Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

21.A.139 Production management system

Annex I · Regulation (EU) No 748/2012 · EAR revision 27 Nov 2025

IRImplementing rule

21.A.139Production management system

(a)The production organisation shall establish, implement and maintain a production management system that includes a safety management element and a quality management element, with clearly defined accountability and lines of responsibility throughout the organisation.

(b)The production management system shall:

1.correspond to the size of the organisation, and to the nature and complexity of its activities, taking into account the hazards and associated risks inherent in those activities;

2.be established, implemented and maintained under the direct accountability of a single manager appointed pursuant to point 21.A.145(c)(1).

(c)As part of the safety management element of the production management system, the production organisation shall:

1.establish, implement and maintain a safety policy and the corresponding related safety objectives;

2.appoint key safety personnel in accordance with point 21.A.145(c)(2);

3.establish, implement and maintain a safety risk management process to identify safety hazards entailed by its aviation activities, evaluate them and manage associated risks, including taking actions to mitigate the risks and verify their effectiveness;

4.establish, implement and maintain a safety assurance process that includes:

(i)the measurement and monitoring of the organisation’s safety performance;

(ii)the management of changes in accordance with point 21.A.147;

(iii)the principles for the continuous improvement of the safety management element;

5.promote safety in the organisation through:

(i)training and education;

(ii)communication;

6.establish an occurrence reporting system in accordance with point 21.A.3A in order to contribute to the continuous improvement of safety.

(d)as part of the quality management element of the production management system, the production organisation shall:

1.ensure that each product, part, appliance, CMU or CMU component produced by the organisation or by its partners, or supplied from or subcontracted to outside parties, conforms to the applicable design data and is in a condition for safe operation, thus enabling the exercise of the privileges set out in point 21.A.163;

2.establish, implement and maintain, as appropriate, within the scope of the approval, control procedures for:

(i)document issue, approval or change;

(ii)vendor and subcontractor assessment audit and control;

(iii)verifying that incoming products, parts, materials, equipment, CMUs or CMU components, including items supplied new or used by the buyers of the products, are as specified in the applicable design data;

(iv)identification and traceability;

(v)manufacturing processes;

(vi)inspection and testing, including production flight tests;

(vii)the calibration of tools, jigs, and test equipment;

(viii)non-conforming item control;

(ix)airworthiness coordination with:

(A)the applicant for, or holder of, the design approval;

(B)the natural or legal person who made a declaration of design compliance in accordance with Subpart C of Section A of Annex Ib (Part 21 Light);

(x)the completion and retention of records;

(xi)the competence and qualifications of personnel;

(xii)the issue of airworthiness release documents;

(xiii)handling, storage and packing;

(xiv)internal quality audits and the resulting corrective actions;

(xv)work within the terms of approval performed at any location other than the approved facilities;

(xvi)work performed after the completion of production but prior to delivery, to maintain the aircraft in a condition for safe operation;

(xvii)the issue of a permit to fly and approval of the associated flight conditions.

3.include specific provisions in the control procedures for any critical parts.

(e)The production organisation shall establish, as part of the production management system, an independent monitoring function to verify compliance of the organisation with the relevant requirements of this Annex as well as compliance with and adequacy of the production management system. Monitoring shall include feedback to the person or group of persons referred to in point 21.A.145(c)(2) and to the manager referred to in point 21.A.145(c)(1) to ensure, where necessary, the implementation of corrective action.

(f)If the production organisation holds one or more additional organisation certificates within the scope of Regulation (EU) 2018/1139, the production management system may be integrated with that required under the additional certificate(s) held.

IR · 21.A.139 — Regulation (EU) No 748/2012 · Regulation (EU) 2024/1108 · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.13921.A.239, 21.B.120, 21.B.140, 21.B.220, and 21.B.240 The use of information and communication technologies (ICT) for performing remote audits

Show the text

This GM provides technical guidance on the use of remote information and communication technologies (ICT) to support: competent authorities when overseeing regulated organisations; regulated organisations when conducting internal audits / monitoring compliance of their organisation with the relevant requirements, and when evaluating vendors, suppliers and subcontractors. In the context of this GM: ‘remote audit’ means an audit that is performed with the use of any real-time video and audio communication tools in lieu of the physical presence of the auditor on-site; the specificities of each type of approval / letter of agreement (LoA) need to be considered in addition to the general overview (described below) when applying the ‘remote audit’ concept; ‘auditing entity’ means the competent authority or organisation that performs the remote audit; ‘auditee’ means the entity being audited/inspected (or the entity audited/inspected by the auditing entity via a remote audit); It is the responsibility of the auditing entity to assess whether the use of remote ICT constitutes a suitable alternative to the physical presence of an auditor on-site in accordance with the applicable requirements. The conduct of a remote audit The auditing entity that decides to conduct a remote audit should describe the remote audit process in its documented procedures and should consider at least the following elements: The methodology for the use of remote ICT is sufficiently flexible and non-prescriptive in nature to optimise the conventional audit process. Adequate controls are defined and are in place to avoid abuses that could compromise the integrity of the audit process. Measures to ensure that the security and confidentiality are maintained throughout the audit activities (data protection and intellectual property of the organisation also need to be safeguarded). Examples of the use of remote ICT during audits may include but are not limited to: meetings by means of teleconference facilities, including audio, video and data sharing; assessment of documents and records by means of remote access, in real time; recording, in real time during the process, of evidence to document the results of the audit, including non-conformities, by means of exchange of emails or documents, instant pictures, video or/and audio recordings; visual (livestream video) and audio access to facilities, stores, equipment, tools, processes, operations, etc. An agreement between the auditing entity and the auditee should be established when planning a remote audit, which should include the following: determining the platform for hosting the audit; granting security and/or profile access to the auditor(s); testing platform compatibility between the auditing entity and the auditee prior to the audit; considering the use of webcams, cameras, drones, etc., when the physical evaluation of an event (product, part, process, etc.) is desired or is necessary; establishing an audit plan which will identify how remote ICT will be used and the extent of their use for the audit purposes to optimise their effectiveness and efficiency while maintaining the integrity of the audit process; if necessary, time zone acknowledgement and management to coordinate reasonable and mutually agreeable convening times; a documented statement of the auditee that they shall ensure full cooperation and provision of the actual and valid data as requested, including ensuring any supplier or subcontractor cooperation, if needed; and data protection aspects. The following equipment and set-up elements should be considered: the suitability of video resolution, fidelity, and field of view for the verification being conducted; the need for multiple cameras, imaging systems, or microphones, and whether the person that performs the verification can switch between them, or direct them to be switched and has the possibility to stop the process, ask a question, move the equipment, etc.; the controllability of viewing direction, zoom, and lighting; the appropriateness of audio fidelity for the evaluation being conducted; and real-time and uninterrupted communication between the person(s) participating to the remote audit from both locations (on-site and remotely). When using remote ICT, the auditing entity and the other persons involved (e.g. drone pilots, technical experts) should have the competence and ability to understand and utilise the remote ICT tools employed to achieve the desired results of the audit(s)/assessment(s). The auditing entity should also be aware of the risks and opportunities of the remote ICT used and the impacts they may have on the validity and objectivity of the information gathered. Audit reports and related records should indicate the extent to which remote ICT have been used in conducting remote audits and the effectiveness of remote ICT in achieving the audit objectives, including any item that it has not been able to be completely reviewed.

