A third-party ship manager does not need to guess at its software requirements, because they are written into the contract it already signs. BIMCO's SHIPMAN 2024, approved in March 2024 and published the following month, added four clauses that between them describe the architecture almost exactly. Clause 21 on Managers' Information Systems gives owners access to ship-related data through the manager's information platform while safeguarding the manager's own intellectual property and digital access. Clause 22 on Vessel's Information and Data was introduced specifically to address the necessity for owners to retain data ownership. Clause 27 covers cyber security. And Clause 40, a new confidentiality provision, binds both parties in respect of all information and data received about the performance of the agreement, with an obligation to ensure that affiliates, subcontractors, employees and agents abide by the same undertaking. Read those four together and the requirement set is unambiguous: owners must be able to see their own vessels, the data must remain theirs, it must be secured, and one owner's information must not reach another. Most managers evaluate platforms on features. The binding requirements are contractual, and a platform that cannot meet them creates exposure rather than inconvenience. Start a free trial of Marine Inspection and test the architecture against your own agreements.
Four Contract Clauses, Four Architectural Requirements
Clause 21
Owner access through your platform
Owners are given access to ship-related data via the managers' information platform, with the manager's intellectual property rights and digital access safeguarded. So owners look into your system rather than receiving extracts — and your platform has to permit that without exposing what makes it yours.
Clause 22
The data belongs to the owner
Introduced to address the necessity for owners to retain data ownership. Management agreements end, vessels move between managers, and when they do the record goes with the ship. Per-owner extraction is therefore a contractual capability rather than a feature request.
Clause 27
Cyber security as a contractual term
Included to implement robust measures protecting digital environments. Your supplier's security posture sits inside an obligation you have accepted to every owner you manage for, which makes it a procurement criterion rather than an IT preference.
Clause 40
Confidentiality, extending to your own staff
Both parties are bound in respect of all information and data received about performance of the agreement, and each must endeavour to ensure that affiliates, subcontractors, employees and agents observe the same undertaking. That last clause is the architectural one: segregation has to hold inside your own organisation, not merely between companies.
The Tension That Defines the Architecture
A managed fleet has to be two contradictory things at once, and resolving that is the entire design problem. Book a Marine Inspection demo and check that both requirements are satisfied simultaneously rather than traded off.
Data must be segregated
Owner A cannot see owner B's vessels, costs, findings or performance
Confidentiality binds employees and agents, so internal access needs scoping too
A superintendent covering two owners sees each owner's ships in that owner's context
Reporting is per owner, matching whatever KPIs that contract established
Extraction on termination takes one owner's data and nothing else
Benchmarking across owners requires care, consent, or aggregation that identifies nobody
Procedures must be common
One safety management system operated across every managed vessel
One equipment hierarchy and naming standard, or nothing can be compared
One definition of priority, overdue and what closing a job requires
One checklist library, varying by vessel type rather than by owner
One reporting and escalation route into your technical function
One audit-ready evidence standard, because your certification covers them all
The resolution is a shared configuration layer over a segregated data layer. Procedures, hierarchy, definitions and checklists are governed centrally and applied to every managed vessel regardless of owner; the records those procedures generate are partitioned by owner and never cross. That is a specific architectural shape, and it is the opposite of what a single-owner fleet requires — which is why platforms built for owners frequently handle it badly, offering either one shared pool or completely separate instances, neither of which is what a manager needs.
The Shared Certificate Nobody Discusses
There is a structural exposure in third-party management that follows directly from how ISM certification works, and it changes how a manager should think about the weakest vessel in the portfolio. Sign up for Marine Inspection and hold every managed vessel to one evidence standard.
How the certification works
Using a third-party manager is a standard and compliant route to fulfilling ISM Code requirements, and the vessel's Safety Management Certificate becomes linked to the manager's Document of Compliance. The manager acts as the operator under international conventions while the owner retains legal title, financial responsibility and strategic control of the asset.
What that means across a portfolio
Every managed vessel is operating under your certification. An audit of your Document of Compliance examines your system as it is implemented across all of them — which means a weakness aboard one owner's ship is a finding against your certification, and your certification is what every other owner's vessel depends on.
The consequence for standards
You cannot let evidence quality vary by owner, however commercially awkward that is. A demanding owner and a hands-off owner must produce records to the same standard, because the certification they share does not distinguish between them. That is the strongest argument available for a common configuration, and it is contractual rather than aesthetic.
