SuperbaLearning Demonstration release

Platforms
ENIT
Compliance and management systems · Open learning path Regulatory path

ISM Code

The Safety Management System and safety leadership

12learning modules
AdvancedLevel
SBL-ISM-ADV-01Code
August 2026Reference date

Learning objectives

  • Describe the historical genesis and functional elements of the ISM Code.
  • Distinguish DOC and SMC and manage their respective certification cycles.
  • Correctly classify minor non-conformities, major non-conformities and observations.
  • Conduct or supervise an internal audit with method and independence.
  • Manage a structured Management of Change process.
  • Contribute to a continuous improvement cycle of the SMS based on the PDCA model.
Module 01

Genesis and purpose of the ISM Code

Module objectiveRecognise what the ISM Code arose from, how it became mandatory and which company takes on its duties.

The International Safety Management Code arose from a series of maritime disasters that revealed how technical compliance with international conventions alone was not sufficient to guarantee real operational safety, in the absence of a structured management system that explicitly made the company, not just the ship, responsible.

The regulatory path

Adopted through IMO Resolution A.741(18) of 4 November 1993, the Code was made mandatory through SOLAS Chapter IX, which at regulation 3 provides that «the requirements of the Code shall be treated as mandatory» and that the ship shall be operated by a company holding a Document of Compliance. Application came in three stages, and the distinction matters more than it looks.

Table 1 — The regulatory path
CategoryThresholdNot later than
Passenger ships, including passenger high-speed craftno tonnage threshold1 July 1998
Oil tankers, chemical tankers, gas carriers, bulk carriers and cargo high-speed craft500 GT and over1 July 1998
Other cargo ships and mobile offshore drilling units (MODUs)500 GT and over1 July 2002

Table 1.1 — Application of the ISM Code (SOLAS regulation IX/2.1).

Two points that summaries tend to lose. First: there is no tonnage threshold for passenger ships — the 500 GT applies to the other two stages, not to them. Second: the chapter does not apply to government-operated ships used for non-commercial purposes (regulation IX/2.2).

Who the «Company» is

The Code does not address the owner generically. §1.1.2 — reproduced word for word in SOLAS regulation IX/1.2 — defines the Company as the owner of the ship or any other organization or person, such as the manager or the bareboat charterer, who has assumed responsibility for operating the ship from the owner and who, on assuming that responsibility, has agreed to take over all the duties and responsibilities imposed by the Code.

That last clause is the important one: ISM responsibility does not transfer merely by operating the ship, but by an explicit assumption. It is why the DOC names one specific company, and why a change of management is a certification event, not only a contractual one.

Key point

The central innovation of the ISM Code is not technical but organisational: for the first time an international instrument explicitly places on the company, and not only on the ship, responsibility for a documented, verifiable safety management system subject to continuous improvement.

The text in force is not the 1993 one

Five sets of amendments have changed the Code. Two of them alter rules used every week.

Table 2 — The text in force is not the 1993 one
ResolutionIn force fromWhat it changes
MSC.104(73) — 20001 July 2002Introduces the definitions of objective evidence, observation, non-conformity, major non-conformity and anniversary date; rewrites certification (§13) and adds interim certification (§14)
MSC.179(79) — 20041 July 2006Adds to the DOC and SMC forms the completion date of the verification on which the certificate is based
MSC.195(80) — 20051 January 2009Adds the Company identification number to the four certificate forms
MSC.273(85) — 20081 July 2010Sets the maximum interval between internal audits at twelve months (§12.1); makes the two limbs of major non-conformity alternative; replaces §1.2.2.2 with the duty to assess all identified risks; adds measures to prevent recurrence to §9.2
MSC.353(92) — 20131 January 2015Introduces §12.2 on verifying those undertaking delegated ISM tasks, renumbering what follows; rewrites §6.2 on manning; adds footnotes to the titles of §§3 and 4 pointing to MSC-MEPC.7/Circ.8 and Circ.6

Table 1.2 — The amendments to the ISM Code and their effects.

Key takeaways

  • The Code was made mandatory through SOLAS Chapter IX, and its application came in three stages.
  • ISM responsibility does not pass to whoever operates the ship without an explicit assumption of the Code's duties.
  • The text in force is not the 1993 one: five sets of amendments have changed the Code.
Module 02

The structure of the Code

The Code is in two parts. Part A — Implementation (§§1-12) defines what the company must build and keep working; Part B — Certification and verification (§§13-16) defines how all of that is certified and verified from outside. Module 04 covers Part B; this module covers Part A.

The six functional requirements of §1.4

Before the operational sections, the Code sets out at §1.4 the six functional requirements every SMS must contain. It is the shortest and most useful list in the Code: if one of these six is missing, there is no SMS.

  • A safety and environmental protection policy.
  • Instructions and procedures to ensure safe operation of ships and protection of the environment in compliance with relevant international and flag State legislation.
  • Defined levels of authority and lines of communication between, and amongst, shore and shipboard personnel.
  • Procedures for reporting accidents and non-conformities with the provisions of the Code.
  • Procedures to prepare for and respond to emergency situations.
  • Procedures for internal audits and management reviews.

The sections of Part A

Table 3 — The sections of Part A
§ElementEssential content
1General provisions, objectives, definitionsScope and purpose of the Code
2Safety and environmental policyCompany's stated commitment, to be made concrete in practice
3Company responsibility and authorityOrganisation chart, delegations, resources
4Designated Person (DPA)Direct access to top management, independent monitoring (dedicated course)
5Master's responsibility and authorityThe master's overriding authority over safety and pollution prevention, and the right to request the Company's assistance (§5.2)
6Resources and personnelManning, familiarisation, competence
7Shipboard operationsProcedures for critical operations
8Emergency preparednessScenarios, drills, exercises
9Non-conformities, incidents, near-missesReporting, analysis, corrective actions (modules 6-7)
10Maintenance of ship and equipmentCritical equipment, PMS (see also the Reliability Management course)
11DocumentationDocument and record control
12Company verification, review and evaluationInternal audits every 12 months, verification of delegated tasks, management review

Table 2.1 — The sections of Part A of the ISM Code (implementation).

And the four sections of Part B

Table 4 — And the four sections of Part B
§SectionEssential content
13Certification and periodical verificationDOC and SMC: who issues them, validity, annual and intermediate verifications, renewal (Module 04)
14Interim certificationInterim DOC for new companies or those adding a ship type; interim SMC for new deliveries, a change of company or a change of flag
15VerificationAll verifications follow the procedures established by the Administration, taking IMO guidelines into account
16Forms of certificatesThe four forms — DOC, SMC and their interim versions — are annexed to the Code

Table 2.2 — The sections of Part B of the ISM Code (certification and verification).

Why the split into two parts matters

Part A is what the company must do; Part B is what someone else verifies. Conflating them leads to the most common error in SMS management: building the system around the certification audit rather than around the operation, and ending up with a manual that passes verification but does not describe how the work is actually done.

Module 03

The PDCA cycle of the SMS

The Safety Management System is not a static document, but a system that the ISM Code wants to be in continuous improvement, following a logic comparable to the classic Plan-Do-Check-Act (PDCA) cycle of quality management systems.

PDCA as a reading key for the SMS, with the ISM Code paragraphs that make each phase mandatory.
PDCA as a reading key for the SMS, with the ISM Code paragraphs that make each phase mandatory.
Table 5 — The PDCA cycle of the SMS
PhaseWhat it involves in the SMSWhere the Code says so
PlanSafety and environmental protection policy, assessment of all identified risks, procedures and instructions for operations§2 · §1.2.2.2 · §7
DoDay-to-day implementation on board and ashore, with adequate resources and personnel and emergency preparedness§6 · §8 · §10
CheckReporting and analysis of non-conformities, accidents and hazardous situations; internal audits every twelve months; verification of delegated tasks§9.1 · §12.1 · §12.2
ActCorrective actions including measures to prevent recurrence; management review of effectiveness; revision of procedures§9.2 · §12.3 · §12.7

Table 3.1 — The PDCA cycle and the paragraphs of the Code that make it mandatory.

PDCA is a useful analogy, not the text of the Code

The Code never names the Plan-Do-Check-Act cycle: it is a model borrowed from quality management systems, and it works well as a mental frame. But when writing a procedure, or answering an auditor, the reference to cite is the paragraph — not the phase. The practical difference is that the phases are four and symmetrical, whereas the Code's text is not: «plan» is stated in general terms, while «check» and «act» carry the only numeric deadlines in the cycle — the twelve months between internal audits in §12.1, the three-month exceptional extension, and the three months within which corrective actions and follow-up audits should normally be closed.

SMS Focus — an SMS that never changes is a warning sign

A Safety Management System whose procedures remain identical for years, with no changes generated by audits, incidents or operational changes, does not reflect a perfect system: more likely it reflects a PDCA cycle that has stalled, with the risk that the documentation no longer reflects real practice.

Module 04

DOC and SMC: the certification structure

Module objectiveDistinguish the DOC from the SMC, recognise the five types of verification, and keep certificate expiry dates under control.

The Document of Compliance (DOC) certifies the company's management system for the ship types it manages; the Safety Management Certificate (SMC) certifies that the individual ship operates in compliance with an approved and verified SMS. These are two distinct certificates, with parallel verification cycles.

Certification structure of the ISM Code: one DOC per company, valid for the ship types listed, and one SMC for each ship managed (§§13.1-13.7).
Certification structure of the ISM Code: one DOC per company, valid for the ship types listed, and one SMC for each ship managed (§§13.1-13.7).
DOC and SMC verifications: interim, initial, annual and intermediate, renewal, plus the additional verification.
DOC and SMC verifications: interim, initial, annual and intermediate, renewal, plus the additional verification (ISM Code §§13-14; A.1188(33) §4.1.1).
Table 6 — DOC and SMC: the certification structure
CertificateSubjectValidityVerifications
DOCCompany management system, for the ship types listed on the certificateup to 5 yearsannual verification within three months before or after the anniversary date
SMCSMS of the individual shipup to 5 yearsat least one intermediate verification between the second and third anniversary of issue
Interim DOCNewly established company, or one adding a ship type not covered by the existing DOCup to 12 monthsassessment at the company offices, §14.1
Interim SMCNewly delivered ship, change of company or change of flagup to 6 months; in special cases the Administration may extend it by no more than a further 6 (§§14.2-14.3)verification that the ship is provided with an SMS, §14.4
Copy of the DOC on boardEvidence that the company holds a valid DOC for that ship typemust be producible on request; the copy need not be authenticated or certified (§13.6)

Table 4.1 — Validity and verification of ISM certificates (§§13-14).

The DOC covers the ship types it lists

This is the detail that produces most surprises during an acquisition: the DOC does not certify the company in the abstract, but its ability to manage those ship types. Adding a type not listed requires an additional verification and, meanwhile, an interim DOC. And in the other direction: during the annual verification the Administration checks whether the company is still operating all the listed types, and acts accordingly if one has been dropped.

Renewal verification: three distinct scenarios

Renewal planning requires three scenarios to be distinguished. If verification is completed within the three months before expiry, the new DOC or SMC runs from completion for a period not exceeding five years from the expiry date of the existing document or certificate (§13.10). If completed more than three months before expiry, the new DOC or SMC runs from completion for no more than five years (§13.11). If renewal verification of an SMC is completed after expiry, §13.12 allows the new SMC to run from completion to a date not exceeding five years from the previous expiry date. This does not authorise operation during a gap without a valid SMC and is not a parallel rule for the DOC.

Five types of verification, not two

The Code sets the rules; how certification actually happens is described in the IMO guidelines for Administrations — today Resolution A.1188(33), adopted on 6 December 2023, which revoked the earlier A.1118(30). At §4.1.1 the process breaks down into five verifications.

Table 7 — Five types of verification, not two
VerificationWhenWhat it involves
InterimNew company, new ship type, newly delivered or transferred shipAssessment of the offices and verification that the ship is provided with an SMS; allows operation while the system beds in
InitialAt first full certificationAssessment of the offices — including sites performing delegated SMS tasks — and then of the ships
Annual (DOC) or intermediate (SMC)During the period of validityAddresses all SMS elements, not a sample; verifies that the system is functioning effectively and that any modifications comply
RenewalBefore expiryAddresses all SMS elements; may be carried out in the preceding three months, to be completed before expiry
AdditionalWhere there are clear groundsScope and depth decided case by case by the Administration

Table 4.2 — The certification process (A.1188(33), §4.1.1).

The three-month rule: when certification can be requested

This is the practical question that most often goes unanswered. §4.3.6 of A.1188(33) settles it: initial verification requires objective evidence that the SMS has been in operation for at least three months ashore, and for at least three months on board at least one ship of each type operated by the company. The evidence expressly includes records from the internal audit already performed by the company.

In management terms: you cannot certify an SMS that has just been written. It takes three months of real operation, with records, and at least one completed round of internal audit. Anyone planning a certification has to count backwards from that threshold, not from the date the manual is ready.

Additional verification: when the audit comes from outside

§4.7.1 is the provision that connects ISM to the rest of the world. The Administration may require an additional verification, where there are clear grounds, to check whether the SMS still functions effectively. The guidelines cite three typical situations, and the first is the one that matters most in daily management.

  • Following a detention in a Port State Control inspection.
  • On reactivation after an interruption of operations due to a period out of service.
  • To verify that corrective actions have been taken and are being properly implemented.

An additional verification may affect the shore organisation, the shipboard one, or both; the Administration determines the scope and depth case by case. This is why a PSC detention does not end when the ship sails: it can trigger a verification of the whole company. The Port State Control course covers the same mechanism from the inspection side, with action codes 19 and 21.