GM · GM1 21.A.139 — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)Production management system

Show the text

SAFETY MANAGEMENT ELEMENT Demonstration of compliance with the international industry standard SM-0001 ‘Implementing a Safety Management System in Design, Manufacturing and Maintenance Organisations’, Issue B, 31 March 2022, is an acceptable means to demonstrate compliance with the safety management element of the production management system.

AMC · AMC1 21.A.139(c) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(c)Production management system

Show the text

SAFETY MANAGEMENT ELEMENT Safety management seeks to proactively identify hazards and mitigate the related safety risks before they result in aviation accidents and incidents. Safety management enables an organisation to manage its activities in a more systematic and focused manner. When an organisation has a clear understanding of its role in, and contribution to, aviation safety, this enables the organisation to prioritise safety risks and more effectively manage its resources for optimal results. Safety should not be considered the responsibility of a single person or a limited group of people in the organisation. A safety culture should be developed throughout the organisation, which involves all the personnel as active contributors to the safety of the final product, part, or appliance (see AMC1 21.A.139(c)(1)). The principles of the requirements in points 21.A.3A, 21.A.5, 21.A.139, 21.A.145, and 21.A.147, and the related AMC constitute the EU production management system framework for aviation safety management. This framework addresses the core elements of the International Civil Aviation Organization (ICAO) safety management system (SMS) framework that is defined in ICAO Annex 19, Appendix 2, and facilitates the introduction of the additional safety management element. This approach is intended to encourage organisations to embed safety management and risk-based decision-making into all their activities, instead of superimposing another system onto their existing management system and governance structure. In addition, if the organisation holds multiple organisation certificates that are issued under Regulation (EU) 2018/1139, it may choose to implement a single management system to cover all of its activities. An integrated management system may be used not only to capture multiple management system requirements resulting from Regulation (EU) 2018/1139, but also to cover for other regulatory provisions requiring compliance with ICAO Annex 19 or for other business management systems, such as security, occupational health, and environmental management systems. Integration will remove duplication and exploit synergies by managing safety risks across multiple activities. Organisations may determine the best means to structure their management systems to suit their business and organisational needs. It is important to recognise that safety management will be a continuous activity, as hazards, risks, as well as the effectiveness of safety risk mitigations, will change over time. The safety management capability of an organisation should be commensurate with the safety risks to be managed, which can be at the product, part, and appliance level or at the organisational level. The risks that are inherent in a complex structure require a robust safety risk management process (e.g. a complex supply chain may induce hazards that are complex to mitigate, or the rate of production, when stretched to the limit, may require more efficient safety barriers). As a consequence, scalability and suitability of the safety management element should be a function of the inherent safety risk capability of the organisation. For instance, for organisations with a lower risk level:

(a)the risk assessment model that is used may be very simple in cases in which the identified hazards are easy to mitigate;

(b)expert judgement might be sufficient to measure the efficiency of safety barriers;

(c)the collection of data, safety information, and occurrences might be very limited;

(d)there might be no need for software or tools to manage the SMS; and

(e)the communication policy might be limited.

GM · GM1 21.A.139(c) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)(1)Production management system

Show the text

SAFETY POLICY & OBJECTIVES

(a)The safety policy should:

(1)reflect organisational commitments regarding safety, and its proactive and systematic management, including the promotion of a positive safety culture;

(2)include internal reporting principles by fostering the reporting of organisational threats as well as events, as defined in AMC3 21.A.3A(a);

(3)be endorsed by the accountable manager (AM);

(4)be communicated, with visible endorsement, throughout the organisation; and

(5)be periodically reviewed to ensure that it remains relevant and appropriate to the organisation.

(b)The safety policy should include the commitment:

(1)to comply with all the applicable legislation, meet all the applicable requirements, and adopt practices to improve safety standards;

(2)to provide the necessary resources for the implementation of the safety policy;

(3)to apply human factors (HF) principles;

(4)to enforce safety as a primary responsibility of all managers; and

(5)to apply ‘just culture’ principles and, in particular, not to make available or use the information on occurrences:

(i)to attribute blame or liability to personnel for action, omissions, or decisions that are commensurate with their experience and training; or

(ii)for any purpose other than the improvement of aviation safety.

