ISM and ISPS: Differences, responsibilities, and training evidence in a shipping company

ReedereiISMISPSMaritime SecuritySchulungsnachweise

AI-generated

ISM and ISPS are often named together because both affect the vessel and the shore organisation. That shortcut is too coarse for decisions. ISM structures safe management, safe working practices, and learning from deviations. ISPS structures security risks, access, information, and responses to threats. A company that mixes both in one list loses accountability, creates duplicate instruction, and may be unable to explain who can make which decision when it matters. A dependable learning architecture connects both systems while keeping their purposes visibly distinct. See also: training offering for shipping companies.

This article is an operating guide, not legal advice and not a substitute for a flag State, classification society, or authority instruction. It helps management, the Designated Person Ashore, the Company Security Officer, and vessel-side owners turn requirements into a manageable learning and evidence process. The starting point is not who has watched a presentation once. It is the concrete task: which situation must the role recognise, which decision must it make, whom must it inform, and which record later shows that the capability exists and remains current?

Two systems, two governance questions

For the ISM system, the core question is: can the organisation manage safety and environmental protection reliably, handle deviations, and review the effectiveness of its safety management? The learning plan therefore includes roles in reporting, investigation, work approval, risk assessment, maintenance, emergency readiness, and management review. The crucial point is the link between procedures and real work. A chief engineer needs different practice cases than a crewing colleague or a shore-based manager. The IMO's official SOLAS overview is a useful starting point, but concrete requirements must always be checked against the vessel, flag, and approved procedures.

For the ISPS system, the core question is different: how does the organisation recognise, assess, and handle security threats to the ship and port facility without leaving information flows or access decisions to chance? According to the IMO's official explanation, the ISPS Code in force under SOLAS Chapter XI-2 provides the framework for a mandatory security regime in international shipping. Its objectives include cooperation, roles, information exchange, security assessments, and plans. The training consequence is clear: not everyone needs the same knowledge, but every role must reliably understand its triggers, reporting paths, and limits. See also: IMO explanation of SOLAS XI-2 and ISPS.

The practical boundary can be explained through observation. A missed maintenance check, an unsafe work approval, or a recurring near deviation initially belongs in safety-management logic. An unauthorised access attempt, suspicious information, or a changed threat situation initially belongs in security logic. One event can affect both systems. In that case, the company needs an agreed handover point rather than two parallel reports. The existing compliance training matrix for vessel, shore, and port provides the right way to think about this: consider the task, role, location, trigger, learning objective, and evidence together.

Port scene with containers and vesselsAI-generated
Safety and security processes meet at handovers between vessel, shore, and port.

Define roles first, then assign learning

Start with a role map, not a course catalogue. For each role, define four things: decision scope, information need, escalation path, and deputy. In the ISM context, this may include the master, chief engineer, shipboard safety owner, DPA, technical management, crewing, and executive management. In the ISPS context, it particularly includes the Company Security Officer, Ship Security Officer, and interfaces with port facilities and authorities. One person may wear several hats, but the plan must show which function is active in which situation. Only then do exercises and records remain reliable through personnel changes.

A blanket statement that cybersecurity belongs to IT is not enough for the shore organisation. A security event can arise through voyage planning, crew communications, suppliers, remote access, or port communications and must enter the responsible process. Roles therefore need to know when not to investigate alone, but to preserve, report, and involve the competent owner. This matters particularly where maritime security and digital resilience meet. The lessons from NIS2 training for management and employees help prevent accountability, reporting behaviour, and management oversight from disappearing into a technical checklist.

A dependable deputy arrangement answers more than who signs during holiday cover. It defines what information the deputy receives, which approvals it may take over, which decision it must document, and when the original role is informed on return. Test the arrangement with a scenario: the usual contact is unavailable, a report arrives outside business hours, and vessel, shore, and port need different information. If the deputy then exists only on an organisation chart, the problem is not a missing course but a missing operating process.

Make training an executable routine

A useful learning path combines concise fundamentals, role-specific case work, and observable application. Fundamentals explain purpose, terms, and accountability. Case work asks the role to assess a situation, notify the right party, and justify a decision. Application can be an exercise, walkthrough, or controlled task in daily operations. Assign each activity to a role and trigger instead of sending one long mandatory course to everyone. The article on mandatory training without spreadsheet chaos shows how status, target group, date, and accountable owner can come together in dependable control.

