The Safety Management System and safety leadership
Module objectiveRecognise what the ISM Code arose from, how it became mandatory and which company takes on its duties.
The International Safety Management Code arose from a series of maritime disasters that revealed how technical compliance with international conventions alone was not sufficient to guarantee real operational safety, in the absence of a structured management system that explicitly made the company, not just the ship, responsible.
Adopted through IMO Resolution A.741(18) of 4 November 1993, the Code was made mandatory through SOLAS Chapter IX, which at regulation 3 provides that «the requirements of the Code shall be treated as mandatory» and that the ship shall be operated by a company holding a Document of Compliance. Application came in three stages, and the distinction matters more than it looks.
| Category | Threshold | Not later than |
|---|---|---|
| Passenger ships, including passenger high-speed craft | no tonnage threshold | 1 July 1998 |
| Oil tankers, chemical tankers, gas carriers, bulk carriers and cargo high-speed craft | 500 GT and over | 1 July 1998 |
| Other cargo ships and mobile offshore drilling units (MODUs) | 500 GT and over | 1 July 2002 |
Table 1.1 — Application of the ISM Code (SOLAS regulation IX/2.1).
Two points that summaries tend to lose. First: there is no tonnage threshold for passenger ships — the 500 GT applies to the other two stages, not to them. Second: the chapter does not apply to government-operated ships used for non-commercial purposes (regulation IX/2.2).
The Code does not address the owner generically. §1.1.2 — reproduced word for word in SOLAS regulation IX/1.2 — defines the Company as the owner of the ship or any other organization or person, such as the manager or the bareboat charterer, who has assumed responsibility for operating the ship from the owner and who, on assuming that responsibility, has agreed to take over all the duties and responsibilities imposed by the Code.
That last clause is the important one: ISM responsibility does not transfer merely by operating the ship, but by an explicit assumption. It is why the DOC names one specific company, and why a change of management is a certification event, not only a contractual one.
The central innovation of the ISM Code is not technical but organisational: for the first time an international instrument explicitly places on the company, and not only on the ship, responsibility for a documented, verifiable safety management system subject to continuous improvement.
Five sets of amendments have changed the Code. Two of them alter rules used every week.
| Resolution | In force from | What it changes |
|---|---|---|
| MSC.104(73) — 2000 | 1 July 2002 | Introduces the definitions of objective evidence, observation, non-conformity, major non-conformity and anniversary date; rewrites certification (§13) and adds interim certification (§14) |
| MSC.179(79) — 2004 | 1 July 2006 | Adds to the DOC and SMC forms the completion date of the verification on which the certificate is based |
| MSC.195(80) — 2005 | 1 January 2009 | Adds the Company identification number to the four certificate forms |
| MSC.273(85) — 2008 | 1 July 2010 | Sets the maximum interval between internal audits at twelve months (§12.1); makes the two limbs of major non-conformity alternative; replaces §1.2.2.2 with the duty to assess all identified risks; adds measures to prevent recurrence to §9.2 |
| MSC.353(92) — 2013 | 1 January 2015 | Introduces §12.2 on verifying those undertaking delegated ISM tasks, renumbering what follows; rewrites §6.2 on manning; adds footnotes to the titles of §§3 and 4 pointing to MSC-MEPC.7/Circ.8 and Circ.6 |
Table 1.2 — The amendments to the ISM Code and their effects.
The Code is in two parts. Part A — Implementation (§§1-12) defines what the company must build and keep working; Part B — Certification and verification (§§13-16) defines how all of that is certified and verified from outside. Module 04 covers Part B; this module covers Part A.
Before the operational sections, the Code sets out at §1.4 the six functional requirements every SMS must contain. It is the shortest and most useful list in the Code: if one of these six is missing, there is no SMS.
