NERC audits are operationally complex events that test the entity's compliance program and the entity's legal preparation simultaneously. The two functions are commonly designed to operate in parallel, with limited coordination, on the assumption that compliance handles the audit and counsel is engaged only if matters escalate. This assumption produces predictable failures at the interface between the functions, where handoffs are required, judgment calls cross between operational and legal domains, and the entity's response posture has to integrate both. This reference describes why the interface matters most during audit, how to define the two functions operationally, where the handoffs happen and where they fail, how privilege protection works in real-time audit conditions, the joint counsel-compliance discipline that produces strong SME interviews, the document production rhythm that protects the entity's posture, the escalation triggers that move counsel from supporting to leading, and the post-audit integration that produces a stronger framework for the next cycle. — Most audit findings trace to gaps at the legal-compliance interface, not to gaps in either function alone. — The interface is engineered before the audit. Audit time is the wrong moment to design coordination. — Handoffs that work in calm conditions fail under audit pressure. The handoffs need rehearsal.
Contents
- Foreword
- Why the Interface Matters Most During Audit
- Defining the Two Functions Operationally
- Where the Handoffs Happen (and Where They Fail)
- Privilege Protection in Real-Time Audit Conditions
- SME Preparation: Joint Counsel-Compliance Discipline
- Document Production During Audit Engagement
- Escalation Triggers: When Counsel Takes the Lead
- Post-Audit Integration and the Operating Loop
- About the Author
- About Energy Compliance, Inc.
- Legal Series Services
Read offline
The complete reference is on this page. The PDF is for circulation inside your organization.
Download the PDFForeword
Foreword
This professional reference is part of the Legal Series published by Energy Compliance, Inc. in partnership with Stich Angell, P.A., for registered entities and the people who run their compliance and legal programs. NERC enforcement is procedurally a civil enforcement regime that registered entities frequently treat as a compliance process. The framing matters. The decisions made early in any enforcement matter bind the entity through every subsequent stage, and many of those decisions involve legal judgment that compliance teams are not trained to make alone. The cost of recognizing this late is significant, rarely visible at the moment, and largely avoidable with the right operating framework in place. Energy Compliance, Inc. partners with Stich Angell, P.A. to provide registered entities with integrated legal-compliance support across the full enforcement lifecycle. Rob Smith brings more than thirty years of operator and regulator-side compliance experience. Cara Passaro and the Stich Angell team bring civil litigation depth, appellate practice, and increasing focus on energy compliance defense. The combination is the structural alternative to the model in which compliance consulting and legal counsel operate as separate engagements that converge only when an enforcement matter has already arrived. These references are written for the compliance manager who has to brief the general counsel honestly. For the in-house attorney who needs to understand how NERC enforcement actually proceeds. For the senior leader who has been told that the enforcement matter is under control and suspects it is not. For the outside counsel who has been asked to advise on a NERC matter for the first time and needs a practitioner's view of the procedural reality. The references do not substitute for engaged counsel and they do not replace operational compliance judgment. They describe how the system actually works, in the voice we use in front of regulators and in the courtroom, so that registered entities can make the decisions in front of them with the information practitioners would want them to have. If the integrated legal-compliance approach we describe is what your entity needs, the back of this reference contains contact information. If not, the reference still belongs to you. Take what is useful, apply it well, and remember that the structural decisions made before an enforcement matter arrives are almost always worth more than the decisions made after.
— Cara C. Passaro and Rob Smith Stich Angell, P.A. · Energy Compliance, Inc.
EC-WP-804 The Legal-Compliance Interface in Audit Defense
Why the Interface Matters Most During Audit
Why the Interface Matters Most During Audit
Audits stress every interface in the entity's compliance program. The legal-compliance interface is the one that matters most and is least often engineered.