Evidence should answer a question, not merely contain a file. For every material learning activity, keep at least the role, reason, learning objective, format, date, participants, outcome, accountable person, and storage location. For an exercise, add the scenario, decisions taken, open actions, and a follow-up date. For a refresher, record whether the procedure, vessel, route, threat situation, or role changed. This makes it clear why the activity was appropriate. For the form of the record, the guide to audit-ready training records is a useful complement.

Separate attendance, understanding, and capability. An attendance list shows only that someone was present. A short knowledge check can test terms and reporting paths. Only a practical decision in a case shows whether the person can prioritise and escalate under time pressure. This logic is useful beyond shipping as well. The documentation approach from online occupational-safety instruction shows why objective, delivery, feedback, and evidence belong together. For maritime roles, the same chain should be connected to actual vessel and shore processes.

View of the interface between vessel and portAI-generated
Exercises become effective when they model real handovers and clear information paths.

Exercise, review, and improve instead of merely checking a box

Plan three types of exercise: a role exercise for an individual trigger, a handover exercise between vessel and shore, and a management exercise for sparse information and competing priorities. The role exercise tests whether the first action is understood. The handover exercise tests whether information arrives complete, timely, and traceable. The management exercise tests whether leaders set priorities, release resources, and document decisions coherently. After every exercise, hold a short debrief, define a few implementable actions, and assign a clear owner. Otherwise, the record becomes storage rather than improvement.

A monthly control meeting does not need to be long. Review new or changed roles, due refreshers, open actions, missing evidence, and changes to procedures or routes. Once a quarter, a small sample can test quality: can the company trace from a role to the learning objective, from the objective to the exercise, and from the exercise to the record? Once a year, leadership checks whether the role map still fits the fleet, ports, suppliers, and threat situation. This rhythm detects gaps early and makes the system less dependent on individual people.

An additional quality review prevents a tidy course plan from becoming detached from reality. Each month, select one completed activity and review it backwards: did the person actually fit the role, was the reason documented, did the case match the approved procedure, was a decision visible, and were open actions followed up? Then review it forwards: did the observation trigger an adjustment to instruction, procedure, manning, or exercise? This double view separates mere documentation from real improvement. It also helps keep the boundary between ISM and ISPS clear. A technical deviation should not be labelled a security event merely because it involves a digital system. Conversely, unusual access must not disappear into a general fault report. A short subject review with the named owners creates clarity, protects confidential information, and gives management a dependable basis for priorities and resources.

Conclusion: Shared platform, distinct decision paths

ISM and ISPS belong in the same operating learning landscape, but not in the same vague mandatory list. ISM focuses on the ability to manage safety and environmental performance through working procedures. ISPS focuses on the ability to recognise security threats, handle information safely, and respond in a coordinated way. A strong shipping company connects both through roles, handovers, exercises, and evidence. Start with a role map, define a few observable learning objectives for each role, test the handover between vessel and shore, and retain results so a second person can understand the decision. Training then becomes a governance tool rather than year-end evidence.

Sources and context

The legal and technical position must be assessed separately for each vessel, flag State, and factual situation. Relevant sources include the applicable international requirements, national implementations, certification requirements, and the shipping company's approved procedures. The official IMO sources below explain SOLAS as well as SOLAS Chapter XI-2 and the ISPS Code. This article does not replace an assessment for an individual case.

Structure the training concept for your shipping company

ConformBase

Turn knowledge into training that works.

Bring compliance, privacy and security awareness into a format your people want to complete — with certificates and audit-ready evidence.

Start free trialAsk about custom courses →

Frequently asked questions

What is the main difference between ISM and ISPS?

ISM governs safety management and environmental protection through procedures, roles, reporting, and improvement. ISPS governs security risks, information paths, access, and responses to threats. The systems meet at interfaces but retain different triggers and decision paths.

Which roles need dedicated ISM or ISPS training?

It depends on the actual task. Relevant vessel-side and shore-side roles may make decisions, receive reports, apply plans, pass on information, approve actions, or act as deputies. Assign learning objectives to the task and trigger, not only to a job title.

What training evidence is useful for exercises?

A good record includes role, reason, learning objective, format, date, participants, scenario, decisions taken, outcome, open actions, owner, and storage location. The company can then explain not only attendance but operational relevance and follow-up.

← All posts

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial