Skip to content

Evidence request lists

EPA Risk Management Program (40 CFR Part 68)

Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Emergency Response Program

68.95
Written emergency response program with local coordination

Program 2 and 3 sources whose employees will respond to releases must maintain a written emergency response program covering: public and agency notification procedures, first-aid and medical treatment procedures, response actions for accidental releases, emergency equipment inspection and maintenance, employee training, and plan update procedures. Sources not employing responders must coordinate with local emergency services and conduct annual notification drills.

Artefacts an auditor will ask for
  • Written emergency response plan on file with last review date
  • Emergency notification procedures with current contact lists for LEPC, SERC, fire department, and 911
  • Annual coordination activity records with local fire department or LEPC
  • Annual notification drill records
  • Employee emergency response training records
  • Emergency equipment inspection and maintenance logs (SCBA, detection equipment, PPE)
  • Coordination agreement or LEPC plan inclusion documentation for non-responding facilities
Where this commonly fails
  • Emergency response plan exists but employees have not been trained on it
  • Local coordination activities not conducted annually
  • No annual notification drill records
  • Emergency contact lists outdated

Hazard Assessment

68.25
Worst-case and alternative release scenario analysis

All covered sources must document worst-case release scenarios per 40 CFR §68.25 (full vessel quantity release assumptions for toxic gases, 1 cm pool spill for toxic liquids, 10% yield VCE for flammables). Program 2 and 3 processes must also analyze at least one alternative release scenario per covered process. Scenarios must be reviewed and updated at minimum every five years, and within 6 months if operational changes alter endpoint distances by a factor of two or more.

Artefacts an auditor will ask for
  • Documented worst-case scenario analysis with quantity calculations, dispersion modeling methodology, and endpoint distances
  • Alternative release scenario analyses for Program 2/3 processes
  • Nearest public receptor identification and distance measurement
  • Five-year review records with comparison to prior scenario assumptions
  • Updated RMP submission records where endpoint distances changed significantly
  • Temperature data source documentation (three-year max daily temperature)
Where this commonly fails
  • Worst-case analysis not updated after inventory increases above original modeling quantity
  • No alternative release scenarios for Program 2/3 processes
  • Passive mitigation credited without meeting the §68.25 passive mitigation criteria
68.42
Five-year accident history documentation

All covered facilities must document accidental releases from covered processes over the preceding five years that caused on-site deaths, injuries, or significant property damage, or off-site deaths, injuries, evacuations, sheltering-in-place, property damage, or environmental damage. Each entry requires: date/time/duration, chemical, estimated quantity, release type, weather conditions, on-site and off-site consequences, initiating event, contributing factors, whether off-site responders were notified, and corrective actions taken.

Artefacts an auditor will ask for
  • Five-year accident history table in the RMP with all required fields
  • Incident investigation reports for each listed event
  • Emergency response notification records for off-site responders
  • Corrective action completion records cross-referenced to accident history
  • OSHA 300 Log cross-reference for on-site injury events
  • EPA and state agency enforcement records (to confirm no unreported incidents)
Where this commonly fails
  • Incidents with off-site consequence potential not included because no actual off-site impact occurred
  • Corrective actions documented only in the RMP without underlying investigation records
  • Five-year history not updated before RMP resubmission

Program 3 Prevention (PSM-equivalent)

68.65
Process Safety Information (PSI) compilation

Program 3 sources must compile written PSI before conducting any PHA, covering: hazards of regulated substances (toxicity, physical/reactivity data, inadvertent mixing effects), process technology (flow diagrams, safe operating limits, consequences of deviation), and equipment information (P&IDs, relief system design, materials of construction, applicable codes).

Artefacts an auditor will ask for
  • Complete PSI package for each covered process: SDS files, P&IDs (as-built and current), process flow diagrams
  • Safe operating limits table with consequences of deviation
  • Equipment design specifications (materials of construction, MAWP, design temperature, area classification)
  • Relief system design and sizing calculations
  • Applicable codes and standards reference list
  • Evidence PSI reflects current equipment (MOC cross-reference)
Where this commonly fails
  • P&IDs not updated after equipment modifications
  • Safe operating limits exist in operating procedures but not in a standalone PSI document
  • Relief system calculations not on file (only physical equipment present)
68.67
Process Hazard Analysis with 5-year revalidation

Program 3 processes must conduct PHA using HAZOP, What-If, FMEA, Fault Tree, or equivalent methodology by a team including operations expertise. PHA must address process hazards, prior incidents, engineering and administrative controls, siting, human factors, natural hazards, and safer technology alternatives. PHA must be revalidated every five years with records retained for the process lifetime.

