Navigate / EASA

GM1 27.1302 Explanatory material

ED Decision 2021/010/R

1       Introduction

(a)      Accidents most often result from a sequence or combination of different errors and safety-related events (e.g. equipment failures and weather conditions). Analyses show that the design of the cockpit and other systems can influence the crew’s task performance and the occurrence and effects of some crew member errors.

(b)     Crew members make a positive contribution to the safety of the aviation system because of their ability to continuously assess changing conditions and situations, analyse potential actions, and make reasoned decisions. However, even well-trained, qualified, healthy, alert crew members make errors. Some of these errors may be induced or influenced by the designs of the systems and their crew interfaces, even with those that are carefully designed. Most of these errors have no significant safety effects, or are detected and mitigated in the normal course of events. However, some of them may lead or contribute to the occurrence of unsafe conditions. Accident analyses have identified crew member performance and errors as recurrent factors in the majority of accidents involving rotorcraft.

(c)      Some current requirements are intended to improve safety by requiring the cockpit and its equipment to be designed with certain capabilities and characteristics. The approval of cockpit systems with respect to design-related crew member error has typically been addressed by referring to system-specific or general applicability requirements, such as CS 27.1301(a), CS 27.771(a), and CS 27.1523. However, little or no guidance exists to show how the applicant may address potential crew member limitations and errors. That is why CS 27.1302 and this guidance material have been developed.

(d)     CS 27.1302 was developed to provide a basis for addressing the design-related aspects of the avoidance and management of crew member errors by taking the following approach.

(i)      Firstly, by providing means to address the design characteristics that are known to reduce or avoid crew member error and that address crew member capabilities and limitations. CS 27.1302 (a) to (c) are intended to reduce the design contribution to such errors by ensuring that the information and controls needed by the crew members to perform the tasks associated with the intended function of installed equipment are provided, and that they are provided in a usable form.

In addition, operationally relevant system behaviour must be understandable, predictable, and supportive of the crew’s tasks. Guidance is provided in this paragraph on the avoidance of design-induced crew member errors.

(ii)     Secondly, CS 27.1302(d) addresses the fact that since crew member errors will occur, even with a well‑trained and proficient crew operating well-designed systems, the design must support the management of those errors to avoid any safety consequences.

Paragraph 5.7 below on crew member error management provides the relevant guidance.

(e)     EASA would like to bring the applicants’ attention to the fact that the implementation of the CS 27.1302 process may require up to several years, depending on the characteristics of the project. However, STCs may require much less time.

2       CS 27.1302: applicability and explanatory material

(a)      CS-27contains certification specifications for the design of cockpit equipment that is system specific (refer to AMC 27.1302, Table 1, in paragraph 2), generally applicable (e.g. CS 27.1301(a), CS 27.771(a)), and establishes minimum crew requirements (e.g. CS 27.1523). CS 27.1302 complements the generally applicable requirements by adding more explicit objectives for the design attributes related to the avoidance and management of crew member errors. Other ways to avoid and manage crew member errors are regulated through the requirements governing the licensing and qualifications of crew members and rotorcraft operations. Taken together, these complementary approaches provide an adequate level of safety.

(b)     The complementary approach is important. It is based upon the recognition that equipment design, training/licensing/qualifications and operations/procedures each provide safety contributions to risk mitigation. An appropriate balance is needed between them. There have been cases in the past where design characteristics known to contribute to crew member errors were accepted based upon the rationale that training or procedures would mitigate that risk. We now know that this can often be an inappropriate approach. Similarly, due to unintended consequences, it would not be appropriate to require equipment design to provide total risk mitigation.

(c)      A proper balance is needed between certification specifications in CS-27and the requirements for training/licensing/qualifications and operations/procedures. CS 27.1302 and this GM were developed with the intent of achieving that appropriate balance.

(1)     Introduction. The introductory sentence of CS 27.1302 states that ‘this paragraph applies to installed systems and equipment intended to be used by the crew members when operating the rotorcraft from their normal seating positions in the cockpit or their operating positions in the cabin’.

