SuperbaLearning Demonstration release

Platforms
ENIT
Management and shore-based roles · Open learning path Role-based path

DPA

The Designated Person Ashore within the Safety Management System

13learning modules
AdvancedLevel
SBL-DPA-ADV-01Code
August 2026Reference date

Learning objectives

  • Explain why the ISM Code requires a shore-based person with direct access to the highest level of management, documented authority and adequate resources.
  • Describe in detail the responsibilities set out in §4 of the Code.
  • Assess the qualifications, training and experience the role requires under MSC-MEPC.7/Circ.6.
  • Define emergency roles, contacts, alternates and escalation levels in the SMS.
  • Manage the relationship with the Master while preserving their operational authority.
  • Conduct or supervise internal audits with method and without conflicts of interest.
  • Build a reporting culture that genuinely feeds SMS improvement.
  • Organise continuity of the role through Deputy DPAs, including across multi-flag fleets.
Module 01

Why the ISM Code requires the DPA

Module objectiveUnderstand the DPA's function within the ISM Code and distinguish the ship–shore link, direct access to senior management, monitoring and support.

The Designated Person Ashore arose from a lesson learned at great cost: the Herald of Free Enterprise ferry disaster (1987) showed how safety management left solely to shipboard initiative, without an effective link between those on board and senior management ashore, could fail systematically. The ISM Code, adopted through IMO Resolution A.741(18) of 4 November 1993, became mandatory on 1 July 1998 with the entry into force of SOLAS Chapter IX, and requires every company to designate one or more people for this role.

The text of the Code, in full

It is worth reading §4 in its entirety, because the part that is quoted least is precisely the part that defines the role.

«To ensure the safe operation of each ship and to provide a link between the Company and those on board, every Company, as appropriate, should designate a person or persons ashore having direct access to the highest level of management. The responsibility and authority of the designated person or persons should include monitoring the safety and pollution prevention aspects of the operation of each ship and ensuring that adequate resources and shore-based support are applied, as required.»ISM Code, §4 — Designated person(s)

The first purpose — to provide a link between the Company and those on board — is the one most often lost in summaries, and yet it is the one everything else follows from: the relationship with the master, the crew reporting channel, availability in an emergency. Monitoring comes after it, not before.

A mirror obligation, often forgotten

§4 creates a duty on the Company too, not only on the DPA. §3.3 says so explicitly: the Company is responsible for ensuring that adequate resources and shore-based support are provided to enable the designated person or persons to carry out their functions. A DPA without time, budget and authority is not a weak DPA: it is a non-conformity of the Company.

The Code and its five sets of amendments

The text in force is not the 1993 one: five sets of amendments have changed it, and the last two bear directly on the DPA's daily work.

Table 1 — The Code and its five sets of amendments
ResolutionIn force fromWhat it changes
MSC.104(73) — 20001 July 2002Introduces the definitions of objective evidence, observation, non-conformity, major non-conformity and anniversary date; rewrites certification (§13) and adds interim certification (§14)
MSC.179(79) — 20041 July 2006Amends the DOC and SMC forms, adding the completion date of the verification on which the certificate is based
MSC.195(80) — 20051 January 2009Adds the Company identification number to all four certificate forms, interim ones included
MSC.273(85) — 20081 July 2010Sets the maximum interval between internal audits at twelve months (§12.1); makes the two limbs of major non-conformity alternative; introduces assessment of all identified risks at §1.2.2.2
MSC.353(92) — 20131 January 2015Introduces §12.2 on verifying those undertaking delegated ISM tasks; rewrites §6.2 on manning; adds to the title of §4 the footnote pointing to the IMO guidance on DPA qualifications

Table 1.1 — The amendments to the ISM Code and their effects.

That last row deserves attention: since 1 January 2015 it is the Code itself, in a footnote to the title of §4, that points to MSC-MEPC.7/Circ.6 for the qualifications, training and experience of the designated person. It is no longer guidance found elsewhere: it is anchored to the text.

Why «ashore» and not «on board»

The DPA is deliberately a shore-based figure: their usefulness lies precisely in not being subject to the same operational, commercial and hierarchical pressures acting on the ship at any given moment. It is a structural counterweight, not a duplicate of the Master.

A role, not necessarily a single person

The Code allows one or more persons to be designated. The company should document their responsibilities, authority and coordination; large or heterogeneous fleets may use a principal DPA supported by alternates or other formally designated persons by geographical area or ship type (see Module 11).

Key takeaways

  • Section 4 requires one or more shore-based persons with direct access to the highest level of management.
  • The DPA links the company and those on board and monitors safety and pollution prevention.
  • Adequate resources and shore-based support remain the company's responsibility under section 3.3.
Module 02

Direct access and organizational effectiveness

Module objectiveAssess whether access, authority, resources and conflict controls make the role effective within the company's actual structure.

The defining feature of the role is not an abstract requirement for organizational independence, but the effective ability to reach the highest level of management directly and to report non-conformities and observations without other functions preventing or neutralizing the process. Reporting structures may vary between companies; what must be demonstrable is that the access, authority, responsibilities and resources defined in the SMS work in practice.

The DPA in the shore organisation: direct access to the highest level of management, a link with those on board, functional interfaces with the other functions (ISM section 4).
The DPA in the shore organisation: direct access to the highest level of management, a link with those on board, functional interfaces with the other functions (ISM section 4).

What «direct access» means in practice

  • The DPA has a defined channel for direct access to the highest level of management.
  • Responsibilities, authority and escalation arrangements are documented in the SMS.
  • Any additional operational or commercial roles are assessed and controlled so that they do not impair monitoring and reporting.
  • The company provides adequate personnel, material resources, training and shore-based support.

