Aviation Audit Software for Part-145 and CAMO: From Checklist to Closed Finding
Ten tests for choosing aviation audit software, then one internal audit in Avioverse, from programme and checklist to a closed, evidenced finding.
Dionysis Kefalas11 min read
On this page
The checklist is a Word file called QA-CHK-07-rev6-FINAL2.docx. Half its items quote rule text from before the last amendment. The findings register is a spreadsheet with a colour code one person can read. The corrective action plan for finding 14 is a PDF attached to the fourth reply in a thread called "RE: FW: audit ExampleMRO". Finding 9 says "Closed". Nothing next to it says why.
Word for the checklist, Excel for the register, email for everything in between. Aviation audit software should turn that chain into one record. Each checklist item carries the rule text it was written against and warns you when an amendment changes it. Findings are graded Level 1, Level 2 or Observation. The auditee answers inside the finding, through a link, not in your inbox. And the close button refuses to work until the root cause, the corrective action plan, the implemented actions and a risk decision are on file.
Below: ten tests for any audit tool, then one internal audit in Avioverse, from programme to closed finding.
What aviation audit software must do: a 10-point checklist
Run these in a trial with your own data. A demo shows the path the vendor chose.
-
Checklist items trace to the current rule text. An item should hold the reference and the exact text it was written against, and the tool should flag items whose text an amendment has changed. Test: open an item. Can you see the text behind it, and whether that text is still in force?
-
Checklists are versioned, and each audit keeps its version. Editing a checklist must not rewrite what an earlier audit was run against. Test: change a checklist you have used, then open the old audit.
-
The programme shows gaps, not just plans. Coverage by activity, location and contractor, with a hard line between an audit planned and an audit done. Test: can it show an area with no completed audit this cycle?
-
Finding levels match your procedure. Level 1, Level 2 and Observation, each with a target date, and your internal grade kept apart from any authority deadline. Level 1 and Level 2 findings explained covers what the rules say about each.
-
The auditee can respond without an account. Ask every department head, contractor and supplier to register first, and the replies go back to email. Test: send a finding to someone outside your organisation and see where their answer lands.
-
Closure is gated on the fix, not on a status change. For findings an authority raises, Part-145 sets out the organisation's side in 145.A.95:
(a) After the receipt of a notification of findings in accordance with point 145.B.350, the organisation shall:
(1) identify the root cause(s) of, and contributing factor(s) to, the non-compliance;
(2) define a corrective action plan;
(3) demonstrate the implementation of corrective action to the satisfaction of the competent authority.
CAMO.A.150 and, for air operators, ORO.GEN.150 have the same three steps. If you hold internal findings to that standard, the tool should refuse to close one until all three are recorded, and accepting the auditee's reply should not count as closing. Test: try to close a finding with an empty root cause.
-
Every finding carries a risk decision. A linked risk assessment, or a written reason why none is needed. A blank field is not a decision.
-
The person who closes is not the person who did the work. In a team, the tool should stop a finding's author or its responsible person from closing it. Test: assign a finding to yourself, then try to close it.
-
Effectiveness is checked after closure. Closed does not mean the fix worked. You need somewhere to schedule a check, record what you verified, or record that none is needed.
-
Issued reports survive reopening, and leave as a record. A correction after issue should keep the version people already saw, and the report and checklist should export in a form an inspector can read. Test: reopen an issued audit. Is the first issue still there?
Doing it in Avioverse: one internal audit, start to finish
Open Audits. It has five tabs: Audit work, Checklists, Findings, Calendar and Programmes. The example is ExampleMRO's quality team auditing tool control at a line station.
1. The programme: coverage and gaps
A programme in Programmes holds the period, objective, scope and boundaries, and applicable criteria. Each coverage requirement names an activity, location or contractor, the Required audits, a Target date, and Why this coverage and frequency are appropriate. Each line then reads Covered, Partly covered, Planned, Not planned, Overdue gap or Excluded.
Only a completed audit counts, and in a team it must also be approved. The screen says it plainly: "Planned audits alone do not close a gap." A programme cannot close while any requirement is neither covered nor excluded with a reason. What the cycle has to include is in the audit programme guide.
2. The checklist: built from the rule text, versioned
Under Checklists, the Avioverse library holds 13 read-only checklists:
- instruments, data and equipment for Part-CAT, Part-NCC and Part-SPO (aeroplanes and helicopters) and Part-NCO (helicopters);
- Part-CAMO;
- the ACAM survey key risk elements from GM1 M.B.303(b);
- Part-26 Subparts B and C;
- a Part-66.A.45(c) OJT compliance aid for Part-145 organisations;
- a Transport Malta aircraft phase-in aid.
