Terminal audits rarely fail because a record is missing. They fail because a record that exists cannot be produced in time, or cannot be shown to come from anywhere.
Auditors test retrievability and traceability, not existence. Nobody asks whether you keep maintenance records: of course you do. They ask you to produce a specific set of them, joined to something else, within the time they have allotted. A record that takes four days to assemble is not functioning as evidence, regardless of how complete or accurate it is.
This is why the experience of a terminal audit so often surprises a well-run operation. The team knows the answers. The systems hold the facts. And the week still turns into an assembly project, because the request crossed a boundary that no single system spans.
Across regulatory inspection, insurance review and certification audit, a consistent set of asks turns up. What they share is that none can be satisfied from one system.
| The request | Systems it spans | Why it is hard |
|---|---|---|
| "Walk me through this incident." | HSSE register, CMMS, gauging, shift logs | The register holds the event. The context around it, open work orders, tank activity, who was on shift, lives elsewhere. |
| "Show the corrective actions from last year's findings, and their closure." | Audit file, CMMS, HSSE | Actions are raised in one place and executed in another. Closure evidence rarely returns to the finding. |
| "Which inspections are overdue, and what is the exposure?" | Permits, inspection schedule, contracts | Overdue is easy. Exposure requires knowing what each asset is committed to. |
| "Evidence that this recurring maintenance actually ran." | CMMS history | Usually available, until the question is a five-year pattern rather than a single order. |
| "Who approved this change, and when?" | Whichever system was edited | Fails where systems record current state without an attributable history of changes. |
| "Reconcile reported throughput against tank movements." | Gauging, operations log, commercial | Two sources that were never designed to agree, reconciled by hand. |
Note the pattern: the hard requests are the joined ones. Any single system, asked a question inside its own boundary, performs well.
Producible inside the window the auditor allows, not eventually. Same-day is the working expectation for records you are required to maintain.
Every figure in a report links back to the source row it derives from. A summary nobody can drill into invites the follow-up it was meant to close.
Who entered it, who changed it, when. A record with no actor is an assertion; one with an actor and a timestamp is evidence.
Silent post-hoc edits must be impossible or visible. This is the property spreadsheets structurally cannot provide, and auditors know it.
The direct cost is visible and usually accepted: a handful of senior operational people pulled off real work for a week, once or twice a year.
Three indirect costs are larger and rarely counted:
The instinct is to consolidate. One system, one source of truth, a migration project measured in years. That instinct is usually wrong, for a reason that has nothing to do with software preference: your CMMS and gauging systems work, your team knows them, and replacing operational technology that functions is the single largest risk a terminal can take on voluntarily.
A DMS makes documents findable, which solves retrievability for anything that is a document. It does not join a work order to a tank to a contract, because those are records rather than documents, and the relationship between them is the thing being asked about. The two solve adjacent problems and a terminal generally needs both.
For maintenance questions, quite possibly, and if so, use it. The test is whether it can answer a question involving a record the CMMS does not hold. Ask the vendor to show throughput reconciled against commercial commitment, or an incident timeline with tank activity alongside it. The answer is informative either way.
Far enough to cover your retention obligations, which for HSSE records commonly runs to years rather than months. The more useful question is how far back it needs to go to be operationally valuable, and the answer there is usually further than compliance requires: recurring-failure patterns and effectiveness trends only become visible across several years.
Several Article 21 obligations cover incident handling, business continuity, supply chain, and assessing effectiveness over time. All of them are demonstrated through exactly these records, and Article 23's 24-hour early warning turns reconstruction speed into a statutory constraint rather than an inconvenience. NIS2 for terminal operators →
Pick one request that crossed two systems. Reconstruct it against your current setup and note how long it takes. That number is your evidence readiness, and it is more informative than any assessment we could sell you.