Segregate the data, standardise the procedure, and never confuse the two
Owners are entitled to confidentiality over their vessels' information and to ownership of the data itself. They are not entitled to a bespoke safety management system, because the certification under which their vessel trades is yours and covers everybody. When an owner asks for a variation, the useful test is whether the request concerns their data — where the answer is usually yes — or your procedures, where the answer has to be no, and the reason is one you can point to in the certification rather than in a preference.
Reporting to Owners Who Agreed Different Things
Key performance indicators are established during the contracting phase to measure operational efficiency and safety outcomes — which means each owner has negotiated their own, and your reporting has to accommodate that. Schedule a walkthrough and check how per-owner reporting is produced.
Same underlying data
Every managed vessel generates records against the same procedures, in the same structure, to the same evidence standard. That consistency is what makes reporting possible at all and it is not negotiable per owner.
Different presentation
One owner wants monthly technical summaries, another wants quarterly with budget detail, a third is a financial institution wanting evidence of asset preservation rather than operational narrative. All three are the same data, arranged differently.
Different indicator sets
KPIs agreed at contracting differ between owners, so the report has to reflect what that owner actually signed rather than a house template. A platform where reporting is fixed forces manual assembly, which is where manager margin quietly goes.
Direct access as well
Clause 21 contemplates owners accessing ship-related data through your platform rather than only receiving reports. Read-only owner access scoped to their own vessels reduces reporting burden and answers questions before they become emails.
Onboarding and Handover Are Contractual Events
Vessels join and leave management, and both directions have obligations attached. Transition timelines generally span thirty to sixty days to allow comprehensive audits and crew mobilisation. Start a free trial and treat both transitions as designed processes rather than exceptions.
Vessel joining
A vessel arrives with a configuration from its previous manager or owner, and a thirty to sixty day window covering audits and crew mobilisation. Conform it to your standard rather than importing what it brings — because everything it brings will otherwise sit permanently outside your comparison and your evidence standard.
During management
The vessel operates under your safety management system, your procedures and your certification, generating records in your structure. The owner sees their own vessels and nobody else's, and the confidentiality undertaking extends to your own employees and any subcontractors involved.
Vessel leaving
Owners retain data ownership under Clause 22, so the record follows the ship. Per-owner, per-vessel extraction in a usable format is the capability that satisfies this, and it should be tested before you need it rather than discovered during a contentious handover.
What you keep
Your own records of how you managed the vessel, subject to whatever the agreement provides and to the confidentiality undertaking, which survives in the ordinary course. Establish that position in the agreement rather than at the point of departure, when the relationship is least likely to be cooperative.
Test per-owner extraction before you need it. A handover is the worst possible moment to discover the platform cannot separate one owner's data from the rest.
The Commercial Frame
Management fees are known, per vessel, and modest relative to operating expenditure — which sets a hard boundary around what a platform can cost per hull. Book a walkthrough and price the software against the fee it comes out of.
Where the fee sits
Industry commentary puts full technical and crew management for a standard handysize bulker in the region of five to nine thousand US dollars per month as a general benchmark, varying by vessel type, flag, trading area and contract scope — and excluding the operational expenditure itself, which the owner bears.
What that implies
Software cost per vessel is measured directly against a known monthly fee rather than against a large operating budget. Per-vessel pricing is therefore the only unit that lets you model margin, and per-user pricing is actively unhelpful because your headcount per vessel varies by contract scope.
Where margin actually leaks
Manual report assembly for owners with different agreed indicators, chasing vessels for records that were never captured properly, and re-keying between systems. These are labour costs inside a fixed fee, which makes them the most direct financial argument for a platform that produces per-owner reporting without assembly.
And a growth constraint
Every additional managed vessel adds reporting, evidence and audit obligations at a fixed fee. If onboarding a vessel is a project rather than a matter of days, the platform limits how quickly you can take on new business — which is a commercial constraint rather than an operational one.
What to Require of a Platform
Each row below traces to a contractual obligation rather than to a preference, which makes it straightforward to justify internally and to explain to an owner. Start a free trial and test the first four rows before considering anything else.
Table 1: Requirements and the Obligation Behind Each
Questions Specific to Managed Fleets
Ask these with an actual scenario rather than in the abstract, because the answers differ considerably between platforms built for owners and platforms built for managers. Schedule a demo and use two of your own owners as the test case.
