ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-105

Foundations · EC-WP-105

Why Entities Fail Audits

Audits don't fail randomly. The patterns are public, read enough Notices of Penalty and the same failure modes show up over and over. Documentation that doesn't match operations. SMEs who can't speak the standard out loud.

Audits don't fail randomly. The patterns are public, read enough Notices of Penalty and the same failure modes show up over and over. Documentation that doesn't match operations. SMEs who can't speak the standard out loud. Self-reports that should have been filed two years earlier. Scope assumptions made once at registration and never revisited. Knowing these patterns in advance is most of the work of preparation, and entities that operate as if the audit could happen tomorrow rarely fail the audit that actually arrives. — Audits don't fail because the standards are unclear. They fail because programs operate differently than they document. — The most common audit failure isn't a missing control. It's documentation that doesn't reconcile with what operators actually do. — An SME who can't explain the program in their own words is a finding waiting for an interview. — Self-reporting timing changes the entire enforcement posture. Late self-reports are findings with extra steps. — Scope drift kills programs slowly. Six months of unmanaged change becomes a year of audit findings. — Audit findings cluster around the same handful of standards every cycle. The pattern is reproducible, and so is the prevention. — The strongest audit-defense posture isn't having no findings. It's having no surprises.

Contents

  1. Foreword
  2. The Real Reason Audits Fail (Hint: It's Not What You Think)
  3. The Documentation-vs-Operation Gap
  4. Evidence That Tells Two Stories
  5. The SME Who Couldn't Speak the Standard
  6. Scope Drift and Why You Didn't Notice
  7. Self-Identification: The Posture That Changes Everything
  8. Audit Findings as Diagnostics
  9. Building the Audit-Resistant Program
  10. About the Author
  11. About Energy Compliance, Inc.

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Foreword

Foreword

This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.

I've spent more than thirty years on every side of the bulk electric system. I've operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I've audited grid facilities and signed off on findings as a senior compliance auditor. I've worked enforcement matters from inside the regulator's process. For the last several years I've advised registered entities directly through the firm I founded.

The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn't. They prepare for audits by building programs that survive real questions, not binders that look thick.

That's the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.

These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who's been told that compliance and reliability are the same thing and suspects they aren't. And for the new compliance hire who got handed a binder and told good luck.

These references aren't marketing material disguised as content. They're the result of three decades of doing this work and watching it succeed and fail. I've written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.

Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don't bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you're looking for in a compliance partner, the back of this reference has our contact information.

If not, the reference still belongs to you. Take what's useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?

Rob Smith, Founder, Energy Compliance, Inc.

The Real Reason Audits Fail (Hint: It's Not What You Think)

The Real Reason Audits Fail (Hint: It's Not What You Think)

ink) Most analyses of audit failure focus on control gaps. The actual failure mode is usually the gap between what the program documents and what operators do.

Across decades of audit experience on both sides of the table, the failure patterns in NERC audits cluster around the same handful of root causes. Programs fail audits because they document one thing and operate another. They fail because SMEs can't reconstruct the reasoning behind decisions made years earlier. They fail because evidence packages were assembled for the binder, not for the question the auditor will actually ask.

The control gap explanation gets too much attention. In most failed audits, the controls existed. Someone designed them. Someone implemented them. The auditor didn't reject the controls. The auditor found the gap between the control design and the operational reality, or between the operational reality and the documentation that was supposed to describe it. That gap is what triggers most findings.

The pattern is reproducible. The same root causes show up in disturbance reports, in Self-Reports, in audit Notices of Possible Violation, and in settlement agreements. Programs that internalize the pattern early build different programs than programs that wait for the audit to teach them.

What you avoid by understanding this: building a program that looks audit-ready on paper, conducts well during the kickoff meeting, and then comes apart during the SME interviews. That's the most expensive failure mode because the program looked successful right up until it wasn't.

