In this episode of the Pipeliners Podcast, Russel speaks with Mallory Gill of EnerSys Corporation about using software to align company policies and regulatory requirements.
They discuss the evolution of software tools like ComplyMgr, how they streamline compliance processes, and the shift towards proactive safety management.
Mallory shares insights from a customer case study and explores the concept of “natural compliance” as a goal for pipeline operators. They conclude with reflections on the importance of agility and continuous improvement in safety programs.
Using Software to Align Company Policies with Regulatory Requirements Show Notes, Links, and Insider Terms
- Control Room Management (CRM) A regulated discipline governing how pipeline control rooms are staffed, operated, and managed to ensure safe pipeline operations, often a primary focus of PHMSA audits.
- PHMSA (Pipeline and Hazardous Materials Safety Administration) The U.S. federal agency responsible for regulating and enforcing pipeline safety requirements, including audits, inspections, and enforcement actions discussed throughout the episode.
- Regulatory Gap Analysis A structured assessment comparing an operator’s policies and procedures against applicable regulatory requirements to identify deficiencies or gaps.
- Audit Protocol PHMSA-issued documents outlining inspection questions and evaluation criteria used during pipeline safety audits.
- Interpretation Guidance Official PHMSA clarifications explaining how specific regulatory requirements should be interpreted or applied by operators.
- Enforcement Guidance PHMSA documentation that provides insight into how the agency enforces regulations and evaluates compliance during inspections.
- Frequently Asked Questions (FAQs) Supplemental regulatory materials issued by PHMSA to clarify intent, expectations, or common compliance questions.
- Comply Manager (ComplyMgr) A software tool developed by EnerSys to centralize regulatory requirements, link them to company policies and procedures, and streamline compliance assessments and audit preparation.
- Compliance Review The term used within Comply Manager to describe a structured, software-based regulatory gap analysis.
- Policy–Procedure–Records Linkage The practice of connecting regulatory requirements to company policies, supporting procedures, and evidence records to demonstrate compliance during audits.
- Corrective Actions Required actions resulting from audit findings or enforcement activities intended to address identified compliance gaps.
- Key Performance Indicators (KPIs) Internal metrics used by operators to track compliance effectiveness, safety performance, and progress in closing regulatory gaps.
- Natural Compliance A philosophy where compliance becomes an inherent outcome of well-designed systems, processes, and workflows rather than a reactive, audit-driven activity.
- PSMS (Pipeline Safety Management System) An industry framework promoted by PHMSA and API focused on continuous improvement, proactive risk management, and systematic safety oversight.
- Change Assessment A review conducted when new or revised regulations are issued to determine applicability and required updates to policies, procedures, or programs.
- Continuous Assessment An ongoing, periodic evaluation of safety programs (e.g., quarterly reviews) rather than infrequent, audit-driven assessments.
- Stakeholder Feedback Input from personnel performing the work (“boots on the ground”) used to refine policies, procedures, and safety programs.
- Evergreen Safety Program A continuously maintained and updated safety management approach, rather than one based on annual or multi-year update cycles.
- Regulatory Applicability Determination The process of assessing whether a specific regulation or guidance applies to an operator’s system or operations.
- API (American Petroleum Institute) An industry standards organization referenced in connection with the API Pipeline Conference and broader pipeline safety initiatives.
- API Pipeline Conference An industry conference where regulatory, operational, and safety management topics—such as natural compliance and PSMS—are presented and discussed.
- Audit Readiness The state of having policies, procedures, records, and regulatory alignment prepared in advance of a PHMSA inspection.
- Proactive Compliance An approach that emphasizes identifying and closing gaps before audits occur, rather than reacting to findings after enforcement actions.
Using Software to Align Company Policies with Regulatory Requirements Full Episode Transcript
Announcer: Welcome to the “Pipeliners Podcast”, Episode 328, sponsored by EnerSys Corporation, providers of POEMS, the Pipeline Operations Excellence Management System, operations and compliance software for the pipeline operator to address safety program management, control room management, and field operations. Find out more about POEMS at enersyscorp. com.
[background music]
Announcer: The Pipeliners Podcast, where professionals, bubba geeks, and industry insiders share their knowledge and experience about technology, projects, and pipeline operations. And now your host, Russel Treat.
