Navigate / EASA
GM1 21L.B.23(b) Airworthiness directives

ED Decision 2023/013/R

DETERMINATION OF AN UNSAFE CONDITION

It is important to note that these guidelines are not exhaustive. However, this material is intended to provide guidelines and examples that will cover most cases, taking into account the applicable certification requirements or technical specifications.

1. INTRODUCTION

The certification, approval or declaration of a product is a demonstration of compliance with the applicable requirements which are intended to ensure an acceptable level of safety. This demonstration, however, includes certain accepted assumptions and predicted behaviours, such as:

— fatigue behaviour is based on analysis supported by test;

— modelling techniques are used for aircraft flight manual (AFM) performance calculations;

— the systems’ safety analyses give predictions of what the systems’ failure modes, effects and probabilities may be;

— the system components’ reliability figures are predicted values derived from general experience, tests or analyses;

— the crew is expected to have the skills to apply the procedures correctly; and

— the aircraft is assumed to be maintained in accordance with the prescribed instructions for continued airworthiness (ICAs) (or maintenance programme).

In-service experience, additional testing, further analysis, etc., may show that certain initially accepted assumptions are not correct. Thus, certain conditions initially demonstrated as safe, are revealed by experience as unsafe. In this case, it is necessary to mandate corrective actions in order to restore a level of safety consistent with the applicable certification requirements or technical specifications.

To support the determination of an unsafe condition, the investigation may need to include examinations of worn, damaged and time-expired parts / analysis / demonstrations / tests / statistical analysis, and comparison with the design assumptions.

See AMC1 21L.B.23(b) for the definition of ‘unsafe condition’ used in point 21L.A.3(a)(3) and (b)(3).

2. GUIDELINES FOR ESTABLISHING WHETHER A CONDITION IS UNSAFE

The following points give general guidelines for analysing the reported events and determining whether an unsafe condition exists, and are provided for each type of product subject to a specific airworthiness approval (type certificates (TCs) or supplemental type certificates (STCs)) for aircraft, engines or propellers or a declaration of design compliance for an aircraft.

This analysis may be qualitative or quantitative, i.e. formal and quantitative safety analyses may not be available. In such cases, the level of analysis should be consistent with that required by the certification specifications or technical specifications and may be based on engineering judgement supported by in-service experience data.

2.1 Analysis method for aircraft

2.1.1 Accidents or incidents without any aircraft, engine, system, propeller or part malfunction or failure

When an accident/incident does not involve any component malfunction or failure but when a human factor of the crew has been a contributing factor, this should be assessed from a man–machine interface standpoint to determine whether the design is adequate or not. Point 2.5 gives further details on this aspect.

2.1.2 Events involving an aircraft, engine, system, propeller or part failure, malfunction or defect

The general approach for analysis of in-service events caused by malfunctions, failures or defects will be to analyse the actual failure effects, taking into account previously unforeseen failure modes or improper or unforeseen operating conditions revealed by in-service experience.

These events may have occurred in service, or have been identified during maintenance, or have been identified as a result of subsequent tests, analyses or quality control.

They may result from a design or production deficiency (non-conformity with the applicable design data), or from improper maintenance. In this case, it should be determined whether improper maintenance is limited to one aircraft, in which case an airworthiness directive may not be issued, or if it is likely to be a general problem due to improper design and/or maintenance procedures, as detailed in point 2.5.

2.1.2.1 Flight

An unsafe condition exists if:

— there is a significant shortfall of the actual performance compared to the approved or declared performance (taking into account the accuracy of the performance calculation method); or

— the handling qualities, although having been found to comply with the applicable certification specifications at the time of initial approval or declared as being compliant with the applicable technical specifications, are subsequently shown by in-service experience not to comply.

2.1.2.2 Structural or mechanical systems

An unsafe condition exists if the deficiency may lead to a structural or mechanical failure which could exist in a principal structural element. Principal structural elements are those which contribute significantly to carrying flight, ground, and pressurisation loads, and whose failure could result in a catastrophic failure of the aircraft.

They could reduce the structural stiffness to such an extent that the required flutter, divergence or control reversal margins are no longer achieved.

They could result in the loss of a structural piece that could damage vital parts of the aircraft, cause serious or fatal injuries to persons other than occupants.

They could, under ultimate load conditions, result in the liberation of items of mass that may injure the aircraft occupants.

They could jeopardise the proper operation of systems and may lead to hazardous or catastrophic consequences, if this effect has not been taken adequately into account in the initial certification safety assessment.

2.1.2.3 Systems

The consequences of reported system components’ malfunctions, failures or defects should be analysed.

