The Designated Person Ashore within the Safety Management System
Module objectiveUnderstand the DPA's function within the ISM Code and distinguish the ship–shore link, direct access to senior management, monitoring and support.
The Designated Person Ashore arose from a lesson learned at great cost: the Herald of Free Enterprise ferry disaster (1987) showed how safety management left solely to shipboard initiative, without an effective link between those on board and senior management ashore, could fail systematically. The ISM Code, adopted through IMO Resolution A.741(18) of 4 November 1993, became mandatory on 1 July 1998 with the entry into force of SOLAS Chapter IX, and requires every company to designate one or more people for this role.
It is worth reading §4 in its entirety, because the part that is quoted least is precisely the part that defines the role.
«To ensure the safe operation of each ship and to provide a link between the Company and those on board, every Company, as appropriate, should designate a person or persons ashore having direct access to the highest level of management. The responsibility and authority of the designated person or persons should include monitoring the safety and pollution prevention aspects of the operation of each ship and ensuring that adequate resources and shore-based support are applied, as required.»ISM Code, §4 — Designated person(s)
The first purpose — to provide a link between the Company and those on board — is the one most often lost in summaries, and yet it is the one everything else follows from: the relationship with the master, the crew reporting channel, availability in an emergency. Monitoring comes after it, not before.
§4 creates a duty on the Company too, not only on the DPA. §3.3 says so explicitly: the Company is responsible for ensuring that adequate resources and shore-based support are provided to enable the designated person or persons to carry out their functions. A DPA without time, budget and authority is not a weak DPA: it is a non-conformity of the Company.
The text in force is not the 1993 one: five sets of amendments have changed it, and the last two bear directly on the DPA's daily work.
| Resolution | In force from | What it changes |
|---|---|---|
| MSC.104(73) — 2000 | 1 July 2002 | Introduces the definitions of objective evidence, observation, non-conformity, major non-conformity and anniversary date; rewrites certification (§13) and adds interim certification (§14) |
| MSC.179(79) — 2004 | 1 July 2006 | Amends the DOC and SMC forms, adding the completion date of the verification on which the certificate is based |
| MSC.195(80) — 2005 | 1 January 2009 | Adds the Company identification number to all four certificate forms, interim ones included |
| MSC.273(85) — 2008 | 1 July 2010 | Sets the maximum interval between internal audits at twelve months (§12.1); makes the two limbs of major non-conformity alternative; introduces assessment of all identified risks at §1.2.2.2 |
| MSC.353(92) — 2013 | 1 January 2015 | Introduces §12.2 on verifying those undertaking delegated ISM tasks; rewrites §6.2 on manning; adds to the title of §4 the footnote pointing to the IMO guidance on DPA qualifications |
Table 1.1 — The amendments to the ISM Code and their effects.
That last row deserves attention: since 1 January 2015 it is the Code itself, in a footnote to the title of §4, that points to MSC-MEPC.7/Circ.6 for the qualifications, training and experience of the designated person. It is no longer guidance found elsewhere: it is anchored to the text.
The DPA is deliberately a shore-based figure: their usefulness lies precisely in not being subject to the same operational, commercial and hierarchical pressures acting on the ship at any given moment. It is a structural counterweight, not a duplicate of the Master.
The Code allows one or more persons to be designated. The company should document their responsibilities, authority and coordination; large or heterogeneous fleets may use a principal DPA supported by alternates or other formally designated persons by geographical area or ship type (see Module 11).
Module objectiveAssess whether access, authority, resources and conflict controls make the role effective within the company's actual structure.
The defining feature of the role is not an abstract requirement for organizational independence, but the effective ability to reach the highest level of management directly and to report non-conformities and observations without other functions preventing or neutralizing the process. Reporting structures may vary between companies; what must be demonstrable is that the access, authority, responsibilities and resources defined in the SMS work in practice.

A widespread practice, especially at smaller companies, is to assign the DPA role to someone who already holds an operational position (for example the Fleet Manager). This is not prohibited by the Code, but it introduces a structural risk: the same person who is accountable for commercial deadlines and costs may find themselves having to decide, wearing the «DPA hat», against the immediate interest of those same deadlines.
How the role actually works is not measured in calm moments, but in those where the correct safety decision conflicts with an imminent commercial deadline. A DPA who has never halted or slowed an operation for safety reasons should check whether access, authority and resources really function, or whether the conflict controls set out in the SMS have stopped holding.
