A DOC certificate proves a company wrote a Safety Management System down. It says nothing about whether that system actually runs the ship day to day. This lesson is about the difference — what a compliant SMS is actually built from, and how an auditor tells a real one from a filed one.
What You'll Learn in This Lesson
- The five-stage architecture every functioning SMS follows, from policy to continuous improvement
- The six functional requirements the ISM Code itself mandates in Section 1.4
- How SMS documentation is actually structured — Manual, Procedure, Form, Record
- How to self-check your own SMS against ten common readiness indicators
- What it looks like when a company has a DOC but its SMS isn't followed on board
The SMS Architecture
Every functioning Safety Management System follows the same underlying architecture, regardless of how a company chooses to format its manual:
A safety and environmental policy sets the intent from top management. Procedures translate that intent into specific, repeatable instructions. Risk assessment identifies what could go wrong in a given task before it's carried out. Records prove the procedure was actually followed. And continuous improvement — internal audits, management review, corrective action — feeds what's learned back into the policy and procedures, closing the loop. A system missing any one of these five stages isn't really a management system; it's a collection of documents.
The Six Functional Requirements (ISM Code Section 1.4)
The ISM Code itself is specific about what a compliant SMS must include. Section 1.4 lists exactly six functional requirements:
| # | Functional Requirement | In Practice |
|---|---|---|
| 1 | Safety and environmental protection policy | A signed, top-management statement of intent |
| 2 | Instructions and procedures for safe operation and environmental protection, compliant with international and flag State law | The operational heart of the SMS manual |
| 3 | Defined levels of authority and communication between shore and shipboard personnel | Who can approve what, and who reports to whom |
| 4 | Procedures for reporting accidents and non-conformities | Covered in depth in Lesson 4 |
| 5 | Procedures to prepare for and respond to emergencies | Drills, contingency plans, muster procedures |
| 6 | Procedures for internal audits and management review | Covered in depth in Lesson 5 |
In practice, most company SMS manuals expand these six legal requirements into a broader set of ten to twelve practical chapters — separating out things like crew familiarisation, maintenance planning, and document control into their own sections — but every one of those practical chapters ultimately exists to satisfy one of these six formal requirements. If a chapter in your SMS manual can't be traced back to one of these six, it's worth asking why it's there.
SMS Document Hierarchy: Manual → Procedure → Form → Record
Auditors think in terms of a four-level document hierarchy, and understanding it helps explain why some non-conformities get raised even when "the paperwork exists":
The Manual states policy and structure at the highest level. A Procedure breaks a policy statement down into a specific, step-by-step instruction. A Form is the blank template used to capture evidence that the procedure was followed. A Record is that same form, completed — the actual proof. An auditor who finds a Manual and Procedure in perfect order, but no completed Records to match, has found exactly the kind of gap this lesson opened with: a system that exists on paper but isn't demonstrably running the ship.
Download the SMS Structure Checklist (PDF)
A practical checklist mapping your SMS manual's chapters back to the six ISM Code functional requirements.
We'll also send you one maritime compliance update per week. Unsubscribe anytime.
Interactive SMS Self-Check
Answer honestly. This is a self-assessment tool, not an official ISM audit.
1. Does your SMS include a signed safety & environmental policy?
2. Can crew explain procedures, not just perform them?
3. Are levels of authority clearly defined and known on board?
4. Is every non-conformity actually logged, not handled verbally?
5. Are emergency procedures drilled with varied scenarios?
6. Are internal audits and management reviews actually completed on schedule?
7. Do completed Records actually match what Procedures require?
8. Is document control (version numbers, revision dates) actually maintained?
9. Are new crew members briefed on SMS content relevant to their role specifically?
10. Would your SMS survive an unannounced spot-check tomorrow?
Mini Case Study: The DOC That Didn't Match the Deck
Auditor: "Your SMS states permits are reviewed before hazardous work begins. Show me the last one."
This is the single most common gap IMT sees in companies newer to the ISM Code: the Manual and Procedures are well written — often better written than the company's actual practice — while the Records that would prove the practice matches the paper simply aren't being kept consistently.
Common SMS Mistakes New Companies Make
- Writing a Manual that describes an idealised process rather than the one the company can actually sustain in daily operations.
- Treating Records as an inspection-week task rather than a continuous by-product of doing the work correctly.
- Copying a generic SMS template without adapting it to the company's actual vessel types and trades.
- Letting document control lapse — outdated procedure versions still in circulation on board while a newer version sits ashore.
- Onboarding new crew with the full SMS manual instead of the specific sections relevant to their actual role.
Not Sure Your SMS Would Survive an Audit?
Talk to an IMT compliance advisor about an independent SMS documentation review.
Contact an ExpertGet Certified in ISM Internal Auditing
IMT's ISM Internal Auditor Course covers SMS documentation review, non-conformity classification, and corrective action management in depth.
View the Course Talk to an AdvisorDownload Center
Everything from this article, in a format you can print, share, or file.
Frequently Asked Questions
How many functional requirements does the ISM Code specify for an SMS?
Six, listed in Section 1.4 of the Code — covering policy, procedures, authority levels, non-conformity reporting, emergency response, and internal audits/management review.
Why do most company SMS manuals have more than six chapters?
Companies typically expand the six legal requirements into 10-12 practical chapters for clarity and day-to-day usability, but every chapter should trace back to one of the six formal requirements.
What's the difference between a Procedure and a Record?
A Procedure is the instruction for how a task should be done; a Record is the completed evidence that it actually was done, on a specific occasion.
Can a company have a valid DOC and still fail a vessel SMC audit?
Yes — the DOC certifies the company's shore-based system; the SMC audit separately verifies that system is genuinely applied on board that specific vessel.
What's the most common SMS gap IMT sees in newer companies?
Well-written Manuals and Procedures with inconsistent Records — the paperwork describing the process exists, but proof the process was actually followed on a given occasion does not.
Test Your Knowledge
5 questions · pass with 4/5 to unlock your Understanding the SMS certificate.
Congratulations!
Badge Earned — Understanding the SMS