Russel Treat: Thanks for listening to the Pipeliners Podcast. I appreciate you taking the time and to show that appreciation, we give away a customized YETI tumbler to one listener every episode. This week, our winner is Doug Miller with the Knoxville Utilities Board. To learn how you can win this signature prize, stick around until the end of the episode.
This week, we speak with Mallory Gill to talk about using software to align regulatory requirements and procedures. Mallory, welcome back to the Pipeliners Podcast.
Mallory Gill: Thanks for having me again, Russel. Glad to be here.
Russel: You’re becoming an old hat at this, like an old hand.
Mallory: I’m a series regular at this point.
Russel: Yes.
Mallory: My name is going into the credits at the beginning of Pipeliners Podcast now.
Russel: There you go. Excellent. Oh, we should do that. We should roll credits, right?
Mallory: Yeah.
Russel: That’s good. Look, I asked you to come on today to talk about how to use software to align company policies and regulatory requirements. Before we dive in a little bit, we should probably both talk a little bit about what we’re doing in that domain.
I’ll start off and then I’ll let you pick up. EnerSys started doing regulatory gap analysis in the control room management world in 2008, 2009 timeframe. A couple of years in advance of the control room management rule going into law.
We did it the old school way. Out of that, us being software guys and me being a guy that always thinks there’s a better way to do something, we came up with an idea for a product and we created a product called ComplyMgr. This conversation is really about why we came up with that idea and what were some of the problems we’re trying to solve.
Maybe you could tell us a little bit about your background experience using ComplyMgr.
Mallory: Yeah, absolutely. When I started with EnerSys four years ago, this was the software tool that I was brought on to assist with in terms of compiling regulation, user experience, things like that. It really was a classic case of invention…What’s the term?
Russel: Invention out of necessity.
Mallory: Yeah. Necessity is the something of invention.
Russel: Necessity is the mother of invention.
Mallory: Yeah.
Russel: That’s what you’re looking for.
Mallory: Thank you. Yeah. We were doing audit prep for control room management operators using this old-fashioned way. Which for some operators listening to this might be their current way still of prepping for audit.
You have multiple tabs open, browsing thumbs are looking for the latest version of an audit protocol. You’re looking for interpretation guidance, enforcement guidances, frequently asked questions. Then there’s that additional layer of then how do I assess my policy against all of this kind of mountain of literature and regulation?
To your point, Russel we took that and we said, there’s a better way to do this. What we created is a tool set that already has the regulation compiled. You’re not sifting through various PHMSA links. I think I came on a podcast previously to talk about ComplyMgr and gave an anecdote about how I was tasked with compiling all these regulations. A ways into this project, I realized that I was using an outdated PHMSA link.
Russel: Oh my gosh.
Mallory: Yeah. We had done all this work to compile regulations and I realized how easy it is to just stumble across an audit protocol that’s out of date. It brought it all home for me and I said, “OK, yeah, there’s real value in having all of this updated, ready to go when an operator is prepared to assess their program.”
That’s that was the idea. Just first of all have all of the necessary documentation in one place easily accessible.
Russel: Yeah, I haven’t thought about it, but when we were doing the CRM gap analysis, one of the things that I was always frustrated by is we seem to be doing the same lift every single time. Like making sure that we had all of the audit protocol and all of the regulatory requirements fully properly documented.
Seems like we did that every time we did an assessment. I’m like, “Why are we doing the same work over and over again? This is crazy.”
Mallory: God forbid they release a new version of a document, and then you have to redo all of that work again. Yeah, it’s prohibitive, I think.
Russel: Yeah. I think it goes to how people like historic, and we were doing what people have historically done. We would build a spreadsheet, we’d put the audit protocol on the spreadsheet. We’d add places to make references to where does this exist in our policies and procedures, and then we’d make references, where does this PHMSA regulations, and then what audit questions relate to this. Then what FAQs relate to this.
We build all that out and then we go through it line by line in the spreadsheet. What I would say is extremely tedious and it was fairly error prone as manual processes tend to be.
Mallory: Doesn’t necessarily support analysis of results, identifying trends. Then to your point, if this is such a labor-intensive process, it’s not likely that the operators will have resources and time dedicated to doing this more than once or twice a year.
Or, in a time crunch in advance of an audit, just trying to figure out where your gaps are and do some last-minute prep. That’s when you don’t really want to be doing this work is when you have an audit in a couple months and you’re scrambling to get all of this information compiled.