(c)Senior management should continuously promote the safety policy to all personnel, demonstrate their commitment to it, and provide the necessary human and financial resources for its implementation.

(d)Taking due account of its safety policy, the organisation should define safety objectives. The safety objectives should:

(1)form the basis for safety performance monitoring and measurement;

(2)reflect the organisation’s commitment to maintaining or continuously improving the overall effectiveness of safety management;

(3)be communicated throughout the organisation; and

(4)be periodically reviewed to ensure that they remain relevant and appropriate to the organisation.

AMC · AMC1 21.A.139(c)(1) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(c)(1)Production management system

Show the text

SAFETY POLICY The safety policy is the means for the organisation to state its intention to maintain and, where practicable, to improve the safety levels of all its activities, and to minimise its contribution to the risk of an aircraft accident or serious incident occurring, as far as reasonably practicable. The safety policy reflects the management’s commitment to safety and the organisation’s philosophy of safety management. It is the foundation on which the organisation’s management system is built and serves as a reminder of ‘how we do business here’. The creation of a positive safety culture begins with issuing a clear, unequivocal policy statement. The commitment to apply ‘just culture’ principles forms the basis for the organisation’s internal rules that describe how ‘just culture’ principles are guaranteed and implemented. Regulation (EU) No 376/2014 defines the ‘just culture’ principles to be applied (refer, in particular, to Article 16(11) of that Regulation).

GM · GM1 21.A.139(c)(1) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)(2)Production management system

Show the text

ORGANISATION AND ACCOUNTABILITY

(a)The management system should encompass safety by including a safety manager and a safety review board in the organisational structure. The functions of the safety manager are defined in AMC1 21.A.145(c)(2).

(b)Safety review board

(1)The safety review board (the ‘board’), sometimes referred to as ‘high-level safety committee’, considers matters of strategic safety in support of the safety accountability of the accountable manager.

(2)The board should be normally chaired by the accountable manager and be generally composed of the person or group of persons nominated under point 21.A.145(c)(2). Its composition can be adapted to its needs, considering point 21.A.145(c)(2).

(3)The board should monitor:

(i)the organisation’s safety performance against its safety policy and objectives;

(ii)whether any safety action is taken in a timely manner; and

(iii)the effectiveness of the organisation’s management system processes.

(4)The board may also be tasked with:

(i)reviewing the results of compliance monitoring; and

(ii)monitoring the implementation of any related corrective and preventive action.

(c)The board should ensure that appropriate resources are allocated to achieve the established safety objectives.

(d)Notwithstanding point (a), if justified by the size of the organisation and the nature and complexity of its activities, and subject to a risk assessment and/or mitigation measures, as well as the competent authority’s agreement, the organisation may not need to establish a board. In that case, the tasks that are normally allocated to the board should be allocated to the safety manager.

AMC · AMC1 21.A.139(c)(2) — Regulation (EU) No 748/2012 · ED Decision 2023/014/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(c)(2)Production management system

Show the text

SAFETY ACTION GROUP

(a)Depending on the size of the organisation and the nature and complexity of its activities, a safety action group may be established as a standing group or as an ad hoc group to assist, or act on behalf of, the safety manager or the safety review board.

(b)More than one safety action group may be established, depending on the scope of the task and the specific expertise that is required.

(c)The safety action group usually reports to, and takes strategic direction from, the safety review board, and may be composed of managers, supervisors, and personnel from operational areas.

(d)The safety action group may be tasked with or assist in the following:

(1)monitoring safety performance;

(2)defining action to control risks to an acceptable level;

(3)assessing the impact of organisational changes on safety;

(4)ensuring that safety action is implemented within the agreed timescales; and

(5)reviewing the effectiveness of previous safety action and safety promotion.

GM · GM1 21.A.139(c)(2) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)(3)and (4) Production management system

Show the text

SAFETY MANAGEMENT KEY PROCESSES

(a)Hazard identification processes

(1)Hazard identification should be based on a combination of reactive and proactive methods.

(2)The organisation should focus in particular on hazards that may generate nonconformity of a product, part, or appliance that is produced.

(b)Safety risk management processes

(1)The organisation should develop and maintain a safety risk management process that ensures a reactive, proactive, and predictive approach composed of the following elements:

(i)analysis (e.g. in terms of the probability or likelihood as well as severity of the consequences of hazards and occurrences)

(ii)assessment (in terms of tolerability); and

(iii)control (in terms of mitigation) of risks to an acceptable level.

(2)The organisation should specify, within the risk management process, who has the authority to make decisions, considering point (b)(1) of this AMC.

(c)Regardless of the approval status of the subcontracted organisations, the production organisation (PO) is responsible for ensuring that hazard identification and risk management activities are performed on subcontracted activities, as required by point 21.A.139(d)(2)(ii), as well as for the monitoring of their compliance and adequacy, as required by point 21.A.139(e).

(d)Internal investigation

(1)In line with ‘just culture’ as part of the safety policy, the organisation should define how to investigate events such as errors or near misses, in order to understand not only what happened, but also how it happened, as well as to prevent or reduce the probability and/or the consequences of any future recurrence.

(2)The scope of internal investigations should extend beyond the scope of the occurrences that are required to be reported to the competent authority in accordance with point 21.A.3A.

(e)Safety performance monitoring and measurement

(1)Safety performance monitoring and measurement should be the processes through which the safety performance of the organisation is verified against the safety policy and the safety objectives.

