ISO 19650, explained for the asset owner.
ISO 19650 is the international standard series for managing information about buildings and civil engineering works across the whole life of an asset. This guide covers the six parts, the parties and what each one owes the others, the four layers of information requirement, the four states of a common data environment (CDE), the Australian position, and a compliance path you can take to procurement.
Most material on the standard is written for the delivery phase and for the contractor with a tender in front of them. An asset owner has a different problem. The record has to stay correct and usable for decades, through events nobody scheduled, long after the delivery team has gone. Part 3 covers that phase, and it gets a section of its own below.
Six published parts · Published in Australia as AS ISO 19650 · Parts 1, 2, 3, and 5 adopted by Standards Australia · Written for the appointing party
- 01The six parts of the series
- 02Appointing party and appointed parties
- 03OIR, AIR, PIR, and EIR
- 04The common data environment and its four states
- 05Naming, revisions, and status codes
- 06The Australian position, and AS ISO 19650
- 07Part 3, the operational phase
- 08A compliance path for an asset owner
- 09What the software has to do
- 10Questions
Six parts, and what each one is for.
The series grew out of British practice. BS 1192 set the conventions for the collaborative production of information, PAS 1192 extended them for building information modelling, and ISO 19650 took the same ideas international. Parts 1 and 2 are the ones tenders cite. Part 3 is the one an asset owner lives in.
- Part 1 · Concepts and principlesISO 2018AS ISO 19650.1:2019
The vocabulary, the parties, the information requirements, the information models, and the common data environment concept the rest of the series builds on.
- Part 2 · Delivery phase of the assetsISO 2018AS ISO 19650.2:2019
The project. Eight information management activities from assessment and need through to project close-out, repeated for every appointment. Most tender requirements point here.
- Part 3 · Operational phase of the assetsISO 2020AS ISO 19650.3:2021
The asset in operation. Trigger events, the asset information model, and the information management the owner runs between projects. The asset owner's part.
- Part 4 · Information exchangeISO 2022Not adopted
The detailed process and criteria for an information exchange, and the checks applied at each exchange point.
- Part 5 · Security-minded approach to information managementISO 2020AS ISO 19650.5:2021
Sensitive assets. A triage process to decide whether an asset needs a security-minded approach, and the controls that follow if it does.
- Part 6 · Health and safety informationISO 2025Not adopted
How health and safety information is identified, structured, shared, and carried across the project and asset life cycles.
Full title: Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM) · Information management using building information modelling
ISO is revising the series. Draft international standards for parts 1 and 2 went out for public comment in March 2026. No revised edition has been published, the 2018 editions remain current, and a tender written today still points at them. Check which edition a requirement cites before you answer it, and expect to re-read your information requirements when a new edition lands.
- ISO 19650-1:2018, ISO catalogue entry for part 1, concepts and principles
- ISO 19650-3:2020, ISO catalogue entry for part 3, operational phase of the assets
- AS ISO 19650.1:2019, Standards Australia catalogue entry for the Australian adoption
Appointing party, lead appointed party, appointed party.
ISO 19650 names parties by their position in an appointment chain rather than by job title, so the same words work on a design contract, a construction contract, and a maintenance contract. As the asset owner you are the appointing party on every one of them.
The client, and on your own assets that is you. ISO 19650-1 defines the appointing party as the receiver of information concerning works, goods, or services from a lead appointed party. You set the information requirements, you accept or reject what comes back, and you keep the result.
The organisation you appoint directly, for example the head design consultant or the main contractor. It coordinates the information its delivery team produces and answers to you for it.
A provider of information concerning works, goods, or services. A lead appointed party is itself an appointed party, and inside a delivery team the sub-consultants, subcontractors, and specialist suppliers sit here.
The appointing party plus every delivery team working on the project.
A lead appointed party together with its appointed parties, working under one appointment.
The people producing information for one discipline or one package inside a delivery team.