The risk of role conflict

A widespread practice, especially at smaller companies, is to assign the DPA role to someone who already holds an operational position (for example the Fleet Manager). This is not prohibited by the Code, but it introduces a structural risk: the same person who is accountable for commercial deadlines and costs may find themselves having to decide, wearing the «DPA hat», against the immediate interest of those same deadlines.

DPA Focus — the role's effectiveness is proven in uncomfortable moments

How the role actually works is not measured in calm moments, but in those where the correct safety decision conflicts with an imminent commercial deadline. A DPA who has never halted or slowed an operation for safety reasons should check whether access, authority and resources really function, or whether the conflict controls set out in the SMS have stopped holding.

Key takeaways

  • The Code prescribes direct access, not a single organisation chart or general hierarchical independence.
  • Responsibilities, authority and escalation arrangements should be defined and documented.
  • A combined role is sustainable only where conflicts are assessed and do not undermine monitoring and reporting.
Module 03

The §4 responsibilities in detail

Module objectiveUse Circular 8 to translate the concise section 4 mandate into verifiable monitoring processes and resources.

The six processes the DPA should verify and monitor and the five resources the company should provide (MSC-MEPC.7/Circ.8, §§4.2-4.3).
The six processes the DPA should verify and monitor and the five resources the company should provide (MSC-MEPC.7/Circ.8, §§4.2-4.3).

The six processes the DPA has to monitor

§4 of the Code is deliberately brief. The operational list of what the DPA must verify and monitor sits not in the Code but in the IMO guidance the Code itself points to: MSC-MEPC.7/Circ.8, «Revised guidelines for the operational implementation of the ISM Code by Companies». At §4.2 it lists, as a minimum, six internal processes.

Table 2 — The six processes the DPA has to monitor
#Internal processWhat it means in practice
1Communication and implementation of the safety and environmental protection policyChecking that the policy is known and acted on aboard, not posted on the bridge
2Evaluation and review of the effectiveness of the SMSNot whether the SMS exists, but whether it works: it feeds the management review
3Reporting and analysis of non-conformities, accidents and hazardous occurrencesSafeguarding the quality of root-cause analysis, not just the event count
4Organising and monitoring internal audits, including verification of the independence and training of the auditorsThe most commonly overlooked duty: the DPA also answers for who conducts the audits and how they were trained
5Appropriate revisions to the SMSClosing the loop: if the analysis finds a weakness, the procedure changes
6Ensuring the Company provides adequate resources and shore-based supportReporting to top management when the resources are not there, with documented evidence

Table 3.1 — The internal processes the DPA must verify and monitor (MSC-MEPC.7/Circ.8, §4.2).

And the five resources the Company owes them

The same guidance, at §4.3, lists what the Company must provide so that the DPA can perform the role. It is the list to use when negotiating your own mandate — or when contesting it.

  • Personnel resources.
  • Material resources.
  • Any training required.
  • Clearly defined and documented responsibility and authority.
  • Authority for reporting non-conformities and observations to the highest level of management.

The last point is the most important and the easiest to hollow out: it is not enough that the DPA can talk to top management — they must be able to put on record non-conformities and observations at that level.

DPA Focus — «monitoring» is not «certifying»

The DPA does not certify that everything is in order: they monitor, verify, raise red flags and secure resources. Operational responsibility for safety remains with the Master and the chain of command; the DPA is the system safeguard that ensures that responsibility can actually be exercised.

Key takeaways

  • Circular 8 identifies the processes the DPA should verify and monitor.
  • The role concerns SMS effectiveness, not the DPA personally certifying every activity.
  • The company should provide personnel, material resources, training, documented authority and access to senior management.
Module 04

Who can be a DPA: qualifications, training, experience

Module objectiveVerify the documented suitability of every formally designated person against the criteria in Circular 6.

§4 of the Code says what the DPA must do, not who may do it. The gap is filled by dedicated IMO guidance, MSC-MEPC.7/Circ.6, which since 1 January 2015 is no longer a document to be found elsewhere: MSC.353(92) added to the title of §4 a footnote pointing explicitly to that circular. It is the benchmark a flag inspector, an external auditor or a charterer uses to judge whether the designated person is equal to the role.

Qualification: three alternative routes

The circular does not impose a single credential. It sets out three, alternative to one another: meeting any one of them is enough.

Table 3 — Qualification: three alternative routes
RouteRequirement
AcademicA qualification from a tertiary institution recognised by the Administration or by the recognized organization, within a relevant field of management, engineering or physical science
Maritime professionalQualification and certification as a ship officer under the STCW Convention 1978, as amended
Experience-basedOther formal education combined with not less than three years of practical senior-level experience in ship management operations

Table 4.1 — The three alternative qualification routes (MSC-MEPC.7/Circ.6, §2.1).

The third route is not a shortcut

The wording «other formal education combined with not less than three years practical senior level experience» is often read as though experience alone would do. It does not: both are needed, and the experience must be at senior level and in ship management operations — not generically in the maritime sector. This is the point on which a flag audit asks for documentary evidence.

Training: what it has to cover

§3.1 of the circular lists the areas the designated person's training must cover. It is the skeleton of a defensible training plan.

  • Knowledge and understanding of the ISM Code.
  • Mandatory maritime rules and regulations.
  • Applicable codes, guidelines and standards.
  • Assessment techniques: examining, questioning, evaluating and reporting.
  • Technical and operational aspects of safety management.
  • Appropriate knowledge of shipping and shipboard operations.
  • Participation in at least one audit of a marine-related management system.
  • Effective communication with shipboard staff and senior management.

The second-to-last point is what separates real training from a certificate: the circular does not ask that you have studied auditing, but that you have taken part in at least one marine-related management system audit. That is a verifiable requirement, and it should be documented.

Experience: six capabilities to demonstrate

§4.1 moves from paper to demonstration: the designated person should be able to do six things.