Module objectiveUse Circular 8 to translate the concise section 4 mandate into verifiable monitoring processes and resources.

§4 of the Code is deliberately brief. The operational list of what the DPA must verify and monitor sits not in the Code but in the IMO guidance the Code itself points to: MSC-MEPC.7/Circ.8, «Revised guidelines for the operational implementation of the ISM Code by Companies». At §4.2 it lists, as a minimum, six internal processes.
| # | Internal process | What it means in practice |
|---|---|---|
| 1 | Communication and implementation of the safety and environmental protection policy | Checking that the policy is known and acted on aboard, not posted on the bridge |
| 2 | Evaluation and review of the effectiveness of the SMS | Not whether the SMS exists, but whether it works: it feeds the management review |
| 3 | Reporting and analysis of non-conformities, accidents and hazardous occurrences | Safeguarding the quality of root-cause analysis, not just the event count |
| 4 | Organising and monitoring internal audits, including verification of the independence and training of the auditors | The most commonly overlooked duty: the DPA also answers for who conducts the audits and how they were trained |
| 5 | Appropriate revisions to the SMS | Closing the loop: if the analysis finds a weakness, the procedure changes |
| 6 | Ensuring the Company provides adequate resources and shore-based support | Reporting to top management when the resources are not there, with documented evidence |
Table 3.1 — The internal processes the DPA must verify and monitor (MSC-MEPC.7/Circ.8, §4.2).
The same guidance, at §4.3, lists what the Company must provide so that the DPA can perform the role. It is the list to use when negotiating your own mandate — or when contesting it.
The last point is the most important and the easiest to hollow out: it is not enough that the DPA can talk to top management — they must be able to put on record non-conformities and observations at that level.
The DPA does not certify that everything is in order: they monitor, verify, raise red flags and secure resources. Operational responsibility for safety remains with the Master and the chain of command; the DPA is the system safeguard that ensures that responsibility can actually be exercised.
Module objectiveVerify the documented suitability of every formally designated person against the criteria in Circular 6.
§4 of the Code says what the DPA must do, not who may do it. The gap is filled by dedicated IMO guidance, MSC-MEPC.7/Circ.6, which since 1 January 2015 is no longer a document to be found elsewhere: MSC.353(92) added to the title of §4 a footnote pointing explicitly to that circular. It is the benchmark a flag inspector, an external auditor or a charterer uses to judge whether the designated person is equal to the role.
The circular does not impose a single credential. It sets out three, alternative to one another: meeting any one of them is enough.
| Route | Requirement |
|---|---|
| Academic | A qualification from a tertiary institution recognised by the Administration or by the recognized organization, within a relevant field of management, engineering or physical science |
| Maritime professional | Qualification and certification as a ship officer under the STCW Convention 1978, as amended |
| Experience-based | Other formal education combined with not less than three years of practical senior-level experience in ship management operations |
Table 4.1 — The three alternative qualification routes (MSC-MEPC.7/Circ.6, §2.1).
The wording «other formal education combined with not less than three years practical senior level experience» is often read as though experience alone would do. It does not: both are needed, and the experience must be at senior level and in ship management operations — not generically in the maritime sector. This is the point on which a flag audit asks for documentary evidence.
§3.1 of the circular lists the areas the designated person's training must cover. It is the skeleton of a defensible training plan.
The second-to-last point is what separates real training from a certificate: the circular does not ask that you have studied auditing, but that you have taken part in at least one marine-related management system audit. That is a verifiable requirement, and it should be documented.
§4.1 moves from paper to demonstration: the designated person should be able to do six things.
Of the six, five are technical and come with practice. The first — presenting safety to top management and keeping their support over time — is political, and it decides whether the other five will amount to anything. A technically impeccable DPA who cannot secure resources is a DPA who accurately documents their own failure.
The Code allows one or more persons to be designated. Where several persons are formally designated, the company should be able to demonstrate the suitability of each person for the functions assigned: Circular 8, paragraph 4.4, applies the qualifications, training and experience in Circular 6 to the «Designated Person(s)». Complementary expertise may strengthen the team, but it does not replace the individual evidence required for anyone formally undertaking the role. Module 11 covers the organisational models that follow.