Table 2: Questions to Put to a Supplier
IMPORTANT: THIS IS NOT LEGAL ADVICE
The clause descriptions here summarise published commentary on BIMCO's SHIPMAN 2024 and are not a substitute for reading the agreement or taking advice on it. Clause numbering, scope and effect depend on the edition in use, on any rider clauses or amendments the parties have negotiated, and on the governing law. Many management relationships operate on earlier SHIPMAN editions or on bespoke agreements with materially different data, confidentiality and information systems provisions. Establish your own obligations from your own contracts rather than from any general description, and take advice on how data ownership, access and confidentiality operate in your specific arrangements. Certification arrangements vary. How a vessel's Safety Management Certificate relates to a manager's Document of Compliance depends on flag, the scope of management and the certification in place; confirm the position for each managed vessel. Fee benchmarks are illustrative and drawn from published commentary, varying widely by vessel type, flag, trading area and scope. This page is published by a software vendor, and every question in the second table is one we should be asked as readily as any competitor.
Frequently Asked Questions
What does a ship manager actually need that an owner does not?
Two things simultaneously that pull against each other. Data segregated by owner, because confidentiality obligations in modern management agreements cover all information and data received about performance of the agreement and extend to affiliates, subcontractors, employees and agents — so the separation has to hold inside your own organisation, not only between companies. And procedures common across every managed vessel, because your safety management system, your certification and your evidence standard cover them all regardless of who owns which ship. The resolution is a shared configuration layer over a segregated data layer, which is a specific architecture and the opposite of what a single-owner fleet needs.
Why can owners not have their own configuration?
Because the certification under which their vessel trades is yours. Using a third-party manager is a standard and compliant route to fulfilling ISM requirements, and the vessel's Safety Management Certificate becomes linked to the manager's Document of Compliance — so an audit of that certification examines your system as implemented across every managed vessel. A weakness aboard one owner's ship is a finding against the certification that every other owner's vessel depends on. Owners are entitled to confidentiality over their data and to ownership of it; they are not entitled to a bespoke safety management system, and the reason is one you can point to rather than assert.
Who owns the data in a managed fleet?
Modern standard agreements are explicit that owners retain ownership of the vessel's information and data, and separately provide for owners to access ship-related data through the manager's information platform while safeguarding the manager's intellectual property and digital access. Practically that means two capabilities. Owners need scoped read access into your system covering their own vessels. And when a management agreement ends, you must be able to extract one owner's data — and only that owner's — in a usable format. That second capability should be tested during evaluation rather than discovered during a handover, which is when relationships are least cooperative.
How should reporting handle owners with different requirements?
By varying presentation and indicator sets over identical underlying data. Key performance indicators are established during the contracting phase to measure operational efficiency and safety outcomes, so each owner has negotiated their own and the report has to reflect what they actually signed. One may want monthly technical summaries, another quarterly with budget detail, and a financial owner may want evidence of asset preservation rather than operational narrative — all the same records, arranged differently. Where a platform's reporting is fixed, the difference gets made up by hand every month, and that manual assembly is one of the main places manager margin leaks inside a fixed fee.
What happens when a vessel joins or leaves management?
Both are contractual events with a clock attached — transitions generally span thirty to sixty days to allow comprehensive audits and crew mobilisation. On the way in, a vessel arrives with a configuration from its previous manager, and the discipline is to conform it to your standard rather than import it, because anything imported sits permanently outside your comparison and your evidence standard. On the way out, the record follows the ship, since owners retain data ownership. Establish what you keep, subject to the agreement and the surviving confidentiality undertaking, in the contract rather than at the point of departure.
Can we benchmark vessels across different owners?
Carefully, and only with a clear position established in advance. Cross-owner comparison is genuinely valuable to a manager — it is how you identify which vessels are drifting and which practices work — but confidentiality undertakings cover information and data received about the performance of each agreement. The workable approaches are aggregation that identifies no individual owner, comparison used internally for management purposes within whatever your agreements permit, or explicit consent. What is not safe is casual cross-owner reporting on the assumption that nobody will mind. Take advice on your own agreements, and treat a supplier who offers cross-owner comparison without raising confidentiality as not having thought about managers.
Third-party ship management
Your Software Requirements Are Already Written Down
Owner access through your platform, data ownership remaining with the owner, cyber security as a contractual term, and confidentiality binding your own employees as well as your company. Four provisions, and between them a complete architectural specification: a shared configuration layer carrying one hierarchy, one definition set and one evidence standard across every managed vessel, over a data layer partitioned by owner and extractable per owner when an agreement ends. Add per-owner reporting that varies presentation without manual assembly, onboarding that fits inside a thirty to sixty day transition, and per-vessel pricing you can model against a per-vessel fee. Evaluate against that list rather than a feature comparison, because that list is what you have already agreed to deliver.