CSA N286-12, Management system requirements for nuclear facilities, is the standard CNSC licensees build their management systems on. The standard itself is copyrighted, so this checklist is organised around its 12 principles as the CNSC lists them in REGDOC-2.1.1. The questions, records and findings under each principle are ours. Check every answer against N286-12 itself.

Confirm the scope before you start. Section 4 of N286-12, the generic requirements, applies to every facility type. One further section applies depending on your facility. Your licence sets out what applies to you.

Which edition, and which sections

CSA N286-12

The current edition is CSA N286-12, Management system requirements for nuclear facilities, published in 2012 and reaffirmed in 2022 (R2022). It replaced N286-05. CSA store

Commentary

CSA N286.0.1:21 (R2026) is the commentary on N286-12. REGDOC-2.1.1 says the commentary “provides background information concerning certain clauses and requirements in CSA N286-12”. CSA store

CNSC

REGDOC-2.1.1, Management System (2019), says the CNSC “expects licensees to adhere to all CSA N286-12 principles as the basis of their management system”, and that it “does not duplicate the generic requirements of CSA N286-12”. REGDOC-2.1.1

REGDOC-2.1.1 sets out which sections of N286-12 apply to each facility type:

Facility typeApplicable sections of CSA N286-12
Uranium mines and mills4. Generic requirements for the management system
5. Specific requirements for uranium mines and mills
Uranium processing and fuel manufacturing facilities4. Generic requirements for the management system
6. Specific requirements for uranium processing and fuel manufacturing facilities
High energy reactor facilities4. Generic requirements for the management system
7. Specific requirements for high energy reactor facilities
Research and isotope processing facilities4. Generic requirements for the management system
8. Specific requirements for research and isotope processing facilities
Radioactive waste management facilities4. Generic requirements for the management system
9. Specific requirements for radioactive waste management facilities
00

Before the audit

If you only have time for one of these, do the trace. Following real work, a real change and a real problem through your system turns up the same gaps an assessor will find.

The checklist, principle by principle

01

Safety comes first

Principle 1

“safety is the paramount consideration guiding decisions and actions”

CNSC REGDOC-2.1.1, section 2

The assessor checks that safety is weighed in decisions at every level, that people can raise concerns and stop work, and that safety culture is looked at, not assumed.

Questions to answer

Records to have ready

  • Safety policy signed by top management
  • Safety culture assessment and action plan
  • Records of concerns raised and how they were resolved
  • Decision records for a recent significant change

Common finding

A schedule-driven decision to defer a safety-related task, with no record of who weighed the risk or why.

02

The business is planned and controlled

Principle 2

“the business is defined, planned and controlled”

CNSC REGDOC-2.1.1, section 2

The assessor checks that the management system is documented, that its processes have owners, and that the requirements of the licence and licensing basis are traced to the processes that meet them.

Questions to answer

Records to have ready

  • Management system description
  • Process map with owners
  • Requirements-to-process traceability
  • Business plan and objectives with progress reports

Common finding

A licence condition with no process owner, found only when the assessor asked who is accountable for it.

03

The organization is defined and understood

Principle 3

“the organization is defined and understood”

CNSC REGDOC-2.1.1, section 2

The assessor checks that roles, responsibilities, authorities and interfaces are written down and that the people in those roles understand them.

Questions to answer

Records to have ready

  • Organization chart
  • Role descriptions and authorities
  • Interface agreements with contractors and other organizations

Common finding

A reorganization that changed reporting lines without updating the role descriptions or the management system documents.

04

Resources are managed

Principle 4

“resources are managed”

CNSC REGDOC-2.1.1, section 2

The assessor checks that you have enough qualified people, the right equipment and the funding the work needs, and that you plan for changes in all three.

Questions to answer

Records to have ready

  • Minimum staffing requirements
  • Training and qualification records
  • Succession plans for key roles
  • Equipment maintenance records

Common finding

A qualified position left vacant for months with its duties spread informally across people not trained for them.