FROM THE FIELD Audits don't fail because the standards are unclear. They fail because programs operate differently than they document. Most failed audits don't have a missing control. They have a control that doesn't match its description. If your program's documentation describes a different operation than your operators perform, you have a finding. The auditor just hasn't named it yet.

The Documentation-vs-Operation Gap

The Documentation-vs-Operation Gap

Documentation that drifts from operations is the single most common audit failure mechanism. The drift is slow, predictable, and preventable.

Documentation drifts the moment it stops being maintained as a living artifact. A procedure written three years ago describes the operation as it existed three years ago. The operation changed, equipment was replaced, software updated, personnel rotated, scope adjusted, and the documentation didn't keep up. By the time the auditor arrives, the procedure describes a system that no longer exists.

The mechanism is mundane. Procedure updates are work. They get scheduled. They get deferred. Six months becomes twelve becomes twenty-four, and the procedure on the shelf is increasingly ceremonial. Operations runs on tribal knowledge and recent practice, not on the procedure. The auditor reads the procedure, watches the operation, asks why they don't match, and writes a finding.

Programs that survive audits keep documentation current as part of the operation, not adjacent to it. Every operational change triggers a documentation review. Every quarter, the documentation gets compared to actual practice. Every annual cycle, the procedures get walked through with the SMEs who execute them. None of this is exotic. It's just discipline that most programs eventually let lapse.

The cost of the lapse compounds. A single procedure out of date is a finding. A pattern of out-of-date procedures across the program is a programmatic finding, with worse penalty exposure and longer mitigation timelines. The auditor doesn't have to find every gap; they just have to find enough to establish the pattern.

FROM THE FIELD A procedure that hasn't been reviewed in 18 months is a procedure that's wrong, even if you haven't noticed yet. Documentation isn't done when it's written. It's done when the next operational change has been reflected in it. The auditor doesn't need to find every gap. They need to find enough to establish a pattern. Patterns produce programmatic findings.

Evidence That Tells Two Stories

Evidence That Tells Two Stories

Evidence packages are supposed to demonstrate compliance. Many demonstrate something different, and the auditor reads both.

Evidence is the backbone of audit defense. It's also where most programs reveal more than they intended. A well-built evidence package tells one consistent story: the program operated as designed, the controls executed as required, and the documentation reflects both. A poorly built package tells two stories, what the program was supposed to do, and what it actually did. The auditor reads both.

Common evidence failures: timestamps that don't reconcile across sources, log entries that show controls executing in ways the procedures don't describe, screenshots from systems that have since been decommissioned, evidence dated three years ago when the procedure says it should be reviewed quarterly. None of these are exotic. All of them cost findings.

Programs that survive audits build evidence as a live deliverable, not a retrospective compilation. Every control execution generates evidence. Every evidence artifact gets cataloged with provenance. When the auditor asks for samples, the program provides them quickly because they were maintained, not assembled.

The other consequence of two-story evidence: it accelerates auditor scrutiny. An auditor who finds one inconsistency starts looking for more. The audit conversation shifts from procedural to investigative. RFI volume increases. Interview scope widens. The program that thought it had a simple audit ends up with a complex one because the evidence raised questions the auditor felt obligated to chase.

FROM THE FIELD Evidence that doesn't reconcile across sources tells the auditor more than the program intended. An evidence package built to answer the audit question is good. One built to demonstrate ongoing operation is better. When evidence raises questions, audit scope expands. The expansion costs more than the underlying issue.

The SME Who Couldn't Speak the Standard

The SME Who Couldn't Speak the Standard

ard SME interviews surface gaps documentation conceals. Programs that don't prepare SMEs end up with findings the documentation alone wouldn't have produced.

The SME interview is one of the most consequential phases of any NERC audit. The auditor reads the documentation. The auditor reviews the evidence. Then the auditor talks to the people who actually do the work, and that conversation surfaces gaps documentation can't conceal. Programs that prepare SMEs survive this phase. Programs that don't, lose findings they otherwise would have avoided.

