphthenic acid corrosion and sulfidation; API RP 939-C on avoiding sulfidic corrosion failures, including low-silicon carbon steel susceptibility; API RP 941 for high temperature hydrogen attack; ASNT SNT-TC-1A and ASNT CP-189 for personnel qualification, and ISO 9712 where used.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
What an auditor asks, which field answers it, and the finding when the field is absent
Auditor's questionField it lands onCommon finding when the field is missing
Show me the technician who took this reading and their certification on that dateTechnician identity plus certification level, method and validity window per readingInspection performed by personnel whose qualification for the method could not be demonstrated at the time of the work
Show me the calibration record for the instrument usedInstrument serial on the reading, joined to the verification record for that day and the reference block usedNo evidence that measuring equipment was verified prior to use, contrary to the accepted quality management system
Show me the CMLs on this circuit that were not measured, and whyExclusion record with coded reason, decision owner, date and review triggerInspection plan not executed as written, with no documented disposition of outstanding locations
Show me the two readings behind this corrosion rateImmutable reading rows referenced by the derived rate, not a stored rate valueRemaining life calculation could not be traced to source measurements
This spool was rotated last outage. Show me the mappingRotation event with prior and new orientation and the CML re-mapping it producedTrend data compared non-equivalent locations; corrosion rates not technically valid
Who changed this value after the report was issued, and whyPer-field change history with author, timestamp and reason for changeRecords altered without traceability; document control requirements not met

What an auditor actually asks for

Teams preparing for an audit usually rehearse the wrong thing. They tidy reports, re-print trend charts and confirm that remaining lives look sensible. The auditor, whether from ABSA reviewing an owner-user inspection organization's quality management system, a client's integrity assurance group, or a certifying body, does something quite different. They pick a small number of items almost at random and pull on each until something comes apart.

The pull goes like this. Take one piece of equipment. Show me its current remaining life. Show me the reading that produced it. Show me who took that reading and what certified them for that method on that day. Show me the instrument and its verification for that day. Show me the procedure they worked to and its revision at that time. Show me the inspection plan and which locations it called for. Show me the ones you did not do and what you decided about them. Each step is a join, and a record fails at whichever join it cannot make.

This is why an audit is not really a test of inspection quality. It is a test of whether your record was built as evidence or as reporting. A team can do excellent ultrasonic work and still fail, because the excellence lived in individuals and field notebooks rather than in a structure that survives their absence. Conversely a record with modest data quality but complete, honest attribution and a well-maintained exclusions register audits far better than most people expect.

The exclusions register is the first thing they open

In oil sands operations, the gap between the inspection plan and the executed campaign is wide and it is not a sign of poor performance. Lines run hot and cannot be gauged in service. Scaffold gets reallocated when a critical path job slips. Insulation removal is refused because the circuit is in service and the cladding will not go back on before weather. A CML sits under a pipe support shoe, which is both the place you most want to measure and the place you cannot reach. Produced water and sludge-handling equipment can carry naturally occurring radioactive material, and gaining access needs a radiation work permit that was not in the plan.

Every one of those is a defensible reason. None of them is defensible when it exists only as a memory. The exclusions register turns a gap into a managed decision: a coded reason, the person who accepted it, the date, the compensating measure if any, and the trigger that will lift it, usually the next outage. An auditor reading that register sees an organisation that knows where its blind spots are. An auditor finding blank cells sees an organisation that does not.

The register also has to be alive rather than archival. If a CML has carried the same exclusion for four consecutive outages, that pattern should surface in a report, because at that point the exclusion has quietly become a permanent decision that nobody ever formally made. This is one of the highest-value reports a thickness history can produce and one that no spreadsheet has ever produced spontaneously.

Rotating a slurry spool rewrites the geometry of your history

Oil sands hydrotransport moves a slurry of bitumen, sand, clay and water at velocities chosen to keep solids in suspension, and the quartz in that slurry is harder than the pipe. Wear is not corrosion; it is mechanical removal, concentrated at the invert of horizontal runs, at the outer radius of bends and downstream of any flow disturbance. Rates are quoted in millimetres per month on the worst spools, and the operating response is to rotate the spool on a schedule so fresh wall moves into the wear path.

That practice is entirely sensible and completely destructive to naive trending. Thickness histories are keyed to a location, usually a clock position on a station along the spool. After a rotation, the point labelled six o'clock is metal that used to be at nine or twelve, with its own quite different history. Compare the new reading to the old one at the same label and you get a large apparent thickness gain or a nonsense loss, and the corrosion rate that comes out of it never happened.