A NERC audit is an operationally intensive event that surfaces every weak interface in the entity's compliance program. The interface between compliance and operations. The interface between compliance and IT. The interface between compliance and engineering. Each of these is exercised under audit conditions, and weaknesses are visible to the auditor in real time. The interface that matters most for the entity's audit posture, and that is least often engineered with discipline, is the interface between compliance and counsel. The legal-compliance interface is exercised at multiple moments during the audit. When the auditor's question implicates a topic that may have legal sensitivity. When a document the auditor requests may contain privileged content. When an SME's response may create exposure that should be developed further before the matter is concluded. When the auditor's evaluation produces a draft finding that would benefit from legal review before the entity responds. When the audit closing meeting previews findings the entity will need to address strategically. Each of these is an interface moment, and how the interface operates in each moment shapes the audit's outcome. In entities where the interface is engineered, the moments are handled cleanly. Compliance recognizes the interface trigger. Counsel is consulted in real time, often through a defined channel established before the audit. The decision is made jointly. The response to the auditor is coordinated. The audit proceeds without the friction that signals weakness. In entities where the interface is not engineered, the moments are handled ad hoc. Compliance either proceeds without consultation, or pauses to figure out how to consult, with the auditor watching. Either response degrades the audit posture, often visibly. The structural fix is to engineer the interface before the audit. The work is uncomfortable for compliance teams that have managed audits independently for years. The discomfort is appropriate to acknowledge. The engineered interface produces meaningfully better audit outcomes than the unengineered one, and the gap is widest in the audits where the matters are most consequential. Engineering the interface is among the highest-return preparations available to a compliance program.
FROM THE PRACTICE A NERC audit stresses every interface in the compliance program. The legal-compliance interface is the one that matters most and is least often engineered. Interface moments are predictable: legally sensitive topics, privilege-relevant documents, SME exposure, draft findings, closing meeting previews. Engineered interfaces produce cleanly handled moments. Unengineered interfaces produce ad hoc responses the auditor watches in real time.
Defining the Two Functions Operationally
Defining the Two Functions Operationally
Compliance and counsel have distinct roles during audit. The roles need to be defined operationally, not philosophically, and the operational definition has to survive audit pressure.
Compliance and counsel each have a defined role during audit, and the roles are complementary rather than overlapping. Compliance owns the operational management of the audit. Counsel owns the legal layer that operates alongside it. Compliance interfaces with the audit team day to day. Counsel is consulted on legal questions, drafts or reviews any submissions, manages any privilege questions, and is positioned to escalate if the audit develops into a potential enforcement matter. The functions are distinct, and the distinction has to be operationally defined rather than left to interpretation in real time. The compliance role includes scheduling, document logistics, witness coordination, response drafting at the operational level, daily debriefs with the audit team, internal communications inside the entity about the audit's progress, and overall management of the audit calendar. These functions are operational and require continuous compliance presence. Compliance is the audit team's primary point of contact for everything that does not require legal judgment. The counsel role is more specific and more selective. Counsel is engaged on identified categories of question. Counsel reviews any document production that may contain privileged content. Counsel drafts or reviews responses to information requests that have legal implications. Counsel manages any matter that escalates beyond routine audit interaction, including responses to draft findings or matters that may proceed into enforcement. Counsel is reachable throughout the audit on a defined response cadence, even when not present in every interaction. The interface between the two roles is the integration point. Compliance recognizes when an interface trigger has occurred and consults counsel before responding. Counsel responds within a cadence that does not delay the audit. The integration is rehearsed in advance, with examples of trigger situations and the expected response from each side. Without rehearsal, the integration fails the first time it is tested, and audit conditions are the wrong place to learn.
FROM THE PRACTICE Compliance and counsel have distinct roles during audit. Compliance owns operational management. Counsel owns the legal layer that operates alongside it. Compliance is the audit team's primary point of contact for everything that does not require legal judgment. Counsel is selective and reachable. The interface is rehearsed in advance with examples. Without rehearsal, the integration fails the first time it is tested under audit pressure.
Where the Handoffs Happen (and Where They Fail)
Where the Handoffs Happen (and Where They Fail)
) Handoffs between compliance and counsel during audit are the failure points that produce most audit-related legal problems. Naming them lets the entity prepare.