The most common SME failure: the SME can't explain in their own words why the program is structured the way it is. They can recite the procedure. They can describe the control. But they can't explain the rationale, the context, the operating reality. To the auditor, that signals a program where the documentation was written by one set of people and executed by a different set, with no shared understanding of why.

A second common failure: the SME contradicts the documentation, or contradicts themselves across questions. This usually isn't intentional. The SME knows the operation better than they know the documentation, and when asked questions framed against the documentation, they answer from operational memory. Their answer is right operationally and wrong against the documented procedure. The auditor records the discrepancy.

Preparation matters and is finite. Five hours of focused SME rehearsal saves twenty hours of post-finding mitigation. The mature programs run dry-run interviews internally, with someone playing the auditor, before the real audit arrives.

FROM THE FIELD An SME who can't explain the program in their own words is a finding waiting for an interview. When the SME contradicts the documentation, the auditor doesn't decide who's right. The auditor records both versions. Five hours of SME rehearsal saves twenty hours of post-finding mitigation. The math is consistent.

Scope Drift and Why You Didn't Notice

Scope Drift and Why You Didn't Notice

ice Compliance scope changes when operations change. Programs that don't track scope continuously end up with audit findings on systems they didn't realize were in scope.

Scope is the foundation of every NERC compliance program. It determines which standards apply, which assets are relevant, which controls are required, and which evidence has to be maintained. Scope decisions made at registration get embedded in the program design. Scope decisions never re-examined become audit findings.

Operations change continuously. Assets get added, removed, repurposed, reclassified. Systems that were Low Impact at registration become Medium Impact when their function expands. BES Cyber Systems get added to or removed from the inventory. Scope assumptions that were correct three years ago can be wrong today, and the program built on those assumptions has gaps it doesn't know about.

The auditor will catch the scope drift. The asset inventory gets compared against operational reality. The classification gets re-validated against current function. The systems that should be in scope but aren't get identified, and they bring with them every requirement that should have applied during the period they were misclassified.

Programs that survive audit on scope share a common practice: continuous scope review. Every operational change triggers a scope reassessment. Every quarter, the scope inventory gets reconciled against the operating environment. Annual scope reviews are documented, evidenced, and cross-checked. None of this prevents scope from drifting; it prevents the drift from going unnoticed.

FROM THE FIELD Scope decisions made at registration become program assumptions for years. Programs that don't re-examine them get caught by their own assumptions. The auditor reconstructs scope from operational reality, not from the program's stated scope. The two had better match. Six months of unmanaged scope change becomes a year of audit findings. The accounting is unforgiving.

Self-Identification: The Posture That Changes Everything

Self-Identification: The Posture That Changes Everything

Self-Reports are not admissions of failure. They are the most strategic tool in audit posture management.

The decision to Self-Report is one of the most consequential decisions in any compliance program. A timely Self-Report changes the enforcement posture, narrows the penalty exposure, accelerates mitigation acceptance, and frames the regulator's perception of the program. A late Self-Report, or a violation discovered first by the auditor, does the opposite.

The data is clear and consistent across enforcement reports. Self-Identified, Self-Reported violations consistently produce lower penalty assessments and faster resolutions than auditor-identified equivalents. The Region treats Self-Reports as evidence of program maturity. The auditor treats lack of Self-Reports as evidence of either an unusually clean program or an unusually opaque one, and they will determine which through investigation.

Programs that under-Self-Report eventually surface their issues at audit, and the audit conversation includes "why didn't this come through Self-Report?" The answer determines whether the discussion is about the violation itself or about a programmatic culture problem.

The mature programs Self-Report routinely, even on minor matters. They build the discipline. They normalize the conversation with the Region. They demonstrate continuous self-assessment. By the time the audit arrives, the Region already has a record of the program's honesty, and that record shapes the audit posture.

FROM THE FIELD Self-Reporting timing changes the entire enforcement posture. Late Self-Reports are findings with extra steps. A program that hasn't Self-Reported in five years is either exemplary or invisible. The Region knows which. The decision not to Self-Report a known issue is the decision to surrender enforcement framing to the regulator.

