KEEPING AN AVIATION COMPANY COMPLIANT: BUILDING A MANAGEMENT SYSTEM THAT WORKS
- Mark Evers

- 4 minutes ago
- 10 min read

Aviation compliance is not achieved by maintaining a collection of approved manuals or preparing hurriedly for the next authority audit. It is achieved through a living management system that continuously identifies change, evaluates its significance, implements the necessary actions and verifies that those actions have been effective. A genuinely compliant aviation organisation should be able to demonstrate not only that it understands the regulations applicable to its operation, but also how it monitors changes, assigns responsibilities, records decisions, and ensures that new or amended requirements are incorporated within the required timescales.
COMPLIANCE IS A CONTINUOUS PROCESS
Regulations, acceptable means of compliance, guidance material and authority publications are continually evolving. Operational risks also change as new technologies, aircraft types, routes and geopolitical threats emerge. An effective compliance monitoring system must therefore answer four fundamental questions:
1. What requirements apply to the organisation?
2. How does the organisation identify changes to those requirements
3. Who is responsible for assessing and implementing each change?
4. How does the organisation verify that the change has been implemented effectively?
If any of these questions cannot be answered through documented evidence, the organisation may have a gap in its compliance assurance process.

TRACKING REGULATORY CHANGES
Every aviation organisation should maintain a structured regulatory change register. This should identify all legislation, standards and authority publications applicable to the scope of its approvals and operations. Depending on the organisation, the sources monitored may include:
• EASA regulations and Easy Access Rules;
• UK aviation legislation and UK CAA publications;
• National aviation authority decisions and notices;
• ICAO Standards and Recommended Practices;
• Airworthiness Directives;
• Operational Directives;
• Acceptable Means of Compliance and Guidance Material;
• certification specifications;
• safety directives and safety information;
• aerodrome, airspace and security requirements;
• dangerous goods requirements;
• information security requirements; and
• applicable industry standards and manufacturer publications.
The Compliance Monitoring Manager should establish a defined frequency for reviewing these sources. Some may require weekly or monthly monitoring, while others may be reviewed whenever an authority issues an update notification. Simply recording that a publication has changed is not sufficient. Each change should be subjected to an applicability assessment. The regulatory change register should record:
• the source and reference number;
• the date the change was published;
• the effective or compliance date;
• a summary of the change;
• whether it applies to the organisation;
• the reason for the applicability decision;
• the departments, aircraft or activities affected;
• the person responsible for implementation;
• the actions required;
• the target completion date;
• the manuals, procedures, forms or training affected;
• the date implementation was completed; and
• the evidence used to verify closure.
Where a regulatory change is assessed as not applicable, the reason should still be recorded. A documented “not applicable” decision demonstrates that the change was considered rather than overlooked.
ENSURING CHANGES ARE INCORPORATED ON TIME
Regulatory changes must be managed as controlled actions rather than informal reminders. Once a change has been identified as applicable, it should be assigned to an accountable action owner with a clear deadline. The implementation process may involve:
• revising manuals and procedures;
• obtaining prior approval or acceptance from the authority;
• changing operational forms or software;
• amending contracts or service-level agreements;
• briefing employees and contracted personnel;
• developing or revising training;
• completing a management of change assessment;
• updating compliance checklists;
• changing operational or technical processes; and
• verifying that the revised process is being followed in practice.
The compliance date must be distinguished from the publication date. Where authority approval is required, sufficient time must be allowed for drafting, internal review, submission and possible regulatory feedback.
The Compliance Monitoring Manager should monitor progress and escalate overdue or at-risk actions to the Accountable Manager. Regulation changes should remain open until objective evidence confirms that every relevant action has been completed.
Closing an action because a manual amendment has been drafted is not sufficient if employees have not been briefed, training has not been completed or the revised procedure has not entered operational use.
TRACKING CONFLICT ZONE INFORMATION BULLETINS
Conflict Zone Information Bulletins, commonly referred to as CZIBs, require particularly careful management because the circumstances surrounding conflict zones can change rapidly.
The safety department should maintain a dedicated CZIB register recording:
