An internal audit programme is the only part of the ISM framework where a company inspects itself, and that makes it the most revealing thing an external auditor looks at. Run properly, it finds problems before a recognised organisation or a port state officer does, and the record of those findings being identified, corrected and verified is the strongest available evidence that the safety management system is genuinely working. Run as a box-ticking exercise — a checklist hurried through the week before the external audit — it stops being a safeguard and becomes the finding itself, because an audit programme that never raises anything tells an auditor either that nobody is looking or that nothing gets reported. Both conclusions are worse than the non-conformities the programme should have caught. The difficulty for ship managers is that the requirement is deceptively simple to state and genuinely demanding to run across a fleet: audits onboard and ashore at intervals not exceeding twelve months, conducted by people independent of what they audit, with every finding driven through to verified closure and fed into management review. This guide covers what Section 12 actually requires, how findings escalate when they are not closed, who can audit, and how to run a programme rather than an annual event. To hold that programme across your fleet, book a demo or start a free trial.

COMPLIANCE GUIDE · SHIP MANAGERS
ISM Code Internal Audit Programmes for Ship Managers in 2026
Scheduling audits onboard and ashore, recording findings, driving corrective actions to verified closure, and proving the safety management system works in the years between DOC renewals.

Early Warning System, or Biggest Finding

The internal audit programme occupies an unusual position. It is simultaneously a requirement to be satisfied and the primary evidence that everything else in the system is functioning — which is why external auditors examine it so closely and why its weaknesses are so costly.

The failure mode is well documented and widespread. Many operators treat internal audits as an administrative obligation, working through a checklist shortly before the external audit falls due, recording few or no findings, and filing the result. An experienced auditor reads that pattern immediately. A programme producing almost nothing across a fleet does not suggest an exceptionally well-run operation; it suggests audits that are not searching, or a reporting culture where people do not raise what they find. Either interpretation points at the safety management system itself, and a systemic failure of implementation is precisely what constitutes a major non-conformity. The inverse is equally true and far more useful: a company that can show it identified a significant non-conformity internally, analysed its root cause, corrected it and verified the correction demonstrates a mature, functioning system. Findings are not a mark against the programme. Their absence is.

What Section 12 Actually Requires

The obligations are compact but each carries operational weight, and several are commonly under-served in practice.

12 months
The audit interval, onboard and ashore
Internal safety audits must be carried out both on board and ashore at intervals not exceeding twelve months, verifying that safety and pollution-prevention activities comply with the safety management system. The shore-side audit is as mandatory as the shipboard one and is the half more often neglected.
+3 months
The exceptional extension, documented
In exceptional circumstances the interval may be exceeded by not more than three months, but the circumstances must be documented by the company. This is a narrow relief for genuine operational impossibility, not a scheduling buffer, and repeated use of it invites scrutiny.
Delegated
Verification of delegated ISM tasks
The company must periodically verify that everyone undertaking delegated ISM-related tasks is acting in conformity with its responsibilities under the Code. Outsourcing an activity does not outsource accountability for it, so third-party providers fall within the audit scope.
Timely
Corrective action by the responsible manager
Management personnel responsible for the area involved must take timely corrective action on deficiencies found. Responsibility sits with the area owner rather than the auditor, which is why findings need named owners rather than being held in a central queue.

One further point is easily missed: internal audits are in addition to external audits, not a substitute for them. The external cycle — initial verification, annual verification of the Document of Compliance, intermediate verification of the Safety Management Certificate, and renewal — runs independently, and the internal programme is what keeps the system healthy between those points. To schedule both cycles visibly across a fleet, book a demo or start a free trial.

The Escalation Ladder

Findings do not sit still. Understanding how they escalate when left unresolved explains why closure discipline matters more than the initial severity of anything raised.

Observation
Not a non-conformity, but an indication of a potential weakness or an opportunity to improve. Addressing it is not mandatory — yet auditors track trends across observations, so a recurring theme in observations becomes an argument about the system rather than a note about an incident.
Minor non-conformity
An observed situation where objective evidence shows a specified requirement has not been fulfilled. It does not pose a serious threat, but it must be corrected within an agreed timeframe — and failure to close it means it is raised again as a major non-conformity at the next audit.
Major non-conformity
A deviation posing a serious threat to personnel or vessel safety or to the environment — or a lack of effective and systematic implementation of an ISM requirement. It demands immediate corrective action and must be corrected within three months.
Certificate withdrawal
An uncorrected major non-conformity leads to withdrawal of the Document of Compliance and the Safety Management Certificate — which are, in effect, the operating licence for international trading, and the DOC covers the whole managed fleet.

