← All articles

The Audit Tests Your Documents, Not Your Intentions

By XNM Technologies · August 13, 2026 · 6 min read

There is a particular kind of regulatory finding that operators dread, and it is not "your asset failed." It is "you could not show us." In June 2026 the Canada Energy Regulator published the results of a facility integrity management audit in which all six regulatory requirements evaluated were deemed non-compliant. Read the findings and a pattern emerges that has remarkably little to do with steel in the ground: procedures that did not meet the regulator's definition of a process, training guides carrying no evidence of management approval, outdated integrity documentation, hazards not consistently captured in the corporate register, and a risk methodology that was not formally approved or traceable.

That is the uncomfortable arithmetic of a modern compliance regime. An auditor cannot inspect your intentions, your engineering judgment, or the competence of the people doing the work. They can only inspect the record those things left behind. A management system is, by definition, a documented one - if a process is not written, controlled, approved and traceable, then for regulatory purposes it does not exist, however diligently the work is actually performed in the field. Energy and utility operators run some of the longest-lived and most heavily documented asset bases in the country, and the paperwork is not administrative overhead sitting beside the safety case. In regulatory terms, it is the safety case.

Recent context

The example is public and specific. A Canada Energy Regulator facility integrity management audit published on 30 June 2026, covering an audit period from September 2025 to January 2026, assessed six regulatory requirements and found all six non-compliant - a zero per cent audit score. The findings are worth reading closely precisely because they are about documentation governance rather than asset condition: management-of-change documents that "do not meet the definition of a process as defined by the CER and are not linked to the MOC process"; uncontrolled training guides lacking "evidence of approval by the appropriate management authority"; and a risk-based methodology under the maintenance, reliability and inspection program that "is not formally approved or traceable." Audits of this kind ordinarily lead to a corrective action plan. The instructive part is not the operator. It is the failure mode.

Why documentation governance decays quietly

Nobody decides to let a management system drift. It happens in increments that each look entirely reasonable at the time. A procedure gets updated in a working file and the controlled copy is never replaced. A training guide is written by a capable person who never routes it for approval, because everyone already agrees with it. A hazard is identified during a site review and captured in that review's own record, but never lands in the corporate register. A risk method is applied consistently for years by people who understand it thoroughly - which is exactly why nobody ever bothered to formalize it. Each of these is invisible from the inside. The work carries on, the assets stay safe, and nothing signals a problem. The drift becomes visible in precisely one circumstance: when someone external asks for evidence. By then the gap is years wide, and closing it under audit conditions costs far more than maintaining it ever would have. The distance between "we do this" and "we can show we do this, and that this is the approved current version" is where compliance is actually won or lost.

Six requirements assessed, none met - an audit score of zero. The findings behind that number are almost entirely documentary: procedures that did not meet the regulator's definition of a process, training guides without evidence of management approval, and a risk methodology that was not formally approved or traceable. It was not the asset that failed the audit. It was the evidence.
Six requirements assessed, none met - an audit score of zero. The findings behind that number are almost entirely documentary: procedures that did not meet the regulator's definition of a process, training guides without evidence of management approval, and a risk methodology that was not formally approved or traceable. It was not the asset that failed the audit. It was the evidence.

How XNM helps

XNM helps energy and utility operators - and other heavily regulated organizations - close the gap between practice and provable practice. In practical terms that means one governed place for the documents a regulator will ask about: procedures and their approval history, management-of-change records, inspection and maintenance evidence, hazard and risk registers, and the training and competency files behind them, with version control that makes the current approved copy unmistakable and keeps the superseded trail intact. Where it fits, XNM-Vision holds that record as a command centre rather than a shared drive - current versions unambiguous, approvals attached to what they approve, and an evidence request answered by producing a file instead of assembling one. The aim is narrow and practical: that on the day an audit letter arrives, the answer is already on the shelf.

Practical takeaways

  1. Ask the evidence question, not the practice question. "Do we do this?" will always get a yes; "can we produce the approved current version and show who approved it?" is the question an auditor is actually asking.

  2. Make controlled and uncontrolled copies distinguishable at a glance. An uncontrolled working file that looks identical to the approved one is how a perfectly good procedure becomes a finding.

  3. Attach approvals to documents, not to memories. If approval lives in an email thread or in the fact that everyone agreed at the time, it is not evidence - route it, record it, and keep it with the document it approves.

  4. Make the corporate register the single destination. Hazards, risks and changes captured in local records but never landed in the register are, from an auditor's seat, simply uncaptured.

  5. Audit yourself on traceability before someone else does. Pick three requirements at random and try to produce the full evidence chain within an hour; whatever you cannot produce is your real finding list.

FAQ

Our engineering is sound and our assets are safe. Does documentation really carry this much weight?

From the regulator's side of the table, it carries essentially the whole weight. An auditor has no mechanism to verify sound engineering except through the record it produced - the approved procedure, the completed inspection, the traceable risk assessment. A non-compliance finding on documentation is not a statement that the work was done badly; it is a statement that it could not be demonstrated. The consequences, and the follow-on scrutiny, are real either way.

We already have a document management system. Isn't this solved?

A repository stores files; a governed record answers questions. The findings that actually hurt in audits are rarely "the file does not exist." They are "this is not the approved version," "we cannot show who approved it," or "this was never linked to the process it belongs to." Those are governance properties rather than storage properties, and a system only delivers them if it is configured, maintained and used that way.

The bottom line

A zero per cent audit score makes a striking headline, but the useful part is how ordinary the underlying failures are. Uncontrolled guides, unapproved methods, hazards recorded in the wrong place - none of these require negligence, only time and the absence of a governing system. Every regulated operator has some version of this drift somewhere in its file room. The ones that do not end up on the wrong side of an audit report are the ones that go looking for it themselves, on a schedule, before a regulator does it for them.