(i)      ‘Intended to be used by the crew members when operating the rotorcraft from their normal seating positions in the cockpit or their operating positions in the cabin’ means that the intended function of the installed equipment includes its use by the crew members when operating the rotorcraft. An example of such installed equipment would be a display that provides information enabling the crew to navigate. The term ‘crew members’ is intended to include any or all individuals comprising the minimum crew as determined for compliance with CS 27.1523. The phrase ‘from their normal seating positions in the cockpit’ means that the crew members are seated at their normal duty stations for operating the rotorcraft.

(ii)     The phrase ‘from their normal seating positions in the cockpit or their operating positions in the cabin’ means that the crew members are positioned at their normal duty stations in the cabin. These phrases are intended to limit the scope of this requirement so that it does not address the systems or equipment that are/is not used by the crew members while performing their duties in operating the rotorcraft in normal, abnormal/malfunction and emergency conditions. For example, this paragraph is not intended to apply to design items such as certain circuit breakers or maintenance controls intended for use by the maintenance crew (or by the crew when not operating the rotorcraft).

(iii)     The phrase ‘The installed systems and equipment must be shown […]’ in the first paragraph means that the applicant must provide sufficient evidence to support compliance determinations for each of the CS 27.1302 objectives. This is not intended to require a demonstration of compliance beyond that required by point 21.A.21(a) of Part 21. Accordingly, for simple design items or items similar to previously approved equipment and installations, the demonstrations, assessments or data needed to demonstrate compliance with CS 27.1302 are not expected to entail more extensive or onerous efforts than are necessary to demonstrate compliance with the previous requirements. 

(iv)     The phrase ‘individually and in combination with other such equipment’ means that the objectives of this paragraph must be met when equipment is installed in the cockpit with other equipment. The installed equipment must not prevent other equipment from complying with these objectives. For example, applicants must not design a display so that the information it provides is inconsistent or is in conflict with information provided from other installed equipment.

(v)     In addition, this paragraph presumes a qualified crew member that is trained to use the installed equipment. This means that the design must meet these objectives for crew members who are allowed to fly the rotorcraft by meeting the qualification requirements of the operating rules. If the applicant seeks a type design or supplemental type design approval before a training programme is accepted, the applicant should document any novel, complex or highly integrated design items and assumptions made during the design phase that have the potential to affect the training time or the crew member procedures. The certification specification and associated material are written assuming that either these design items and assumptions or the knowledge of a training programme (proposed or in the process of being developed) will be coordinated with the appropriate operational approval organisation when assessing the adequacy of the design.

(vi)     The objective for the equipment to be designed so that the crew members can safely perform their tasks associated with the intended function of the equipment applies in normal, abnormal/malfunction and emergency conditions. The tasks intended to be performed under all the above conditions are generally those prescribed by the crew member procedures. The phrase ‘safely perform their tasks’ is intended to describe one of the safety objectives of this certification specification. The objective is for the equipment design to enable the crew members to perform their tasks with sufficient accuracy and in a timely manner, without unduly interfering with their other required tasks. The phrase ‘tasks associated with its intended function’ is intended to characterise either the tasks required to operate the equipment or the tasks for which the intended function of the equipment provides support.

(2)     CS 27.1302(a) requires the applicant to install the appropriate controls and provide the necessary information for any cockpit equipment identified in the first paragraph of CS 27.1302. The controls and the information displays must be sufficient to allow the crew members to accomplish their tasks. Although this may seem obvious, this objective is included because a review of CS-27 on the subject of HFs revealed that a specific objective for cockpit controls and information to meet the crew member needs is necessary. This objective is not reflected in other parts of the rules, so it is important to be explicit.