Circular 6 is IMO guidance referenced in a footnote to the Code. The reference strengthens its relevance during verification, but does not automatically turn every «should» statement into a prescriptive requirement equivalent to the mandatory text of the Code.
Module objectiveDefine a response arrangement that supports the master, activates shore resources and provides continuity without confusing company practice with the text of the Code.
During an emergency, the DPA may act as the principal link between the ship, senior management and shore-based support, in accordance with the responsibilities defined in the SMS. The Code does not prescribe a single activation chain or expressly require the DPA personally to be available 24/7; it requires the company to establish adequate procedures, resources and support. For many operations this entails a continuously monitored contact route, competent alternates and tested handovers.

Where the company's analysis requires 24/7 coverage, the SMS should identify who monitors the contact route, who acts in the DPA's absence, what information is handed over and how availability is tested — periodic call tests, for instance. It is a sound organizational control, and often a necessary one: it should not, however, be presented as wording contained in section 4 itself.
Module objectiveIntegrate operational sources and indicators to identify systemic signals without relying on a single data point or a formally green dashboard.
Outside of an emergency, the DPA's most important daily work is continuous monitoring: reading the signals the fleet produces before they become a serious problem.
| Source | What it reveals |
|---|---|
| Internal and external audits | The SMS's real adherence to shipboard practice |
| PSC and vetting outcomes | Patterns of deficiencies and observations by ship and by fleet |
| Near-miss and incident reports | Early risk signals before a serious event |
| Maintenance indicators (PMS) | Backlog and availability of critical spares |
| Direct crew reports | Problems the chain of command might filter or downplay |
Table 6.1 — Main information sources for DPA monitoring.
The DPA's value lies not in collecting data, but in knowing how to read it together: a ship with recurring vetting observations on human factors, a growing maintenance backlog and a low near-miss reporting rate together tell a more concerning story than any single data point does on its own.
An all-green dashboard can mean two opposite things: that the ship is genuinely doing well, or that no one is reporting problems. The experienced DPA always combines data with direct contact (visits on board, conversations with the crew) to tell the two situations apart.
Module objectiveDistinguish the ISM categories and verify that reporting, analysis, corrective action and recurrence prevention form an effective process.
The company must have procedures for reporting, investigating and analysing non-conformities, accidents and hazardous occurrences and for implementing corrective action. The DPA verifies and monitors the effectiveness of these processes and may participate in or coordinate them as defined by the SMS, but the Code does not make every investigation a personal, non-delegable duty of the DPA.
The Code devotes two very short paragraphs to this, and they contain everything.
«The SMS should include procedures ensuring that non-conformities, accidents and hazardous situations are reported to the Company, investigated and analysed, with the objective of improving safety and pollution prevention.»ISM Code, §9.1
«The Company should establish procedures for the implementation of corrective action, including measures intended to prevent recurrence.»ISM Code, §9.2, as amended by MSC.273(85)
The words added to §9.2 in 2010 — prevent recurrence — shift the centre of gravity: closing the case is not enough, you have to show you acted so it does not come back. That is precisely the difference between a correction and a corrective action, and it is the point a well-run audit presses on.

These four notions are not industry jargon: they are defined in the Code at §§1.1.7-1.1.10, introduced by MSC.104(73). Using them precisely is what separates a defensible audit report from a contestable one.
| Term | The Code's definition | Operational consequence |
|---|---|---|
| Objective evidence §1.1.7 | Quantitative or qualitative information, records or statements of fact pertaining to safety or to the existence and implementation of an SMS element, based on observation, measurement or test, and verifiable | Without objective evidence there is neither an observation nor a non-conformity: there is an opinion |
| Observation §1.1.8 | A statement of fact made during a safety management audit and substantiated by objective evidence | No formal corrective action required, but it must be recorded and considered in the management review |
| Non-conformity §1.1.9 | An observed situation where objective evidence indicates the non-fulfilment of a specified requirement | Requires root-cause analysis and corrective action with an owner and a deadline |
| Major non-conformity §1.1.10 | An identifiable deviation that poses a serious threat to the safety of personnel or the ship, or a serious risk to the environment, requiring immediate corrective action; or the lack of effective and systematic implementation of a requirement of the Code | Requires immediate corrective action and application of the procedures for major non-conformities; it may affect the validity of the DOC and SMC. In port State control, a serious failure or lack of effectiveness of ISM implementation may constitute grounds for detention |
Table 7.1 — The ISM Code definitions, §§1.1.7-1.1.10.