(2)This process may include, as appropriate to the size, nature, and complexity of the organisation, the following elements:

(i)safety reporting that also addresses the status of compliance with the applicable requirements;

(ii)safety reviews, including trend reviews, which should be conducted during the introduction and deployment of new products, parts, or new equipment/technologies, the implementation of new or changed procedures, or in cases of organisational changes that may have an impact on safety;

(iii)safety audits that focus on the integrity of the organisation’s management system, and that periodically assess the status of safety risk controls;

(iv)safety surveys that examine particular elements or procedures of a specific area, such as the following:

(A)the problem areas identified;

(B)bottlenecks in the daily production management activities;

(C)the perceptions and opinions of the production management personnel; and

(D)any areas of dissent or confusion; and

(v)other indicators relevant to safety performance.

(f)Management of change Changes to the production management system may pose new hazards or decrease the effectiveness of existing safety risk controls. The organisation should manage any safety risks that are related to change in that organisation. The management of change should be a documented process to identify external or internal change that may have an adverse effect on safety. The management of change should use the organisation’s existing processes for hazard identification, risk assessment, and risk mitigation.

(g)Continuous improvement The organisation should continuously seek to improve its safety performance and the effectiveness of its production management system. Continuous improvement may be achieved through review of the following elements:

(1)compliance monitoring and audits;

(2)assessments, including assessments of the effectiveness of the safety culture and of the management system, to assess in particular the effectiveness of the safety risk management processes;

(3)staff surveys, including safety culture surveys, that can provide useful feedback on how engaged the staff are in the production management system;

(4)the monitoring of events and their recurrence;

(5)the evaluation of the safety performance indicators as well as reviews of all the available safety performance information; and

(6)the identification of lessons learned.

AMC · AMC1 21.A.139(c)(3) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)(4)(ii)Production management system

Show the text

MANAGEMENT OF CHANGE This AMC provides a means to consider organisational changes for their potential impact on safety. Organisational changes should also be evaluated for their significance, as required by point 21.A.147. In addition, necessary changes should be introduced into the production organisation exposition (POE), as per point 21.A.143(c). The production management system should be designed such that all the above points are taken into account.

(a)Organisational changes should be proactively considered for their safety implications. The magnitude of a change, its safety criticality, and its potential impact on human performance (HP) should be assessed in any process for the management of change. Certain non-complex organisational changes may not require additional assessment.

(b)Special consideration, including human factors (HF) issues, should be given to the transition period during which the change becomes effective.

(c)During the process for the management of change, relevant previous risk assessments and existing hazards should be reviewed for their possible effects.

AMC · AMC1 21.A.139(c)(4)(ii) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(c)(4)(ii)Production management system

Show the text

MANAGEMENT OF CHANGE Unless properly managed, changes in the organisational structure, facilities, scope of work, personnel, documentation, policies and procedures, etc. may result in inadvertently creating new hazards, which may expose the organisation to new or greater risks. Effective organisations seek to improve their processes, while being conscious of the fact that changes may expose the organisation to potential hazards and risks if they are not properly and effectively managed. The process for the management of change typically provides principles and a structured framework for managing all aspects of change. The disciplined implementation of management of change may maximise the effectiveness of change, engage staff, and minimise the risks that are inherent in change. Change may have the potential to raise new HF issues, or to exacerbate existing ones. For example, changes in computer systems, equipment, technology, personnel changes (including changes in management personnel), procedures, the organisation of work, or work processes are likely to affect performance. Effective management of change is supported by the following elements:

(a)the implementation of a process for hazard identification/risk analysis and assessment for major operational changes, major organisational changes, changes in key personnel, and changes that may affect the way in which production management is carried out;

(b)the identification of changes that may have a considerable impact on:

(1)resources (material and human);

(2)management direction (policies, processes, procedures, training); and

(3)management control;

(c)safety cases/risk assessments that are aviation-safety-focused; and

(d)the involvement of key stakeholders in the process for the management of change, as appropriate.

GM · GM1 21.A.139(c)(4)(ii) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)(5)Production management system

Show the text

SAFETY COMMUNICATION

(a)The organisation should establish communication to the staff, as appropriate to their safety responsibilities, regarding safety matters, which:

(1)ensures awareness of safety management activities;

(2)conveys safety-critical information, especially related to assessed risks and analysed hazards;

(3)explains why particular action is taken; and

(4)explains why safety procedures are established or changed.

(b)Regular meetings with staff, during which information, action, and procedures are discussed, may be used to communicate safety matters.

AMC · AMC1 21.A.139(c)(5) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(c)(5)Production management system

Show the text

SAFETY PROMOTION

(a)Safety training, combined with safety communication and information sharing, is part of safety promotion.

(b)Safety promotion activities support the following:

(1)the organisation’s policies, encouraging a positive safety culture, thus creating an environment that is favourable to the achievement of the organisation’s safety objectives;

(2)organisational lessons learned; and

(3)the implementation of an effective safety reporting scheme and the development of a ‘just culture’.

(c)Depending on the particular safety issue, safety promotion may also constitute or complement risk mitigation action.

GM · GM1 21.A.139(c)(5) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(c)(5)(i)Production management system

Show the text

SAFETY TRAINING

(a)The production management staff, as described in points 21.A.145(c)(1) and (2), should receive initial and recurring safety training, as appropriate to their responsibilities, including in safety management principles and the associated safety objectives, to ensure their continued competency.

(b)The organisation should identify the category of other staff to which safety training should be provided, and define the initial and recurrent training programmes, including appropriate timelines.

(c)Adequate records of the safety training that is provided should be kept in accordance with point 21.A.5.

AMC · AMC1 21.A.139(c)(5)(i) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(c)(5)(i)Production management system

Show the text

SAFETY TRAINING

(a)The main purpose of the safety training programme is:

(1)to support safety management policies and processes; and

(2)to ensure that personnel at all levels of the organisation develop and maintain their competency to fulfil their safety roles.