Add to My checklists copies one to run or adapt. There is no Part-145 or Part-147 checklist in the library, so ExampleMRO builds its own: New checklist, then Add from regulation to turn 145.A.40 into items. Each item keeps its wording, the reference and a frozen copy of the regulation text, and Show regulation text puts that copy beside the item during the audit. Each checklist uses one response scale: Compliance, Documented / Implemented, or Yes / No / N/A.
Lock version before the first audit. Later changes go through Edit (new version), so earlier audits keep the version they ran. When an amendment changes the text behind an item, the checklist says so: "Amendment … changed the regulation behind 3 checklist items. Review the changes before running new audits." It shows In your checklist (frozen) beside In force today.
3. The schedule: one-off or repeating
A checklist can be scheduled One-time or Repeating: daily, weekly, monthly or yearly. After the first save, any change asks for a Reason for schedule change, and only future occurrences not yet started are cancelled. When you start a scheduled audit, you enter the real date: "Enter when the audit is actually taking place. The planned date stays in your programme." An occurrence that slips shows Overdue. Once the next one is also past due, the older one becomes Missed. The Calendar tab shows the year's programme, and audit dates also appear on your Avioverse calendar.
4. The audit itself
Plan & team (Plan in a personal audit) holds the Objective, Scope, Criteria and Sampling method. Save and confirm plan confirms it, and any later change asks for a reason. Team roles are Lead auditor, Auditor, Independent reviewer and Observer. In Checklist, the auditor answers each item, filters to Unanswered or Needs a finding, adds Custom items for what the checklist missed, and uses Raise finding on the spot.
Mark audit complete stays blocked until every criterion is checked, every adverse answer has a finding and the summary is written. A team audit also needs a confirmed plan and a responsible person on every finding. Completion preserves the report, gives each open finding a close-out date no more than three months away, and creates a close-out task for each one. The report is then signed off with Approve report.
5. The findings
A finding is Level 1 — Significant non-compliance, Level 2 — Non-compliance or Observation — Improvement recommended. It holds a description, evidence, proposed corrective actions, a regulatory reference and a Target close-out date, and it gets a reference such as AUD-000014.2. Every finding card carries the same line: "Internal finding grade: follow your organisation's procedure. Authority-issued deadlines are separate." The Findings tab lists them by audit.
6. The auditee's response: a link, not an attachment
Share with auditee creates one link for the open findings you select. A passphrase protects it by default. It expires after 1 to 365 days (90 by default), and you can revoke it. Avioverse sends no email: you send the link yourself.
The auditee needs no account. They answer in two stages: first the plan (root cause classification, root cause notes, corrective action plan and files), then the actions taken and preventive actions, with files of up to 20 MB each. Nothing reaches you until they send it: "Draft saved privately. It is shared with the auditor only when you send it." They can also ask for a later close-out date.
You review each stage with Approve plan or Request plan changes, then Accept actions or Request action changes. Accepting closes nothing. The card says what comes next: "The finding owner records the risk decision; the finding can then be closed."
7. Closing: the gate
Mark closed stays disabled, with a Before closing: list under it, until these are recorded:
- for Level 1, the immediate containment decision;
- for Level 1 and Level 2, the actual root cause (classified and explained) and the corrective action plan;
- for every level, the implemented actions and evidence, or for an observation, the outcome;
- a risk decision.
The Responsible person makes the risk decision: Create new, Link existing or No risk assessment. A linked assessment must be finalised before the finding can close. No risk assessment needs a written Rationale (required). Closing after the target date asks Close as overdue?, and the finding is marked Closed overdue.
In a team audit, the independent reviewer closes. They hold the reviewer role, have written an independence statement, and are neither the finding's author nor its responsible person. Nobody else gets Mark closed, and a reviewer who raised or edited the finding, or is its responsible person, is refused: "You cannot review your own work. Assign an independent reviewer." In a personal workspace, you close your own findings. How to reach a root cause that holds up is covered in the root cause and corrective action guide.
8. Verification after closure
A closed finding offers Schedule verification, Not required and Record verification. Recording asks one question: "What did you verify, and did it work?" The finding then shows Verification scheduled, Verification done or Verification not required, and a scheduled check becomes a task. It is refused on an open finding: the fix comes first, the check on it after.
