Those who deal with OSHA’s PSM and EPA’s RMP regulations on a daily basis know all about the 3-year audit schedule we are required to maintain; but what many professionals responsible for PSM/RMP compliance may not know, is there are as many BAD audits done each year as there are GOOD audits. Sadly, we get proposal request for BAD audits on a monthly basis and although it is tough to walk away from a new client, we do so when the manner in which the potential client wants their audit done does not align with our audit methodology and expectations. Just how long should a PSM/RMP audit take, how many auditors should participate, what kind of background is necessary for a process safety auditor, and to what level of detail is needed are just a few of the many questions I will try to cover in this article. But as I said, there are just a few “compliance requirements” that must be met, the rest of what I say is based on true process safety and not necessarily driven by compliance with a government regulation.
First let’s lay out the ground rules for ALL audits that are done in order to comply with OSHA/EPA audit requirements. It should be no surprise that the two standards have identical audit requirements and it should also be no surprise that these regulatory requirements are the ABSOLUTE BARE MINIMUM requirements for an audit. Both OSHA and EPA have published some extensive checklist OSHA’s Checklist and EPA’s Checklist) that auditors should use as a GUIDE and a means to document the audit scope and level of audit detail. I never recommend “audit by checklist”, especially when conducting a process safety audit. There is just NO WAY that any one checklist can adequately cover each type of PSM/RMP covered process; much like the way OSHA ended up writing one PSM standard that is to be adapted to all covered processes. But when we conduct an audit of these processes, we should be digging much deeper than any of these OSHA and EPA published checklists take us.
Every three years facilities are required to CERTIFY that they have evaluated compliance with provisions of PSM/RMP to verify that the procedures and practices developed under the standard(s) are adequate and are being followed. The compliance audit must be conducted by at least one (1) person knowledgeable in the PSM/RMP covered process (MUCH MORE on this requirement later on). The audit team must develop a report of the findings and the facility management must PROMPTLY determine and document an appropriate response to each of the findings from the compliance audit, and document that deficiencies have been corrected. And lastly, the facility shall retain the two (2) most recent compliance audit reports. First thing many process safety professionals notice is the “squirrelly” wording used in these requirements! For instance, line up 50 safety/EHS/Process Safety professionals and ask each one to define “knowledgeable” and “promptly” in the context they are used in the standards. Do any of us think for one second that we can get 100% agreement on quantifying these terms? Of course not, and this is just one of the many reasons why we should ALWAYS view OSHA and EPA standards as “building blocks” to world-class process safety performance and not the end-all of our process safety efforts.
So let’s break down these five (5) audit requirements and discuss the pro’s and con’s in the manner companies tend to comply:
1) Employers shall certify that they have evaluated compliance with the provisions of this section at least every three years to verify that the procedures and practices developed under the standard are adequate and are being followed.
Twenty years into PSM (and 13 years into RMP), this is not as big a deal anymore, but in the early days the BIG QUESTION looming over everyone was… “when do I have start auditing my system?”. The standard became effective on May 26, 1992, but we had until May 26, 1997 to have all of our first round PHA’s completed; so many assumed this was when the “audit clock started to tick”. I disagreed with that and I always followed the May 26, 1992 schedule. In my eyes, as a safety manager at the time responsible for Process Safety, the last thing I wanted to do when getting started implementing my PSM programs was to put a ton of time and resources into PSM, only to find out five years later that what we did was WRONG! And trust me; in the early years of PSM, making mistakes was very common. Of course there are those who would argue that “no one knew what was expected so where in the heck would you find qualified auditors?” I would agree that there was much confusion when PSM came out, even OSHA was not 100% sure of themselves in the early years, but just as I said earlier, I wanted to know we were implementing a “process safety management system” and not just checking off on OSHA compliance requirements. Being a participant in VPP back in those days I went shopping for a PSM Mentor company who was already doing process safety because it was a “competitive business advantage” in their eyes. I was lucky and found such a company, as well as a great personal mentor in all facets of industrial safety. We had this mentor bring his entire PSM team to our plant for a week to train us in what process safety was suppose to look like, act like, smell like, and sound like and this is where we learned that 29 CFR 1910.119 was just scratching the surface of true process safety practices. Each year we had this team come back and “audit” our work as we progressed. And after each annual audit, we felt both a sense of accomplishment in all the work we had done, as well as a sense of direction for the next years work.
