Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

How to Set SPI Targets and Alert Levels: 12 Examples and a Worked Year

Set SPI targets and alert levels from a baseline: 12 example SPIs with formulas, a worked year of data, the mean and SD maths, and a low-count warning.

Dionysis Kefalas12 min read

On this page

March 2026 closes at ExampleMRO with 16 tool-control events against 6,700 labour hours: 2.39 per 1,000 hours, the highest reading in fifteen months and the third month in a row above target. The safety review board meets next week. Signal or noise?

You can only answer that with levels set before the month arrived. A common method: express the SPI as a rate, take at least 12 months as a baseline, and calculate the mean and standard deviation of the monthly values. Put the first alert level at the mean plus one standard deviation, the second at the mean plus two. Set the target as a planned reduction from the baseline mean, such as 10%, and judge it over the year. A month below the first alert level is normal variation. Above it, look closer. Above the second, investigate. When counts are small, widen the window or use leading indicators.

The ExampleMRO numbers are fictional and fully worked, so you can check each one. The methods are common practice. What the rules say about safety performance monitoring is quoted in the EASA safety performance indicators guide.

What makes an SPI usable

The EU Basic Regulation defines a safety performance indicator and a safety performance target in one line each. An SPI is usable when two people calculating it from the same records get the same number, and someone answers for it. That takes:

  • A counting rule. A tool reported missing and found ten minutes later: one event or none? Decide before the data arrives.
  • A numerator and a denominator. Twelve events in a 5,000-hour month is 2.40 per 1,000 hours; in an 8,000-hour month it is 1.50. Divide by the exposure that drives the risk: flight hours, cycles or departures for an operator or CAMO, labour hours or work packages for a maintenance organisation.
  • A multiplier that gives readable numbers: per 1,000 flight hours, per 100 work packages. Proportions become percentages.
  • A named data source for both halves, and the person who extracts it.
  • A frequency and a cut-off: monthly, completed months only, the same working day each month.
  • An owner who answers for the decision on each reading.
  • A direction and a type. Is lower or higher better? Is it lagging, counting outcomes that already happened, or leading, measuring the checks, training and actions meant to prevent them?

Pair the types. The lagging SPI says whether the controls work. The leading one says it sooner, usually with a denominator large enough to be statistically useful. A barrier in a bow-tie is a good place to find it.

12 example SPIs with formulas and data sources

Written for this article, not taken from any catalogue. Adapt the counting rule, the window and the multiplier to your organisation.

SPIAreaTypeFormulaData source
Tool-control eventsMaintenanceLaggingTools lost, unaccounted for or misused ÷ labour hours × 1,000Internal reports, tool store log
Defects traced to maintenance after releaseMaintenanceLaggingPost-release defects attributed to the organisation's work ÷ work packages released × 100Customer defect reports, investigations
Complete handovers at spot checkMaintenanceLeadingSampled handovers fully recorded ÷ handovers sampled × 100Supervisor spot checks
Shift-end tool checks completedMaintenanceLeadingChecks signed off ÷ shifts worked × 100Tool-board check sheets, roster
Maintenance tasks completed lateCAMOLaggingTasks due that passed their limit ÷ tasks due × 1,000Maintenance tracking records
Repeat defectsCAMOLaggingDefects recurring on the same aircraft and ATA chapter within the repeat window ÷ flight hours × 1,000Technical log, defect records
AD applicability assessed on timeCAMOLeadingNew ADs assessed within the internal target time ÷ new ADs received × 100AD assessment records
Deferred defects closed within their limitCAMOLeadingDeferrals rectified within their rectification interval ÷ deferrals rectified × 100Deferred defect log
Unstabilised approachesFlight opsLaggingApproaches outside the stabilisation criteria ÷ approaches flown × 1,000Flight data monitoring
Ground damage eventsFlight opsLaggingGround damage events ÷ departures × 1,000Occurrence and handling reports
Crew training completed before due dateFlight opsLeadingItems completed before due ÷ items due × 100Crew training records
Safety reports answered on timeFlight opsLeadingReports answered within the internal target time ÷ reports closed × 100Safety reporting system

Lower is better for every lagging row, higher for every leading percentage.

