Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

145.A.200 Management system

Annex II (Part-145) · Regulation (EU) No 1321/2014 · EAR revision 2 Sep 2025

IRImplementing rule

145.A.200Management system

(a)The organisation shall establish, implement and maintain a management system that includes:

(1)clearly defined accountability and lines of responsibility throughout the organisation, including a direct safety accountability of the accountable manager;

(2)a description of the overall philosophies and principles of the organisation with regard to safety (“the safety policy”), and the related safety objectives;

(3)the identification of aviation safety hazards entailed by the activities of the organisation, their evaluation and the management of the associated risks, including taking actions to mitigate the risks and verify their effectiveness;

(4)maintaining personnel trained and competent to perform their tasks;

(5)documentation of all management system key processes, including a process for making personnel aware of their responsibilities and the procedure for amending that documentation;

(6)a function to monitor the compliance of the organisation with the relevant requirements. Compliance monitoring shall include a feedback system of findings to the accountable manager to ensure the effective implementation of corrective actions as necessary.

(b)The management system shall correspond to the size of the organisation and the nature and complexity of its activities, taking into account the hazards and the associated risks inherent in those activities.

(c)If the organisation holds one or more additional organisation certificates within the scope of Regulation (EU) 2018/1139, the management system may be integrated with that required under the additional certificate(s) held.

IR · 145.A.200 — Regulation (EU) No 1321/2014 · Regulation (EU) 2021/1963 · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200Management system

Show the text

GENERAL Safety management seeks to proactively identify hazards and to mitigate the related safety risks before they result in aviation accidents and incidents. Safety management enables an organisation to manage its activities in a more systematic and focused manner. When an organisation has a clear understanding of its role and contribution to aviation safety, it can prioritise safety risks and more effectively manage their resources and obtain optimal results. The principles of the requirements in points 145.A.200, 145.A.202, 145.A.205 and the related AMC constitute the EU management system framework for aviation safety management. This framework addresses the core elements of the ICAO safety management system (SMS) framework defined in Appendix 2 to Annex 19, includes the elements of the compliance monitoring system, and promotes an integrated approach to the management of an organisation. It facilitates the introduction of the additional safety management components, building upon the existing management system, rather than adding them as a separate framework. This approach is intended to encourage organisations to embed safety management and risk-based decision-making into all their activities, instead of superimposing another system onto their existing management system and governance structure. In addition, if the organisation holds multiple organisation certificates within the scope of Regulation (EU) 2018/1139, it may choose to implement a single management system to cover all of its activities. An integrated management system may not only be used to capture management system requirements resulting from Regulation (EU) 2018/1139, but also could cover other regulatory frameworks requiring compliance with Annex 19 or other business management systems such as security, occupational health and environmental management systems. Integration will remove any duplication and exploit synergies by managing safety risks across multiple activities. Organisations may determine the best means to structure their management systems to suit their business and organisational needs. The core part of the management system framework (145.A.200) focuses on what is essential to manage safety, by mandating the organisation to:

(a)clearly define accountabilities and responsibilities;

(b)establish a safety policy and the related safety objectives;

(c)implement safety reporting procedures in line with just culture principles;

(d)ensure the identification of aviation safety hazards entailed by its activities, ensure their evaluation, and the management of the associated risks, including:

(1)taking actions to mitigate the risks;

(2)verifying the effectiveness of the actions taken to mitigate the risks;

(e)monitor compliance, while considering any additional requirements that are applicable to the organisation;

(f)keep their personnel trained, competent, and informed about significant safety issues; and