| § | Element | Essential content |
|---|---|---|
| 1 | General provisions, objectives, definitions | Scope and purpose of the Code |
| 2 | Safety and environmental policy | Company's stated commitment, to be made concrete in practice |
| 3 | Company responsibility and authority | Organisation chart, delegations, resources |
| 4 | Designated Person (DPA) | Direct access to top management, independent monitoring (dedicated course) |
| 5 | Master's responsibility and authority | The master's overriding authority over safety and pollution prevention, and the right to request the Company's assistance (§5.2) |
| 6 | Resources and personnel | Manning, familiarisation, competence |
| 7 | Shipboard operations | Procedures for critical operations |
| 8 | Emergency preparedness | Scenarios, drills, exercises |
| 9 | Non-conformities, incidents, near-misses | Reporting, analysis, corrective actions (modules 6-7) |
| 10 | Maintenance of ship and equipment | Critical equipment, PMS (see also the Reliability Management course) |
| 11 | Documentation | Document and record control |
| 12 | Company verification, review and evaluation | Internal audits every 12 months, verification of delegated tasks, management review |
Table 2.1 — The sections of Part A of the ISM Code (implementation).
| § | Section | Essential content |
|---|---|---|
| 13 | Certification and periodical verification | DOC and SMC: who issues them, validity, annual and intermediate verifications, renewal (Module 04) |
| 14 | Interim certification | Interim DOC for new companies or those adding a ship type; interim SMC for new deliveries, a change of company or a change of flag |
| 15 | Verification | All verifications follow the procedures established by the Administration, taking IMO guidelines into account |
| 16 | Forms of certificates | The four forms — DOC, SMC and their interim versions — are annexed to the Code |
Table 2.2 — The sections of Part B of the ISM Code (certification and verification).
Part A is what the company must do; Part B is what someone else verifies. Conflating them leads to the most common error in SMS management: building the system around the certification audit rather than around the operation, and ending up with a manual that passes verification but does not describe how the work is actually done.
The Safety Management System is not a static document, but a system that the ISM Code wants to be in continuous improvement, following a logic comparable to the classic Plan-Do-Check-Act (PDCA) cycle of quality management systems.

| Phase | What it involves in the SMS | Where the Code says so |
|---|---|---|
| Plan | Safety and environmental protection policy, assessment of all identified risks, procedures and instructions for operations | §2 · §1.2.2.2 · §7 |
| Do | Day-to-day implementation on board and ashore, with adequate resources and personnel and emergency preparedness | §6 · §8 · §10 |
| Check | Reporting and analysis of non-conformities, accidents and hazardous situations; internal audits every twelve months; verification of delegated tasks | §9.1 · §12.1 · §12.2 |
| Act | Corrective actions including measures to prevent recurrence; management review of effectiveness; revision of procedures | §9.2 · §12.3 · §12.7 |
Table 3.1 — The PDCA cycle and the paragraphs of the Code that make it mandatory.
The Code never names the Plan-Do-Check-Act cycle: it is a model borrowed from quality management systems, and it works well as a mental frame. But when writing a procedure, or answering an auditor, the reference to cite is the paragraph — not the phase. The practical difference is that the phases are four and symmetrical, whereas the Code's text is not: «plan» is stated in general terms, while «check» and «act» carry the only numeric deadlines in the cycle — the twelve months between internal audits in §12.1, the three-month exceptional extension, and the three months within which corrective actions and follow-up audits should normally be closed.
A Safety Management System whose procedures remain identical for years, with no changes generated by audits, incidents or operational changes, does not reflect a perfect system: more likely it reflects a PDCA cycle that has stalled, with the risk that the documentation no longer reflects real practice.
Module objectiveDistinguish the DOC from the SMC, recognise the five types of verification, and keep certificate expiry dates under control.
The Document of Compliance (DOC) certifies the company's management system for the ship types it manages; the Safety Management Certificate (SMC) certifies that the individual ship operates in compliance with an approved and verified SMS. These are two distinct certificates, with parallel verification cycles.


| Certificate | Subject | Validity | Verifications |
|---|---|---|---|
| DOC | Company management system, for the ship types listed on the certificate | up to 5 years | annual verification within three months before or after the anniversary date |
| SMC | SMS of the individual ship | up to 5 years | at least one intermediate verification between the second and third anniversary of issue |
| Interim DOC | Newly established company, or one adding a ship type not covered by the existing DOC | up to 12 months | assessment at the company offices, §14.1 |
| Interim SMC | Newly delivered ship, change of company or change of flag | up to 6 months; in special cases the Administration may extend it by no more than a further 6 (§§14.2-14.3) | verification that the ship is provided with an SMS, §14.4 |
| Copy of the DOC on board | Evidence that the company holds a valid DOC for that ship type | — | must be producible on request; the copy need not be authenticated or certified (§13.6) |
Table 4.1 — Validity and verification of ISM certificates (§§13-14).
