The Regulatory Crosswalk

🎯 Who this is for: Regulatory, licensing, and QA leads who need a single, defensible table — capability to application to regulation — to hand an auditor or to check an analyst deck against.

Series: Part 6 of 7 — Maximo for Nuclear on MAS 9 | Read time: 16 minutes

📋 One Table for the Audit

The previous five parts walked the applications one module at a time. This part does the opposite: it lays out the whole thing as a single capability-to-regulator crosswalk, so you can answer the auditor's question — "show me where that obligation is met in the system" — without hunting.

The organizing principle is what the source calls anti-invention discipline: where an expected capability has no IBM-named application, the crosswalk says so, rather than inventing an app to fill the cell. That honesty is the entire value of the table. A crosswalk that quietly upgrades every "configured" capability into a "shipped app" is worse than useless in an audit, because the first cell an inspector probes and finds empty discredits every other cell. A crosswalk that flags its five gaps openly earns credibility for its "Yes" rows.

🗺️ The Capability Crosswalk

Here is the table. Each row is a user-requested nuclear capability, whether a named app delivers it, the IBM-named application, and the primary regulatory driver.

CapabilityNamed app?IBM-named applicationPrimary regulatory driver
Condition EvaluationYesCondition Reports (Nuc) + evaluation tabs10 CFR 50 App B XVI; NQA-1
Action TrackingYesCondition Reports (Nuc) follow-up WOs + Commitment Tracking (Nuc)10 CFR 50 App B XVI; 10 CFR Part 21
Tech Spec SurveillanceYesTech Specs (Nuc) + Surveillance Requirements (Nuc) + LCO Tracking (Nuc)10 CFR 50.36; NRC Reg Guide 1.33
Operating Experience (OPEX)Partial — no named appCondition Reports + Solutions library + Commitment TrackingINPO OE program (voluntary)
Corrective Action Program (CAP)YesCondition Reports (Nuc) CAP engine10 CFR 50 App B XVI
AP-913 Equipment ScopingPartial — no named appClassifications + critical-component flag + Reliability StrategiesINPO AP-913
Maintenance RulePartial — no named appAssets (Nuc) + failure codes + Condition Monitoring + Maximo Health10 CFR 50.65; NRC Reg Guide 1.160 Rev 3
Clearance / Tagout (nuclear)YesClearances (Nuc), Clearances Kiosk, Clearance Groups, Sign On/Off10 CFR 50 App B; 10 CFR 50.65; plant procedures
Hold Points / QC Points / Inspection PointsPartial — no named appJob Plan task statuses + inspection plans + receiving inspection10 CFR 50 App B X (Inspection); NQA-1
Calibration / M&TEYes (pattern)Data Sheet Template + PM (Nuc) + WOT (Nuc) + Tools (as M&TE)10 CFR 50 App B XII; ANSI/IEEE 498; DOE STD-1054
Configuration Management / Design BasisYesConfiguration Change Designer, Changes, Releases, Configuration Items10 CFR 50.59; 10 CFR 50 App B III
e-Signature / electronic recordsPartial — no nuclear-specific appCore Maximo ESig / eAudit applied across nuclear apps10 CFR 50 App B XVII; NQA-1 Records
Nuclear PM templates + frequency controlsYesPM (Nuc), Master PM, PM Frequencies (Nuc)EPRI PM Basis; INPO AP-913
Nuclear KPIs + reportingYes (suite)KPI Manager, KPI Templates, KPI Viewer, Cognos, Report Administration/ViewerPlant performance / INPO indicators
Event ReportingYesEvents (Nuc) + Notifications (Nuc) + Commitment Tracking (Nuc) + Condition Reports (Nuc)10 CFR 50.72 / 50.73

<aside>

💡 Key insight: Scan the "Named app?" column and a clean pattern emerges. The regulatory core — CAP, Tech Spec surveillance, clearance/tagout, configuration management, event reporting, nuclear PM — all ships as named applications. The five gaps — OPEX, AP-913 scoping, the Maintenance Rule, hold points, and nuclear e-signature — are configuration capabilities. That is not a random distribution: obligations with a rigid, defined process (App B XVI, 50.36, 50.59) get purpose-built apps; the ones that are frameworks or overlays (INPO programs, the Rule's judgment loop, records signatures) ride configuration. Knowing which is which is how you scope without over-promising.

