This guide compiles IMT's free ISM Code Learning Path — ten lessons covering the SMS, the DPA, audits, management review, and implementation — into one comprehensive reference. It's built for anyone who wants the full picture of ISM Code compliance in a single read, and for anyone returning to check a specific detail before an audit.
What This Guide Covers
- Why the ISM Code exists, and what DOC/SMC certification actually means
- How the SMS is structured, and the role of the Designated Person Ashore
- How findings are classified, and how internal and external audits work
- Management Review, continual improvement, and common findings
- A complete implementation roadmap, and where to go next
Why the ISM Code Exists, and What Certification Means
The ISM Code's origins trace to a string of serious accidents in the 1980s — including the capsize of the ro-ro ferry Herald of Free Enterprise in 1987 — that exposed a consistent pattern: technically seaworthy vessels failing because of how they were managed, not how they were built. The IMO adopted the Code in 1993 as Resolution A.741(18), and it became mandatory through SOLAS Chapter IX, entering into force on 1 July 1998 for most passenger ships and certain tanker and bulk carrier types, extending to most other cargo ships by 1 July 2002.
Certification runs on two linked levels. A Document of Compliance (DOC) is issued to a company, confirming its shore-based Safety Management System meets ISM requirements — one DOC can cover a whole fleet. A Safety Management Certificate (SMC) is issued to an individual vessel, confirming that system is genuinely applied on board. A vessel cannot hold a valid SMC unless its managing company holds a valid DOC. Notably, the Code's definition of "Company" isn't necessarily the registered owner — it's whoever has actually assumed responsibility for the vessel's operation, which may be a manager or bareboat charterer instead.
The SMS: Structure and the Six Functional Requirements
Every functioning Safety Management System follows the same architecture: a policy setting intent from top management, procedures translating that intent into specific instructions, risk assessment identifying hazards before a task begins, records proving procedures were actually followed, and continuous improvement feeding what's learned back into the system. ISM Code Section 1.4 formally requires six functional elements: a safety and environmental policy; instructions and procedures for safe operation; defined levels of authority and communication; procedures for reporting accidents and non-conformities; procedures for emergency preparedness; and procedures for internal audits and management review. Most company SMS manuals expand these six legal requirements into 10-12 practical chapters for usability, but every chapter should trace back to one of the six.
Auditors think in a four-level document hierarchy: Manual states policy, Procedure breaks it into steps, Form is the blank template for capturing evidence, and Record is that form completed. A gap between well-written Procedures and missing Records — not a missing Manual — is the single most common way a company discovers its SMS is real on paper but unproven on deck.
The Designated Person Ashore
ISM Code Section 4 requires every company to designate a person with direct access to the highest level of management — meaning the DPA can raise a safety concern straight to the CEO without going through the operational department it might concern first. The DPA's responsibility (monitoring safety and pollution-prevention performance) and authority (the standing to require corrective action) are deliberately separated, because responsibility without real authority would leave the role unable to act on what it finds. Communication is meant to flow both ways between ship, DPA, and top management — the Master raises concerns, the DPA verifies and escalates, and top management funds the fix, not just acknowledges the report.
Download the Complete ISM Code Guide (PDF)
This entire guide, formatted for offline reading, printing, or sharing with your management team.
We'll also send you one maritime compliance update per week. Unsubscribe anytime.
Non-Conformities, Audits, and Management Review
The ISM Code classifies findings into three tiers. An Observation is a documented fact that doesn't yet breach a specific requirement. A Non-Conformity means objective evidence shows a specific SMS or ISM requirement wasn't fulfilled. A Major Non-Conformity poses a serious safety or environmental threat and can block DOC or SMC issue until resolved. Classification follows a simple logic: does the finding breach a specific requirement, and if so, does it pose a serious threat? Corrective actions should target root cause, not symptom — the 5 Whys method traces a missing spare back through "no requisition raised" to "crew unaware of the process" to the real root cause, often a gap in onboarding.