A withdrawn DOC or an invalid SMC prevents compliant operation

MSC/Circ.1059–MEPC/Circ.401 requires that a ship not operate where the company’s DOC or the ship’s SMC has been withdrawn, until it is reissued. This is not merely a commercial-acceptance issue.

Key takeaways

  • The DOC covers the ship types it lists: adding one not listed requires an additional verification and an interim DOC.
  • Renewal must be completed before expiry: if it slips, §13.12 shortens the validity of the new certificate.
  • Where there are clear grounds the Administration may require an additional verification, including after a PSC detention.
Module 05

The safety policy: from document to practice

Module objectiveRecognise the safety policy as the instrument for achieving the §1.2 objectives, and the conditions that make it real on board and ashore.

§2.1 of the Code requires the company to establish a safety and environmental protection policy which describes how the objectives given in §1.2 will be achieved. The wording is precise: the policy is not a free-standing statement of intent, it is the instrument for achieving objectives the Code has already written. They are worth reading.

The objectives the policy has to achieve

§1.2.1 sets the objectives of the Code: to ensure safety at sea, prevention of human injury or loss of life, and avoidance of damage to the environment — in particular the marine environment — and to property.

§1.2.2 translates those into three safety management objectives for the company.

  • Provide for safe practices in ship operation and a safe working environment.
  • Assess all identified risks to its ships, personnel and the environment, and establish appropriate safeguards.
  • Continuously improve safety management skills of personnel ashore and aboard ships, including preparing for emergencies related both to safety and to environmental protection.
The second objective changed in 2010, and it is not a detail

The original 1993 text said only «establish safeguards against all identified risks». MSC.273(85), in force from 1 July 2010, replaced it with «assess all identified risks to its ships, personnel and the environment and establish appropriate safeguards». Adding the verb assess introduced into the Code a duty of risk assessment that had not previously been explicit. It is the legal basis of everything now done on risk analysis inside an SMS — including the Management of Change of Module 08.

§1.2.3 completes the picture: the SMS must ensure compliance with mandatory rules and regulations, and that codes, guidelines and standards recommended by the IMO, Administrations, classification societies and industry organisations are taken into account. It is the only point where the Code explicitly opens to non-binding sources — and the reason an auditor may ask how an industry recommendation has been considered, even though it is not mandatory.

The most common risk

That the policy remains a formal document, little known and little lived on board. §2.2 anticipates the problem by requiring the company to ensure the policy is implemented and maintained at all levels of the organisation, both ship-based and shore-based.

How to make the policy real

  • Active and repeated communication, not a single posting at the entrance to the bridge.
  • Consistency between stated objectives and daily operational decisions, including those made under commercial pressure.
  • Involvement of the crew in periodic review of the policy, not just its passive reception.
SMS Focus — a policy is judged by the exceptions, not the rule

A safety policy proves itself true or false not in ordinary moments, but in those where complying with it comes at an immediate cost (a delay, an unplanned expense). An organisation that follows its own policy only when it costs nothing does not, in fact, have a real safety policy.

Key takeaways

  • Since 2010 MSC.273(85) requires assessing all identified risks, not only establishing safeguards against them.
  • §1.2.3 opens the Code to non-binding sources: an auditor may ask how an industry recommendation has been considered.
  • A policy proves itself when complying costs a delay or an expense: following it only when it is free is not a real policy.
Module 06

Non-conformities: classification and management

Module objectiveDistinguish observation, non-conformity and major non-conformity under the Code's definitions at §§1.1.7-1.1.10, and manage their closure.

Correct classification of non-conformities is essential to calibrate the organisational response: not every deviation requires the same level of intervention, but every deviation must still be treated rigorously.

The four ISM Code definitions at §§1.1.7-1.1.10 and the two alternative major non-conformity grounds made explicit in 2010.
The four ISM Code definitions at §§1.1.7-1.1.10 and the two alternative major non-conformity grounds made explicit in 2010.

These categories are not industry jargon: they are defined in the Code, at §§1.1.7-1.1.10, introduced by MSC.104(73). Using them in the Code's own words is what makes an audit report defensible.

Table 8 — Non-conformities: classification and management
TermDefinition and treatment
Objective evidence (§1.1.7)Verifiable information or statements of fact based on observation, measurement or test: the basis for every finding.
Observation (§1.1.8)A statement of fact made during a safety management audit and substantiated by objective evidence. The definition does not itself require corrective action or management-review referral: treatment and trending depend on the SMS and context.
Non-conformity (§1.1.9)An observed situation where evidence indicates non-fulfilment of a specified requirement. The company determines and initiates the action required under §9.2 and the applicable follow-up.
Major non-conformity (§1.1.10)A serious threat or risk requiring immediate action; or lack of effective and systematic implementation. Certification consequences follow Circ.1059/401 and Administration/RO decisions.

