Skip to content
04Operations & Asset Management

ISO 55001 tells you what to build. It will not tell you what to build first

The standard states in its own introduction that the order of its requirements implies no order of implementation. That is a defensible position for a standards committee and an expensive one for an organisation standing up an asset management function under compliance pressure, which is what a great many organisations in this region are now doing.

9 min read

There is a specific moment, repeated across the region at present, when an organisation decides it needs an asset management function. Usually something has forced it. A regulator, an auditor, a reporting deadline, a tender that asked a question nobody could answer.

The first thing the organisation does is obtain the standard. The question it asks of the standard is what does this require. The question that determines whether the function turns out to be useful is a different one, and the standard declines to answer it.

What ISO says about its own order

ISO 55001 was revised in July 2024. The second edition cancels and replaces the 2014 edition, and it says this in its introduction:

The order in which requirements are presented in this document does not reflect their importance nor imply the order in which they are to be implemented.

That sentence is easy to read past. It should not be. It means the document that defines the requirements is explicitly refusing to sequence them, and sequence is the entire problem facing an organisation building the thing from nothing.

The refusal is correct on its own terms. A standards committee writing for every organisation of every size in every sector cannot know whether the reader is a water utility with a century of records or a development company that took delivery of its first completed asset last year. Prescribing an order would be prescribing a context. ISO declined, and it was right to.

But the consequence is real. An organisation reading the clauses in numerical order and implementing them in that order will produce something that satisfies an assessor and does very little else. The clauses are a specification for a finished system. They are not a route to one.

What "establishing it right" now means

The second edition changed enough that advice written against the 2014 edition is no longer safe. ISO lists the main changes itself, and four of them alter what a new function has to do on day one.

Asset management decision-making is now a requirement. Clause 4.5 is entirely new, with three parts: a framework, criteria, and methods, processes and tools. An organisation must now document how asset decisions get made and who is entitled to make them. This is the requirement most organisations will fail first, because what it asks for usually exists only as habit.

The strategic asset management plan has its own clause. In the 2014 edition the SAMP was referred to in several places without ever being gathered into one requirement. It is now Clause 6.2.1.

Data and information were separated from documented information. Clause 7.6 is substantially revised and now reaches attributes, quality and sources, including the alignment of financial and non-financial terminology. A separate new clause, 7.7, covers knowledge.

Preventive action became predictive action. Clause 10.3 was renamed and, in ISO's own words, fully technically revised. The question moved from whether to intervene to when, which is a different discipline requiring condition data most organisations do not collect.

Read together, these are not editorial tidying. They are the standard moving towards decisions and data and away from documentation, and they change what a function established in 2026 should look like compared to one established in 2016.

How many organisations have actually done this

Fewer than almost anyone assumes.

The ISO Survey, which counts valid certificates issued by accredited certification bodies, reported 687 valid ISO 55001 certificates worldwide across 2,168 sites in its 2024 results. For a standard that applies to every asset-intensive organisation on earth, in every utility, transport authority, port, hospital estate and property portfolio, that is a very small number.

It is also a number that has to be handled carefully, and the careful reading is more useful than the headline.

A certificate count measures certification, not practice. An organisation can operate a competent, standards-aligned asset management system and never certify it, and many do, because certification costs money and answers a question nobody has asked them. The converse is also true: a certificate demonstrates that a system was conforming on the day it was assessed, which is not the same as a system that changes decisions.

So the figure does not prove low adoption. What it does establish is that ISO 55001 is nowhere near the default, in a way that ISO 9001, with certificates in the hundreds of thousands, plainly is. An organisation adopting it now is not late. It is early, and it will find correspondingly little local precedent to copy.

Note also what this publication cannot tell you. ISO moved the Survey to the IAF CertSearch database, where the dataset is downloadable free of charge on registration. The country-level breakdown for this region has not been examined here, so no claim is made about how many of those 687 certificates sit in the Gulf.

Why the pressure is arriving here now, and from an unusual direction

Elsewhere, asset management adoption has generally been driven by regulators of utilities, by safety regimes, or by the operating cost of ageing networks. In this region a different mechanism is doing the work.

Saudi Arabia's Royal Decree No. 13059 of December 2016 requires government institutions to convert from cash to accrual accounting under IPSAS. Accrual accounting obliges an entity to recognise, value and depreciate the assets it controls. To do that, it must first establish what it controls, where those assets are and what condition they are in.

That is an accounting reform. Its practical effect is to require the core dataset of an asset management system, and to attach a reporting deadline to it.

The register is the precondition

, read: Accrual conversion gave three years. It did not give anyone a register.

The organisations affected are also, in many cases, the organisations that spent the last decade delivering. They were built to procure and construct, and are now becoming organisations that own. An asset management function established under those conditions inherits an asset base it did not specify, records it did not commission, and a deadline it did not set.

