← Maritime QHSE
Meriden Compliance Insights · Maritime QHSE

False Assurance in Maritime Compliance: When Good Records Hide Poor Control

Documentation can show that a control exists. Only operational evidence can show whether it works.

Maritime companies rarely lack paperwork

They have policies, procedures, certificates, permits, audit questions, training records, performance dashboards and corrective-action systems. These records are necessary. They establish expectations, allocate responsibility and provide evidence that required activities have taken place.

The problem begins when their existence is treated as proof that the underlying risk is controlled.

A procedure describes how work should be done. A permit records the conditions under which work has been authorised. A certificate shows that a ship or management system has been inspected against a defined scope. None of these, by itself, proves that the control is understood, implemented or effective during real operations.

That gap between documented compliance and operational reality is false assurance.

What false assurance means

Assurance is justified confidence that controls are appropriately designed, consistently implemented and effective in practice.

False assurance occurs when an organisation mistakes evidence that a control exists for evidence that the control works.

  • We have a policy for that.
  • It is covered by the safety management system.
  • The permit was signed.
  • The training was completed.
  • The audit found no major non-conformities.
  • The ship holds the required certificate.
  • The dashboard is green.

Each statement may be factually correct. The mistake is assuming that it ends the enquiry.

The four alignments of credible assurance

1. Requirement

What does the applicable regulation, standard or company requirement actually require?

2. Documentation

Has that requirement been translated accurately into the company’s system?

3. Understanding

Do affected personnel understand the control and how to apply it?

4. Practice

Is the control implemented and effective during real work?

When these elements do not align, apparently strong records can conceal weak control.

How an assurance system should validate control

Tracing a regulatory requirement from documentation through to operational practice

1. REQUIREMENTWhat is required? External standards, regulations and rules
2. DOCUMENTATIONIs it captured accurately in the system? Policies, procedures and work instructions
3. UNDERSTANDINGDo affected personnel understand it? Competence, training and awareness
4. PRACTICEIs it implemented and effective in practice? Observation, verification and control effectiveness
VALIDATION COMPLETE

Requirement translated into controls → documentation addresses the requirement → personnel understanding aligns with documented controls → implementation and effectiveness are verified.

Figure 1. A four-stage assurance model for tracing a requirement through to verified operational practice.

When an incomplete system audits itself

I encountered a clear example while reviewing a company’s arrangements under the Maritime Labour Convention, 2006.

The company’s safety management documentation ran to approximately 98 pages, but its coverage of the MLC was limited to roughly half a page. Its internal audit framework contained 16 MLC-related questions. When those questions were compared with the SMS, only six could be traced to identifiable supporting provisions.

The company could point to an MLC section in the SMS and an MLC audit checklist and conclude that the subject was covered. The difficulty was that both the documented framework and the audit criteria were incomplete.

  • the SMS defines too little;
  • the internal audit tests only what the company has chosen to define;
  • satisfactory answers are treated as evidence of compliance;
  • management receives confidence from a framework that has not tested the full requirement.

How an incomplete system can assure itself

How a control gap survives documentation, audit and management review

CONTROL GAP EXISTS
INCOMPLETE SMS COVERAGE
INCOMPLETE AUDIT CRITERIA
MANAGEMENT CONFIDENCE
FALSE ASSURANCE LOOP

A gap is treated as adequately addressed; audit scope follows incomplete criteria; previous positive results reinforce confidence.

Figure 2. Incomplete SMS coverage and audit criteria can create management confidence while leaving the underlying gap unresolved.

Certification provides legitimate evidence, but the MLC itself does not treat a certificate as an unlimited guarantee. Regulation 5.1.1 describes the Maritime Labour Certificate and DMLC as prima facie evidence that the ship has been inspected and that requirements have been met “to the extent so certified.” The same regulation requires an effective system ensuring that working and living conditions “meet, and continue to meet” the Convention’s standards.

Certification is evidence within a defined scope. It does not remove the need for continuing verification.

The certificate existed, but the requirement was not met

On every vessel I personally visited during this review, the Maritime Labour Certificate and DMLC were onboard. When I asked where the crew could see them, the answer was that the documents were retained in the Master’s certificate folder.

The people involved were not deliberately concealing them. They treated the documents like other statutory certificates: valid, onboard and available if an inspector requested them.

Standard A5.1.3 is more specific. It requires the current Maritime Labour Certificate and DMLC to be carried onboard and copies to be posted in a conspicuous place where they are available to seafarers.

The documents existed, but the purpose of the requirement had not been achieved.

The issue was corrected on one vessel, but the same condition was then found on another. That showed that the first response had addressed a local condition rather than the management system.

