ISM Code Internal Audit of Safety Management System
An ISM Code internal audit checklist for shipboard Safety Management Systems, organized to verify implementation, evidence, and closeout of findings across the required annual audit cycle.
Trusted by frontline teams 15 years of frontline software AI customization in seconds
Built for: Maritime Shipping · Tanker Operations · Bulk Carriers · Passenger Vessels · Offshore Support Vessels
Overview
This template is an ISM Code internal audit checklist for a shipboard Safety Management System. It is structured to follow the 12 ISM elements in a practical audit sequence, starting with scope, vessel details, auditor independence, and prior corrective actions, then moving through policy, authority, resources, shipboard operations, emergency preparedness, non-conformities, maintenance, documentation, and management review.
Use it when you need a repeatable annual SMS audit that checks both implementation and evidence. It is especially useful before management review, after a serious incident, when a vessel changes crew or operating profile, or when the company wants to verify that shore-side support and shipboard procedures are actually working. The template is built to surface deficiencies, non-conformities, and overdue corrective actions, not just confirm that documents exist.
Do not use it as a substitute for flag-state inspections, class surveys, or port state control. It is also not meant for a quick housekeeping walkthrough; the value comes from reviewing records, interviewing crew, observing critical operations, and checking that emergency and maintenance controls are functioning. If the vessel is in lay-up, under conversion, or outside normal operating conditions, the scope should be adjusted so the audit reflects the actual SMS in use. The result should leave the auditor with a clear evidence trail and the operator with actionable findings tied to specific ISM elements.
Standards & compliance context
- The template aligns with the ISM Code’s requirement for internal verification of the Safety Management System and annual review of implementation and effectiveness.
- Its policy, authority, resources, and emergency preparedness prompts support the broader expectations of flag-state and company SMS oversight under maritime safety management practice.
- The maintenance, drills, and documentation sections help demonstrate control of safety-critical equipment and records in a way that supports port state and class scrutiny.
- Where applicable, the audit can also support related fire-life-safety expectations under NFPA-based vessel safety programs and company emergency procedures.
- If the vessel handles hazardous cargo or regulated operations, the audit can be expanded to reflect additional environmental and operational controls required by the operator’s SMS and applicable authorities.
General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.
What's inside this template
Audit Scope, Vessel, and Auditor Details
This section matters because it establishes whether the audit is valid, in scope, and supported by the right evidence before any findings are recorded.
- Audit date recorded and within annual interval requirement
- Vessel, company, and audit location identified
- Auditor independence and competence confirmed
- Previous audit findings and overdue corrective actions reviewed
- Audit scope includes shipboard and shore-side SMS interfaces
- Audit evidence package attached
ISM Code Element 1-2: Safety and Environmental Protection Policy
This section matters because the policy should be current, communicated, and visible in day-to-day operations, not just filed in the SMS manual.
- Safety and environmental protection policy is current, signed, and posted or readily available
- Policy is communicated to crew and relevant shore staff
- Objectives and measurable targets for safety and pollution prevention are defined
- Evidence of policy review and management endorsement is available
- Policy implementation examples observed during walkthrough
ISM Code Element 3-4: Company Responsibility, Authority, and Designated Person
This section matters because crew need clear reporting lines and a reachable shore-side contact when safety or pollution concerns arise.
- Company responsibilities and authority are defined in the SMS
- Designated Person Ashore (DPA) is identified and contactable
- Master's overriding authority is documented and understood
- Crew can describe reporting lines for safety and pollution concerns
- Organizational chart and emergency contact list are current
ISM Code Element 5-6: Master's Responsibility, Resources, and Personnel
This section matters because the Master’s authority, crew competence, and available resources determine whether the SMS can be executed safely.
- Master demonstrates authority to make safety decisions without delay
- Crew levels and qualifications are adequate for safe operation
- Required certificates, endorsements, and medical fitness records are current
- Crew familiarization and job-specific training records are available
- Adequate resources, spares, and support are available to maintain safe operations
ISM Code Element 7-8: Shipboard Operations and Emergency Preparedness
This section matters because critical work and emergency response must be controlled, practiced, and ready at the point of use.
- Critical shipboard operations have approved procedures available at point of use
- Permits, checklists, and risk assessments are completed for controlled operations
- Emergency drills are conducted at required intervals and recorded
- Crew can demonstrate emergency response roles and muster responsibilities
- Emergency equipment, alarms, and escape routes are unobstructed and operational
ISM Code Element 9-10: Non-Conformities, Accidents, and Maintenance
This section matters because the audit should show whether the vessel identifies problems, investigates them, and keeps safety-critical equipment in service.
- Non-conformities and deficiencies are recorded, investigated, and closed out
- Accidents, near misses, and hazardous occurrences are reported per SMS procedure
- Preventive and corrective actions are tracked to completion
- Planned maintenance system covers safety-critical equipment and intervals are met
- Maintenance backlogs present a risk to safe operation
ISM Code Element 11-12: Documentation, Verification, and Management Review
This section matters because controlled documents, internal verification, and management review are what keep the SMS current and effective.
- SMS documentation is controlled, current, and accessible to users
- Obsolete documents are removed from use or clearly marked
- Internal verification and management review are completed at required intervals
- Audit findings are summarized with root cause and corrective action owner
- Inspector signature
How to use this template
- 1. Enter the audit date, vessel name, company, location, and auditor details, then confirm the audit falls within the annual interval and that the auditor is independent and competent.
- 2. Review the previous audit report, open findings, and overdue corrective actions before the walkthrough so repeat issues and unresolved risks are included in scope.