Until 2010 the definition of major non-conformity read «and includes»: both limbs had to be present. MSC.273(85), in force from 1 July 2010, replaced that with «or». Since then the lack of effective and systematic implementation of a requirement of the Code is, on its own, a major non-conformity, even without a serious and immediate threat. It is the legal basis of the whole logic of «systemic» ISM deficiencies.
The procedures for handling observed major non-conformities are in MSC/Circ.1059-MEPC/Circ.401, referenced in a footnote to §1.1.10 of the Code.
The DPA verifies that the root-cause analysis and corrective-action closure process is rigorous, but does not necessarily need to conduct it personally every time: their added value is ensuring the process is not «tamed» to quickly close an uncomfortable case.
Module objectiveBuild a DPA–master relationship that protects overriding authority, access to assistance and timely information flow.
One of the most delicate and most often misunderstood relationships in maritime organisation is that between the DPA and the master. The Code leaves no room for doubt: at §5.2 it requires the Company to include in the SMS a clear statement that the master has overriding authority and the responsibility to make decisions with respect to safety and pollution prevention, and to request the Company's assistance as may be necessary. The DPA does not command the ship.
That second half of the sentence is the hinge between the two roles, and it is quoted far less than the first. Overriding authority is not only the master's power to say «no» to an operation: it is also their right to ask for help — and therefore the Company's corresponding duty to answer that request. The SMS should define how that request is received and met: the DPA is often the central channel, but the duty to provide support remains with the company and the practical arrangement depends on the documented responsibilities. An SMS that asserts the master's authority but does not define how and to whom to request assistance has implemented half of §5.2.
The quality of the relationship between the DPA and the Master is built over time, through regular visits on board (not only when problems arise), honest communication even on sensitive matters, and a reputation for fairness in handling reports. A DPA seen only during moments of crisis is unlikely to receive timely reports during normal times.
If the first real contact between a new Master and the DPA happens during an incident, the trust needed for honest, timely communication starts at a disadvantage. Regular visits, scheduled even in the absence of problems, are the cheapest investment a DPA can make in the quality of the system.
Module objectiveGovern audits, reviews, certification and follow-up while maintaining auditor independence, correct deadlines and evidence of SMS effectiveness.
The DPA has a supervisory role, and sometimes a direct conducting role, over the audits that verify the SMS's adherence to actual practice: internal company audits, external class/flag audits (DOC/SMC verification), and checks prompted by vetting or PSC.
| Type of audit | Who conducts it | DPA's typical role |
|---|---|---|
| Internal company audit | Qualified internal auditors, independent of the audited area | Supervision, review of findings, guarantee of independence |
| External DOC/SMC verification | Classification society (RO) on behalf of the flag | Main interface, management of identified non-conformities |
| PSC inspections / vetting | Port authority / commercial inspector | Analysis of outcomes from a systemic, not just single-ship, perspective |
Table 9.1 — Types of audit relevant to the DPA.
Section 12 of the Code is the DPA's operational mandate on verification. Its current structure is worth knowing, because two of the seven paragraphs are more recent than many SMSs reflect.
| § | Obligation | What it means for the DPA |
|---|---|---|
| 12.1 | Internal safety audits on board and ashore, at intervals not exceeding twelve months; in exceptional circumstances the interval may be exceeded by not more than three months | This is the number to keep on the dashboard: the due date is per ship and per office, not fleet-wide |
| 12.2 | Periodic verification that all those undertaking delegated ISM-related tasks act in conformity with the Company's responsibilities under the Code | Third-party ship managers, crewing agencies, technical service providers: if an ISM task is delegated, the responsibility stays with the Company and the verification is the DPA's |
| 12.3 | Periodic evaluation of the effectiveness of the SMS, in accordance with Company procedures | This is the management review |
| 12.4 | Audits and any corrective actions carried out in accordance with documented procedures | The audit programme is itself an SMS procedure |
| 12.5 | Personnel carrying out audits must be independent of the areas audited, unless this is impracticable due to the size and nature of the Company | No one verifies their own work: a superintendent does not audit the ship they manage |
| 12.6 | Audit and review results are brought to the attention of all personnel responsible for the area involved | An outcome that stays in a folder does not satisfy §12.6 |
| 12.7 | The management personnel responsible for the area take timely corrective action on the deficiencies found | Closure is the line's responsibility, not the DPA's: the DPA verifies that it happens |
Table 9.2 — Section 12 of the ISM Code in its current numbering.