</aside>

🧱 How 10 CFR 50 Appendix B Distributes

Because Appendix B is the spine of nuclear QA, it is worth isolating where its criteria land. The eighteen criteria of Appendix B are the backbone of every nuclear quality program, and the ones an EAM touches map cleanly:

App B criterionSubjectWhere it lives in Maximo
IIIDesign ControlConfiguration Change Designer, Changes, Releases, Configuration Items (Part 3)
VInstructions, Procedures, DrawingsWOT (Nuc), Quick WOs, Quick Reporting, Impact Plans, Permits
XInspectionJob Plan task statuses + inspection plans + receiving inspection (Part 3)
XIIControl of Measuring & Test EquipmentCalibration pattern: Data Sheet Templates + PM (Nuc) + WOT + Tools as M&TE
XVICorrective ActionCondition Reports (Nuc) CAP engine (Part 5)
XVIIQuality Assurance RecordsCore Maximo ESig / eAudit applied across nuclear apps (no nuclear-specific app)

The calibration row (App B XII) deserves a note. Like hold points, it is a pattern rather than a single named "Calibration" app — but it is a well-established one. Calibration is delivered inside Maximo Nuclear through Data Sheet Templates (holding calibration specifications), calibration-extended Assets/Locations (modeled as calibration loops), Tools (as M&TE devices), PM-driven calibration frequency, and Work Order Tracking execution. It is important to clarify that it is a pattern — not a single app — in any analyst review, alongside its standards drivers (ANSI/IEEE 498, DOE STD-1054).

<aside>

💡 Key insight: Notice which Appendix B criteria get named apps and which get patterns. XVI (Corrective Action) and III (Design Control) — the criteria with defined, rigid processes — get purpose-built applications. X (Inspection), XII (M&TE), and XVII (Records) — the criteria that are really controls applied to work and data — get configuration patterns riding existing machinery. The distribution is not arbitrary; it tracks how process-shaped versus control-shaped each criterion is. That distinction is the deepest logic of the whole crosswalk.

</aside>

🚫 The Five Gaps, One by One

The five "no named app" cells recur across the series, so it is worth stating each one precisely — what it is, how Maximo delivers it, and the one sentence that scopes it honestly.

OPEX (Operating Experience)

INPO's voluntary OE framework. Delivered through Condition Reports (Nuc) + a reusable Solutions library + Commitment Tracking. Honest scoping: "OPEX is supported through Condition Reports, the Solutions library, and Commitment Tracking" — not "an OPEX module."

AP-913 Equipment Scoping

INPO's equipment-reliability process. Delivered through classifications + the critical-component flag + Reliability Strategies. Honest scoping: "AP-913 scoping uses classifications, the critical-component flag, and Reliability Strategies" — not "an AP-913 module."

The Maintenance Rule (10 CFR 50.65)

The biggest gap, covered in full in Part 4. Delivered through Assets (Nuc) + failure codes + Condition Monitoring + Maximo Health, with (a)(4) risk in Impact Plans. Honest scoping: "50.65 monitoring runs through Assets (Nuc), failure codes, Condition Monitoring, and Health" — not "a Maintenance Rule module."

Hold Points / QC Points / Inspection Points

The work-control gap, covered in Part 3. Delivered through Job Plan task statuses + inspection plans + receiving inspection, with role-based sign-off. Honest scoping: "hold points are Job Plan task statuses plus inspection plans" — not "a Hold Points app."

Nuclear-specific e-Signature

QA records under App B XVII. Delivered through the core Maximo ESig / eAudit framework applied across nuclear apps — a platform capability configured for nuclear use, not a bespoke nuclear e-signature module. Honest scoping: "electronic signature and audit are the core ESig/eAudit framework configured for nuclear records" — not "a nuclear e-signature app."