Worked example: tool-control events at ExampleMRO

ExampleMRO is a fictional maintenance organisation with a main base and a line station. The main base's definition card doubles as a template:

FieldExampleMRO's entry
NameTool-control events per 1,000 labour hours
One event isA tool lost, unaccounted for at shift end, found in an aircraft, or used past its calibration date; one per tool per task
Numerator / denominatorEvents in the month / labour hours booked to work orders
Multiplier× 1,000
Data sourceSafety reports and tool store log; time booking
FrequencyMonthly, completed months, by the fifth working day
OwnerSafety manager
Direction, typeLower is better; lagging
Leading partnerShift-end tool checks completed

Step 1: the baseline year

Month (2025)Labour hoursEventsRate per 1,000 h
January6,400111.72
February6,100121.97
March6,900101.45
April6,700131.94
May7,200121.67
June7,000142.00
July6,300111.75
August5,600122.14
September6,800101.47
October7,100152.11
November6,900121.74
December5,90091.53

The mean of the twelve rates is 1.79, and the year as a whole gives the same: 141 events over 78,900 hours. The sample standard deviation (STDEV.S in a spreadsheet) is 0.24. Record which formula you used, so next year's recalculation matches.

Step 2: alert levels and the target

  • First alert level: mean + 1 SD = 1.79 + 0.24 = 2.03
  • Second alert level: mean + 2 SD = 1.79 + 0.48 = 2.27
  • Target: 10% below the baseline mean = 1.79 × 0.9 = 1.61

Run 2025 back through those levels: nine months above the target, two above the first alert level (August and October), none above the second. That is the expected shape if the rates are roughly normal: about one month in six above the first level by chance, rarely one above the second.

At 2025's workload, 1.61 means about 127 events a year instead of 141: fourteen fewer, just over one a month. Monthly counts already ranged from 9 to 15, so a one-event improvement disappears inside any single month. Judge the target on the year's rate and let the alert levels do the monthly work.

How big a cut is a management decision, and it should rest on a change. ExampleMRO's rests on shadow boards and a signed shift-end tool check from January 2026. A target with no action behind it is a hope.

Step 3: read three months and decide

MonthLabour hoursEventsRateAgainst the levels
January 20266,600111.67Misses the target (1.61), below the baseline mean
February 20265,400122.22Above the first alert level (2.03)
March 20266,700162.39Above the second alert level (2.27)
January–March 202618,700392.09Above the baseline mean (1.79)

January: no action, reason recorded. 1.67 misses the target but sits below the 2025 mean. The recorded reason: "Below the 2025 mean and inside normal variation. The target is assessed on the annual rate."

February: look closer, then decide. Twelve events is exactly the 2025 median. The rate jumped because winter leave cut hours to 5,400, 18% below the 2025 average of 6,575; at average hours the same count reads 1.83. The safety manager reads the twelve reports anyway: different tools, shifts and tasks, no common thread. No investigation. The reason records the hours and the review, and March is flagged to watch. Check the numerator and the denominator before you believe the rate.

March: investigate. Sixteen events on normal hours, above the second alert level, and the third miss in a row. The quarter's 2.09 is above the 2025 mean, not just the target. Each month had a story. Together they are a trend, and it started with the new shift-end check.

That timing is the first question. A check built to find loose tools often raises the count before it lowers it. The safety manager raises a task for the stores supervisor, due before the April board: split the sixteen events into those caught at the shift-end check, where the barrier worked, and those found after the aircraft left the bay, where it did not. If most were caught, the SPI needs a sharper definition that counts escapes separately, applied from a stated month with the old history kept. The occurrence analysis guide covers the wider loop from reports to corrective action.

Low counts: when the alert levels mislead

ExampleMRO's line station books 400 labour hours a month. Its 2025 months read 0, 1, 0, 0, 1, 0, 0, 2, 0, 1, 0, 1 tool-control events.

One event is 2.50 per 1,000 hours; two is 5.00. The mean of the monthly rates is 1.25 and the standard deviation 1.69, larger than the mean. Mean plus one SD is 2.94, mean plus two is 4.62, and no month can land between them: one event stays below the first level, two jump past the second. The "second alert level" just means "two or more events in a month". If events occur at random at half an event a month on average (a Poisson model), that happens by chance about 9% of the time, roughly once a year. At the same average, about 61% of months have no event at all. Those are not good months, only empty ones.

At these numbers:

  • Widen the window: a rolling 12-month count or a quarterly rate.
  • Pool the data: report the station inside the organisation-wide rate, with the station split for context.
  • Use leading indicators: shift-end tool checks run to hundreds a month even at a small station.
  • Treat each event as a case. At six a year, every report is worth reading and the rate adds little.

EASA's guidance on reliability programmes for small fleets makes the same point about alert levels calculated from little data, and calls for engineering judgement when a single event reaches one: see paragraphs 6.2.4 and 6.2.5 of Appendix I to AMC M.A.302 in the Easy Access Rules for Continuing Airworthiness (revision of 2 September 2025). It is written for maintenance-programme reliability rather than SMS indicators, but the statistics behave the same way. The reliability programme guide sets out that context.