The twelve-month maximum interval in §12.1 was not in the 1993 text: it came in with MSC.273(85) and has been in force since 1 July 2010. §12.2 on verifying delegated ISM tasks is more recent still — MSC.353(92), in force from 1 January 2015 — and it renumbered the paragraphs that follow. An SMS that still cites «§12.2 — evaluation of effectiveness» is using pre-2015 numbering.
§12.3 requires the review but does not define its content. MSC-MEPC.7/Circ.8 does, at §5.2, listing what the review must take into account as a minimum: the results of internal audits; non-conformities reported by personnel; the master's reviews; the analysis of non-conformities, accidents and hazardous occurrences; and any other evidence of possible SMS failure, including non-conformities raised by external parties and PSC inspection reports.
The same guidance adds that the review should be performed periodically as defined by the Company or when needed — for example in case of serious system failures — and that its results should be brought formally to the attention of all personnel involved.
The DPA is the main interface for certification verifications, and therefore the keeper of a calendar that tolerates no slippage. The rules are in §§13 and 14 of the Code, in the version introduced by MSC.104(73).
| Document | Validity | Verifications |
|---|---|---|
| Document of Compliance (company) | up to 5 years | annual verification within three months before or after the anniversary date |
| Safety Management Certificate (ship) | up to 5 years | at least one intermediate verification between the second and third anniversary |
| Interim DOC | up to 12 months | for newly established companies, or companies adding a new ship type |
| Interim SMC | up to 6 months, extendable by a further 6 | for a newly delivered ship, a change of company or a change of flag |
Table 9.3 — Validity and verification of ISM certificates (§§13-14).
For verification and certification by Administrations the current reference is resolution A.1188(33), adopted in 2023, which revoked A.1118(30). Circular 8 remains the operational guidance addressed to companies; the two instruments have different audiences and functions.
Two details that are often missed: a copy of the DOC must be on board, so the master can produce it on request (§13.3); and if the renewal verification is completed after the existing certificate has expired, the new certificate runs from the date of completion to no more than five years from the expiry of the previous one — not from the date of issue.
An ISM deficiency raised by a Port State Control inspector does not stay with the ship: it travels up to the company, and the DPA is its operational addressee. Under the Paris MoU regime, ISM deficiencies carry a single defective item code, 15150, with two possible outcomes.
This is the difference that counts, and it is missed with regularity: a broken light is rectified on board, a 15150 deficiency is closed ashore. The three-month deadline is not an administrative reminder but an automatic trigger that puts the ship back in the targeting system's sights — and complying with it is, in practice, the DPA's job. The Port State Control course covers the mechanism from the inspection side.
The §12.5 principle has a stated limit: independence is required unless this is impracticable due to the size and nature of the Company. That is a real allowance for small operations, but it is not an exemption: where an auditor who is not fully independent has to be used, the choice should be reasoned and compensated — for instance by having a second person review the findings, or by rotating auditors between ships. The DPA safeguards this balance at the level of the whole company's audit programme and — as Circ.8 §4.2 notes — also answers for the training of internal auditors, not only for their independence. In short: the DPA organizes and monitors the audit programme and verifies auditor independence and training, and may personally conduct an audit only where independence from the audited area is maintained, in accordance with section 12.5 and the company's procedures.
An internal audit programme that never finds anything to improve is not a sign of excellence: it is almost always a sign that the audit is not conducted with sufficient rigour. A DPA reviewing audit outcomes should be more concerned by a repeated «all in order» report than by one with a few honestly reported issues.
Module objectiveDesign a near-miss reporting system consistent with Circular 7 that supports learning without making indiscriminate promises of immunity.
The success of the DPA role depends largely on the reporting culture they manage to build within the company: a system in which minor near-misses remain hidden deprives the DPA of precisely the most valuable signals for preventing serious events.
The idea that serious events rest on a broad base of minor events and at-risk behaviours goes back to the studies of Heinrich (1931, a 300:29:1 ratio) and Bird (1969, 600:30:10:1). The numerical ratios are contested in more recent literature and should not be used as a prediction: the value of the pyramid is to illustrate a principle — the base is the only part you can act on before anything happens — not to provide a quantitative model.