  • Present safety matters to senior management and sustain their support for improvement programmes.
  • Verify the safety management system's compliance with the requirements of the ISM Code.
  • Evaluate the system's effectiveness through internal audits and management reviews.
  • Assess compliance with applicable rules beyond what statutory surveys cover.
  • Evaluate industry recommendations on safety culture.
  • Analyse hazardous occurrences and carry the lessons learned back into the system.
DPA Focus — the first capability is the hardest

Of the six, five are technical and come with practice. The first — presenting safety to top management and keeping their support over time — is political, and it decides whether the other five will amount to anything. A technically impeccable DPA who cannot secure resources is a DPA who accurately documents their own failure.

When the DPA is more than one person

The Code allows one or more persons to be designated. Where several persons are formally designated, the company should be able to demonstrate the suitability of each person for the functions assigned: Circular 8, paragraph 4.4, applies the qualifications, training and experience in Circular 6 to the «Designated Person(s)». Complementary expertise may strengthen the team, but it does not replace the individual evidence required for anyone formally undertaking the role. Module 11 covers the organisational models that follow.

Circular 6 is IMO guidance referenced in a footnote to the Code. The reference strengthens its relevance during verification, but does not automatically turn every «should» statement into a prescriptive requirement equivalent to the mandatory text of the Code.

Key takeaways

  • Circular 6 provides three alternative routes to initial qualification.
  • Training, participation in at least one audit and operational experience should be evidenced.
  • Team members may have complementary expertise, but this does not replace the suitability of each designated person.
Module 05

The DPA in emergencies

Module objectiveDefine a response arrangement that supports the master, activates shore resources and provides continuity without confusing company practice with the text of the Code.

During an emergency, the DPA may act as the principal link between the ship, senior management and shore-based support, in accordance with the responsibilities defined in the SMS. The Code does not prescribe a single activation chain or expressly require the DPA personally to be available 24/7; it requires the company to establish adequate procedures, resources and support. For many operations this entails a continuously monitored contact route, competent alternates and tested handovers.

Example of an SMS emergency activation route, from the master's notification to the lessons learned returning into the SMS: an organisational arrangement, not a sequence prescribed by the Code.
Example of an SMS emergency activation route, from the master's notification to the lessons learned returning into the SMS: an organisational arrangement, not a sequence prescribed by the Code.

The DPA's role during the emergency

  • Receive notification from the Master as quickly as possible, through the monitored contact route established in the SMS.
  • Quickly assess severity and activate, if necessary, the company's Emergency Response Team.
  • Coordinate the necessary external resources: technical, legal, insurance, media, port authorities.
  • Keep top management informed in real time, without filters that delay their awareness.
  • Provide ongoing support to the Master, who retains the overriding authority under §5.2 and remains responsible for immediate decisions on board (Module 08).
  • Once the event has concluded, conduct the debrief and ensure the lessons learned enter the SMS.
DPA Focus — response continuity is designed and tested

Where the company's analysis requires 24/7 coverage, the SMS should identify who monitors the contact route, who acts in the DPA's absence, what information is handed over and how availability is tested — periodic call tests, for instance. It is a sound organizational control, and often a necessary one: it should not, however, be presented as wording contained in section 4 itself.

Key takeaways

  • The master retains overriding authority for immediate decisions on board.
  • Roles, contacts, alternates and escalation arrangements should be established in the SMS.
  • 24-hour coverage is a possible organizational control, not wording prescribed by section 4.
Module 06

Safety and environmental monitoring

Module objectiveIntegrate operational sources and indicators to identify systemic signals without relying on a single data point or a formally green dashboard.

Outside of an emergency, the DPA's most important daily work is continuous monitoring: reading the signals the fleet produces before they become a serious problem.

The DPA's information sources

Table 4 — The DPA's information sources
SourceWhat it reveals
Internal and external auditsThe SMS's real adherence to shipboard practice
PSC and vetting outcomesPatterns of deficiencies and observations by ship and by fleet
Near-miss and incident reportsEarly risk signals before a serious event
Maintenance indicators (PMS)Backlog and availability of critical spares
Direct crew reportsProblems the chain of command might filter or downplay

Table 6.1 — Main information sources for DPA monitoring.

From data to warning signal

The DPA's value lies not in collecting data, but in knowing how to read it together: a ship with recurring vetting observations on human factors, a growing maintenance backlog and a low near-miss reporting rate together tell a more concerning story than any single data point does on its own.

DPA Focus — avoid the green-dashboard illusion

An all-green dashboard can mean two opposite things: that the ship is genuinely doing well, or that no one is reporting problems. The experienced DPA always combines data with direct contact (visits on board, conversations with the crew) to tell the two situations apart.

Key takeaways

  • Audits, PSC, vetting, maintenance and reporting describe different aspects of the same system.
  • Trends and recurrence are more informative than isolated event counts.
  • Data should be tested against qualitative evidence and direct contact with the ship and crew.
Module 07

Non-conformities, incidents and near-misses

Module objectiveDistinguish the ISM categories and verify that reporting, analysis, corrective action and recurrence prevention form an effective process.

The company must have procedures for reporting, investigating and analysing non-conformities, accidents and hazardous occurrences and for implementing corrective action. The DPA verifies and monitors the effectiveness of these processes and may participate in or coordinate them as defined by the SMS, but the Code does not make every investigation a personal, non-delegable duty of the DPA.

What §9 requires

The Code devotes two very short paragraphs to this, and they contain everything.

