Document control is the part of ISM most people file under paperwork, and it’s a narrower, sharper requirement than that filing suggests. Clause 11.1 requires the Company to establish and maintain procedures to control all documents and data relevant to the safety management system. Clause 11.2.2 is more specific still: changes to documents are reviewed and approved by authorized personnel. Not generated. Not auto-applied. Reviewed, by someone, and approved, by someone — two separate steps, both attributable to a name.
The Quiet Failure Mode in Document Control
Plenty of AI products describe themselves as improving from feedback, and for a general-purpose assistant that’s a reasonable selling point. For a tool sitting on top of a safety management system, it’s a governance problem dressed up as a feature. If a wrong answer simply nudges a model’s future behaviour with no visible trail, the SMS is being edited — functionally, that’s what a change to what a crew member gets told amounts to — without anyone reviewing or approving anything. An auditor asking who approved this procedure change would get no answer, because there was no procedure change in the ISM sense. There was just a system quietly getting different.
Two Gates, One Decision
ISM 5.2 already answers who has authority on the ship: the master has the overriding authority and responsibility to make decisions with respect to safety and pollution prevention. That’s why nothing raised from the ship side moves without Master’s Review first — a crew member flagging a wrong answer, or raising any other observation, needs the Master’s sign-off before it leaves the vessel at all.
But that sign-off governs escalation, not document control. Whether the observation actually becomes a change to the SMS is a separate document control decision, made ashore.
That’s where ISM Clause 4 does the actual work. The Company designates a person ashore with direct access to the highest level of management, responsible for monitoring the safety and pollution-prevention aspects of every ship’s operation — the DPA. Whatever clears Master’s Review on the ship side lands with the same editor an office-raised item goes to directly through Office Review — one decision point regardless of where it started.
Either way, the loop closes back to whoever raised it: included or closed, but not left unanswered. Nobody who flags something finds out only by checking later whether anything changed.
The Signal Nobody Has to Flag
The first two gates depend on someone noticing a wrong answer and doing something about it. There’s a third signal that doesn’t need anyone to notice anything: what people are actually asking SMS Search for, in aggregate, visible at the admin level — including searches that don’t return a good match at all. That’s a different kind of gap than a wrong answer.
A wrong answer means the procedure exists and the tool got it wrong. A search with no good match at all can mean the procedure was never there to begin with — the exact blind spot a structural gap analysis can’t see, because a gap analysis checks the manual’s contents, not what the fleet is actually asking it. Search analytics turns that blind spot into a visible pattern an admin can act on, before it turns into an incident that makes the gap obvious the hard way.
Where Wayfinder Fits In
These signals all feed the same governed path rather than separate ones. A flag on a wrong answer clears Master’s Review if it started on the ship, or goes straight to Office Review if it started ashore — either way, it lands with the DPA and editor, who decide whether it becomes a change and notify whoever raised it either way.
Aggregate search data with no good match surfaces at the admin level as a candidate for the same review. Nothing enters document control without that decision being made by someone ISM already names for the role — the Master governing what leaves the ship, the DPA and editor deciding what actually changes the manual.
It’s worth being precise about what that doesn’t mean: not every flag or every search gap results in a change. Plenty won’t. What it means is that the ones that do go through a reviewed, approved, attributable path — not a model quietly getting smarter in a way nobody can point to.
The Practical Point
The real test for an AI search tool sitting on top of your SMS isn’t whether it improves after getting something wrong. Most will, eventually, one way or another. The test is whether you could name who reviewed the fix and who approved it if an auditor asked — the same test 11.2.2 already applies to every other change your document control procedure governs, and the same two names — the Master, the DPA — the Code already puts on that decision.
See how a flagged answer becomes a tracked review in Wayfinder →
More from the Wayfinder Series
→ Explore the Wayfinder Platform — See Wayfinder in Action





