SuperbaKnowledge Demonstration release
Platforms
ENIT
Operational guide · SMS process

Management Review

The moment when the Company — not the DPA alone — formally takes responsibility for verifying that the SMS truly works, not just that it exists on paper.

ISM CodeManagement Reviewtop managementSMS

Operational Explanation

The Management Review is the periodic assessment of the continuing adequacy and effectiveness of the Safety Management System, which the ISM Code assigns to the Company (§12.3). It is not an audit (which verifies point-in-time compliance), but a strategic evaluation: is the SMS still achieving the Company's safety and environmental protection objectives? Does it need to be changed?

Direct involvement of the top of the organisation is the practical point of this exercise: it exists to prevent safety from being delegated solely to the DPA or technical offices, without real visibility and commitment at the highest decision-making levels. But it is worth stating exactly how the Code expresses this, because it does not use the phrase «top management»: evaluation of the effectiveness of the SMS is attributed to the Company (§12.3), the Designated Person's direct access to the “highest level of management” is imposed by §4, and the commitment of the top is stated in the Preamble (§6). The difference matters the moment an auditor asks which paragraph the claim rests on.

Regulatory Reference

ISM Code, par. 1.4 (Functional Requirements) and par. 12 (Company Verification, Review and Evaluation). The specific provision is §12.3: “The Company should periodically evaluate the effectiveness of the SMS in accordance with procedures established by the Company”.

Two points, on the number and on the words, because both circulate wrongly. On the number: until 31 December 2014 this provision was §12.2; resolution MSC.353(92), in force from 1 January 2015, inserted a new §12.2 on verifying delegated ISM tasks and renumbered the paragraphs that followed. Anyone still citing §12.2 for the effectiveness of the SMS is reading a text that expired more than ten years ago.

On the words: the expression «top management» appears nowhere in the ISM Code. §12.3 attributes the evaluation to the Company, and the Company is a subject defined by §1.1.2, not a rung of the hierarchy. That does not make the top irrelevant: §4 requires the Designated Person to have “direct access to the highest level of management”, and the Preamble, at §6, states that “the cornerstone of good safety management is commitment from the top”. The substance holds; the citation does not. In an audit, presenting «top management involvement» as an explicit requirement of the Code invites a challenge you lose, because the auditor asks for the paragraph number and that paragraph does not exist.

Scope of Application

Every ISM-certified Company, typically on an annual basis (or at intervals defined in its own internal procedure), before or in preparation for the applicable external verifications: annual and renewal for the Document of Compliance, intermediate and renewal for the Safety Management Certificate. The DOC has no intermediate verification, and the Code does not require the review to be held immediately before each external verification: the Company procedure sets the interval.

Procedure / How to Complete It

  1. Gather inputs: outcomes of internal and external audits, open/closed NCs, Near Misses and incidents, crew feedback, complaints, PSC/vetting inspection results.
  2. Convene the meeting with documented attendance of whoever decides on resources, not of the DPA alone: the Code does not use the phrase “top management”, but §4 requires the Designated Person to have direct access to the “highest level of management”, and without that level in the room the review cannot produce decisions on resources.
  3. Assess the adequacy of resources assigned to the SMS (personnel, training, maintenance and safety budget).
  4. Identify trends, areas for improvement and any need to amend SMS procedures or objectives.
  5. Record decisions and assigned actions, with an owner and a deadline, and verify their implementation at the next review.

Practical Example

Example minutes: "2026 Management Review — Reviewed 18 NCs (3 major, 15 minor) and 42 Near Misses for the year. Trend identified: 6 minor NCs linked to overdue preventive maintenance on two fleet vessels. (“minor NC” is a category of practice: the ISM Code defines only the major non-conformity — see the dedicated page.) Decision: review of resources allocated to the maintenance department and a special internal audit targeted at the two vessels within the following quarter."

What Typically Goes Wrong

During external DOC renewal audits, certification auditors raise as an NC a Management Review reduced to a completed form without real, documented discussion, because in that case there is no evidence that the evaluation required by §12.3 was carried out; top-management attendance is not prescribed by the Code, but without the level that decides on resources the review is unlikely to produce the decisions it must produce: this undermines the credibility of the entire management system in the certifier's eyes.

Common Mistakes Mistake Library

MistakeConsequenceHow to avoid it
Management Review reduced to a completed form without real discussionNC in certification audit for lack of evidence that the review was conducted at the level that decides on resourcesDocument the meeting with minutes, participants and concrete decisions
Data analysis (NC, Near Miss) purely quantitative, without looking for trendsSystemic problems remain invisible until an incident or a serious deficiency occursAlways include trend analysis, not just event counts
Management Review decisions without an owner or a deadlineAgreed actions are never completedAlways assign an owner and a date to every decided action

What the PSCO Checks

The Management Review is not typically subject to direct verification by Port State Control Officers (PSCOs) (who inspect the ship, not the shore offices), but it is a central element of external ISM audits (DOC/SMC) and is often requested during oil major vetting.

Operational Tips

Preparation checklist

Educational checklist. This summary supports learning and preparation only. It does not replace the vessel’s approved procedures, manuals, statutory documents, company SMS, or applicable official requirements. Completing it demonstrates neither compliance nor readiness for an inspection: it shows that a list has been read, not that the ship is in order. Always verify the current documents carried on board.

FAQ

How often must the Management Review be conducted?
The ISM Code does not impose a fixed frequency, but requires it to be periodic; established practice at most Companies is annual, often in preparation for the external audit.
Can the DPA conduct the Management Review alone?
No — but the correct reason is not the usual one. The Code does not name «top management»: §12.3 attributes the evaluation of the effectiveness of the SMS to the Company, and the DPA is a function of the Company, not the Company. The DPA prepares and presents the data; the review and the decisions bind the organisation, and §4 guarantees the DPA direct access to the top precisely so that they do not decide alone.
What distinguishes the Management Review from an internal audit?
The internal audit verifies point-in-time compliance of procedures and records (§12.1, at intervals not exceeding twelve months); the Management Review is the Company's periodic evaluation of the overall effectiveness of the SMS over time (§12.3).

Related Topics

Last substantive revision of this page: 29 August 2026 · page fingerprint d546c4d62024