(g)document all the key management system processes. Compared with the previous Part-145 quality system ‘framework’ (now covered by point (b) and (e)), the new elements that are introduced by the management system are, in particular, those addressed under points (c) and (d). Points (a), (b) and (g) address component 1 ‘Safety policy and objectives’ of the ICAO SMS framework. Points (c) and (d)(1) address component 2 ‘Safety Risk Management’ of the ICAO SMS framework. Point (d)(2) addresses component 3 ‘Safety Assurance’ of the ICAO SMS framework. Finally, point (f) addresses component 4 ‘Safety Promotion’ of the ICAO SMS framework. Point 145.A.200 introduces the following as key safety management processes; these are further specified in the related AMC and GM: Hazard identification; Safety risk management; Internal investigation; Safety performance monitoring and measurement; Management of change; Continuous improvement; Immediate safety action and coordination with the aircraft operator’s Emergency Response Plan (ERP). It is important to recognise that safety management will be a continuous activity, as hazards, risks and the effectiveness of safety risk mitigations will change over time. These key safety management processes are supported by a compliance monitoring function as an integral part of the management system. Most aviation safety regulations constitute generic safety risk controls established by the ‘regulator’. Therefore, ensuring effective compliance with the regulations during daily operations and independent monitoring of compliance are fundamental to any management system for safety. The compliance monitoring function may, in addition, support the follow-up of safety risk mitigation actions. Moreover, where non-compliances are identified through internal audits, the causes will be thoroughly assessed and analysed. Such an analysis in return supports the risk management process by providing insights into causal and contributing factors, including human factors, organisational factors and the environment in which the organisation operates. In this way, the outputs of compliance monitoring become some of the various inputs to the safety risk management functions. Conversely, the output of the safety risk management processes may be used to determine focus areas for compliance monitoring. In this way, internal audits will inform the organisation’s management of the level of compliance within the organisation, whether safety risk mitigation actions have been implemented, and where corrective or preventive action is required. The combination of safety risk management and compliance monitoring should lead to an enhanced understanding of the end-to-end process and the process interfaces, exposing opportunities for increased efficiencies, which are not limited to safety aspects. As aviation is a complex system with many organisations and individuals interacting together, the primary focus of the key safety management processes is on the organisational processes and procedures, but it also relies on the humans in the system. The organisation and the way in which it operates can have a significant impact on human performance. Therefore, safety management necessarily addresses how humans can contribute both positively and negatively to an organisation’s safety outcomes, recognising that human behaviour is influenced by the organisational environment. The effectiveness of safety management largely depends on the degree of commitment of the senior management to create a working environment that optimises human performance and encourages personnel to actively engage in and contribute to the organisation’s management processes. Similarly, a positive safety culture relies on a high degree of trust and respect between the personnel and the management, and it must therefore be created and supported at the senior management level. If the management does not treat individuals who identify hazards and report adverse events in a consistently fair and just way, those individuals are unlikely to be willing to communicate safety issues or to work with the management to effectively address the safety risks. As with trust, a positive safety culture takes time and effort to establish, and it can be easily lost. It is further recognised that the introduction of processes for hazard identification and risk assessment, mitigation and verification of the effectiveness of such mitigation actions will create immediate and direct costs, while related benefits are sometimes intangible, and may take time to materialise. Over time, an effective management system will not only address the risks of major occurrences, but also identify and address production inefficiencies, improve communication, foster a better organisational culture, and lead to a more effective control of contractors and suppliers. In addition, through an improved relationship with the authority, an effective management system may result in a reduced oversight burden. Thus, by viewing safety management and the related organisational policies and key processes as items that are implemented not only to prevent incidents and accidents, but also to meet the organisation’s strategic objectives, any investment in safety should be seen as an investment in productivity and organisational success.

GM · GM1 145.A.200 — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC1 145.A.200(a)(1)Management system

Show the text

ORGANISATION AND ACCOUNTABILITIES

(a)The management system should encompass safety by including a safety manager and a safety review board in the organisational structure. The functions of the safety manager are those defined in AMC1 145.A.30(c);(ca).

(b)Safety review board

(1)The safety review board should be a high-level committee that considers matters of strategic safety in support of the accountable manager’s safety accountability.

(2)The board should be chaired by the accountable manager and composed of the person or group of persons nominated under points 145.A.30.

(3)The safety review board should monitor:

(i)the safety performance against the safety policy and objectives;

(ii)that any safety action is taken in a timely manner; and

(iii)the effectiveness of the organisation’s management system processes.

(4)The safety review board may also be tasked with:

(i)reviewing the results of compliance monitoring;

(ii)monitoring the implementation of related corrective and preventive actions.

(c)The safety review board should ensure that appropriate resources are allocated to achieve the established safety objectives.

(d)Notwithstanding point (a), where justified by the size of the organisation and the nature and complexity of its activities and subject to a risk assessment and agreement by the competent authority, the organisation may not need to establish a formal safety review board. In this case, the tasks normally allocated to the safety review board should be allocated to the safety manager.

AMC · AMC1 145.A.200(a)(1) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(1)Management system

Show the text

SAFETY ACTION GROUP

(a)Depending on the size of the organisation and the nature and complexity of its activities, a safety action group may be established as a standing group or as an ad hoc group to assist, or act on behalf of the safety manager or the safety review board.

(b)More than one safety action group may be established, depending on the scope of the task and the specific expertise required.

(c)The safety action group usually reports to, and takes strategic direction from, the safety review board, and may be composed of managers, supervisors and personnel from operational areas.

(d)The safety action group may be tasked or assist with:

(1)monitoring safety performance;

(2)defining actions to control risks to an acceptable level;

(3)assessing the impact of organisational changes on safety;

(4)ensuring that safety actions are implemented within the agreed timescales;

(5)reviewing the effectiveness of previous safety actions and safety promotion.