For this analysis, the certification or design data may be used as supporting material, in particular systems’ safety analyses (if applicable).

The general approach for analysis of in-service events caused by systems’ malfunctions, failures or defects will be to analyse the actual failure effects.

As a result of this analysis, an unsafe condition will be assumed if it cannot be shown that the safety objectives for hazardous and catastrophic failure conditions are still achieved, taking into account the actual failure modes and rates of the components affected by the reported deficiency.

The failure probability of a system component may be affected by:

— a design deficiency (the design does not meet the specified reliability or performance);

— a production deficiency (non-conformity with the certified type design or declared design data) that affects either all components, or a certain batch of components;

— improper installation (for instance, insufficient clearance of pipes to surrounding structure);

— susceptibility to adverse environment (corrosion, moisture, temperature, vibrations etc.);

— ageing effects (component failure rate increases when the component ages);

— improper maintenance.

When the failure of a component is not immediately detectable (hidden or latent failures), it is often difficult to have a reasonably accurate estimation of the component failure rate since the only data available are usually results of maintenance or flight crew checks. This failure probability should, therefore, be conservatively assessed.

As it is difficult to justify that the safety objectives for the following systems are still met, a deficiency that affect these types of systems may often lead to a mandatory corrective action:

— backup emergency systems; or

— fire detection and protection systems (including shut-off means).

Deficiencies that affect the systems used during an emergency evacuation (emergency exits, evacuation assist means, emergency lighting system, etc.) and to locate the site of a crash (emergency locator transmitter (ELT)) will also often lead to mandatory corrective action.

2.1.2.4 Others

In addition to the above, the following conditions are considered unsafe:

— There is a deficiency in certain components which are involved in fire protection or which are intended to minimise/retard the effects of fire/smoke in a survivable crash, preventing them to perform their intended function (for instance, deficiency in cargo liners or cabin material leading to non-compliance with the applicable flammability requirements).

— There is a deficiency in the lightning or the high-intensity radiated field (HIRF) protection of a system which may lead to hazardous or catastrophic failure conditions.

— There is a deficiency which could lead to a total loss of power or thrust due to common mode failure.

2.2 Engines

The consequences and probabilities of engine failures should be assessed at the aircraft level in accordance with point 2.1, and also at the engine level for those failures considered as 'hazardous’ in CS E‑510, CS E‑210, CS‑22 Subpart H or the applicable technical specifications.

The latter will be assumed to constitute unsafe conditions, unless it can be shown that the consequences at the aircraft level do not constitute an unsafe condition for a particular aircraft installation.

2.3 Propellers

The consequences and probabilities of propeller failures should be assessed at the aircraft level in accordance with point 2.1, and also at the propeller level for those failures considered as ‘hazardous’ in CS P‑150, CS‑22 Subpart J or the applicable technical specifications.

The latter will be assumed to constitute unsafe conditions, unless it can be shown that the consequences at the aircraft level do not constitute an unsafe condition for a particular aircraft installation.

2.4 Parts

The consequences and probabilities of equipment failures should be assessed at the aircraft level in accordance with point 2.1.

2.5 Human-factors aspects in establishing and correcting unsafe conditions

This point provides guidance on the way to treat an unsafe condition that results from a maintenance or crew error observed in service.

It is recognised that human-factors techniques are under development. However, the following is a preliminary guidance on the subject.

Systematic review should be used to assess whether the crew or maintenance error raises issues that require regulatory action (whether in design or other areas) or should be noted as an isolated event without intervention. This may need the establishment of a multidisciplinary team (designers, crews, human-factors experts, maintenance experts, aircraft operators, etc.).

The assessment should include at least the following:

— Characteristics of the design intended to prevent or discourage incorrect assembly or operation.

— Characteristics of the design that allow or facilitate incorrect operation.

— Unique characteristics of a design feature differing from established design practices.

— The presence of indications or feedback that alerts the operator to an erroneous condition.

— The existence of similar previous events, and whether or not they resulted (on those occasions) in unsafe conditions.

— Complexity of the system, associated procedures and training (has the crew a good understanding of the system and its logic after a standard crew qualification programme?).

— Clarity/accuracy/availability/currency and practical applicability of manuals and procedures.

— Any issues arising from interactions among personnel, such as shift changeover, dual inspections, team operations, supervision (or lack of it), or fatigue.

Apart from a design change, the corrective actions, if found necessary, may consist of modifications of the manuals, inspections, training programmes, and/or information to the operators about particular design features. The Agency may decide to make mandatory such corrective action if necessary.