(3)     CS 27.1302(b) addresses the objective for cockpit controls and information that are/is necessary and appropriate for the crew members to accomplish their tasks, as determined in (a) above. The intent is to ensure that the design of the controls and information devices makes them usable by the crew members. This subparagraph seeks to reduce design‑induced crew member errors by imposing design objectives for cockpit information presentation and controls. Subparagraphs (1) through (3) specify these design objectives. The design objectives for information and controls are necessary to:

(i)      properly support the crew members in planning their tasks;

(ii)     make available to the crew members appropriate, effective means to carry out planned actions; and

(iii)     enable the crew members to have appropriate feedback information about the effects of their actions on the rotorcraft.

(4)     CS 27.1302(b)(1) specifically requires controls and information to be designed in a clear and unambiguous form, at a resolution and precision appropriate to the task.

(i)      As applied to information, ‘clear and unambiguous’ means that it can be perceived correctly (is legible) and can be comprehended in the context of the crew member tasks associated with the intended functions of the equipment, such that the crew members can perform all the associated tasks.

(ii)     For controls, the objective for ‘clear and unambiguous’ presentation means that the crew members must be able to use them appropriately to achieve the intended functions of the equipment. The general intent is to foster the design of equipment controls whose operation is intuitive, consistent with the effects on the parameters or states that they affect, and compatible with the operation of the other controls in the cockpit.

(iii)     CS 27.1302(b)(1) also requires the information or control to be provided, or to operate, at a level of detail and accuracy appropriate for accomplishing the task. Insufficient resolution or precision would mean the crew members could not perform the task adequately. Conversely, excessive resolution has the potential to make a task too difficult because of poor readability or the implication that the task should be accomplished more precisely than is actually necessary.

(5)     CS 27.1302(b)(2) requires controls and information to be accessible and usable by the crew members in a manner appropriate to the urgency, frequency, and duration of their tasks. For example, controls that are used more frequently or urgently must be readily accessible, or require fewer steps or actions to perform the task. Less accessible controls may be acceptable if they are needed less frequently or less urgently. Controls that are used less frequently or less urgently should not interfere with those used more urgently or more frequently. Similarly, tasks requiring a longer time for interaction should not interfere with the accessibility to information required for urgent or frequent tasks.

(6)     CS 27.1302(b)(3) requires equipment to present information that makes the crew members aware of the effects of their actions on the rotorcraft or systems, if that awareness is required for the safe operation of the rotorcraft. The intent is for the crew members to be aware of the system or rotorcraft states resulting from crew actions, permitting them to detect and correct their own errors. This subparagraph is included because new technology enables new kinds of crew member interfaces that previous objectives did not address. Specific deficiencies of existing objectives in addressing HFs are described below:

(i)      CS 27.771(a) addresses this topic for controls, but does not include criteria for the presentation of information;

(ii)     CS 27.777(a) addresses controls, but only their location;

(iii)     CS 27.777(b) and CS 27.779 address the direction of motion and actuation but do not encompass new types of controls, such as cursor-control devices. These requirements also do not encompass types of control interfaces that can be incorporated into displays via menus, for example, thus affecting their accessibility;

(iv)     CS 27.1523 has a different context and purpose (determining the minimum crew), so it does not address these requirements in a sufficiently general way.

(7)     CS 27.1302(c) requires installed equipment to be designed so that its behaviour that is operationally relevant to crew member tasks is:

(i)      predictable and unambiguous, and

(ii)     designed to enable the crew members to intervene in a manner appropriate to the task (and intended function).

Other related considerations are the following:

(iii)     Improved cockpit technologies involving integrated and complex information and control systems have increased safety and performance. However, they have also introduced the need to ensure proper interactions between the crew and those systems. In-service experience has shown that some equipment behaviour (especially from automated systems) is excessively complex or dependent upon logical states or mode transitions that are not well understood or expected by the crew members. Such design characteristics can confuse the crew members and have been determined to contribute to incidents and accidents.

(8)     CS 27.1302(c)(1) requires the behaviour of a system to be such that a qualified crew member knows what the system is doing and why it is doing it. It requires operationally relevant system behaviour to be ‘predictable and unambiguous’. This means that a crew can retain enough information about what their action or a changing situation will cause the system to do under foreseeable circumstances, so they can operate the system safely.

