Skip to content
fig. 01 · ISO 19650 for asset owners

ISO 19650, explained for the asset owner.

ISO 19650 is the international standard series for managing information about buildings and civil engineering works across the whole life of an asset. This guide covers the six parts, the parties and what each one owes the others, the four layers of information requirement, the four states of a common data environment (CDE), the Australian position, and a compliance path you can take to procurement.

Most material on the standard is written for the delivery phase and for the contractor with a tender in front of them. An asset owner has a different problem. The record has to stay correct and usable for decades, through events nobody scheduled, long after the delivery team has gone. Part 3 covers that phase, and it gets a section of its own below.

Six published parts · Published in Australia as AS ISO 19650 · Parts 1, 2, 3, and 5 adopted by Standards Australia · Written for the appointing party

fig. 02 · the series

Six parts, and what each one is for.

The series grew out of British practice. BS 1192 set the conventions for the collaborative production of information, PAS 1192 extended them for building information modelling, and ISO 19650 took the same ideas international. Parts 1 and 2 are the ones tenders cite. Part 3 is the one an asset owner lives in.

The ISO 19650 series6 parts · 4 adopted in AU
  • Part 1 · Concepts and principlesISO 2018AS ISO 19650.1:2019

    The vocabulary, the parties, the information requirements, the information models, and the common data environment concept the rest of the series builds on.

  • Part 2 · Delivery phase of the assetsISO 2018AS ISO 19650.2:2019

    The project. Eight information management activities from assessment and need through to project close-out, repeated for every appointment. Most tender requirements point here.

  • Part 3 · Operational phase of the assetsISO 2020AS ISO 19650.3:2021

    The asset in operation. Trigger events, the asset information model, and the information management the owner runs between projects. The asset owner's part.

  • Part 4 · Information exchangeISO 2022Not adopted

    The detailed process and criteria for an information exchange, and the checks applied at each exchange point.

  • Part 5 · Security-minded approach to information managementISO 2020AS ISO 19650.5:2021

    Sensitive assets. A triage process to decide whether an asset needs a security-minded approach, and the controls that follow if it does.

  • Part 6 · Health and safety informationISO 2025Not adopted

    How health and safety information is identified, structured, shared, and carried across the project and asset life cycles.

Full title: Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM) · Information management using building information modelling

The 2026 revision

ISO is revising the series. Draft international standards for parts 1 and 2 went out for public comment in March 2026. No revised edition has been published, the 2018 editions remain current, and a tender written today still points at them. Check which edition a requirement cites before you answer it, and expect to re-read your information requirements when a new edition lands.

References
fig. 03 · the parties

Appointing party, lead appointed party, appointed party.

ISO 19650 names parties by their position in an appointment chain rather than by job title, so the same words work on a design contract, a construction contract, and a maintenance contract. As the asset owner you are the appointing party on every one of them.

Appointing party

The client, and on your own assets that is you. ISO 19650-1 defines the appointing party as the receiver of information concerning works, goods, or services from a lead appointed party. You set the information requirements, you accept or reject what comes back, and you keep the result.

Lead appointed party

The organisation you appoint directly, for example the head design consultant or the main contractor. It coordinates the information its delivery team produces and answers to you for it.

Appointed party

A provider of information concerning works, goods, or services. A lead appointed party is itself an appointed party, and inside a delivery team the sub-consultants, subcontractors, and specialist suppliers sit here.

Project team

The appointing party plus every delivery team working on the project.

Delivery team

A lead appointed party together with its appointed parties, working under one appointment.

Task team

The people producing information for one discipline or one package inside a delivery team.

One organisation holds more than one role at a time. Your main contractor is an appointed party to you and an appointing party to its own suppliers, and the same duties apply one level down. Write that flow-down into the contract, or it stops at the first tier.

fig. 04 · information requirements

Four sets of requirements, and two information models.

Everything the standard asks you to specify follows from one question: what do you need to know, and why. ISO 19650 breaks the answer into four layers, each narrower than the one above, and every layer belongs to the appointing party.