GM · GM1 145.A.200(a)(1) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM2 145.A.200(a)(1)Management system

Show the text

MEANING OF THE TERMS ‘ACCOUNTABILITY’ AND ‘RESPONSIBILITY’ In the English language, the notion of accountability is different from the notion of responsibility. Whereas ‘accountability’ refers to an obligation which cannot be delegated, ‘responsibility’ refers to an obligation that can be delegated.

GM · GM2 145.A.200(a)(1) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC1 145.A.200(a)(2)Management system

Show the text

SAFETY POLICY AND OBJECTIVES

(a)The safety policy should:

(1)reflect organisational commitments regarding safety, and its proactive and systematic management, including the promotion of a positive safety culture;

(2)include internal reporting principles, and encourage personnel to report maintenance-related errors, incidents and hazards;

(3)recognise the need for all personnel to cooperate with the compliance monitoring and internal investigations referred to under point (c) of AMC1 145.A.200(a)(3);

(4)be endorsed by the accountable manager;

(5)be communicated, with visible endorsement, throughout the organisation; and

(6)be periodically reviewed to ensure it remains relevant and appropriate for the organisation.

(b)The safety policy should include a commitment to:

(1)comply with all the applicable legislation, to meet all the applicable requirements, and adopt practices to improve safety standards;

(2)provide the necessary resources for the implementation of the safety policy;

(3)apply human factors principles, including giving due consideration to the aspect of fatigue;

(4)enforce safety as a primary responsibility of all managers; and

(5)apply ‘just culture’ principles to internal safety reporting and the investigation of occurrences and, in particular, not to make available or use the information on occurrences:

(i)to attribute blame or liability to front-line personnel or other persons for actions, omissions or decisions taken by them that are commensurate with their experience and training; or

(ii)for any purpose other than maintaining or improving aviation safety.

(c)Senior management should continually promote the safety policy to all personnel, demonstrate its commitment to it, and provide necessary human and financial resources for its implementation.

(d)Taking due account of its safety policy, the organisation should define safety objectives. The safety objectives should:

(1)form the basis for safety performance monitoring and measurement;

(2)reflect the organisation’s commitment to maintain or continuously improve the overall effectiveness of the management system;

(3)be communicated throughout the organisation; and

(4)be periodically reviewed to ensure they remain relevant and appropriate for the organisation.

AMC · AMC1 145.A.200(a)(2) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(2)Management system

Show the text

SAFETY POLICY

(a)The safety policy is the means whereby the organisation states its intention to maintain and, where practicable, improve safety levels in all its activities and to minimise its contribution to the risk of an aircraft accident or serious incident as far as is reasonably practicable. It reflects the management’s commitment to safety, and should reflect the organisation’s philosophy of safety management, as well as being the foundation on which the organisation’s management system is built. It serves as a reminder of ‘how we do business here’. The creation of a positive safety culture begins with the issuance of a clear, unequivocal policy.

(b)The commitment to apply ‘just culture’ principles forms the basis for the organisation’s internal rules describing how ‘just culture’ principles are guaranteed and implemented.

(c)For organisations that have their principal place of business in a Member State, Regulation (EU) No 376/2014 defines the ‘just culture’ principles to be applied (refer in particular to Article 16(11) of that Regulation).

GM · GM1 145.A.200(a)(2) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC1 145.A.200(a)(3)Management system

Show the text

SAFETY MANAGEMENT KEY PROCESSES

(a)Hazard identification processes

(1)A reporting scheme should be the formal means of collecting, recording, analysing, acting on, and generating feedback about hazards, events and the associated risks that may affect safety.

(2)The hazards identification should include in particular:

(i)hazards that may be linked to human factors issues that affect human performance; and

(ii)hazards that may stem from the organisational set-up or the existence of complex operational and maintenance arrangements (such as when multiple organisations are contracted, or when multiple levels of contracting/subcontracting are included).

(b)Risk management processes

(1)A formal safety risk management process should be developed and maintained that ensures reactive, proactive and predictive approach composed by:

(i)analysis (e.g. in terms of the probability and severity of the consequences of hazards and occurrences);

(ii)assessment (in terms of tolerability);

(iii)control (in terms of mitigation) of risks to an acceptable level. Note: The severity of the consequence should be evaluated to the best knowledge and engineering judgement of the organisation, and this evaluation may require collecting information from the competent authority, incident/accident investigation reports, the design approval holder, the declarant of a declaration of design compliance, etc.

(2)The levels of management who have the authority to make decisions regarding the tolerability of safety risks, in accordance with (b)(1)(ii), should be specified.

(c)Internal investigation

(1)In line with its just culture policy, the organisation should define how to investigate incidents such as errors or near misses, in order to understand not only what happened, but also how it happened, to prevent or reduce the probability and/or consequence of future recurrences (refer to AMC1 145.A.202). This approach should avoid concentrating the analysis on who was (were) directly or indirectly concerned by the events.