Russel: Yeah. You don’t want to be doing this in the time period between receipt of the letter from PHMSA, and they’re arriving on site to perform the inspection.
Mallory: Yeah. It’s go time, right?
Russel: Yeah, right. It’s no, I’d rather spend that time getting ready to perform well in the audit versus just am I even ready for the audit? Which I think most people are answering that second question. Am I ready?
Mallory: Exactly. The approach that we’ve taken since implementing ComplyMgr. Obviously, we’ve eliminated so much of the upfront work in compiling the regulations, performing that linking in advance of even performing the assessment.
We save so much time and then we find that when we perform this work for clients in advance of their control room audits, that we have enough time to even close some of the gaps that we’ve found.
First of all, we’re not surprised by the state of our program. We know our strengths and we know our weaknesses and that’s key. That’s invaluable I think, not being surprised in an audit when or if they uncover something.
There’s that peace of mind and then yeah, just eliminating some of that prep time so that you can say here’s the state of my program. Now I have some additional time and I’m going to close some of my policy gaps while I’m here.
Russel: When you’re prepping for the inspection, there’s three levels there. Does my policy say what it needs to say to conform to what’s required? The next level is, do my procedures indicate I’m following my policy? Then the last one is, do I have records that indicate I’m in compliance with my policy?
Bing able to link all that together is really important for not only streamlining the inspection, but also streamlining the analysis.
Mallory: Yeah, absolutely.
Russel: We ought to talk a little bit about what are the things you need in the system to make this work well? I think one of the most critical things is you need to have the…One thing, the system should just contain all of the regulatory requirements and the supporting governing documents.
Things like frequently asked questions, standards, anything that is informing how you write and manage your program would need to be in the tool. Then the second thing is you’ve got to get all your policies and procedures in the tool, and you’ve got to link all that.
The thing that you really need is a quick, easy way to see, given this particular policy statement, what are all the things in the rule that are impacted by this policy statement? Then what are all the things that beyond just the letter of what’s in the rule, what are all the other things that have been said about that?
And corrective actions coming out of PHMSA, frequently asked questions, or any of that kind of thing. Having all of that in a single tool, having it all linked, and having views so that I can navigate it in an intelligent way, aligned with the way I do my work, really important.
Mallory: Yeah. I do find that…Your first point knowing exactly where in your policy is impacted by the rule or an audit question, that’s so important. I do find that your second point of the sort of context of the rule via FAQs and enforcement guidances, that that ends up actually saving a ton of time having that accessible.
There’s a lot of, for anyone who’s done audit prep, who’s assessed their program, there can be a lot of ambiguity and, how does this rule apply to us as an operator? How do I take this and apply it to us? Having some of that context available cuts down quite a bit on the back and forth of how do we apply this? Does it apply? How are other people doing this?
It definitely saves a little bit of that research and maybe arguing back and forth.
Russel: Yeah, exactly. I think that’s exactly right. I wanted to talk to you a little bit about a customer story. We have a customer who did what I would call an advanced adoption of this approach. They went all in. Could you walk us through a little bit, some of the key things they did to really get to an improved level of safety performance, and how they approach doing that using this tool set?
Mallory: Absolutely. This customer, I’ll call them operator X, did a number of things that set them apart and put them in, I would say, a super user category. I don’t mean super user in the sense that they have any more skill with the tool than any of our other users, but just that they’ve integrated it so fully into their policies, procedures, and compliance assessments that they’ve created a very efficient system using the tool.
As much as I would love to say, “Hey, implement this ComplyMgr tool and it will solve all of your problems.” It does require a degree of adoption. This operator X really saw the value of the tool right away. They immediately put a dedicated resource on ComplyMgr. Not all operators have the resources to have a dedicated individual for all of their safety programs.
At least one user who is intimately familiar with the tool can perform some internal training, and who can work with the individuals who update policy and procedure and figure out how to incorporate the use of the tool into run of the mill business practices.
This operator has a unique approach and that they didn’t just complete one compliance review up front. Compliance review is the term we use for gap analysis that’s specific to our ComplyMgr tool. Based on opportunity, because we’ve streamlined so much of the prep work that has to occur, they have taken that extra step to perform periodic assessments on a quarterly basis.
They’re assessing key parts of their program, in this case, control room management, assessing individual or parsing sections of the control room management program, and assessing those on a quarterly basis, and then being very targeted and intentional and proactive about closing those gaps throughout the year.