  • 01OIROrganisational information requirementsPer organisation

    What your organisation needs to know to run itself, across the whole portfolio. Health and safety compliance, environmental management, capital investment and life-cycle costing, risk, maintenance and repairs, asset operations, and space utilisation are the usual headings. Set out in ISO 19650-1 clause 5.2 and ISO 19650-3 clause 5.1.2.

  • 02AIRAsset information requirementsPer asset

    What you need to know about one asset, derived from the OIR. The asset and facilities management team leads this, and it has to exist before any appointment that touches the asset. Set out in ISO 19650-1 clause 5.3 and ISO 19650-3 clause 5.1.4.

  • 03PIRProject information requirementsPer project

    What you need at each key decision point on one project, so you can decide rather than wait. There is one set per project, partly derived from the OIR. Set out in ISO 19650-1 clause 5.4 and ISO 19650-2 clause 5.1.2.

  • 04EIRExchange information requirementsPer appointment

    What one appointed party must deliver, in what form, to what level of information need, and when. This is the set that belongs in the tender pack. Under ISO 19650-3, EIR are also issued for operational-phase appointments in response to a trigger event.

PIM · project information model

What the delivery phase produces. It grows through design and construction, and it is what you accept at the end of an appointment.

AIM · asset information model

What you maintain through operation. Every accepted information model is aggregated into it, and it feeds the next project.

At the start of a project, relevant information moves from the AIM into the PIM. At the start of operation, it moves back the other way. Keeping that loop closed is the whole job.

fig. 05 · the common data environment

One agreed source, and four states.

ISO 19650-1 describes the common data environment as an agreed source of information for any given project or asset, for collecting, managing, and disseminating each information container through a managed process. Every phrase in that sentence is a requirement. An information container is any named, structured set of information: a drawing, a model, a document, a spreadsheet, or a report.

ISO 19650-1 puts every container in one of four states. The states matter less than the gates between them. A container does not drift from work in progress to shared. A check moves it there. It does not become published because someone renamed a folder. A review and an authorisation release it.

Container statesISO 19650-1
  • 01
    Work in progress

    Information being developed by its originator or task team, not visible to or accessible by anyone else.

    Leaves on a check, a review, and an approval inside the task team.

  • 02
    Shared

    Information approved for sharing with other task teams and delivery teams, or with the appointing party. Coordination between disciplines happens here.

    Leaves on a review and an authorisation.

  • 03
    Published

    Information authorised for use in more detailed design, for construction, or for asset management. This is the record other parties commit decisions to.

    Superseded by a later revision, which sends the earlier one to archive.

  • 04
    Archive

    A journal of information transactions, providing an audit trail of how each information container developed.

    Nothing leaves. Superseded containers stay retrievable here.

agreed source of information · information container · check · review · authorise · audit trail

state · workflowfig. 05.1
A document's metadata and workflow panel in Lunr, showing its current state and the workflow steps it moves through.

The standard also separates the CDE workflow from the CDE solution. The workflow is the process: the states, the gates, the naming, the status codes, and the audit trail. The solution is the platform the process runs on. A shared drive with a tidy naming convention looks organised and manages nothing, because it cannot enforce a transition or record who authorised what.

Read the practical guide for document controllers
fig. 06 · naming and status

Naming, revision codes, and status codes.

Three pieces of metadata carry most of the standard. A naming convention gives each container a unique, predictable identifier. A revision code records which iteration you hold. A status code, also called a suitability code, records what the container may be used for.

ISO 19650-2 asks the project information standard to define these codes, and fixes no values itself. The set most projects work to comes from the UK National Annex to BS EN ISO 19650-2, revised in February 2021 and shown below. The 2021 revision added S5, removed S6, S7, and CR, and deprecated the B codes, so a register built on the 2018 set still carries values the annex has retired. Australian clients either adopt this set or publish their own, so read the project information standard before you assume a code means what you think.

Work in progress
  • S0Initial status. Preliminary revision and version.
Shared, non-contractual
  • S1Suitable for coordination.
  • S2Suitable for information.
  • S3Suitable for review and comment.
  • S4Suitable for review and authorisation by the lead appointed party.
  • S5Suitable for review and acceptance by the appointing party. Added in 2021.
Published, contractual
  • A1, AnAuthorised and accepted. Contractual revision.
  • B1, BnPartial sign-off, with comments. Deprecated in 2021, so avoid it on new work.
Retired in the 2021 revision
  • S6, S7Suitable for PIM and AIM authorisation. Removed, and the work they described is now split between S4 and S5.
  • CRAs-constructed record document. Removed, because it duplicated an A code.