Table 6.1 — The ISM Code definitions, §§1.1.7-1.1.10.

The wording made explicit in 2010

MSC.273(85) replaced the words «and includes» in §1.1.10 with «or». The current text makes two alternative grounds unequivocal: a deviation posing a serious threat or risk and requiring immediate corrective action; or lack of effective and systematic implementation. It should not be taught that both necessarily had to coexist before 2010: «and includes» already brought the second category within the definition. The amendment removed ambiguity and made the alternative structure explicit.

The procedures for handling observed major non-conformities are in MSC/Circ.1059-MEPC/Circ.401, referenced in a footnote to §1.1.10 of the Code.

MSC/Circ.1059–MEPC/Circ.401 distinguishes correction, downgrade and withdrawal. A major non-conformity may be downgraded where the Administration or RO is satisfied that effective corrective action is being taken; if raised on a ship, it must be downgraded before the ship sails. A corrective-action schedule not exceeding three months must be agreed and at least one additional audit carried out within that period to verify effectiveness. If a DOC or SMC is withdrawn, an interim certificate cannot be used to bypass withdrawal: reissue requires the prescribed verifications.

Closure deadlines, and what happens if they slip

The Code makes the company responsible for determining and initiating corrective action; the A.1188(33) guidelines add the deadlines and the consequences, at §§4.14.1-4.14.3.

  • The company is responsible for determining and initiating the corrective action needed to correct the non-conformity or its cause. Failure to correct non-conformities with specific requirements of the Code may affect the validity of the DOC and the related SMCs.
  • Corrective actions and any follow-up audits are to be completed within the agreed time period, which should not normally exceed three months. It is the company that must apply for the follow-up audit.
  • And here is the provision that changes the perspective: failure to take adequate corrective actions in compliance with the Code, including measures to prevent recurrence, may be considered a major non-conformity.
An inadequate response does not automatically reclassify an NC

A.1188(33) §4.14.3 states that failure to take adequate corrective action, including measures to prevent recurrence, may be considered a major non-conformity. The decision requires objective evidence and assessment against §1.1.10. Recurrence, ineffective CAPA and lack of systematic implementation may provide that evidence.

SMS Focus — the same deficiency can change category over time

A single minor non-conformity, if it recurs several times without the root cause being addressed, can be reclassified as major: this signals that the system is not really correcting the problem, not just that an isolated problem exists.

Key takeaways

  • Without objective evidence there is neither an observation nor a non-conformity, only an opinion.
  • Since 2010, under MSC.273(85), lack of effective and systematic implementation of the Code is on its own a major non-conformity.
  • Corrective actions and follow-up audits are to be completed within the agreed time period, normally not exceeding three months.
Module 07

Internal audit of the SMS

The internal audit is the tool with which the company itself verifies, independently, that the SMS really works in daily practice, not only on paper.

The internal SMS audit programme under ISM Code §12, step by step.
The internal SMS audit programme under ISM Code §12, step by step.

The rule the Code actually sets

§12.1, in the wording introduced by MSC.273(85) and in force since 1 July 2010, leaves no interpretive room: the company must carry out internal safety audits on board and ashore at intervals not exceeding twelve months; only in exceptional circumstances may that interval be exceeded, and by not more than three months.

The internal programme should ensure that each ship and each shore site or function within the SMS scope is covered at a frequency complying with §12.1. Compliance is not established by a fleet average, but the obligation should not automatically be extended to offices outside the SMS scope.

The independence principle, and its limit

§12.5 requires personnel carrying out audits to be independent of the areas being audited — a superintendent should not audit the ship they personally manage — but it adds a condition almost always dropped from quotations: unless this is impracticable due to the size and the nature of the Company.

That is a genuine allowance for small operations, not an exemption. Where an auditor who is not fully independent must be used, the choice should be reasoned and compensated: have a second person review the findings, rotate auditors between ships, or have a third party review the programme. And there is a further duty, often overlooked: MSC-MEPC.7/Circ.8 §4.2 includes among the designated person's tasks the verification not only of the independence but also of the training of internal auditors.

The method, step by step

Section 12 establishes the requirements for internal audit: coverage of safety and pollution-prevention activities on board and ashore, an interval not exceeding twelve months subject to the exceptional extension, independence where practicable, communication of results and timely corrective action. The procedure in §§4.9-4.14 of A.1188(33), by contrast, governs certification audits performed by the Administration or RO. Document review, opening and closing meetings, evidence collection and reporting provide a useful model internally, but should not be attributed to §12 as a mandatory textual sequence.