(b)Each organisation may adapt its syllabus to its own needs. Typically, depending on the targeted staff, to contribute to a positive safety culture, the following items may be included:

(1)the organisational roles and responsibilities related to safety, including the hazard identification and risk management processes;

(2)the safety objectives and the associated safety performance indicators;

(3)human factors (HF) principles, including human performance (HP) and limitations;

(4)legislation, where applicable;

(5)safety reporting systems and investigations; and

(6)safety issues.

(c)The purpose of the recurrent safety training is:

(1)primarily to ensure that staff are kept abreast notably of changes to safety management system (SMS) principles, processes, and procedures; and

(2)also to share feedback on safety issues that are relevant to the organisation or lessons learned.

(d)The training staff should have sufficient knowledge and experience to teach the topics at the required level, as well as the skills to influence attitudes and behaviours.

GM · GM1 21.A.139(c)(5)(i) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(d)Production management system

Show the text

QUALITY SYSTEM ELEMENT The quality system element is an organisational structure, included in the production management system, with responsibilities, procedures, processes, and resources that implement a management function to determine and enforce quality principles. The quality system should be documented in such a way that the documentation can be made easily available to personnel who need to use the material for performing their normal duties, in particular: procedures, instructions, data to cover the issues of point 21.A.139(d)(2) are available in a written form; distribution of relevant procedures to offices/persons is made in a controlled manner, procedures which identify persons responsible for the prescribed actions are established; and the updating process is clearly described. The competent authority will verify on the basis of the exposition and by appropriate investigations that the production organisation (PO) has established and can maintain their documented quality system.

AMC · AMC1 21.A.139(d) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(d)(1)Production management system

Show the text

CONFORMITY OF SUPPLIED PARTS OR APPLIANCES The production organisation approval (POA) holder is responsible for determining and applying acceptance standards for physical condition, configuration status and conformity of supplied products, parts or appliances, whether to be used in production or delivered to customers as spare parts. This responsibility also includes BFE (Buyer Furnished Equipment) items. To discharge this responsibility the quality system needs an organisational structure and procedures to adequately control suppliers. Elements of the quality system for the control of suppliers may be performed by other parties provided that the conditions of AMC1 21.A.139(d)(2)(ii) or AMC2 21.A.139(d)(2)(ii) are met. Control can be based upon use of the following techniques (as appropriate to the system or product orientation necessary to ensure conformity): qualification and auditing of the supplier’s quality system; evaluation of the supplier's capability in performing all the manufacturing activities, inspections and tests necessary to establish the conformity of parts or appliances to the type design; first article inspections, including destruction, if necessary, to verify that the article conforms to the applicable data for a new production line or a new supplier; incoming inspections and tests of supplied parts or appliances that can be satisfactorily inspected on receipt; identification of incoming documentation and data relevant to the showing of conformity to be included in the certification documents; a vendor rating system which gives confidence in the performance and reliability of this supplier; and any additional work, tests or inspection which may be needed for parts or appliances which are to be delivered as spare parts and which are not subjected to the checks normally provided by subsequent production or inspection stages. The POA holder may rely on the results of inspections/tests performed by the supplier if it can establish that: the personnel responsible for these tasks satisfy the competency standards of the POA quality system; quality measurements are clearly identified; and the records or reports showing evidence of conformity are available for review and audit. The POA holder retains direct responsibility for inspections/tests that are performed either at its own facilities or at the supplier’s facilities. The control of suppliers holding a POA for the parts or appliances to be supplied can be reduced to a level at which a satisfactory interface between the two quality systems can be demonstrated. Thus, for the purpose of showing conformity, a POA holder can rely upon documentation for parts or appliances, which is released in accordance with the supplier’s privileges that are defined in point 21.A.163. A supplier who does not hold a POA is considered to be a subcontractor under the direct control of the POA quality system.

GM · GM1 21.A.139(d)(1) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM2 21.A.139(d)(1)Production management system

Show the text

QUALITY SYSTEM ELEMENT — PARTNER AND SUBCONTRACTOR ARRANGEMENTS When defining the arrangements between the production organisation (PO) and its partners and subcontractors, both elements of the production management system should be taken into account, i.e. the safety management element and the quality system element. The following guidance should therefore be considered applicable to both elements.

(a)When the PO subcontracts activities, the arrangements should consider the safety risk management process that is part of the PO’s safety management element (see point 21.A.139(c)(3)). When the subcontractor does not have a safety management element, the subcontractor should be integrated into the safety management element of the PO; when the subcontractor has implemented a safety management system (such as for design organisation approval (DOA) or production organisation approval (POA)), the two safety management systems, i.e. of the PO and of the subcontractor, should be harmonised.

(b)Depending on the complexity and criticality of those arrangements, the following elements within the arrangements should be addressed:

(1)coordination and interfaces between all the parties involved;

(2)applicable procedures;

(3)safety culture, including internal safety reporting schemes (see point 21.A.3A);

(4)communication between all the parties involved, including reporting, regular meetings, and feedback channels;

(5)allocation of tasks, of clear accountability, and of responsibilities; and (6 the qualifications and competency of key personnel with reference to point 21.A.145.

(c)The safety risk management should focus on the need to exchange safety data and safety information that are deemed significant for the determination of relevant risks in terms of likelihood, severity, impact, and acceptability, such as, wherever appropriate, but not limited to the following:

(1)(at product level) failure, malfunction, defect, or other occurrences, non-conformity or outcome of the compliance monitoring function, quality escape, process failure, foreign object damage (FOD), deviation (e.g. calibration of tools), component failure analysis, in-service event, etc.;

(2)(at documentation level) key processes (e.g. airworthiness directives, production documentation, production processes); and

(3)(at organisational level) organisational changes, disruptive events, resources’ issues, human performance (HP) issues.