The codes are how a recipient knows what they may do with a file. A container at S3 is out for review and comment, so nobody should be ordering steel from it. A container at S5 sits with the appointing party for acceptance. A container at A1 has been authorised and accepted. See issued for construction for where the familiar drawing statuses sit against these codes.

fig. 07 · the Australian position

AS ISO 19650, and whether you have to comply.

Standards Australia publishes the series as AS ISO 19650, as identical adoptions of the international standards. Parts 1 and 2 were adopted in November 2019, parts 3 and 5 followed in 2021, and parts 4 and 6 have no Australian adoption yet. Committee BD-104 is the Australian mirror of ISO/TC 59/SC 13, the committee that writes the series, so Australian practitioners have taken part in drafting it.

Is ISO 19650 mandatory in Australia?

No Australian law requires it. Like most standards it is voluntary in itself, and the obligation to use it has to be created, either by citing it in a contract or by adopting it as organisational policy. What has changed is who creates that obligation. Government policy and client information requirements now do it for a growing share of Australian asset owners, and the four programmes below are the ones an owner is most likely to meet.

Infrastructure NSW
NSW Infrastructure Digitalisation and Data Policy

Thirteen mandatory actions for Budget Material NSW Government agencies that plan, design, build, operate, or maintain government-owned built infrastructure, excluding state-owned corporations and public financial and non-financial corporations. The policy requires data and information requirements to be established and documented in accordance with ISO 19650, and requires the agency common data environment and its data workflows to be consistent with ISO 19650. Released in October 2025 with an 18-month transition, taking effect in April 2027.

Transport for NSW
Digital Engineering Framework

The Digital Engineering Standard states that the structure of the framework is based on the information principles of ISO 19650, and that information flows through approval states based on BS 1192:2007, PAS 1192-2:2013, and ISO 19650-1:2018. TfNSW runs a two-environment model, a contractor CDE and a TfNSW CDE, with information submitted from one to the other.

Office of Projects Victoria
Victorian Digital Asset Strategy

The VDAS guidance states that its information process is aligned to ISO 19650, and that ISO 19650 is embedded in the VDAS approach. It sets out OIR, AIR, EIR, the AIM, and the PIM in a Victorian context, with templates, and ties them to asset and facilities management activity.

Queensland Department of Transport and Main Roads
BIM for Transport and Main Roads Guideline

The guideline states that its information requirements are aligned to international best practice standards which include the ISO 19650 series, and that the processes in ISO 19650-2 should be considered alongside the department's Transport Infrastructure Project Delivery System. TMR issues AIR, EIR, and PIR as procurement documents, and requires a BIM execution plan at tender.

Read the requirement before you assume. An Australian client can cite ISO 19650, AS ISO 19650, BS EN ISO 19650 with its UK National Annex, or its own framework that borrows the vocabulary. The words are the same across all four. The status codes, the deliverables, and the naming fields are not.

References
fig. 08 · the operational phase

Part 3 is the owner's part of the standard.

Parts 1 and 2 describe a project: it starts, it delivers, it closes. Part 3 describes an asset you will hold for thirty years. It reuses the eight-step shape of part 2, so the process is recognisable, then changes what drives it.

Trigger events

Trigger events are the occurrences during the life of an asset that cause new or updated information to be required. They set the tempo of information management in operation the way plan-of-work stages set it on a project. Some are foreseeable, such as a scheduled inspection, a maintenance cycle, or a planned refurbishment, and part 3 asks you to identify those in advance. Others cannot be planned for, such as a failure or a storm, and the plans you made for the foreseeable ones are what you fall back on. The idea came across from PAS 1192-3.

The asset information model

The AIM is the information you hold about the asset in operation. Each accepted information model from a delivery team is aggregated into it, and part 3 asks you to establish it, establish the processes that maintain it, and keep reviewing it. Treating it as a deliverable you receive once, at practical completion, is the mistake the standard is written to prevent.

