SC Diagnostic: Before You Fix Anything, Find Out Where You Stand

Getting a compliance program right is three steps, in order: (1) find out where you stand, (2) fix what is broken, and (3) sustain and improve. SC Diagnostic is step one. It is a fixed-fee service offered by Systemic Compliance that asks two questions about your programs: does each one meet the rule that governs it today, and does it still agree with the programs it depends on and the programs that depend on it. You decide the scope.

Two questions, not one

Take any program in your system. Your O&M manual. Your Integrity Management Plan. Your Emergency Response Plan. Your OQ Program. The two questions below apply to each of them on its own, and to all of them together.

The first question is conformance: does the program meet the requirements that apply to it today, including applicable state requirements, at the level of each individual obligation rather than the program as a whole. That is the question every compliance review asks, and it is worth asking well.

The second question is coherence: is the program still connected to everything it depends on, and everything that depends on it. Does the covered-task list match the work this manual actually requires now? Did the decision recorded in this plan reach the procedure the crew used last month? When this document changed, did anything else change with it? For a distribution operator, your DIMP depends on leak history and corrosion records, and your O&M procedures and OQ program depend on it. We check both directions: whether a decision made in one place arrived in the other, whether a change rippled, whether two documents describing the same work still describe it the same way. A break in either direction is a finding.

The first question is about the document. The second is about whether the document is still telling the truth about how work gets done. A document can pass the first and fail the second, and when it does, nothing looks wrong. Nothing conflicts. Nothing is missing. Each program reads as several answers to the same question, and the crew at the excavation site picks one.

Conformance and coherence are scored separately, reported separately, and rolled together into a single index. Keeping them apart is what makes the diagnosis useful. Combining them is what makes it trackable.

That second question is not part of a traditional compliance review, because reviews grade documents one at a time. SC Diagnostic asks both. Every time.

Where it fits: step one of three

Too often, we start with step two, because step two feels like progress. But you cannot fix what you have not found, and you cannot sequence a fix you cannot rank. Work that starts at step two fixes the visible things, in the order someone remembered them, and leaves the structural problems where they were.

The SC Diagnostic is step one, and only step one. It is the one thing we do that is purely diagnostic, and it is not a commitment dressed up as an assessment.

What you get

Five parts, one fixed fee.

1. Background and scope

Your operator identity, assets, commodities, operating states, and a description of exactly what was reviewed.

2. Applicability determination

What applies to you and what does not, as citations rather than categories. This reaches past 49 CFR: the federal PHMSA requirements, the pipeline safety program of every state you operate in, and the consensus standards those rules incorporate by reference. It becomes a dated source of truth, and nothing downstream moves until it is finalized.

3. Gap analysis, at granular depth

Every applicable requirement broken down to the individual obligation and scored one at a time against your actual programs and records. No sampling, no screening, no program-level shortcuts. Every finding carries citation on both sides: the requirement, and the place in your program that is supposed to satisfy it.

Two things ride on each obligation that a conventional review leaves out.

The first is which rule actually governs you. Federal requirements are a floor, and states often impose something stricter on the same subject. We identify both and score you against whichever is more protective.

The second is the agency’s own published position. Findings are linked to the applicable FAQs, interpretation letters, advisory bulletins, and guidance tied to that citation, plus the enforcement record on it. That enforcement signal feeds the risk ranking so your priorities reflect what the agency has acted on rather than what feels urgent.

4. The SCI scorecard

The Systemic Compliance Index (SCI) is our own scoring construct, not a regulatory or industry standard. It has three components:

  • Conformance, the extent to which assessed obligations are fully met by your programs.
  • Coherence, scored from the document-to-document checks described above, and banded as Coherent, Partially Integrated, or Fragmented.
  • Effectiveness, whether the program is working in the field. This cannot be scored from documents. It requires operational evidence such as performance measures and assurance data.

Because a Diagnostic is a document and records review, Effectiveness reports as Pending until operational evidence is assessed. Pending is not a passing grade. It means the index is incomplete, and we will not hand you a finished number we did not measure.