(d)Regular communication should be ensured between all the parties involved, to discuss work progress, risk mitigation measures, changes to the arrangements, as well as any other significant issues.

GM · GM2 21.A.139(d)(1) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(d)(2)Production management system

Show the text

QUALITY SYSTEM — ELEMENTS OF THE QUALITY SYSTEM

(1)The control procedures covering the elements of point 21.A.139(d)(2) should document the standards to which the production organisation intends to work.

(2)An organisation having a quality system designed to meet a recognised Standard such as ISO 9001 (relevant to the scope of approval being requested) should expand it to include at least the following additional topics, as appropriate, in order to demonstrate compliance with the requirements of Part 21: mandatory and voluntary occurrence reporting, as required by points 21.A.3A and 21.A.139(c) and continued airworthiness as required by point 21.A.165(e); control of work occasionally performed (outside the POA facility by POA personnel); coordination with the applicant for, or holder of, an approved design, as required by points 21.A.133(b) and (c) and 21.A.165(g); issue of certifications within the scope of approval for the privileges of point 21.A.163; incorporation of airworthiness data in production and inspection data, as required in points 21.A.133(b) and (c) and 21.A.145(b) when applicable, ground test and/or production flight test of products in accordance with procedures defined by the applicant for, or holder of, the design approval; procedures for traceability including a definition of clear criteria of which items need such traceability; traceability is defined as a means of establishing the origin of an article by reference to historical records for the purpose of providing evidence of conformity; and personnel training and qualification procedures especially for certifying staff as required in 21.A.145(d).

(3)An organisation having a quality system designed to meet a recognised aerospace quality standard will still need to ensure compliance with all the requirements of Part 21. In all cases, the competent authority will still need to be satisfied that compliance with Part 21 is established.

AMC · AMC1 21.A.139(d)(2) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(d)(2)(ii)Production management system

Show the text

VENDOR AND SUBCONTRACTOR ASSESSMENT, AUDIT AND CONTROL — PRODUCTION ORGANISATION APPROVAL HOLDER THAT USES DOCUMENTED ARRANGEMENTS WITH OTHER PARTIES FOR THE ASSESSMENT AND SURVEILLANCE OF A SUPPLIER

(1)General The production organisation is required by point 21.A.139(d) to demonstrate that it has established and maintains a quality system that enables the organisation to ensure that each item produced conforms to the applicable design data and is in a condition for safe operation. To discharge this responsibility, the quality system should have, among other requirements, procedures to adequately carry out the assessment and surveillance of suppliers. The use of other parties (OPs), such as a consulting firm or quality assurance company, for supplier assessment and surveillance does not exempt the production organisation approval (POA) holder from its obligations under point 21.A.165. The supplier assessment and surveillance, corrective action and follow-up activity conducted at any of its supplier’s facilities may be performed by OPs. The purpose of using an OP cannot be to replace the assessment, audit and control of the POA holder. It is to allow an element (i.e. the assessment of the quality system) to be delegated to another organisation under controlled conditions. The use of OPs to perform supplier assessments and surveillance should be part of the production organisation quality system and fulfil the conditions of this AMC. This AMC is applicable to a method whereby a POA holder has a documented arrangement with an OP for the purpose of assessing and/or surveying a POA’s supplier.

(2)Reserved

(3)Conditions and criteria for the use of OPs to perform supplier assessment and surveillance

(a)The POA holder should include the use of OPs for supplier assessment and surveillance in the POA holders’ quality system to demonstrate compliance with the applicable requirements of Part 21.

(b)The procedures that are required for using OPs for supplier assessment and surveillance should be consistent with other procedures of the POA holders’ quality system.

(c)The procedures of the POA holder that uses OPs to perform supplier assessment and surveillance should include the following:

(1)Identification of the OP that will conduct the supplier assessment and surveillance.

(2)A listing of suppliers under surveillance by the OP. This listing should be maintained by the POA holder and made available to the competent authority upon request.

(3)The method used by the POA holder to evaluate and monitor the OP. The method should include the following as a minimum:

(i)verification that standards and checklists used by the OP are acceptable for the applicable scope;

(ii)verification that the OP is appropriately qualified and has sufficient knowledge, experience, and training to perform its allocated tasks;

(iii)verification that the frequency with which the OP carry out surveillance of the suppliers is commensurate with the complexity of the product and with the surveillance frequency established by the POA holder’s suppliers control programme;

(iv)verification that the assessment and surveillance of the suppliers is including on-site surveillance activities that are conducted by the OP; and

(v)verification that the OP has access to the applicable proprietary data to the level of detail necessary to survey suppliers functions. Where the POA holder uses an OP accredited by a signatory to the European cooperation for Accreditation (EA) Multilateral Agreement and works in accordance with an aviation standard (e.g. EN 9104 series of requirements) that describes requirements for the assessment and surveillance by the other party, items (ii) and (iv) shall be deemed to be complied with.

(4)A definition that states to what extend the OP will conduct surveillance of the suppliers on behalf of the POA holder. If the OP partly replaces surveillance by the POA holder, the POA holder should identify the functions that will continue to be surveyed by the POA holder.

(5)The procedures used by the OP to notify the POA holder of any non-conformity that is discovered at the supplier's facility, and of the corrective action and follow-up.

(d)The POA should make arrangements that allow the competent authority to make investigations in accordance with point 21.A.9 to include OP activities.