Handoffs between compliance and counsel during an active audit happen at predictable moments. An information request arrives that requires document production. A witness interview is scheduled that may surface legally sensitive testimony. The auditor poses a question that goes beyond operational scope into legal interpretation. A draft finding is shared that will require formal response. The audit team requests guidance on the entity's intent regarding settlement or admission. Each of these is a handoff moment, and each has a documented failure pattern when the interface is not engineered. The most common failure is the unrecognized handoff. Compliance does not recognize that the auditor's question or request implicates a legal layer, and proceeds to respond without consulting counsel. The response goes into the record. The legal implications surface later, often in a way that constrains the entity's options. The recognition failure is not a fault of compliance personnel; it is a failure of the interface design that did not equip them to recognize the trigger. The second common failure is the late handoff. Compliance recognizes the trigger but consults counsel after the operational response is already in motion. The auditor has received a draft answer. The document has been produced. The witness has been interviewed. Counsel arrives to inherit a record that has already been built and cannot be unbuilt. The late handoff is a function of compliance proceeding on default speed without the brief pause that a recognized trigger should produce. The third common failure is the over-handoff. Compliance is aware of legal sensitivity but unsure where the line is, and consults counsel on every interaction. Counsel becomes a bottleneck. The audit slows. The relationship with the audit team is strained. The over-handoff is a function of insufficient interface design that left compliance without confidence about which triggers actually require consultation. All three failures are addressable by interface design that names the triggers, defines the response, and rehearses the discipline before the audit arrives.
FROM THE PRACTICE Handoff moments are predictable: document production, witness interviews, legally complex questions, draft findings, settlement or admission requests. Three failure patterns: unrecognized, late, and over-handoff. All three are addressable by interface design that names the triggers and defines the response. The recognition failure is not a fault of compliance personnel. It is a failure of interface design. Engineer the design before the audit, or accept the failures.
Privilege Protection in Real-Time Audit Conditions
Privilege Protection in Real-Time Audit Conditions
Privilege protection during an active audit is harder than privilege protection in calmer matters. The protection has to operate in real time and survive audit pressure.
Privilege protection during an active audit operates under conditions that calmer enforcement matters do not face. The audit team is present. Decisions about document production happen in compressed timeframes. Witness interviews are scheduled with limited preparation time. Internal communications about the audit happen frequently and across many participants. Each of these conditions creates privilege risk that has to be managed in real time, by a discipline that has been established before the audit began. The discipline starts with a privileged communication channel for any matter-related conversation that may surface during the audit. The channel is established before the audit. The participants are named. Email distribution lists used for normal compliance communication are not used for audit communications about legally sensitive topics. Phone calls about such topics involve counsel rather than being relayed afterward. The discipline is socialized to the team in writing, with examples, before the audit begins. Document production during audit is the highest-volume privilege risk. Auditors request documents on relatively short timelines. Compliance produces documents to meet the timeline. The privilege review is at risk of being skipped or compressed. The interface design addresses this by routing every production through a privilege review step, even when the timeline is tight. Counsel reviews quickly when needed but is not bypassed. The privilege log is maintained in real time, alongside the production, not retroactively after the audit closes. The witness interview privilege risk is different but equally real. Interviews with SMEs may surface communications that occurred under privileged conditions. The witness is not always equipped to recognize when a question is asking for content that is privileged. Counsel preparation addresses this by walking through likely categories of question and identifying where the witness should defer or where counsel should be consulted before answering. Counsel may also choose to be present at interviews that are likely to surface privilege issues. The presence is usually accepted by audit teams that understand the entity's posture, and the alternative of unprotected testimony is significantly worse.
FROM THE PRACTICE Privilege protection during audit operates under compressed timeframes and high communication volume. The discipline has to be established before the audit. Every document production routes through a privilege review step, even when the timeline is tight. Counsel reviews quickly. The step is not bypassed. Witness interview privilege risk is real and is addressed in preparation. Walk through likely questions. Identify where the witness defers or counsel is consulted.
SME Preparation: Joint Counsel-Compliance Discipline
SME Preparation: Joint Counsel-Compliance Discipline
SME interviews produce more audit findings than any other audit phase. Preparation that integrates counsel and compliance is the discipline that survives them.