<aside>

💡 Key insight: Every one of these five is a defensible, industry-standard delivery. The failure mode is never "the capability is missing" — it is "someone claimed a shipped app that is not there." Convert each gap into a scoping sentence in the statement of work and the gap becomes a plan, not a surprise. That single move — configuration named as configuration — is what separates an implementation that survives its first audit from one that gets caught explaining a phantom module.

</aside>

🏛️ Where NQA-1 Lives

ASME NQA-1, the nuclear quality-assurance standard, threads through the whole solution, but it concentrates in three places worth calling out:

Procurement. The Purchasing (Nuc) module carries NQA-1 procurement controls: Purchase Requisitions, Purchase Orders, and Request Quotations (Nuc) with augmented-quality flags and dedication requirements; Companies (Nuc) holding supplier audit results and the qualified-supplier flag (the Approved Suppliers List, ASL); Terms and Conditions (Nuc) for nuclear procurement terms including 10 CFR Part 21 clauses; and Item Master / Inventory (Nuc) distinguishing safety-related from commercial-grade-dedicated items, with shelf-life and storage conditions.

Records. QA records under App B XVII and NQA-1 Records ride the core Maximo ESig / eAudit framework, applied across nuclear applications. This is the "no nuclear-specific app" row — electronic signature and audit are a platform capability configured for nuclear use, not a bespoke nuclear e-signature module.

Quality controls throughout. NQA-1 also backs the CAP (App B XVI), calibration (App B XII), and inspection (App B X) patterns already covered — a quality thread running through corrective action, measurement control, and inspection. When someone asks "how do you control commercial-grade dedication and supplier qualification?", the augmented-quality flag and the Purchasing (Nuc) module and its Approved Suppliers List are the answer.

<aside>

💡 Key insight: NQA-1 is not one row in the crosswalk — it is a thread through many rows. It shows up as procurement controls, as records via ESig/eAudit, and as the quality discipline behind CAP, calibration, and inspection. When an auditor asks "where is your NQA-1 program in the system?", the honest answer is "in several places, deliberately" — the ASL and augmented-quality flags in Purchasing (Nuc), the ESig/eAudit records layer, and the quality controls woven through the corrective-action, measurement, and inspection patterns.

</aside>

🧩 A Worked Example: Answering an Auditor's Traversal

The crosswalk earns its keep the moment an auditor asks a pointed question. Watch it resolve one. The applications are the documented ones; the identifiers echo Part 2's EDG example.

The question. "Show me that surveillance SR 3.8.1.2 for EDG-1A was performed on its required frequency, what its last result was, and — if it ever failed — that the LCO completion time was met."

The traversal, straight down the crosswalk:

  1. Tech Spec Surveillance row → Tech Specs (Nuc). The Tech Spec record for LCO 3.8.1 links to SR 3.8.1.2, establishing the requirement and its 31-day frequency under 10 CFR 50.36.
  2. → Surveillance Requirements (Nuc). The SR record shows each performance, its pass/fail result, and the last result — the "prove it" evidence.
  3. → PM / frequency machinery. The driving frequency record shows the schedule and the 25% grace window, anchored to the base cadence — proving the surveillance stayed on frequency.
  4. → LCO Tracking (Nuc). For the historical failure, the action-statement record shows entry time, the 72-hour completion time, the repair work order, the passing re-test, and the exit time — proving the clock was met.
  5. CAP row → Condition Reports (Nuc). The condition report raised for the failure shows the corrective action, closing the loop under App B XVI.

Every hop is a named application and a specific record. The auditor's one question resolves to a five-record trail, each cell of it already mapped in the crosswalk.

<aside>

💡 Key insight: This is why the crosswalk is a navigation tool, not just a reference. An auditor's question is almost always a traversal — "prove obligation X was met" — and the crosswalk turns it into a route: capability → application → record. An implementation team that has walked this traversal in advance answers in minutes; one that has not spends the audit hunting. Rehearse the traversals before the audit, not during it.