- 3. Walk through each ISM element in order, collecting objective evidence from documents, interviews, logs, drills, permits, maintenance records, and direct observation.
- 4. Record each deficiency or non-conformity with a clear description, the related SMS element, the evidence reviewed, and whether the issue is safety-critical or operational.
- 5. Assign corrective action owners and due dates, then verify closure against the evidence package and summarize root causes and management review inputs.
- 6. Sign off the audit only after obsolete documents, unresolved actions, and any scope gaps have been addressed or formally escalated.
Best practices
- Start with the previous audit and open corrective actions so the current audit tests whether the SMS actually improved.
- Interview crew at the point of work, because a procedure that exists on paper but cannot be explained on deck is a real non-conformance.
- Treat emergency drills, permit-to-work records, and maintenance logs as evidence of implementation, not as paperwork to collect at the end.
- Flag safety-critical deficiencies separately from administrative gaps so management can prioritize immediate risk reduction.
- Check shore-side interfaces such as the DPA, document control, and maintenance support, because SMS failures often start off the vessel.
- Photograph or attach objective evidence at the time of the audit, especially for missing postings, blocked access, or defective equipment.
- Use the same section order on every vessel so fleet trends and repeat findings are easier to compare.
- Close the loop on root cause, not just the symptom, or the same deficiency will reappear in the next annual audit.
What this template typically catches
Issues teams running this template most often surface in practice:
Common use cases
Frequently asked questions
What does this ISM Code internal audit template cover?
This template covers the shipboard Safety Management System audit required under the ISM Code, organized around the 12 elements in Part A. It prompts the auditor to verify policy, authority, resources, operational controls, emergency preparedness, non-conformities, maintenance, documentation, and management review. It is designed to capture evidence, not just answers, so the result can support corrective action and follow-up.
How often should this audit be used?
Use it at least once every 12 months, with any allowed extension handled according to your company’s SMS and applicable flag or class expectations. Many operators also use the same structure for interim spot checks after major incidents, vessel changes, or repeated deficiencies. The key is that the annual cycle is documented and the prior findings are reviewed before the next audit begins.
Who should run the audit?
The auditor should be independent of the area being audited and competent in ISM Code requirements and shipboard operations. In practice, that often means a trained internal auditor from the company or a qualified shore-side representative who is not directly responsible for the vessel’s day-to-day execution. The template includes prompts to confirm independence and competence so the audit record is defensible.
Does this template replace statutory inspections or class surveys?
No. This is an internal SMS audit tool, not a substitute for flag-state inspections, port state control, class surveys, or other external verification. It helps you find deficiencies before an outside authority does, and it creates evidence that the company is checking implementation of its own procedures. You can use it alongside those external regimes, but it should not be treated as the same thing.
What are the most common mistakes when using an ISM audit checklist?
The biggest mistake is treating the audit like a yes/no form and skipping evidence. Another common issue is failing to review overdue corrective actions from the previous audit, which hides repeat non-conformities. Teams also miss shore-side interfaces, such as DPA contactability, document control, and maintenance support, even though those are part of the SMS.
Can this template be customized for different vessel types?
Yes. You can tailor the evidence prompts for tankers, bulk carriers, container ships, passenger vessels, offshore support vessels, or mixed fleets while keeping the ISM structure intact. The section order and core audit logic should stay the same, but the examples of critical operations, drills, permits, and maintenance items should match the vessel’s actual risk profile.
What evidence should be attached to make the audit useful?
Attach the audit date, vessel identification, scope, prior findings review, supporting records, photos where appropriate, and the corrective action log. For operational sections, include drill records, permit-to-work samples, maintenance records, training and familiarization evidence, and any relevant logs or checklists. The more the audit points to objective evidence, the easier it is to close findings and demonstrate compliance.
How does this help with corrective action tracking?
The template is built to capture non-conformities, root cause, owner, and closure status in one place. That makes it easier to assign actions, follow up overdue items, and show management review what was actually fixed. It also helps prevent repeat findings by linking the issue back to the SMS element that failed.
How is this different from an ad hoc vessel walkthrough?
An ad hoc walkthrough may find obvious issues, but it usually does not verify all 12 ISM elements or preserve a consistent evidence trail. This template gives you a repeatable audit structure, so each vessel is reviewed against the same expectations and gaps are easier to compare across the fleet. It also reduces the chance that important shore-side responsibilities or documentation controls are overlooked.
Related templates
Go deeper on the topic
-
Predictive scheduling laws — also called fair workweek laws or secure scheduling — require employers in covered industries to publish employee schedules...
-
Overtime calculation is the process of applying federal, state, local, and contractual rules to hours worked to determine the correct pay — including...
-
A near-miss is an event that could have caused injury or damage but didn't — a slip that didn't fall, a load that shifted but didn't drop, a machine that...
-
Lockout/tagout (LOTO) is the procedure for controlling hazardous energy — electrical, hydraulic, pneumatic, mechanical, thermal, chemical — before...
-
Artificial intelligence in the workplace: boost productivity, streamline tasks, and empower employees with smarter, more meaningful work.
-
Intranet file naming conventions that improve search, reduce clutter, and help employees find the right document fast.
-
Discover why manufacturing teams need mobile tools — from real-time safety alerts to on-the-go training and frontline recognition. See how MangoApps helps.
-
Discover 7 common intranet platform failures that exclude frontline workers—and the specific capabilities that close the gap for deskless teams.
Ready to use this template?
Get started with MangoApps and use ISM Code Internal Audit of Safety Management System with your team — pricing built for small business.