# 141 — ISO 55001 Shared-Responsibility Matrix

> Status: Active · Owner: Director of Asset Management lens · Created 2026-06-12 (Decision 0067)
> Standard: ISO 55001:2024 (asset management system requirements). KB pack:
> `knowledge/standards/asset-management/iso-55001-ams.md`

## Purpose and claim boundary

ISO 55001 certifies an **organization's asset management system (AMS)** — the audit is performed
on the customer's organization by an accredited certification body (ISO/IEC 17021-1). **Software
cannot be ISO 55001 certified.** Osolix's truthful claim is therefore:

> *Osolix supports and is structured around the ISO 55000 asset-management lifecycle, and
> provides the records, workflows, and reports a customer presents as evidence when pursuing
> their own ISO 55001 certification.*

Forbidden wording anywhere in marketing, sales, or product copy (Decision 0045/0046 claim-safety
rule): "ISO 55001 certified", "ISO 55001 compliant", "certification-ready" applied to Osolix
itself.

Each clause below is marked:
- **P** — Platform-delivered: a shipped Osolix feature produces the required records/behaviour.
- **S** — Shared: the platform provides the instrument; the customer must operate it.
- **C** — Customer-owned: inherently organizational; Osolix can at most store evidence.

## Clause 4 — Context of the organization

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 4.1 | Understand org context relevant to AM | **C** | — | Define purpose, context, strategic plan |
| 4.2 | Stakeholder needs → AM requirements | **C** | Custom fields / custom reports can record stakeholder requirements | Identify stakeholders, document expectations |
| 4.3 | Define AMS scope incl. asset portfolio | **S** | Asset register, categories, asset groups, locations, multi-entity structure define the portfolio boundary | Decide and document which assets/sites are in scope |
| 4.4 | Establish, implement, maintain the AMS | **S** | The platform is the system of record for AM processes and their evidence | Operate the AMS; integrate with business processes |
| 4.5 | AM decision-making and value (**new in :2024**) — framework, criteria, methods/tools for value-realizing decisions | **P** | Repair-vs-replace analysis, TCO model, Capex risk scoring + portfolio optimisation, DOA approval matrix, capitalisation rules — a consistent, auditable decision framework | Define the value criteria and decision thresholds |

## Clause 5 — Leadership

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 5.1 | Top-management leadership & commitment | **C** | Dashboards give leadership visibility | Demonstrate commitment; integrate AM into business processes |
| 5.2 | Asset management policy | **C** | Document storage for the policy | Write, approve, communicate the policy |
| 5.3 | Roles, responsibilities, authorities | **S** | RBAC matrix, delegation-of-authority chains, approval matrix config, custodian assignments | Assign accountable persons; keep org chart current |

## Clause 6 — Planning

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 6.1.2 / 6.1.3 | Actions to address risks / opportunities (split subclauses in :2024) | **P** | Risk score per asset, criticality matrix, cost-of-failure heatmap, Capex risk scoring; opportunity side: portfolio optimisation, smart reorder, bundle optimiser | Set risk appetite and criteria |
| 6.2.1 | Strategic Asset Management Plan — SAMP (**new subclause in :2024**) | **S** | Capex projects tie spend to strategic objectives; maintenance plans tie work to availability targets; reporting hub rolls up the SAMP narrative | Author and approve the SAMP; keep line-of-sight current |
| 6.2 | AM objectives + planning to achieve them | **S** | Capex portfolio optimisation, budget rounds, maintenance plans, measurable KPIs in reporting hub | Set the objectives; approve the plans |

