Trusting third-party UT data on an HRSG and its balance of plant

A thickness reading is only evidence if you know when it was taken, by whom, with which instrument and by which method. In a combined-cycle plant most readings come from contract crews, so the history module's real job is to preserve that provenance on import, flag readings it cannot verify, and record every planned point that was not read and why.

In a gas or combined-cycle plant the thinning that matters is rarely uniform general corrosion. Flow-accelerated corrosion attacks carbon steel in the LP evaporator, economizer inlets and feedwater and heater-drain piping, concentrated in the roughly 130-260 C band and made worse by low chromium content, reducing all-volatile treatment and two-phase flow at elbows and downstream of orifices. Damage is local, sometimes a scallop a few inches across, and it moves as the plant's dispatch pattern changes. That means the trend at a single CML carries the whole argument, and the trend is destroyed by anything that changes what was measured rather than what is there. Contract crews rotate between outages. Instruments change. One crew reads through the coating, the next uses echo-to-echo and drops eight thousandths overnight. A history module that stores only a number and a date cannot tell you which of those two things happened, and both look identical on a chart.

Source: Sources: ASME Section I and ASME B31.1 for HRSG pressure parts and boiler external piping; National Board Inspection Code NB-23 for repairs and alterations; EPRI flow-accelerated corrosion guidance and CHECWORKS predictive modelling; API 579-1/ASME FFS-1 Parts 4 and 5 for local metal loss and local thin area assessment; ASTM E797 practice for manual pulse-echo thickness measurement; ASNT SNT-TC-1A and ANSI/ASNT CP-189 for UT personnel qualification; OSHA 29 CFR 1910.119, in particular 1910.119(j) mechanical integrity, where the SCR anhydrous ammonia system is a covered process.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Contractor data defects, how they surface in a thickness trend, and the field that would have caught them
Defect in the delivered dataHow it surfaces in the trendWrong conclusion it producesWhat the history record must hold
Read through coating in single-echo modeStep increase of 0.2 to 0.5 mm at one outage, then flatWall gained metal, so the line is declared stableMeasurement mode per reading: single echo, echo-to-echo or interface echo
Dual-element probe doubling on a thin wallOne reading near twice nominal, usually deleted or quietly averaged inGrid mean rises and the local thin area is maskedProbe type, element configuration, frequency and instrument minimum range
No temperature correction on a 200 C lineA consistent over-read of roughly 3 percent, only at hot CMLsCorrosion rate under-stated on the hottest and fastest-thinning pointsSurface temperature at time of reading and whether a correction was applied
Grid point relocated by a new crewSawtooth trend that alternates thin and thick each outageRate computed from repositioning noise, replacement scoped earlyDatum weld, offset and orientation, plus a photo or sketch reference
Point skipped, cell left blank or back-filled from last timeZero apparent corrosion at exactly the inaccessible pointsThe points nobody can reach look like the healthiest on the unitAn explicit exclusion code, the reason, and who authorised it
Instrument outside calibration on the day of the readingNothing visible at allA whole outage of data survives an audit it should not haveInstrument serial number and calibration due date bound to each reading

Combined-cycle thinning does not behave like refinery thinning

A refinery corrosion loop has a chemistry you can name and a rate you can defend across years. A combined-cycle plant has a duty cycle that follows the power market. The same HRSG that ran baseload a decade ago now starts several times a week, and its damage mechanisms track dispatch rather than process. Flow-accelerated corrosion in the LP evaporator, economizer inlet headers, feedwater piping and heater drains is governed by temperature, pH, dissolved oxygen, chromium content and local hydrodynamics, every one of which shifts when the unit cycles. A rate derived from a baseload decade does not predict a cycling one.

That makes each individual reading unusually load-bearing. FAC damage is local. It appears as a scalloped patch a few inches across downstream of an orifice, a control valve or a tee, thinning fast while the CML eighteen inches away loses effectively nothing. There is no general corrosion signal underneath to average against and no comfortable statistical floor. If the grid moved, the probe changed, or the coating was left in place, the artefact is the same order of magnitude as the damage you are trying to detect.

The honest statement about a combined-cycle thickness programme, then, is that its accuracy is bounded by the consistency of the crews taking the readings. In this industry those crews are almost never yours. They are mobilised for an outage, demobilised, and frequently a different company entirely by the next one.

What a contractor deliverable usually loses on the way in

The typical package is a PDF report with a cover sheet and an Excel workbook with three useful columns: point identifier, nominal, and reading. The instrument is named once in an appendix. The probe is named once for the whole job. The technician is named on the cover, even though the readings were taken over six shifts by three people. Whatever provenance existed lives in prose, and the moment the workbook is loaded it collapses into a tuple of point, date and number. Every one of the failure modes in the table above becomes invisible at that instant.