All three components are always displayed alongside the index, never folded into it, so a program strong on Conformance and weak on Coherence shows both rather than an average that hides them.

The score is worth more the second time you see it. Because the SCI applies the same rubric to the same obligation set every time, a re-scored program is directly comparable to its own prior result: Conformance climbing as gaps close, Coherence climbing as the seams get connected. That is a trend you can put in front of your board, your insurer, or an inspector. Continuous improvement is a central tenet of any pipeline safety management system, and it is hard to demonstrate without a measure that holds still. The SCI is built to hold still.

5. Remediation roadmap and a one-page recommended path

This is the part most operators use hardest, because it is not a narrative. It is a ranked, prioritized to-do list.

Every gap becomes a line item you can assign. Each one carries what has to be done, the requirement driving it, its exposure across safety, environmental, enforcement, records, and civil liability, and its place in a Now / Next / Later sequence. Conformance fixes and coherence fixes are tagged separately, so you can see at a glance which items are document problems and which are integration problems, and you can hand a project manager the Now list without translating anything first.

On top of it sits a one-page recommended path your executive team can act on, with the full detail behind it.

Why coherence is the harder question

Conformance is well-understood work. Coherence is the half that explains why this service exists.

The regulations never settled on a single word for connecting your programs to each other. But the same requirement keeps surfacing in different clothes. Gas transmission operators are told outright to run a management of change process, with named elements and a consensus standard behind it. The integrity management rules require one as well, not by spelling it out again, but by pointing back at that same transmission requirement and making it a required element. Operator qualification, for gas and hazardous liquids alike, requires you to communicate changes that affect covered tasks to the people performing those tasks. Distribution integrity management is built on the assumption that information moves between programs.

Different words, different places, one idea. Everywhere you look in these rules, something is trying to make sure a change arrives where it matters. And whichever provision happens to name your operation, the underlying exposure is the same, because the pipe does not care which paragraph applies to it.

If your goal is passing an inspection, the floor may be enough. If your goal is minimizing risk, it is not. An operator who gets the change to the person doing the work is safer than the rules require. An operator who does not is exposed in a way no document review will show, because each document still passes.

And notice what every one of those requirements quietly assumes. To analyze the implications of a change, or to communicate it to affected parties, you have to already know what depends on what. You need a map. Almost nothing in the regulations requires you to have one. So the duty is real but the prerequisite is optional. Too often, the map ends up living in one person’s head, where it cannot be audited, inherited, or handed to a crew at 2 a.m.

This is also why management of change sits at the center of the API RP 1173 (Pipeline Safety Management System) framework, alongside safety assurance and management review. A management system is not a better binder. It is the machinery that carries a decision from where it is made to where it is executed, and then checks whether it landed. Coherence measures whether that machinery is working. An operator can adopt a PSMS, document it properly, and still be fragmented underneath it, and the PSMS will not tell you, because it was not built to grade itself.

What this looks like: DIMP

Distribution integrity management is the clearest worked example.

Under Subpart P, a DIMP is not a binder. It is the distribution operator’s risk system. Section 192.1007 requires a written plan with procedures for seven elements: knowledge of the system, identifying threats, evaluating and ranking risk, identifying and implementing measures to address those risks, measuring performance and evaluating effectiveness, periodic evaluation and improvement, and reporting results. Section 192.1011 separately requires records demonstrating compliance for at least ten years. Those are discrete, auditable duties, and a Diagnostic scores them one at a time.

But a DIMP fails at the seams more than on the cover page. It draws on leak history, corrosion records, damage prevention experience, and materials and construction records. It then has to push measures back out into O&M procedures and frequencies, contractor controls, operator qualification, corrosion monitoring, and emergency response. So a DIMP can conform to 192.1007 and still be incoherent:

  • The program ranks excavation damage as a top threat, but the damage prevention procedure and contractor onboarding never changed.
  • Leak history is named as the knowledge basis, but leak survey frequency in the O&M manual was never revisited.
  • A measure requires a new covered task, but Operator Qualification still qualifies to the old covered task list.
  • The manual was revised; the field form the technician fills out was not.
  • A state distribution requirement is stricter than the federal rule, and the program was written to the federal one.
  • Lessons from a line strike never re-enter threat ranking.