Some will notice the use of the word “certify” in the language of the standard. Many will read this to mean that someone from the facility must certify the audit report and you and I would be in agreement. Why did OSHA and EPA use this language? Simply, they knew that many reports are received from 3rd party consultants only to be buried or just thrown out. They did not want this to occur with process safety audits.
2) The compliance audit shall be conducted by at least one person knowledgeable in the process.
This short and concise wording is without a doubt the one aspect of PSM/RMP auditing that drives most process safety professionals crazy. I have been involved in debates where some in the field believed OSHA meant that the “person knowledgeable in the process” was that they knew the “audit process”. Then there was the camp that assumed OSHA meant the person knew “all about the process”. Which do you think is correct?
I personally go with the requirement as it relates to the physical process being audited and I would also like to point out that this is a CRITICAL PATH in my eyes. With this said, I also want to caution some that there are some companies out there who will “certify” you as a “process safety auditor” and there are some companies out there who require this certification of any person who will audit their process (contractors and in-house personnel). Having some close friends and colleagues who have participated in this “auditor certification” felt that the “certification process” should have had a prerequisite… to have developed, implemented and managed process safety management system or been responsible for the day to day management of a process safety management system. In their opinion, and mine, to many consultants are getting this certification by attending a one week course and then being branded as an expert process safety auditor. This is a problem!
I have always taken a different approach to evaluating my auditors. Yes, you heard me right, I evaluated each auditor against the elements they will be auditing. I did this very much like we evaluate our contractors who will be working in, on, and adjacent to our covered process(s), but was more focused on skill sets rather than OSHA rates and EMR’s. For example, the person who would be auditing our PHA’s should have experience in facilitating PHA’s, especially with the methodologies the facility had used in the past. Imagine hiring someone to audit your PHA(s) only to find out they had never led a PHA and only participated in What-If’s and all of your PHAs were done using the Hazard and Operability (HAZOP) methodology. How good do we really think this audit of your PHAs will be? Now if all we want is a report with few findings, then I would say those folks are on the right path; but those who really want an in-depth look at the PHA’s will be sorely disappointed. As my mentor told me… hiring someone to audit your PHA’s who has never utilized the methodologies used in your PHA’s is like asking me to audit a diesel mechanic’s work based on the fact that I have driven several diesel vehicles in my professional career! Just because I have driven vehicles with diesel engines does not make me knowledgeable in the workings of a diesel engine!
I have taken this approach for all of my critical elements: PSI, PHA, SOP/SWP, MOC, PSSR, II, Contractors, ER. I may let a rookie audit the EP, TS, and CA elements but that would be all they could audit on their own.
So what did OSHA intend with their wording… “person knowledgeable in the process”? Did they mean an operator, engineer, or manager from the actual chemical process or did they mean someone knowledgeable in how a PSM audit should be conducted? Well one reason why this is still being debating is that they have never really drawn the line in the sand and said! The best source of information we can turn to is the PSM Preamble where what OSHA stated may surprise some.
In the original PSM draft standard, OSHA used the term “team” in the audit requirement. They received a lot of feedback about the use of the word team and agreed that some audits will not be conducted by a team and such the word should be revised. Which they did and so we ended up with the revised wording “by at least one person knowledgeable”. That’s it! Nothing more, but from what some would call a “common sense approach” (their words not mine), OSHA feels their wording is clear in that the “one person” must be knowledgeable in the physical process being audited.
With that said, let’s attempt to define the term “knowledgeable”. The first question I have is “knowledgeable” in what? Just to say someone is “knowledgeable” can be downright scary! But I do think we could get a consensus that the person needs to know and understand 1910.119 requirements and to be a REALLY GREAT auditor they should understand how all 14 elements work together to form an all encompassing process safety “MANAGEMENT SYSTEM”.