This is the detail that produces most surprises during an acquisition: the DOC does not certify the company in the abstract, but its ability to manage those ship types. Adding a type not listed requires an additional verification and, meanwhile, an interim DOC. And in the other direction: during the annual verification the Administration checks whether the company is still operating all the listed types, and acts accordingly if one has been dropped.
Renewal planning requires three scenarios to be distinguished. If verification is completed within the three months before expiry, the new DOC or SMC runs from completion for a period not exceeding five years from the expiry date of the existing document or certificate (§13.10). If completed more than three months before expiry, the new DOC or SMC runs from completion for no more than five years (§13.11). If renewal verification of an SMC is completed after expiry, §13.12 allows the new SMC to run from completion to a date not exceeding five years from the previous expiry date. This does not authorise operation during a gap without a valid SMC and is not a parallel rule for the DOC.
The Code sets the rules; how certification actually happens is described in the IMO guidelines for Administrations — today Resolution A.1188(33), adopted on 6 December 2023, which revoked the earlier A.1118(30). At §4.1.1 the process breaks down into five verifications.
| Verification | When | What it involves |
|---|---|---|
| Interim | New company, new ship type, newly delivered or transferred ship | Assessment of the offices and verification that the ship is provided with an SMS; allows operation while the system beds in |
| Initial | At first full certification | Assessment of the offices — including sites performing delegated SMS tasks — and then of the ships |
| Annual (DOC) or intermediate (SMC) | During the period of validity | Addresses all SMS elements, not a sample; verifies that the system is functioning effectively and that any modifications comply |
| Renewal | Before expiry | Addresses all SMS elements; may be carried out in the preceding three months, to be completed before expiry |
| Additional | Where there are clear grounds | Scope and depth decided case by case by the Administration |
Table 4.2 — The certification process (A.1188(33), §4.1.1).
This is the practical question that most often goes unanswered. §4.3.6 of A.1188(33) settles it: initial verification requires objective evidence that the SMS has been in operation for at least three months ashore, and for at least three months on board at least one ship of each type operated by the company. The evidence expressly includes records from the internal audit already performed by the company.
In management terms: you cannot certify an SMS that has just been written. It takes three months of real operation, with records, and at least one completed round of internal audit. Anyone planning a certification has to count backwards from that threshold, not from the date the manual is ready.
§4.7.1 is the provision that connects ISM to the rest of the world. The Administration may require an additional verification, where there are clear grounds, to check whether the SMS still functions effectively. The guidelines cite three typical situations, and the first is the one that matters most in daily management.
An additional verification may affect the shore organisation, the shipboard one, or both; the Administration determines the scope and depth case by case. This is why a PSC detention does not end when the ship sails: it can trigger a verification of the whole company. The Port State Control course covers the same mechanism from the inspection side, with action codes 19 and 21.
MSC/Circ.1059–MEPC/Circ.401 requires that a ship not operate where the company’s DOC or the ship’s SMC has been withdrawn, until it is reissued. This is not merely a commercial-acceptance issue.
Module objectiveRecognise the safety policy as the instrument for achieving the §1.2 objectives, and the conditions that make it real on board and ashore.
§2.1 of the Code requires the company to establish a safety and environmental protection policy which describes how the objectives given in §1.2 will be achieved. The wording is precise: the policy is not a free-standing statement of intent, it is the instrument for achieving objectives the Code has already written. They are worth reading.
§1.2.1 sets the objectives of the Code: to ensure safety at sea, prevention of human injury or loss of life, and avoidance of damage to the environment — in particular the marine environment — and to property.
§1.2.2 translates those into three safety management objectives for the company.
The original 1993 text said only «establish safeguards against all identified risks». MSC.273(85), in force from 1 July 2010, replaced it with «assess all identified risks to its ships, personnel and the environment and establish appropriate safeguards». Adding the verb assess introduced into the Code a duty of risk assessment that had not previously been explicit. It is the legal basis of everything now done on risk analysis inside an SMS — including the Management of Change of Module 08.