They’ve set internal KPIs and internal goals and initiatives around performing the assessments periodically, and then proactively closing them by the time the next quarter rolls around and they do another assessment.
Whereas some operators may see, “Hey, I’ve got this tool. It’s really helpful in advance of an audit.” The success that operator X is having is because they’re not just using it as a reactive tool. They’re seeing the value and they’re being proactive about it.
Russel: Yeah, they’re actually driving safety performance with the tool and the audit prep is a secondary benefit.
Mallory: Absolutely.
Russel: Yeah, and it’s really interesting because they’re doing it for the entirety of the safety program. All of the entirety of the PHMSA requirements for their pipeline operations. The other thing that you said early there, Mallory, I think I say this all the time, but software never solved a problem.
Software combined with the right organizational commitment and alignment will solve problems. A lot of times, you can get there without software tool, all the software tools it helps to ingrain it. It helps it to operate more smoothly once you make the shift. I think that’s a very important part of what, as you said, Operator X did.
The other thing is the ability to focus on specific areas allows them, when a change comes out, they can do a change assessment. When new regulatory requirements come out, they can do a change assessment, determine applicability, and work that into their quarterly cycle because they’re constantly doing that. It’s not like I got to get those gears up and going every time.
That’s one of the big challenges that operators have is because of the nature of their systems, tools, and approach is just a lot of effort to get the gears turning.
Mallory: While ComplyMgr does streamline, if you’re only assessing your program once a calendar year or once every three years, there’s still going to be a significant amount of prep work. Incorporating it and a continuous assessment of the program ultimately saves time in the long run when an audit comes around.
Russel: Yeah. I think the other thing too, that you were saying that the idea of this idea of what I would call a very focused plan for how we are going to adopt, and get the value out of the program. That’s one of the things that operator X did really well.
I think the dedicated person was just part of a bigger plan that they had about how are we actually going to make this drive value for us.
Mallory: Operator X is a great example of really what any company should do when they make the decision to implement software, no matter what the software is. They committed fully to the implementation of the software and to realizing the value of the software. It has paid off for them.
Russel: We probably ought to talk a little bit about what drives us to do all this, and what is the broader vision around this idea? We’ve coined a phrase that we call natural compliance. Which is the idea that if I put my systems in the right way, and I define my work in the right way, then compliance is just there.
What I mean by that is if you do what operator X has done, you don’t have to worry about, am I compliant? Because you’re always compliant and you always understand the state of your compliance. That compliance becomes natural. It’s just, I’m doing work, and my compliance is the natural outcome of the work I’m otherwise doing.
What would you say that that operator X is doing well in that domain?
Mallory: Yeah, that’s a great question. That’s the root of why they’re having so much success with the tool, and with their kind of proactive assessment of their programs. Like we said, they committed very fully to realizing the value of this tool.
Then they took that one step further and having this dedicated individual to bridge the gap between software, policy, and procedure, they took that additional step of creating internal policies and procedures that revolved around the use of the tool, and they combined the use of the tool with existing compliance activities.
What some operators may be hesitant to do is to rework their policies when they adopt a software tool, they say, “We’re doing this work. We’re alluding to it in our policies and procedures. We’re just using this tool to accomplish it.”
What they did is they said, “Here is the value that we want to see with this tool. Here is how this tool can help us be proactive in our program. We’re going to take that extra step and make a commitment to being very safety management forward. We’re going to implement policy and procedure.” That otherwise they wouldn’t be able to achieve without a tool that streamlines that work.
They’re really holding themselves accountable via policy and procedure.
Russel: Yeah. It’s not just policy and procedure that implements what’s required by PHMSA. It’s policy and procedure for how we use our tools and systems to make sure that we have our desired level of safety performance.
What I was going to ask is where are they going next? Where are they going next with this whole plan? What I’m driving at is the approach to pipeline safety management.
Mallory: Where they’re going next is what I imagine to be the end result of what we’re trying to achieve with initiatives like PSMS, adopting and creating systems that enable proactive safety management.
I really think that some of the PSMS initiatives are completed. We talk about natural compliance, and we’ve talked about this in the previous podcast, but PSMS is realized because they are being so proactive.
Russel: Yeah, I think you’re right. I think this is what we’re looking to discover. When you’re really leaning into a problem like that, an opportunity, or a challenge, frame it how you like, you don’t really know everything you need to know going in. They’re already implementing PSMS on the program.