A practical fleetwide response would have been straightforward: define a consistent conspicuous location and incorporate it into the fleet’s documented arrangements and verification process.

The visible problem had been corrected. The system that allowed it had not.

Internal administrative practice is not regulatory authority

The same review identified gaps involving seafarers’ employment agreements, collective bargaining arrangements, contractual terms and wage information.

Regulation 2.1 and Standard A2.1 require clear, written and legally enforceable employment terms, signed originals for the parties, employment information available onboard, applicable collective bargaining agreements onboard, and wage particulars in the agreement.

Following a company-wide pay rise, updated contracts had not been issued. HR instead placed a note in its system stating that contractual pay had been updated.

Whether that method was legally sufficient would depend on the applicable flag-State law, agreement terms and collective bargaining arrangements. The assurance failure was more basic: an internal administrative method had been adopted without demonstrating how it satisfied the applicable external requirements.

A payroll system may prove that the correct amount was paid. An HR note may prove that the organisation recorded a change. Neither automatically proves that the applicable regulatory and contractual requirements have been met.

A permit does not make work safe

A permit is required because the proposed task presents higher or less routine risk and therefore needs specified conditions before work begins. The permit itself does not make the job safer. Protection comes from the isolations, tests, barriers, competent personnel, communications, rescue arrangements, equipment and worksite readiness behind it.

False assurance arises when the completed document is treated as proof that those controls exist.

For familiar work, a permit issuer may believe that they already know the area and sign without visiting the worksite. The greater danger may be the condition that is different today: another task nearby, changed access, moved equipment, a missing barrier, a live energy source or a work area that no longer matches the plan.

A permit based on yesterday’s knowledge cannot confirm today’s conditions.

Requiring an inspection in a procedure is not enough. The organisation must establish how it will ensure that the inspection actually occurs.

Each control needs a distinct purpose

Risk assessment

Identifies hazards, evaluates risk and defines controls. It should not become a full repetition of the job plan.

Job plan or method

Describes sequence, responsibilities, critical stages, resources, hold points and contingency arrangements.

Permit to work

Authorises a defined higher-risk activity within stated limits and records the conditions required before work begins.

Pre-job briefing

Confirms understanding, focuses attention on critical stages and invites operational input. It should not consist of one person reading every possible hazard while the team disengages.

Start Work Verification Check

Provides final physical verification at the worksite. An independent person asks for controls to be demonstrated: show me the isolation, the barrier, the required equipment, what has changed, and whether all permit conditions are actually in place.

The permit records what should exist. The Start Work Verification Check confirms that it does.

How auditors test whether the system works

A good system can be explained by the people operating it. Valuable evidence often comes from asking personnel to describe their work rather than testing whether they can repeat a procedure word for word.

The discussion can begin simply: Tell me about your role onboard and the work you normally perform.

From there, ask where the documentation is, what each document is for, how planning occurs, whether the person contributes to the briefing, what happens if conditions change, when they would stop, and how the task is closed.

A weak audit reads each checklist question and records the answer received. A stronger audit uses the checklist to confirm coverage but follows the evidence through conversation, documents, records and observation.

The checklist supports the auditor. It should not replace judgement.

When actual practice differs from the procedure

A difference between written procedure and actual practice is not automatically proof that the worker is wrong. It is a reason to investigate.

The person may not know the procedure, may be using an unsupported shortcut, may be compensating for an impractical instruction, may have developed a safer method, or may not know how to request a document change.

A fleet should operate as a learning system. But the existence of a document-change system does not prove that learning occurs. If a work instruction has accumulated 20 unresolved requests, the organisation already has evidence that it may be outdated, unclear or impractical.

Where resources are constrained, the backlog must be prioritised by risk. A minor editorial amendment can wait. A work instruction capable of contributing to injury, non-conformity or detention cannot.

How false assurance moves upward

Senior leaders often genuinely want the system to work properly. The difficulty may arise in middle management, where escalating a weakness means asking for money, people, time, operational disruption or uncomfortable scrutiny.

Issues may therefore be softened, narrowed or treated as isolated. Management review should distinguish between one-off deficiencies and recurring patterns across vessels or activities.

Senior management should receive a clear decision package: what happened, why it happened, what has been tried, why that was insufficient, what must happen next, how urgent it is, the consequences of delay, realistic solution options, and the financial and resource implications.

Closing an action is not proving effectiveness

Systemic issues should not be closed because management has agreed to update a policy. A revised document proves that an action was taken. It does not prove that the problem was solved.