One organisation holds more than one role at a time. Your main contractor is an appointed party to you and an appointing party to its own suppliers, and the same duties apply one level down. Write that flow-down into the contract, or it stops at the first tier.
Four sets of requirements, and two information models.
Everything the standard asks you to specify follows from one question: what do you need to know, and why. ISO 19650 breaks the answer into four layers, each narrower than the one above, and every layer belongs to the appointing party.
- 01OIROrganisational information requirementsPer organisation
What your organisation needs to know to run itself, across the whole portfolio. Health and safety compliance, environmental management, capital investment and life-cycle costing, risk, maintenance and repairs, asset operations, and space utilisation are the usual headings. Set out in ISO 19650-1 clause 5.2 and ISO 19650-3 clause 5.1.2.
- 02AIRAsset information requirementsPer asset
What you need to know about one asset, derived from the OIR. The asset and facilities management team leads this, and it has to exist before any appointment that touches the asset. Set out in ISO 19650-1 clause 5.3 and ISO 19650-3 clause 5.1.4.
- 03PIRProject information requirementsPer project
What you need at each key decision point on one project, so you can decide rather than wait. There is one set per project, partly derived from the OIR. Set out in ISO 19650-1 clause 5.4 and ISO 19650-2 clause 5.1.2.
- 04EIRExchange information requirementsPer appointment
What one appointed party must deliver, in what form, to what level of information need, and when. This is the set that belongs in the tender pack. Under ISO 19650-3, EIR are also issued for operational-phase appointments in response to a trigger event.
What the delivery phase produces. It grows through design and construction, and it is what you accept at the end of an appointment.
What you maintain through operation. Every accepted information model is aggregated into it, and it feeds the next project.
At the start of a project, relevant information moves from the AIM into the PIM. At the start of operation, it moves back the other way. Keeping that loop closed is the whole job.
One agreed source, and four states.
ISO 19650-1 describes the common data environment as an agreed source of information for any given project or asset, for collecting, managing, and disseminating each information container through a managed process. Every phrase in that sentence is a requirement. An information container is any named, structured set of information: a drawing, a model, a document, a spreadsheet, or a report.
ISO 19650-1 puts every container in one of four states. The states matter less than the gates between them. A container does not drift from work in progress to shared. A check moves it there. It does not become published because someone renamed a folder. A review and an authorisation release it.
- 01Work in progress
Information being developed by its originator or task team, not visible to or accessible by anyone else.
Leaves on a check, a review, and an approval inside the task team.
- 02Shared
Information approved for sharing with other task teams and delivery teams, or with the appointing party. Coordination between disciplines happens here.
Leaves on a review and an authorisation.
- 03Published
Information authorised for use in more detailed design, for construction, or for asset management. This is the record other parties commit decisions to.
Superseded by a later revision, which sends the earlier one to archive.
- 04Archive
A journal of information transactions, providing an audit trail of how each information container developed.
Nothing leaves. Superseded containers stay retrievable here.
agreed source of information · information container · check · review · authorise · audit trail

The standard also separates the CDE workflow from the CDE solution. The workflow is the process: the states, the gates, the naming, the status codes, and the audit trail. The solution is the platform the process runs on. A shared drive with a tidy naming convention looks organised and manages nothing, because it cannot enforce a transition or record who authorised what.
Read the practical guide for document controllersNaming, revision codes, and status codes.
Three pieces of metadata carry most of the standard. A naming convention gives each container a unique, predictable identifier. A revision code records which iteration you hold. A status code, also called a suitability code, records what the container may be used for.
ISO 19650-2 asks the project information standard to define these codes, and fixes no values itself. The set most projects work to comes from the UK National Annex to BS EN ISO 19650-2, revised in February 2021 and shown below. The 2021 revision added S5, removed S6, S7, and CR, and deprecated the B codes, so a register built on the 2018 set still carries values the annex has retired. Australian clients either adopt this set or publish their own, so read the project information standard before you assume a code means what you think.
- S0Initial status. Preliminary revision and version.
- S1Suitable for coordination.
- S2Suitable for information.