(2)The scope of internal investigations should extend beyond the scope of the occurrences required to be reported to the competent authority in accordance with point 145.A.60, to include the reports referred to in 145.A.202(b).

(d)Safety performance monitoring and measurement

(1)Safety performance monitoring and measurement should be the processes by which the safety performance of the organisation is verified in comparison with the safety policy and the safety objectives.

(2)These processes may include, as appropriate to the size, nature and complexity of the organisation:

(i)safety reporting, which may also address the status of compliance with the applicable requirements;

(ii)safety reviews, including trend reviews, which would be conducted during the introduction of new products and their components, new equipment/technologies, the implementation of new or changed procedures, or in situations of organisational changes that may have an impact on safety;

(iii)safety audits that focus on the integrity of the organisation’s management system, and on periodically assessing the status of safety risk controls;

(iv)safety surveys, examining particular elements or procedures in a specific area, such as identified problem areas, or bottlenecks in daily maintenance activities, perceptions and opinions of maintenance management personnel, and areas of dissent or confusion; and

(v)other indicators relevant to safety performance, which may be generated by automated means.

(e)Management of change Changes may introduce new hazards or threaten existing safety risk controls. The management of change should be a documented process established by the organisation to identify external and internal changes that may have an adverse effect on the safety of its maintenance activities. It should make use of the organisation’s existing hazard identification, risk assessment and mitigation processes.

(f)Continuous improvement The organisation should continuously seek to improve its safety performance and the effectiveness of its management system. Continuous improvement may be achieved through:

(1)audits carried out by external organisations;

(2)assessments, including assessments of the effectiveness of the safety culture and management system, in particular to assess the effectiveness of the safety risk management processes;

(3)staff surveys, including cultural surveys, that can provide useful feedback on how engaged personnel are with the management system;

(4)monitoring the recurrence of incidents and occurrences;

(5)evaluation of safety performance indicators and reviews of all the available safety performance information; and

(6)the identification of lessons learned.

(g)Immediate safety action and coordination with the operator’s Emergency Response Plan (ERP)

(1)Procedures should be implemented that enable the organisation to act promptly when it identifies safety concerns with the potential to have an immediate effect on flight safety, including clear instructions on who to contact at the owner/operator/CAMO, and how to contact them, including outside of normal business hours. These provisions are without prejudice to the occurrence reporting required by point 145.A.60.

(2)If applicable, procedures should be implemented to enable the organisation to react promptly if the ERP is triggered by the operator and it requires the support of the Part-145 organisation.

AMC · AMC1 145.A.200(a)(3) — Regulation (EU) No 1321/2014 · ED Decision 2023/013/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(3)Management system

Show the text

SAFETY RISK MANAGEMENT — INTERFACES BETWEEN ORGANISATIONS

(a)Safety risk management processes should specifically address the planned implementation of, or participation of the organisation in, complex operational and maintenance arrangements (such as when multiple organisations are contracted, or when multiple levels of contracting/subcontracting are included).

(b)Hazard identification and risk assessment start with the identification of all the parties involved in the arrangement, including independent experts and non-approved organisations. This identification process extends to cover the overall control structure, and assesses in particular the following elements across all subcontract levels and all parties within such arrangements:

(1)coordination and interfaces between the different parties;

(2)applicable procedures;

(3)communication between all the parties involved, including reporting and feedback channels;

(4)task allocation, responsibilities and authorities; and

(5)the qualifications and competency of key personnel with reference to point 145.A.30.

(c)Safety risk management should focus on ensuring the following aspects:

(1)clear assignment of accountability and allocation of responsibilities;

(2)that only one party is responsible for a specific aspect of the arrangement, with no overlapping or conflicting responsibilities, in order to eliminate coordination errors;

(3)the existence of clear reporting lines, both for occurrence reporting and progress reporting;

(4)the possibility for staff to directly notify the organisation of any hazard that suggests an obviously unacceptable safety risk as a result of the potential consequences of this hazard.

(d)The safety risk management processes should ensure that there is regular communication between all the parties involved to discuss work progress, risk mitigation actions, and changes to the arrangements, as well as any other significant issues.

GM · GM1 145.A.200(a)(3) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM2 145.A.200(a)(3)Management system

Show the text

MANAGEMENT OF CHANGE

(a)Unless they are properly managed, changes in organisational structure, facilities, the scope of work, personnel, documentation, policies and procedures, etc. can result in the inadvertent introduction of new hazards, and expose the organisation to new or increased risks. Effective organisations seek to improve their processes, with conscious recognition that changes can expose the organisation to potentially latent hazards and risks if they are not properly and effectively managed.

(b)Regardless of the magnitude of a change, large or small, its safety implications should always be proactively considered. This is primarily the responsibility of the team that proposes and/or implements the change. However, a change can only be successfully implemented if all the personnel affected by the change are engaged, are involved and participate in the process. The magnitude of a change, its safety criticality, and its potential impact on human performance should be assessed in any change management process.