More than one pathway

Information reaches an operating asset in several ways, so part 3 has several routes through the process: an appointment made ahead of a foreseeable trigger event, an appointment made after an unforeseen one, a delivery-phase project run to ISO 19650-2, and the acquisition of an existing asset from another owner. That last pathway is why the standard applies to the estate you already have.

ISO 19650-3 process8 steps
  1. 01Assessment and need
  2. 02Invitation to tender, or request to provide a service
  3. 03Response to that invitation or request
  4. 04Appointment
  5. 05Mobilisation
  6. 06Production of information
  7. 07Information model acceptance by the appointing party
  8. 08Aggregation into the asset information model
Clauses part 3 carries that part 2 does not
  • Establish organisational information requirements (5.1.2)
  • Identify the assets for which information will be managed (5.1.3)
  • Establish asset information requirements (5.1.4)
  • Identify foreseeable trigger events (5.1.5)
  • Establish links to enterprise systems (5.1.10)
  • Establish the asset information model (5.1.11)
  • Establish processes to maintain the asset information model (5.1.12)
  • Decide the type of activity providing information (5.2.1)
  • Maintain resources in readiness for a trigger event (5.5.4)
  • Aggregate an accepted information model into the AIM (5.8.1)
  • Review and continue maintenance of the AIM (5.8.2)

Read that clause list as a job description. Almost all of it describes standing work the owner does continuously, in a system the owner controls, between projects. This is where most implementations leave a gap: the delivery-phase environment closes with the project, the AIM has nowhere to live, and by the next trigger event the record is a shared drive again. An asset owner who has written the AIR, established the AIM, and kept the audit trail in one place answers a part 3 question from the record. An owner who has not answers it from an inbox.

trigger events · asset information model · aggregation · maintenance · links to enterprise systems

audit trail · asset recordfig. 08.1
Lunr's document activity view, showing an audit trail of workflow transitions, dismissed validation issues, and tag updates on a timeline.
fig. 09 · the compliance path

What an asset owner actually has to do.

None of this needs a consultant to start. Work top to bottom, and write down what you decide, because a written decision is what an audit reads. Compliance is a property of how you work, so the artefacts below are the evidence.

ABefore you appoint anyoneWrite it down · 10 steps
  • 01Write the OIR. Name the business activities that need asset information, and the reason each one needs it.
  • 02Write the AIR for each class of asset you own, derived from the OIR, and have the asset management team lead it.
  • 03Write the PIR for each project, tied to the key decision points you actually make.
  • 04Write an EIR for every appointment, and put it in the tender pack rather than in a covering email.
  • 05Publish a project information standard: the naming convention, the status codes in use, the revision convention, and the metadata every container carries.
  • 06Publish information production methods and procedures, including the native formats you will accept alongside published PDFs.
  • 07Set the level of information need for each exchange, so you receive what you asked for and no more.
  • 08Name the common data environment, say who operates it, and say who holds it after the project ends.
  • 09Run the ISO 19650-5 triage to decide whether the asset is security sensitive before you publish anything about it.
  • 10Cite the information requirements in the contract, so they are a deliverable rather than a preference.
BWhile the appointment runsRun the states · 6 steps
  • 01Enforce the gates. A container advances on a check, a review, and an authorisation, never on a rename or a folder move.
  • 02Require a status code and a revision code on every container, at every exchange.
  • 03Review each exchange against the EIR at the exchange point, and reject an incomplete one there rather than at handover.
  • 04Issue information to parties outside the environment as a recorded transmittal, with the cover sheet listing every container and its revision.
  • 05Keep the audit trail complete: who changed a container, who reviewed it, who authorised it, and when.
  • 06Keep superseded revisions in archive rather than deleting them, so what was issued stays retrievable.
CAt handoverTake the record · 5 steps
  • 01Validate the package against the EIR and the delivery plan, container by container, before you accept it.
  • 02Take native files as well as plots, so the record stays editable by the next appointment.
  • 03Take the metadata, the revision history, and the audit trail alongside the files themselves.
  • 04Move accepted containers to the as-constructed record status, and aggregate the accepted information model into the AIM.
  • 05Confirm the record now sits in a system you control, on an instance you can export from.
DIn operationKeep it usable · 5 steps
  • 01List your foreseeable trigger events, and write an EIR for each one ahead of time.
  • 02Update the AIM after every trigger event, so it keeps representing the asset as it stands.
  • 03Link the AIM to the enterprise systems that consume it, for example asset management, maintenance, and GIS.
  • 04Audit the record each year: sample a set of containers and check the current revision, the status, and the completeness of the history.
  • 05Test an export. A record you cannot get out is a record you do not own.