9. Reopening, and the record
Reopening an audit needs a reason. The earlier issue is kept as a Preserved audit report, the sign-off is cleared, and live share links are revoked. An issued or shared audit cannot be deleted, only archived. A single finding can also be reopened, with a reason and a new due date. The record leaves as PDF: Audit report, Audit checklist and Preserved audit report.
Where AI helps, and what stays with the auditor
Every AI action in Audits starts with a button you press.
- Add with AI takes the purpose of the audit and proposes regulation paragraphs from the library, plus custom questions. You tick the ones you want and choose Add selected.
- Paraphrase with AI offers a rewrite of an item. Replace item accepts it.
- Draft with AI drafts the Auditor actions for an item.
- Fill with AI drafts the factual part of the report summary. The box says where it stops: "the compliance judgment stays yours to write."
No AI answers a checklist item, grades a finding, accepts a response or closes a finding. In chat, Metis can turn your audit facts into a proposed finding with the requirement quoted, for you to review. It records nothing. It can change a finding's root cause classification and corrective action plan only after you approve the change. It can draft a linked risk assessment, but it cannot finalise one or choose No risk assessment. Can AI draft aviation audit findings safely? sets out the guardrails, and AI for aviation audits covers the preparation around the audit day.
Plans, teams and limits
Everything above except sharing runs on the Free plan, with no create limits: programmes, checklists, schedules, audits, findings, closure, verification and PDFs. AI inside Audits also works on Free and spends the small monthly AI allowance. Creating a share needs Pro: the auditee response link, the report acceptance link and a checklist copy link. The auditee opens a response or report link with no account and no plan. Pricing has the detail.
Audits run in a personal workspace or a team workspace, for teams of any size. In a team, owners and admins manage checklists and programmes. Any member can start an audit from a locked team checklist and becomes its lead. The lead and auditors carry out the audit, the independent reviewer approves the report, reviews auditee responses and closes findings, and observers can only read.
The limits, in one place. Avioverse supports compliance monitoring under your organisation's own approval scope and procedures. It does not certify compliance, decide what applies, choose your sample or judge competence. Report acceptance is a typed name, not an electronic signature, and a passphrase protects a link without proving who opened it. Implemented actions and evidence are recorded as text, and no file is required. Exports are PDF only, with no CSV or Excel. Findings an authority raises against your organisation fit the External audit findings template in Trackers rather than an internal audit.
Frequently asked questions
What should aviation audit software do?
Keep each checklist item tied to the rule text it was written against, show gaps in the audit programme, grade findings Level 1, Level 2 or Observation, take the auditee's response inside the finding, and refuse closure until the root cause, corrective action plan, implemented actions and a risk decision are recorded. Reopening an issued report should keep the earlier issue.
Is there a Part-145 audit checklist in Avioverse?
Not in the library. The 13 library checklists include Part-CAMO, Air Ops instruments and equipment, Part-26 and a Part-66 OJT aid, but no Part-145 or Part-147 checklist. You build your own with Add from regulation, which puts the rule text behind each item.
Does the auditee need an account to respond to a finding?
No. They open a link, protected by a passphrase by default, and send their plan and then their actions, with files. Creating the link needs the Pro plan. Opening it needs no account and no plan.
Can a finding be closed without a root cause or evidence?
No. Mark closed stays disabled until the implemented actions and evidence (for an observation, the outcome) are recorded and a risk decision is made. Level 1 and Level 2 findings also need a classified root cause and a corrective action plan, and a Level 1 finding needs the containment decision.
Does AI grade or close findings in Avioverse?
No. AI can propose checklist items, rewrite an item, draft auditor actions and draft the factual part of the report summary. Answering items, grading findings, accepting responses and closing findings stay with the auditor.
What can I export from an audit?
PDFs of the audit report, the audit checklist and any preserved earlier issue of the report. There is no CSV or Excel export for audits.
Related
- EASA Level 1 and Level 2 Findings: Rules and DeadlinesGuide · 17 min
- Root Cause Analysis and CAPs for EASA Audit FindingsGuide · 16 min
- Compliance Monitoring Audit Programme: Part-145 and CAMOGuide · 18 min
- Can AI Draft Aviation Audit Findings Safely?Article · 9 min
- AI for Aviation Audits, Not a ReplacementArticle · 9 min
- Using AI to Prepare an Aviation CAP for ReviewArticle · 8 min
Written by Dionysis Kefalas. Retired Hellenic Air Force Captain and founder of Avioverse. About the author
Build a checklist or copy one from the Avioverse audit library, run the audit, raise findings and export the report as a PDF; the audit judgement stays yours. Opens in October 2026.