ISO 55001 comes up in most of our first conversations with utilities and transport operators in the UAE. Sometimes a regulator or a shareholder has asked for it. Sometimes a tender has made it a condition. Either way the question is usually framed as “how do we get certified?”, and the more useful question is “what do we need to have in place for certification to mean something?” This article is about the second one.
What ISO 55001 asks for, in plain terms
ISO 55001 is a management system standard. It does not tell you how to maintain a pump or when to renew a main. It asks you to show that the way you make those decisions is deliberate, written down, and connected to what the organisation is trying to achieve. Stripped of the clause numbers, it wants four things.
- A policy. A short statement, signed off at the top, of how the organisation intends to manage its assets and why.
- A strategic asset management plan (SAMP). The document that turns organisational objectives into asset management objectives and sets out how the asset management system will deliver them.
- Objectives and plans. Measurable asset management objectives, and the asset management plans that say what will be done, by whom, with what resources and by when.
- Evidence that decisions follow from them. Records showing that maintenance, renewal and investment decisions actually trace back to the plans, and that performance is measured and fed back into the next cycle.
The fourth is where most of the audit effort goes, and where most of the real work is. Writing a policy and a SAMP takes weeks. Producing the evidence that decisions follow from them depends on data the organisation may not have.
Why the certificate helps less than it looks
A great deal of infrastructure data in the GCC still sits in a spreadsheet on somebody’s laptop, or was never collected at all. It is entirely possible to write a sound policy and SAMP on top of that, pass a certification audit on the strength of the documents, and change very little about how assets are maintained.
The standard is not the problem. A management system can only be as good as the information it reasons about. If the register is thin, the objectives cannot be measured, the plans cannot be prioritised on evidence, and the performance evaluation is a set of opinions. The certificate goes on the wall and the maintenance programme runs as it did before. Operators who have been through this once tend to ask a different question the second time: not “are we certified?” but “could we defend this renewal decision to the regulator using our own records?”
The usual gaps
The same three gaps turn up at almost every operator we look at, whatever the sector.
An incomplete asset register. Assets are missing, duplicated, or held at the wrong level: a whole pumping station as one line, or every bolt as its own record. Installation dates and condition grades are blank for the older part of the network, which is the part that matters most.
No failure coding. Work orders record that something was repaired, not what failed, how, or why. Without that, there is no reliability history to analyse, and no way to show that a maintenance strategy is working.
Criticality scored by hand. Most registers carry a criticality score that someone assigned in a workshop, asset by asset. It is better than nothing, but a network does not fail one asset at a time, and a hand score often misses which asset actually matters. We have written about this separately in Criticality should come out of the model, not go into it.
None of these is an ISO 55001 requirement in so many words. All three make it very hard to produce the evidence the standard asks for.
A practical order of work
We follow the same five stages on every engagement, described on How We Work. Applied to ISO 55001 readiness, they look like this.
- Discover. Audit the asset register and run a data gap analysis against what the standard will ask you to evidence. This tells you how far away the audit really is.
- Instrument. Where the data on critical assets does not exist, go and get it: condition surveys, and continuous monitoring where the risk justifies it.
- Analyse. Turn the register and the condition data into a risk picture: which assets matter, how they are degrading, and what that means for the network.
- Recommend. Write the policy, the SAMP, the objectives and the asset management plans, on top of the analysis rather than ahead of it. This is where the management system documentation comes from.
- Monitor. Measure performance against the objectives, review, and adjust. This is the cycle the auditor will want to see running, not just described.
The point of the order is that the documents come fourth. Operators who start by writing the SAMP usually have to rewrite it once the register has been cleaned up.
Where condition data and software fit
The performance evaluation part of the standard asks you to monitor, measure, analyse and evaluate, and to keep the evidence. For most operators that is the hardest part to show, because the measurements either do not exist or live in separate systems that do not talk to each other.
Two things help. Continuous condition data on critical assets, such as the vibration monitoring we build in Sensored, gives you a measured record of how those assets are behaving between inspections. And a single asset management system that holds the register, the work orders, the failure coding and the cost, such as Keystone Asset, means every decision and every figure traces back to the same asset record. Neither is required by the standard. Both make the evidence much easier to produce and much harder to argue with.
What to ask a consultant before you sign
PRAXIS advises operators on asset management and ISO 55001. We are not a certification body; certification is carried out by an accredited certification body, independently of whoever helped you prepare. Whoever you work with, these questions are worth asking.
- Do you start with our data or with a document template? A SAMP written before the register has been looked at is a template with your logo on it.
- What will our register look like at the end? Ask for the data gap analysis as a deliverable, and for a plan to close the gaps that matter.
- How will criticality be established? Workshop scores, a network model, or both, and how the answer will be checked.
- Who runs the system after the audit? The standard expects continual improvement. If the answer is “the consultant”, the organisation has not built the capability the standard is asking for.
- Are you also selling us the certificate? The adviser and the certifier should be different organisations.
ISO 55001 is worth doing properly. Done properly, the certificate is the least important thing you get out of it.