  1. the control was revised;
  2. related documents and forms were updated;
  3. the change was communicated;
  4. affected personnel understood it;
  5. the change was implemented onboard;
  6. observed practice changed;
  7. the intended outcome improved over time;
  8. the original failure stopped recurring.

Until effectiveness has been demonstrated, the organisation has changed its paperwork, not necessarily its control.

Five warning signs of false assurance

1. A self-audit reports no findings

Repeated clean audits in a complex operational system should trigger scrutiny of sampling, depth, interviews, observation and willingness to challenge.

2. Controls are documented or certified but not validated in operation

Policies, procedures, permits and certificates exist, but no one tests whether controls work under actual conditions.

3. Assurance activity reduces anxiety rather than risk

Forms, signatures, meetings and approvals are added because they make the organisation feel protected, without materially improving control.

4. Indicators remain green because they are lagging or aggregated

  • Audit pass rates: high scores where testing was limited.
  • Incident rates: no lost-time injuries while near misses or under-reporting rise.
  • Training completion: 100% completed without testing competence.
  • Corrective-action closure: actions closed administratively without effectiveness review.

5. Crew cannot locate or explain task-specific documentation

If personnel cannot find the relevant document, explain what each stage is for or describe what to do when conditions change, the management system is not functioning as intended.

Operational dilemma: the green fleet dashboard

You are the Designated Person Ashore for a company operating 18 vessels. The management-review dashboard shows 97% audit compliance, no major non-conformities, the lowest lost-time injury frequency in five years, 100% training completion, 96% permit compliance and 94% corrective actions closed on time.

Then several signals emerge: audits relied heavily on records with limited observation; permit issuers signed site checks without visiting; crew could not distinguish the controls; high-risk procedures had unresolved change requests; and an MLC deficiency recurred after closure.

Choice A: preserve confidence while investigating quietly

Continue presenting the dashboard and commission a limited review framed as continuous improvement. This protects short-term confidence but risks later appearing to conceal known warning signs.

Choice B: escalate the uncertainty immediately

Tell senior management that the indicators may not accurately represent operational control, identify what remains uncertain and commission a risk-based independent review.

I would choose Choice B. That does not require declaring the whole SMS ineffective. It requires reporting that several independent signals now call the reliability of the assurance indicators into question.

The numbers may still be correct.
The conclusion drawn from them may no longer be.

AI can make false assurance more convincing

AI does not create false assurance, but it can make it easier to produce and harder to recognise. It can rapidly generate procedures, risk assessments, audit checklists, corrective-action plans, training material and management summaries.

Polished output may appear more complete, current and authoritative than the underlying evidence supports. AI-generated material can reproduce earlier assumptions, copy incomplete controls across multiple documents or introduce plausible but incorrect regulatory statements.

AI can support regulatory comparison, gap identification, document review and preparation. It should not convert unverified information into a final compliance conclusion. Claims still need checking against primary sources, applicability must be confirmed for the vessel and flag, and generated documents must be compared with actual work.

The more convincing the documentation becomes, the more important operational verification becomes.

A practical assurance test

StageQuestions
RequirementWhat requirement is being addressed? Has it been fully mapped? Is the interpretation current and applicable?
DocumentationIs the control accurately documented, current and consistent across procedures, forms and instructions?
UnderstandingCan affected personnel find it, explain its purpose and describe what to do when conditions change?
ImplementationIs the stated control visible in practice? Has the activity been observed? Do records reflect what occurred?
EffectivenessHas the control reduced the intended risk? Are findings recurring? Have outcomes improved?
LearningAre deviations investigated, changes processed, improvements shared and recurring issues escalated?
A completed document may answer an administrative question. Only operational evidence can show whether the organisation is actually in control.

Conclusion

Maritime assurance is not created when paperwork looks correct. It is created when applicable requirements are translated into workable controls, personnel understand why those controls exist, actual conditions are verified and management responds when evidence shows that the system is not working.

Policies, permits, certificates, audits and dashboards remain essential. Their value lies in what they reliably demonstrate, not in their existence.

Compliance is demonstrated not when the paperwork is complete, but when the intended control consistently works under real operating conditions.

The final question is not Is the document complete?

Can the organisation demonstrate that the work, obligation or risk is actually under control?

References

  1. Maritime Labour Convention, 2006, Regulation 2.1 and Standard A2.1 — Seafarers’ employment agreements.
  2. Maritime Labour Convention, 2006, Regulation 5.1.1 — General principles of flag-State inspection and certification.
  3. Maritime Labour Convention, 2006, Regulation 5.1.3 and Standard A5.1.3 — Maritime Labour Certificate and Declaration of Maritime Labour Compliance.