Investigating near-misses is not a voluntary good practice: it is an obligation flowing from the «hazardous occurrences» part of §9 of the Code. The IMO devoted specific guidance to it, MSC-MEPC.7/Circ.7, which also gives the operational definition.
«A sequence of events and/or conditions that could have resulted in loss. This loss was prevented only by a fortuitous break in the chain of events and/or conditions. The potential loss could be human injury, environmental damage, or negative business impact — repair or replacement costs, scheduling delays, contract violations, loss of reputation.»MSC-MEPC.7/Circ.7, Annex §2.1
Two elements of this definition are regularly lost in shipboard practice. The first is that the loss must have been prevented by a break in the chain of events or conditions: the same guidance, however, includes among its examples an event in which an emergency procedure, plan or response is activated and prevents the loss. An occurrence should therefore not be excluded automatically merely because a planned barrier worked — the sequence, loss potential and the classification established in the SMS should be assessed and applied consistently over time. The second is business impact: an event that came nowhere near a person but could have cost a detention or a contractual penalty falls squarely within the definition, and must be reported.
The circular gives three example categories, useful for calibrating crew training: an event that triggers an emergency procedure and thereby prevents the loss; an event where an unexpected condition could have led to an adverse consequence that did not occur; and a hazardous situation discovered only after the danger has passed — for instance a ship that, hours into the voyage, finds its radio was not tuned to the Harbour Master's frequency.
The same guidance is explicit about why near-misses go unreported: fear of being blamed, disciplined, embarrassed or found legally liable. To those it adds barriers that come directly from management: complacency about known deficiencies, insincerity in addressing safety issues, and the implicit discouragement created by expecting seafarers to conduct investigations in their own time.
Circ.7 defines a just culture as «an atmosphere of responsible behaviour and trust whereby people are encouraged to provide essential safety-related information without fear of retribution», but immediately adds the distinction between acceptable and unacceptable behaviour: the latter does not necessarily carry a guarantee against consequences. And above all — §1.4 — it is a crucial requirement that the company clearly defines the circumstances in which it will guarantee a non-punitive outcome and confidentiality, and that it trains everyone involved on that approach. A policy that vaguely promises «no punishment» without stating its boundaries does not survive the first uncomfortable report.
Circ.7 sets five questions as the minimum content of any report.
The answers to the last two decide the depth of the work: a full investigation is required for near-misses likely to recur and/or which could have had severe consequences. For the rest a cursory report suffices. It is a simple, defensible criterion, and it belongs in the SMS: without it, the risk is investigating everything badly rather than a few things well.
Once the investigation is complete, the circular asks for two things: a report proportionate to the depth of the analysis, and storing the information in a way that supports long-term trend analysis. That is the point at which the DPA's work stops being reactive and becomes monitoring.
If the number of reported near-misses suddenly drops, the first hypothesis to check is not that the ship has become safer, but that something in the reporting culture has deteriorated: a change of Master, a perceived retaliation incident, a workload that discourages reporting.
Module objectiveConfigure and test a continuity model suited to the company's size, fleet, risks and documented responsibilities.
The DPA role cannot have gaps in coverage: illness, leave, or simply the volume of a large fleet make a continuity structure necessary, typically through one or more Deputy DPAs.
The Deputy DPA is not a role defined in the Code: §4 speaks of «a person or persons» designated and leaves the choice of model to the company, according to its size, the composition of its fleet and the risks that follow. It follows that the arrangement should be made explicit in the SMS — who stands in for whom, with what responsibilities and what authority, with what competence and with what handover — and that, where several persons are formally designated, the suitability of each for the functions assigned should be demonstrable against the Circular 6 criteria (Module 04).
| Model | When it is used |
|---|---|
| Single DPA with backup Deputy | Small/medium homogeneous fleets |
| Principal DPA + Deputy by geographical area | Fleets operating under multiple flags/regions with different regulatory needs |
| Principal DPA + Deputy by ship type | Heterogeneous fleets (e.g. tankers and dry bulk) with differentiated technical expertise |
Table 11.1 — Organisational models for DPA role continuity.
