Internal Maritime Audits: Planning, Evidence, Interviews and Corrective Action

Best for: maritime internal auditors, DPAs, QHSE managers, marine superintendents, masters and department heads responsible for verifying the effectiveness of a Safety Management System.

A useful internal audit does more than confirm that documents are present. It tests whether the management system is understood, implemented and effective in controlling real operational risk.

The audit should connect four things: requirement, procedure, evidence and actual practice. Weak audits usually examine only one or two of them.

The audit logic

Requirement → company control → objective evidence → operational reality → finding → corrective action → effectiveness review.

If the audit cannot show that full chain, its conclusions will be difficult to defend.

1. Define the purpose before the checklist

Start by deciding what the audit must establish. Common objectives include:

  • verifying implementation of the company SMS;
  • testing whether previous corrective actions remain effective;
  • reviewing a high-risk activity, vessel or department;
  • checking readiness after significant operational or organisational change;
  • examining recurring incidents, deficiencies or equipment failures;
  • preparing for external verification without turning the audit into a rehearsal.

A generic annual checklist can support coverage, but it should not replace risk-based planning.

2. Build a risk-based audit plan

Planning input Why it matters
Previous audit findings Shows repeat weaknesses and ineffective close-out.
Incidents and near misses Identifies controls that may have failed in practice.
PSC, flag, class and client findings Shows external evidence of management-system weakness.
Operational change New vessels, equipment, routes, crewing or contractors create fresh risk.
Overdue defects and actions Indicates control, ownership or resource problems.
Performance trends Helps target areas where records appear acceptable but outcomes are deteriorating.

The audit programme should cover the full SMS over time, while individual audits should focus effort where consequence, change or weak evidence justifies it.

3. Prepare an evidence map

For each audit topic, identify:

  • the applicable requirement;
  • the company procedure or control;
  • the expected records;
  • the people who perform or supervise the work;
  • the physical location or equipment to inspect;
  • the sampling period;
  • known weak points or contradictions to test.

This prevents the audit from becoming a sequence of disconnected questions.

4. Sample across time, people and evidence types

A reliable sample should not consist only of the newest or best-presented records. Use a mixture of:

  • recent and older records;
  • day and night operations where relevant;
  • different departments and ranks;
  • routine and abnormal work;
  • completed and open actions;
  • paper, digital and physical evidence;
  • records created before and after a known event or system change.

Sampling should be large enough to support the conclusion, but focused enough to allow depth.

5. Use interviews to test understanding

Interviews are strongest when they ask people to explain how work is actually controlled.

Useful interview prompts

  • What happens when this equipment is unavailable?
  • Who must be informed and who can authorise continued operation?
  • Show me where the current procedure is kept.
  • What changed after the last incident or drill?
  • How do you know this action was effective?
  • What would cause you to stop this job?
  • What happens if shore management does not respond?

Avoid leading questions that reveal the expected answer. Interview role holders separately where possible and compare explanations with the procedure and records.

6. Trace evidence from record to reality

For each important sample, follow the full trail:

  1. Read the requirement and company procedure.
  2. Examine the completed record.
  3. Speak to the person involved.
  4. Inspect the equipment, location or control.
  5. Check follow-up, escalation and closure.

Contradictions are often more valuable than missing paperwork. Examples include:

  • a maintenance task shown as complete while the defect remains;
  • a drill record describing performance that crew cannot explain;
  • a permit form that conflicts with the isolation arrangement;
  • hours-of-rest records that do not match known work activity;
  • a closed action with no evidence of effectiveness.

7. Distinguish observations from findings

Element What to record
Requirement The applicable external or company expectation.
Objective evidence What was seen, read, heard or demonstrated.
Gap How the evidence failed to meet the requirement.
Extent Whether the issue is isolated, repeated or systemic.
Risk The operational or management consequence requiring priority.

A finding should be factual and reproducible. Avoid vague statements such as “poor safety culture” unless supported by specific evidence and a defined requirement.

8. Write findings that can be acted on

A strong finding contains:

  • a clear requirement;
  • specific objective evidence;
  • the exact non-fulfilment;
  • relevant sample details;
  • enough context to support investigation without prescribing an untested solution.

Do not weaken a valid finding merely to avoid disagreement. Equally, do not escalate an issue beyond what the evidence supports.

9. Control corrective action properly

Corrective action should address why the gap existed, not only repair the immediate example.

Stage Minimum expectation
Immediate correction Control the current unsafe or non-compliant condition.
Cause analysis Identify contributing system, competence, resource or supervision factors.
Corrective action Change the system so recurrence becomes less likely.
Ownership Name the accountable person and completion date.
Verification Confirm the action was completed as described.
Effectiveness Test later whether the intended result was sustained.

10. Close the audit with management decisions

The closing meeting should confirm:

  • the scope and sample limitations;
  • each finding and its evidence;
  • immediate risks requiring control;
  • responsible managers and target dates;
  • how disagreements will be resolved;
  • who will verify completion and effectiveness;
  • which issues require fleet-wide review or management escalation.

Internal audit checklist

  • ☐ Scope, objective and criteria defined.
  • ☐ Auditor independence and competence confirmed.
  • ☐ Previous findings and operational changes reviewed.
  • ☐ Evidence map and sampling plan prepared.
  • ☐ Records sampled across time and departments.
  • ☐ Relevant personnel interviewed separately.
  • ☐ Physical conditions and equipment checked.
  • ☐ Contradictions between records and practice investigated.
  • ☐ Findings contain requirement, evidence and gap.
  • ☐ Immediate risks escalated before audit close.
  • ☐ Corrective-action owners and dates assigned.
  • ☐ Effectiveness review method defined.
  • ☐ Systemic lessons communicated beyond the audited area where necessary.

Common audit failures

  • Using the same checklist every year without adjusting for risk.
  • Reviewing only selected records prepared by the audited department.
  • Accepting completed forms as proof of effective control.
  • Interviewing only senior officers or managers.
  • Writing findings without a clear requirement.
  • Prescribing solutions before the cause has been investigated.
  • Closing actions on document issue alone.
  • Failing to test whether previous corrective actions worked.
  • Using AI-generated audit conclusions without verifying source evidence.

Using AI in internal audits

AI may assist with planning, evidence indexing, question generation, document comparison and draft report structure. It should not replace auditor judgement, determine physical condition remotely, invent evidence or classify findings without competent review.

Every AI-assisted conclusion should remain traceable to verified source material and an accountable auditor.

Related Meriden tools

Official reference point

The ISM Code requires companies to conduct internal safety audits and periodically evaluate the effectiveness of the Safety Management System. Audit planning and reporting should be aligned with the current official Code, applicable flag-state instructions and company procedures.


Use note: This guide supports internal audit planning and evidence control. It is not legal advice, flag-state or class approval, or a substitute for competent auditing against current requirements and company-specific procedures.