The ladder makes the practical argument for the programme. A minor non-conformity closed properly within its timeframe ends there. The same finding left open does not remain minor — it is re-raised as a major at the next audit, and the clock that follows a major runs to three months before certification is at risk. Almost every serious ISM outcome begins as something small that nobody closed.

Findings that close on time never climb the ladder
Scheduling audits across a fleet, recording findings with owners and deadlines, tracking corrective actions through to verified closure, and surfacing anything approaching its window — this is what keeps minor findings from becoming major ones. Marine Inspection runs that loop across every vessel and the shore organisation. Book a demo to see it on your fleet, or start a free trial.

Who Can Audit, and Why Independence Matters

Two conditions govern who may conduct an internal audit, and both are tested when an external auditor reviews the programme.

The first is competence. Internal auditors must have completed relevant auditor training covering the principles of auditing and the requirements of the Code, and the company itself is responsible for specifying those competence requirements under the Code's provisions on resources and personnel. The second is independence: auditors should be independent of the area being audited. This is where small organisations struggle, because the person who knows a process well enough to audit it is frequently the person who runs it — and an auditor examining their own work produces a finding-free report that persuades nobody.

Practical solutions are familiar to most managers. Cross-auditing between vessels lets a master or chief engineer audit a sister ship rather than their own. Shore staff can audit vessels and vessel staff can contribute to shore audits, satisfying both halves of the requirement while breaking the self-review problem. Where an organisation is genuinely too small to achieve independence internally, external auditors can be engaged for the internal programme, which remains an internal audit for the Code's purposes. What does not work is a nominal separation that everyone understands to be fictional; auditors ask who audited what, and the answer needs to survive the question. To manage auditor assignment and independence across a fleet programme, book a demo or start a free trial.

A Programme, Not an Event

The most consequential design choice is whether the twelve-month requirement is met by one large annual exercise or by a continuous programme that happens to satisfy it. The difference in outcome is substantial.

The annual event
One audit per vessel, timed near the external audit
Findings surface with little time to correct them properly
Pressure to record few findings, since each one is now urgent
The system is examined once and assumed healthy for eleven months
The rolling programme
A planned schedule spreading audits across the year and the fleet
Focused spot checks and mini-audits on specific areas between full audits
Findings raised early, with time to correct and verify properly
Weak areas revisited sooner rather than waiting a full cycle

A rolling programme also handles the parts of the scope that a single annual sweep tends to skip. Internal audits should review corrective actions arising from previous audits, from port state control inspections and from flag state surveys — a genuinely useful step that closes the gap between external findings and internal follow-up, and one that is far easier to perform meaningfully several times a year than once. Spreading the programme across the fleet calendar also means audit capacity is not concentrated into a few weeks, which is usually what forces the superficial checklist in the first place.

Closing the Loop into Management Review

An internal audit that produces findings and nothing else is incomplete. The Code closes the loop by requiring that audit results feed a periodic management review, and that review is where the company evaluates whether the safety management system is actually effective.

The review should take into account the results of internal audits, non-conformities reported by personnel, the master's reviews, analysis of non-conformities, accidents and hazardous occurrences, and any other evidence of possible failure of the system — including findings raised by external parties such as port state control. That list is worth reading as a specification for what the audit programme needs to produce. If the review is to consider trends in non-conformities, the non-conformity register has to be maintained and analysable rather than a scatter of closed forms. If it is to weigh external findings alongside internal ones, both need to sit in the same record. And if the master's review is part of the input, it needs to have been conducted and documented rather than assumed.

This is also the mechanism by which the programme demonstrates effectiveness between certification points. The external verification cycle touches the company periodically; the internal audit and management review cycle is what an auditor examines to judge whether the system was alive in between. A company that can show a full year of audits conducted on schedule, findings raised and closed with evidence, trends analysed, and decisions taken at management review has answered the central question before it is asked. To build that evidence trail continuously, book a demo or start a free trial.