AMC · AMC1 21.A.139(d)(2)(ii) — Regulation (EU) No 748/2012 · ED Decision 2023/014/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC2 21.A.139(d)(2)(ii)Production management system

Show the text

VENDOR AND SUBCONTRACTOR ASSESSMENT, AUDIT, AND CONTROL — PRODUCTION ORGANISATION APPROVAL HOLDER THAT USES OTHER PARTIES SUPPLIER CERTIFICATION

(1)General Other party (OP) supplier certification is a method whereby a supplier contracts an appropriately recognised or accredited OP for the purpose of obtaining a certification from that OP. Certification indicates that the supplier has satisfactorily demonstrated that it meets the applicable standard on a continuing basis. OP certification results in placing the supplier on the OP list of certified organisations, or in the supplier receiving a certificate identifying the requirements that have been met. Periodic follow-up evaluations are conducted by the OP to verify continued compliance with the requirements of the applicable standard. The production organisation is required by point 21.A.139(d) to demonstrate that it has established and maintains a quality system that enables the organisation to ensure that each item produced conforms to the applicable design data and is in a condition for safe operation. To discharge this responsibility, the quality system should have, among other requirements, procedures to adequately carry out the assessment and surveillance of suppliers. The assessment and surveillance of suppliers by an OP should be deemed to satisfy the requirements of point 21.A.139(b)(1)(ii) when the conditions of this AMC are satisfied. The assessment and surveillance of suppliers by OP as part of supplier certification does not exempt the production organisation approval (POA) holder from its obligations under point 21.A.165. The supplier assessment and surveillance, corrective action and follow-up activity conducted at any of its supplier’s facilities may be performed by OP. The purpose of using an OP cannot be to replace the assessment, audit and control of the POA holder. It is to allow an element (i.e. the assessment of the quality system) to be delegated to another organisation under controlled conditions. The use of suppliers that are certified by OP in accordance with this AMC should be part of a production organisation quality system.

(2)Reserved

(3)Conditions and criteria for using supplier certification for supplier assessment and surveillance

(a)The POA holder should include the use of supplier certification for the supplier assessment and surveillance in the POA holder’s quality system to demonstrate compliance with the applicable requirements of Part 21.

(b)The procedures that are required for use of supplier certification for the supplier assessment and surveillance should be consistent the with other procedures of the POA holders’ quality system.

(c)The procedures of the POA holder that uses supplier certification for the supplier assessment and surveillance should include the following:

(1)A listing of the OPs that have certified or will certify suppliers and will conduct supplier assessment and surveillance or the scheme under which the accreditation of the OP is controlled. This listing should be maintained by the POA holder and made available to the competent authority upon request.

(2)A listing of the certified suppliers that are under surveillance by the OP and that are used by the POA holder. This listing should be maintained by the POA holder and made available to the competent authority upon request.

(3)The method used by the POA holder to evaluate and monitor the certification process of any OP certification body or OP certification scheme used. This applies not only to new suppliers, but also to any decision by the POA holder to rely on OP certification of current suppliers. The method should include the following as a minimum:

(i)verification that certification standards and checklists are acceptable and applied to the applicable scope;

(ii)verification that the OP is appropriately qualified and has sufficient knowledge, experience and training to perform its allocated tasks;

(iii)verification that the frequency with which the OP carries out surveillance of the suppliers is commensurate with the complexity of the product and with the surveillance frequency established by the POA holder’s suppliers control programme;

(iv)verification that the surveillance of the suppliers is including on-site surveillance activities that are conducted by the OP;

(v)verification that the surveillance report will be made available to the competent authority upon request;

(vi)verification that the OP continues to be recognised or accredited; and

(vii)verification that the OP has access to the applicable proprietary data to the level of detail necessary to survey the suppliers’ functions. Where the POA holder uses an OP accredited by a signatory to the European cooperation for Accreditation (EA) Multilateral Agreement and works in accordance with an aviation standard (e.g. EN 9104 series of requirements) that describes the requirements for the OP certification, items (ii), (iv), and (v) should be deemed to be complied with.

(4)A definition that states to what extend the OP will conduct supplier surveillance on behalf of the POA holder. If the OP partly replaces surveillance by the POA holder, the POA holder should identify the functions that will continue to be surveyed by the POA holder.

(5)the procedures that ensure that the POA is aware of the loss of an existing certification.

(6)the procedures that ensure that the POA holder is aware of any non-conformity and has access to detailed information on any non-conformity.

(7)the procedures to evaluate the consequences of non-conformity and take appropriate actions.

(d)The POA should make arrangements that allow the competent authority to make investigations in accordance with point 21.A.9 to include OP activities.

AMC · AMC2 21.A.139(d)(2)(ii) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(d)(2)(ii)Production management system

Show the text

ASSESSMENT, AUDIT, AND CONTROL OF VENDOR AND SUBCONTRACTOR For the purposes of AMC1 21.A.139(d)(2)(ii) and AMC2 21.A.139(d)(2)(ii), vendors and subcontractors are referred to as ‘suppliers’,whether they hold production organisation approvals (POAs) or not; audit and control are hereinafter referred to as ‘surveillance’. Implementing or significantly changing procedures to use an OP for supplier assessment and surveillance is a significant change to the quality system, and it requires approval in accordance with point 21.A.147.