So the record has to treat the physical component and the measurement location as distinct things, with a rotation event that re-maps between them. Then the history can be read two ways: what has happened to this piece of metal, and what has happened at this position in the flow. Both matter. The first tells you when the spool is due for replacement; the second tells you where wear is being generated so the piping design can be changed. An auditor asking about a spool that shows a thickness increase will accept a rotation log immediately and will not accept anything else.

Erosion is not corrosion, and annualising hides it

The default arithmetic in most inspection systems assumes a roughly steady electrochemical process: loss accumulates gradually, an annual rate is meaningful, and remaining life is thickness margin divided by that rate. Erosive wear does not behave that way. It is proportional to throughput, particle loading and velocity, all of which change with ore quality, production rate and process upsets. A month of high sand content can remove what a normal quarter would.

Two consequences follow for the record. First, the reading interval on erosion-controlled circuits has to be short enough that the interval itself is not longer than the remaining life it is meant to protect, which sometimes means monthly or per-outage measurement rather than annual. Second, the history has to keep enough resolution to see rate changes. A system that stores an annualised rate rounded to two decimal places, or that averages across a circuit, will report a steady picture right up until a spool fails.

Storing throughput or operating hours alongside the readings converts a calendar rate into a rate per unit of production, which is both physically better founded and far more useful for planning. When the plant runs ninety days at elevated rate, the integrity engineer can predict the wear rather than discover it. That capability is not exotic, but it depends entirely on the reading history being granular, complete and joined to operating data instead of collapsed into a single trend line.

The upgrader is a different plant with different traps

Bitumen upgrading brings mechanisms that the mine and extraction side never sees. Naphthenic acid corrosion in hot crude and vacuum service is a function of total acid number, temperature, velocity and sulphur content, and it attacks in a smooth, gouged pattern that appears exactly where turbulence is highest. Sulfidation follows temperature and chromium content, so the material of construction determines the rate as much as the process does. Hydroprocessing units bring high temperature hydrogen attack, managed through API RP 941 and its Nelson curve relationships.

The trap that catches records rather than metallurgists is the low-silicon carbon steel problem described in API RP 939-C. Carbon steel with low silicon content sulfidises considerably faster than otherwise identical steel with normal silicon, and the difference is invisible from outside the pipe. A spool replaced during an outage with material from a different heat can thin at several times the rate of the run it sits in, and the thickness history will show a single anomalous CML that looks like a bad reading. Unless the record carries material identity and heat traceability against the component, nobody connects the dots until there is a leak.

Hot service also changes the reading itself. Ultrasonic velocity in steel falls as temperature rises, so an uncompensated reading on a line at three hundred degrees reads thicker than the metal actually is. The common field correction of roughly one percent of indicated thickness per hundred degrees Fahrenheit above ambient is an approximation that should be verified against a heated reference block for the alloy and the instrument in use. What matters for the record is that surface temperature at the time of measurement and the compensation applied are both stored, because a later engineer cannot otherwise tell whether the correction was made once, twice or not at all.

Certification and calibration are joins, not attachments

Most organisations hold their personnel certifications and their instrument calibration certificates, often carefully, in a document management system or a shared folder. That is storage, not integration. The audit question is never whether you possess a certificate; it is whether you can demonstrate that this particular reading was taken by someone qualified and with equipment verified, on that particular date. A folder of PDFs cannot answer that without a person spending an afternoon on it, and an auditor sampling ten readings will not wait.

Building it as a join is straightforward once the reading carries a technician identity and an instrument identity. The system then holds certification records with validity windows and calibration or verification records with dates and reference standards, and the answer becomes a lookup. It also becomes preventive rather than forensic: a reading captured with an instrument whose verification has lapsed, or by a technician whose vision check expired last month, can be flagged at the moment of capture instead of discovered in an audit two years later.

The same structure supports the awkward conversation that follows a lapse. If a technician's certification was found to have expired for six weeks, the immediate question is which readings fall in that window and what their consequence is. With the join in place that is a query returning a list. Without it, the honest answer is that you do not know, and the auditor's finding will be scoped to everything rather than to the six weeks it should have covered.

Turnaround data from four contractors and one written practice

An oil sands turnaround compresses an enormous amount of inspection into a few weeks. Multiple service companies mobilise, each with its own written practice, its own certification scheme, its own instruments and its own data formats. Readings arrive by the thousand, often as spreadsheets emailed at the end of a shift, and the integrity team's job during the outage is to make repair decisions faster than the data can be properly assimilated.