Table 9 — The method, step by step
StepWhat it involves
Request and appointmentThe company requests the audit; a lead auditor and, where relevant, an audit team are nominated
Preliminary document reviewThe auditor reviews the safety management manual to determine whether the system is adequate against the Code. If the review shows it is not, the audit is delayed until the company takes corrective action
PreparationThe auditor reviews the company's safety performance records — flag State records, port State control reports, class and accident reports — and takes them into account in the audit plan
Opening meetingIntroduction of the team to senior management, methods, confirmation that agreed facilities are available, time and date of the closing meeting
ExecutionAssessment based both on the documentation presented and on objective evidence of the effectiveness of implementation, gathered through interviews and examination of documents; where necessary also by observing activities and conditions
Classifying the findingsHaving reviewed the evidence collected, the team determines what is to be reported as major non-conformities, non-conformities or observations, reasoned on the provisions of the Code
Closing meetingBefore preparing the report, a meeting with senior management and those responsible for the functions concerned, so that the results are understood, not merely communicated
Report and follow-upReport prepared under the direction of the lead auditor, who is responsible for its accuracy and completeness; a copy goes to the company, which should provide the ship with a copy of shipboard audit reports

Table 7.1 — The safety management audit procedure (A.1188(33), §§4.9-4.14).

Delay for an inadequate manual

The preliminary document review is not a formality: if the manual does not stand up against the Code's requirements, the audit does not take place and is postponed. For a company planning an initial certification — or bringing in a new ship type — this is the most concrete schedule risk, and the easiest to avoid by having the manual reviewed in advance.

Remote auditing: what is actually allowed

This is what the 2023 revision introduced, and it needs reading precisely because it is often over-simplified. A.1188(33) distinguishes two situations.

In extraordinary circumstances beyond the control of the parties — natural disasters, warfare, epidemic or pandemic outbreak, strike, riot, crime, sudden legal change — and only where the parties have taken all reasonable steps to perform the audit physically, remote auditing methods may be used. The assessment is made case by case by the flag Administration, and the outcome is limited: issuance of an interim certificate, or a certificate valid no longer than the time needed for the audit to be performed physically and in any case not exceeding six months. The assessment criteria include the type and age of the ship, the safety and compliance record of the ship and of the company including PSC performance, the documented justification, the scope of the remote audit, the training of the personnel involved, and transparency about the fact that the audit was carried out remotely.

A.1188(33), adopted in 2023, still contains the phrase «until guidance … is developed». That reference has since been satisfied: in 2026 MEPC 84 and MSC 111 approved MSC-MEPC.5/Circ.17, Guidance on assessments and applications of remote surveys, ISM Code audits and ISPS Code verifications. The resolution and circular should be read together. Remote methods are not unrestricted or equivalent to attendance by default: their use requires an applicability assessment, technical objectives, data integrity and security, adequate evidence and authorisation according to the Administration/RO role. Initial, intermediate, renewal and additional shipboard audits should still not be fully replaced by remote audit.

SMS Focus — an audit programme that never finds anything is not a good sign

An internal audit programme that, year after year, finds no non-conformities almost never reflects a perfect system: more often it signals an audit conducted with insufficient rigour, or an organisational climate that discourages honest reporting of issues.

Module 08

Management of Change

Every change to equipment, procedures, key personnel or operating methods introduces new risks that must be assessed before implementation. Management of Change (MoC) is, in practice, one of the most frequently neglected links in real safety management systems.

Where it is written — and where it is not

The ISM Code neither names nor prescribes a standalone process called «Management of Change». Section 1.2.2.2 nevertheless requires identified risks to ships, personnel and the environment to be assessed and appropriate safeguards established; §§11 and 12 require document control, verification and review. MoC is therefore a recognised method for demonstrating that risks introduced by change are identified, assessed, controlled and reviewed. A company may use a dedicated workflow or an equivalent integrated process, provided that verifiable evidence exists.

Management of Change in the SMS: a recognised method for demonstrating control of change-related risk, not a workflow named by the Code.
Management of Change in the SMS: a recognised method for demonstrating control of change-related risk, not a workflow named by the Code.

Typical situations requiring MoC

  • Replacement of critical equipment with one of a different type or configuration.
  • Modification of an established operating procedure.
  • Change of key personnel (Master, Chief Engineer, DPA) during a critical operational phase.
  • Change of routes, trades or the type of cargo habitually carried.
SMS Focus — the «temporary» change is the most common trap

Many organisations apply MoC only to changes declared permanent, neglecting temporary changes (a simplified procedure for an emergency, a provisional installation) that then become de facto permanent without ever going through a formal risk assessment.

Module 09

Management review

The management review is the point at which company top management formally assesses the SMS's overall performance, to decide whether and how to update policy and procedures. §12.3 requires it in these terms: the company should periodically evaluate the effectiveness of the SMS, in accordance with procedures it establishes itself.