(c)The process for the management of change typically provides principles and a structured framework for managing all aspects of the change. Disciplined application of the management of change can maximise the effectiveness of the change, engage the staff, and minimise the risks that are inherent in a change.

(d)The introduction of a change is the trigger for the organisation to perform their hazard identification and risk management processes. Some examples of change include, but are not limited to:

(1)changes to the organisational structure;

(2)the inclusion of a new aircraft type in the terms of approval;

(3)the addition of aircraft of the same or a similar type;

(4)significant changes in personnel (affecting key personnel and/or large numbers of personnel, high turnover);

(5)new or amended regulations;

(6)changes to the security arrangements;

(7)changes in the economic situation of an organisation (e.g. commercial or financial pressure);

(8)new schedule(s), location(s), equipment, and/or operational procedures; and

(9)the addition of new subcontractors.

(e)A change may have the potential to introduce new, or to exacerbate pre-existing, human factors issues. For example, changes in computer systems, equipment, technology, personnel changes, including changes in management personnel, procedures, work organisation, or work processes are likely to affect performance.

(f)The purpose of integrating human factors (HF) into the management of change is to minimise potential risks by specifically considering the impact of the change on the people within a system.

(g)Special consideration, including any HF issues, should be given to the ‘transition period’. In addition, the activities utilised to manage these issues should be integrated into the change management plan.

(h)Effective management of change should be supported by the following:

(1)implementation of a process for formal hazard identification/risk assessment for major operational changes, major organisational changes, changes in key personnel, and changes that may affect the way maintenance is carried out;

(2)identification of changes that are likely to occur in business which would have a noticeable impact on:

(i)resources — material and human;

(ii)management direction — policies, processes, procedures, training; and

(iii)management control;

(3)safety cases/risk assessments that are focused on aviation safety;

(4)the involvement of key stakeholders in the change management process, as appropriate.

(i)During the management of change process, previous risk assessments and existing hazards are reviewed for possible effect.

GM · GM2 145.A.200(a)(3) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC1 145.A.200(a)(4)Management system

Show the text

COMMUNICATION ON SAFETY

(a)The organisation should establish communication regarding safety matters that:

(1)ensures that all personnel are aware of the safety management activities, as appropriate for their safety responsibilities;

(2)conveys safety-critical information, especially related to assessed risks and analysed hazards;

(3)explains why particular actions are taken; and

(4)explains why safety procedures are introduced or changed.

(b)Regular meetings with personnel, at which information, actions, and procedures are discussed, may be used to communicate safety matters.

AMC · AMC1 145.A.200(a)(4) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(4)Management system

Show the text

SAFETY PROMOTION

(a)Safety training, combined with safety communication and information sharing, forms part of safety promotion.

(b)Safety promotion activities should support:

(1)the organisation’s policies, encouraging a positive safety culture, creating an environment that is favourable to the achievement of the organisation’s safety objectives;

(2)organisational learning; and

(3)the implementation of an effective safety reporting scheme and the development of a just culture.

(c)Depending on the particular safety issue, safety promotion may also constitute or complement risk mitigation actions.

(d)Qualifications and training aspects are further specified in the AMC and the GM to point 145.A.30.

GM · GM1 145.A.200(a)(4) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(5)Management system

Show the text

MANAGEMENT SYSTEM DOCUMENTATION

(a)The organisation may document its safety policy, safety objectives and all its key management system processes in a separate manual (e.g. a Safety Management Manual or Management System Manual), or in its MOE (see AMC1 145.A.70(a), Part 3 ‘Management system procedures’). Organisations that hold multiple organisation certificates within the scope of Regulation (EU) 2018/1139 may prefer to use a separate manual in order to avoid duplication. That manual or the MOE, depending on the case, should be the key instrument for communicating the approach to the management system for the whole of the organisation.

(b)The organisation may also choose to document some of the information that is required to be documented in separate documents (e.g. policy documents, procedures). In that case, it should ensure that the manual or the MOE contains adequate references to any document that is kept separately. Any such documents are to be considered to be integral parts of the organisation’s management system documentation.

GM · GM1 145.A.200(a)(5) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC1 145.A.200(a)(6)Management system

Show the text

COMPLIANCE MONITORING — GENERAL

(a)The primary objectives of compliance monitoring are to provide an independent monitoring function on how the organisation ensures compliance with the applicable requirements, policies and procedures, and to request action where non-compliances are identified.

(b)The independence of the compliance monitoring should be established by always ensuring that audits and inspections are carried out by personnel who are not responsible for the functions, procedures or products that are audited or inspected.

