Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch

For Upstream + Midstream + Downstream Operators

One platform for process safety, pipeline integrity, and TSA cybersecurity across every asset.

Oil and gas operators face the densest US safety + environmental + cybersecurity regulatory stack of any sector. PHMSA 49 CFR 192/195. OSHA PSM 14-element program. EPA RMP for chemical thresholds. API RP 1173 SMS. TSA pipeline-security directives. BSEE SEMS offshore. RiskWatch handles all of it as one survey-based assessment platform sized for HSE, integrity, and process-safety teams.

Trusted by upstream + midstream + downstream operators managing PHMSA, OSHA PSM, EPA RMP, TSA security directives, and API standards across drilling, production, gathering, transmission, processing, refining, and marketing assets.

Iberdrola USATE ConnectivityHalexBoseJohnson & JohnsonPfizer
4.8G2 Crowd·108+
4.7Capterra·76+
4.8Gartner Peer Insights·Voice of Customer

Why HSE + Integrity Teams Pick RiskWatch

RiskWatch turns API 1173, PSM, RMP, and TSA into one program.

RiskWatch runs API RP 1173 SMS, OSHA PSM, EPA RMP, PHMSA pipeline regs, TSA security directives, and BSEE SEMS as one program on one platform, scored against the same controls library, and tracked through a single inspection-ready evidence trail. Built for operators where one HSE + integrity team covers every regulator, every asset class, and every audit cycle, without enterprise-bank GRC overhead.

Process safety + pipeline integrity in one library

PSM 14 elements + API 1173 SMS plan + EPA RMP program elements cross-mapped. PHA, MOC, MOC-PSSR, mechanical integrity, and incident investigation share evidence, no parallel binders.

TSA pipeline-security directives built in

SD-Pipeline-2021-02C + the cybersecurity-focused successors are tracked as overlays. Operations + IT + OT cybersecurity controls map to the same access-review and patch-management evidence already captured for API 1173.

Sized for HSE + integrity team scale

VP HSE + integrity manager + PSM coordinator share one platform. Pre-built libraries cut prep time. White-glove implementation in 30 days, not 6 months.

The Oil + Gas Regulatory Landscape

Oil and gas compliance is multi-regulator. The numbers prove it.

The TSA Pipeline Security Directive arrived after Colonial Pipeline (May 2021). PHMSA inspection enforcement collected $5M+ in 2024 civil penalties. OSHA PSM 14 elements have not changed since 1992 but still drive most refinery audit findings. EPA's amended RMP rule (Safer Communities by Chemical Accident Prevention) took effect in 2024. Each regulator wants its own evidence package.

SD-2021-02C
TSA pipeline cybersecurity directive, third revision in force
14
OSHA PSM elements (29 CFR 1910.119), refinery audit baseline
RP 1173
API recommended practice for Pipeline Safety Management Systems
40 CFR 68
EPA Risk Management Program, amended Safer Communities rule effective 2024

Three Domains, One Platform

Oil and gas risk lives in three concrete domains

RiskWatch covers all three. Each domain has a dedicated workflow, scoring model, and remediation queue. They share data so a single management-of-change event satisfies PSM §1910.119(l), API 1173 §6.4, MOC-PSSR, and EPA RMP §68.75 simultaneously.

Risk

Process Safety + Asset Integrity

Survey-based risk assessment across PHA, mechanical integrity, asset register, and process-hazard scoring, aligned to API 1173 SMS + PSM + RMP.

  • PHA + LOPA evidence captured
  • API 1173 SMS plan scoring
  • Mechanical integrity register
Explore Risk Management
Compliance

PHMSA + OSHA PSM + EPA RMP

PHMSA 49 CFR 192/195, OSHA 1910.119 PSM, EPA 40 CFR Part 68 RMP, BSEE SEMS, API standards in one cross-mapped library.

  • PHMSA inspection-ready packages
  • PSM 14-element evidence captured
  • EPA RMP submission ready
Explore Compliance Management
Security

TSA + Cybersecurity + Physical Security

TSA Pipeline Security Directives, ANSI/API 780 security risk assessment, IT/OT cybersecurity, and physical security across every asset.