05

Communication is effective

Principle 5

“communication is effective”

CNSC REGDOC-2.1.1, section 2

The assessor checks that expectations, decisions and changes reach the people who need them, and that information flows back up as well as down.

Questions to answer

Records to have ready

  • Communication plans
  • Records of briefings on recent changes
  • Staff feedback and responses
  • Correspondence control for regulator communications

Common finding

A procedure change issued without a briefing, so the night shift kept working to the old version.

06

Information is managed

Principle 6

“information is managed”

CNSC REGDOC-2.1.1, section 2

The assessor checks that documents and records are controlled, current, retrievable and kept for as long as required.

Questions to answer

Records to have ready

  • Controlled document list
  • Records retention schedule
  • Electronic records controls and backups

Common finding

Records kept on a shared drive with no control over who can change or delete them.

07

Work is managed

Principle 7

“work is managed”

CNSC REGDOC-2.1.1, section 2

The assessor checks that work is planned, done to approved procedures, verified, and that contractors doing work are overseen.

Questions to answer

Records to have ready

  • Work plans and work packages
  • Procedures and completed verification records
  • Approved supplier list and supplier evaluations
  • Contractor oversight records

Common finding

Contractor work accepted on the contractor’s own sign-off, with no licensee verification on file.

08

Problems are identified and resolved

Principle 8

“problems are identified and resolved”

CNSC REGDOC-2.1.1, section 2

The assessor checks that problems are reported, analysed in proportion to their significance, corrected, and checked to see the fix worked.

Questions to answer

Records to have ready

  • Problem reporting log
  • Significance screening criteria
  • Cause analyses
  • Corrective action tracking and effectiveness reviews
  • Trend reports

Common finding

A repeat problem closed three times, each with a local fix and no trend review to connect them.

09

Changes are controlled

Principle 9

“changes are controlled”

CNSC REGDOC-2.1.1, section 2

The assessor checks that changes to the plant, the organization, procedures and the management system are reviewed for their effect on safety before they are made.

Questions to answer

Records to have ready

  • Change control procedure
  • Change records with safety reviews
  • Configuration management records
  • Temporary change log

Common finding

A temporary modification still in place years later, with no record of review since it was installed.

10

Assessments are performed

Principle 10

“assessments are performed”

CNSC REGDOC-2.1.1, section 2

The assessor checks that you assess your own management system, independently as well as by self-assessment, and that top management reviews its effectiveness.

Questions to answer

Records to have ready

  • Assessment schedule
  • Self-assessment and independent assessment reports
  • Management effectiveness review records
  • Finding closure records

Common finding

A management review that summarised activity but reached no conclusion on whether the management system was effective.

11

Experience is sought, shared and used

Principle 11

“experience is sought, shared and used”

CNSC REGDOC-2.1.1, section 2

The assessor checks that you learn from your own events and from others in the industry, and that lessons change how work is done.

Questions to answer

Records to have ready

  • Operating experience program procedure
  • Screening records for industry events
  • Actions arising from operating experience

Common finding

Industry event reports filed as read, with no screening record showing whether they applied.

12

The management system is improved

Principle 12

“the management system is continually improved”

CNSC REGDOC-2.1.1, section 2

The assessor checks that results from assessments, problems, experience and performance measures feed back into changes to the management system.

Questions to answer

Records to have ready

  • Performance indicators and reviews
  • Improvement action register
  • Management system revision history

Common finding

Performance indicators reported every quarter for years with no action taken when they turned red.

13

Topics the CNSC singles out

Section 3 of REGDOC-2.1.1 covers specific topics that have been “the subject of recent developments in management system standards, as well as those of recent regulatory interest”. Quotations are from REGDOC-2.1.1, with its reference numbers left out.

