Training for Effective ISPS Auditing

The comprehensive security regime for international shipping adopted by the IMO in December 2002 includes a number of amendments to SOLAS, the most far reaching of which enshrine the International Ship and Port Facility Security Code, which contains detailed security related requirements for Governments, port authorities and shipping companies.

The ISPS Code requires that shipping companies (Part A 9.4.8) and port facilities (Part A 16.3.13) include within their security plans ‘Procedures for Auditing the Plan’. For some companies, the persons responsible for the provision and maintenance of maritime security have little experience in the audit process.

ISPS auditing, like any other form of quality or safety audit, is a process based upon evidence collection and fact gathering.

This process is unfortunately sometimes seen as complicated and cumbersome, a view occasionally reinforced by some practitioners who incorrectly audit against their own views and interpretations, not against the required standards and regulations. This often leads to the personnel who are being audited viewing the process as a witch hunt, which clearly it should not be. The process should be seen positively as part of an ongoing improvement process.

It is important to ensure that Audits of Ship and Port Facility Security Plans are conducted effectively and that those undertaking the task do so in a logical and consistent way.

These auditors should ideally be independent of the system being audited, so that a fresh eye can be brought to bear.

This will allow any deficiencies to be identified, recorded and the necessary corrective measures to be put in place.

It should also clearly identify the positives, something often overlooked. The process should clearly encourage. By taking this approach the best principles are applied.

It is important that ISPS auditors audit only against the Code, the security plan and regulatory requirements. This means that Part A must be fully covered, since it is mandatory. Any elements of Part B which Administrations have adopted, such as in Europe the requirements of EU Regulation 725:2004 must be included. Further, the audit needs to review and verify elements of SOLAS V and XI and the actual procedures and requirements of the security plan. In other words, can we substantiate that we do what we say we do. Both port facilities and ships should have appropriate records maintained to provide the necessary evidence. For ships, these are clearly identified in Part A Section 10. For port facilities there is not such clear guidance but Section 10 provides a suitable indication of what records ports should consider in order to be seen to act with due diligence. Administrations may specify what specific records they require and will set time limits for the retention of such records.

To assist companies and their staff in conducting effective audits, Lairdside Maritime Centre have recently introduced an ISPS Internal Auditors Course.

Phil Davies, Short Courses Manager at Lairdside said, ‘This course is aimed at those who are tasked with conducting ISPS Audits and who may have little or no knowledge of the process.

However the course will also benefit those who are familiar with the audit process through ISM and ISO9001 Auditing, but who may not have detailed knowledge of the ISPS Code’.

Focusing on the ISPS requirements as part of a management system, practical examples and checklists are used throughout the course to guide delegates though the process in stages. Delegates are encouraged to use a quality management approach throughout to develop their auditing skills.

MJInformation No: 22249