§1.2.3 completes the picture: the SMS must ensure compliance with mandatory rules and regulations, and that codes, guidelines and standards recommended by the IMO, Administrations, classification societies and industry organisations are taken into account. It is the only point where the Code explicitly opens to non-binding sources — and the reason an auditor may ask how an industry recommendation has been considered, even though it is not mandatory.
That the policy remains a formal document, little known and little lived on board. §2.2 anticipates the problem by requiring the company to ensure the policy is implemented and maintained at all levels of the organisation, both ship-based and shore-based.
A safety policy proves itself true or false not in ordinary moments, but in those where complying with it comes at an immediate cost (a delay, an unplanned expense). An organisation that follows its own policy only when it costs nothing does not, in fact, have a real safety policy.
Module objectiveDistinguish observation, non-conformity and major non-conformity under the Code's definitions at §§1.1.7-1.1.10, and manage their closure.
Correct classification of non-conformities is essential to calibrate the organisational response: not every deviation requires the same level of intervention, but every deviation must still be treated rigorously.

These categories are not industry jargon: they are defined in the Code, at §§1.1.7-1.1.10, introduced by MSC.104(73). Using them in the Code's own words is what makes an audit report defensible.
| Term | Definition and treatment |
|---|---|
| Objective evidence (§1.1.7) | Verifiable information or statements of fact based on observation, measurement or test: the basis for every finding. |
| Observation (§1.1.8) | A statement of fact made during a safety management audit and substantiated by objective evidence. The definition does not itself require corrective action or management-review referral: treatment and trending depend on the SMS and context. |
| Non-conformity (§1.1.9) | An observed situation where evidence indicates non-fulfilment of a specified requirement. The company determines and initiates the action required under §9.2 and the applicable follow-up. |
| Major non-conformity (§1.1.10) | A serious threat or risk requiring immediate action; or lack of effective and systematic implementation. Certification consequences follow Circ.1059/401 and Administration/RO decisions. |
Table 6.1 — The ISM Code definitions, §§1.1.7-1.1.10.
MSC.273(85) replaced the words «and includes» in §1.1.10 with «or». The current text makes two alternative grounds unequivocal: a deviation posing a serious threat or risk and requiring immediate corrective action; or lack of effective and systematic implementation. It should not be taught that both necessarily had to coexist before 2010: «and includes» already brought the second category within the definition. The amendment removed ambiguity and made the alternative structure explicit.
The procedures for handling observed major non-conformities are in MSC/Circ.1059-MEPC/Circ.401, referenced in a footnote to §1.1.10 of the Code.
MSC/Circ.1059–MEPC/Circ.401 distinguishes correction, downgrade and withdrawal. A major non-conformity may be downgraded where the Administration or RO is satisfied that effective corrective action is being taken; if raised on a ship, it must be downgraded before the ship sails. A corrective-action schedule not exceeding three months must be agreed and at least one additional audit carried out within that period to verify effectiveness. If a DOC or SMC is withdrawn, an interim certificate cannot be used to bypass withdrawal: reissue requires the prescribed verifications.
The Code makes the company responsible for determining and initiating corrective action; the A.1188(33) guidelines add the deadlines and the consequences, at §§4.14.1-4.14.3.
A.1188(33) §4.14.3 states that failure to take adequate corrective action, including measures to prevent recurrence, may be considered a major non-conformity. The decision requires objective evidence and assessment against §1.1.10. Recurrence, ineffective CAPA and lack of systematic implementation may provide that evidence.
A single minor non-conformity, if it recurs several times without the root cause being addressed, can be reclassified as major: this signals that the system is not really correcting the problem, not just that an isolated problem exists.
The internal audit is the tool with which the company itself verifies, independently, that the SMS really works in daily practice, not only on paper.

§12.1, in the wording introduced by MSC.273(85) and in force since 1 July 2010, leaves no interpretive room: the company must carry out internal safety audits on board and ashore at intervals not exceeding twelve months; only in exceptional circumstances may that interval be exceeded, and by not more than three months.
The internal programme should ensure that each ship and each shore site or function within the SMS scope is covered at a frequency complying with §12.1. Compliance is not established by a fleet average, but the obligation should not automatically be extended to offices outside the SMS scope.