• the affected state, region or airspace;
• the CZIB reference and revision;
• the publication and expiry dates;
• the flight levels, routes or airports affected;
• the nature of the identified threat;
• existing operational restrictions;
• the organisation’s applicability assessment;
• any supporting risk assessment;
• the operational decision taken;
• the person authorising that decision;
• the date flight crews and operational personnel were informed; and
• subsequent reviews, changes or closure.
The existence of a CZIB should trigger coordination between flight operations, safety management, security and compliance monitoring. The organisation must consider not only whether it currently operates through the affected airspace, but also whether diversion routes, alternates, technical stops or ad hoc charter activity could create exposure. Relevant restrictions and mitigations should be reflected in flight planning processes, operational notices, route risk assessments and crew briefings. Dispatchers, flight planners and flight crews must receive the same current information. CZIBs should also be reviewed before expiry because an expiring bulletin may be renewed, amended or replaced. The withdrawal of a CZIB should not automatically result in the removal of company restrictions without a documented review of the remaining risk.
TRACKING SAFETY INFORMATION BULLETINS
Safety Information Bulletins, or SIBs, may not always impose mandatory requirements, but they can contain important information concerning emerging hazards, operational experience, aircraft systems, maintenance practices and recommended mitigations.
SIBs should therefore be managed through a formal review process between compliance and safety, rather than circulated without further action.
A SIB register should include: •
the SIB reference and title; •
the date of issue and revision status;
• the aircraft, equipment or operation concerned;
• the organisational applicability assessment;
• the departments responsible for review;
• any safety or operational assessment completed;
• recommended actions accepted or rejected;
• the justification for the decision;
• the implementation deadline; and
• evidence of completion.
Where a recommendation is not adopted, the organisation should document why. The decision may be entirely reasonable, but it must be demonstrable and supported by an appropriate technical, operational or safety assessment. Relevant SIBs may also reveal new hazards or indicate that an existing risk assessment requires review. This is one of the areas in which compliance monitoring and safety management must work together.
INTERNAL FINDINGS DEMONSTRATE THAT THE SYSTEM IS WORKING
Some organisations are reluctant to raise findings against themselves because they believe that a clean internal audit record presents a picture of strong compliance. In reality, an organisation that never identifies a non-compliance may simply have an ineffective or superficial audit programme.
Internal findings are not evidence of failure. Properly managed, they are evidence that the compliance monitoring system is capable of detecting weaknesses before those weaknesses result in an occurrence, operational disruption, or authority finding.
An effective internal finding should:
• identify the precise requirement that has not been met;
• describe the objective evidence observed;
• explain the nature and extent of the non-compliance;
• be assigned an appropriate classification;
• identify the responsible action owner;
• establish a realistic corrective-action deadline; and
• be subject to verification before closure.
The purpose of an audit is not to protect departments from criticism. It is to provide the Accountable Manager with an independent and accurate picture of organisational compliance.
A healthy compliance culture encourages employees and managers to identify problems early. Concealing a weakness merely allows it to develop into a more serious issue.
CORRECTING THE CAUSE, NOT MERELY THE SYMPTOM
A finding should not be closed simply because the immediate discrepancy has been corrected. The organisation must establish why the non-compliance occurred and whether the same cause could affect other areas.
For example, if an employee completed mandatory training after the required deadline, recording the late completion may correct the immediate problem. It does not explain why the training became overdue.
The root cause may involve:
• unclear responsibility;
• an ineffective reminder process;
• inaccurate personnel records;
• insufficient management oversight;
• inadequate resources;
• poor communication;
• unsuitable software controls; or
• a procedure that does not reflect operational reality.
Corrective action should address the root cause and prevent recurrence. The auditor must then verify implementation and, where appropriate, review effectiveness after a suitable period.
Compliance is the responsibility of the nominated persons, not the compliance monitoring manager. The compliance monitoring manager should ask the responsible person to carry out a root cause analysis. There are several techniques that can be used. Asking ‘why’ repeatedly is an easy and effective method to get to the root cause.

