IRImplementing rule
ATM/ANS.AR.B.005Allocation of tasks to qualified entities
[applicable until 21 February 2026 - Regulation (EU) 2017/373] ATM/ANS.AR.B.005 Allocation of tasks [applicable from 22 February 2026 - Regulation (EU) 2023/203]
(a)The competent authority may allocate its tasks related to the certification or oversight of service providers under this Regulation, other than the issuance of certificates themselves, to qualified entities. When allocating such tasks, the competent authority shall ensure that it has:
(1)a system in place to initially and continuously assess that the qualified entity complies with Annex V to Regulation (EC) No 216/2008. This system and the results of the assessments shall be documented; and
(2)established a documented agreement with the qualified entity, approved by both parties at the appropriate management level, which clearly defines:
(i)the tasks to be performed;
(ii)the declarations, reports and records to be provided;
(iii)the technical conditions to be met when performing such tasks;
(iv)the related liability coverage;
(v)the protection given to information acquired when carrying out such tasks.
(b)The competent authority shall ensure that the internal audit process and the safety risk management process required by point ATM/ANS.AR.B.001(a)(4) cover all tasks performed on its behalf by the qualified entity.
(c)With regard to the certification and oversight of the organisation’s compliance with point ATM/ANS.OR.B.005A, the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that:
(1)all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority;
(2)the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation;
(3)its own information security management system established in accordance with point ATM/ANS.AR.B.001(e) covers all the certification and continuing oversight tasks performed on its behalf. [applicable from 22 February 2026 - Regulation (EU) 2023/203]
IR · ATM/ANS.AR.B.005 — Regulation (EU) 2017/373 · Regulation (EU) 2023/203 · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025