Regulatory Compliance Audit
Regulatory Compliance Audit Services
An audit conducted by a regulatory agency looks for violations. An audit conducted by iSi looks for gaps before the agency arrives. A comprehensive assessment of your facility's compliance with OSHA, EPA, and state agency requirements — delivered with a prioritized action plan.
What a Regulatory Compliance Audit Covers
Regulatory compliance audits are comprehensive assessments that map which regulations actually apply to your facility, evaluate your current compliance status against those regulations, and document what needs to change.
Regulatory Applicability Review
Determine which federal, state, and local requirements actually apply to your facility. Many operations are either over-regulated (wasting resources) or under-regulated (carrying hidden exposure). We identify which regulations bind your operation and quantify the compliance burden.
Compliance Gap Assessment
Against each applicable regulation, assess your current compliance status. Document what you're doing right, identify specific gaps, and quantify the regulatory risk of each gap in terms of penalty exposure and enforcement likelihood.
Documentation & Permitting Review
Verify that required permits are current and properly maintained. Confirm that required documentation exists, is accessible, and meets regulatory standards. Identify missing or outdated documents.
Cross-Program Integration
Identify where environmental, safety, and health compliance requirements overlap or conflict. Many facilities miss cross-program gaps because separate teams manage each domain independently.
Personnel Training & Competency
Verify that personnel responsible for compliance-critical tasks have received required training and possess documented competency. Many violations arise from untrained personnel.
Corrective Action Planning
Produce a prioritized findings report with a detailed remediation roadmap: what needs to change, in what order, with cost estimates, timelines, and assigned responsibility.
When You Need One — 5 Triggers
A regulatory compliance audit becomes essential when your compliance status is unclear or has changed. Here are the five most common triggers.
1. New Facility or Acquisition
You've opened a new facility or acquired an operation. Regulatory applicability is unknown. You don't have documented baseline compliance. An audit establishes which regulations apply and identifies what needs to be built or corrected immediately.
2. Change in Ownership or Control
Change of ownership creates legal continuity questions. Banks, PE investors, and strategic acquirers require audit evidence of baseline compliance. A formal audit documents your starting point and prevents surprises from undisclosed regulatory exposure.
3. Notice of Violation (NOV) Received
An EPA or OSHA agency issued a Notice of Violation. Before responding, you need to understand whether the NOV represents an isolated gap or a systemic compliance failure. An audit identifies the full scope of the problem and prevents similar violations elsewhere.
4. New Regulation or Industry Change
New EPA or OSHA rules affecting your industry have taken effect. Your existing compliance program may not cover the new requirements. An audit maps the changes and identifies what documentation, training, or operational changes are needed.
5. Routine Compliance Review
You haven't audited your facility's regulatory compliance in 12+ months. Regulations change, personnel turn over, and operational changes create gaps silently. A periodic audit — even without a specific trigger — validates that your compliance program remains current.
Regulations iSi Audits Against
iSi conducts regulatory compliance audits across federal and state frameworks. Which regulations apply to your facility depends on your industry, processes, and location. The audit determines applicability.
OSHA Standards (29 CFR)
Occupational Safety and Health Administration requirements covering workplace safety, hazard communication, fall protection, respiratory protection, personal protective equipment, machine guarding, lockout/tagout, and industry-specific standards.
EPA Environmental Rules (40 CFR)
Environmental Protection Agency requirements covering air emissions (CAA, NESHAP, MACT, Title V), water discharge (CWA, stormwater, wastewater), waste management (RCRA, hazardous waste), contaminated sites (CERCLA, petroleum underground storage tanks), and emergency planning (EPCRA).
State Agency Requirements
State-specific environmental and safety regulations from the respective state environmental department. Requirements vary significantly: Kansas (KDHE), Missouri (MDNR), Oklahoma (ODEQ), Nebraska (NDEE), and others. Some states impose stricter requirements than federal minimums.
Industry-Specific Standards
Manufacturing, construction, industrial hygiene, transportation, and other vertical standards where regulations are more specific than general industry rules. Examples: foundry standards, construction work zones, chemical manufacturing process safety.
Engagement Process
iSi's regulatory compliance audits follow a defined process designed to be comprehensive without disrupting your operations.
We gather information about your facility, operations, processes, and industry. We identify preliminary regulatory applicability and schedule the site visit.
Comprehensive walkthrough of all operational areas. Document review. Interviews with operations and compliance personnel. Photographic evidence of observations.
Detailed analysis of findings against applicable regulations. Documentation of each gap with regulatory citation, risk ranking, and penalty exposure estimate.