«The SMS should include procedures ensuring that non-conformities, accidents and hazardous situations are reported to the Company, investigated and analysed, with the objective of improving safety and pollution prevention.»ISM Code, §9.1
«The Company should establish procedures for the implementation of corrective action, including measures intended to prevent recurrenceISM Code, §9.2, as amended by MSC.273(85)

The words added to §9.2 in 2010 — prevent recurrence — shift the centre of gravity: closing the case is not enough, you have to show you acted so it does not come back. That is precisely the difference between a correction and a corrective action, and it is the point a well-run audit presses on.

The SMS improvement cycle

Connecting ISM controls to improve the SMS, paragraph by paragraph (§§9.1, 9.2, 12.1, 12.2, 12.3): separate requirements, not a prescribed flowchart.
Connecting ISM controls to improve the SMS, paragraph by paragraph (§§9.1, 9.2, 12.1, 12.2, 12.3): separate requirements, not a prescribed flowchart.

The Code's definitions, not convenient ones

These four notions are not industry jargon: they are defined in the Code at §§1.1.7-1.1.10, introduced by MSC.104(73). Using them precisely is what separates a defensible audit report from a contestable one.

Table 5 — The Code's definitions, not convenient ones
TermThe Code's definitionOperational consequence
Objective evidence
§1.1.7
Quantitative or qualitative information, records or statements of fact pertaining to safety or to the existence and implementation of an SMS element, based on observation, measurement or test, and verifiableWithout objective evidence there is neither an observation nor a non-conformity: there is an opinion
Observation
§1.1.8
A statement of fact made during a safety management audit and substantiated by objective evidenceNo formal corrective action required, but it must be recorded and considered in the management review
Non-conformity
§1.1.9
An observed situation where objective evidence indicates the non-fulfilment of a specified requirementRequires root-cause analysis and corrective action with an owner and a deadline
Major non-conformity
§1.1.10
An identifiable deviation that poses a serious threat to the safety of personnel or the ship, or a serious risk to the environment, requiring immediate corrective action; or the lack of effective and systematic implementation of a requirement of the CodeRequires immediate corrective action and application of the procedures for major non-conformities; it may affect the validity of the DOC and SMC. In port State control, a serious failure or lack of effectiveness of ISM implementation may constitute grounds for detention

Table 7.1 — The ISM Code definitions, §§1.1.7-1.1.10.

The conjunction that changes everything

Until 2010 the definition of major non-conformity read «and includes»: both limbs had to be present. MSC.273(85), in force from 1 July 2010, replaced that with «or». Since then the lack of effective and systematic implementation of a requirement of the Code is, on its own, a major non-conformity, even without a serious and immediate threat. It is the legal basis of the whole logic of «systemic» ISM deficiencies.

The procedures for handling observed major non-conformities are in MSC/Circ.1059-MEPC/Circ.401, referenced in a footnote to §1.1.10 of the Code.

DPA Focus — supervise without taking over

The DPA verifies that the root-cause analysis and corrective-action closure process is rigorous, but does not necessarily need to conduct it personally every time: their added value is ensuring the process is not «tamed» to quickly close an uncomfortable case.

Key takeaways

  • Section 9 places the process on the company; the DPA verifies and monitors its effectiveness.
  • A major non-conformity requires immediate action and specific procedures and may affect certificate validity.
  • Objective evidence, observation, non-conformity and major non-conformity are not interchangeable terms.
Module 08

The relationship with the Master

Module objectiveBuild a DPA–master relationship that protects overriding authority, access to assistance and timely information flow.

One of the most delicate and most often misunderstood relationships in maritime organisation is that between the DPA and the master. The Code leaves no room for doubt: at §5.2 it requires the Company to include in the SMS a clear statement that the master has overriding authority and the responsibility to make decisions with respect to safety and pollution prevention, and to request the Company's assistance as may be necessary. The DPA does not command the ship.

That second half of the sentence is the hinge between the two roles, and it is quoted far less than the first. Overriding authority is not only the master's power to say «no» to an operation: it is also their right to ask for help — and therefore the Company's corresponding duty to answer that request. The SMS should define how that request is received and met: the DPA is often the central channel, but the duty to provide support remains with the company and the practical arrangement depends on the documented responsibilities. An SMS that asserts the master's authority but does not define how and to whom to request assistance has implemented half of §5.2.

Support, not overlap

  • The DPA provides resources, information and support: they do not issue direct operational orders to the ship under normal conditions.
  • In an emergency, the DPA coordinates external resources while the Master retains command of immediate decisions on board.
  • A Master who perceives the DPA as a hostile controller, rather than an ally, will tend to hide problems rather than report them.

Building mutual trust

The quality of the relationship between the DPA and the Master is built over time, through regular visits on board (not only when problems arise), honest communication even on sensitive matters, and a reputation for fairness in handling reports. A DPA seen only during moments of crisis is unlikely to receive timely reports during normal times.

DPA Focus — the first visit on board should not be during an emergency

If the first real contact between a new Master and the DPA happens during an incident, the trust needed for honest, timely communication starts at a disadvantage. Regular visits, scheduled even in the absence of problems, are the cheapest investment a DPA can make in the quality of the system.

Key takeaways

  • The DPA supports the master but does not assume operational command of the ship.
  • The duty to provide assistance remains with the company and should be operationalised in the SMS.
  • Trust and regular contact increase the likelihood that problems are reported in time.
Module 09

DPA and audits

Module objectiveGovern audits, reviews, certification and follow-up while maintaining auditor independence, correct deadlines and evidence of SMS effectiveness.

The DPA has a supervisory role, and sometimes a direct conducting role, over the audits that verify the SMS's adherence to actual practice: internal company audits, external class/flag audits (DOC/SMC verification), and checks prompted by vetting or PSC.

Table 6 — DPA and audits
Type of auditWho conducts itDPA's typical role
Internal company auditQualified internal auditors, independent of the audited areaSupervision, review of findings, guarantee of independence
External DOC/SMC verificationClassification society (RO) on behalf of the flagMain interface, management of identified non-conformities
PSC inspections / vettingPort authority / commercial inspectorAnalysis of outcomes from a systemic, not just single-ship, perspective

Table 9.1 — Types of audit relevant to the DPA.

