Insights

What a Real Internal ISM, ISPS and MLC Audit Covers

Section 12.1 of the ISM Code requires every company to carry out internal safety audits on board and ashore at intervals not exceeding twelve months, a period that may be exceeded by not more than three months in exceptional circumstances. The ISPS Code and MLC 2006 add their own verification cycles.

Done honestly, the internal audit is the cheapest inspection a ship will ever have. It examines the same evidence a Port State Control officer, a flag auditor or a vetting inspector would examine, months earlier and without commercial consequences. Done as a formality, it produces clean paper and leaves the real findings for someone with the power to detain the ship.

4 MIN READ

The ISM audit: does the system describe reality?

An ISM internal audit tests whether the safety management system as written matches the ship as operated. That means walking the procedures where they happen. How a permit to work is actually raised before an enclosed space entry. Whether maintenance records reflect the real condition of the machinery. Whether masters genuinely review the SMS and report nonconformities upward. Whether the Designated Person Ashore has the direct access to the highest level of management that section 4 of the Code requires. Good auditors work from objective evidence: records, interviews and direct observation. They distinguish between a slip and a system failure. A single overdue job is a finding. A planned maintenance backlog that nobody escalated is a nonconformity in how the system manages resources, and it is the kind of pattern that gets recorded as a Port State Control deficiency when it is found on board first.

The ISPS element: security you can demonstrate

The security audit verifies the ship security plan against practice. Access control actually enforced at the gangway. Visitor and stores screening carried out as written. Security levels understood by the crew. Drills and exercises conducted and recorded at the required frequency: the Code's guidance sets drills at least once every three months, with an additional drill within one week where more than 25 per cent of the ship's personnel are replaced at one time by personnel who have not previously participated in any drill on that ship within the last three months, and exercises at least once each calendar year with no more than 18 months between them. The Ship Security Officer should be able to show how the ship interfaces with port facilities, including declarations of security where required. Because most of the ship security plan is restricted material, the internal audit is one of the few structured opportunities to test it end to end, including the parts an external inspector can only probe indirectly.

The MLC element: the human side of compliance

MLC verification covers seafarers' employment agreements, wage accounts paid on time and in full, hours of rest records that reconcile with the ship's actual operations, food and catering, accommodation, medical care and the on-board complaint procedure. Accommodation, food, medical care and welfare are among the most frequently recorded Port State Control findings, and wage and employment agreement failures are among the most serious (Paris MoU Annual Report 2025). The audit should also confirm that the ship is tracking the convention as it changes. The 2022 amendments entered into force on 23 December 2024 and covered items including free drinking water, appropriately sized personal protective equipment and strengthened connectivity provisions. A further set was approved by the International Labour Conference in June 2025 and is expected to enter into force on 23 December 2027, including a strengthened right of shore leave. A system that only reflects the MLC as it stood at certification will drift out of compliance on a known schedule.

Findings are the product, closure is the point

The value of an internal audit is measured in verified closures, not in the elegance of the report. Each finding needs a root cause, a corrective action, an owner and a deadline. The next audit should begin by testing whether the last round of actions actually held. An audit programme that recycles the same findings year after year is documenting a problem, not managing it. Independence matters too. Auditors should not audit their own work. And fleet level analysis of findings, by ship, by department and by clause, tells the office where the system itself needs redesign rather than another reminder memo.

STAY CURRENT

Get New Insights by Email

Practical maritime compliance guidance, sent when we publish. No noise. Unsubscribe at any time.

We use your email only to send insights.

Put This Into Practice

SolarisTech carries out internal ISM, ISPS and MLC audits as an independent third party. Our founder is a qualified ISM, ISPS and MLC auditor and served as Deputy Commissioner of Maritime Affairs for the Republic of the Marshall Islands. Engagements are led by our founder, and every report names the reviewer who wrote it. Our audit work is non-statutory. It gives you and your flag an evidenced view of the system, and the statutory decisions remain with the flag administration and its recognized organizations. Our reports are prepared for the party that instructs us and for the purpose stated in the engagement. Reliance by any other party requires our written agreement.