§12.5 requires personnel carrying out audits to be independent of the areas being audited — a superintendent should not audit the ship they personally manage — but it adds a condition almost always dropped from quotations: unless this is impracticable due to the size and the nature of the Company.
That is a genuine allowance for small operations, not an exemption. Where an auditor who is not fully independent must be used, the choice should be reasoned and compensated: have a second person review the findings, rotate auditors between ships, or have a third party review the programme. And there is a further duty, often overlooked: MSC-MEPC.7/Circ.8 §4.2 includes among the designated person's tasks the verification not only of the independence but also of the training of internal auditors.
Section 12 establishes the requirements for internal audit: coverage of safety and pollution-prevention activities on board and ashore, an interval not exceeding twelve months subject to the exceptional extension, independence where practicable, communication of results and timely corrective action. The procedure in §§4.9-4.14 of A.1188(33), by contrast, governs certification audits performed by the Administration or RO. Document review, opening and closing meetings, evidence collection and reporting provide a useful model internally, but should not be attributed to §12 as a mandatory textual sequence.
| Step | What it involves |
|---|---|
| Request and appointment | The company requests the audit; a lead auditor and, where relevant, an audit team are nominated |
| Preliminary document review | The auditor reviews the safety management manual to determine whether the system is adequate against the Code. If the review shows it is not, the audit is delayed until the company takes corrective action |
| Preparation | The auditor reviews the company's safety performance records — flag State records, port State control reports, class and accident reports — and takes them into account in the audit plan |
| Opening meeting | Introduction of the team to senior management, methods, confirmation that agreed facilities are available, time and date of the closing meeting |
| Execution | Assessment based both on the documentation presented and on objective evidence of the effectiveness of implementation, gathered through interviews and examination of documents; where necessary also by observing activities and conditions |
| Classifying the findings | Having reviewed the evidence collected, the team determines what is to be reported as major non-conformities, non-conformities or observations, reasoned on the provisions of the Code |
| Closing meeting | Before preparing the report, a meeting with senior management and those responsible for the functions concerned, so that the results are understood, not merely communicated |
| Report and follow-up | Report prepared under the direction of the lead auditor, who is responsible for its accuracy and completeness; a copy goes to the company, which should provide the ship with a copy of shipboard audit reports |
Table 7.1 — The safety management audit procedure (A.1188(33), §§4.9-4.14).
The preliminary document review is not a formality: if the manual does not stand up against the Code's requirements, the audit does not take place and is postponed. For a company planning an initial certification — or bringing in a new ship type — this is the most concrete schedule risk, and the easiest to avoid by having the manual reviewed in advance.
This is what the 2023 revision introduced, and it needs reading precisely because it is often over-simplified. A.1188(33) distinguishes two situations.
In extraordinary circumstances beyond the control of the parties — natural disasters, warfare, epidemic or pandemic outbreak, strike, riot, crime, sudden legal change — and only where the parties have taken all reasonable steps to perform the audit physically, remote auditing methods may be used. The assessment is made case by case by the flag Administration, and the outcome is limited: issuance of an interim certificate, or a certificate valid no longer than the time needed for the audit to be performed physically and in any case not exceeding six months. The assessment criteria include the type and age of the ship, the safety and compliance record of the ship and of the company including PSC performance, the documented justification, the scope of the remote audit, the training of the personnel involved, and transparency about the fact that the audit was carried out remotely.
A.1188(33), adopted in 2023, still contains the phrase «until guidance … is developed». That reference has since been satisfied: in 2026 MEPC 84 and MSC 111 approved MSC-MEPC.5/Circ.17, Guidance on assessments and applications of remote surveys, ISM Code audits and ISPS Code verifications. The resolution and circular should be read together. Remote methods are not unrestricted or equivalent to attendance by default: their use requires an applicability assessment, technical objectives, data integrity and security, adequate evidence and authorisation according to the Administration/RO role. Initial, intermediate, renewal and additional shipboard audits should still not be fully replaced by remote audit.
An internal audit programme that, year after year, finds no non-conformities almost never reflects a perfect system: more often it signals an audit conducted with insufficient rigour, or an organisational climate that discourages honest reporting of issues.
Every change to equipment, procedures, key personnel or operating methods introduces new risks that must be assessed before implementation. Management of Change (MoC) is, in practice, one of the most frequently neglected links in real safety management systems.
