CSA N286-12, Management system requirements for nuclear facilities, is the standard CNSC licensees build their management systems on. The standard itself is copyrighted, so this checklist is organised around its 12 principles as the CNSC lists them in REGDOC-2.1.1. The questions, records and findings under each principle are ours. Check every answer against N286-12 itself.
Confirm the scope before you start. Section 4 of N286-12, the generic requirements, applies to every facility type. One further section applies depending on your facility. Your licence sets out what applies to you.
Which edition, and which sections
The current edition is CSA N286-12, Management system requirements for nuclear facilities, published in 2012 and reaffirmed in 2022 (R2022). It replaced N286-05. CSA store
CSA N286.0.1:21 (R2026) is the commentary on N286-12. REGDOC-2.1.1 says the commentary “provides background information concerning certain clauses and requirements in CSA N286-12”. CSA store
REGDOC-2.1.1, Management System (2019), says the CNSC “expects licensees to adhere to all CSA N286-12 principles as the basis of their management system”, and that it “does not duplicate the generic requirements of CSA N286-12”. REGDOC-2.1.1
REGDOC-2.1.1 sets out which sections of N286-12 apply to each facility type:
| Facility type | Applicable sections of CSA N286-12 |
|---|---|
| Uranium mines and mills | 4. Generic requirements for the management system 5. Specific requirements for uranium mines and mills |
| Uranium processing and fuel manufacturing facilities | 4. Generic requirements for the management system 6. Specific requirements for uranium processing and fuel manufacturing facilities |
| High energy reactor facilities | 4. Generic requirements for the management system 7. Specific requirements for high energy reactor facilities |
| Research and isotope processing facilities | 4. Generic requirements for the management system 8. Specific requirements for research and isotope processing facilities |
| Radioactive waste management facilities | 4. Generic requirements for the management system 9. Specific requirements for radioactive waste management facilities |
Before the audit
If you only have time for one of these, do the trace. Following real work, a real change and a real problem through your system turns up the same gaps an assessor will find.
The checklist, principle by principle
Safety comes first
Principle 1
“safety is the paramount consideration guiding decisions and actions”
CNSC REGDOC-2.1.1, section 2
The assessor checks that safety is weighed in decisions at every level, that people can raise concerns and stop work, and that safety culture is looked at, not assumed.
Questions to answer
Records to have ready
- Safety policy signed by top management
- Safety culture assessment and action plan
- Records of concerns raised and how they were resolved
- Decision records for a recent significant change
Common finding
A schedule-driven decision to defer a safety-related task, with no record of who weighed the risk or why.
The business is planned and controlled
Principle 2
“the business is defined, planned and controlled”
CNSC REGDOC-2.1.1, section 2
The assessor checks that the management system is documented, that its processes have owners, and that the requirements of the licence and licensing basis are traced to the processes that meet them.
Questions to answer
Records to have ready
- Management system description
- Process map with owners
- Requirements-to-process traceability
- Business plan and objectives with progress reports
Common finding
A licence condition with no process owner, found only when the assessor asked who is accountable for it.
The organization is defined and understood
Principle 3
“the organization is defined and understood”
CNSC REGDOC-2.1.1, section 2
The assessor checks that roles, responsibilities, authorities and interfaces are written down and that the people in those roles understand them.
Questions to answer
Records to have ready
- Organization chart
- Role descriptions and authorities
- Interface agreements with contractors and other organizations
Common finding
A reorganization that changed reporting lines without updating the role descriptions or the management system documents.
Resources are managed
Principle 4
“resources are managed”
CNSC REGDOC-2.1.1, section 2
The assessor checks that you have enough qualified people, the right equipment and the funding the work needs, and that you plan for changes in all three.
Questions to answer
Records to have ready
- Minimum staffing requirements
- Training and qualification records
- Succession plans for key roles
- Equipment maintenance records
Common finding
A qualified position left vacant for months with its duties spread informally across people not trained for them.
Communication is effective
Principle 5
“communication is effective”
CNSC REGDOC-2.1.1, section 2
The assessor checks that expectations, decisions and changes reach the people who need them, and that information flows back up as well as down.