- S3Suitable for review and comment.
- S4Suitable for review and authorisation by the lead appointed party.
- S5Suitable for review and acceptance by the appointing party. Added in 2021.
- A1, AnAuthorised and accepted. Contractual revision.
- B1, BnPartial sign-off, with comments. Deprecated in 2021, so avoid it on new work.
- S6, S7Suitable for PIM and AIM authorisation. Removed, and the work they described is now split between S4 and S5.
- CRAs-constructed record document. Removed, because it duplicated an A code.
The codes are how a recipient knows what they may do with a file. A container at S3 is out for review and comment, so nobody should be ordering steel from it. A container at S5 sits with the appointing party for acceptance. A container at A1 has been authorised and accepted. See issued for construction for where the familiar drawing statuses sit against these codes.
AS ISO 19650, and whether you have to comply.
Standards Australia publishes the series as AS ISO 19650, as identical adoptions of the international standards. Parts 1 and 2 were adopted in November 2019, parts 3 and 5 followed in 2021, and parts 4 and 6 have no Australian adoption yet. Committee BD-104 is the Australian mirror of ISO/TC 59/SC 13, the committee that writes the series, so Australian practitioners have taken part in drafting it.
No Australian law requires it. Like most standards it is voluntary in itself, and the obligation to use it has to be created, either by citing it in a contract or by adopting it as organisational policy. What has changed is who creates that obligation. Government policy and client information requirements now do it for a growing share of Australian asset owners, and the four programmes below are the ones an owner is most likely to meet.
Thirteen mandatory actions for Budget Material NSW Government agencies that plan, design, build, operate, or maintain government-owned built infrastructure, excluding state-owned corporations and public financial and non-financial corporations. The policy requires data and information requirements to be established and documented in accordance with ISO 19650, and requires the agency common data environment and its data workflows to be consistent with ISO 19650. Released in October 2025 with an 18-month transition, taking effect in April 2027.
The Digital Engineering Standard states that the structure of the framework is based on the information principles of ISO 19650, and that information flows through approval states based on BS 1192:2007, PAS 1192-2:2013, and ISO 19650-1:2018. TfNSW runs a two-environment model, a contractor CDE and a TfNSW CDE, with information submitted from one to the other.
The VDAS guidance states that its information process is aligned to ISO 19650, and that ISO 19650 is embedded in the VDAS approach. It sets out OIR, AIR, EIR, the AIM, and the PIM in a Victorian context, with templates, and ties them to asset and facilities management activity.
The guideline states that its information requirements are aligned to international best practice standards which include the ISO 19650 series, and that the processes in ISO 19650-2 should be considered alongside the department's Transport Infrastructure Project Delivery System. TMR issues AIR, EIR, and PIR as procurement documents, and requires a BIM execution plan at tender.
Read the requirement before you assume. An Australian client can cite ISO 19650, AS ISO 19650, BS EN ISO 19650 with its UK National Annex, or its own framework that borrows the vocabulary. The words are the same across all four. The status codes, the deliverables, and the naming fields are not.
- NSW Infrastructure Digitalisation and Data Policy, Infrastructure NSW, released October 2025, effective April 2027
- Digital Engineering Framework, Transport for NSW, Digital Engineering Standard DMS-ST-202
- Victorian Digital Asset Strategy, Office of Projects Victoria, published by the Victorian Department of Treasury and Finance
- BIM for Transport and Main Roads Guideline, Queensland Department of Transport and Main Roads, technical standards and publications
Part 3 is the owner's part of the standard.
Parts 1 and 2 describe a project: it starts, it delivers, it closes. Part 3 describes an asset you will hold for thirty years. It reuses the eight-step shape of part 2, so the process is recognisable, then changes what drives it.
Trigger events are the occurrences during the life of an asset that cause new or updated information to be required. They set the tempo of information management in operation the way plan-of-work stages set it on a project. Some are foreseeable, such as a scheduled inspection, a maintenance cycle, or a planned refurbishment, and part 3 asks you to identify those in advance. Others cannot be planned for, such as a failure or a storm, and the plans you made for the foreseeable ones are what you fall back on. The idea came across from PAS 1192-3.