The review has no twelve-month deadline

A frequent confusion: the twelve months in §12.1 apply to internal audits, not to the review. §12.3 says «periodically», and MSC-MEPC.7/Circ.8 §5.2 adds «or when needed» — for example in case of serious system failures. A company may therefore legitimately choose an annual cadence, but it must write it into the SMS, and it must be able to convene an extraordinary review when an event calls for one.

What the review must take into account

The Code does not define its content. Circ.8 does, at §5.2, listing what the review must consider as a minimum.

  • The results of internal audits.
  • Non-conformities reported by personnel.
  • The master's reviews — §5.1.5 requires the master to review the SMS periodically and report its deficiencies to shore-based management.
  • The analysis of non-conformities, accidents and hazardous occurrences.
  • Any other evidence of possible SMS failure, including non-conformities raised by external parties and PSC inspection reports.

That last item is what connects the review to the outside world: a PSC report is not just a problem for the ship that received it, it is data that must reach the review table. And the same guidance closes the loop: deficiencies found during the review should be given appropriate corrective action, and the results should be brought formally to the attention of all personnel involved.

SMS Focus — a review is not an annual formality to be filed away

A management review that merely confirms that «everything is fine», without ever generating concrete decisions for change, betrays the spirit of the continuous improvement cycle required by the Code. Top management should come out of every review with at least one traceable decision.

Module 10

Safety leadership

No documented system, however well designed, produces real safety without leadership that supports it with visible consistency, from company top management down to the individual crew member.

What distinguishes effective safety leadership

  • Visibility: top management actively shows interest in safety, not only during moments of crisis.
  • Consistency: commercial decisions do not systematically contradict stated safety objectives.
  • Listening: signals coming from on board are taken seriously, not filtered or minimised by middle management.
  • Investment: safety resources (training, maintenance, critical spares) are not the first item cut when containing costs.
SMS Focus — safety culture is built from the top, not imposed from the bottom

A crew does not build a safety culture on its own if management does not demonstrate it consistently in its own day-to-day decisions. Organisational culture tends to reflect, with a certain delay, the real behaviour of leadership, not its declarations.

Module 11

ISM and other control systems

Module objectiveRecognise how the ISM Code connects to Port State Control, vetting and class verifications, and why a solid SMS makes every control easier.

The ISM Code does not exist in isolation: it interacts closely with Port State Control, with vetting programmes and with class verifications, as already seen in the courses dedicated to these topics.

Table 10 — ISM and other control systems
SystemCorrect relationship with ISM
Port State ControlISM-related deficiencies may indicate SMS implementation failure. Detention depends on severity, combined evidence and applicable PSC procedures; not every ISM deficiency is automatically detainable.
Vetting / TMSAThey assess management maturity, evidence and performance that may overlap with SMS elements, but do not certify ISM compliance and have their own scope and purpose.
Administration / RO / classDOCs and SMCs are issued by the Administration, a recognised organisation or, where provided, another Administration. The statutory ISM role is distinct from class verification and need not be performed by the ship’s classification society.

Table 11.1 — Relationship of the ISM Code with other control systems.

SMS Focus — a solid SMS makes every other control easier

A company with a genuinely functioning SMS, not merely formally compliant, tends to face both PSC and vetting more easily, because the three systems ultimately observe the same operational reality from different angles. Investing in the SMS produces benefits that spread to all other areas of control.

Key takeaways

  • ISM-related deficiencies in Port State Control signal a systemic problem, not just an isolated one.
  • TMSA and vetting questionnaires assess the maturity of the management system, largely overlapping with the SMS.
  • DOC/SMC verifications are typically conducted by the same classification society that follows the ship as RO.
Module 12

Emerging trends

ISM implementation is evolving under the pressure of digitalisation, cyber risk, human factors and new operating models.

Directions to watch

  • Remote methods assessed under MSC-MEPC.5/Circ.17 together with A.1188(33), without automatic equivalence to attendance.
  • Digitalisation and cyber risk integrated into the SMS with traceability, data integrity and operational continuity.
  • In May 2026 IMO adopted the non-mandatory MASS Code through MSC.595(111), effective 1 July 2026: operating modes, roles, competence, fallback arrangements and risks should be integrated into the applicable SMS.
  • IMO has launched a comprehensive review of ISM implementation guidelines, targeted for completion in 2028. The mandatory Code remains unchanged while the implementation layer evolves.
SMS Focus — substance matters more than digital form

Digitalising an SMS that does not substantively work does not improve its effectiveness: it only speeds up the production of formally compliant documentation. The priority remains building a system that really works, before investing in the tools that facilitate its management.