Questions to answer
Records to have ready
- Communication plans
- Records of briefings on recent changes
- Staff feedback and responses
- Correspondence control for regulator communications
Common finding
A procedure change issued without a briefing, so the night shift kept working to the old version.
Information is managed
Principle 6
“information is managed”
CNSC REGDOC-2.1.1, section 2
The assessor checks that documents and records are controlled, current, retrievable and kept for as long as required.
Questions to answer
Records to have ready
- Controlled document list
- Records retention schedule
- Electronic records controls and backups
Common finding
Records kept on a shared drive with no control over who can change or delete them.
Work is managed
Principle 7
“work is managed”
CNSC REGDOC-2.1.1, section 2
The assessor checks that work is planned, done to approved procedures, verified, and that contractors doing work are overseen.
Questions to answer
Records to have ready
- Work plans and work packages
- Procedures and completed verification records
- Approved supplier list and supplier evaluations
- Contractor oversight records
Common finding
Contractor work accepted on the contractor’s own sign-off, with no licensee verification on file.
Problems are identified and resolved
Principle 8
“problems are identified and resolved”
CNSC REGDOC-2.1.1, section 2
The assessor checks that problems are reported, analysed in proportion to their significance, corrected, and checked to see the fix worked.
Questions to answer
Records to have ready
- Problem reporting log
- Significance screening criteria
- Cause analyses
- Corrective action tracking and effectiveness reviews
- Trend reports
Common finding
A repeat problem closed three times, each with a local fix and no trend review to connect them.
Changes are controlled
Principle 9
“changes are controlled”
CNSC REGDOC-2.1.1, section 2
The assessor checks that changes to the plant, the organization, procedures and the management system are reviewed for their effect on safety before they are made.
Questions to answer
Records to have ready
- Change control procedure
- Change records with safety reviews
- Configuration management records
- Temporary change log
Common finding
A temporary modification still in place years later, with no record of review since it was installed.
Assessments are performed
Principle 10
“assessments are performed”
CNSC REGDOC-2.1.1, section 2
The assessor checks that you assess your own management system, independently as well as by self-assessment, and that top management reviews its effectiveness.
Questions to answer
Records to have ready
- Assessment schedule
- Self-assessment and independent assessment reports
- Management effectiveness review records
- Finding closure records
Common finding
A management review that summarised activity but reached no conclusion on whether the management system was effective.
Experience is sought, shared and used
Principle 11
“experience is sought, shared and used”
CNSC REGDOC-2.1.1, section 2
The assessor checks that you learn from your own events and from others in the industry, and that lessons change how work is done.
Questions to answer
Records to have ready
- Operating experience program procedure
- Screening records for industry events
- Actions arising from operating experience
Common finding
Industry event reports filed as read, with no screening record showing whether they applied.
The management system is improved
Principle 12
“the management system is continually improved”
CNSC REGDOC-2.1.1, section 2
The assessor checks that results from assessments, problems, experience and performance measures feed back into changes to the management system.
Questions to answer
Records to have ready
- Performance indicators and reviews
- Improvement action register
- Management system revision history
Common finding
Performance indicators reported every quarter for years with no action taken when they turned red.
Topics the CNSC singles out
Section 3 of REGDOC-2.1.1 covers specific topics that have been “the subject of recent developments in management system standards, as well as those of recent regulatory interest”. Quotations are from REGDOC-2.1.1, with its reference numbers left out.
