What a reviewer checks before an owner-user accepts an API inspection report
A reviewer recomputes the report rather than reading it. Six checks decide acceptance: the inspector's certification status on the examination date, whether the examination extent met the code interval, thickness data quality and CML traceability, which corrosion rate was selected, the remaining-life and next-date arithmetic, and whether the written disposition follows from the numbers the report itself contains.
Acceptance is a legal act, not a filing step. When an owner-user signs a contractor's API 510, 570 or 653 report, the inspection interval, the corrosion rate and the next-inspection date in that report become the owner-user's mechanical integrity record, defensible in front of a regulator and in front of a jury. The contractor's certification does not transfer that liability back. The reports that fail review are rarely wrong about the metal. They are wrong about the paperwork that makes the metal finding usable: a thickness table with no CML map, a corrosion rate calculated across a service change, a next date that does not reconcile with the remaining life stated three pages earlier, or a recommendation deferred without the record entry the code requires. A validation review recomputes each of those from the report's own data, which is the only test an auditor will later apply.
Source: API 510, Pressure Vessel Inspection Code, Eleventh Edition, October 2022 — clauses 4.5, 5.7.1.3, 6.4.1, 6.5.1, 6.5.2.1, 6.8, 6.9, 7.1.1, 7.2.1, 7.8 and Annex B. API 653, Tank Inspection, Repair, Alteration, and Reconstruction, Fifth Edition, November 2014 carried through Addendum 3, November 2023 — clauses 3.4, 4.4.5, 6.3, 6.4, 6.8, 12.1.1.4, Annex G, Tables 4.4 and 6.1. API 570 interval, CUI and injection-point values verified in the Fourth Edition, February 2016 with Addendum 2, April 2018; the Fifth Edition, February 2024 is the current edition.
| Code and clause | Interval the report must justify | What the reviewer recomputes | Edition verified |
|---|---|---|---|
| API 510, 6.4.1 | External visual at the lesser of five years or the required internal/on-stream interval | Whether the external date was driven by the internal interval or set independently at five years | Eleventh Edition, October 2022 |
| API 510, 6.5.1.1 | Internal or on-stream at the lesser of one-half remaining life or 10 years; under four years remaining life, full remaining life capped at two years | Remaining life from the report's own thickness table, then halved and capped | Eleventh Edition, October 2022 |
| API 510, 6.5.2.1 | On-stream in lieu of internal only where every listed condition holds, including corrosion rate under 0.125 mm (0.005 in.) per year and remaining life above 10 years | Each listed condition individually, not the corrosion rate alone | Eleventh Edition, October 2022 |
| API 570, Recommended Maximum Inspection Intervals | Class 1: 5 years thickness and 5 years external. Class 2: 10 and 5. Class 3: 10 and 10. Injection points: 3 years thickness | Whether the assigned service class matches the actual service and consequence | Fourth Edition, February 2016 with Addendum 2, April 2018 |
| API 570, 5.8 | CUI inspection considered for externally insulated carbon and low-alloy piping operating between 10 °F (−12 °C) and 350 °F (175 °C) | Whether insulated circuits inside that band appear anywhere in the scope | Fourth Edition, February 2016 with Addendum 2, April 2018 |
| API 653, 6.3.2.1 | External inspection by an authorised inspector at least every five years or RCA/4N years, whichever is less | RCA/4N from the report's own shell thickness and corrosion rate | Fifth Edition through Addendum 3, November 2023 |
| API 653, 6.3.3.2 | External UT at five years where the corrosion rate is unknown; the smaller of RCA/2N or 15 years where it is known | Which branch the report claimed, and whether the rate supports the claim | Fifth Edition through Addendum 3, November 2023 |
| API 653, 6.4.2.1.1 and Table 6.1 | Initial internal at 10 years plus cumulative safeguard credits, capped at 20 years without a release prevention barrier and 30 years with one | Each credit claimed against documented evidence the safeguard is installed | Fifth Edition through Addendum 3, November 2023 |
Acceptance transfers the finding, not the liability
The owner-user owns the mechanical integrity programme. A contractor supplies data and a professional opinion; the owner-user decides whether that opinion becomes the record. Once accepted, the interval and next-inspection date printed in the report govern when that equipment is next opened, and the owner-user carries the consequence of running it to that date. API 510 makes the ownership explicit by requiring documented inspection results to be approved by the responsible owner-operator inspector, engineer or qualified designee. Approval is a decision the owner-user makes, and a decision can be wrong.