A continuity plan that exists only on paper risks failing precisely when it is needed. Periodic tests of availability and handover (for example simulating the principal DPA's absence during an emergency drill) verify that the system actually works, not just that it is documented.
Module objectiveGovern additional requirements and different interfaces while maintaining a coherent SMS, dated sources and clear responsibilities.
Companies managing ships under different flags, with different classes, face additional complexity: national requirements adding to the common IMO framework, and different class contacts for each ship.
The most structured companies keep an updated register of the specific requirements for each flag managed, assign area expertise to Deputy DPAs, and maintain an ongoing dialogue with local representatives of classification societies to anticipate procedural differences. For the register to be verifiable, each entry should carry the applicable source, the ships it applies to, the person responsible and the date of the last check: a generic list of possible requirements, not tied to a specific Administration and a date, does not survive an audit.
A single, coherent Safety Management System for the whole fleet remains the right objective, but the DPA must know and manage national exceptions without letting them fragment the company's shared safety culture.
Module objectiveDistinguish company obligations, DPA functions and possible individual liability while integrating cyber and emerging risks correctly into the SMS.
The ISM Code places the duties of the system on the Company and defines the designated person's role within that organization. It does not, however, determine exhaustively the civil, criminal, administrative or contractual liability of an individual DPA: any personal exposure depends on the applicable law, the actual appointment, delegated authority, the facts and the person's conduct, and may require qualified legal advice. Meanwhile the role is evolving, driven by digitalisation and growing attention to human factors in safety culture.
The ISM Code operates at Company level: §1.1.2 defines the Company as the owner or anyone else — manager, bareboat charterer — who has assumed responsibility for operating the ship and has agreed to take over all the duties and responsibilities imposed by the Code. The DPA is not an autonomous bearer of those obligations: they are the person through whom the Company exercises them.
That does not make the DPA's position irrelevant. After a serious event, what gets examined is the documentary chain: what was reported, to whom, when, on what evidence, and what followed. A DPA who requested resources in writing and recorded the answer is in a structurally different position from one who raised the same point verbally in a meeting. This is not defensive caution: decisions, reports, requests for resources and responses recorded accurately and traceably support monitoring, review and verification of SMS effectiveness. Section 12.6 specifically requires audit and review results to be brought to the attention of responsible personnel: it is not a general rule on the DPA's personal liability.
Flags, recognized organizations and national legal systems may introduce additional requirements or procedures — residence, language, notification of the name, or prior approval of the designated person, for instance. For each ship the company should maintain a verified matrix of applicable sources, avoiding generic lists of possible requirements that are not tied to a specific Administration and reference date. It is the register discussed in Module 12.
This is the point most often treated as an IT topic rather than an ISM one. Resolution MSC.428(98) establishes that cyber risks must be managed within the safety management system, verified from the first annual verification of the Document of Compliance after 1 January 2021. The current IMO guidance is MSC-FAL.1/Circ.3/Rev.4.
The practical consequence is stark: a weakness in cyber risk management is not a matter for the IT department, it is a potential SMS non-conformity. The DPA verifies and monitors its integration in accordance with the documented responsibilities, while responsibility for developing, implementing and maintaining the system remains with the company. For ships contracted for construction from 1 July 2024, IACS unified requirements UR E26 and E27 apply on top; the Cyber Security course covers them.
The more abundant data becomes, the more the DPA's distinctive value shifts from collection to critical interpretation and direct human contact with crews and Masters. No dashboard replaces the ability to sense, in a conversation, that something is wrong.
From the Mistake Library of SuperbaKnowledge, filtered to the subjects this course covers. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.