AMC · AMC1 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC2 145.A.200(a)(6)Management system

Show the text

COMPLIANCE MONITORING — INDEPENDENT AUDIT

(a)An essential element of the compliance monitoring function is the independent audit.

(b)The independent audit should be an objective process of routine sample checks of all aspects of the organisation’s ability to carry out all maintenance to the standards required by this Regulation. It should include checking compliance of the organisation procedures with the Regulation, adherence of the organisation to these procedures, and product or maintenance sampling (i.e. product audit), as this is the end result of the maintenance process.

(c)The independent audit should provide an objective overview of the complete set of maintenance-related activities. It should include a percentage of unannounced audits carried out on a sample basis while maintenance is being carried out. This means that some audits should be carried out during the night for those organisations that work at night.

(d)The organisation should establish an audit plan to show when and how often the activities as required by this Regulation will be audited.

(e)Except as specified in points (h) and (j), the audit plan should ensure that all aspects of Part-145 compliance are verified every year, including all the subcontracted activities. The auditing may be carried out as a complete single exercise or subdivided over the annual period. The independent audit should not require each procedure to be verified against each product line when it can be shown that the particular procedure is common to more than one product line and the procedure has been verified every year without resultant findings. Where findings have been identified, compliance with the particular procedure should be verified against other product lines until the findings have been closed, after which the independent audit procedure may revert back to a yearly interval for the particular procedure.

(f)Except as specified otherwise in point (h), the independent audit should sample check one product (such as one aircraft or engine or component) while undergoing maintenance on each product line every year as a demonstration of compliance with the maintenance procedures and requirements associated with that specific product. This should include in particular the verification of: the maintenance data and compliance with the organisation procedures, including consideration of human factors issues; the facility and maintenance environment; the standard of inspection and precautions; the completion of work cards/worksheet; the tools and material; the authorisation of the person carrying out maintenance. For the purpose of this AMC, a product line includes any product under an Appendix II approval class rating as specified in the terms of approval issued to the particular organisation. It therefore follows, for example, that a Part-145 maintenance organisation approved to maintain aircraft, engines, brakes and autopilots would need to carry out at least four complete product audits each year, except as specified otherwise in points (f), (h) or (j).

(g)The product audit includes witnessing any relevant testing and visually inspecting the product and the associated documentation. The product audit should not involve repeated disassembly or testing unless the product audit identifies findings that require such an action.

(h)Except as specified otherwise in point (j), where the organisation contracts the independent audit element of the compliance monitoring function in accordance with point (l), the audit should be carried out twice every year.

(i)Except as specified otherwise in point (j), where the organisation has line stations listed as per point 145.A.75(d), the compliance monitoring documentation should include a description of how these line stations are integrated into the monitoring and include a plan to audit each listed line station at a frequency consistent with the extent of flight activity at the particular line station and the related safety hazards identified. Except as specified otherwise in point (j), the maximum period between audits of a particular line station should not exceed 2 years.

(j)Except as specified otherwise in point (f), provided that there are no safety-related findings, the audit planning cycle specified in this AMC may be increased by up to 100 %, subject to a risk assessment and/or mitigation actions, and agreement by the competent authority.

(k)A report should be issued each time an audit is carried out describing what was checked and the resulting non-compliance findings against applicable requirement and procedures.

(l)Organisations with a maximum of 10 maintenance staff actively engaged in carrying out maintenance may subcontract the whole independent audit element of the compliance monitoring function to another organisation or contract a qualified and competent person to become responsible for this element, with the agreement of the competent authority. This does not prevent a larger organisation from occasionally using external support for conducting particular audits.

AMC · AMC2 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC3 145.A.200(a)(6)Management system

Show the text

COMPLIANCE MONITORING — CONTRACTING OF THE INDEPENDENT AUDIT

(a)If external personnel are used to perform independent audits:

(1)any such audits should be performed under the responsibility of the compliance monitoring manager; and

(2)the organisation remains responsible for ensuring that the external personnel have the relevant knowledge, background, and experience that are appropriate to the activities being audited, including knowledge and experience in compliance monitoring.

(b)The organisation retains the ultimate responsibility for the effectiveness of the compliance monitoring function, in particular for the effective implementation and follow-up of all corrective actions.

AMC · AMC3 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

AMCAcceptable means of compliance

AMC4 145.A.200(a)(6)Management system

Show the text

COMPLIANCE MONITORING — FEEDBACK SYSTEM

(a)Another essential element of the compliance monitoring function is the feedback system.

(b)The feedback system should not be contracted to external persons or organisations.

(c)When a non-compliance is found, the compliance monitoring function should ensure that the root cause(s) and contributing factor(s) are identified (see GM1 145.A.95), and that corrective actions are defined. The feedback part of the compliance monitoring function should define who is required to address any non-compliance in each particular case, and the procedure to be followed if the corrective action is not completed within the defined time frame. The principal functions of the feedback system are to ensure that all findings resulting from the independent audits of the organisation are properly investigated and corrected in a timely manner, and to enable the accountable manager to be kept informed of safety issues and the extent of compliance with Part-145.