SME interviews produce more audit findings than any other phase of a NERC audit. The interview surfaces gaps that documentation conceals, contradictions that operational practice creates, and uncertainty that the SME has not been prepared to manage. The preparation that produces strong SME interviews is joint counsel-compliance work, designed before the audit and executed in the days before each interview. Compliance owns the substantive preparation. The SME's domain knowledge is reviewed and refreshed. Procedures and controls relevant to the interview topic are walked through. Operational reality is reconciled with the documentation. Common audit questions in the topic area are anticipated and discussed. The SME develops fluency in describing the program in their own words, which is the test the audit will apply. This work is what compliance has historically owned and continues to own under the joint preparation discipline. Counsel owns the posture and boundary preparation. The SME is briefed on what to do if a question implicates legally sensitive content. The SME is prepared to defer to counsel when appropriate, in language that does not signal evasion. The SME is briefed on the difference between describing what they know operationally and speculating about matters outside their direct knowledge. The SME understands that the interview produces testimony, not casual conversation, and adjusts posture accordingly. This work is uncommon in compliance preparation and standard in legal preparation, and is the addition that joint discipline brings. The integrated preparation also addresses what the SME does not say. Volunteering information beyond what the question asks, even with good intent, can create new audit threads that the entity then has to address. The SME is briefed to answer the question asked, completely and accurately, and to stop. Counsel rehearses this discipline with each SME, often with counsel playing the auditor in mock interviews. The investment is small relative to the cost of a single avoidable finding produced by an unprepared SME, and the discipline compounds across the audit because every interview is conducted
FROM THE PRACTICE SME interviews produce more audit findings than any other phase. Joint counsel-compliance preparation is the discipline that survives them. Compliance owns substantive preparation. Counsel owns posture and boundary preparation. Both are required. Either alone is insufficient. The SME answers the question asked, completely and accurately, and stops. Counsel rehearses this discipline with each SME before the interview.
Document Production During Audit Engagement
Document Production During Audit Engagement
Document production during audit has different stakes than routine compliance production. The privilege and strategic posture both have to be preserved under time pressure.
Document production during an active audit operates under different stakes than routine compliance document production. The audit team is reading the documents in real time. The documents are being used to evaluate the entity's compliance with the standards in scope. The documents may also be reviewed for evidence relevant to potential enforcement matters that could emerge from the audit. Production decisions made under time pressure can have legal consequences that extend beyond the audit, and the production discipline has to reflect that. The basic discipline is consistent with what counsel applies in any document-intensive matter. Document requests are reviewed before production for scope, privilege, and any other applicable protections. Privilege determinations are documented in a log maintained in real time. Productions are made on a schedule that allows the review without missing the auditor's deadline. The cooperative posture of producing what is requested is preserved. The discipline of producing only what is responsive, after privilege review, is preserved at the same time. The audit-specific addition is the speed requirement. Audit teams expect productions on cadences shorter than enforcement-matter productions typically require. Compliance is operationally responsible for assembling the documents on the cadence. Counsel is responsible for the privilege review on the same cadence. The two functions work in parallel rather than sequentially, with counsel's review pre-positioned by an interface design that anticipates the production volume and timing. The other audit-specific consideration is the secondary use of produced documents. Documents produced during audit may surface again in any subsequent enforcement matter, with the framing they had in the audit production. Counsel is attentive to how the documents are produced, what production cover language accompanies them, and how the privilege log is structured, with attention to the possibility that the entity may be defending positions about these documents in enforcement contexts months or years later. The audit production discipline is not just about the audit. It is about the record the audit creates that may be referenced in matters yet to arise.
FROM THE PRACTICE Document production during audit operates under different stakes than routine production. Documents may be referenced in enforcement matters that have not yet arisen. Compliance assembles documents on the auditor's cadence. Counsel reviews privilege on the same cadence. The two functions work in parallel. The privilege log is maintained in real time, alongside the production, not retroactively after the audit closes. Late privilege claims rarely hold.
Escalation Triggers: When Counsel Takes the Lead
Escalation Triggers: When Counsel Takes the Lead
Most audits do not require counsel to lead. Some do. The trigger has to be defined in advance because real-time judgment about escalation fails consistently.
