IRImplementing rule
ATM/ANS.AR.B.001Management system
(a)The competent authority shall establish and maintain a management system, including, as a minimum, the following elements:
(1)documented policies and procedures to describe its organisation, means and methods to achieve compliance with Regulation (EU) 2018/1139 and the delegated and implementing acts adopted on the basis thereof, as necessary, for the exercise of its certification, oversight and enforcement tasks. The procedures shall be kept up to date and serve as the basic working documents within that competent authority for all related tasks;
(2)a sufficient number of personnel, including inspectors, to perform its tasks and discharge its responsibilities under this Regulation. Such personnel shall be qualified to perform their allocated tasks and have the necessary knowledge, experience, initial, on-the-job and recurrent training to ensure continuing competence. A system shall be in place to plan the availability of personnel, in order to ensure the proper completion of all related tasks;
(3)adequate facilities and office accommodation to perform those allocated tasks;
(4)a process to monitor compliance of the management system with the relevant requirements and adequacy of the procedures, including the establishment of an internal audit process and a safety risk management process. Compliance monitoring shall include a feedback system of audit findings to the senior management of the competent authority to ensure implementation of corrective actions as necessary;
(5)a person or group of persons ultimately responsible to the senior management of the competent authority for the compliance monitoring function.
(b)The competent authority shall, for each field of activity included in the management system, appoint one or more persons with the overall responsibility for the management of the relevant task(s).
(c)The competent authority shall establish procedures for the participation in a mutual exchange of all necessary information and assistance with other competent authorities concerned, whether from within the Member State or in other Member States, including the following information:
(1)the relevant findings raised and follow-up actions taken as a result of oversight of ATM/ANS providers exercising activities in the territory of a Member State, but certified by the competent authority of another Member State or the Agency; and
(2)stemming from mandatory and voluntary occurrence reporting as required by point ATM/ANS.OR.A.065.
(d)A copy of the procedures related to the management system and their amendments shall be made available to the Agency for the purpose of standardisation.
(e)In addition to the requirements contained in point (a), the management system established and maintained by the competent authority shall comply with Annex I (Part-IS.AR) of Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety. [applicable from 22 February 2026 - Regulation (EU) 2023/203]
IR · ATM/ANS.AR.B.001 — Regulation (EU) 2017/373 · Regulation (EU) 2023/203 · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025