(d)The independent audit reports referred to in AMC2 145.A.200(a)(6) should be sent to the relevant department(s) for corrective action, giving target closure dates. These target dates should be discussed with the relevant department(s) before the compliance monitoring function confirms the dates in the report. The relevant department(s) is (are) required to implement the corrective action and inform the compliance monitoring function of the status of the implementation of the action.

(e)Unless the review of the results from compliance monitoring is given to the safety review board (ref. AMC1 145.A.200(a)(1) point (b)(4)), the accountable manager should hold regular meetings with staff to check the progress of corrective actions. These meetings may be delegated to the compliance monitoring manager on a day-to-day basis, provided that the accountable manager:

(1)meets the senior staff involved at least twice per year to review the overall performance of the compliance monitoring function; and

(2)receives at least a half-yearly summary report on non-compliance findings.

(f)All records pertaining to the independent audit and the feedback system should be retained for the period specified in point 145.A.55(c) or for such periods as to support changes to the audit planning cycle in accordance with AMC2 145.A.200(a)(6), whichever is the longer.

AMC · AMC4 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(6)Management system

Show the text

COMPLIANCE MONITORING FUNCTION The compliance monitoring function is one of the elements that is required to be in compliance with the applicable requirements. This means that the compliance monitoring function itself should be subject to independent monitoring of compliance in accordance with 145.A.200(a)(6).

GM · GM1 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM2 145.A.200(a)(6)Management system

Show the text

COMPLIANCE MONITORING — AUDIT PLAN

(a)The purpose of this GM is to provide guidance on one acceptable working audit plan to meet part of the needs of point 145.A.200(a)(6). There is any number of other acceptable working audit plans.

(b)The audits described in the audit plan are intended to monitor compliance with the applicable requirements, and at the same time to review all areas of the organisation to which those requirements are applicable.

(c)In order to achieve this objective, as a first element, the organisation needs to identify all the regulatory requirements that are applicable to the activity and the scope of work under consideration, to allow the audit plan to focus on the relevant topics. Each topic (e.g. facilities, personnel, etc.) should be cross-referred with the relevant requirement and the related procedure of the organisation in the exposition that describes the particular topic. If the organisation follows a specific means of compliance to demonstrate compliance with the rule, that information may also be stated.

(d)As a second element, all the functional areas of the organisation in which Part-145 functions are intended to be carried out (i.e. the types of maintenance-related activities), including subcontracting, need to be listed in order to identify the applicability of any topic to each functional area.

(e)A matrix can be used, as shown in the example below, to capture the two elements mentioned above. This matrix is intended to be a living document to be customised by each particular organisation depending on its scope of work and its structure. This matrix should represent the overall compliance of the audit system, and needs to be amended, as necessary, based upon any change to the applicable regulations, the procedures of the organisation or the functional areas of the organisation (e.g. a change in the scope of work to include line maintenance, etc.) Example (to be further completed) of an audit matrix for an organisation involved in aircraft base maintenance that does not hold airworthiness review privilege:

TopicRequirementExpositionFunctional areas
Base maintenanceCompliance monitoringSubcontractingComponent workshop…
Facilities145.A.25(a)(1)1.8XN/AXX…
AMC 145.A.25(a)2.22XN/AN/AX…
…………………
Personnel…………………
145.A.30(c)1.4N/AXN/AN/A…
145.A.30(d)1.7, 2.22XXXX…
…………………
145.A.37N/AN/AN/AN/AN/A…
……………………
Record-keeping145.A.55………………
…………………
……………………

(f)The audit plan can be presented as a simplified schedule (see below), showing the operational areas of the organisation (i.e. where the maintenance-related activities are effectively carried out) against a timetable to indicate when each particular area was scheduled for audit and when the audit was completed. The audit plan should include a number of product audits (depending on the number of product lines), some of which should be unannounced (see AMC2 145.A.200(a)(6)). Example (to be further completed) of an audit plan for an organisation, mentioned in point (e), that has two base maintenance hangars, and hydraulic and electrical workshops:

Operational areaFunctional areaPlannedCompletedRemarks
Base maintenance hangar 1Base maintenancemmm yyyydd mmm yyyy
Base maintenance hangar 2Base maintenancemmm yyyydd mmm yyyy
Hydraulic workshopComponent workshopmmm yyyydd mmm yyyy
Electrical workshopComponent workshopmmm yyyydd mmm yyyy
Subcontractor 1Subcontractingmmm yyyydd mmm yyyy
Product audit 1Base maintenancemmm yyyydd mmm yyyyDuring night
Product audit 2Component workshopunannounceddd mmm yyyy
…………

(g)The audit of each operational area will review all the topics that are applicable to the relevant functional area. For each topic, the audit should check that the particular Part-145 requirement is documented in the corresponding procedure in the exposition, and that the procedure is effectively implemented in the operational area that is being audited. In addition, the audit should also identify any practice/process implemented in the operational area which has not been documented in any procedure in the exposition.