The monthly review routine

  1. Close the month on a fixed day, for completed months only.
  2. Check the inputs before the rate. Is the count complete? Did the hours move? Were reports reclassified? A missing denominator means no value, not zero.
  3. Read each SPI against its levels and its last 12 months. One month is a data point. The line is the evidence.
  4. Decide on every miss. Normal variation: record why no action is needed. First alert: read the reports, then decide. Second alert: investigate, with an owner, a question and a date.
  5. Look for runs. Three misses in a row, or four in the last six, deserve attention even when no month reached an alert level.
  6. Follow up what is open. Did the SPI move after the action?
  7. Give the safety review board one page: SPIs in alert, decisions taken, investigations open. The management review article covers the rest of that pack.
  8. Recalculate once a year, applied from a stated month. Levels that move every month stop being levels. Retire any SPI that never moves or that nobody acts on.

Doing this in Avioverse

The Safety Performance Indicators module follows the same steps. Setting up an SPI runs through Definition, Tracking and Review. In Definition you pick A rate, fill in What are you counting? and Measured against what?, and set Show per to "× 1,000 (per 1,000)". In Tracking you Set a Safety Performance Target: the SPT, the Direction ("Lower is better"), optional Yellow alert and Orange alert levels, and when the Target applies from. ExampleMRO sets up the SPI in December 2025 and enters 1.61, 2.03 and 2.27 to apply from January 2026. A target applies from the current month or a later one; it cannot be backdated.

Each month you Enter monthly data for the completed month, and Avioverse calculates the value. A missing measure or a zero denominator leaves the month unassessed, not zero. Every month is compared with the SPT: January shows SPT exceeded, February Yellow alert, March Orange alert. The alert levels grade a miss and never fire on their own; with no SPT, nothing is flagged. A target below the baseline mean will therefore be missed in ordinary months. Two trend rules in Settings & versions catch runs: Trigger after N consecutive SPT misses and Trigger when K of the last W periods miss the SPT. Set the first to 3 and March is flagged as a trend too.

Each exceedance offers three actions. Acknowledge records that you have seen it and leaves it open. Reviewed — no action required resolves it and needs a written reason. Create task opens a task titled "Investigate Tool-control events per 1,000 labour hours — March 2026", and completing that task resolves the exceedance.

Formula, target and alert changes apply from a month you choose, and Saved versions keeps the earlier ones. The chart draws the SPT and alert lines, and each SPI exports to PDF and Measurement history (CSV). The Reference library holds 112 definitions, each showing its source: 47 derive from the UK CAA's CAP 3114 and 65 are written by Avioverse. As the library says, alert and action thresholds aren't prescribed; they depend on your fleet and baseline.

You calculate the baseline, choose the levels and judge each month. Values come from what you enter, or from an import you approve.

Frequently asked questions

How do you set an alert level for a safety performance indicator?

A common method takes at least 12 months of the SPI as a monthly rate and calculates the mean and standard deviation. The first alert level sits at the mean plus one standard deviation, the second at the mean plus two. Recalculate once a year, not every month.

What is the difference between an SPI target and an alert level?

The target is the improvement you plan, such as 10% below the baseline mean, and it is judged over the year. An alert level marks a month outside normal variation, which calls for a closer look or an investigation.

How much data do you need to set SPI alert levels?

Twelve monthly values is a common minimum. If the SPI counts only a few events a year, the standard deviation is too coarse to use: widen the window, pool the data, or use a leading indicator with a larger denominator.

What should you do when an SPI goes above its alert level?

Check the count and the denominator first, then read the underlying reports. Decide whether it is normal variation (record why no action is needed), something to watch, or something to investigate with an owner, a question and a due date.

What are examples of leading and lagging SPIs?

Lagging: tool-control events per 1,000 labour hours, repeat defects per 1,000 flight hours, ground damage per 1,000 departures. Leading: the percentage of shift-end tool checks completed, of ADs assessed on time, or of safety reports answered within the target time.

Does Avioverse calculate SPI alert levels?

It calculates each month's SPI value from your formula and compares it with the target and the optional Yellow and Orange alert levels you enter. You derive those levels from your own baseline.

Related

Written by Dionysis Kefalas. Retired Hellenic Air Force Captain and founder of Avioverse. About the author

Request early access →

Start from a reference library of SPI definitions or write your own formula, enter each completed month's figures, and see when a result misses your target. Opens in October 2026.

ShareLinkedInX