Most NERC audits proceed with compliance leading and counsel supporting in the background. Some audits develop conditions that require counsel to take the lead, and the transition needs to happen quickly when those conditions emerge. The triggers for the transition should be defined in advance and rehearsed, because real-time judgment about whether to escalate, made under audit pressure, fails consistently. The triggers are observable. The audit team has identified findings that are likely to lead to a Notice of Penalty. The audit team has requested information that goes beyond routine audit scope and into investigation territory. The audit team has begun discussing potential enforcement consequences in the daily debriefs. The audit team has indicated that the matter may be referred to enforcement counsel rather than handled within the audit framework. Any of these signals warrants counsel taking the lead, with compliance executing operationally under counsel's direction rather than running the matter independently. When the transition happens, the operational change is structural. Counsel becomes the primary interface with the audit team for substantive matters. Compliance continues to handle logistics and operational coordination. Communications about the audit are routed through counsel. Any submissions to the audit team are drafted or reviewed by counsel. The privilege protocols are tightened. The internal communication discipline is reviewed. None of this is hostile. It is the appropriate posture for a matter that has moved into enforcement territory, and audit teams generally recognize and respect the transition when it is conducted professionally. Entities that fail to make the transition cleanly, either by missing the trigger or by resisting the role change, end up with audits that develop into enforcement matters with weaker postures than the same matters would have had if counsel had taken the lead earlier. The cost of late transition is structural and rarely recoverable. The cost of timely transition is small and produces a meaningfully better posture across the rest of the matter. The trigger framework is the cheapest insurance available against the late-transition cost.
FROM THE PRACTICE Most audits do not require counsel to lead. Some do. The trigger framework has to be defined in advance because real-time escalation judgment fails consistently. Triggers are observable: NOP-likely findings, investigation-territory information requests, enforcement discussion in debriefs, referral signals. Late transition produces audits that develop into enforcement matters with weaker postures. The trigger framework is cheap insurance against that cost.
Post-Audit Integration and the Operating Loop
Post-Audit Integration and the Operating Loop
Audits produce learning that updates the legal-compliance operating framework. Capturing the learning depends on treating the post-audit as a deliberate phase.
The audit closes. The findings are issued or are pending. The team that has been operating at high intensity for weeks returns to baseline. The temptation is to celebrate or recover and to file the audit experience as a completed event. The defensible posture is the opposite. The post-audit phase is when the audit's learning is captured and integrated into the entity's operating framework, and missing this phase forfeits the structural improvement the audit just paid for. The post-audit work has two products. A privileged after-action review, drafted by counsel and shared inside the privilege circle, captures honestly what worked and what did not. The handoffs that succeeded. The handoffs that failed. The privilege moments that were handled well. The moments where privilege was at risk. The SME interviews that landed cleanly. The interviews that produced findings that better preparation would have prevented. The candor in this document is the operational input the entity needs to actually change the framework. The second product is the operational lessons document, drafted at a higher level for broader internal distribution. The compliance program changes. The training updates. The cadence changes. The documentation discipline updates. This document does not contain the legally sensitive analysis. It contains the operational changes the entity will make in response to what the audit taught. It is the basis for the cycle of program improvement that compliance owns and counsel supports. The integration of these products into the legal-compliance operating framework described in EC-WP-800 is the loop that produces meaningful improvement across audit cycles. The framework is revised. The interface design is updated. The escalation triggers are refined. The handoff rehearsals are scheduled. None of this is glamorous. All of it is the structural work that distinguishes programs that improve year over year from programs that produce roughly the same audit outcomes regardless of how many cycles they accumulate. The improvement is the actual return on the audit just closed, and capturing it depends on the discipline of running the post-audit as a deliberate phase.
FROM THE PRACTICE The post-audit phase captures the audit's learning. Missing this phase forfeits the structural improvement the audit just paid for. Two products: a privileged after-action review (candor inside the privilege circle) and an operational lessons document (program changes for broader distribution). Integration into the legal-compliance operating framework is the loop that produces year-over-year improvement. Without the loop, audit outcomes stay roughly constant.