I would think that the next opportunity for them is to implement PSMS on the procedures, and the systems for doing the work. Been a while since we’ve talked to them, so they may already be leaning into that. To me, that’s just the natural part of this.
Because they’ve already got natural compliance working around all their policies and procedures. What we don’t know is do they have it working around their record keeping and KPIs. That’s probably what’s next. There’s opportunity for us. Certainly we’re having conversations about what that would look like for us as we go forward and try to learn and support the industry.
Mallory: Yeah, I do think that’s an interesting point. When we talk about PSMS, we’ve talked about having to be a little bit agile and the way that we adjust our KPIs and assess the effectiveness of our program. I think if at the highest level, at the policy level, you’re already implementing that practice, that it becomes much easier to adapt when you receive that feedback from boots on the ground.
When you engage with your stakeholders, the whole vision of PSMS becomes a little bit more attainable when the systems are agile. Assessing your policy on a semi-periodic basis does enable that.
Russel: Yeah, that’s actually really good. I hadn’t thought about that, but you’re absolutely right. If you build that muscle, if you build that competency, that way of thinking about the work that, we’re going to take feedback and we’re going to immediately put it into this quarterly review process.
You’re causing my mind to spin, Mallory. That’s awesome. You just gave the gears a big kick and they’re spinning. What I’m seeing is if I can combine that quarterly cycle with stakeholder feedback, then I really have an opportunity to do some lift in the organization. Then I can focus on driving it down, not just building the cycle, if that makes sense?
Mallory: It does. I like what you said about building the muscle. That, again, comes back to the idea of building trust, disposition, resolution of feedback, and observations from the individuals performing the work. It also, I think creates, I’ve said attainable, but the lift to respond, react, and update our operating practices is significantly less if you’re attacking it throughout the year, as opposed to one annual update, right?
Russel: Yeah, there’s two problems with that. One, is there’s more work and the other is when you’re doing it quarterly, and that’s an ongoing thing that you’re doing, versus doing it annually or longer, it’s actually not just four times the work, because it’s more effort to get your brain fully wrapped around your current context.
Mallory: I do think it’s a totally different mindset and it suggests that safety programs should be managed as an evergreen system, versus what we’re used to is the annual 12 to 15, not to exceed 15 months. Collect, collect, collect and then implement and adjust. This is really speaking to a totally different mindset, which is, adjust constantly. That shortening the timeframe between collecting feedback and adjusting.
Russel: Yeah. I think a lot of people listen to this, that comment will blow their head up a little bit when they start trying to wrap their mind their mind around the level of work. If you modify the systems correctly, you can actually reduce the work by doing it more frequently. That’s counterintuitive, but it’s true.
Mallory: Hopefully improve the quality and the safety.
Russel: Yeah, absolutely. Look, I think that’s a great place to leave the conversation. I will say for the listeners that this is a little different than what we often do, and I hope this doesn’t come off as commercial. That’s really not the intent. The intent here is to educate people about what we’re finding in the work that we’re doing around compliance and safety performance.
I think that one of the things that Mallory said here that I’m taking away, because I always learn in these conversations as well, is part of the leap or the migration from compliance to safety is the speed at which you run these cycles and make the corrections.
Mallory: Yeah. That is food for thought.
Russel: Yeah, it is food for thought. I don’t know what we do with that, but we’ll figure that out. When we figure that out, we’ll do another podcast and let everybody know. If you want to hear more about this subject, we will be at the API Pipeline Conference and we’re giving a paper on this subject. Plan to come to the API Pipeline Conference and look us up. We’d love to talk to you.
Mallory: I’ll see you there.
Russel: All right. Thanks, Mallory. I hope you enjoyed this week’s episode of the Pipeliners Podcast and our conversation with Mallory. Just a reminder, before you go, you should register to win our customized Pipeliners Podcast YETI Tumbler. Simply visit pipelinepodcastnetwork.com/win and enter yourself in the drawing.
If you’d like to support us, best way to do that is leave a review, and you can do that on Apple Podcasts, Google Play, wherever you happen to listen, and you can find instructions at pipelinepodcastnetwork.com.
[background music]
Russel: If you have ideas, questions, or topics you’d be interested in, please let me know on the Contact Us page at pipelinepodcastnetwork.com, or reach out to me on LinkedIn. Thanks for listening. I’ll talk to you next week.



