Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

ATM/ANS.AR.C.035 Decision to review a notified change to the functional system

REQUIREMENTS FOR COMPETENT AUTHORITIES — OVERSIGHT OF SERVICES AND OTHER ATM NETWORK FUNCTIONS · Regulation (EU) 2017/373 · EAR revision 12 Mar 2025

IRImplementing rule

ATM/ANS.AR.C.035Decision to review a notified change to the functional system

(a)Upon receipt of a notification in accordance with point ATM/ANS.OR.A.045(a)(1), or upon receipt of modified information in accordance with point ATM/ANS.OR.A.045(b), the competent authority shall make a decision on whether to review the change or not. The competent authority shall request any additional information needed from the service provider to support this decision.

(b)The competent authority shall determine the need for a review based on specific, valid and documented criteria that, as a minimum, ensure that the notified change is reviewed if the combination of the likelihood of the argument being complex or unfamiliar to the service provider and the severity of the possible consequences of the change is significant.

(c)When the competent authority decides the need for a review based on other risk based criteria in addition to point (b), these criteria shall be specific, valid and documented.

(d)The competent authority shall inform the service provider of its decision to review a notified change to a functional system and provide the associated rationale to the service provider upon request.

IR · ATM/ANS.AR.C.035 — Regulation (EU) 2017/373 · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025

AMCAcceptable means of compliance

AMC1 ATM/ANS.AR.C.035Decision to review a notified change to the functional system

Show the text

CRITERIA The novelty of ATM/ANS equipment subject to certification/declaration/statement of compliance should be considered when the competent authority takes a decision to review a notified change to the functional system. New functionalities, new concept of operation, new technologies, etc. should be considered to be novelty.

AMC · AMC1 ATM/ANS.AR.C.035 — Regulation (EU) 2017/373 · ED Decision 2023/018/R · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025

AMCAcceptable means of compliance

AMC1 ATM/ANS.AR.C.035(a)Decision to review a notified change to the functional system

Show the text

MEANS AND METHOD OF SUBMITTING NOTIFICATION OF CHANGES TO FUNCTIONAL SYSTEMS The competent authority should agree with the service provider on the means and method of submitting the notification of changes and additional information referred to in ATM/ANS.OR.A.045(a). Until an agreement is reached, the competent authority will prescribe the means of submission.

AMC · AMC1 ATM/ANS.AR.C.035(a) — Regulation (EU) 2017/373 · ED Decision 2017/001/R · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025

GMGuidance material

GM1 ATM/ANS.AR.C.035(b)Decision to review a notified change to the functional system

Show the text

SELECTION CRITERIA FOR REVIEWING A NOTIFIED CHANGE TO THE FUNCTIONAL SYSTEM The need for review should be based on a combination of the likelihood that the safety (support) argument may be complex or unfamiliar to the service provider undertaking the change and the severity of the consequences associated with the change. This is a risk function and is referred to as the ‘risk posed by the change’. The following two aspects of the change: the novelty of the change; and the capabilities of the service provider (e.g. the effectiveness of the service provider’s (safety) management system), as well as the service provider performing the change contribute to the service provider’s unfamiliarity of the necessary argument. The assessment of the severity of the consequence is made at a very early stage in the development of the change and, therefore, will be based on coarse data. It should, therefore, be conservative. The risk posed by a change could be a scalar measure associated with the change and be some combination of the two inputs: the probability of a complex or unfamiliar argument and the severity of the consequences of the proposed change. The result is that the risk posed by a particular change is the sum of the inputs. One possibility may be based on the use of a risk matrix in which risk parameters are represented according to a coarse-grained measurement scheme, and the selection criteria establish the boundary beyond which changes will be selected for review, as shown below:

The selection criterion, a function of risk with the value ‘significant’, is then a straight line, if the scales are logarithmic.

GM · GM1 ATM/ANS.AR.C.035(b) — Regulation (EU) 2017/373 · ED Decision 2017/001/R · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025

GMGuidance material

GM1 ATM/ANS.AR.C.035(c)Decision to review a notified change to the functional system

Show the text

OTHER SELECTION CRITERIA

(a)Some changes may not necessarily need to be reviewed providing that, even though they relate to safety, they can be considered as routine by the provider as they have been consistently assessed, implemented and proved safe in the past and, therefore, the competent authority has sufficient confidence that the provider will address them in a similar manner.

(b)The selection criterion for review may deviate from a simple threshold on the scalar risk metric (distance from the origin), to deal with concerns due to the coarse grain and high uncertainty of the inputs. For instance, a separate threshold on the ‘severity’ axis may be used to specify, for instance:

(1)that changes with very high potential severity should always be reviewed, irrespective of the probability of the safety argument being incomplete and/or incorrect (Figure below). This criterion may well respond to common perceptions and could be justified by the fact that judgements of low probabilities based on limited information are often unreliable, and errors in the judgment of risk are proportional to the error on probability and the size of the loss; and

(2)that changes with minor potential severity need not be reviewed, irrespective of the probability of the safety argument being incomplete and/or incorrect (Figure below) (though the process may retain the option for the competent authority to review the change, since the estimate itself of potential severity may be suspected of being erroneous).

(c)It is also possible that deviations be required on the basis of some of the component factors that affect either probability or severity, e.g. exempting changes based on small size of change and high competence of the air traffic services provider.

(d)In order to validate the process or provide data for the evolution of the process, it may be advisable to randomly select changes to review and then assess whether the safety argument is complete and/or correct or not and whether or not the case would have been selected for review using the current criteria for the selection process.

Figure 1: Criteria that may be used when severity is high

Figure 2: Criteria that may be used when severity is low

GM · GM1 ATM/ANS.AR.C.035(c) — Regulation (EU) 2017/373 · ED Decision 2017/001/R · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025

All rules in SUBPART C — OVERSIGHT, CERTIFICATION AND ENFORCEMENT (ATM/ANS.AR.C)

Consolidated from the EASA Easy Access Rules (revision 12 Mar 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about ATM/ANS.AR.C.035 →

Metis opens with Avioverse in October 2026 · request early access.