Audit Findings as Diagnostics

Audit Findings as Diagnostics

An audit finding is information. The right response treats it as a diagnostic, not just a problem to mitigate.

Most programs treat audit findings reactively. The finding arrives, the mitigation plan gets drafted, the corrective action gets implemented, and the matter closes. That's the minimum response, and it satisfies the regulator. It doesn't make the next audit better.

The mature programs treat findings as diagnostics. Each finding signals something about the program, a process gap, a documentation drift, a training shortfall, a coordination failure. The mitigation addresses the immediate finding. The diagnostic addresses the systemic issue that produced it. Programs that do both have decreasing finding rates over time. Programs that do only the first have stable finding rates that show up in every audit.

Reading findings as diagnostics requires honesty. The temptation is to treat each finding as isolated, attributable to a specific person or moment, and therefore not indicative of a broader issue. That framing avoids difficult internal conversations but produces no improvement. Programs that can have the difficult conversation, the kind that examines whether the program design itself enabled the finding, improve.

Findings also age. A finding from three years ago that produced no programmatic change will produce a similar finding three years from now. The Region notices repeat patterns. Repeat findings on the same program elements move enforcement from individual to programmatic, with worse penalty exposure and more aggressive mitigation requirements.

FROM THE FIELD An audit finding is a diagnostic. The mitigation closes the finding. The diagnostic prevents the next one. Repeat findings on the same program elements move enforcement from individual to programmatic. The penalty math changes. Programs with decreasing finding rates over time read findings as information. Programs with stable finding rates treat them as paperwork.

Building the Audit-Resistant Program

Building the Audit-Resistant Program

Audit-resistance isn't a posture you can adopt during preparation. It's a program design choice made early and reinforced continuously.

The audit-resistant program isn't built during audit preparation. It's built years earlier through deliberate design choices that compound. The choices aren't dramatic. They're a series of small disciplines maintained over time: documentation kept current, evidence captured continuously, SMEs trained on rationale not just procedure, scope reviewed quarterly, Self-Reports filed routinely, findings analyzed diagnostically.

The hallmark of an audit-resistant program is that audit preparation looks no different from normal operations. The documentation is already current. The evidence is already organized. The SMEs already know how to talk about their work. The scope is already verified. The audit is a checkpoint, not a sprint.

Programs that achieve this state share another characteristic: they treat the Region as a peer, not an adversary. The Region's role is to verify reliability through compliance enforcement. The program's role is to deliver reliability and demonstrate compliance. Both sides of that relationship benefit from clean, transparent, ongoing communication. Programs that maintain that relationship have different audit experiences than programs that maintain distance.

The investment is real and the return is real. Audit-resistant programs spend less on emergency mitigation, less on legal defense, less on reputational repair, and less on the operational disruption that comes with extended enforcement matters. The math works. The discipline is the price.

FROM THE FIELD Audit-resistance is a series of small disciplines maintained for years. There's no shortcut. The hallmark of an audit-resistant program: audit preparation looks no different from normal operations. The strongest audit posture isn't having no findings. It's having no surprises, for the entity or for the regulator.

About the Author

About the Author

Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.

Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk-based oversight of utility mitigation activities.

Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.

About Energy Compliance, Inc.

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.

Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.

We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don't staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.

Energy Compliance services include, but are not limited to:

  • NERC reliability and compliance advisory support
  • Reliability governance and program assessments
  • Registration and applicability analysis
  • Operational and engineering reliability alignment
  • Compliance program design and improvement
  • Audit and enforcement support (non-advocacy)
  • Mitigation planning and Self-Report development
  • Training and executive briefings on reliability frameworks
  • Regulator-perspective program reviews

Each engagement is scoped to the entity's role, function, and bulk system impact.

Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.

NERC COMPLIANCE SENIOR ADVISORY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.

INDUSTRY ENGAGEMENT AUDIT DEFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.

CONNECT WITH US

Foundations