What is the ISM Code — and does your vessel need it?
If you operate a commercial vessel and have encountered the ISM Code, you have probably also encountered conflicting advice about whether it applies to you, what it actually requires, and what happens if you get it wrong. This article offers a clear, practical explanation — written from the perspective of someone who has managed a Safety Management System at sea and audited them from the shore side.
What the ISM Code is
The International Safety Management Code — the ISM Code — is a mandatory IMO standard adopted under SOLAS Chapter IX. Its purpose is straightforward: to establish an international standard for the safe management and operation of ships and for pollution prevention.
In plain terms, the ISM Code requires a shipping company to have a documented Safety Management System (SMS) — a set of policies, procedures, and records that define how the vessel is operated safely. The SMS must cover everything from maintenance and emergency procedures to crew training, incident reporting, and the communication lines between ship and shore.
The Code also requires a company-level point of accountability ashore — the Designated Person Ashore (DPA) — who has direct access to the highest level of management and can be reached at all times when the vessel is operating.
Which vessels does it apply to?
The ISM Code applies to ships engaged in international voyages in the following categories:
- Passenger ships, including high-speed passenger craft
- Oil tankers, chemical tankers, gas carriers, bulk carriers and cargo high-speed craft of 500 gross tonnage (GT) and above
- Other cargo ships and mobile offshore drilling units of 500 GT and above
For commercially operated yachts and superyachts, the threshold matters: ISM applies to commercially operated passenger vessels on international voyages. A superyacht operating commercially under a Red Ensign Group flag (Isle of Man, Cayman Islands, Channel Islands) will generally fall within this requirement once it exceeds 500GT or carries passengers on international voyages. Smaller commercially operated yachts typically fall under the MCA Large Yacht Code (LY3), which contains its own SMS requirements — but the principles of good safety management apply regardless of which framework governs your vessel.
What does compliance actually look like?
A company subject to the ISM Code must hold two certificates:
- A Document of Compliance (DOC) — issued to the company, covering the types of ships it operates
- A Safety Management Certificate (SMC) — issued to each individual vessel
Both are issued by a Recognised Organisation (a classification society authorised by the vessel's flag state — Lloyd's Register, DNV, Bureau Veritas, ABS, ClassNK, and others) or directly by the flag state administration. They follow a statutory audit, are renewed periodically, and verified through annual or intermediate audits.
What the certificates represent, though, is not the end of the story — they represent a point-in-time assessment. What happens between those statutory audits is where genuine compliance either exists or doesn't.
The internal audit — and why independence matters
ISM Code Clause 12.1 requires companies to carry out internal safety audits to verify that safety and pollution-prevention activities comply with the SMS. The Code specifically requires that auditors be independent of the activities being audited — meaning the engineer cannot audit his own maintenance records, and the captain cannot be the sole auditor of bridge procedures he has authored.
That requirement for independence from the activity is the floor, not the ceiling. The deeper value of internal audit comes from genuine objectivity — an assessor who brings no assumptions about how things are done, no loyalty to existing procedures, and no hesitation in recording what the evidence actually shows rather than what the SMS says should be happening.
This is where good audit methodology matters. A structured internal audit follows a consistent process: planning against defined criteria, gathering objective evidence, assessing findings impartially, and reporting clearly — including findings that are uncomfortable. These are not bureaucratic steps; they are what separates an audit that actually improves safety from one that confirms what everyone already believes.
The most common pattern in SMS audits: the system is well-written but not well-lived. The procedures exist on paper; the records tell a different story. A rigorous internal audit closes that gap — before a statutory auditor or port state control officer does it for you.
Critically, internal audit findings are confidential to the company — they exist to drive improvement, not to create a paper trail for regulators. That confidentiality is itself a cornerstone of effective auditing: it allows genuine findings to be reported and addressed without fear of external consequence.
Evidence-based assessment — what auditors actually look at
A well-conducted ISM internal audit is evidence-based. It does not rely on what crew members say should be happening — it examines what the records show actually happened. Drill logs, maintenance records, non-conformity reports, hours of rest records, safety committee minutes — these are the objective evidence against which the SMS is assessed.
An SMS with no non-conformity reports is almost always an SMS where the reporting culture hasn't taken hold, not one where nothing has gone wrong. Port state control officers in New Zealand and Australia know this — an empty NCR log is a finding in itself.
Risk-based thinking throughout the SMS
The ISM Code requires companies to identify risks and implement safeguards — but the Code itself doesn't prescribe exactly how. Good safety management means applying risk-based thinking proportionately: the hazards relevant to a 45-metre superyacht on a Pacific circuit are not the same as those for a bulk carrier on a fixed route, and the SMS should reflect that. A Safety Management System that has been lifted wholesale from a template and applied without adaptation to the specific vessel, its operations, and its trading areas is one that will struggle under scrutiny — both in an audit and at the quayside.
What port state control checks in New Zealand and Australia
Port state control in both New Zealand (Maritime NZ) and Australia (AMSA) actively checks ISM compliance for visiting foreign-flagged vessels. PSC officers can board your vessel, examine your SMS, check your certificates, and detain the vessel if serious deficiencies are found. A missing or expired SMC, an unreachable DPA, or an SMS that clearly does not reflect actual operations are all grounds for detention.
For vessels arriving in this region on a Pacific circuit — often after a long passage from French Polynesia or following a refit period — PSC attention at the first port of call is a real risk if compliance preparations have been deferred during the voyage. The time to close nonconformities is before you arrive, not after a PSC officer has recorded them.
Summary
The ISM Code requires commercially operated vessels above certain thresholds to have a documented Safety Management System, a company-level Document of Compliance, a vessel-level Safety Management Certificate, and a Designated Person Ashore available at all times. For vessels planning passages to New Zealand, Australia, or the Pacific, ensuring all of these are current and genuinely implemented — not just on paper — before arrival is the single most valuable compliance step you can take.
If you are unsure whether the ISM Code applies to your vessel or what your current compliance position looks like, a short initial conversation is usually all it takes to get clarity.
Have a question about this topic?
Book a free 15-minute call with Craig Hopkins — practical answers, no jargon.