Artefacts an auditor will ask for
  • Completed PHA report with methodology, team member names and qualifications, node-by-node analysis
  • PHA recommendation resolution log showing each finding, assigned owner, resolution date, and action taken
  • Revalidation schedule showing 5-year cycle and completed revalidations
  • All prior PHA records retained for the process lifetime
  • Evidence of operations, maintenance, and safety personnel participation in the PHA team
Where this commonly fails
  • PHA past the 5-year revalidation deadline
  • Recommendation resolution log not maintained (recommendations lost after original study)
  • PHA team does not include operations personnel with hands-on process knowledge
68.75
Management of Change (MOC) for processes, equipment, and procedures

Before implementing any change to process chemicals, technology, equipment, or procedures (excluding replacements in kind), Program 3 sources must document: technical basis, safety and health impacts, required procedure modifications, implementation timeline, and authorization. Affected employees must be trained before startup. PSI and operating procedures must be updated.

Artefacts an auditor will ask for
  • MOC forms for each change with technical review, safety assessment, and authorization signatures
  • Pre-startup training records for employees affected by the change
  • Updated P&IDs, process descriptions, and operating procedures cross-referenced to MOC number
  • Replacements-in-kind determination records where MOC was determined not required
  • MOC log showing all changes in chronological order with completion dates
Where this commonly fails
  • 'Temporary' changes made without MOC that become permanent
  • Replacements-in-kind determination not documented
  • PSI and operating procedures not updated after MOC completion
68.79
Compliance audits every 3 years with documented resolution

Program 2 and 3 sources must conduct compliance audits at least every 3 years to evaluate whether procedures are adequate and being followed. At least one auditor must be knowledgeable in the process. Third-party audits required after qualifying accidental releases or when mandated by the implementing agency. Two most recent audit reports must be retained.

Artefacts an auditor will ask for
  • Audit reports for two most recent cycles with audit dates and auditor names/qualifications
  • Written audit findings with severity ratings
  • Corrective action tracking log showing each finding, responsible person, target date, and completion status
  • Third-party audit reports where required (post-release or agency-mandated)
  • Evidence deficiencies were addressed promptly (work orders, procedure updates, training records)
Where this commonly fails
  • Audit conducted past the 3-year deadline
  • Findings documented but resolution not tracked to completion
  • Audit conducted entirely by facility personnel without knowledgeable external review
68.81
Incident investigation within 48 hours of qualifying releases

Program 2 and 3 sources must investigate each incident that resulted in, or could reasonably have resulted in, a catastrophic release. Investigation must begin within 48 hours. Program 3 reports must be completed within 12 months for §68.42(a) reportable accidents and include root cause analysis using a recognized analytical method. Reports must be reviewed with affected personnel and retained for five years.

Artefacts an auditor will ask for
  • Investigation initiation records showing date/time vs. incident date/time (48-hour compliance)
  • Investigation report with team member list, incident description, contributing factors, and recommendations
  • Root cause analysis documentation using a named methodology (TapRoot, MORT, Bow-Tie, 5-Why, etc.)
  • Recommendation resolution tracking system with completion evidence
  • Records of report review with affected personnel (sign-in sheets, meeting minutes)
  • 5-year retention of investigation reports
Where this commonly fails
  • Investigation not started within 48 hours because 'near-miss' classification used to defer
  • Root cause analysis performed but not using a recognized methodology
  • Recommendations tracked informally without completion evidence

Program Applicability and Management System

68.10
RMP applicability determination and program level assignment

Facilities holding any regulated substance at or above its threshold quantity (Appendix A to Part 68) in a process must comply with 40 CFR Part 68. Each covered process must be assigned to Program 1, 2, or 3 based on five-year accident history, distance to public receptors, NAICS code, and OSHA PSM applicability. The facility must submit a single RMP covering all covered processes.

Artefacts an auditor will ask for
  • Written applicability determination memo for each process showing regulated substance quantities vs. threshold quantities
  • Program 1/2/3 assignment rationale for each covered process
  • RMP registration confirmation from EPA RMP*eSubmit system
  • Distance-to-endpoint documentation for Program 1 determinations
  • Five-year accident history review supporting program level
Where this commonly fails
  • No written applicability determination (relies on informal knowledge)
  • Program level not reassessed after process changes or quantity increases
  • Facility changes caused threshold to be exceeded but no RMP filed
68.15
RMP management system with named responsible persons

Program 2 and 3 sources must establish a management system assigning overall responsibility for RMP implementation to a qualified person or position. Where responsibility is delegated, names or position titles and reporting relationships must be documented.

Artefacts an auditor will ask for
  • Written RMP management system document
  • Org chart or responsibility matrix naming the RMP program manager
  • Delegation records for each individual RMP element (PHA, mechanical integrity, MOC, etc.)
  • Job descriptions or role assignments for RMP component owners
Where this commonly fails
  • Overall responsibility assigned to a position that no longer exists
  • Delegation not documented for individual elements
  • No succession plan when the named program manager changes roles
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.