“The specific requirements for a supply chain described in CSA N286-12 apply to the supply of services as well as items.” REGDOC-2.1.1, section 3
See: CSA N299 audit checklist for supplier QA programs
“While not mentioned in any specific section of CSA N286-12, effectively implemented supply chain processes and adherence to the requirements of the management system can mitigate against the introduction of counterfeit, fraudulent and suspect items (CFSI) into the supply chain of a nuclear facility and/or activity.” REGDOC-2.1.1, section 3
See: CFSI prevention
“Therefore, licensees provide the oversight required to ensure the work performed by contractors meets regulatory requirements for which they are responsible.” REGDOC-2.1.1, section 3
See: Principle 7, work is managed
“As a result, CSA standard N286.10-16, Configuration management for high energy reactor facilities, was issued to provide guidance on maintaining configuration throughout the full lifecycle of a facility.” REGDOC-2.1.1, section 3
“CSA standard N286.7-16, Quality assurance of analytical, scientific, and design computer programs, applies to high energy reactor facilities as defined in CSA N286-12.” REGDOC-2.1.1, section 3
Questions about N286 audits
What does a CSA N286 audit check?
A CSA N286 audit, whether an internal assessment or a regulator’s inspection, checks that a licensee’s management system meets CSA N286-12 and is followed in practice. This checklist is organised around the 12 principles the CNSC lists for N286-12 in REGDOC-2.1.1, from safety as the paramount consideration to continual improvement of the management system.
Which sections of CSA N286-12 apply to my facility?
According to REGDOC-2.1.1, section 4, Generic requirements for the management system, applies to every facility type, plus one specific section: 5 for uranium mines and mills, 6 for uranium processing and fuel manufacturing facilities, 7 for high energy reactor facilities, 8 for research and isotope processing facilities, and 9 for radioactive waste management facilities.
What are the 12 principles of CSA N286-12?
As listed in CNSC REGDOC-2.1.1: safety is the paramount consideration guiding decisions and actions; the business is defined, planned and controlled; the organization is defined and understood; resources are managed; communication is effective; information is managed; work is managed; problems are identified and resolved; changes are controlled; assessments are performed; experience is sought, shared and used; the management system is continually improved.
How does REGDOC-2.1.1 relate to CSA N286-12?
REGDOC-2.1.1 says the CNSC “expects licensees to adhere to all CSA N286-12 principles as the basis of their management system”, and that the regulatory document “does not duplicate the generic requirements of CSA N286-12”. It adds information on specific topics such as leadership, safety culture, supply chain, configuration management and software quality assurance.
What is the difference between CSA N286 and CSA N299?
N286 sets the management system requirements for the licensee operating a nuclear facility. N299 sets the quality assurance program requirements for suppliers of items and services to nuclear power plants, in four categories chosen by the purchaser. A licensee works to N286 and may require its suppliers to work to N299.
Does CSA N286 cover counterfeit, fraudulent and suspect items?
Not in a specific section. REGDOC-2.1.1 says CFSI are “not mentioned in any specific section of CSA N286-12”, but that effective supply chain processes and adherence to the management system can mitigate against them entering the supply chain.
How do I prepare for a CSA N286 audit?
Confirm which sections of N286-12 apply to your facility. Work through each principle on this checklist against your management system documents, then follow one recent piece of work, a change or a problem from start to finish and check that every record is there. Close what you find before the audit.
Find your gaps before the auditor does. The free readiness assessment scores a quality program against CSA N299, NQA-1 or ISO 19443 and lists the gaps. In Forged, each record on this checklist is filed against the work, change or problem it belongs to, so the records for a trace are in one place. In Forged, each record on this checklist is filed against the job it belongs to, so the record package for an order is in one place when the purchaser asks for it.
References
- CSA Group. CSA N286-12 (R2022): Management system requirements for nuclear facilities. Toronto, Ontario: CSA Group, 2012, reaffirmed 2022.
- CSA Group. CSA N286.0.1:21 (R2026): Commentary on CSA N286-12, Management system requirements for nuclear facilities. Toronto, Ontario: CSA Group, 2021, reaffirmed 2026.
- Canadian Nuclear Safety Commission. REGDOC-2.1.1, Management System. Ottawa: CNSC, 2019. Accessed 4 October 2026.
Forged Operations builds quality management software for nuclear suppliers and operators. Score your program for free at forgedops.com/assessment, or email [email protected].
This checklist is a preparation aid. It does not reproduce or replace CSA N286-12. Principles are quoted from CNSC REGDOC-2.1.1. Latest version: forgedops.com/csa-n286-audit-checklist/