Internal audits (the company checking its own SMS, at intervals not exceeding 12 months, by staff independent of the area audited) and external audits (Initial, Annual, and Renewal for the DOC; Initial, Intermediate, and Renewal for the SMC) both verify compliance. Management Review under Section 12 asks a different, harder question: is the SMS actually effective, not just followed? The 2010 amendment specifically changed "efficiency" to "effectiveness" in the Code's wording. A genuine review takes into account internal audit results, non-conformities, Master's Reviews, accident analysis, and external findings like PSC inspections — and it requires timely corrective action on what it finds, not just discussion.
Continual Improvement and Common Findings
Companies that only improve right before an external audit, that collect data but never analyse it, or that treat improvement as a one-off project rather than a habit, tend to see the same findings resurface. The PDCA cycle — Plan, Do, Check, Act, Repeat — is the general pattern behind both the Corrective Action Lifecycle and Management Review. Real sources of improvement data include internal and external audits, near misses, accidents, PSC inspections, customer feedback, and crew suggestions — the last of which deserves the same weight as a formal audit finding, since crew often spot friction points before they escalate.
The most common findings recur across ten categories: SMS documentation, risk assessment, permit-to-work, maintenance, training, emergency preparedness, internal audits, management review, records, and corrective actions. Most sit at Non-Conformity or Observation level individually, but a pattern of small findings spread across several categories often signals a systemic SMS weakness worth addressing at a company level, even when no single finding looks severe.
A Complete Implementation Roadmap
Implementation follows seven phases: Gap Assessment, SMS Development, Implementation, Internal Audit, Management Review, Certification Audit, and Continual Improvement — which loops back into ongoing operation rather than ending at certification. A practical 30/60/90-day plan covers a gap assessment against all six functional requirements in the first 30 days, SMS documentation development in the next 30, and crew training with the first internal audit scheduled by day 90. Responsibility is best distributed using a RACI framework: the Company typically holds Accountable, while the DPA, Master, and Department Heads hold Responsible for most activities — and crew hold Responsible specifically for continual improvement, not just compliance.
The most common implementation mistakes: treating certification as the finish line rather than building continual improvement in from day one; copying a generic SMS template without adapting it to real operations; appointing a DPA with conflicting operational duties; and skipping root cause analysis under time pressure, which all but guarantees the same findings recur.
Frequently Asked Questions
Is this guide a substitute for the full 10-lesson Learning Path?
No — this guide is a comprehensive overview; the full Learning Path includes interactive tools, self-checks, and lesson-specific downloads not reproduced here.
How current is the information in this guide?
It reflects IMO guidance as of July 2026, including the 2010 amendment's "effectiveness" wording for Management Review.
Can I use this guide as a starting point for ISM implementation?
Yes — many companies use it alongside the Implementation Roadmap lesson and Resource Library templates to plan their own rollout.
Ready to Implement, But Not Sure Where to Start?
This guide is a starting point — the full 10-lesson Learning Path includes interactive tools this summary can't replicate.
Start the Full Learning PathRelated Courses
IMT's ISM Internal Auditor Course and DPA Training Course cover audit practice, evidence standards, and real scenarios in depth.
View the ISM Internal Auditor Course Request Corporate TrainingContinue Reading: The Full Learning Path
- Lesson 1: Introduction to the ISM Code
- Lesson 2: Understanding the SMS
- Lesson 3: The Designated Person Ashore
- Lesson 4: Non-Conformities & Observations
- Lesson 5: Internal & External Audits
- Lesson 6: Preparing for an ISM Audit
- Lesson 7: Management Review
- Lesson 8: Continual Improvement
- Lesson 9: Common Findings & Best Practices
- Lesson 10: Complete ISM Implementation Roadmap
- Browse the Full Resource Library (40 downloads) →
- Take the Final Assessment →