The ISM Code neither names nor prescribes a standalone process called «Management of Change». Section 1.2.2.2 nevertheless requires identified risks to ships, personnel and the environment to be assessed and appropriate safeguards established; §§11 and 12 require document control, verification and review. MoC is therefore a recognised method for demonstrating that risks introduced by change are identified, assessed, controlled and reviewed. A company may use a dedicated workflow or an equivalent integrated process, provided that verifiable evidence exists.

Many organisations apply MoC only to changes declared permanent, neglecting temporary changes (a simplified procedure for an emergency, a provisional installation) that then become de facto permanent without ever going through a formal risk assessment.
The management review is the point at which company top management formally assesses the SMS's overall performance, to decide whether and how to update policy and procedures. §12.3 requires it in these terms: the company should periodically evaluate the effectiveness of the SMS, in accordance with procedures it establishes itself.
A frequent confusion: the twelve months in §12.1 apply to internal audits, not to the review. §12.3 says «periodically», and MSC-MEPC.7/Circ.8 §5.2 adds «or when needed» — for example in case of serious system failures. A company may therefore legitimately choose an annual cadence, but it must write it into the SMS, and it must be able to convene an extraordinary review when an event calls for one.
The Code does not define its content. Circ.8 does, at §5.2, listing what the review must consider as a minimum.
That last item is what connects the review to the outside world: a PSC report is not just a problem for the ship that received it, it is data that must reach the review table. And the same guidance closes the loop: deficiencies found during the review should be given appropriate corrective action, and the results should be brought formally to the attention of all personnel involved.
A management review that merely confirms that «everything is fine», without ever generating concrete decisions for change, betrays the spirit of the continuous improvement cycle required by the Code. Top management should come out of every review with at least one traceable decision.
No documented system, however well designed, produces real safety without leadership that supports it with visible consistency, from company top management down to the individual crew member.
A crew does not build a safety culture on its own if management does not demonstrate it consistently in its own day-to-day decisions. Organisational culture tends to reflect, with a certain delay, the real behaviour of leadership, not its declarations.
Module objectiveRecognise how the ISM Code connects to Port State Control, vetting and class verifications, and why a solid SMS makes every control easier.
The ISM Code does not exist in isolation: it interacts closely with Port State Control, with vetting programmes and with class verifications, as already seen in the courses dedicated to these topics.
| System | Correct relationship with ISM |
|---|---|
| Port State Control | ISM-related deficiencies may indicate SMS implementation failure. Detention depends on severity, combined evidence and applicable PSC procedures; not every ISM deficiency is automatically detainable. |
| Vetting / TMSA | They assess management maturity, evidence and performance that may overlap with SMS elements, but do not certify ISM compliance and have their own scope and purpose. |
| Administration / RO / class | DOCs and SMCs are issued by the Administration, a recognised organisation or, where provided, another Administration. The statutory ISM role is distinct from class verification and need not be performed by the ship’s classification society. |
Table 11.1 — Relationship of the ISM Code with other control systems.
A company with a genuinely functioning SMS, not merely formally compliant, tends to face both PSC and vetting more easily, because the three systems ultimately observe the same operational reality from different angles. Investing in the SMS produces benefits that spread to all other areas of control.
ISM implementation is evolving under the pressure of digitalisation, cyber risk, human factors and new operating models.
Digitalising an SMS that does not substantively work does not improve its effectiveness: it only speeds up the production of formally compliant documentation. The priority remains building a system that really works, before investing in the tools that facilitate its management.
From the Mistake Library of SuperbaKnowledge, filtered to the subjects this course covers. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.