The AIM is the information you hold about the asset in operation. Each accepted information model from a delivery team is aggregated into it, and part 3 asks you to establish it, establish the processes that maintain it, and keep reviewing it. Treating it as a deliverable you receive once, at practical completion, is the mistake the standard is written to prevent.
Information reaches an operating asset in several ways, so part 3 has several routes through the process: an appointment made ahead of a foreseeable trigger event, an appointment made after an unforeseen one, a delivery-phase project run to ISO 19650-2, and the acquisition of an existing asset from another owner. That last pathway is why the standard applies to the estate you already have.
- 01Assessment and need
- 02Invitation to tender, or request to provide a service
- 03Response to that invitation or request
- 04Appointment
- 05Mobilisation
- 06Production of information
- 07Information model acceptance by the appointing party
- 08Aggregation into the asset information model
- Establish organisational information requirements (5.1.2)
- Identify the assets for which information will be managed (5.1.3)
- Establish asset information requirements (5.1.4)
- Identify foreseeable trigger events (5.1.5)
- Establish links to enterprise systems (5.1.10)
- Establish the asset information model (5.1.11)
- Establish processes to maintain the asset information model (5.1.12)
- Decide the type of activity providing information (5.2.1)
- Maintain resources in readiness for a trigger event (5.5.4)
- Aggregate an accepted information model into the AIM (5.8.1)
- Review and continue maintenance of the AIM (5.8.2)
Read that clause list as a job description. Almost all of it describes standing work the owner does continuously, in a system the owner controls, between projects. This is where most implementations leave a gap: the delivery-phase environment closes with the project, the AIM has nowhere to live, and by the next trigger event the record is a shared drive again. An asset owner who has written the AIR, established the AIM, and kept the audit trail in one place answers a part 3 question from the record. An owner who has not answers it from an inbox.
trigger events · asset information model · aggregation · maintenance · links to enterprise systems

What an asset owner actually has to do.
None of this needs a consultant to start. Work top to bottom, and write down what you decide, because a written decision is what an audit reads. Compliance is a property of how you work, so the artefacts below are the evidence.
- 01Write the OIR. Name the business activities that need asset information, and the reason each one needs it.
- 02Write the AIR for each class of asset you own, derived from the OIR, and have the asset management team lead it.
- 03Write the PIR for each project, tied to the key decision points you actually make.
- 04Write an EIR for every appointment, and put it in the tender pack rather than in a covering email.
- 05Publish a project information standard: the naming convention, the status codes in use, the revision convention, and the metadata every container carries.
- 06Publish information production methods and procedures, including the native formats you will accept alongside published PDFs.
- 07Set the level of information need for each exchange, so you receive what you asked for and no more.
- 08Name the common data environment, say who operates it, and say who holds it after the project ends.
- 09Run the ISO 19650-5 triage to decide whether the asset is security sensitive before you publish anything about it.
- 10Cite the information requirements in the contract, so they are a deliverable rather than a preference.
- 01Enforce the gates. A container advances on a check, a review, and an authorisation, never on a rename or a folder move.
- 02Require a status code and a revision code on every container, at every exchange.
- 03Review each exchange against the EIR at the exchange point, and reject an incomplete one there rather than at handover.
- 04Issue information to parties outside the environment as a recorded transmittal, with the cover sheet listing every container and its revision.
- 05Keep the audit trail complete: who changed a container, who reviewed it, who authorised it, and when.
- 06Keep superseded revisions in archive rather than deleting them, so what was issued stays retrievable.
- 01Validate the package against the EIR and the delivery plan, container by container, before you accept it.
- 02Take native files as well as plots, so the record stays editable by the next appointment.
- 03Take the metadata, the revision history, and the audit trail alongside the files themselves.
- 04Move accepted containers to the as-constructed record status, and aggregate the accepted information model into the AIM.