The fix is unglamorous and specific. Provenance has to bind at the level of the individual reading, not the job: technician identity with certification method, level and expiry as of that day; instrument serial with calibration due date; probe type, element configuration and frequency; couplant; measurement mode; surface temperature; surface condition and what preparation was done; the nominal and the governing minimum thickness in force at that time; and the datum used to locate the point. The import batch itself must be an object too, holding the source file, its hash, who loaded it, when, and what the loader rejected.

An import that cannot fail is not an import, it is a paste. The loader needs rules that stop a batch: a reading against a point that does not exist, a reading from an instrument whose calibration lapsed before the date on the row, a technician with no valid certification on that date, a value above nominal plus mill tolerance, a value below the governing minimum with no accompanying flag. Rejected rows go into a quarantine the contractor is asked to resolve, not into the trend.

A negative corrosion rate is the cheapest diagnostic you own

Metal does not grow back. Any point that reads thicker than it did last time is telling you that something in the measurement changed, and it is telling you for free. Yet most spreadsheets and a surprising number of commercial systems clamp negative rates to zero, on the reasoning that a negative rate is physically meaningless. It is. That is precisely why it is worth reading.

There are three common causes and they are distinguishable if the provenance survived. First, coating: a crew working in single-echo mode with a couplant film on painted steel adds the coating to the wall, typically two to twenty thousandths of an inch, whereas echo-to-echo mode ignores it. Second, relocation: the new crew re-established the grid from a different datum and is measuring different steel. Third, doubling, where a dual-element probe on a wall below its usable range locks onto the second backwall echo and reports roughly twice the true thickness.

Work an example. A 0.375 inch nominal feedwater elbow reads 0.311 inch in one outage and 0.331 inch in the next. Taken at face value that is a gain of twenty thousandths and a corrosion rate of zero, which closes the case. Taken as a data-quality event, it is a twenty-thousandths coating on a point that has already lost seventeen percent of wall, and the real rate is still running. The difference between those two readings of the same pair of numbers is whether the record kept the measurement mode.

Temperature, velocity, and the reading that is thick only on paper

Longitudinal sound velocity in carbon steel falls as temperature rises, by roughly one percent for every 55 C above ambient. An instrument calibrated on a step block in the workshop and then used on a hot line computes thickness from a velocity that is too high, and therefore over-reads. On a feedwater line at 200 C, calibrated at 20 C, that is about three percent. On a 9.5 mm wall it is close to 0.3 mm of wall that does not exist.

The correction is arithmetic a technician can do in their head. The problem is not the correction, it is that the temperature was never recorded, so you cannot apply it afterwards and, worse, you cannot tell a corrected value from an uncorrected one. A history module that stores a single number per point has already destroyed the distinction. It has to store the raw reading, the correction factor and its basis, the corrected reading, and an explicit statement of which value the corrosion rate is computed from.

The same discipline applies to the calibration itself. Calibrating on a five-step block of unknown provenance and then measuring a different alloy imports a velocity error into every reading of the outage. Record the block or reference sample used, its identity, and the velocity the instrument was set to. When two outages disagree by a percent and a half, that field is usually the answer.

Exclusions are data, and blanks are a lie

Every outage produces points that could not be read. The scaffold was not built. The insulation was not opened because the removal crew ran out of window. The line was still above the couplant's temperature limit. A valve body, a support shoe or a pipe clamp sat over the CML. The cladding was intact but the jacket screws sheared. These are ordinary, and they are not failures of the inspection crew. What is a failure is recording them as nothing.

When a skipped point comes back as a blank cell, three things happen. Coverage reports show a number close to a hundred percent because the denominator quietly shrank. The corrosion rate at that point stays at whatever it was, which is often zero. And the points that are hardest to reach, which for structural reasons are frequently the points nearest the failures you fear, present as the healthiest assets in the fleet. Back-filling last outage's value is the same error with the evidence removed.

An exclusion record needs a coded reason drawn from a governed list, the person who authorised it, and a link to what would have to change for the point to be read next time. That last field is what turns exclusions into a work list. If the module can produce a report of every CML excluded for two or more consecutive cycles, ordered by remaining life at last successful reading, it has paid for itself before anyone looks at a trend chart.

Score the contractor instead of arguing with the contractor

Data quality disputes after an outage go nowhere because both sides are reasoning from the same impoverished file. The way out is to instrument the deliverable in advance. Seed roughly five percent of the grid as blind repeat points, read by a different technician on a different shift without either being told. The spread on those points is your reproducibility, measured on your steel, in your conditions, with that crew.

