Navigate / EASA
AMC1 CAMO.B.200(a)(5) Management system

ED Decision 2020/002/R

SAFETY RISK MANAGEMENT PROCESS

(a) The safety risk management process required by point CAMO.B.200 should be documented. The following should be defined in the related documentation:

(1) means for hazard identification, and the related data sources, taking into account data that comes from other competent authorities with which the competent authority interfaces in the State, or from the competent authorities of other Member States;

(2) risk management steps including:

(i) analysis (in terms of the probability and the severity of the consequences of hazards and occurrences);

(ii) assessment (in terms of tolerability); and

(iii) control (in terms of mitigation) of risks to an acceptable level;

(3) who holds the responsibilities for hazard identification and risk management;

(4) who holds the responsibilities for the follow-up of risk mitigation actions;

(5) the levels of management who have the authority to make decisions regarding the tolerability of risks;

(6) means to assess the effectiveness of risk mitigation actions; and

(7) the link with the compliance monitoring function.

(b) To demonstrate that the safety risk management process is operational, competent authorities should be able to provide evidence that:

(1) the persons involved in internal safety risk management activities are properly trained;

(2) hazards that could impact the authority’s capabilities to perform its tasks and discharge its responsibilities have been identified and the related risk assessment is documented;

(3) regular meetings take place at appropriate levels of management of the competent authority to discuss the risks identified, and to decide on the tolerability of risks and possible risk mitigations;

(4) in addition to the initial hazard identification exercise, the risk management process is triggered as a minimum whenever changes occur that may affect the competent authority’s capability to perform any of the tasks required by Part-CAMO;

(5) a record of the actions taken to mitigate risks is maintained, showing the status of each action and the owner of the action;

(6) there is a follow-up on the implementation of all risk mitigation actions;

(7) risk mitigation actions are assessed for their effectiveness; and

(8) the results of risk assessments are periodically reviewed to check whether they remain relevant. (Are the assumptions still valid? Is there new information?).