Two of these carry more weight than the rest. Naming the common data environment and saying who holds it after the project decides whether you own the record or borrow it. Testing an export decides whether that ownership is real. Take a drawing register template if you need somewhere to start the audit.

fig. 10 · how a platform carries it

What the software has to do, and where Lunr lines up.

No software makes you compliant, because compliance is a property of how you work. What a platform can do is carry the workflow so the discipline survives a busy week, and hold the record after the delivery team has gone. Each line below maps a requirement from this guide to something Lunr does.

An agreed source of information

One controlled register for every drawing, model, and document. Automatic numbering applies your register format as containers are booked in, and title-block tags are read into metadata, so the number, revision, and discipline come off the sheet. See document control.

States, gates, and approvals

Define the states your project uses, the reviews and approvals that move a container between them, and the roles that can act at each gate. See configurable workflows.

Unique identification and metadata

Every information container carries its number, revision, status, and metadata as first-class fields, across DWG, DGN, RVT, PDF, and IFC, with superseded revisions kept and marked.

Controlled access and controlled issue

External organisations join as collaborators with access to only what their role needs, or receive a tracked transmittal without any repository access at all.

An audit trail you can answer a review with

Every change, review, and state transition is logged against the container, so a question about who approved a drawing, and when, is answered from the record rather than an inbox.

Acceptance into the asset information model

Validate each handover package against a manifest, so a missing as-constructed drawing is caught on upload, then keep the containers, the revision history, and the audit trail after the delivery team leaves.

Information that stays usable for decades

XRAY runs OCR and full-text search across scans and CAD, so a valve tag on a 1994 sheet is findable, and Rift, Foundry, and Nimbus open drawings, models, and point clouds in the browser with no CAD licence.

Security and data sovereignty

Hosted in Australia and the US, operated by an ISO/IEC 27001:2022 certified partner, with SAML sign-in and export at any time. See security and compliance.

Lunr is engineering document management that serves as your common data environment, built for the appointing party rather than for the project. When the project closes the environment stays with you, along with every information container, its revision history, and its audit trail. Universities, utilities, energy companies, and government departments run their record on it, and more than 10 million documents are under management today.

Lunr holds no ISO 19650 certification, and no vendor can certify your process for you. The platform carries the workflow. You run the process.

information containers · configurable workflows · transmittals · manifest validation · full audit trail · hosted in Australia and the US

information containerfig. 10.1
A single document record in Lunr, showing its metadata, revision history, and workflow state on one page.
fig. 11 · questions

Questions asset owners ask about ISO 19650.

Whether it is mandatory, what it replaced, how it relates to a common data environment, and which part matters most to an owner.