What the inheritance costs

, read: Handover is where the cost lands, and the Gulf is now taking delivery

The order the dependencies require

If the standard will not sequence the requirements, something has to, and the honest way to do it is to derive the order from what each requirement needs in order to be answerable at all.

This is the ordering this publication uses. It is not ISO's, it is not endorsed by ISO, and the reasoning is set out so it can be argued with.

The chain runs like this. You cannot state a scope until you know what the organisation is for and who depends on it, so context precedes scope. You cannot write decision criteria until the scope tells you which decisions are yours, so 4.5 follows 4.3. A policy is a statement of intent about decisions, so it follows the criteria rather than preceding them, which reverses the usual instinct to write the policy first because it is the easiest document to produce. The strategic asset management plan converts that intent into a plan, so it needs the policy. Objectives are drawn from the plan. Risk and opportunity are assessed against the objectives, because a risk is only a risk relative to something you are trying to achieve.

The dependency order of ISO 55001 requirementsTwelve requirement groups arranged in the order their dependencies allow, rather than in clause order. Each states what it needs before it can be answered. Risk at clause 6.1 falls after objectives at 6.2, the one place where dependency runs against the numbering.StepClauseWhat it establishesWhat it depends on014.1, 4.2Context and stakeholdersNothing. This is the floor.024.3, 4.4Scope of the systemRequires context, to know what is inside it.034.5Decision-makingRequires scope, to know which decisions are yours.045.2PolicyRequires criteria, or it declares intent about nothing.056.2.1The SAMPRequires policy, which it converts into a plan.066.2.2ObjectivesDrawn from the plan.076.1Risk and opportunityRequires objectives. A risk is only a risk relative to one.087.2CompetenceRequires knowing what the system asks people to do.097.6Data and informationRequires 4.5, to know which decisions the data serves.108OperationExecution of a plan that now exists.119Performance evaluationRequires something to evaluate against.1210.3Predictive actionRequires operating history to predict from.Eleven of the twelve run with the numbering. Risk is the exception, and itis why the order has to be argued rather than read off the contents page.
FIG. 01The twelve requirement groups in the order their dependencies allow. Clause references are ISO's; the ordering is this publication's, and ISO states in the introduction to ISO 55001:2024 that its own clause order implies no order of implementation.

Then the supporting clauses, which are conventionally treated as administrative and are the point at which most systems quietly fail. Competence requirements can only be determined once you know what the system asks people to do. Data requirements can only be specified once you know which decisions the data serves, which is why Clause 7.6 has to come after 4.5 and not, as most implementations have it, at whatever point the software is procured.

Only then does operation mean anything, because operational control is the execution of a plan that now exists. Performance evaluation requires something to evaluate against. Improvement, and in particular predictive action, requires enough operating history to predict from.

What follows

The parts of this series each take one group of requirements and treat it as a complete subject: what the clause asks for, what changed in 2024, what it looks like when it has been done to satisfy an assessor rather than to work, and what it costs to build properly.

They are placed across the four stages of the lifecycle rather than gathered into one, because the requirements do not all bite in the same place. Decision-making and the SAMP shape what gets built and belong at inception. Competence and externally provided services bite during delivery. Data and knowledge are tested at handover. Operational control, evaluation and predictive action belong to the operating life.

Each part also names the assurance domain that later tests whether the thing was built as described, because a management system nobody examines is a filing convention.

There is one more reason to be deliberate about the order. A function established badly is harder to fix than one not yet established, since the second has no sunk cost, no incumbent process and nobody whose credibility is attached to the current arrangement. The organisations now standing these functions up under deadline pressure have exactly one opportunity to do it in a sensible order, and the deadline is pushing hard in the other direction.


Sources. ISO 55001:2024, Asset management, Asset management system, Requirements, second edition, July 2024, prepared by ISO/TC 251, ISO standard 83054. Clause structure, the list of main changes and the quoted sentence are taken from the introduction and foreword as published by ISO. ISO 55000:2024 provides the vocabulary and overview. Further guidance referred to by ISO 55001 is published as ISO 55002, ISO/TS 55010 on the alignment of financial and non-financial functions, ISO 55011 on public policy, ISO 55012 on people involvement and competence and ISO 55013 on the management of asset data. Certificate counts are from the ISO Survey 2024 results, which ISO now compiles from and hosts on the IAF CertSearch database. Saudi Arabia's transition to accrual accounting is required by Royal Decree No. 13059 of December 2016. Standards published behind a paywall are cited without a link.

Tags

  • ISO 55000
  • Asset management
  • Governance
  • Saudi Arabia
  • Compliance

Related reading