Navigate / EASA

GM10 Article 15(1) Conditions for obtaining a certificate

ED Decision 2022/022/R

APPROACH TO CERTIFICATION

Based on the presentation of the applicant’s CONOPS, strategy for certification, and the associated set of data and evidence, the competent authority defines the scope and depth of the certification investigations and selects the documents, set of data, and activities (e.g. onboarding process, software development, tests, change management procedures, etc.) to be assessed.

The competent authority’s investigation comprises two main types of investigation:

(a)     Desktop reviews: mostly dedicated to documentation reviews performed remotely, without visiting the applicant’s facilities.

(b)     Audits: to perform an in-depth and comprehensive assessment/inspection of the applicant’s organisation, activities, processes, and evidence. Depending on whether or not a physical inspection is necessary, audits may be performed on-site or remotely considering, for example, the efficiency of the access and the assessment of the items subject to investigation, and access to personnel in charge of the applicant’s activities.