GM · GM1 21.A.139(d)(2)(ii) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.A.139(e)and 21.A.139(d)(2)(xiv) Production management system

Show the text

INDEPENDENT MONITORING FUNCTION

(a)The independent monitoring function should ensure that:

(1)the activities of the production organisation (PO) are monitored for their compliance with the applicable requirements and with any additional requirements as established by the organisation, and that those activities are properly performed under the supervision of the nominated persons that are referred to in point 21.A.145(c)(2); furthermore, compliance with, and the adequacy of, the production management system should be monitored;

(2)all subcontracted production activities are monitored for compliance and adequacy with the applicable arrangements;

(3)an objective review of the complete set of production-management-related activities is provided through independent monitoring activities, such as audits, inspections, reviews;

(4)the independence of the monitoring activities is established by always ensuring that those activities and inspections are performed by staff that are not involved in the function, procedure, or products that they monitor, and that are independent from the operating managers of the function(s) being monitored; however, this should not exclude support by domain experts during monitoring;

(5)a monitoring plan is established to show when and how often the activities that are required by Part 21 will be audited;

(6)the monitoring cycle should not exceed the applicable oversight planning cycle that is established according to point 21.B.222; the determination of the monitoring plan should consider at least the following aspects:

(i)the criticality of the items checked; and

(ii)the safety performance of the organisation, including any previous findings and root causes;

(7)when non-compliance is found, the root cause(s) and contributing factor(s) are identified, and corrective action is defined and followed up;

(8)feedback is provided to the management of the PO; and

(9)the above elements perform the planned continuing and systematic evaluations or audits of the factors that affect the conformity (and, where required, the safe operation) of the products, parts, or appliances to the applicable design; this evaluation should include all the elements of the production management system to demonstrate compliance with Part 21.

(b)The staff performing an independent monitoring function should have access to all the parts of the PO and, as necessary, to any subcontracted organisations.

AMC · AMC1 21.A.139(e) — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.139(f)Production management system

Show the text

ADEQUACY OF THE PRODUCTION MANAGEMENT SYSTEM ‘Adequacy of the production management sytem’ means that the production organisation, through the use of the procedures as defined, is capable of meeting the conformity objectives that are identified in 21.A.139(d)(1).

GM · GM1 21.A.139(f) — Regulation (EU) No 748/2012 · ED Decision 2023/014/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.A.13921.A.239, 21.B.120, 21.B.140, 21.B.220, and 21.B.240 The use of information and communication technologies (ICT) for performing remote audits

Show the text

This GM provides technical guidance on the use of remote information and communication technologies (ICT) to support: competent authorities when overseeing regulated organisations; regulated organisations when conducting internal audits / monitoring compliance of their organisation with the relevant requirements, and when evaluating vendors, suppliers and subcontractors. In the context of this GM: ‘remote audit’ means an audit that is performed with the use of any real-time video and audio communication tools in lieu of the physical presence of the auditor on-site; the specificities of each type of approval / letter of agreement (LoA) need to be considered in addition to the general overview (described below) when applying the ‘remote audit’ concept; ‘auditing entity’ means the competent authority or organisation that performs the remote audit; ‘auditee’ means the entity being audited/inspected (or the entity audited/inspected by the auditing entity via a remote audit); It is the responsibility of the auditing entity to assess whether the use of remote ICT constitutes a suitable alternative to the physical presence of an auditor on-site in accordance with the applicable requirements. The conduct of a remote audit The auditing entity that decides to conduct a remote audit should describe the remote audit process in its documented procedures and should consider at least the following elements: The methodology for the use of remote ICT is sufficiently flexible and non-prescriptive in nature to optimise the conventional audit process. Adequate controls are defined and are in place to avoid abuses that could compromise the integrity of the audit process. Measures to ensure that the security and confidentiality are maintained throughout the audit activities (data protection and intellectual property of the organisation also need to be safeguarded). Examples of the use of remote ICT during audits may include but are not limited to: meetings by means of teleconference facilities, including audio, video and data sharing; assessment of documents and records by means of remote access, in real time; recording, in real time during the process, of evidence to document the results of the audit, including non-conformities, by means of exchange of emails or documents, instant pictures, video or/and audio recordings; visual (livestream video) and audio access to facilities, stores, equipment, tools, processes, operations, etc. An agreement between the auditing entity and the auditee should be established when planning a remote audit, which should include the following: determining the platform for hosting the audit; granting security and/or profile access to the auditor(s); testing platform compatibility between the auditing entity and the auditee prior to the audit; considering the use of webcams, cameras, drones, etc., when the physical evaluation of an event (product, part, process, etc.) is desired or is necessary; establishing an audit plan which will identify how remote ICT will be used and the extent of their use for the audit purposes to optimise their effectiveness and efficiency while maintaining the integrity of the audit process; if necessary, time zone acknowledgement and management to coordinate reasonable and mutually agreeable convening times; a documented statement of the auditee that they shall ensure full cooperation and provision of the actual and valid data as requested, including ensuring any supplier or subcontractor cooperation, if needed; and data protection aspects. The following equipment and set-up elements should be considered: the suitability of video resolution, fidelity, and field of view for the verification being conducted; the need for multiple cameras, imaging systems, or microphones, and whether the person that performs the verification can switch between them, or direct them to be switched and has the possibility to stop the process, ask a question, move the equipment, etc.; the controllability of viewing direction, zoom, and lighting; the appropriateness of audio fidelity for the evaluation being conducted; and real-time and uninterrupted communication between the person(s) participating to the remote audit from both locations (on-site and remotely). When using remote ICT, the auditing entity and the other persons involved (e.g. drone pilots, technical experts) should have the competence and ability to understand and utilise the remote ICT tools employed to achieve the desired results of the audit(s)/assessment(s). The auditing entity should also be aware of the risks and opportunities of the remote ICT used and the impacts they may have on the validity and objectivity of the information gathered. Audit reports and related records should indicate the extent to which remote ICT have been used in conducting remote audits and the effectiveness of remote ICT in achieving the audit objectives, including any item that it has not been able to be completely reviewed.

GM · GM1 21.A.139 — Regulation (EU) No 748/2012 · ED Decision 2022/021/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

All rules in SECTION A — TECHNICAL REQUIREMENTS

Consolidated from the EASA Easy Access Rules (revision 27 Nov 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about 21.A.139 →

Metis opens with Avioverse in October 2026 · request early access.