A shipping company does not simply write a Safety Management System and declare itself certified. Certification is a formal process run by an independent certification body (for ISM, the flag Administration or an organisation authorised by it), and it repeats in a predictable cycle: request → certification audit → certificate → surveillance visits → recertification audit.
The same pattern applies whether the system is an ISM Safety Management System (leading to the company's Document of Compliance and each ship's Safety Management Certificate) or an ISO management system such as ISO 9001 (quality), ISO 14001 (environment) or ISO 45001 (occupational health and safety).
The five steps of the certification process
- Request. The company applies to the certification body, defines the scope of the system, and the body plans the audit: scope confirmation, audit team, dates and logistics.
- Certification audit. Carried out in two phases — documentation first, implementation second.
- Obtaining the certificate. After a successful audit and closure of non-conformities, the certificate is issued, valid for three years. Under ISM this is the company's DOC; each ship then receives its SMC once the DOC is verified onboard.
- Surveillance visits. Periodic visits during the three-year cycle confirm the system is still living and improving, not just documented.
- Recertification audit. A full review before expiry — audit history, incidents, complaints, changes — renews the certificate for a new three-year cycle.
The certification audit: two phases
Phase 1 — documentation review
Phase 1 examines the system on paper. The auditor checks the manuals, procedures and plans for compliance with the standard, confirms that internal audits and management reviews have been carried out, and verifies the company is ready for the implementation audit. Phase 1 also sets the scope and plan for Phase 2.
Phase 2 — implementation audit
Phase 2 checks that the documented system is actually in use: records, drills, maintenance, reporting and corrective actions, verified through interviews ashore and onboard and through objective evidence. Non-conformities must be corrected — a major non-conformity blocks the certificate until it is closed.
After the certificate: surveillance and recertification
The certificate is not a one-off event. During its three years of validity, the certification body carries out surveillance visits (typically annually) to confirm ongoing compliance. Findings are classified and must be closed.
Before expiry, the recertification audit reviews the entire cycle. It is normally planned about three months before expiry, because an expired certificate means the system is not certified — and charterers, flag States and port State control will ask for it.
| Milestone | When | What happens |
|---|---|---|
| Certification audit | Year 0 | Phase 1 + Phase 2; certificate issued |
| Surveillance visit 1 | ~Year 1 | Implementation and improvement verified |
| Surveillance visit 2 | ~Year 2 | Trends, incidents, previous findings reviewed |
| Recertification audit | Before Year 3 ends | Full cycle review; new 3-year certificate |
What this means for the crew
For a Master or senior officer, certification visits are not a formality. The auditor will talk to the people who operate the system: do you know where the procedures are, how you report a near-miss, how a drill is recorded, how the planned maintenance system links to the safety system? A certificate is earned on paper in Phase 1 — and kept by the crew in practice.