Navigate / EASA
AMC1 ORA.GEN.200(a)(3) Management system

ED Decision 2012/007/R

COMPLEX ORGANISATIONS - SAFETY RISK MANAGEMENT

(a) Hazard identification processes

(1) Reactive and proactive schemes for hazard identification should be the formal means of collecting, recording, analysing, acting on and generating feedback about hazards and the associated risks that affect the safety of the operational activities of the organisation.

(2) All reporting systems, including confidential reporting schemes, should include an effective feedback process.

(b) Risk assessment and mitigation processes

(1) A formal risk management process should be developed and maintained that ensures analysis (in terms of likelihood and severity of occurrence), assessment (in terms of tolerability) and control (in terms of mitigation) of risks to an acceptable level.

(2) The levels of management who have the authority to make decisions regarding the tolerability of safety risks, in accordance with (b)(1), should be specified.

(c) Internal safety investigation

(1) The scope of internal safety investigations should extend beyond the scope of occurrences required to be reported to the competent authority.

(d) Safety performance monitoring and measurement

(1) Safety performance monitoring and measurement should be the process by which the safety performance of the organisation is verified in comparison to the safety policy and objectives.

(2) This process should include:

(i) safety reporting;

(ii) safety studies, that is, rather large analyses encompassing broad safety concerns;

(iii) safety reviews including trends reviews, which would be conducted during introduction and deployment of new technologies, change or implementation of procedures, or in situations of structural change in operations;

(iv) safety audits focussing on the integrity of the organisation’s management system, and periodically assessing the status of safety risk controls; and

(v) safety surveys, examining particular elements or procedures of a specific operation, such as problem areas or bottlenecks in daily operations, perceptions and opinions of operational personnel and areas of dissent or confusion.

(e) The management of change

The organisation should manage safety risks related to a change. The management of change should be a documented process to identify external and internal change that may have an adverse effect on safety. It should make use of the organisation’s existing hazard identification, risk assessment and mitigation processes.

(f) Continuous improvement

The organisation should continuously seek to improve its safety performance. Continuous improvement should be achieved through:

(1) proactive and reactive evaluations of facilities, equipment, documentation and procedures through safety audits and surveys;

(2) proactive evaluation of individuals’ performance to verify the fulfilment of their safety responsibilities; and

(3) reactive evaluations in order to verify the effectiveness of the system for control and mitigation of risk.

(g) The emergency response plan (ERP)

(1) An ERP should be established that provides the actions to be taken by the organisation or specified individuals in an emergency. The ERP should reflect the size, nature and complexity of the activities performed by the organisation.

(2) The ERP should ensure:

(i) an orderly and safe transition from normal to emergency operations;

(ii) safe continuation of operations or return to normal operations as soon as practicable; and

(iii) coordination with the emergency response plans of other organisations, where appropriate.