## Clause 7 — Support

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 7.1 | Resources | **C** | — | Provide budget, people, tools |
| 7.2 | Competence | **C** | Training/learning records can be attached to users | Define competence requirements; train; evidence it |
| 7.3 | Awareness | **C** | In-app announcements, notification preferences | Run the awareness programme |
| 7.4 | Communication | **S** | Notifications, scheduled reports, announcements, audit-ready exports | Decide what/when/whom to communicate |
| 7.5 | Documented information control | **P** | Versioned records, soft-delete retention, immutable audit log, document attachments, retention policies | Operate document approval workflow |
| 7.6 | Data and information (revised in :2024 — asset data quality, configuration, traceability) | **P** | Asset register attribute model, audit interceptor (who/what/when on every write), data-integrity rules DG-1–DG-10, verification cycles, RFID/barcode traceability | Define which attributes matter for their decisions |
| 7.7 | Knowledge (**new in :2024**) — knowledge needed to operate the AMS, kept current | **S** | In-app standards knowledge base, learning paths, runbooks/doc attachments, AI advisory with cited sources | Capture organizational know-how; keep it current |

## Clause 8 — Operation

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 8.1 | Operational planning & control of life-cycle activities | **P** | Full lifecycle workflows: acquisition/additions, transfers, maintenance work orders, verification, revaluation, impairment, retirement/disposal — each with four-eyes approval and audit trail | Execute the work; keep approvals real |
| 8.2 | Management of change | **S** | Approval workflows + change records on transfers, policy changes, write-offs; SoD checks | Assess risk of organizational/process changes |
| 8.3 | Externally provided processes, products, technologies and services (renamed from "outsourcing" in :2024) | **S** | Vendor master, vendor SLA tracking, contractor gate passes, vendor performance scorecards | Select, contract, and supervise external providers |

## Clause 9 — Performance evaluation

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 9.1 | Monitoring, measurement, analysis, evaluation | **P** | Condition monitoring, IoT-fed anomaly alerts, MTBF/MTTR/OEE, utilization logs, energy M&V, verification cycles, KPI dashboards | Choose KPIs; act on results |
| 9.2 | Internal audit of the AMS | **S** | Audit module: dimensions, scores, evidence packs, SOX 404 support, certificates | Run an independent internal-audit programme |
| 9.3 | Management review | **C** | Quarterly review-board template; reporting hub packs | Hold the reviews; record decisions |

## Clause 10 — Improvement

| Clause | Requirement | Split | Osolix delivery | Customer obligation |
|---|---|---|---|---|
| 10.1 | Continual improvement | **S** | Every verification/maintenance/audit cycle outcome feeds the next plan; trend analytics | Own the improvement loop |
| 10.2 | Nonconformity & corrective action | **S** | Incident/defect records, FMEA, RCA support in maintenance module, CAPA-style workflows | Investigate causes; verify effectiveness |
| 10.3 | Predictive action (**new in :2024** — replaces 2014 §10.2 preventive action) | **P** | Predictive maintenance engine, RUL prediction, telemetry anomaly detection, demand sensing, insurance drift watcher, energy M&V — exactly the "predict future behaviour of decision-relevant parameters" the clause requires | Act on the predictions; set intervention thresholds |

## Summary

- **Platform-delivered (P):** 4.5, 6.1.2/6.1.3, 7.5, 7.6, 8.1, 9.1, 10.3 — the clauses where
  certification evidence is mostly system records, which Osolix produces natively with immutable
  audit trails. Notably, both clauses **new** in the :2024 edition (4.5 decision-making & value,
  10.3 predictive action) land squarely on shipped Osolix capability.
- **Shared (S):** 4.3, 4.4, 5.3, 6.2/6.2.1, 7.4, 7.7, 8.2, 8.3, 9.2, 10.1, 10.2.
- **Customer-owned (C):** 4.1, 4.2, 5.1, 5.2, 7.1, 7.2, 7.3, 9.3 — inherently organizational;
  no software can deliver these.

> Clause numbering verified 2026-06-12 against the official ISO TC251 guidance
> ("ISO 55001:2024 — Updated Guidance on Asset Management System Requirements", Rev3,
> committee.iso.org/tc251). Renumbering traps vs the 2014 edition: SAMP moved into §6.2.1;
> "information requirements" became §7.6 "data and information"; preventive action (2014 §10.2)
> was replaced by predictive action (§10.3).

A customer pursuing ISO 55001 certification uses this matrix as the starting point for their
gap analysis: the P rows are evidenced from Osolix reports/exports; the S rows need the customer
to operate the provided instruments; the C rows are entirely theirs.