Recurring mistakes

From the Mistake Library of SuperbaKnowledge, filtered to the subjects this course covers. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.

Recurring mistakes published in SuperbaKnowledge
TopicMistakeTypical consequenceTopic sheet
Internal SMS AuditAn auditor verifying their own area of responsibilityLoss of independence, NC in external auditSee the topic sheet
Master's AuthorityThe Master's overriding authority documented in the SMS but not concretely upheld when it carries a commercial costErosion of the Master's trust in the systemSee the topic sheet
Designated Person Ashore (DPA)DPA appointed only formally, without real access to top managementNC in certification audit, ineffective escalation system in an emergencySee the topic sheet
Document of Compliance (DOC) and Safety Management Certificate (SMC)DOC and SMC periodical verifications treated as if they had the same cadence, applying the SMC's intermediate window to the DOCThe Code does not say the certificate lapses by itself: §13.5 provides for withdrawal of the DOC when the annual verification is not requested, §13.9 for withdrawal of the SMC when the intermediate one is not. Both omissions are detainable deficiencies (A.1206(34), App. 2, §5 “Areas under the ISM Code”): item .8 “Evidence of the DOC annual verification is not available on board” and item .4 “The SMC intermediate verification is overdue”See the topic sheet
Crew Familiarisation and TrainingFamiliarization treated as a formality to be signed off, without real knowledge transferCrew nominally 'familiarised' but unprepared in a real emergencySee the topic sheet
Management ReviewManagement Review reduced to a completed form without real discussionNC in certification audit for lack of evidence of genuine top management involvementSee the topic sheet
Management of ChangeChanges implemented informally without a structured assessment processRisks associated with the change not identified before implementationSee the topic sheet
Near MissPunitive culture towards those who reportThe reporting rate collapses and useful information is lostSee the topic sheet
Autonomous Ships (MASS): the Company's Responsibility under the SMSMASS/remote operations introduced without a formal Management of Change in the SMSAbsence of a documented risk assessment specific to the new operating modelSee the topic sheet
TMSA: the Company's self-assessment, not the ship'sLevels declared before the evidence is collectedVisible gap between TMSA and SIRE reports for the same fleetSee the topic sheet
Cyber Risk Management in the SMS (MSC.428(98))Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessmentLack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measuresSee the topic sheet
Crew FatigueRest hour logging treated as a mere documentary formality, without reflecting real fatigue management on boardFormal compliance that fails to prevent chronic fatigue build-up in the crewSee the topic sheet

Related PSC deficiencies

From the PSC Knowledge Base of SuperbaKnowledge. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.

Related PSC deficiencies published in SuperbaKnowledge
DeficiencyRegulationIndicative frequencyPossible consequenceTopic sheet
Internal audit not conducted on one or more ships within 12 monthsISM Code, para. 12Medium-HighNC at external DOC/SMC renewal auditSee the topic sheet

Glossary of acronyms

Table 11 — Glossary of acronyms
AcronymDefinition
DOCDocument of Compliance
GTGross Tonnage
DPADesignated Person Ashore
ISMInternational Safety Management Code
MoCManagement of Change
MODUMobile Offshore Drilling Unit
NCNon-conformity (§1.1.9); major NC: §1.1.10
PDCAPlan-Do-Check-Act
PMSPlanned Maintenance System
RORecognized Organization
SMCSafety Management Certificate
SMSSafety Management System

References and sources

Consolidated list of the sources cited. Updated as of August 2026; always consult the official text in force.

Table 12 — References and sources by status
StatusSourceFunction
MandatorySOLAS chapter IX and consolidated ISM Code: A.741(18), as amended by MSC.104(73), MSC.179(79), MSC.195(80), MSC.273(85) and MSC.353(92)Mandatory basis, scope, definitions, implementation and certification.
Guidance — Administration/ROA.1188(33), 6 December 2023; MSC/Circ.1059–MEPC/Circ.401; MSC-MEPC.5/Circ.17, approved in 2026Certification, treatment of major NCs and application of remote methods.
Guidance — CompanyMSC-MEPC.7/Circ.8, Circ.6 and Circ.7; MSC.428(98) and current cyber guidanceImplementation, DPA, near-miss reporting and cyber-risk integration into the SMS.
Connected regimesA.1206(34), Procedures for Port State Control 2025; MSC.595(111), non-mandatory MASS Code, effective 1 July 2026PSC control and integration of MASS operations; they do not themselves amend the mandatory ISM Code.
Industry practiceTMSA and company proceduresImplementation methods and maturity assessment; they do not certify ISM compliance.
Educational material

This course is educational material for training purposes and does not constitute a professional certification or qualifying credential. Read the full disclaimer.