That is why acceptance deserves a separate technical pass. The reviewer is not re-inspecting the equipment and is not second-guessing the technician's hands on the probe. The reviewer is testing whether the document supports the conclusion printed on its cover page, using only what the document itself contains. Where it does not, the correct outcome is a returned report with specific defects listed, not an outage. The difference between those two responses is set out in third-party review versus re-inspection.
Check one: certification status on the date of the work
Three separate qualification questions sit inside one report and get collapsed into one signature. The first is the authorised inspector. API 510 Annex B makes recertification due three years from the date of certificate issuance, so a certificate valid at report issue can have been expired on the examination date weeks earlier. API 653 defines the authorised inspector as an employee of an authorised inspection agency who is qualified and certified under that standard. API 570 requires certification under its own Annex A. The reviewer checks the certificate against the examination date.
The second question concerns the NDE examiner, who is a different person under different rules. API 510 states plainly that the examiner needs no API 510 certification and need not be an owner-operator employee, but must be trained and competent in the procedures used, and names ASNT SNT-TC-1A, ASNT CP-189, CGSB and AWS QC1 as examples of certifications an owner-operator may require. The examiner's employer must maintain certification records including dates and results, available to the inspector — and API 510 places responsibility on the inspector to determine that all NDE examiners are properly qualified for the work performed.
The third question is method-specific and the one most often missed. API 653 requires examiners performing ultrasonic thickness measurements to hold ASNT UT Level II certification, full or limited, for either digital thickness measurement with numeric output only or A-scan thickness measurement, under SNT-TC-1A or an equivalent national standard recognised by the owner/operator. API 510 goes further for flaw work: where detection or through-wall sizing of internal flaws from the outside surface is required, the owner-operator shall specify industry-qualified UT angle beam examiners, which API defines as holding QUTE or QUSE detection and sizing qualification, or an owner-approved equivalent.
Check two: did the examination extent match the interval claimed
An interval is a claim, and a claim needs matching evidence. API 510 caps internal or on-stream inspection at one-half the remaining life or 10 years, whichever is less, and external visual at the lesser of five years or the required internal interval. Where remaining life falls under four years, the interval may be the full remaining life to a maximum of two years. A report assigning a ten-year interval must therefore also show remaining life of at least twenty years, computed from its own thickness data. Reviewers regularly find ten-year intervals sitting above remaining-life figures of twelve or fourteen years.
Substituting on-stream inspection for internal inspection has conditions, and failing reports typically satisfy one of them while ignoring the rest. API 510 permits the substitution where vessel entry is physically possible only when all listed conditions are met together: general corrosion rate known to be below 0.125 mm (0.005 in.) per year, remaining life greater than ten years, corrosive character established by at least five years of the same or similar service, no questionable condition found during the external inspection, shell temperature below the creep rupture range referenced in API 579-1/ASME FFS-1, and no susceptibility to environmental cracking or hydrogen damage.
On piping, the claim is the service class. API 570 sets thickness-measurement and external-visual maxima by class — five and five years for Class 1, ten and five for Class 2, ten and ten for Class 3 — with injection points on a three-year thickness interval, and the thickness interval further capped at half the remaining life. The reviewer tests whether the assigned class matches the actual service, because reclassifying a circuit from Class 1 to Class 2 doubles the thickness interval on paper without anyone touching the pipe.
Check three: thickness data quality and CML traceability
A thickness number without a location is not data. API 510 requires inspection records to document the date of each inspection and examination, the date of the next scheduled inspection, the name of the person who performed it, the serial number or other identifier of the equipment, a description of the examination performed, and the results. API 653 requires the inspection history to contain all measurements taken, the condition of all parts inspected, a record of all examinations and tests, and the corrosion rate and inspection interval calculations themselves. A table of bare readings fails both requirements.
The traceability test a reviewer applies is repeatability: could a different technician, on the next campaign, place the probe on the same square inch? That needs a CML identifier, a location description or sketch, the component the CML belongs to, and the design minimum for that component. Where the readings feed a corrosion rate, the previous campaign's readings must sit at the same CMLs. Comparing this year's grid against last year's different grid produces a number that describes surface variation, not metal loss.