  • TSA SD-Pipeline overlay tracked
  • API 780 security risk method
  • OT + control-system evidence
Explore Cybersecurity

The Coverage Gap

Most oil and gas software covers one regulator

EHS platforms cover incident reporting + leading indicators. Pipeline integrity vendors cover MAOP + ILI tracking. PSM specialty tools cover the 14 elements. TSA-directive specialty cover cyber. Each does one job. HSE + integrity teams still operate four parallel programs.

Platform CategoryAPI 1173OSHA PSMEPA RMPPHMSATSA SDMulti-asset
EHS PlatformsSphera, Enablon, IntelexPartialYesPartial··Yes
Pipeline IntegrityPODS, ESRI APR, Bentley OpenFlowsPartial··Yes·Partial
PSM Specialty ToolsPHA-Pro, BowtieXP·Yes····
TSA Pipeline CyberDragos, Claroty, Nozomi····Yes·
Internal Audit / ERMWorkiva, AuditBoardPartialPartialPartial···
Spreadsheets & Email······
RiskWatchThe unified inspection-ready platformYesYesYesYesYesYes

RiskWatch is the only platform covering all six oil and gas compliance domains: API RP 1173 SMS, OSHA PSM 14 elements, EPA RMP, PHMSA 49 CFR 192/195, TSA Pipeline Security Directives, and multi-asset coordination. EHS platforms cover incident reporting. Pipeline integrity vendors cover MAOP + ILI. PSM specialty tools cover the 14 elements. Each does one job. RiskWatch unifies all six in one survey-based assessment workflow.

How It Works

One platform. Continuous compliance across every regulator.

RiskWatch is a survey-based assessment platform. The work is structured around questionnaires that capture process-safety, integrity, environmental, and cybersecurity posture in a consistent format, then scored against every framework you align to.

For oil and gas, that workflow runs continuously across API RP 1173 SMS, OSHA PSM 14 elements, EPA RMP three program levels, PHMSA inspection cycles, TSA pipeline security directives, and BSEE SEMS audits. A single MOC record scores against PSM §1910.119(l), API 1173 §6.4, EPA RMP §68.75, and the operator's own change-control SOP simultaneously.

The same platform runs all of it, surfaces gaps before regulator arrival, assigns remediation owners, and tracks completion. Replace the four parallel tools and the spreadsheet bridge between them.

The Workflow

  1. 01
    Assess
    Survey-based questionnaires capture process-safety, integrity, environmental, and cybersecurity posture across every asset, business unit, and pipeline segment.
  2. 02
    Score
    Responses score against your chosen framework: API RP 1173 SMS, OSHA PSM, EPA RMP, PHMSA 192/195, TSA SD-Pipeline, BSEE SEMS, ANSI/API 780, NIST CSF 2.0, or custom.
  3. 03
    Remediate
    Gaps become assigned tasks. Owners get deadlines. Contractor + vendor + 3rd-party tasks cascade to the supplier portal automatically.
  4. 04
    Audit
    Evidence trails export to PDF, PHMSA inspection format, OSHA PSM audit binder, EPA RMP submission, or TSA quarterly report. Inspection-ready in minutes.
PSMIntegrityEnvironmentalTSAContractors

Built For Your Role

Who uses RiskWatch in an oil and gas operator

VP HSE / EHS Director

Owns enterprise-wide HSE program, board-level safety performance, and PSM/RMP regulator-facing posture.

API RP 1173 SMS scoring continuous. PSM + RMP audit-ready. Board metrics + leading indicators surface from the same vault.

Pipeline Integrity Manager

Owns 49 CFR 192/195 inspection cycles, MAOP, ILI program, and PHMSA-facing integrity evidence.

PHMSA inspection ready. Integrity management plan scored continuously. Threat assessment + assessment-frequency intervals tracked.

PSM Coordinator

Owns OSHA PSM 14 elements + 5-year compliance audits + contractor PSM responsibilities.

All 14 PSM elements scored. PHA backlog visible. MOC + MOC-PSSR cycle time tracked. 5-year audit captured continuously.

Process Safety Engineer

Owns PHA / LOPA / Bowtie analysis, mechanical integrity inspection cycles, and process-hazard register.

PHA + LOPA evidence captured. Recommendations tracked to closure. Mechanical integrity backlog visible.