Every one of those is invisible to a review that reads the DIMP by itself, and every one is a real change to how work gets done.

DIMP is the sharpest illustration, not the only one. The same pattern runs through transmission integrity management and its preventive and mitigative measures, through control room management and the procedures it depends on, and through hazardous liquid integrity management.

You decide the scope

The deliverable is fixed. The subject matter is yours to set.

We will always recommend the connected set. Pick the program you are most concerned about, then include the programs it feeds and the programs that feed it. The DIMP example above is the reason: the coherence half of this service has more to work with as the dependency set fills in, and that is where the value concentrates.

If you want only one program assessed, we will do that, and we will do it well. It delivers the full five-part product within that boundary, scoped and priced to that boundary. Be clear-eyed about the limit. A single-program Diagnostic can tell you whether that program meets the rule. It cannot fully answer whether the system holds, because the second question needs the neighbors.

Start where your budget and your pain points are, and widen later if the first answer earns it.

How it runs

Four moves: Collect, Assess, Engage, Synthesize.

We do the homework before we spend your time. We assess what is applicable to you from the public record first, assets, commodities, operating states, and enforcement and incident history, with no meeting required. The meeting that follows is spent only on what public research cannot establish, and on confirming what we found.

Nothing proceeds on a guess. Every applicability line stays marked verify until it is confirmed by the operator.

It is reviewed by our advisory group before it reaches you. That group includes a former PHMSA Deputy Associate Administrator who helped write API RP 1173 and a career PHMSA inspector, plus operator, contractor, and code committee review. All are API-Approved PSMS Assessors. Systemic Compliance prepares and is responsible for the deliverable; the advisory group provides senior subject-matter review before it is delivered.

One fixed fee, sized to the scope you set.

What it is not

It is not a rewrite of your manuals, and it is not remediation. We diagnose. Building and fixing are separate, optional decisions you make afterward.

It does not cover occupational safety. The scope is pipeline safety: federal PHMSA requirements, state pipeline safety programs, and the standards those rules incorporate.

It is not legal advice. Systemic Compliance is not a law firm. We surface and flag.

Who should start here

  • Preparing for a PHMSA or state inspection, and you would rather find it yourself than be shown it by a regulatory inspector.
  • Suspicious of one program in particular. Start with that one and the programs around it.
  • Hiring for a compliance seat. The diagnosis helps define the job, and whoever you hire inherits a map instead of a backlog.
  • Buying, selling, or lending, and needing a diligence-grade read.
  • Considering a PSMS build or a platform change, and wanting the baseline first.
  • Fifteen years of accumulated programs, and no longer certain they still fit together.

What happens after

The diagnosis stands alone. You own it, and you can hand it to anyone.

Steps two and three are decisions you make once you can see the map, not commitments you make to get the map. And if the roadmap names work you decide to take on with our help, the Diagnostic fee becomes a credit balance against it. We will put the terms of that in writing before you commit to anything.

Start here

A twenty-minute conversation, not a proposal. We come back with exactly what the engagement should cover and what it costs before any work begins. Bring one document or bring all of them.

You are going to find out where you stand eventually. The only question is whether you find it, or whether an inspector does.

Start the conversation with us.

Telephone: 817-717-1563 · Email: info@systemic-compliance.com

Compliance should be systemic.

Regulatory citations are current as of publication and should be confirmed. Requirements described generally vary by pipeline type, commodity, and jurisdiction; applicability to your operation is determined in the engagement, not assumed here. API RP 1173 is a voluntary recommended practice; adoption and applicability vary. The Systemic Compliance Index is a Systemic Compliance scoring construct, not a regulatory or industry-standard measure. Public enforcement against other operators is used as a risk signal, never as evidence of your exposure. Systemic Compliance is not a law firm.

Ready to strengthen your compliance program?

Talk with our team about how Systemic Compliance can help align your organization with PSMS, RP 1173, and modern contractor accountability.

Discover more from Systemic Compliance

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Systemic Compliance

Subscribe now to keep reading and get access to the full archive.

Continue reading