Injection points deserve separate scrutiny because the code defines their boundaries explicitly. API 570 recommends the upstream limit of an injection point circuit at a minimum of 12 in. (300 mm) or three pipe diameters upstream, whichever is greater, and the downstream limit at the second change in flow direction past the injection point, or 25 ft (7.6 m) beyond the first change in flow direction, whichever is less. A report showing two CMLs at the quill and none at the downstream elbow has not inspected the circuit.
Check four: which corrosion rate the report actually used
API 510 defines both rates arithmetically. The long-term rate is the initial thickness at a CML minus the actual thickness, divided by the years between those two measurements. The short-term rate is the previous thickness minus the actual thickness, divided by the years between them. Both are computed at the same CML. The code then requires the inspector, in consultation with a corrosion specialist, to select the rate that best reflects current conditions — which means a report computing only one rate, or computing both and never stating which drove the interval, has skipped a required step.
The selection is where judgement becomes auditable. API 510 lists what must be considered: whether the damage mechanism is general or localised, areas subject to impingement or erosive-corrosive conditions, the estimated time the corrosion problem initiated, the point where a process change may have caused it, the effect of scale formation or the loss of that protection, accelerated corrosion in stagnant areas, continued operation within integrity operating windows, and whether a short-term rate arose from an episodic event since corrected. A reviewer looks for that reasoning written down.
On tanks, one exclusion is explicit and frequently violated. Where an API 653 internal interval is set by risk-based inspection, corrosion rates derived from low inspection effectiveness — spot ultrasonic readings are the named example — shall not be used in the RBI process. A tank report that stretches an internal interval on the strength of a handful of spot UT readings has used data the standard excludes for exactly that purpose, and the interval falls with the data.
Check five: remaining life and next-date arithmetic
This is the single most common defect, and it is a subtraction error. API 510 defines remaining life as the actual thickness at a CML minus the required thickness at that CML, divided by the corrosion rate. The required thickness is computed by the design formulas for pressure and structural loading, and expressly does not include corrosion allowance or manufacturer's tolerances. Reports routinely substitute nominal thickness minus corrosion allowance, or the original design thickness. Neither is what the code specifies, and each distorts the interval in a direction nobody has checked.
On tanks the minimum is not a single number. API 653 sets minimum bottom plate thickness at the next inspection at 0.10 in. where the tank bottom and foundation design has no means for detection and containment of a bottom leak, and 0.05 in. where it does, or where a reinforced lining thicker than 0.05 in. has been applied per API 652. The critical zone carries its own floor: the smaller of 0.118 in. or 50 % of the lower shell course minimum thickness, never below 0.10 in. — and averaging of bottom thickness is not permitted there.
Then the date has to reconcile. Take the report's own remaining life, halve it, cap it at the code maximum for that equipment and interval type, apply the short-life rule where remaining life falls under four years, and compare the result against the printed next-inspection date. Where the printed date sits later than the computed one, the report contradicts itself, and accepting it puts the owner-user on record as approving the later date. The API 510 programme requirements cover the surrounding obligations.
Check six: does the disposition follow from the data
A finding creates an obligation, and the obligation leaves a paper trail. API 510 states that recommendations not completed by the required due date, without a documented and approved change of date, are not permitted by the code and are considered overdue, and that equipment shall remain within its minimum required thickness throughout any deferral period. Separately, inspector recommendations can be changed or deleted only after review by a pressure vessel engineer or by inspection supervision — and the records shall capture the reasoning, the date of the change or deletion, and the name of the person who reviewed it.
API 653 sets its own conditions for deferring an internal inspection, and a reviewer checks each one against the file. Among them: the deferral request has the written agreement of an authorised inspector and the tank owner/operator; an API 653 external inspection has been completed within 12 months before the current internal inspection due date; the owner/operator has stated a valid reason and documented an assessment of alternative measures considered; and the tank records carry the deferral documentation before the tank operates beyond the due date. A verbal agreement recorded nowhere fails all four.
Finally, the clock. API 510 requires documented inspection results to be approved by the responsible owner-operator inspector, engineer or qualified designee, and states they should be posted into the inspection data management system within 90 days of completion of the inspection or start-up. A report accepted but never loaded is invisible to the next interval calculation, and the gap between acceptance and loading is what an OSHA PSM mechanical integrity audit surfaces first.