Supply chain

“The specific requirements for a supply chain described in CSA N286-12 apply to the supply of services as well as items.” REGDOC-2.1.1, section 3

See: CSA N299 audit checklist for supplier QA programs

Counterfeit, fraudulent and suspect items

“While not mentioned in any specific section of CSA N286-12, effectively implemented supply chain processes and adherence to the requirements of the management system can mitigate against the introduction of counterfeit, fraudulent and suspect items (CFSI) into the supply chain of a nuclear facility and/or activity.” REGDOC-2.1.1, section 3

See: CFSI prevention

Management of contractors

“Therefore, licensees provide the oversight required to ensure the work performed by contractors meets regulatory requirements for which they are responsible.” REGDOC-2.1.1, section 3

See: Principle 7, work is managed

Configuration management

“As a result, CSA standard N286.10-16, Configuration management for high energy reactor facilities, was issued to provide guidance on maintaining configuration throughout the full lifecycle of a facility.” REGDOC-2.1.1, section 3

See: Configuration management

Software quality assurance

“CSA standard N286.7-16, Quality assurance of analytical, scientific, and design computer programs, applies to high energy reactor facilities as defined in CSA N286-12.” REGDOC-2.1.1, section 3

See: N286 editions and companion standards

14

Questions about N286 audits

What does a CSA N286 audit check?

A CSA N286 audit, whether an internal assessment or a regulator’s inspection, checks that a licensee’s management system meets CSA N286-12 and is followed in practice. This checklist is organised around the 12 principles the CNSC lists for N286-12 in REGDOC-2.1.1, from safety as the paramount consideration to continual improvement of the management system.

Which sections of CSA N286-12 apply to my facility?

According to REGDOC-2.1.1, section 4, Generic requirements for the management system, applies to every facility type, plus one specific section: 5 for uranium mines and mills, 6 for uranium processing and fuel manufacturing facilities, 7 for high energy reactor facilities, 8 for research and isotope processing facilities, and 9 for radioactive waste management facilities.

What are the 12 principles of CSA N286-12?

As listed in CNSC REGDOC-2.1.1: safety is the paramount consideration guiding decisions and actions; the business is defined, planned and controlled; the organization is defined and understood; resources are managed; communication is effective; information is managed; work is managed; problems are identified and resolved; changes are controlled; assessments are performed; experience is sought, shared and used; the management system is continually improved.

How does REGDOC-2.1.1 relate to CSA N286-12?

REGDOC-2.1.1 says the CNSC “expects licensees to adhere to all CSA N286-12 principles as the basis of their management system”, and that the regulatory document “does not duplicate the generic requirements of CSA N286-12”. It adds information on specific topics such as leadership, safety culture, supply chain, configuration management and software quality assurance.

What is the difference between CSA N286 and CSA N299?

N286 sets the management system requirements for the licensee operating a nuclear facility. N299 sets the quality assurance program requirements for suppliers of items and services to nuclear power plants, in four categories chosen by the purchaser. A licensee works to N286 and may require its suppliers to work to N299.

Does CSA N286 cover counterfeit, fraudulent and suspect items?

Not in a specific section. REGDOC-2.1.1 says CFSI are “not mentioned in any specific section of CSA N286-12”, but that effective supply chain processes and adherence to the management system can mitigate against them entering the supply chain.

How do I prepare for a CSA N286 audit?

Confirm which sections of N286-12 apply to your facility. Work through each principle on this checklist against your management system documents, then follow one recent piece of work, a change or a problem from start to finish and check that every record is there. Close what you find before the audit.


Find your gaps before the auditor does. The free readiness assessment scores a quality program against CSA N299, NQA-1 or ISO 19443 and lists the gaps. In Forged, each record on this checklist is filed against the work, change or problem it belongs to, so the records for a trace are in one place. In Forged, each record on this checklist is filed against the job it belongs to, so the record package for an order is in one place when the purchaser asks for it.

References

  1. CSA Group. CSA N286-12 (R2022): Management system requirements for nuclear facilities. Toronto, Ontario: CSA Group, 2012, reaffirmed 2022.
  2. CSA Group. CSA N286.0.1:21 (R2026): Commentary on CSA N286-12, Management system requirements for nuclear facilities. Toronto, Ontario: CSA Group, 2021, reaffirmed 2026.
  3. Canadian Nuclear Safety Commission. REGDOC-2.1.1, Management System. Ottawa: CNSC, 2019. Accessed 4 October 2026.