- 05Confirm the record now sits in a system you control, on an instance you can export from.
- 01List your foreseeable trigger events, and write an EIR for each one ahead of time.
- 02Update the AIM after every trigger event, so it keeps representing the asset as it stands.
- 03Link the AIM to the enterprise systems that consume it, for example asset management, maintenance, and GIS.
- 04Audit the record each year: sample a set of containers and check the current revision, the status, and the completeness of the history.
- 05Test an export. A record you cannot get out is a record you do not own.
Two of these carry more weight than the rest. Naming the common data environment and saying who holds it after the project decides whether you own the record or borrow it. Testing an export decides whether that ownership is real. Take a drawing register template if you need somewhere to start the audit.
What the software has to do, and where Lunr lines up.
No software makes you compliant, because compliance is a property of how you work. What a platform can do is carry the workflow so the discipline survives a busy week, and hold the record after the delivery team has gone. Each line below maps a requirement from this guide to something Lunr does.
One controlled register for every drawing, model, and document. Automatic numbering applies your register format as containers are booked in, and title-block tags are read into metadata, so the number, revision, and discipline come off the sheet. See document control.
Define the states your project uses, the reviews and approvals that move a container between them, and the roles that can act at each gate. See configurable workflows.
Every information container carries its number, revision, status, and metadata as first-class fields, across DWG, DGN, RVT, PDF, and IFC, with superseded revisions kept and marked.
External organisations join as collaborators with access to only what their role needs, or receive a tracked transmittal without any repository access at all.
Every change, review, and state transition is logged against the container, so a question about who approved a drawing, and when, is answered from the record rather than an inbox.
Validate each handover package against a manifest, so a missing as-constructed drawing is caught on upload, then keep the containers, the revision history, and the audit trail after the delivery team leaves.
XRAY runs OCR and full-text search across scans and CAD, so a valve tag on a 1994 sheet is findable, and Rift, Foundry, and Nimbus open drawings, models, and point clouds in the browser with no CAD licence.
Hosted in Australia and the US, operated by an ISO/IEC 27001:2022 certified partner, with SAML sign-in and export at any time. See security and compliance.
Lunr is engineering document management that serves as your common data environment, built for the appointing party rather than for the project. When the project closes the environment stays with you, along with every information container, its revision history, and its audit trail. Universities, utilities, energy companies, and government departments run their record on it, and more than 10 million documents are under management today.
Lunr holds no ISO 19650 certification, and no vendor can certify your process for you. The platform carries the workflow. You run the process.
information containers · configurable workflows · transmittals · manifest validation · full audit trail · hosted in Australia and the US

Questions asset owners ask about ISO 19650.
Whether it is mandatory, what it replaced, how it relates to a common data environment, and which part matters most to an owner.
- Is ISO 19650 mandatory in Australia?
- No Australian law requires ISO 19650. Standards Australia has adopted parts 1, 2, 3, and 5 as AS ISO 19650, but a standard is voluntary in itself, and the obligation to use it has to be created, either by citing it in a contract or by adopting it as organisational policy. In practice that obligation is increasingly created for asset owners by government policy. The NSW Infrastructure Digitalisation and Data Policy, released by Infrastructure NSW in October 2025 and taking effect in April 2027, requires in-scope NSW agencies to establish information requirements in accordance with ISO 19650 and to run a common data environment consistent with it. Transport for NSW, the Victorian Digital Asset Strategy, and the Queensland Department of Transport and Main Roads all base their digital engineering requirements on the series. For a private owner, the obligation arrives through the tenders you write and the contracts you sign.
- What replaced BS 1192 and PAS 1192?
- ISO 19650 did. BS 1192:2007 set the original British conventions for the collaborative production of architectural, engineering, and construction information, and PAS 1192-2:2013 extended them for building information modelling on the delivery phase. BS EN ISO 19650-1:2018 and BS EN ISO 19650-2:2018 superseded both, and PAS 1192-3, which covered the operational phase, was carried into ISO 19650-3:2020. Anyone who worked to BS 1192 will recognise most of ISO 19650: the states, the naming discipline, and the suitability codes came across, with new labels and a wider scope.