Tank-specific traps that only appear on API 653 reports
Interval credits must match installed hardware, item by item. API 653 builds the initial internal interval from a ten-year base plus cumulative safeguards: five years for a thick-film reinforced product-side lining installed per API RP 652, two years for a thin-film or unreinforced thick-film lining, five years for soil-side cathodic protection installed, maintained and inspected per API RP 651, ten years for a release prevention barrier per API 650 Annex I, ten years for a qualifying stainless bottom, plus a thickness credit where the initial bottom exceeds 6.0 mm (0.25 in.). Every credit claimed needs installation evidence in the file.
The caps are absolute outside a risk-based programme. Initial and subsequent internal intervals shall not exceed 20 years for tanks without a release prevention barrier, or 30 years for tanks with one. A report arriving at 24 years on a tank with no barrier has stacked credits past a ceiling. The external side has its own arithmetic: external inspection at least every five years or RCA/4N, whichever is less, and external UT at five years where the corrosion rate is unknown, or the smaller of RCA/2N and 15 years where it is known.
Bottom scanning brings a qualification requirement most reports omit entirely. API 653 Annex G requires the authorised inspection agency to qualify every examiner it employs — both scanning operators and those proving up indications — by examination on test plates, and states that only third-party companies with no conflict of interest in tank bottom examination, or owner/operator companies, may facilitate those qualification tests. The examiner qualification record must capture the essential variables, the test results, training hours and the written examination score. See API 653 tank inspector services and tank inspection intervals explained.
What the review returns to the owner-user
The output is a defect list an owner-user can act on without a technical argument: each item tied to the clause it fails, the page it appears on, and the recomputed value wherever arithmetic is involved. Items split into three dispositions — return to contractor for correction, accept with a documented owner-user note, or escalate to re-inspection because the underlying data cannot support any interval at all. Most reports come back with correctable documentation defects. A minority reveal that the examination itself was too thin to conclude anything.
That distinction is the value. Re-inspection is expensive and disruptive; returning a report for correction costs one revision cycle. Knowing which of the two a report needs, before the acceptance signature rather than after, is what independent validation provides, and the underlying standard for a defensible document is set out in what makes an NDT report defensible. Atlantis reviews API 510, 570 and 653 reports as an independent party. Affordable, accessible, fully customizable — request a quote or a sample review.
Can an owner-user accept a report signed by an inspector whose certificate expired after the work?
Yes, where the certificate was in force on the examination date. API 510 sets recertification three years from the date of certificate issuance, so the test is the date the examination happened, not the date the report issued or the date acceptance is signed. A reviewer records the examination date, the certificate number and its expiry, then compares the first against the third.
What thickness goes into the remaining-life calculation?
API 510 defines remaining life as actual thickness at a CML minus required thickness at that CML, divided by the corrosion rate. Required thickness comes from the design formulas for pressure and structural loading, and expressly excludes corrosion allowance and manufacturer's tolerances. Substituting nominal thickness minus corrosion allowance is the most common arithmetic defect found in vessel reports.
Short-term and long-term corrosion rates disagree — which one sets the interval?
API 510 requires the inspector, in consultation with a corrosion specialist, to select the rate that best reflects current conditions, and lists the factors to weigh: general versus localised damage, impingement and erosive-corrosive conditions, when the problem initiated, process changes, scale formation or its loss, stagnant areas, operation within integrity operating windows, and whether a short-term spike was episodic and has been corrected.
Does an on-stream inspection satisfy the API 510 internal inspection requirement?
Only where every listed condition holds together. General corrosion rate known to be below 0.125 mm (0.005 in.) per year, remaining life above ten years, corrosive character established by at least five years of the same or similar service, no questionable condition found during the external inspection, shell temperature below the creep rupture range, and no susceptibility to environmental cracking or hydrogen damage.
How quickly must accepted inspection results reach the data management system?
API 510 requires documented results to be approved by the responsible owner-operator inspector, engineer or qualified designee, and states they should be posted into the inspection data management system within 90 days of completion of the inspection or of start-up. A report accepted but never loaded does not influence the next interval calculation and is invisible to an audit.
Can an API 653 internal inspection be deferred past its due date?
Yes, under stated conditions the reviewer checks individually. The deferral needs written agreement from an authorised inspector and the tank owner/operator, an API 653 external inspection completed within 12 months before the current internal due date, a documented valid reason with an assessment of alternative measures considered, and tank records updated with the deferral documentation before the tank operates past the date.