</aside>

📐 The Standards Beyond 10 CFR 50

The crosswalk's regulatory-driver column names more than 10 CFR 50, and the extra standards matter for a complete scoping. A quick reference:

Standard / frameworkWhat it drivesWhere it lands
10 CFR Part 21Reporting of defects and noncomplianceTerms and Conditions (Nuc); Commitment Tracking; Condition Reports
10 CFR 50.72 / 50.73Event and licensee event report notificationsEvents (Nuc) + Notifications (Nuc) + Condition Reports
NRC Reg Guide 1.33Quality assurance program (operations)Surveillance and program records
ANSI/IEEE 498; DOE STD-1054Calibration / M&TE controlThe calibration pattern (App B XII)
EPRI PM BasisPreventive-maintenance templates and intervalsPM (Nuc), Master PM, PM Frequencies (Nuc)
INPO indicatorsPlant-performance measurementKPI Manager / KPI Viewer / Cognos reporting

These are not decoration in the crosswalk — they are the reason certain rows are "pattern" rather than "app." Calibration answers to ANSI/IEEE 498 and DOE STD-1054, not to a Maximo feature; nuclear PM answers to the EPRI PM Basis. Naming the standard alongside the regulation is what makes the crosswalk defensible to a specialist reviewer.

✂️ The Line the Crosswalk Draws

Two boundaries hold across every row of the table, and stating them protects any implementation from over-claiming:

Maximo supplies evidence; it does not make the compliance judgment. Every "Yes" in the crosswalk means Maximo produces a record — a corrective action, a surveillance result, an LCO timer, a procurement audit trail. The determination of compliance remains a human program decision. That is the correct division of labor, and it is what a regulator expects: an accountable program owner, backed by a defensible system record.

A "Partial — no named app" cell is a scoping instruction, not a defect. The five configuration capabilities are delivered through defensible, industry-standard patterns. The only failure mode is claiming them as shipped apps. Scope them as configuration in the statement of work and the gap becomes a plan, not a surprise.

<aside>

💡 Key insight: This crosswalk is the single most useful artifact in the series because it serves two audiences at once. Hand it to an auditor and it shows exactly where each obligation is met, gaps and all. Hand it to an analyst who claims "Maximo doesn't cover nuclear compliance" and it refutes the claim row by row — while conceding, honestly, the five cells that are configuration. The honesty about the gaps is precisely what makes the "Yes" rows credible.

</aside>

📋 Practical Notes: Using the Crosswalk

  1. Keep it current with your build. The crosswalk describes the catalog; your implementation is a subset. Annotate which rows you have configured, which you have deferred, and which you scoped as patterns.
  2. Rehearse the traversals. For each "Yes" row, walk the capability-to-record route once before an audit so the answer is a route, not a hunt.
  3. Attach the standards. Where a row cites ANSI/IEEE 498, DOE STD-1054, or the EPRI PM Basis, keep the standard reference with the row — a specialist reviewer will ask.
  4. Own the five gaps in writing. Convert OPEX, AP-913, Maintenance Rule, hold points, and e-signature into scoping sentences, not silent assumptions.
  5. Keep judgment with the program. Every "Yes" is evidence, not a determination. Name the accountable program owner for each obligation.

Key Takeaways

  • This part is the capability-to-application-to-regulation crosswalk — one table for an auditor or analyst, with the gaps flagged.
  • 10 CFR 50 Appendix B criteria land in specific named apps: XVI in Condition Reports, III in Configuration Change Management, XII in the calibration pattern, XVII in ESig/eAudit.
  • Five capabilities have no named app: OPEX, AP-913 scoping, the Maintenance Rule, hold points, and nuclear e-signature — each delivered through a defensible configuration pattern.
  • ASME NQA-1 lives in three places: procurement (Purchasing (Nuc), Approved Suppliers List), records (ESig/eAudit), and the CAP/calibration/inspection quality patterns.
  • Maximo supplies compliance evidence; it does not automate the compliance judgment — the human program owner remains accountable.

References

Series Navigation

Previous:Part 5 — Corrective Action Program & Clearance/Tagout
Next:Part 7 — What's New in MAS 9.x

About TheMaximoGuys: We help Maximo developers and teams navigate the move to MAS 9 with practical, no-hype guidance grounded in how the platform actually behaves.

Published by TheMaximoGuys | July 2026