About the Author
About the Author
Cara C. Passaro is Shareholder and Firm President at Stich Angell, P.A., where she has practiced civil trial and appellate law for more than two decades. She is licensed to practice in the state and federal courts of Minnesota and North Dakota and has been recognized as a Super Lawyer for her work in civil litigation and construction litigation defense. Cara's practice has historically focused on products liability, premises liability, transportation liability, and complex commercial litigation, with an emphasis on the defense of corporate clients in high-stakes matters across the Midwest. She has tried jury cases to verdict in Minnesota state court, argued matters at the Minnesota Court of Appeals, and managed appellate work through the Minnesota Supreme Court. In recent years, Cara and the Stich Angell team have extended the firm's civil litigation practice into energy compliance defense, working with registered entities and their compliance partners on NERC enforcement matters, Notice of Penalty response, settlement negotiations with Regional Entities, and the integrated legal-compliance frameworks that determine whether enforcement matters resolve as manageable procedural events or as multi-year exposures. Cara serves as the named legal author of the Energy Compliance, Inc. Legal Series and is the partner engagement lead for the Stich Angell side of the integrated practice.
About Stich Angell, P.A. Stich Angell, P.A. is a Minneapolis-based civil litigation firm founded in 1971. The firm represents businesses, individuals, and organizations across a broad range of civil practice areas, with particular depth in complex litigation, products liability, transportation liability, professional liability, insurance defense, construction litigation, and appellate practice. The firm's trial and appellate attorneys are recognized among the most experienced civil trial lawyers in the state, with extensive experience representing clients through trial verdict and appellate review. Although the firm is based in Minnesota, the attorneys represent clients in matters across the United States. Stich Angell has expanded the firm's civil litigation practice into energy compliance defense, partnering with Energy Compliance, Inc. to provide registered entities with integrated legal and compliance support across the NERC enforcement lifecycle. The combined practice brings civil litigation discipline, appellate strength, and senior regulatory experience to a category of matters that has historically lacked that combination. Stich Angell, P.A. is located at 3601 Minnesota Drive, Suite 450, Minneapolis, Minnesota 55435, and may be reached at (612) 333-6251 or at stichlaw.com.
About Energy Compliance, Inc.
About Energy Compliance, Inc.
Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System. Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers, across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks. Energy Compliance partners with Stich Angell, P.A. for legal matters arising in the NERC enforcement lifecycle, including Notice of Penalty response, settlement negotiation, internal investigation under privilege, and the integrated legal-compliance operating frameworks that registered entities need before enforcement arrives. The integrated practice replaces the sequential model in which compliance and legal engage separately and converge only when a matter has already escalated. Engagements are led by a single senior practitioner on the compliance side and by a named partner on the legal side. We do not staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.
Legal Series Services
Legal Series Services
The Legal Series supports registered entities across the full enforcement lifecycle. The work is structured for operational execution and legal defensibility. Every engagement is led by a named senior practitioner on the compliance side and by a named partner at Stich Angell on the legal side.
Integrated legal-compliance services include, but are not limited to:
- Notice of Penalty response strategy and execution
- Internal investigation conducted under privilege
- Document production and privilege log management
- Witness preparation for Regional Entity interviews
- Settlement negotiation with Regional Entity counsel
- Self-Report drafting and legal review
- FERC submission preparation and review
- Legal-compliance operating framework design
- Counsel-led after-action review and lessons integration
Each engagement is scoped to the entity's role, function, regulatory posture, and the procedural stage of the matter.
ENERGY COMPLIANCE LEGAL SERIES
Defensible Compliance. Disciplined Defense. Energy Compliance, Inc. and Stich Angell, P.A. partner to provide registered entities with integrated legal and compliance support across the NERC enforcement lifecycle, from Self-Report through Notice of Penalty through settlement at FERC.
ENFORCEMENT DEFENSE PRIVILEGE COUNSEL Notice of Penalty response and settlement Internal investigation and document production strategy. under privilege.
REGULATORY ADVISORY LEGAL-COMPLIANCE INTEGRATION FERC submission, Regional Entity counsel Operating frameworks built before enforcement engagement. arrives.
CONNECT WITH US