| Topic | Mistake | Typical consequence | Topic sheet |
|---|---|---|---|
| Internal SMS Audit | An auditor verifying their own area of responsibility | Loss of independence, NC in external audit | See the topic sheet |
| Master's Authority | The Master's overriding authority documented in the SMS but not concretely upheld when it carries a commercial cost | Erosion of the Master's trust in the system | See the topic sheet |
| Designated Person Ashore (DPA) | DPA appointed only formally, without real access to top management | NC in certification audit, ineffective escalation system in an emergency | See the topic sheet |
| Document of Compliance (DOC) and Safety Management Certificate (SMC) | DOC and SMC periodical verifications treated as if they had the same cadence, applying the SMC's intermediate window to the DOC | The Code does not say the certificate lapses by itself: §13.5 provides for withdrawal of the DOC when the annual verification is not requested, §13.9 for withdrawal of the SMC when the intermediate one is not. Both omissions are detainable deficiencies (A.1206(34), App. 2, §5 “Areas under the ISM Code”): item .8 “Evidence of the DOC annual verification is not available on board” and item .4 “The SMC intermediate verification is overdue” | See the topic sheet |
| Crew Familiarisation and Training | Familiarization treated as a formality to be signed off, without real knowledge transfer | Crew nominally 'familiarised' but unprepared in a real emergency | See the topic sheet |
| Management Review | Management Review reduced to a completed form without real discussion | NC in certification audit for lack of evidence of genuine top management involvement | See the topic sheet |
| Management of Change | Changes implemented informally without a structured assessment process | Risks associated with the change not identified before implementation | See the topic sheet |
| Near Miss | Punitive culture towards those who report | The reporting rate collapses and useful information is lost | See the topic sheet |
| Autonomous Ships (MASS): the Company's Responsibility under the SMS | MASS/remote operations introduced without a formal Management of Change in the SMS | Absence of a documented risk assessment specific to the new operating model | See the topic sheet |
| TMSA: the Company's self-assessment, not the ship's | Levels declared before the evidence is collected | Visible gap between TMSA and SIRE reports for the same fleet | See the topic sheet |
| Cyber Risk Management in the SMS (MSC.428(98)) | Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessment | Lack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measures | See the topic sheet |
| Crew Fatigue | Rest hour logging treated as a mere documentary formality, without reflecting real fatigue management on board | Formal compliance that fails to prevent chronic fatigue build-up in the crew | See the topic sheet |
From the PSC Knowledge Base of SuperbaKnowledge. This view selects and organises content published in SuperbaKnowledge; it does not modify or replace it. The linked Knowledge page remains the reference version, while official texts remain authoritative.
| Deficiency | Regulation | Indicative frequency | Possible consequence | Topic sheet |
|---|---|---|---|---|
| Internal audit not conducted on one or more ships within 12 months | ISM Code, para. 12 | Medium-High | NC at external DOC/SMC renewal audit | See the topic sheet |
| Acronym | Definition |
|---|---|
| DOC | Document of Compliance |
| GT | Gross Tonnage |
| DPA | Designated Person Ashore |
| ISM | International Safety Management Code |
| MoC | Management of Change |
| MODU | Mobile Offshore Drilling Unit |
| NC | Non-conformity (§1.1.9); major NC: §1.1.10 |
| PDCA | Plan-Do-Check-Act |
| PMS | Planned Maintenance System |
| RO | Recognized Organization |
| SMC | Safety Management Certificate |
| SMS | Safety Management System |
Consolidated list of the sources cited. Updated as of August 2026; always consult the official text in force.
| Status | Source | Function |
|---|---|---|
| Mandatory | SOLAS chapter IX and consolidated ISM Code: A.741(18), as amended by MSC.104(73), MSC.179(79), MSC.195(80), MSC.273(85) and MSC.353(92) | Mandatory basis, scope, definitions, implementation and certification. |
| Guidance — Administration/RO | A.1188(33), 6 December 2023; MSC/Circ.1059–MEPC/Circ.401; MSC-MEPC.5/Circ.17, approved in 2026 | Certification, treatment of major NCs and application of remote methods. |
| Guidance — Company | MSC-MEPC.7/Circ.8, Circ.6 and Circ.7; MSC.428(98) and current cyber guidance | Implementation, DPA, near-miss reporting and cyber-risk integration into the SMS. |
| Connected regimes | A.1206(34), Procedures for Port State Control 2025; MSC.595(111), non-mandatory MASS Code, effective 1 July 2026 | PSC control and integration of MASS operations; they do not themselves amend the mandatory ISM Code. |
| Industry practice | TMSA and company procedures | Implementation methods and maturity assessment; they do not certify ISM compliance. |
This course is educational material for training purposes and does not constitute a professional certification or qualifying credential. Read the full disclaimer.