Management systems that pass audits because they work.
ISO 9001, 14001 and 45001. ISM Code, ISPS Code and MLC 2006. Implemented, maintained and audited with your team — never in place of it.
- ISM Code · DoC · SMC
- ISPS Code · ISSC
- MLC 2006
- ISO 9001
- ISO 14001
- ISO 45001
If your company needs a Document of Compliance or a Safety Management Certificate, we are the solution.
The ISM Code requires a Safety Management System that is documented, implemented ashore and on board, and verified by the flag Administration or a Recognized Organization. The DoC certifies the Company; the SMC certifies each ship.
We build the SMS with the people who will run it — the Designated Person Ashore, the office, the Masters and the crews — train them, run the internal audits and prepare the company for the initial verification, the interim certificates and the five-year cycle of annual DoC and intermediate SMC verifications. The same approach serves the ISPS Code (Ship Security Plan, CSO/SSO, ISSC) and MLC 2006 (DMLC Part II, Maritime Labour Certificate).
Implement. Maintain. Audit.
Across the ISO standards and the maritime instruments — integrated into one system, not six parallel ones.
ISM Code — DoC and SMC readiness
Shore-based and on-board SMS: policies, responsibilities, Designated Person Ashore, procedures, emergency preparedness, records and the evidence the auditor will ask for. Preparation for interim, initial, annual, intermediate and renewal verifications.
ISPS Code — SSP and ISSC readiness
Ship Security Assessment, Ship Security Plan, Company and Ship Security Officer functions, drills and records for the International Ship Security Certificate.
MLC 2006 — DMLC Part II
Shipowner's measures for the Declaration of Maritime Labour Compliance Part II, on-board inspection readiness and the Maritime Labour Certificate.
ISO 9001 · 14001 · 45001
Implementation, maintenance and internal audits of the quality, environmental and occupational health and safety management systems, on the latest revisions, integrated with the maritime instruments.
Internal audits and pre-certification audits
Audits by auditors who are not selling you the certificate — so the findings are honest and closed before the external auditor arrives.
Audit accompaniment
We prepare the operation, organise the evidence and are present during the external audit, ashore and on board.
Training
Training in the requirements and the routine of the system, so your team masters it and sustains compliance day to day.
Continuous maintenance
Management review, indicators, non-conformities, corrective actions and the improvement cycle — the system stays alive after the certificate.
The instruments — and who issues the certificate.
We prepare; the flag, the Recognized Organization or the registrar verifies and issues.
| Flag Administration / Recognized Organization | ISM Code | Document of Compliance for the Company and Safety Management Certificate for each ship, verified by audit. |
|---|---|---|
| Flag Administration / Recognized Organization | ISPS Code | Approved Ship Security Plan and International Ship Security Certificate. |
| Flag Administration / Recognized Organization | MLC 2006 | DMLC Parts I and II and Maritime Labour Certificate after inspection of working and living conditions. |
| Certification body (registrar) | ISO 9001 · 14001 · 45001 | An auditable system, maintained and evidenced over time. |
| ANP (Brazil) | SGSO | Operational safety management articulated with the company's management system, for units in Brazil. |
Honest about the limit.
We are not a certification body — and that is deliberate.
What GRICCO takes on
- Implementation and maintenance of the system, with the people who will use it.
- Internal audits and preparation for the external audit or verification.
- Handling non-conformities and findings raised.
- Training the teams in the system's routine.
What only the certifier does
- Issuing the DoC, SMC, ISSC, Maritime Labour Certificate or ISO certificate.
- Auditing and certifying the same operation (conflict of interest).
- Guaranteeing approval in a third-party audit.
- Maintaining the system in place of your team.
From the gap analysis to the certificate — and beyond.
It is common to find that part of the system already exists; it is just not evidenced.
- 01
Gap analysis
The company and the ships against the standard or the code; what exists, what is missing, what is written but not practised.
- 02
Design and integration
One system for the applicable standards and codes, built on what the company already does.
- 03
Implementation and training
Procedures, records and training ashore and on board, with the people who will run the system.
- 04
Internal audit
Honest findings, corrective actions and the evidence file for the external auditor.
- 05
External verification
We accompany the flag, the Recognized Organization or the registrar — and close any findings.
- 06
Maintenance
Management review, indicators and the next verification in the cycle.
Ship managers, shipowners and offshore companies — certifying for the first time or keeping a certificate alive.
Companies setting up a Safety Management System from scratch to obtain the DoC and SMC; fleets integrating ISM, ISPS and MLC with ISO; and operations arriving in Brazil that need the system Brazilian authorities also expect to find.
Modular or turnkey, fixed price. Always alongside the client's HSE, marine and quality leaders.
Questions about ISM, ISPS, MLC and ISO.
What is the difference between the DoC and the SMC?
The Document of Compliance is issued to the Company — the entity that has assumed responsibility for operating the ships — after verification that its Safety Management System complies with the ISM Code. The Safety Management Certificate is issued to each ship after verification that the Company and its shipboard management operate in accordance with the approved SMS. A ship cannot hold an SMC without its Company holding a valid DoC covering that ship type.
How long does it take to obtain the DoC and SMC?
It depends on the starting point. A company with an existing but undocumented practice can be ready for the interim verification in a few months; building the SMS from scratch takes longer. Interim certificates allow operation while the full verification is scheduled. The initial diagnostic indicates the critical path.
Do you issue the certificates?
No, and that is deliberate. Certificates are issued by the flag Administration or by a Recognized Organization acting on its behalf; ISO certificates by an accredited registrar. We implement, maintain, audit internally and prepare for the external verification. Because we do not sell certificates, we have no incentive to say the system is ready when it is not.
Can ISO, ISM, ISPS and MLC be integrated into a single system?
Yes, and that is what avoids the bloat. Much of the requirement repeats across the standards and codes; keeping them in parallel systems multiplies procedures without adding control. Integration is how the system stays in use.
What does an internal ISM audit check?
Whether the SMS as described is actually practised on board and ashore: defined responsibilities, procedures genuinely used, consistent records, non-conformity handling and the ability to respond to an emergency. The internal audit exists to find that before the external one does.
We already hold the certificates. Why would we need you?
To keep them. Annual DoC and intermediate SMC verifications, ISO surveillance audits and renewal cycles find systems that stopped living in the routine. We maintain the system — management review, indicators, non-conformities, internal audits — so the next verification confirms what already works.
Tell us which certificate you need — or which one you need to keep.
We respond with a gap read and the critical path to verification.