The auditor should be technically sound in ALL the elements he/she is auditing. Asking a person who has never managed a Management of Change and Prestart-Up Safety Review system to audit your system is like asking me to audit a diesel mechanic’s work based on the fact that I have driven several diesel vehicles in my professional career! Just because I have driven vehicles with diesel engines does not make me knowledgeable in the workings of a diesel engine! Sound familiar?
The auditor needs to understand where these management systems that make up the process safety management process are likely to be flawed and how to best find these flaws if they exist. After all, we are not OSHA; meaning we do not have up to 6 months to audit the systems. We have, in most cases one (1) week to audit all 14 elements so we need to be smart in how we audit to ensure we have sampled and tested the systems adequately in the limited time we have.
The auditor should be very familiar with the Highly Hazardous Chemical(s)/Extremely Hazardous Chemical(s) used in the process. They do not need to be a chemical engineer or a chemist, but they should understand the primary hazardous properties of the HHC/EHS and how these properties pose hazards to BOTH process safety and individual safety. Hiring someone who struggles to understand the basic properties and behaviors of flammable liquids and gases is not someone who will be able to adequately audit the inner workings of several PSM elements (e.g. PSI, PHA, MOC, SOP/SWP).
So basically, it all boils down to specific knowledge of the standard requirements, chemicals used in the process and these chemicals pose hazards to the process and people. If there is a “auditor certification process” that can do this for all the different chemical processes that fall under PSM/RMP then I have yet to find it! And oh yeah, being a Certified Safety Professional (CSP) may validate your ability to manage an occupational safety and health process, but it means very little in the PSM/RMP arena. Although some companies require their auditors to be CSP (or CIH), there is not one thing about either professional certification process that even remotely resembles process safety management or comes close to validating knowledge of process safety management systems. There are a lot of CSPs who are outstanding process safety professionals and then there are some that could not even tell you there are 14 fundamental elements of process safety. Not knocking the certification process, just the idea that some companies think they are hiring a competent process safety professional solely based on the fact the individual has either the CSP or CIH certification. (I am sure I will get a lot of feedback on these comments!)
3) A report of the findings of the audit shall be developed.
This is another wide open requirement that we have seen at both ends of the spectrum. But one thing is for sure, the facility should be able to provide a written report (actually the last two written reports) to an OSHA/EPA official (as well as a 3rd party auditor hired to conduct an audit). What the report contains is open for debate, but I will offer this bit of advice from experience having participated in dozens of NEPs and VPP assessments over the years:
1. the report needs to document that ALL fourteen elements were audited. Although, not a specific requirement of 1910.119(o), it is an expectation that an audit (even those done piece meal over time ) have audited all fourteen elements. And while I have not mentioned EPA’s RMP yet, I would suggest that the audit report include that the audit reviewed not only the “prevention plan” elements (which by the way are nearly identical to PSM) but also the off-site consequence analysis (e.g. worst case and alternative case), the RMP submission, and the RMP written management system. These are the few RMP items that are NOT part of OSHA’s PSM requirements. Let me be clear here, a facility will NOT be cited for not including these aspects within their RMP audit; however, if any of these RMP requirements are incorrect or just not done then the facility would be cited. So not including these RMP requirements is not a violation of the auditing element requirements, but not covering them may lead a facility to believe all is well with their RMP submission(s).
If we look back at the very first requirement we will see that the word “certify” is used… “Employers shall certify that they have evaluated compliance…”. It is our strong belief that the report should contain a section where the plant manager or “the person responsible for implementation of the RMP” should sign and date the audit report showing their acceptance of the findings. Again, let me be clear here – a facility will NOT be cited if the plant manager or the “person responsible for implementing RMP” does not sign the audit report. But what has happened many times in the past is that someone in the facility receives the audit report; he/she attempts to get the management staff engaged in the resolution of the findings, only to be told “that is your responsibility”. Or worse yet, the person leaves the company and the report just goes into oblivion until an auditor or OSHA/EPA arrive at the plant. We have actually had companies try and prove they conducted an audit by showing us financial records of where an invoice for the audit was paid. I have found that by having a spot on the cover page for the Plant Manager, or the highest ranking on-site manager, to “certify” the report drives the responsibility for process safety to the correct person. This “certifying” manager will also play a critical role in developing the action plan to resolve all the findings, so having them take the first step in “certifying” the audit report only makes good business sense.
The report should contain very clear and detailed audit findings that are linked back to a specific requirement. In a PSM/RMP report this is ABSOLUTELY CRITICAL as many of the findings will be referencing Recognized and Generally Accepted Good Engineering Practices (RAGAGEPs) which are not listed in 1910.119. The findings need to be written so that 6 months after the audit, the finding can be read and clearly understood by a competent process safety professional. Also, we are still finding some “holy cow” situations in our auditing and the types of findings that rise to the “holy cow” level are usually quite expensive to bring to resolution. So by providing the facility with a clear explanation as to how the finding plays into their process, it will make it easier for the engineers to scope out the work that needs to be done and obtain the necessary funds and resources to bring the finding to resolution.
The facility must develop an action plan for each finding and this plan becomes part of the audit report. Again this is my opinion and I have to admit I have seen companies do this outside of the report and do it very well. But as we will discuss later, an action plan is a requirement of the audit element and the documentation of this plan and actions taken are an ABSOLUTE requirement.
The report should include a listing of the auditors, their experience/credentials, and the elements they audited. I also believe the audit should include those facility personnel (and contractors) who participated in the audit and to what capacity they participated. This would include even those employees and contractors who may have been interviewed in the field ever so briefly during the audit. (I know some companies do not like listing names of those interviewed for concern over some managers or supervisors being more worried over who said what than what was said!) We have a practice that we “officially list” someone from the facility as an auditor, linking back to the “knowledgeable person” requirement.
4) The employer shall promptly determine and document an appropriate response to each of the findings of the compliance audit, and document that deficiencies have been corrected.
This is a HUGE gap for those companies still struggling with understanding process safety “management”! OSHA’s (and EPA’s) expectations are very clear here… each finding, regardless of the level of risk, must have a resolution plan. Sometimes the action plan for a finding is a no brainer; but often times the resolution involves a “management system” resolution, meaning there is not a simple one-time fix. Don’t get me started on this, as I could write/talk for days on the flaws in this area. The best example I can give anyone is this…
Tom conducts a safety inspection of his area on Monday morning and notes in the inspection report that the fire extinguisher by the exit door was blocked. Tom indicates on the report that he moved the cart during the inspection and that the unsafe condition was corrected.
Tom conducts a safety inspection of his area on Monday morning and notes in the inspection report that the fire extinguisher by the exit door was blocked. Tom indicates on the report that he moved the cart during the inspection and that the unsafe condition was corrected.
Tom conducts a safety inspection of his area on Monday morning and notes in the inspection report that the fire extinguisher by the exit door was blocked. Tom indicates on the report that he moved the cart during the inspection and that the unsafe condition was corrected.
Tom conducts a safety inspection of his area on Monday morning and notes in the inspection report that the fire extinguisher by the exit door was blocked. Tom indicates on the report that he moved the cart during the inspection and that the unsafe condition was corrected.
Are you seeing the pattern yet!!!!!!!!!!!!! Here is how we get a break in this pattern…
During the incident investigation into the fire, Lisa stated that she was injured during the fire when she tripped and fell while trying to obtain the fire extinguisher!
You guessed it, she tripped over the same fire extinguisher that Tom had written up and “corrected” each week. We have to understand that the actions Tom took; albeit noble and necessary were not really a fix to the problem. A “resolution plan” is more than taking a single action! Certainly we want to take some type of immediate action to correct unsafe actions/conditions, but we cannot stop there. We have to understand why the cart was in front of the fire extinguisher and what needs to be done to ensure that it is not put there again.
Lastly regarding resolutions… pay close attention to ALL of the documents, training materials, etc. that will be impacted by the changes involved with each resolution. Making a change to one document may also require a change to other documents, updating training materials for operators, maintenance, contractors, emergency responders, etc. Of course all changes need to be managed through the facility’s management of change program.
5) Employers shall retain the two (2) most recent compliance audit reports.
I must first say this about this requirement… OSHA, nor EPA, will NOT use your 3-years audits against you! They will not ask for your audit reports and begin writing citations based on findings from your reports. HOWEVER, if you have open findings that are, in their opinion, way past due they will not write citations for those items, BUT THEY WILL cite a facility for NOT “promptly” addressing the audit findings!!! See #4 above for more on this. So why does OSHA/EPA require the two most recent audits be retained? Simply, it is a great source for testing the facility’s management system(s). Between audits, PHA’s, and incident investigations tracking of action items, an inspecting agency can quickly ascertain if a management group is serious about process safety. They are also looking for trends and repeats from one audit report to another. Keep in mind these two audit reports will most likely cover at least the past six years of process safety activities. If OSHA and EPA have found “XYZ” during their inspection and they see in the audit reports the same “XYZ” type issues, or in some cases the exact same issues, this is a very strong indicator that the facility is not managing their process risk appropriately. Whether this results in citations depends on too many factors to discuss here, but in most cases it will result in some citation and it MAY be classified as WILLFUL (although there is a high bar for OSHA to issue willful citations – but there has been a substantial increase regarding willful PSM citations).
Not having the last two reports of your audits, which MUST COVER all 14 elements of the standard, is a slam dunk for OSHA to issue a citation. I have a very high standard when I audit this requirement – if a facility PSM leader cannot find the reports and has to track down a consultant to get a copy of the report, I issue a finding as the facility did not actual “retain the last two reports”. This usually ends up the facility having many recommendations from these audit(s) that were not addressed in a timely manner, which would be another audit finding based on #4 above.
So those are the basics in meeting OSHA/EPA auditing requirements. But there are many other non-compliance driven issues concerning PSM/RMP audit that I would like to mention here.
#1 – Using the same company that built the management system to audit their own work! I will never understand the comfortable relationships that companies get into with these large consulting firms; but they are often times a disaster in the long run. We do a lot of PSM/RMP investigations for companies and we tend to find a pattern with these companies… they hired a consulting firm to write their PSM/RMP program, the facility does nothing to actually implement the program, and then three years later hire the same firm, often times the exact same person(s), to return and audit the program. These audits results in very few findings. Regardless of credentials of those who developed the program and audited the program this is a recipe for disaster, as our investigations are evident of such. Along these lines, we have seen companies that do millions of dollars of EHS business with large consulting firms and will use this firm to also audit their PSM/RMP programs. Now this EHS consulting firm did not have any involvement in the company’s PSM/RMP efforts before hand, but will now be auditing these programs. The auditors are very skilled and capable PSM/RMP auditors, but the audit results in very few findings. We come in 3-years later and find over 100 deficiencies, of which many are significant and should have been discovered many years earlier. What am I saying here… a company that does over $1 million in EHS business each year doing Title V permits, RCRA management, water sampling, etc. and then is asked to perform an audit function, we tend to believe the consulting firm is more worried about pissing of the client and losing $1 million in repeat business than providing a solid and honest audit. Not ALL large consulting firms does this, but we have seen it firsthand so it is something PSM/RMP managers need to be aware of.