01
Is ISO 19650 mandatory in Australia?
No Australian law requires ISO 19650. Standards Australia has adopted parts 1, 2, 3, and 5 as AS ISO 19650, but a standard is voluntary in itself, and the obligation to use it has to be created, either by citing it in a contract or by adopting it as organisational policy. In practice that obligation is increasingly created for asset owners by government policy. The NSW Infrastructure Digitalisation and Data Policy, released by Infrastructure NSW in October 2025 and taking effect in April 2027, requires in-scope NSW agencies to establish information requirements in accordance with ISO 19650 and to run a common data environment consistent with it. Transport for NSW, the Victorian Digital Asset Strategy, and the Queensland Department of Transport and Main Roads all base their digital engineering requirements on the series. For a private owner, the obligation arrives through the tenders you write and the contracts you sign.
02
What replaced BS 1192 and PAS 1192?
ISO 19650 did. BS 1192:2007 set the original British conventions for the collaborative production of architectural, engineering, and construction information, and PAS 1192-2:2013 extended them for building information modelling on the delivery phase. BS EN ISO 19650-1:2018 and BS EN ISO 19650-2:2018 superseded both, and PAS 1192-3, which covered the operational phase, was carried into ISO 19650-3:2020. Anyone who worked to BS 1192 will recognise most of ISO 19650: the states, the naming discipline, and the suitability codes came across, with new labels and a wider scope.
03
What is the difference between ISO 19650 and a common data environment?
ISO 19650 is the standard. A common data environment is one of the things the standard asks for. ISO 19650-1 describes the CDE as an agreed source of information for any given project or asset, for collecting, managing, and disseminating each information container through a managed process. The standard also draws a line between the CDE workflow, which is the process of states, gates, naming, status codes, and audit trail, and the CDE solution, which is the platform that process runs on. You can buy a solution and still fail the workflow, because a folder cannot enforce a state transition or record who authorised what.
04
Does ISO 19650 apply to existing assets, or only to new projects?
It applies to existing assets. ISO 19650-3 covers the operational phase, and its process has a pathway specifically for acquiring an asset from a previous owner, alongside pathways for foreseeable trigger events, unforeseeable ones, and delivery-phase projects run to ISO 19650-2. For an owner with decades of inherited drawings, the practical starting point is to write the asset information requirements, establish the asset information model with whatever you hold today, and improve it at each trigger event rather than waiting for a greenfield project.
05
What are the four CDE states in ISO 19650?
Work in progress, shared, published, and archive. Work in progress holds information being developed by its originator or task team, not visible to anyone else. Shared holds information approved for sharing with other task teams, delivery teams, or the appointing party, for coordination and review. Published holds information authorised for use in more detailed design, for construction, or for asset management. Archive is a journal of information transactions that provides an audit trail of how each container developed, and it is where superseded revisions stay retrievable. The states matter less than the gates between them: a check moves a container from work in progress to shared, and a review and an authorisation move it to published.
06
What are the ISO 19650 status codes?
A status code, also called a suitability code, records what an information container may be used for. ISO 19650-2 requires the project's information standard to define the codes, and does not fix the values itself. The set most projects work to comes from the UK National Annex to BS EN ISO 19650-2, revised in February 2021: S0 initial status in work in progress; then S1 suitable for coordination, S2 suitable for information, S3 suitable for review and comment, S4 suitable for review and authorisation by the lead appointed party, and S5 suitable for review and acceptance by the appointing party while shared; then A1 to An authorised and accepted once published, with B1 to Bn partial sign-off now deprecated. The 2021 revision added S5 and removed S6, S7, and CR, so a register built on the 2018 set still carries values the annex has retired. Australian clients either adopt this set or publish their own, so read the project information standard before assuming what a code means.
07
Which part of ISO 19650 matters most to an asset owner?
Part 3, the operational phase. Parts 1 and 2 describe a project that starts, delivers, and closes, which is why most commentary and most tender requirements point there. Part 3 describes the asset you hold for decades. It introduces trigger events, the occurrences during the life of an asset that cause new or updated information to be required, and it makes the asset information model something you establish, maintain, and keep reviewing rather than something you receive once at handover. Eleven of its clauses have no counterpart in part 2, and almost all of them describe standing work the owner does between projects.
08
Can a software product be ISO 19650 certified?
Not in the sense most buyers mean. ISO 19650 describes a process, so it names no software and mandates no file format, and no product can make an organisation compliant on its own. Certification schemes do exist against the series, including the BSI Kitemark, which is awarded to organisations for their own information management and separately to software vendors for user functionality that supports the process. Treat a vendor claim as evidence that a platform can carry the workflow, and treat your own compliance as a property of how your team works, evidenced by your information requirements, your states and gates, and your audit trail.
fig. 12 · get started

Run the standard, and keep the record.

Book a walkthrough and watch Lunr move an information container through work in progress, shared, and published, with the decision and the reviewer recorded at every gate, then hold it after the project team leaves.

10M+ documents under management · Hosted in Australia and the US · SAML · Full audit trail · Export anytime

entity
Lunr Labs Pty Ltd
location
Melbourne AU
workspace
documents.lunr.app
rev
2026