The seven rules of §12, in order

Section 12 of the Code is the DPA's operational mandate on verification. Its current structure is worth knowing, because two of the seven paragraphs are more recent than many SMSs reflect.

Table 7 — The seven rules of §12, in order
§ObligationWhat it means for the DPA
12.1Internal safety audits on board and ashore, at intervals not exceeding twelve months; in exceptional circumstances the interval may be exceeded by not more than three monthsThis is the number to keep on the dashboard: the due date is per ship and per office, not fleet-wide
12.2Periodic verification that all those undertaking delegated ISM-related tasks act in conformity with the Company's responsibilities under the CodeThird-party ship managers, crewing agencies, technical service providers: if an ISM task is delegated, the responsibility stays with the Company and the verification is the DPA's
12.3Periodic evaluation of the effectiveness of the SMS, in accordance with Company proceduresThis is the management review
12.4Audits and any corrective actions carried out in accordance with documented proceduresThe audit programme is itself an SMS procedure
12.5Personnel carrying out audits must be independent of the areas audited, unless this is impracticable due to the size and nature of the CompanyNo one verifies their own work: a superintendent does not audit the ship they manage
12.6Audit and review results are brought to the attention of all personnel responsible for the area involvedAn outcome that stays in a folder does not satisfy §12.6
12.7The management personnel responsible for the area take timely corrective action on the deficiencies foundClosure is the line's responsibility, not the DPA's: the DPA verifies that it happens

Table 9.2 — Section 12 of the ISM Code in its current numbering.

Two paragraphs more recent than many SMSs reflect

The twelve-month maximum interval in §12.1 was not in the 1993 text: it came in with MSC.273(85) and has been in force since 1 July 2010. §12.2 on verifying delegated ISM tasks is more recent still — MSC.353(92), in force from 1 January 2015 — and it renumbered the paragraphs that follow. An SMS that still cites «§12.2 — evaluation of effectiveness» is using pre-2015 numbering.

The management review: what has to go into it

§12.3 requires the review but does not define its content. MSC-MEPC.7/Circ.8 does, at §5.2, listing what the review must take into account as a minimum: the results of internal audits; non-conformities reported by personnel; the master's reviews; the analysis of non-conformities, accidents and hazardous occurrences; and any other evidence of possible SMS failure, including non-conformities raised by external parties and PSC inspection reports.

The same guidance adds that the review should be performed periodically as defined by the Company or when needed — for example in case of serious system failures — and that its results should be brought formally to the attention of all personnel involved.

Certification: DOC, SMC and the interim ones

The DPA is the main interface for certification verifications, and therefore the keeper of a calendar that tolerates no slippage. The rules are in §§13 and 14 of the Code, in the version introduced by MSC.104(73).

Table 8 — Certification: DOC, SMC and the interim ones
DocumentValidityVerifications
Document of Compliance (company)up to 5 yearsannual verification within three months before or after the anniversary date
Safety Management Certificate (ship)up to 5 yearsat least one intermediate verification between the second and third anniversary
Interim DOCup to 12 monthsfor newly established companies, or companies adding a new ship type
Interim SMCup to 6 months, extendable by a further 6for a newly delivered ship, a change of company or a change of flag

Table 9.3 — Validity and verification of ISM certificates (§§13-14).

For verification and certification by Administrations the current reference is resolution A.1188(33), adopted in 2023, which revoked A.1118(30). Circular 8 remains the operational guidance addressed to companies; the two instruments have different audiences and functions.

Two details that are often missed: a copy of the DOC must be on board, so the master can produce it on request (§13.3); and if the renewal verification is completed after the existing certificate has expired, the new certificate runs from the date of completion to no more than five years from the expiry of the previous one — not from the date of issue.

When the audit arrives from the quayside: ISM deficiencies in a PSC inspection

An ISM deficiency raised by a Port State Control inspector does not stay with the ship: it travels up to the company, and the DPA is its operational addressee. Under the Paris MoU regime, ISM deficiencies carry a single defective item code, 15150, with two possible outcomes.

  • Code 21 — the deficiencies do not warrant detention but indicate a lack of effectiveness in implementing the ISM Code: the company must take corrective action on the system within three months. Once that period passes with the deficiency still open, an unexpected factor is generated and the ship becomes eligible for an additional inspection again.
  • Code 19 — the deficiencies indicate a serious failure: the deficiency is a ground for detention and the flag Administration must carry out a safety management audit before the ship can sail. Once the audit is done, closure is recorded with code 21.
Code 21 commits the office, not the ship

This is the difference that counts, and it is missed with regularity: a broken light is rectified on board, a 15150 deficiency is closed ashore. The three-month deadline is not an administrative reminder but an automatic trigger that puts the ship back in the targeting system's sights — and complying with it is, in practice, the DPA's job. The Port State Control course covers the mechanism from the inspection side.

Conflict of interest in internal audit

The §12.5 principle has a stated limit: independence is required unless this is impracticable due to the size and nature of the Company. That is a real allowance for small operations, but it is not an exemption: where an auditor who is not fully independent has to be used, the choice should be reasoned and compensated — for instance by having a second person review the findings, or by rotating auditors between ships. The DPA safeguards this balance at the level of the whole company's audit programme and — as Circ.8 §4.2 notes — also answers for the training of internal auditors, not only for their independence. In short: the DPA organizes and monitors the audit programme and verifies auditor independence and training, and may personally conduct an audit only where independence from the audited area is maintained, in accordance with section 12.5 and the company's procedures.