From there the metrics are all things the deliverable already contains. Percentage of readings with complete metadata. Standard deviation across seeded repeat pairs. Count of readings that exceed the prior reading beyond combined uncertainty. Exclusion rate against the agreed scope, split by reason. Number of resubmissions before acceptance. Days from last reading to accepted delivery. None of this requires the contractor's cooperation to compute, and all of it is defensible.

Then use it. Publish the scorecard back after every outage, with the specific rows that failed, and carry the running score into the next tender as a weighted evaluation criterion alongside price. Contractors respond to being measured on something they can control. The plants that solve this problem do not solve it with a better clause about accuracy, they solve it by making data quality a line item that affects who wins the next job.

The regulatory boundary that runs through the middle of the plant

A combined-cycle site is not uniformly regulated. Natural gas burned as fuel for the facility's own consumption is outside OSHA process safety management, so the HRSG and its feedwater train are governed by ASME Section I, B31.1, the jurisdictional boiler inspector and the National Board Inspection Code when repairs happen. Meanwhile the SCR system's anhydrous ammonia storage, above the threshold quantity, is a covered process, and its piping and vessels fall under 1910.119(j) mechanical integrity with documented inspection and test results and mandatory correction of deficiencies.

So on any given day one crew, moving across one site, generates readings that belong to two different record regimes with different retention, different deficiency-closure obligations and different audit exposure. Aqueous ammonia at typical dilution changes that picture again. Plants that keep two systems for this end up with two truths, and the ammonia records are usually the ones nobody can find during an audit.

The module answer is a per-asset regulatory classification carried on the equipment record and inherited by every CML beneath it. Readings on covered equipment then enforce the extra fields, block closure of an inspection with an open deficiency, and export in the form the PSM audit expects, while readings on the HRSG follow the boiler regime. One system, one import, two behaviours.

Questions to put to a vendor before you sign

Ask to see an import fail. Hand over a workbook with one row from a lapsed instrument, one from an uncertified technician, one value above nominal and one blank cell where a reading was scoped, and watch what the loader does. A system that swallows all four and produces a clean trend chart is the system that will lose your data quietly for four years. Ask what the quarantine looks like and who is notified.

Ask whether the raw and corrected values are both retained, and whether the corrosion rate can be recomputed on demand under a different convention without editing history. Ask whether an exclusion can exist as a record. Ask to see the audit trail on an edited reading, including the prior value, the reason and the approver. Ask whether the technician certification held on the record is the one valid on the reading date or the one valid today, because those are different questions and only one of them is useful in an audit.

Finally, ask what leaves the system. Thickness histories outlive vendors. The export must be complete, human-readable, and independent of the application that produced it, with every provenance field intact rather than a printed trend chart. If a vendor cannot demonstrate that in a session, the answer to how your data will look in fifteen years is already known.

What must a thickness reading carry besides the number?

At minimum: date and time, the technician with certification method, level and expiry as of that day, instrument serial number and calibration due date, probe type and frequency, couplant, measurement mode, surface temperature, surface condition and preparation, the nominal and minimum thickness in force at that moment, the datum used to locate the point, and the import batch the value arrived in.

Why do negative corrosion rates matter more than high ones?

Steel does not grow. A reading higher than the last one is a measurement change, not a condition change, so it is a free diagnostic on the whole data set. Most spreadsheets clamp negatives to zero and lose the signal. Surface every reading exceeding the prior by more than combined uncertainty, and treat it as a contractor data-quality event rather than a condition finding.

How should the module treat a CML that was not read?

As a first-class record, never a blank. Store an exclusion with a coded reason, the authorising person, and whether the same point was excluded in prior cycles. A point missed three outages running is the highest-value item in next outage's scope. Systems that store blanks cannot produce that list, and systems that carry forward last outage's value actively hide it.

Is API 510, 570 or 653 inspector training part of this offer?

No. API inspector certification is administered by API and its examinations sit outside what Atlantis delivers. Atlantis provides NDT training and certification support to ASNT SNT-TC-1A and ISO 9712 across Level I, II and III in UT, RT, MT, PT, ET, VT, PAUT and TOFD, plus ASNT Level III consulting, inspection management software, reporting software and digital twins.

Does the SCR ammonia system change the record-keeping requirement?

It can. Anhydrous ammonia above the threshold quantity makes that system a covered process under OSHA 29 CFR 1910.119, so its mechanical integrity records must meet 1910.119(j), including documented inspection and test results and correction of deficiencies. The HRSG feedwater line beside it usually is not covered. One crew, one day, two record regimes, so the module needs a per-asset regulatory flag.

How do we compare two contractors on data quality rather than price?

Score them on things the deliverable already contains: percentage of readings with complete metadata, spread on seeded blind repeat points, count of negative-growth flags, exclusion rate against agreed scope, number of resubmissions and days to deliver. Publish the scorecard back to the vendor after every outage and carry it into the next bid evaluation as a weighted criterion.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.