Guide · Evidence

What auditors actually ask for

Terminal audits rarely fail because a record is missing. They fail because a record that exists cannot be produced in time, or cannot be shown to come from anywhere.

The distinction that decides the audit

Direct answer

Auditors test retrievability and traceability, not existence. Nobody asks whether you keep maintenance records: of course you do. They ask you to produce a specific set of them, joined to something else, within the time they have allotted. A record that takes four days to assemble is not functioning as evidence, regardless of how complete or accurate it is.

This is why the experience of a terminal audit so often surprises a well-run operation. The team knows the answers. The systems hold the facts. And the week still turns into an assembly project, because the request crossed a boundary that no single system spans.

The requests that recur

Across regulatory inspection, insurance review and certification audit, a consistent set of asks turns up. What they share is that none can be satisfied from one system.

The requestSystems it spansWhy it is hard
"Walk me through this incident."HSSE register, CMMS, gauging, shift logsThe register holds the event. The context around it, open work orders, tank activity, who was on shift, lives elsewhere.
"Show the corrective actions from last year's findings, and their closure."Audit file, CMMS, HSSEActions are raised in one place and executed in another. Closure evidence rarely returns to the finding.
"Which inspections are overdue, and what is the exposure?"Permits, inspection schedule, contractsOverdue is easy. Exposure requires knowing what each asset is committed to.
"Evidence that this recurring maintenance actually ran."CMMS historyUsually available, until the question is a five-year pattern rather than a single order.
"Who approved this change, and when?"Whichever system was editedFails where systems record current state without an attributable history of changes.
"Reconcile reported throughput against tank movements."Gauging, operations log, commercialTwo sources that were never designed to agree, reconciled by hand.

Note the pattern: the hard requests are the joined ones. Any single system, asked a question inside its own boundary, performs well.

The four properties of a record that holds up

Retrievable

Producible inside the window the auditor allows, not eventually. Same-day is the working expectation for records you are required to maintain.

Traceable

Every figure in a report links back to the source row it derives from. A summary nobody can drill into invites the follow-up it was meant to close.

Attributable

Who entered it, who changed it, when. A record with no actor is an assertion; one with an actor and a timestamp is evidence.

Tamper-evident

Silent post-hoc edits must be impossible or visible. This is the property spreadsheets structurally cannot provide, and auditors know it.

Why the spreadsheet summary backfires. A hand-built summary satisfies none of the four. It is retrievable only because someone already built it, traces to nothing, carries no attribution, and could have been edited five minutes before the meeting. Producing one in response to a request frequently generates more scrutiny than it resolves: the auditor now has to test the summary as well as the underlying question.

What "days, not minutes" actually costs

The direct cost is visible and usually accepted: a handful of senior operational people pulled off real work for a week, once or twice a year.

Three indirect costs are larger and rarely counted:

Closing the gap without replacing anything

The instinct is to consolidate. One system, one source of truth, a migration project measured in years. That instinct is usually wrong, for a reason that has nothing to do with software preference: your CMMS and gauging systems work, your team knows them, and replacing operational technology that functions is the single largest risk a terminal can take on voluntarily.

  1. Leave the systems of record alone. They stay authoritative for their own domain. Nothing migrates.
  2. Read what they already export. Scheduled reports and structured exports the systems produce today, without an integration project or a vendor API.
  3. Join on the operational entity. Tank, site, asset, counterparty. Joining on documents gives you search; joining on entities gives you answers.
  4. Attribute every change, append-only. Actor, timestamp, before and after. This is what converts a queryable record into an evidence trail.
  5. Test it against a real past request. Take an audit request from two years ago and answer it against the joined record. That comparison is the only benchmark that matters.

Common questions

Is this not what a document management system does?

A DMS makes documents findable, which solves retrievability for anything that is a document. It does not join a work order to a tank to a contract, because those are records rather than documents, and the relationship between them is the thing being asked about. The two solve adjacent problems and a terminal generally needs both.

Our CMMS vendor says their reporting module covers this.

For maintenance questions, quite possibly, and if so, use it. The test is whether it can answer a question involving a record the CMMS does not hold. Ask the vendor to show throughput reconciled against commercial commitment, or an incident timeline with tank activity alongside it. The answer is informative either way.

How far back does the historical record need to go?

Far enough to cover your retention obligations, which for HSSE records commonly runs to years rather than months. The more useful question is how far back it needs to go to be operationally valuable, and the answer there is usually further than compliance requires: recurring-failure patterns and effectiveness trends only become visible across several years.

What does this have to do with NIS2?

Several Article 21 obligations cover incident handling, business continuity, supply chain, and assessing effectiveness over time. All of them are demonstrated through exactly these records, and Article 23's 24-hour early warning turns reconstruction speed into a statutory constraint rather than an inconvenience. NIS2 for terminal operators →

Take last year's audit request and time it

Pick one request that crossed two systems. Reconstruct it against your current setup and note how long it takes. That number is your evidence readiness, and it is more informative than any assessment we could sell you.