DPA Focus — an honest audit looks for discrepancies

An internal audit programme that never finds anything to improve is not a sign of excellence: it is almost always a sign that the audit is not conducted with sufficient rigour. A DPA reviewing audit outcomes should be more concerned by a repeated «all in order» report than by one with a few honestly reported issues.

Key takeaways

  • The DPA organizes and monitors audits; auditors should remain independent of the area being verified.
  • DOC and SMC have different verification arrangements and windows and should not be treated as equivalent.
  • Resolution A.1188(33) is the current reference for implementation and certification by Administrations.
Module 10

Safety culture and reporting

Module objectiveDesign a near-miss reporting system consistent with Circular 7 that supports learning without making indiscriminate promises of immunity.

The success of the DPA role depends largely on the reporting culture they manage to build within the company: a system in which minor near-misses remain hidden deprives the DPA of precisely the most valuable signals for preventing serious events.

The idea that serious events rest on a broad base of minor events and at-risk behaviours goes back to the studies of Heinrich (1931, a 300:29:1 ratio) and Bird (1969, 600:30:10:1). The numerical ratios are contested in more recent literature and should not be used as a prediction: the value of the pyramid is to illustrate a principle — the base is the only part you can act on before anything happens — not to provide a quantitative model.

The reporting pyramid and the historical Heinrich and Bird ratios, illustrative of the principle and not predictive.
The reporting pyramid and the historical Heinrich and Bird ratios, illustrative of the principle and not predictive.

What a near-miss is, according to the IMO

Investigating near-misses is not a voluntary good practice: it is an obligation flowing from the «hazardous occurrences» part of §9 of the Code. The IMO devoted specific guidance to it, MSC-MEPC.7/Circ.7, which also gives the operational definition.

«A sequence of events and/or conditions that could have resulted in loss. This loss was prevented only by a fortuitous break in the chain of events and/or conditions. The potential loss could be human injury, environmental damage, or negative business impact — repair or replacement costs, scheduling delays, contract violations, loss of reputation.»MSC-MEPC.7/Circ.7, Annex §2.1

Two elements of this definition are regularly lost in shipboard practice. The first is that the loss must have been prevented by a break in the chain of events or conditions: the same guidance, however, includes among its examples an event in which an emergency procedure, plan or response is activated and prevents the loss. An occurrence should therefore not be excluded automatically merely because a planned barrier worked — the sequence, loss potential and the classification established in the SMS should be assessed and applied consistently over time. The second is business impact: an event that came nowhere near a person but could have cost a detention or a contractual penalty falls squarely within the definition, and must be reported.

The circular gives three example categories, useful for calibrating crew training: an event that triggers an emergency procedure and thereby prevents the loss; an event where an unexpected condition could have led to an adverse consequence that did not occur; and a hazardous situation discovered only after the danger has passed — for instance a ship that, hours into the voyage, finds its radio was not tuned to the Harbour Master's frequency.

The barriers to reporting, and how to bring them down

The same guidance is explicit about why near-misses go unreported: fear of being blamed, disciplined, embarrassed or found legally liable. To those it adds barriers that come directly from management: complacency about known deficiencies, insincerity in addressing safety issues, and the implicit discouragement created by expecting seafarers to conduct investigations in their own time.

  • Encourage a just culture that explicitly covers near-miss reporting.
  • Assure confidentiality, both through company policy and by «sanitizing» analyses and reports of personal information — which should not be retained once the investigation and reporting processes are complete.
  • Ensure investigations are adequately resourced: if the investigation happens after the watch, the message is that it does not matter.
  • Follow through on the recommendations, and disseminate the decision widely — including when the decision is not to implement them.
  • Maintain the DPA's regular physical presence on board, which builds the trust needed for informal reporting.
A just culture has to be bounded, not just declared

Circ.7 defines a just culture as «an atmosphere of responsible behaviour and trust whereby people are encouraged to provide essential safety-related information without fear of retribution», but immediately adds the distinction between acceptable and unacceptable behaviour: the latter does not necessarily carry a guarantee against consequences. And above all — §1.4 — it is a crucial requirement that the company clearly defines the circumstances in which it will guarantee a non-punitive outcome and confidentiality, and that it trains everyone involved on that approach. A policy that vaguely promises «no punishment» without stating its boundaries does not survive the first uncomfortable report.

What to gather, and when to dig deeper

Circ.7 sets five questions as the minimum content of any report.

  • Who and what was involved?
  • What happened, where, when, and in what sequence?
  • What were the potential losses and their potential severity?
  • What was the likelihood of a loss being realized?
  • What is the likelihood of a recurrence of the chain of events and/or conditions?

The answers to the last two decide the depth of the work: a full investigation is required for near-misses likely to recur and/or which could have had severe consequences. For the rest a cursory report suffices. It is a simple, defensible criterion, and it belongs in the SMS: without it, the risk is investigating everything badly rather than a few things well.

Once the investigation is complete, the circular asks for two things: a report proportionate to the depth of the analysis, and storing the information in a way that supports long-term trend analysis. That is the point at which the DPA's work stops being reactive and becomes monitoring.

DPA Focus — a low number of reports is never good news

If the number of reported near-misses suddenly drops, the first hypothesis to check is not that the ship has become safer, but that something in the reporting culture has deteriorated: a change of Master, a perceived retaliation incident, a workload that discourages reporting.

Key takeaways

  • A just culture distinguishes acceptable from unacceptable behaviour and clearly defines confidentiality and limits.
  • An occurrence is not excluded automatically from near-miss classification because a procedure or barrier prevented the loss.
  • Consistent reports, proportionate investigation and data retention support trend analysis.
Module 11

Deputy DPA and continuity of the role

Module objectiveConfigure and test a continuity model suited to the company's size, fleet, risks and documented responsibilities.