Prioritized findings report with detailed corrective action plan. Cost estimates, timelines, and responsibility assignment for each remediation item.
What It Costs
Regulatory compliance audit pricing is based on facility size, number of applicable regulations, and operational complexity. Most audits fall into one of three price tiers.
A full-time compliance officer costs $130,000–$195,000 per year. An iSi regulatory compliance audit typically identifies critical gaps within 2–4 weeks, after which most clients move to a COOP retainer for ongoing oversight — combining periodic audits, regulatory monitoring, and documentation management for $15,000–$90,000/year. One team, one retainer, 40 states.
Regulatory Gaps Most Facilities Miss
These compliance gaps are common. They look invisible until an audit or inspection reveals them.
You Have the Permit. You Don't Have Current Compliance with It.
A facility holds an EPA air permit (Title V) or wastewater discharge permit (NPDES). The permit exists and is technically "current." But internal procedures for monitoring, reporting, and maintenance haven't been updated to match the permit conditions.
The facility is technically in violation without knowing it — because nobody cross-referenced the permit language with operational procedures.
EPA permit violations carry penalties of $15,000–$40,000+ per violation. Each missed monitoring event is a separate violation.
Is this happening at your facility?
The Regulation Changed. Your Compliance Program Didn't.
A new EPA or OSHA rule took effect affecting your industry. Your compliance program was designed for the old standard. Nobody has reviewed the program against the new requirements because the change was buried in the Federal Register or missed during routine monitoring.
You're not deliberately non-compliant — you just don't know the new rule exists or how it applies to you.
Regulatory agencies expect you to know about changes affecting your operation. Ignorance is not a valid defense.
Is this happening at your facility?
We Plug In. You Level Up.
A regulatory compliance audit is where the relationship often starts. You discover what's broken via the audit. Then iSi stays in place via a COOP retainer to keep it from breaking again.
iSi doesn't replace your safety manager or compliance officer. We plug in alongside them. Your person handles the 40% of compliance work requiring on-site presence and professional judgment. iSi handles the 60% surrounding work — the monitoring schedules, regulatory tracking, documentation, permit renewals, and training calendars that consume bandwidth without requiring physical presence.
Regulatory Compliance Audit FAQ
What is a regulatory compliance audit?
A regulatory compliance audit is a comprehensive assessment of your facility's compliance with applicable EPA, OSHA, and state agency requirements. It identifies which regulations apply to your specific operation, assesses your current compliance status against those regulations, documents gaps, and produces a prioritized action plan for remediation.
What regulations does iSi audit against?
iSi conducts regulatory compliance audits covering OSHA standards (29 CFR Part 1900+), EPA environmental regulations (40 CFR across multiple environmental media), and state-specific agency requirements from the respective state environmental department. Audits assess applicability to your specific facility and operations — you may be over-regulated or under-regulated depending on your industry and location.
Who needs a regulatory compliance audit?
Any facility should consider an audit after: a new facility opening or acquisition (regulatory applicability unknown), a change in ownership or operational control, receipt of a Notice of Violation (NOV) or enforcement letter, significant new regulation affecting your industry, or if you haven't audited for 12+ months. Multi-site operators often audit to establish baseline compliance across their portfolio.
How does a regulatory compliance audit differ from an internal audit?
An internal audit evaluates your facility against your own documented policies and procedures. A regulatory compliance audit measures your facility against external regulatory standards — EPA and OSHA rules that are legally binding. Regulatory audits are often required after enforcement activity or as part of due diligence for acquisition. Many facilities do both: internal audits for continuous improvement, regulatory audits for external accountability.
What does a regulatory compliance audit cost?
iSi's regulatory compliance audits start at $4,200 for a straightforward single-facility assessment and scale based on facility size, number of applicable regulations, and complexity of operations. A full-time compliance officer costs $130,000–$195,000/year; an iSi audit typically identifies critical gaps within 2–4 weeks, after which clients often move to a COOP retainer for ongoing oversight at $15,000–$90,000/year.
What happens after the audit is complete?
You receive a prioritized findings report detailing each regulatory gap, the specific regulation(s) violated or at-risk, risk ranking, and a corrective action plan with timelines and cost estimates. Most clients transition from audit to a COOP retainer for ongoing compliance oversight — the audit identifies what's broken, the retainer prevents it from breaking again.
Service Available in These Markets
Related Compliance Services
Regulatory Gaps Hide Until an Audit or Inspection Reveals Them.
Find them first. Get a regulatory compliance audit tailored to your facility and your regulations.
Scope Your Regulatory Compliance Audit