Engineering Firm Regulatory Compliance Checklist
Quarterly compliance review run by the Compliance Officer at an engineering consulting firm, covering PE licensure and sealed work, IT and export controls, environmental permitting, workplace and field safety, and professional ethics. Findings flow to the QA/QC Manager and Pri...
Licensure & Sealed Work Compliance
-
Verify PE licenses across states of practice
Pull each licensed engineer's NCEES record or state-board verification for every state where they have sealed work in the last 12 months. Flag anyone whose renewal cycle closes in the next 90 days; lapsed renewals during a sealing window are unauthorized practice and a board-discipline risk.
Collects list -
Remediate lapsed or pending licenses
For each lapse, freeze new sealing assignments until the state board confirms reinstatement. Identify any deliverables sealed during the lapse window and consult counsel on disclosure to the client and AHJ. Document required PDH makeup including any state-mandated ethics hours.
-
Audit seal use against the issued-deliverables log
Cross-check the firm's IFC / IFB / permit-set log against EOR scope-of-competence records. Confirm calculation packages are PDF'd, dated, and archived alongside each sealed drawing set, and that any specialty work (geotech, fire protection, blast, seismic) was sealed by a specialist rather than by the lead EOR.
Data Security, IT & Export Controls
-
Refresh the software and hardware inventory
Reconcile licensed seats for AutoCAD, Revit, Civil 3D, ProjectWise, ACC, and the analysis suites (SAP2000, ETABS, RAM, RISA, HEC-RAS) against active staff. Flag retired hardware still attached to license tokens and any unmanaged personal devices accessing the CDE.
Collects file -
Review access controls in ProjectWise and ACC Docs
Run the access report for each active project workspace. Remove subconsultants whose contract closed last quarter and confirm sealed-deliverable folders are read-only outside the EOR group. Verify CAD files released externally carry the firm's non-reliance disclaimer.
-
Identify active CUI and ITAR-controlled projects
Walk the active project list with the PMs and tag any federal contracts carrying Controlled Unclassified Information clauses, DoD work subject to CMMC, or ITAR/EAR-controlled deliverables. Confirm the access list is restricted to US-person staff with documented need-to-know.
Collects list -
Audit NIST 800-171 controls on CUI engagements
Walk the 14 control families and confirm the SSP and POA&M reflect current configurations. Pay special attention to media protection (CAD files on portable drives) and incident response timing — DoD reporting is 72 hours from discovery, not from confirmation.
-
Verify backup and disaster-recovery test logs
Confirm the last quarterly restore test actually restored a project from cold storage — not just that the backup job ran green. Project archives covering the statute-of-repose window (typically 6-12 years from substantial completion) need readable native CAD and Revit, not just PDFs.
Environmental & Permitting Compliance
-
Audit NPDES and SWPPP coverage on active sites
For every project disturbing more than one acre, confirm the construction general permit NOI is on file and the SWPPP is current with the latest grading set. Designer-drafted SWPPPs that didn't get updated after a redesign are a common citation source for owners.
Collects file -
Verify NEPA documentation on federal projects
Confirm each federal-aid or federal-permit project has the right NEPA pathway documented — CatEx, EA / FONSI, or EIS — and that Section 7 (ESA), Section 106 (NHPA), and Section 4(f) consultations are closed before any final design seal. Flag any project advancing to PS&E without environmental clearance in hand.
-
Confirm Phase I ESA record currency
Per ASTM E1527, records older than 180 days at signature break the AAI requirement and the innocent-landowner defense goes with them. Pull the records date for each open Phase I and trigger refreshes where the report has been sitting on a closing schedule.
-
Reconcile Section 404 and floodplain permits
Cross-check active wetlands fills against issued Corps permits and verify CLOMR/LOMR submittals match current grading. Confirm every floodplain drawing labels its datum (NGVD29 vs. NAVD88) and conversion factor — datum confusion remains the most common reason a building ends up below the LFE.
Workplace & Field Health & Safety
-
Conduct office and field safety inspections
Walk the office for egress, electrical, and ergonomic findings. For field staff, audit the last month of construction-observation visit logs — confirm site-specific JHAs were completed and that observation reports define what was and was not observed (an observation is a snapshot, not an inspection).
-
Verify OSHA 10 and 30 training currency
Pull training records for every Resident Engineer, Construction Inspector, and Field Engineer. OSHA 10 minimum for site visitors; OSHA 30 for full-time CA staff. Add NFPA 70E arc-flash awareness for anyone observing energized electrical work and confined-space training where applicable.
-
Review the incident log and corrective actions
Reconcile the OSHA 300 log with internal incident reports for the quarter. Confirm corrective actions from prior incidents are closed or have a documented in-progress owner; recurring near-misses on the same site are a leading indicator that warrants a stop-work conversation with the contractor.
Collects file
Professional Ethics & Anti-Corruption
-
Refresh conflict-of-interest disclosures from PMs and PICs
Send the disclosure form to every Principal-in-Charge and Project Manager. Probe for ownership stakes in contractors or material suppliers, family relationships with AHJ reviewers, and side-consulting that could implicate the NSPE paramountcy-of-public-safety obligation.
-
Verify FCPA and anti-bribery training records
For staff supporting international pursuits or federally-funded projects, confirm FCPA training is current within the past 12 months. Re-circulate the gifts-and-hospitality policy before year-end conference season — vendor-paid travel to industry events is the most common policy gray-zone.
-
Review the ethics hotline log
Pull every report submitted since the prior compliance review. Triage by severity and confirm anonymous reports were not back-traced. Cross-reference against state-board complaint inquiries the firm has received.
Collects list -
Investigate open ethics hotline reports
Assign an investigator outside the reported person's reporting chain. Document interview dates, evidence reviewed, and disposition. For findings that touch sealed work or public safety, escalate to outside counsel and consider mandatory state-board self-reporting under the engineer's ethical obligations.
-
Sign off on the quarterly compliance review
The QA/QC Manager and Principal-in-Charge review findings together. A 'Pass with findings' disposition requires a tracked POA&M with dated owners; a 'Fail' triggers a board-level briefing within two weeks.
Collects list Collects paragraph Collects signature
Use this template
Copy it to your account, customize the steps, and run it with your team in minutes.
Browse hundreds of free templates across every team and industry.
Back to template libraryRun Engineering Firm Regulatory Compliance Checklist with your team
Customize the steps, assign roles, set a schedule, and keep a complete record for every run.