Cybersecurity / OT Security Lead

Owns TSA Pipeline Security Directive compliance, OT cybersecurity, control-system protection, and IT/OT boundary.

TSA SD-Pipeline evidence captured year-round. OT incident-response plan tested + tracked. Quarterly TSA reports built from live data.

Compliance / Regulatory Affairs Lead

Owns multi-regulator program (PHMSA + OSHA + EPA + TSA + state), CCPS Process Safety Beacon adoption, and regulator-facing correspondence.

Regulator-by-regulator dashboards live. Submission-ready evidence packages on demand. Cross-regulator overlap surfaced rather than duplicated.

Built For Your Segment

Oil + gas segments we serve

Upstream Producers

Onshore + offshore drilling and production operators under BSEE SEMS (30 CFR 250 Subpart S) + state oil-gas commission rules.

Midstream Pipeline Operators

Gas + liquid pipeline operators under PHMSA 49 CFR 192/195 + TSA Pipeline Security Directives + API RP 1173 SMS.

Refining + Petrochemical

Refineries + petrochemical plants under OSHA PSM (1910.119) + EPA RMP (40 CFR 68) + state-specific PSM analogs (e.g., California PSM).

Gas Distribution + LDCs

Local distribution companies under PHMSA 49 CFR 192 + state PUC + DIMP (Distribution Integrity Management Program).

Storage + Terminals

Underground gas storage (PHMSA 192 Subpart J), liquid terminals, and LNG facilities under federal + state oversight.

Service Companies + Contractors

Drilling, completions, well-servicing, and integrity-services firms under client-imposed contractor management programs.

Frameworks We Cover

Oil and gas frameworks built into the library

RiskWatch ships with pre-built libraries for every major US oil and gas regulation + recommended practice + industry standard. Map controls once. Score against the framework that matters this audit cycle.

Regulatory Frameworks

OSHA PSM
29 CFR 1910.119, 14-element Process Safety Management standard.
EPA RMP
40 CFR Part 68, Risk Management Program (Safer Communities rule, 2024 amendments).
PHMSA 49 CFR 192
Federal pipeline safety regulations for natural gas + other gas pipelines.
PHMSA 49 CFR 195
Federal pipeline safety regulations for hazardous liquid pipelines.
TSA SD-Pipeline
TSA Pipeline Security Directives (post-Colonial Pipeline, 2021–) for cybersecurity + reporting.
BSEE SEMS
30 CFR 250 Subpart S, Safety and Environmental Management Systems for offshore operators.

Industry + Recommended Practices

API RP 1173
Pipeline Safety Management Systems, the industry SMS standard PHMSA references.
API Std 754
Process Safety Performance Indicators for refining + petrochemical industries.
ANSI/API 780
Security Risk Assessment Methodology for the petroleum and petrochemical industries.
API 510 / 570 / 653
Pressure-vessel + piping + tank inspection codes, mechanical integrity baseline.
ISO 14001 / 45001
Environmental + Occupational Health & Safety management system standards.
NIST CSF 2.0
Cybersecurity Framework 2.0 (Feb 2024), TSA SD-Pipeline aligns to NIST functions.

Trusted across oil + gas operators

Iberdrola USATE ConnectivityHalexBoseJohnson & JohnsonPfizerPuma North America
We had three program owners running PSM, integrity, and TSA cyber on three different tools. Now it's one platform. PSM 14-element scoring, API 1173 SMS plan, PHMSA integrity program, and TSA SD-Pipeline overlay all run from the same evidence vault. Our last PHMSA inspection produced two notices of probable violation instead of nine.
C. Adekoya
VP HSE, Mid-cap midstream operator · 1,300 employees · 4,200 miles of pipeline
3 → 1programs consolidated to one platform
9 → 2PHMSA notices of probable violation on most recent inspection
30 daysfrom kickoff to first API 1173 SMS scoring live
FAQ

Frequently asked questions

Upstream · Midstream · Downstream

See RiskWatch run an API 1173 + PSM + TSA cycle live

30-minute walkthrough of the oil + gas library, your asset + regulator inputs, and the single evidence-trail output. No slideware, no consulting upsell.

Or call US: +1 401 884 5236

Request a Demo