Navigate / EASA

AMC1 BOP.ADD.030(a)(6) Management system

ED Decision 2018/004/R

COMPLIANCE MONITORING — AUDIT AND ORGANISATIONAL REVIEW

(a)     Methodology

(1)     The operator should accomplish the compliance monitoring by means of internal auditing.

(2)     Notwithstanding (1), an operator with five or less full-time equivalents (FTEs), involved in the activity subject to this Subpart, may choose to accomplish compliance monitoring through an organisational review.

(b)     General provisions for compliance monitoring

(1)     The operator should specify the basic structure of the compliance monitoring function applicable to the activities conducted.

(2)     The operator should ensure that personnel performing an audit or an organisational review, either internal to the operator or external, have relevant knowledge, background and experience as appropriate to the activities being audited or reviewed, including knowledge and experience in compliance monitoring.

(3)     The operator should monitor compliance with the procedures it has designed to ensure safe activities. In doing so, the operator should as a minimum, and where appropriate, monitor compliance with:

(i)      all activities for which the declaration is required;

(ii)     manuals, logs and records;

(iii)     training standards;

(iv)     management system procedures; and

(v)      standard operating procedures (SOPs).

(4)     The operator should ensure that the status of all corrective and preventive actions is monitored and that these actions are implemented within a specified time frame. Action closure should be recorded along with a summary of the action taken.

(5)     Based on the results of the audit or the organisational review, the accountable manager should determine the need for and initiate, as appropriate, further actions to address deficiencies or to further improve the operator’s management system.

(c)      Provisions, in addition to (b), for auditing

(1)     The independence of the audit function should be ensured, in particular in cases where those performing the audit are also responsible for other functions for the operator.

(2)     The operator should establish a compliance monitoring programme, defining a calendar for the audits to be performed. The frequency and depth of such audits should be determined with due regard to:

(i)      the volume and complexity of operations;

(ii)     results of the safety risk management processes;

(iii)     results of past compliance monitoring;

(iv)     findings raised by the competent authority; and

(v)      the scope of changes not requiring prior competent authority approval.

(d)     Provisions, in addition to (b), for the organisational review

(1)     The organisational review should be performed at intervals not exceeding 12 months.

(2)     As part of the management system documentation, the operator should describe the organisational review programme and related responsibilities.

(3)     The organisational review programme may consist of:

(i)      checklist(s) covering all items necessary to be addressed in order to demonstrate that the operator ensures effective compliance with the applicable requirements; and

(ii)     a schedule for the accomplishment of the different checklist items, where each item should be checked at least at intervals not exceeding 12 months.