- What is the difference between ISO 19650 and a common data environment?
- ISO 19650 is the standard. A common data environment is one of the things the standard asks for. ISO 19650-1 describes the CDE as an agreed source of information for any given project or asset, for collecting, managing, and disseminating each information container through a managed process. The standard also draws a line between the CDE workflow, which is the process of states, gates, naming, status codes, and audit trail, and the CDE solution, which is the platform that process runs on. You can buy a solution and still fail the workflow, because a folder cannot enforce a state transition or record who authorised what.
- Does ISO 19650 apply to existing assets, or only to new projects?
- It applies to existing assets. ISO 19650-3 covers the operational phase, and its process has a pathway specifically for acquiring an asset from a previous owner, alongside pathways for foreseeable trigger events, unforeseeable ones, and delivery-phase projects run to ISO 19650-2. For an owner with decades of inherited drawings, the practical starting point is to write the asset information requirements, establish the asset information model with whatever you hold today, and improve it at each trigger event rather than waiting for a greenfield project.
- What are the four CDE states in ISO 19650?
- Work in progress, shared, published, and archive. Work in progress holds information being developed by its originator or task team, not visible to anyone else. Shared holds information approved for sharing with other task teams, delivery teams, or the appointing party, for coordination and review. Published holds information authorised for use in more detailed design, for construction, or for asset management. Archive is a journal of information transactions that provides an audit trail of how each container developed, and it is where superseded revisions stay retrievable. The states matter less than the gates between them: a check moves a container from work in progress to shared, and a review and an authorisation move it to published.
- What are the ISO 19650 status codes?
- A status code, also called a suitability code, records what an information container may be used for. ISO 19650-2 requires the project's information standard to define the codes, and does not fix the values itself. The set most projects work to comes from the UK National Annex to BS EN ISO 19650-2, revised in February 2021: S0 initial status in work in progress; then S1 suitable for coordination, S2 suitable for information, S3 suitable for review and comment, S4 suitable for review and authorisation by the lead appointed party, and S5 suitable for review and acceptance by the appointing party while shared; then A1 to An authorised and accepted once published, with B1 to Bn partial sign-off now deprecated. The 2021 revision added S5 and removed S6, S7, and CR, so a register built on the 2018 set still carries values the annex has retired. Australian clients either adopt this set or publish their own, so read the project information standard before assuming what a code means.
- Which part of ISO 19650 matters most to an asset owner?
- Part 3, the operational phase. Parts 1 and 2 describe a project that starts, delivers, and closes, which is why most commentary and most tender requirements point there. Part 3 describes the asset you hold for decades. It introduces trigger events, the occurrences during the life of an asset that cause new or updated information to be required, and it makes the asset information model something you establish, maintain, and keep reviewing rather than something you receive once at handover. Eleven of its clauses have no counterpart in part 2, and almost all of them describe standing work the owner does between projects.
- Can a software product be ISO 19650 certified?
- Not in the sense most buyers mean. ISO 19650 describes a process, so it names no software and mandates no file format, and no product can make an organisation compliant on its own. Certification schemes do exist against the series, including the BSI Kitemark, which is awarded to organisations for their own information management and separately to software vendors for user functionality that supports the process. Treat a vendor claim as evidence that a platform can carry the workflow, and treat your own compliance as a property of how your team works, evidenced by your information requirements, your states and gates, and your audit trail.
Run the standard, and keep the record.
Book a walkthrough and watch Lunr move an information container through work in progress, shared, and published, with the decision and the reviewer recorded at every gate, then hold it after the project team leaves.
10M+ documents under management · Hosted in Australia and the US · SAML · Full audit trail · Export anytime
- entity
- Lunr Labs Pty Ltd
- location
- Melbourne AU
- workspace
- documents.lunr.app
- rev
- 2026