GM · GM2 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

GMGuidance material

GM1 145.A.200(a)(6)and 145.B.300 Management system and Oversight principles

Show the text

THE USE OF INFORMATION AND COMMUNICATION TECHNOLOGIES (ICT) FOR PERFORMING REMOTE AUDITS This GM provides technical guidance on the use of remote information and communication technologies (ICT) to support: competent authorities when overseeing regulated organisations; regulated organisations when conducting internal audits/monitoring compliance of their organisation with the relevant requirements, and when evaluating vendors, suppliers and subcontractors. In the context of this GM: ‘remote audit’ means an audit that is performed with the use of any real-time video and audio communication tools instead of the physical presence of the auditor on-site; the specificities of each type of approval need to be considered in addition to the general overview (described below) when applying the ‘remote audit’ concept; ‘auditing entity’ means the competent authority or organisation that performs the remote audit; ‘auditee’ means the entity being audited/inspected (or the entity audited/inspected by the auditing entity via a remote audit); It is the responsibility of the auditing entity to assess whether the use of remote ICT constitutes a suitable alternative to the physical presence of an auditor on-site in accordance with the applicable requirements.

THE CONDUCT OF A REMOTE AUDIT The auditing entity that decides to conduct a remote audit should describe the remote audit process in its documented procedures and should consider at least the following elements: The methodology for the use of remote ICT is sufficiently flexible and non-prescriptive in nature to optimise the conventional audit process. Adequate controls are defined and are in place to avoid abuses that could compromise the integrity of the audit process. Measures to ensure that the security and confidentiality are maintained throughout the audit activities (data protection and intellectual property of the organisation also need to be safeguarded). Examples of the use of remote ICT during audits may include but are not limited to: meetings by means of teleconference facilities, including audio, video and data sharing; assessment of documents and records by means of remote access, in real time; recording, in real time during the process, of evidence to document the results of the audit, including non-conformities, by means of exchange of emails or documents, instant pictures, video or/and audio recordings; visual (livestream video) and audio access to facilities, stores, equipment, tools, processes, operations, etc. An agreement between the auditing entity and the auditee should be established when planning a remote audit, which should include the following: determining the platform for hosting the audit; granting security and/or profile access to the auditor(s); testing platform compatibility between the auditing entity and the auditee prior to the audit; considering the use of webcams, cameras, drones, etc. when the physical evaluation of an event (product, part, process, etc.) is desired or is necessary; establishing an audit plan which will identify how remote ICT will be used and the extent of their use for the audit purposes to optimise their effectiveness and efficiency while maintaining the integrity of the audit process; if necessary, time zone acknowledgement and management to coordinate reasonable and mutually agreeable convening times; a documented statement of the auditee that they shall ensure full cooperation and provision of the actual and valid data as requested, including ensuring any supplier or subcontractor cooperation, if needed; and data protection aspects. The following equipment and set-up elements should be considered: the suitability of video resolution, fidelity, and field of view for the verification being conducted; the need for multiple cameras, imaging systems, or microphones, and whether the person that performs the verification can switch between them, or direct them to be switched and has the possibility to stop the process, ask a question, move the equipment, etc.; the controllability of viewing direction, zoom, and lighting; the appropriateness of audio fidelity for the evaluation being conducted; and real-time and uninterrupted communication between the person(s) participating to the remote audit from both locations (on-site and remotely). When using remote ICT, the auditing entity and the other persons involved (e.g. drone pilots, technical experts) should have the competence and ability to understand and utilise the remote ICT tools employed to achieve the desired results of the audit(s)/assessment(s). The auditing entity should also be aware of the risks and opportunities of the remote ICT used and the impacts they may have on the validity and objectivity of the information gathered. Audit reports and related records should indicate the extent to which remote ICT have been used in conducting remote audits and the effectiveness of remote ICT in achieving the audit objectives, including any item that has not been able to be completely reviewed.

GM · GM1 145.A.200(a)(6) — Regulation (EU) No 1321/2014 · ED Decision 2022/011/R · Continuing Airworthiness Easy Access Rules · EAR revision 2 Sep 2025

All rules in SECTION A — TECHNICAL AND ORGANISATION REQUIREMENTS

Consolidated from the EASA Easy Access Rules (revision 2 Sep 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about 145.A.200 →

Metis opens with Avioverse in October 2026 · request early access.