AUDIT RECORDS MUST SHOW WHAT THE AUDITOR EXAMINED
An audit report containing nothing more than ticks, “satisfactory” entries or short statements such as “procedure reviewed” provides little assurance. It does not show what the auditor actually examined or how the conclusion was reached.
Audit records should contain sufficient evidence to allow another competent person to understand:
• what was sampled;
• who was interviewed;
• which records were examined;
• which dates or operational periods were covered;
• which aircraft, flights, personnel or locations were included;
• what was observed;
• what was tested; and
• how the auditor concluded that the requirement was compliant.
Useful audit evidence may include:
• document references and revision numbers;
• training records and completion dates;
• personnel or licence records;
• flight numbers and dates;
• technical log references;
• occurrence report numbers;
• meeting minutes;
• screenshots from controlled systems;
• photographs, where appropriate;
• sampled forms or records;
• interview notes; and
• links to electronically retained evidence.
Evidence must be handled in accordance with the organisation’s confidentiality and data-protection procedures. The objective is not to attach unnecessary volumes of information, but to create an auditable trail supporting the conclusion.
A completed checklist should demonstrate the work performed. It should never give the impression that the auditor sat at a desk and ticked boxes without testing whether the documented process was operating in practice.
COMPLIANCE AND SAFETY MANAGEMENT MUST BE INTEGRATED
Compliance monitoring and safety management perform different functions, but they should not operate as separate administrative islands.
Compliance monitoring establishes whether the organisation conforms to applicable requirements and its own approved procedures. Safety management identifies hazards, assesses operational risk and monitors whether risk controls remain effective.
A matter can be compliant but still create unacceptable risk. Equally, an activity may appear operationally safe but fail to meet a mandatory regulatory requirement. An all-encompassing management system must consider both dimensions.
Integration should include:
• sharing relevant audit findings with the Safety Manager;
• assessing whether findings reveal hazards or ineffective risk controls;
• reviewing occurrence trends when planning audits;
• using safety data to target compliance-monitoring activity;
• incorporating regulatory changes into management of change;
• reviewing significant risks during compliance audits;
• considering audit results at Safety Action Group meetings;
• reporting both safety and compliance performance to the Safety Review Board or equivalent senior management forum; and
• providing the Accountable Manager with a combined picture of organisational performance.
For example, repeated unstable approaches are primarily a safety concern, but they may also indicate weaknesses in training, standard operating procedures, checking, supervision or data monitoring processes. These aspects should be examined through the compliance programme.
Similarly, a compliance finding concerning incomplete dangerous goods training may create an operational safety risk. The finding should therefore be managed through both the corrective-action process and, where appropriate, the safety risk-management process.
THE AUDITOR IS ALSO AN EDUCATOR
An aviation auditor is not merely an enforcement officer. A good auditor helps the organisation understand the purpose of a requirement and encourages managers and employees to recognise how compliance supports safe and effective operations.
This does not mean that the auditor should become responsible for solving the auditee’s problem or writing the corrective action on their behalf. The auditor must remain independent. However, the auditor can explain the requirement, identify the nature of the gap and help the auditee understand what effective compliance should achieve.
Auditing should improve organisational knowledge. When performed well, an audit becomes an opportunity to test processes, exchange experience, identify weaknesses and reinforce good practice.
The most effective auditors are firm on standards but constructive in their approach.
THE ETIQUETTE OF AVIATION AUDITING
Audit etiquette is essential. The way an audit is conducted can determine whether employees engage openly or become defensive.
Before the audit, the auditor should:
• provide reasonable notice unless an unannounced audit is justified;
• explain the scope, objectives and expected duration;
• identify the information and personnel required;
• understand the operational pressures affecting the department; and
• arrive prepared and familiar with the applicable requirements.
During the audit, the auditor should:
• conduct a clear opening meeting;
• remain professional, courteous and impartial;
• ask open questions and allow people to explain their processes;
• listen before reaching conclusions;
• distinguish between regulatory requirements, company procedures and personal preferences;
• avoid trying to catch people out;
• refrain from criticising employees in front of colleagues;
• protect confidential or sensitive information;
• verify facts before raising a finding;
• recognise effective practices as well as shortcomings; and
• minimise unnecessary disruption to the operation.
An auditor should never use intimidation, sarcasm or displays of superior knowledge. A finding should not be raised merely because the auditor would have designed a process differently. There must be a demonstrable failure to meet a requirement or an established organisational procedure.
Where a potential finding is identified, it should normally be discussed with the responsible manager before the closing meeting. This allows factual misunderstandings to be corrected and ensures that the final finding is accurate.
At the closing meeting, the auditor should clearly explain:
• the evidence examined;
• the positive aspects identified;
• each finding or observation;
• the requirement against which the finding has been raised;
• the expected corrective-action process;
• the applicable timescales; and
• the arrangements for follow-up and closure.
There should be no surprises in the final audit report.
INDEPENDENCE WITH A CONSTRUCTIVE PURPOSE
The Compliance Monitoring Manager must have sufficient independence and direct access to the Accountable Manager. That independence is essential, but it should be exercised constructively.
The compliance function exists to provide assurance, not to create an adversarial relationship with the operation. Its purpose is to identify areas in which the organisation may be exposed and to ensure that management has reliable information on which to act.
The best compliance systems are respected because they are consistent, evidence-based and fair. They challenge the organisation when necessary, but they also help departments understand what is required and why it matters.
COMPLIANCE MUST BE VISIBLE IN EVERYDAY OPERATIONS
An organisation is not compliant because its manuals say the right things. It is compliant when employees understand those manuals, follow the procedures and can produce evidence that the required activities have taken place.
A mature aviation management system will therefore demonstrate:
• systematic monitoring of regulatory publications;
• documented applicability assessments;
• timely implementation of regulatory changes;
• formal tracking of CZIBs and SIBs;
• evidence-based internal auditing;
• willingness to raise internal findings;
• effective root-cause analysis and corrective action;
• integration between compliance and safety management;
• constructive and professional audit behaviour; and
• active oversight by the Accountable Manager and senior leadership team.
Compliance should never be treated as a periodic exercise undertaken for the benefit of the aviation authority. It is a continuous organisational discipline.
When regulatory intelligence, auditing, safety risk management and management oversight work together, compliance becomes more than an obligation. It becomes an early-warning system—one that helps the organisation recognise weaknesses, control risk and protect the safety and integrity of its operation.
.png)





Comments