The DPA role cannot have gaps in coverage: illness, leave, or simply the volume of a large fleet make a continuity structure necessary, typically through one or more Deputy DPAs.

The Deputy DPA is not a role defined in the Code: §4 speaks of «a person or persons» designated and leaves the choice of model to the company, according to its size, the composition of its fleet and the risks that follow. It follows that the arrangement should be made explicit in the SMS — who stands in for whom, with what responsibilities and what authority, with what competence and with what handover — and that, where several persons are formally designated, the suitability of each for the functions assigned should be demonstrable against the Circular 6 criteria (Module 04).

Typical organisational models

Table 9 — Typical organisational models
ModelWhen it is used
Single DPA with backup DeputySmall/medium homogeneous fleets
Principal DPA + Deputy by geographical areaFleets operating under multiple flags/regions with different regulatory needs
Principal DPA + Deputy by ship typeHeterogeneous fleets (e.g. tankers and dry bulk) with differentiated technical expertise

Table 11.1 — Organisational models for DPA role continuity.

DPA Focus — continuity must be tested, not just written down

A continuity plan that exists only on paper risks failing precisely when it is needed. Periodic tests of availability and handover (for example simulating the principal DPA's absence during an emergency drill) verify that the system actually works, not just that it is documented.

Key takeaways

  • The Deputy DPA is an organizational choice by the company, not a role defined in the Code.
  • Alternates, authority, competence and handovers should be explicit.
  • Where several persons are formally designated, each person's suitability should be demonstrable.
Module 12

DPA in multi-flag, multi-class fleets

Module objectiveGovern additional requirements and different interfaces while maintaining a coherent SMS, dated sources and clear responsibilities.

Companies managing ships under different flags, with different classes, face additional complexity: national requirements adding to the common IMO framework, and different class contacts for each ship.

The main challenges

  • Additional national requirements that some flags impose on the DPA role, beyond the minimum required by the ISM Code.
  • Multiple interfaces with different classification societies, each with its own timelines and verification procedures.
  • Need for diverse language and cultural skills in communicating with multinational crews.
  • Coordination with the performance lists of multiple PSC regimes (Paris MoU, Tokyo MoU, USCG) simultaneously.

A workable approach

The most structured companies keep an updated register of the specific requirements for each flag managed, assign area expertise to Deputy DPAs, and maintain an ongoing dialogue with local representatives of classification societies to anticipate procedural differences. For the register to be verifiable, each entry should carry the applicable source, the ships it applies to, the person responsible and the date of the last check: a generic list of possible requirements, not tied to a specific Administration and a date, does not survive an audit.

DPA Focus — a uniform SMS does not mean uniform requirements

A single, coherent Safety Management System for the whole fleet remains the right objective, but the DPA must know and manage national exceptions without letting them fragment the company's shared safety culture.

Key takeaways

  • The common IMO framework does not remove flag, recognized organization or national legal requirements.
  • Differences should be tied to a source, a ship, an owner and a verification date.
  • A verified register prevents local exceptions from fragmenting the fleet SMS.
Module 13

Personal liability and emerging trends

Module objectiveDistinguish company obligations, DPA functions and possible individual liability while integrating cyber and emerging risks correctly into the SMS.

The ISM Code places the duties of the system on the Company and defines the designated person's role within that organization. It does not, however, determine exhaustively the civil, criminal, administrative or contractual liability of an individual DPA: any personal exposure depends on the applicable law, the actual appointment, delegated authority, the facts and the person's conduct, and may require qualified legal advice. Meanwhile the role is evolving, driven by digitalisation and growing attention to human factors in safety culture.

Where responsibility sits

The ISM Code operates at Company level: §1.1.2 defines the Company as the owner or anyone else — manager, bareboat charterer — who has assumed responsibility for operating the ship and has agreed to take over all the duties and responsibilities imposed by the Code. The DPA is not an autonomous bearer of those obligations: they are the person through whom the Company exercises them.

That does not make the DPA's position irrelevant. After a serious event, what gets examined is the documentary chain: what was reported, to whom, when, on what evidence, and what followed. A DPA who requested resources in writing and recorded the answer is in a structurally different position from one who raised the same point verbally in a meeting. This is not defensive caution: decisions, reports, requests for resources and responses recorded accurately and traceably support monitoring, review and verification of SMS effectiveness. Section 12.6 specifically requires audit and review results to be brought to the attention of responsible personnel: it is not a general rule on the DPA's personal liability.

National requirements beyond the IMO minimum

Flags, recognized organizations and national legal systems may introduce additional requirements or procedures — residence, language, notification of the name, or prior approval of the designated person, for instance. For each ship the company should maintain a verified matrix of applicable sources, avoiding generic lists of possible requirements that are not tied to a specific Administration and reference date. It is the register discussed in Module 12.

Emerging trends

  • Continuous data: condition monitoring and digital reporting offer the DPA more timely signals than periodic audits alone.
  • Human factors: growing attention to fatigue, safety culture and communication (already seen in the Vetting course regarding PIFs) is also entering the DPA's daily practice.
  • Crew wellbeing: MLC inspections and attention to psychological wellbeing broaden the informational scope the DPA must monitor.

Cyber risk sits inside the SMS, and therefore inside the DPA's remit

This is the point most often treated as an IT topic rather than an ISM one. Resolution MSC.428(98) establishes that cyber risks must be managed within the safety management system, verified from the first annual verification of the Document of Compliance after 1 January 2021. The current IMO guidance is MSC-FAL.1/Circ.3/Rev.4.

The practical consequence is stark: a weakness in cyber risk management is not a matter for the IT department, it is a potential SMS non-conformity. The DPA verifies and monitors its integration in accordance with the documented responsibilities, while responsibility for developing, implementing and maintaining the system remains with the company. For ships contracted for construction from 1 July 2024, IACS unified requirements UR E26 and E27 apply on top; the Cyber Security course covers them.

