API RP 1168 wasn’t rewritten so much as clarified, and that distinction is worth keeping in mind as you read it.
Published in May 2026, the Third Edition of API RP 1168, Pipeline Control Room Management, doesn’t introduce a new philosophy of control room management. The Control Room Management rule itself, 49 CFR 195.446 and 192.631, hasn’t changed since it took full effect in 2012. What’s changed is 15 years of inspection findings, PHMSA feedback, and operator experience, all of which the Third Edition folds into the standard.
One note on legal weight before getting into the changes themselves: the Third Edition is not incorporated by reference into the CFR. For liquids operators, Sections 5 and 7 of the First Edition still carry that status. The Third Edition reflects years of operator experience, inspection lessons, and work group discussions. A PHMSA representative participated throughout the development process, making the document one of the clearest indicators available of where industry guidance and inspection expectations have evolved.
The First Edition centered on establishing and implementing a CRM program, while the Third Edition places greater emphasis on demonstrating one. Many operators have found inspections increasingly focused on how those procedures show up in daily operations, how controllers make and communicate decisions, and what evidence exists that the program actually works. Each of the five changes below reflects that same shift in emphasis, applied to a different part of the operation.

Why the Update Happened
The work group behind this revision wasn’t starting from scratch. Most of what changed grew out of operators comparing notes on where inspections had gotten more specific, combined with PHMSA input on where operator practice had drifted from expectation, which is why the result reads more like documentation of existing best practice than a rewrite. It gives newer operators a clearer map of what “compliant” actually looks like in practice, while confirming for mature programs that they’re largely already doing the right things.
With that context, here are five areas the Third Edition expands.
1. Point-to-Point Verification
Point-to-point verification, confirming that field instrumentation, SCADA values, HMI displays, and alarm indications all represent the same operating condition, has always been one of the most resource-intensive parts of CRM, and it’s also one where guidance had been vague enough to leave room for inconsistent practice across the industry.
The Third Edition reduces that ambiguity by outlining more specific documentation expectations: the location and asset tested, everyone involved (not just the SCADA technician and controller, but the field personnel who physically verified the point), the field value, the SCADA value, the displayed value, and a clear pass or fail outcome. That last item addresses a real pattern across the industry, since many operators historically only kept records of the tests that passed, and if an inspector asks what happens when a point fails, “we don’t document that” isn’t an acceptable answer.
The reason this matters goes beyond documentation. Controllers trust the system until they have a reason not to, and once that trust breaks, it rarely breaks selectively. A couple of bad points out of a thousand can erode confidence in the entire board.
2. Control Room Determination and Applicability
Back when CRM plans were first built, most operators simply listed their primary and backup control rooms and considered the question settled, but the Third Edition makes clear that a facility list alone doesn’t hold up anymore.
PHMSA’s definition of a control room goes well beyond having a screen, an HMI, or SCADA access. The real questions are whether operational decisions are being made at that location, whether it’s directing pipeline operations, and whether it’s exercising control authority, and that framing creates real gray areas: field offices with SCADA access, compressor stations with some degree of operational authority, and gathering or production facilities with centralized control functions all raise the question of whether they meet PHMSA’s definition, regardless of what an operator informally calls them.
Inspectors increasingly want a documented rationale rather than just a facility list, and in practice that almost always shows up as a records request: can you produce the determination, and the reasoning behind it, for each location in question.
3. Direct or Supersede Authority
Who can override a controller’s operational decisions has been a live question since CRM took effect, and the Third Edition finally provides operators with a framework for answering it, rather than leaving it to informal practice.
If your organization allows direct or supersede authority in any form, procedures should define who holds it (a supervisor, a qualified supervisor, specific operations personnel), what qualifications they need (system-specific training, abnormal operations qualification, CRM training), what actions can and can’t be directed, and what gets documented when it happens.
There’s a distinction worth building into your procedures explicitly: directing an operating outcome (“we need to reduce pressure here”) is not the same as directing a technical action (“move this valve to this position”). The standard’s language of “direct or supersede technical actions” is doing real work there, and procedures that blur the two tend to be the ones that generate the most friction, and the most risk, during an actual override.
4. Backup Control Room Testing
Historically, backup testing meant testing the backup SCADA system, but the Third Edition shifts the focus to testing the backup operating location itself, which is a meaningfully different bar, since a backup SCADA environment that comes up clean doesn’t tell you whether people can actually operate safely from that physical location.
The updated guidance places greater emphasis on verifying physical readiness, operational capability, communications, procedures, and staffing readiness, not just system connectivity, and if your organization has more than one backup control room, the standard is explicit that all of them need to be tested, not just the primary backup.
That expectation matters more now than it did in 2012, simply because operations have consolidated: fewer organizations rely on field-based operation as a fallback, and more of them rely on the backup control room actually functioning as a control room. Keeping that testing scheduled and documented across every backup location is what turns “we tested the backup” into something that holds up to a records request.
5. Shift Turnover
Shift turnover has always been one of the highest-risk communication points in control room operations, and the Third Edition broadens what’s expected to be covered during it.
Previous guidance focused heavily on reviewing third-party incidents, while the revised language expands that to any event that could directly or indirectly affect operations: equipment outages, planned maintenance, communications issues, system limitations, and external events like upstream or downstream disruptions that affect flow. The underlying risk hasn’t changed, since errors at turnover happen because information gets omitted, misunderstood, or handed off inconsistently, often at the end of a long shift when attention is thin.
What Didn’t Change
It’s worth saying plainly that this is not a wholesale rewrite, and most operators with mature CRM programs are likely already doing much of what’s described above. The Third Edition’s main job is to clarify expectations, document what industry best practice already looks like, and give newer operators a more concrete starting point than the original rule’s page and a half ever provided.
The Real Takeaway
The underlying philosophy of CRM hasn’t changed. What’s changed is the emphasis: the question inspectors are asking has moved from “do you have a procedure” to “can you demonstrate that your CRM program consistently supports safe operational decision-making,” and each of the changes above reflects that same shift in emphasis, applied to a specific part of your operation.
Reviewing procedures against this standard is a reasonable start, but reviewing whether you can prove those procedures are working, with records, documentation, and evidence an inspector would recognize, is the actual bar the Third Edition sets. For a quick-reference checklist pulling the specific action item from each of the five areas above, see our companion post.
For more on the reasoning behind these changes, listen to the Pipeliners Podcast episode with Vickie Cain, who chaired the API work group behind the Third Edition. She walks through the inspection stories and work group debates that shaped several of these changes, including the point-to-point documentation example that made it into the standard itself.
