ISM Code Internal Audits: How to Prepare Your Safety Management System

An ISM internal audit is not a formality to survive; it is the mechanism that keeps a safety management system honest between external verifications. For the DPA and safety team, a well-run internal audit surfaces the small gaps before a flag state auditor or a port state control officer does, when the cost of fixing them is far lower.

The problem is that internal audits often get treated as a box-ticking exercise, which is precisely how the findings that lead to detentions slip through. Here is how to prepare an internal SMS audit properly, what auditors examine, and where companies most often fall short.

What Is an ISM Code Internal Audit?

An ISM Code internal audit is a systematic evaluation of a company's Safety Management System (SMS) to verify that safety and pollution-prevention activities actually comply with the ISM Code and the company's own procedures. Unlike an external audit conducted by a flag state or Recognized Organization for certification, an internal audit is carried out by the company itself.

Internal audits are conducted in two places: on board every ship subject to the ISM Code, and within the company's shore-based operations. Both are required because the SMS is a single system spanning ship and shore, and a gap in either undermines the whole. For the full background on the ISM Code, its structure, and the certification framework, see the guide on understanding the ISM Code and guidelines.

The purpose is not to catch people out. It is to demonstrate that the SMS is a living system that is genuinely implemented, not a set of manuals sitting unread on a shelf.

How Often Are Internal SMS Audits Required?

Internal safety audits must be carried out at intervals not exceeding 12 months. This requirement comes directly from paragraph 12.1 of the ISM Code, which applies to both shipboard and shore-based activities.

The Code allows one narrow exception. In exceptional circumstances, the 12-month interval may be exceeded by not more than three months, and the company must be able to document and explain the exceptional circumstances that prevented the audit. Some flag administrations impose additional requirements for exceeding the interval, such as seeking prior authorization, so the exception should be treated as a genuine last resort rather than a routine extension.

Missing the interval without a documented exceptional circumstance is itself a non-conformity, and a straightforward one for an external auditor to identify.

What Internal Auditors Check

An internal audit examines whether the SMS is implemented in practice, not just written down. The audit typically focuses on several core areas.

Document Control and SMS Manual Currency

Auditors verify that SMS documents are controlled, current, and available to the personnel who need them. Obsolete documents must be removed from circulation, revisions must be tracked, and the version aboard the ship must match the controlled master. Outdated procedures still in use are a common finding.

Non-Conformity Tracking and Corrective Actions

The non-conformity process is where many companies are found wanting. Auditors check that non-conformities, near-misses, and hazardous occurrences are reported, investigated for root cause, and tracked through corrective action to verified closure. A log full of open findings with no closure evidence signals an SMS that identifies problems but does not resolve them.

Crew Familiarity With SMS Procedures

Documentation means nothing if the crew cannot apply it. Auditors assess whether shipboard personnel understand the SMS procedures relevant to their roles, from emergency response to permit-to-work systems. Familiarization records, drill performance, and direct questioning during the shipboard audit all feed this assessment.

Preparing for Your Internal Audit

Effective preparation treats the audit as a genuine health check rather than an inspection to pass. The practical steps are consistent across well-run companies:

  • Confirm the audit schedule keeps every ship and the shore office within the 12-month interval, with no gaps.
  • Assign auditors who are independent of the area being audited, as the ISM Code requires under paragraph 12.5, unless company size genuinely makes this impracticable.
  • Review the open non-conformity log and close out or progress every outstanding item with documented evidence before the audit.
  • Confirm the SMS manual and all procedures aboard are the current controlled versions.
  • Check that familiarization and training records are complete and up to date for the current crew.
  • Verify drills and exercises have been carried out and recorded on schedule.

Common Non-Conformities Found in Internal Audits

Knowing where audits typically find fault lets a company address the gaps proactively:

  • Obsolete or uncontrolled SMS documents still in use aboard.
  • Non-conformities logged but never closed out with corrective-action evidence.
  • Overdue drills or incomplete drill records.
  • Familiarization records missing for recently joined crew.
  • Maintenance of critical equipment not carried out or recorded at the required intervals.
  • The internal audit interval itself was exceeded without a documented exceptional circumstance.

ISM Code Publications to Support Your Audit

A well-prepared audit rests on the current reference texts. The ISM Code and Guidelines, 2018 Edition provides the Code text itself along with guidelines for implementation, guidance on the DPA role, near-miss reporting, and maritime cyber risk management, the standard against which the SMS is audited.

For practical audit preparation, the Guidelines on the Application of the ISM Code, 6th Edition 2024 is especially useful, because this edition adds a dedicated chapter on internal audits to help companies with ongoing compliance, alongside a toolkit of checklists for familiarizing crew and writing procedures. For a DPA building or refining an internal audit program, it is the most directly relevant reference. Both titles are available in the ANS IMO publications range.

Audit to Improve, Not Just to Pass

An ISM internal audit done well is one of the most valuable tools a safety management system has: a scheduled, honest look at whether the system works in practice, with time to fix what does not before it becomes a detention. Prepare for it as a genuine review, keep the 12-month interval, and close your non-conformities, and the external audit takes care of itself. Shop ISM Code publications and compliance references, or contact American Nautical Services at +1 (954) 522-3321 or sales@amnautical.com.

Frequently Asked Questions

Here are answers to common questions about ISM Code internal audits.

How often must internal ISM audits be conducted?

Internal safety audits must be carried out at intervals not exceeding 12 months, both on board and ashore, under paragraph 12.1 of the ISM Code. In exceptional, documented circumstances, the interval may be exceeded by no more than three months.

What happens if an internal audit finds a major non-conformity?

A major non-conformity requires immediate corrective action, because it represents a serious threat to safety or the environment, or a failure to implement an ISM requirement effectively. It must be addressed through root-cause analysis and corrective action tracked to closure. A major non-conformity found during external verification must be corrected before a DOC or SMC can be issued or renewed.

Who can conduct an ISM Code internal audit?

Internal audits should be conducted by trained auditors who are independent of the area being audited, as required by paragraph 12.5 of the ISM Code, to maintain objectivity. This independence requirement may be relaxed only where the size and nature of the company make it genuinely impracticable.

What is the difference between an internal and external ISM audit?

An internal audit is conducted by the company itself to verify its own SMS compliance, at intervals not exceeding 12 months. An external audit is conducted by the flag state or a Recognized Organization to issue or renew the Document of Compliance and Safety Management Certificate. Both assess the same SMS.

What are the most common ISM internal audit findings?

Common findings include obsolete or uncontrolled documents still in use, non-conformities logged but not closed out, overdue or unrecorded drills, incomplete crew familiarization records, and critical-equipment maintenance not carried out or recorded at required intervals.

What is a non-conformity under the ISM Code?

A non-conformity is an observed situation where objective evidence indicates a requirement of the ISM Code or the company's SMS has not been met. A major non-conformity is a more serious deviation posing a threat to safety or the environment, or a systematic failure to implement a Code requirement, and requires immediate corrective action.

GO TO FULL SITE