The audit exposure created here is specific and predictable. Which written practice governed each contractor's personnel: theirs, or the owner's? Did the owner review and accept it, and is that acceptance dated and stored? Were procedures approved by a Level III, and which revision was in force during the outage? When a contractor's technician recorded a reading against a CML that did not exist in the owner's register, what happened to it? These questions are almost never asked during the outage and almost always asked afterwards.

The practical remedy is to make the ingestion path the same for everybody and to make it refuse ambiguity at the edge. Contractors submit structured data with technician, certification reference, instrument serial, procedure reference and CML identity, and readings that cannot be matched to a known CML are held in a queue rather than dropped or force-fitted. The queue is uncomfortable to look at during a turnaround, which is precisely its value: it converts a silent data loss into a visible, assignable task while the crew is still on site.

Testing the record before the auditor does

The most useful preparation for an audit is to run one on yourself with the same method the auditor will use, and to do it on your least favourite unit rather than your best. Pick five pieces of equipment across different services: a hydrotransport spool, a SAGD steam line, an upgrader hot circuit, a produced water vessel and a storage tank. For each, start from the published remaining life and walk the chain of joins backwards until you either reach a mill certificate or hit a wall.

Record where each walk stops, because the stopping points are the audit findings you have not received yet. Typical stops are a corrosion rate with no retrievable inputs, a reading with an inspector's initials and no certification link, an instrument identified only as the shop unit, a CML that appears in the plan but has no readings and no exclusion, and a value that was changed after issue with no author. None of these are unusual and none are catastrophic; all of them are fixable if you find them yourself.

Then fix them additively. Do not delete the questionable history, mark it. A reading whose attribution is unknown at source is a legitimate historical record and should be labelled as such rather than removed or invented. An organisation that can show an auditor a quantified picture of its own data quality, with a dated remediation plan and evidence of progress, is in a much stronger position than one presenting a record that looks immaculate until the third question. Auditors are far more comfortable with known and managed weaknesses than with surprises.

Why do audits fail on exclusions rather than on readings?

Because readings that exist are self-evidencing and readings that do not exist require an explanation. An auditor sampling a circuit will find the gaps quickly: a plan calling for forty CMLs and a campaign delivering thirty-one. The question is never why the thirty-one are wrong; it is what happened to the other nine. If the answer is a shrug or a recollection, the finding writes itself, and it is a systems finding rather than a technical one.

What does rotating a slurry spool do to the thickness history?

It invalidates position-keyed trending unless the rotation is recorded. Hydrotransport lines wear preferentially at the invert and along the outer radius of bends, so operators rotate spools to move fresh metal into the wear path and extend service life. After a ninety degree rotation, the CML at the twelve o'clock mark sits over metal that was previously at three o'clock and has a completely different history. The rotation event and the re-mapping have to travel with the readings.

How current does a technician's certification have to be in the record?

It has to be demonstrably valid on the date of the reading, not merely valid today. Under an SNT-TC-1A based written practice, that means the certification level for the specific method, the annual near-vision and colour contrast differentiation checks, and the recertification interval the employer's written practice specifies. Storing only the technician's current status makes it impossible to prove qualification for work done three years ago, which is precisely the work being sampled.

Why does the instrument serial number matter on each individual reading?

Because it is the join key to the calibration and verification evidence. An auditor picks a reading, reads its instrument serial and date, and asks for the verification record covering that day, including the reference block or step wedge used and its traceability. Recording the instrument at campaign level rather than reading level breaks that join as soon as a technician swaps a unit mid-shift, which on a large turnaround happens routinely.

Is API 510, 570 or 653 inspector training part of this offer?

No. API inspector certification is administered by API's Individual Certification Programs and is obtained through them. Atlantis NDT provides NDT training to ASNT SNT-TC-1A and ISO 9712 across UT, RT, MT, PT, ET, VT, PAUT and TOFD, together with ASNT Level III consulting, inspection management and reporting software, digital twins, 3D laser scanning and report validation. The software records whichever certifications a technician actually held on each reading date.

How should turnaround readings from multiple contractors be handled?

As separately attributed data streams inside one record, each carrying its own technician, certification basis, instrument and procedure reference. A large oil sands turnaround can generate tens of thousands of readings from several service companies in a few weeks. The auditor will ask which written practice governed each contractor's personnel and whether the owner reviewed and accepted it. That acceptance should be a stored, dated record linked to the readings it covers.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.