DPA Focus — remaining a human safeguard in an increasingly digital system

The more abundant data becomes, the more the DPA's distinctive value shifts from collection to critical interpretation and direct human contact with crews and Masters. No dashboard replaces the ability to sense, in a conversation, that something is wrong.

Key takeaways

  • The ISM Code does not by itself determine the DPA's civil, criminal, administrative or contractual liability.
  • Accurate records support governance and verification, but section 12.6 concerns audit and review results.
  • Cyber risk should be integrated into the SMS; the current IMO guidance is MSC-FAL.1/Circ.3/Rev.4.

Recurring mistakes

From the Mistake Library of SuperbaKnowledge, filtered to the subjects this course covers. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.

Recurring mistakes published in SuperbaKnowledge
TopicMistakeTypical consequenceTopic sheet
Internal SMS AuditAn auditor verifying their own area of responsibilityLoss of independence, NC in external auditSee the topic sheet
Master's AuthorityThe Master's overriding authority documented in the SMS but not concretely upheld when it carries a commercial costErosion of the Master's trust in the systemSee the topic sheet
Corrective and Preventive Action (CAPA)Corrective action addressing the symptom, not the root causeThe NC recurs in similar formSee the topic sheet
Designated Person Ashore (DPA)DPA appointed only formally, without real access to top managementNC in certification audit, ineffective escalation system in an emergencySee the topic sheet
Document of Compliance (DOC) and Safety Management Certificate (SMC)DOC and SMC periodical verifications treated as if they had the same cadence, applying the SMC's intermediate window to the DOCThe Code does not say the certificate lapses by itself: §13.5 provides for withdrawal of the DOC when the annual verification is not requested, §13.9 for withdrawal of the SMC when the intermediate one is not. Both omissions are detainable deficiencies (A.1206(34), App. 2, §5 “Areas under the ISM Code”): item .8 “Evidence of the DOC annual verification is not available on board” and item .4 “The SMC intermediate verification is overdue”See the topic sheet
Crew FatigueRest hour logging treated as a mere documentary formality, without reflecting real fatigue management on boardFormal compliance that fails to prevent chronic fatigue build-up in the crewSee the topic sheet
Near MissPunitive culture towards those who reportThe reporting rate collapses and useful information is lostSee the topic sheet
Crew Familiarisation and TrainingFamiliarization treated as a formality to be signed off, without real knowledge transferCrew nominally 'familiarised' but unprepared in a real emergencySee the topic sheet
Autonomous Ships (MASS): the Company's Responsibility under the SMSMASS/remote operations introduced without a formal Management of Change in the SMSAbsence of a documented risk assessment specific to the new operating modelSee the topic sheet
Cyber Risk Management in the SMS (MSC.428(98))Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessmentLack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measuresSee the topic sheet

Related PSC deficiencies

From the PSC Knowledge Base of SuperbaKnowledge. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.

Related PSC deficiencies published in SuperbaKnowledge
DeficiencyRegulationIndicative frequencyPossible consequenceTopic sheet
Internal audit not conducted on one or more ships within 12 monthsISM Code, para. 12Medium-HighNC at external DOC/SMC renewal auditSee the topic sheet

Glossary of acronyms

Table 10 — Glossary of acronyms
AcronymDefinition
CAPACorrective and Preventive Action
CSOCompany Security Officer
DOCDocument of Compliance (ISM)
DPADesignated Person Ashore
ERTEmergency Response Team
ISMInternational Safety Management Code
STCWStandards of Training, Certification and Watchkeeping, 1978 as amended
MLCMaritime Labour Convention 2006
NCNon-conformity (ISM §1.1.9); major NC: §1.1.10
PSCPort State Control
RORecognized Organization
SMCSafety Management Certificate (ISM)
SMSSafety Management System
hazardous occurrenceHazardous situation reportable under §9 of the ISM Code

References and sources

Consolidated list of the sources cited. Updated as of August 2026; always consult the official text in force.

Table 11 — References and sources
SourceScope
IMO Resolution A.741(18), 4 November 1993Original text of the ISM Code
MSC.104(73), MSC.179(79), MSC.195(80), MSC.273(85), MSC.353(92)The five sets of amendments to the Code, in force from 2002, 2006, 2009, 2010 and 2015 respectively
MSC-MEPC.7/Circ.8Operational implementation of the ISM Code by Companies: the DPA's role (§4), SMS review (§5), handling of reports (§6)
MSC-MEPC.7/Circ.6Qualifications, training and experience necessary for the role of designated person; referenced in a footnote to §4 of the Code
MSC-MEPC.7/Circ.7IMO guidance on near-miss reporting: definition, barriers, investigation process
MSC/Circ.1059-MEPC/Circ.401Procedures concerning observed major non-conformities
SOLAS Chapter IXMandatory application of the ISM Code from 1 July 1998
IACS — unified requirements UR E26 and E27, applicable versionsCyber resilience of ships and onboard systems within their respective scope; ships contracted for construction on or after 1 July 2024
IMO resolution A.1188(33), 2023Guidelines on ISM Code implementation by Administrations; revokes A.1118(30)
Resolution MSC.428(98)Integration of maritime cyber risk management into the SMS
MSC-FAL.1/Circ.3/Rev.4Current guidelines on maritime cyber risk management, issued on 28 May 2026 following approval by FAL 50 and MSC 111
Paris MoU — current instructions on ISM and action-taken codesDeficiency 15150 and actions 19 and 21; always verify the current revision
Flag AdministrationsAny additional national requirements on the DPA role
Educational material

This course is educational material for training purposes and does not constitute a professional certification or qualifying credential. Read the full disclaimer.