#2 – Using personnel from within the company to audit other facilities within the company has both pro’s and con’s. I am a firm believer that this is a GREAT PRACTICE for the company, as well as the safety professionals. This is how I started out in PSM and the amount of experience I gained from doing many audits with more senior engineers was immeasurable to where I am today with my process safety skill sets. But I also got to see the ugly side of this practice! Auditors quickly found out that if you audit hard and find a lot of findings, then when it is your turn to be audited the auditors will “retaliate”; but if you are an easy auditor and although you find a lot of issues you handle them off line, then when it is your turn your audit will be much more favorable. This is just the human nature side of auditing, but this issue can be easily overcome with a strong and determined lead auditor from a corporate position that acts as the “impartial” auditor and ensures even auditing methodologies across all audits. Many of the audits that we do for clients involves a corporate lead auditor who provides leadership and ensures that audit teams are consistent with their auditing and sample sizes. Several of our clients use this “in-house” audit team concept and they will add one of the SAFTENG members to the team for a “fresh perspective”. Often times they will have us either audit the elements that show few findings over the previous audits or they have us audit the elements that they have seen serious problems with during OSHA/EPA inspections or through incident investigations. Again, I am a firm believer this is a win-win for everyone involved, but it takes a very strong willed personality to lead these audits so that there is no funny business, in which everyone suffers – some paying the ultimate price in suffering!!!
#3 – Comparing facilities based on number of findings. This is without a doubt the biggest mistake senior level managers make in the auditing aspect of process safety. I have personally heard plant manager get berated in a public forum by senior managers for having too many findings and the next week hear a different plant manager being congratulated for having only 14 findings. The plant that had 100 findings was in MUCH BETTER shape than the plant that had only 14 findings. The more mature a process safety management system is, the more opportunities there are for minor issues and thus may result in more findings, but these findings are much less severe than the facility that has NO programs and has done nothing! This is the plant that has the 14 findings (e.g. develop the 14 elements of PSM). So the number of findings means ABSOLUTELY nothing! Another example of the numbers game is based on the skill set of the audit team. We always audit the “audit” element last so as to not prejudice our views of the facility and to ensure we stay focused on our own audit methodology; but we come across audit reports that contain only a couple of audit findings. This is after a week of auditing and we have come across some serious deficiencies and have dozens of findings (sometimes over 100 findings); so needless to say we are always shocked at this situation. The audit reports do not contain auditor credentials so we never know what happened during the previous audits that resulted in such a poor outcome, but this is why measuring (and ranking) facilities based merely on audit results is a flawed concept. Now if a company hires the same audit team to audit all their facilities then there should be more credence given to the audit results being a reflection of performance.
#4 – Using the same audit team year after year to audit the same management system. Even with skilled and well credentialed auditors, we always suggest to the client that at least make up the audit team with different company personnel with different skill sets and different levels of exposure to world-class process safety management systems. Facility’s can become “comfortable” with their level of achievement; this is just human nature. By always raising the bar every three years we keep PSM professionals on their feet and every audit becomes a learning tool as well as an audit. I know I personally grew each time my systems were audited because each time it was a new auditor with new ideas and new expectations of what compliant looks like and acts like. We have to get out of this mindset that when we go through a PSM/RMP audit and receive no findings that our work is done! Well I am one to believe that any PSM/RMP audit that finds no discrepancies needs to be thrown away and the audit started over with competent auditors. The fact is that over a 3-year period there have been ample opportunities for workers to shortcut management systems, missing training, MOC not completed before the change is implemented, training misunderstood resulting in safe work permitting deficiencies, etc. It is should be expected that an audit team will find errors in judgment and practice.
Bottom line… Process safety is a way of life! It is not an “activity” that we do and then stop once it is done. It is a daily process that directs every activity and decision made regarding safety of the workers and process. Auditing these activities is an ABSOLUTE NECESSITY to ensure that what we believe to be happening on a daily basis is indeed that which is happening. We all know many of our colleagues believe that PSM/RMP compliance is an unachievable exercise and many just give up once they have come to this conclusion. I would agree with them that achieving 100% compliance with PSM/RMP is a futile effort; but our goals in process safety should not be 100% compliance and giving up may one day cause the loss of many lives. Instead we need to educate our management teams that process safety should not be measured by the 3-year audit results, but rather by our daily actions, management decisions, and many other leading process safety indicators. The 3-year audit, although very important, is just a snap shot in time and may be too late to save a life.
