glossary
The terms of an audit, explained.
Written for the people who run audits and the people who get audited. Every term gets a direct definition and the context the legal texts leave out.
Energy
- Energy audit
- An energy audit is a systematic examination of a site's energy use that identifies where energy goes, what it costs, and which measures would reduce it.
- It ends in a report of quantified improvement measures: investment, expected saving and payback period. It can be voluntary, to cut costs or support ISO 50001, or mandatory under a legal regime such as Portugal's SGCIE.
- SGCIE
- SGCIE is the Portuguese regime that requires energy-intensive installations to carry out periodic energy audits and to execute an approved energy-reduction plan.
- It applies from 500 tep per year. The cycle is always the same: audit, a PREn submitted to the DGEG, an approved ARCE, then a REP every two years evidencing execution. Non-compliance carries fines.
- PREn
- The PREn is the energy-rationalisation plan produced from an energy audit, setting the consumption-reduction targets an installation commits to.
- It is drawn up by a DGEG-recognised technician from the audit data and submitted to the DGEG. Once approved it becomes the ARCE, and it is against the PREn targets that execution is measured in every later REP.
- ARCE
- The ARCE is the PREn once the DGEG has approved it, the point at which the targets stop being a proposal and become an obligation on the installation.
- It runs for eight years for installations at or above 1000 tep per year and six years below that threshold. It unlocks the exemptions and benefits the regime provides, conditional on meeting the targets.
- REP
- The REP is the two-yearly progress report that demonstrates to the DGEG whether the targets committed to in the ARCE are being met.
- It compares actual consumption for the period against the agreed targets and explains the gaps. It is the document that requires compiling every energy invoice for the period again, which makes it the most time-consuming part of the SGCIE cycle for the auditor.
- DCRE
- The DCRE is the declaration an installation files with the DGEG reporting its annual energy consumption.
- It is what brings an installation into the SGCIE once consumption passes the threshold. An incorrect declaration compromises the whole cycle that follows, because the deadlines are derived from it.
- DGEG
- The DGEG is the Portuguese energy authority that administers the SGCIE, recognises the technicians and receives the PREn, ARCE and REP.
- It also enforces the regime and issues fines. In practice, the DGEG sets the deadlines an energy auditor has to work to.
- Recognised technician
- A recognised technician is the professional authorised by the DGEG to carry out energy audits and prepare the PREn and REP under the SGCIE.
- The recognition is personal, not corporate, and sits in a public register. A report submitted without a recognised technician's signature is not accepted under the regime.
- tep
- A tep, tonne of oil equivalent, is the unit that converts different forms of energy onto a common basis so electricity, gas and fuels can be added together.
- It is the unit the SGCIE thresholds are written in: 500 tep per year to enter the regime, 1000 tep per year for the stricter tier. One tep is roughly 11,630 kWh.
- ISO 50001
- ISO 50001 is the international standard for energy management systems, setting out how an organisation structures continuous improvement of its energy performance.
- It is voluntary and certifiable by an accredited certification body. It differs from an energy audit: the audit is a point-in-time examination, ISO 50001 is the system that keeps energy management running over time.
- EN 16247
- EN 16247 is the European standard that defines the requirements and methodology of an energy audit, including what the report must contain.
- It has separate parts by subject: part 1 is general, part 2 covers buildings, part 3 industrial processes and part 4 transport. It is the methodological reference that makes a report defensible to both the client and the regulator.
- Contracted power
- Contracted power is the maximum power an installation is entitled to draw under its supply contract, and it is billed every month regardless of how much is actually used.
- It is one of the most common audit findings: sites paying for years for headroom they never touch. Fixing it needs no capital investment, only a contract change.
- Reactive power
- Reactive power is the energy drawn by inductive loads such as motors and ballasts that does no useful work but still circulates on the network and is billed separately.
- It appears on industrial bills as its own penalised line. It is correctable with power-factor compensation, typically at short payback, which makes it a routine measure in an energy-reduction plan.
- Peak, mid, off-peak and super-off-peak
- Peak, mid, off-peak and super-off-peak are the time-of-day bands an electricity tariff is split into, each with a different price per kWh.
- Peak is the most expensive band and super-off-peak the cheapest. Splitting consumption by band is what allows shifting production in time to be evaluated, which is why extracting an invoice has to preserve that breakdown.
- CPE and CUI
- The CPE uniquely identifies an electricity supply point in Portugal; the CUI does the same for natural gas.
- They are the key that ties invoices to specific installations. In a company with several contracts and several suppliers, it is by CPE and CUI that you prove no consumption point was left out of the audit.
- IDAE
- IDAE is the Spanish body responsible for energy-efficiency policy and the equivalent counterpart to Portugal's DGEG in the energy-audit regime.
- In Spain the audit obligation lives in RD 56/2016 and audits are registered with the autonomous communities. The shape of the work is close to the Portuguese one, but the deadlines and the registration are not.