| Topic | Mistake | Typical consequence | Topic sheet |
|---|---|---|---|
| Internal SMS Audit | An auditor verifying their own area of responsibility | Loss of independence, NC in external audit | See the topic sheet |
| Master's Authority | The Master's overriding authority documented in the SMS but not concretely upheld when it carries a commercial cost | Erosion of the Master's trust in the system | See the topic sheet |
| Corrective and Preventive Action (CAPA) | Corrective action addressing the symptom, not the root cause | The NC recurs in similar form | See the topic sheet |
| Designated Person Ashore (DPA) | DPA appointed only formally, without real access to top management | NC in certification audit, ineffective escalation system in an emergency | See the topic sheet |
| Document of Compliance (DOC) and Safety Management Certificate (SMC) | DOC and SMC periodical verifications treated as if they had the same cadence, applying the SMC's intermediate window to the DOC | The Code does not say the certificate lapses by itself: §13.5 provides for withdrawal of the DOC when the annual verification is not requested, §13.9 for withdrawal of the SMC when the intermediate one is not. Both omissions are detainable deficiencies (A.1206(34), App. 2, §5 “Areas under the ISM Code”): item .8 “Evidence of the DOC annual verification is not available on board” and item .4 “The SMC intermediate verification is overdue” | See the topic sheet |
| Crew Fatigue | Rest hour logging treated as a mere documentary formality, without reflecting real fatigue management on board | Formal compliance that fails to prevent chronic fatigue build-up in the crew | See the topic sheet |
| Near Miss | Punitive culture towards those who report | The reporting rate collapses and useful information is lost | See the topic sheet |
| Crew Familiarisation and Training | Familiarization treated as a formality to be signed off, without real knowledge transfer | Crew nominally 'familiarised' but unprepared in a real emergency | See the topic sheet |
| Autonomous Ships (MASS): the Company's Responsibility under the SMS | MASS/remote operations introduced without a formal Management of Change in the SMS | Absence of a documented risk assessment specific to the new operating model | See the topic sheet |
| Cyber Risk Management in the SMS (MSC.428(98)) | Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessment | Lack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measures | See the topic sheet |
From the PSC Knowledge Base of SuperbaKnowledge. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.
| Deficiency | Regulation | Indicative frequency | Possible consequence | Topic sheet |
|---|---|---|---|---|
| Internal audit not conducted on one or more ships within 12 months | ISM Code, para. 12 | Medium-High | NC at external DOC/SMC renewal audit | See the topic sheet |
| Acronym | Definition |
|---|---|
| CAPA | Corrective and Preventive Action |
| CSO | Company Security Officer |
| DOC | Document of Compliance (ISM) |
| DPA | Designated Person Ashore |
| ERT | Emergency Response Team |
| ISM | International Safety Management Code |
| STCW | Standards of Training, Certification and Watchkeeping, 1978 as amended |
| MLC | Maritime Labour Convention 2006 |
| NC | Non-conformity (ISM §1.1.9); major NC: §1.1.10 |
| PSC | Port State Control |
| RO | Recognized Organization |
| SMC | Safety Management Certificate (ISM) |
| SMS | Safety Management System |
| hazardous occurrence | Hazardous situation reportable under §9 of the ISM Code |
Consolidated list of the sources cited. Updated as of August 2026; always consult the official text in force.
| Source | Scope |
|---|---|
| IMO Resolution A.741(18), 4 November 1993 | Original text of the ISM Code |
| MSC.104(73), MSC.179(79), MSC.195(80), MSC.273(85), MSC.353(92) | The five sets of amendments to the Code, in force from 2002, 2006, 2009, 2010 and 2015 respectively |
| MSC-MEPC.7/Circ.8 | Operational implementation of the ISM Code by Companies: the DPA's role (§4), SMS review (§5), handling of reports (§6) |
| MSC-MEPC.7/Circ.6 | Qualifications, training and experience necessary for the role of designated person; referenced in a footnote to §4 of the Code |
| MSC-MEPC.7/Circ.7 | IMO guidance on near-miss reporting: definition, barriers, investigation process |
| MSC/Circ.1059-MEPC/Circ.401 | Procedures concerning observed major non-conformities |
| SOLAS Chapter IX | Mandatory application of the ISM Code from 1 July 1998 |
| IACS — unified requirements UR E26 and E27, applicable versions | Cyber resilience of ships and onboard systems within their respective scope; ships contracted for construction on or after 1 July 2024 |
| IMO resolution A.1188(33), 2023 | Guidelines on ISM Code implementation by Administrations; revokes A.1118(30) |
| Resolution MSC.428(98) | Integration of maritime cyber risk management into the SMS |
| MSC-FAL.1/Circ.3/Rev.4 | Current guidelines on maritime cyber risk management, issued on 28 May 2026 following approval by FAL 50 and MSC 111 |
| Paris MoU — current instructions on ISM and action-taken codes | Deficiency 15150 and actions 19 and 21; always verify the current revision |
| Flag Administrations | Any additional national requirements on the DPA role |
This course is educational material for training purposes and does not constitute a professional certification or qualifying credential. Read the full disclaimer.