Frequently Asked Questions

How often must ISM internal audits be conducted?
Internal safety audits must be carried out both on board and ashore at intervals not exceeding twelve months, verifying that safety and pollution-prevention activities comply with the safety management system. In exceptional circumstances, documented by the company, this interval may be exceeded by not more than three months — but that is a narrow relief for genuine operational impossibility rather than a scheduling buffer, and repeated reliance on it attracts scrutiny. Two points are commonly under-served. The shore-side audit is as mandatory as the shipboard one and is the half more often neglected. And internal audits are in addition to external audits rather than a replacement for them, since the external verification cycle for the Document of Compliance and Safety Management Certificate runs independently.
Who is allowed to conduct an internal audit?
Two conditions apply. Auditors must be competent — having completed relevant auditor training covering auditing principles and the requirements of the Code — with the company itself responsible for specifying those competence requirements under the Code's provisions on resources and personnel. And auditors should be independent of the area being audited, which is where smaller organisations struggle, because the person who knows a process well enough to audit it is often the person who runs it. Workable approaches include cross-auditing between vessels so a master or chief engineer audits a sister ship rather than their own, shore staff auditing vessels and vessel staff contributing to shore audits, or engaging external auditors to conduct the internal programme where genuine independence cannot be achieved in-house.
What happens if a non-conformity is not closed?
It escalates, which is why closure discipline matters more than the initial severity of a finding. A minor non-conformity is an observed situation where objective evidence shows a requirement has not been fulfilled; it does not pose a serious threat, but it must be corrected within an agreed timeframe, and failure to close it means it is raised again as a major non-conformity at the next audit. A major non-conformity is a deviation posing a serious threat to personnel or vessel safety or to the environment, or a lack of effective and systematic implementation of an ISM requirement, and it must be corrected within three months. An uncorrected major leads to withdrawal of the Document of Compliance and Safety Management Certificate. Almost every serious ISM outcome starts as something small that nobody closed.
Is it a problem if our internal audits find very little?
Usually yes, and it is one of the clearest warning signs an external auditor looks for. A programme producing almost nothing across a fleet does not read as evidence of an exceptionally well-run operation; it reads as audits that are not searching, or a reporting culture in which people do not raise what they find. Either interpretation points at the safety management system itself, and a lack of effective and systematic implementation of an ISM requirement is precisely what constitutes a major non-conformity. The opposite is far stronger evidence: a company that identified a significant non-conformity internally, analysed its root cause, corrected it and verified the correction demonstrates a mature, functioning system. Findings are not a mark against the programme — their absence is.
What should an internal audit actually cover?
Beyond verifying that safety and pollution-prevention activities comply with the safety management system across its elements, the scope should include reviewing corrective actions arising from previous internal audits, from port state control inspections and from flag state surveys. That step closes the gap between external findings and internal follow-up, and it is one of the more valuable parts of the programme. The company must also periodically verify that anyone undertaking delegated ISM-related tasks is acting in conformity with its responsibilities under the Code, so third-party providers fall within scope — outsourcing an activity does not outsource accountability for it. Common blind spots worth examining deliberately include the non-conformity register itself, emergency contact details and muster arrangements after crew changes, documented master's reviews, and cyber risk within the system.
How do internal audits connect to the management review?
The management review is where the loop closes and the company evaluates whether the system is genuinely effective. It should take into account the results of internal audits, non-conformities reported by personnel, the master's reviews, analysis of non-conformities, accidents and hazardous occurrences, and any other evidence of possible system failure — including findings raised by external parties such as port state control. Read the other way, that list is a specification for what the audit programme must produce: a maintained and analysable non-conformity register rather than scattered closed forms, internal and external findings held in the same record so trends can be weighed together, and documented master's reviews rather than assumed ones. This cycle is also how a company demonstrates the system was alive between external verification points.
Prove the System Works Between Renewals
External verification touches the company periodically. The internal audit programme is what shows the safety management system was working in between — audits conducted on schedule onboard and ashore, findings raised by independent auditors, corrective actions closed with evidence before they escalate, and trends carried into management review. Marine Inspection runs that programme across the fleet with scheduling, finding capture, corrective-action tracking and audit-ready records. Book a demo or start a free trial.