- RD 56/2016
- RD 56/2016 is the Spanish royal decree that transposes the European obligation for large companies to undergo periodic energy audits.
- It requires large companies to audit at least 85 per cent of their total energy consumption every four years. It is the functional equivalent of the SGCIE for anyone working on the Spanish side of the border.
Certification
- Certification body
- A certification body is the independent organisation that audits a company against a standard and decides whether to issue, maintain or withdraw the certificate.
- Independence is the product: a body cannot consult for and certify the same client. That is why the certification decision must always rest with a competent decision-maker inside the body, whatever tooling was used to prepare the analysis.
- Accreditation
- Accreditation is the formal recognition, by a national authority, that a certification body is competent to certify against a given standard.
- In Portugal accreditation comes from IPAC, in Spain from ENAC. Accreditation and certification sit at different levels: the body is accredited, the body's client is certified.
- Nonconformity
- A nonconformity is a failure to meet a requirement of the standard, identified during an audit.
- It is normally classified as major or minor. A major casts doubt on the management system's ability to achieve its objectives and blocks certification until resolved; a minor is an isolated lapse that requires corrective action but does not stop the decision.
- Stage 1 and Stage 2 audit
- A Stage 1 audit checks whether an organisation is ready to be audited; a Stage 2 audit assesses whether the management system is actually implemented and effective.
- Stage 1 focuses on documentation, scope and planning. Stage 2 happens on site and is where nonconformities are raised. Initial certification requires both.
- Scope of certification
- The scope of certification is the exact statement of which activities, products and sites a certificate covers.
- It is the boundary of what was audited, and the source of a lot of commercial misunderstanding: a certificate with a narrow scope does not cover the whole company. It is printed on the certificate itself.
- Audit evidence
- Audit evidence is the record, statement or verifiable fact an auditor relies on to conclude whether a requirement is met.
- It has to be verifiable, not an impression. That is why collecting documents from the client governs every later phase: without evidence there is no conclusion that holds up in front of a client or a regulator.
- Surveillance audit
- A surveillance audit is the periodic audit during a certification cycle that checks the management system still meets the standard.
- It is usually annual and narrower in scope than the initial audit, and at the end of the cycle it gives way to a recertification audit. It is what makes certification an ongoing commitment rather than a single exam.
- Chain of custody
- Chain of custody is the documented traceability of a certified product through every stage of ownership and transformation, from producer to end customer.
- It is what allows a finished product to be claimed as certified in origin. It is used in forestry, food and organic schemes, where a claim is worth exactly as much as the paperwork behind it.
Cybersecurity and supply chain
- NIS2
- NIS2 is the European cybersecurity directive that extends security and incident-reporting obligations to a far wider set of sectors and holds management bodies directly accountable.
- It does not apply directly: it applies through the national law that transposes it, in Portugal the Cybersecurity Legal Regime. One of its most demanding consequences is supply-chain security, which requires assessing third parties and not only your own house.
- QNRCS
- The QNRCS is the Portuguese national cybersecurity reference framework, which turns legal cybersecurity obligations into concrete measures an entity can implement and evidence.
- It is what gives the law a practical shape: instead of a general principle, a set of measures an entity or a supplier can be assessed against. That makes it the natural map for a supplier assessment questionnaire.
- Essential and important entities
- Essential and important entities are the two categories NIS2 splits covered organisations into, carrying the same obligations but different supervision and penalty regimes.
- Essential entities face proactive supervision and higher fines; important entities are supervised mainly after evidence of non-compliance. Which category applies depends on sector and size, and working that out is the first step of any NIS2 project.
- Supplier risk assessment
- A supplier risk assessment is the process of verifying that the entities in a supply chain have security measures proportionate to the risk they represent to the organisation buying from them.
- It combines a questionnaire, evidence collection and a risk rating per supplier. Under NIS2 it stopped being good practice and became an obligation for covered entities, which turns it into recurring work for consultancies and audit firms.
Agriculture
- GLOBALG.A.P.
- GLOBALG.A.P. is a private certification scheme for good agricultural practice, required by much of European retail as a condition of purchase.
- It covers food safety, environment, animal welfare and working conditions. In practice it works less as a marketing badge and more as a commercial licence: without it, many buyers will not start the conversation.
- TRACES
- TRACES is the European Commission's system for certifying and tracking consignments of agri-food products, animals and organic goods across EU trade and imports.
- It is where certificates of inspection for imported organic products are issued and validated. For a control body it is a mandatory step in the process, not an optional archive.
- Organic production
- Organic production is the EU-regulated method of farming that prohibits synthetic agrochemicals and genetically modified organisms, and which may only be claimed after certification by a control body.
- It requires a conversion period before produce can be sold as organic, typically two to three years depending on the crop. Control is annual and includes on-site inspection, which generates a considerable documentary load per operator.
Do you work with these terms every day?
foraudits collects the documents, extracts the data and checks the report against the standard. The decision and the signature stay yours.
Book a demo