The behaviour of a system must be unambiguous because the actions of the crew may have different effects on the rotorcraft, depending on its current state or operational circumstances.

(9)     CS 27.1302(c)(2) requires the design to be such that the crew members will be able to take some action, or change or alter an input to the system, in a manner appropriate to the task.

(10)   CS 27.1302(d) addresses the reality that even well-trained, proficient crews using well‑designed systems will make errors. It requires the equipment to be designed such in order to enable the crew members to manage such errors. For the purpose of this CS, errors ‘resulting from crew interaction with the equipment’ are those errors that are in some way attributable, or related, to the design of the controls, the behaviour of the equipment, or the information presented. Examples of designs or information that could cause errors are indications and controls that are complex and inconsistent with each other or with other systems on the cockpit. Another example is a procedure that is inconsistent with the design of the equipment. Such errors are considered to be within the scope of this CS and the related AMC.

(i)      What is meant by a design which enables the crew members to ‘manage errors’ is that:

(A)     the crew members must be able to detect and/or recover from errors resulting from their interaction with the equipment; or

(B)     the effects of such crew member errors on the rotorcraft functions or capabilities must be evident to the crew members, and continued safe flight and landing must be possible; or

(C)     crew member errors must be prevented by switch guards, interlocks, confirmation actions, or other effective means; or

(D)     the effects of errors must be precluded by system logic or redundant, robust, or fault-tolerant system design.

(ii)     The objective to manage errors applies to those errors that can be reasonably expected in service from qualified and trained crews. The term ‘reasonably expected in service’ means errors that have occurred in service with similar or comparable equipment. It also means errors that can be predicted to occur based on general experience and knowledge of human performance capabilities and limitations related to the use of the type of controls, information, or system logic being assessed.

(iii)     CS 27.1302(d) includes the following statement: ‘This subparagraph does not apply to skill-related errors associated with the manual control of the rotorcraft.’

That statement is intended to exclude errors resulting from the crew’s proficiency in the control of the flight path and attitude with the primary roll, pitch, yaw and thrust controls, and which are related to the design of the flight control systems. These issues are considered to be adequately addressed by the existing certification specifications, such as CS-27 Subpart B and CS 27.671(a). It is not intended that the design should be required to compensate for deficiencies in crew training or experience. This assumes at least the minimum crew requirements for the intended operation, as discussed at the beginning of paragraph 5.1 above.

(iv)     This objective is intended to exclude the management of errors resulting from crew member decisions, acts or omissions that are not in good faith. It is intended to avoid imposing requirements on the design to accommodate errors committed with malicious or purely contrary intent. CS 27.1302 is not intended to require applicants to consider errors resulting from acts of violence or threats of violence.

This ‘good faith’ exclusion is also intended to avoid imposing requirements on designs to accommodate errors due to a crew member’s obvious disregard for safety. However, it is recognised that errors committed intentionally may still be in good faith, but could be influenced by the characteristics of the design under certain circumstances. An example would be a poorly designed procedure that is not compatible with the controls or information provided to the crew members.

Imposing requirements without considering their economic feasibility or the commensurate safety benefits should be avoided. Operational practicability should also be addressed, such as the need to avoid introducing error management features into the design that would inappropriately impede crew actions or decisions in normal, abnormal/malfunction and emergency conditions. For example, it is not intended to require so many guards or interlocks on the means to shut down an engine that the crew members would be unable to do this reliably within the available time. Similarly, it is not intended to reduce the authority or means for the crew to intervene or carry out an action when it is their responsibility to do so using their best judgment in good faith.

This subparagraph is included because managing errors (which can be reasonably expected in service) that result from crew member interactions with the equipment is an important safety objective. Even though the scope of applicability of this material is limited to errors for which there is a contribution from or a relationship to the design, CS 27.1302(d) is expected to result in design changes that will contribute to safety. One example, among others, would be the use of ‘undo’ functions in certain designs.

[Amdt 27/8]