Part-IS Supplier Evidence: Review the Interface, Not Just the Certificate
Build a practical Part-IS supplier review note connecting a service, aviation safety interface, evidence, limitations and accountable review.
About this article: This information illustrates the potential benefits of Aviation.Bot’s upcoming regulatory library and desktop/web document-review features. It is not compliance guidance, legal advice or a basis for a regulatory, certification or operational decision. Examples demonstrate the workflow; verify applicable official sources and use qualified professional judgement for actual work.
A supplier sends a security certificate, a questionnaire and a polished incident-response policy. The procurement folder looks complete. Yet the operational question remains unanswered: if this service delivers incorrect information or becomes unavailable, what happens in your aviation operation, and who recognises the problem?
A useful supplier evidence review starts at that interface. It connects the service your organisation actually uses with the records needed to understand the arrangement. It does not turn a certificate into a finding that every aviation risk is controlled.
This article offers a practical review method and a fictional example. It is not an applicability assessment or a prescribed Part-IS checklist.
Workflow at a glance
Original workflow illustration. Candidate findings remain subject to qualified human review; the diagram does not establish an approval or compliance decision.
Define the service before requesting more documents
Write a short service description in operational language. “Cloud supplier” says little. “Provides the maintenance planning data exported into our scheduled-work preparation process” gives a reviewer a starting point. Identify the information transferred, receiving process, responsible internal role and dependencies.
Then separate two questions. Does the supplier provide a system or service with a relevant information-security interface? Is the organisation contracting information-security management activities? Those arrangements can overlap, but they should not be assumed identical. EASA's Part-IS.I.OR material addresses contracting information-security management activities under IS.I.OR.235. The linked Issue 1 material is a source reference, not a claim to be the current consolidated text: check the applicable edition and associated amendments before assessing an actual arrangement. EASA Part-IS.I.OR AMC/GM, Issue 1, official consolidated publication page.
Keep the review specific to one service. A vendor may provide several products with different contracts, responsibilities and evidence. Evidence for one product is not automatically evidence for another.
Ask what each attachment establishes
For every document, record its issuer, scope, version or period, and intended use in the review. A certificate can describe an assessed scope. A contract can allocate responsibilities. A test record can show what was exercised on one occasion. None should silently stand in for the others.
A reviewer should be able to answer: which part of our arrangement does this evidence support, and what remains unknown? If a document covers the supplier's corporate environment but does not identify the contracted service, record that limitation and ask for clarification. Do not fill the gap with an AI inference.
Worked example: an interface review note
The following artifact is entirely synthetic. The names, records and issues are invented to illustrate the method; they are not customer results or regulatory findings.
Review ID: SUP-EXAMPLE-07
Service: Meridian Planning export used by fictional Northbank Maintenance
Interface: nightly job-data export into work preparation
Internal owner: maintenance planning lead
Review question: how would staff detect an incomplete export?
Evidence inspected:
Service agreement v3, section 4: service boundary and support route
Supplier assurance response v2: backup process described
Internal import SOP v5: count reconciliation described
Unresolved:
Supplier response does not identify the contracted export service.
No authorised exercise record supplied for the reconciliation step.
Next action:
Owner requests service-specific clarification and locates a test record.
Decision status: open; no compliance conclusion recorded
This note does not require a large new spreadsheet. It gives a second reviewer enough information to find the evidence, repeat the question and understand why the record remains open. The next action concerns the missing link, rather than a request for every security document the supplier owns.
Keep communication and acceptance separate
A supplier response may resolve a factual uncertainty without resolving the organisation's risk decision. Record the response as new evidence, then let the responsible reviewer determine its effect. Preserve the original question so a later reader can see what changed.
Avoid labels such as “supplier compliant” when the review only covered one interface. A narrower conclusion might say that the service boundary is now documented, while the internal reconciliation evidence remains outstanding. Record the role that accepts the decision, the documents considered and any review trigger the organisation chooses. This is a working method, not a universal retention or review-period requirement.
Where source lookup and future workflows fit
Aviation.Bot’s upcoming regulatory library and desktop/web features are designed to support supplier evidence review like this. The starting libraries cover EASA, FAA, UK CAA, CAAC and Dutch IL&T across multiple document categories. The workflow lets a reviewer connect the relevant Part-IS passages with the selected supplier agreement, service description and internal risk records, then identify questions the evidence does not yet answer. Desktop users work with selected local folders and files; browser users upload selected documents to their workspace. Available sources and editions remain visible parts of the review rather than an assumed complete collection. This example remains tied to the identified Part-IS context.
The practical difference from a typical ChatGPT upload session is the aviation-specific source collection and repeatable document-review workflow: selected regulatory material sits alongside the organisation’s manuals, procedures and evidence, with references the reviewer can reopen. ChatGPT also supports file analysis; Aviation.Bot’s differentiation is how the source set and review task are organised, rather than a claim that general assistants cannot read documents.
Complex tables and forms deserve the same inspection as prose. The workflow is being developed to retain table relationships, headings, footnotes and form context, and to let the reviewer check the original page when extraction is uncertain. Reliable review depends on seeing that structure—not merely receiving a confident summary. Better accuracy, complete table fidelity and time savings require task-specific validation; they are not established by having a curated database.
For background, see the existing Part-IS evidence-readiness article and regulatory change-impact review. Those explain broader workflows; this article isolates the supplier/interface evidence problem. Some older posts describe demonstrations and should not be read as the current capability list.
Start with one supplier service and one review note. The useful result is a traceable question, evidence and decision trail that your responsible people can inspect.
Sign up on Aviation.Bot to stay up to date about upcoming releases.
Prepared with AI assistance and editorial checks against linked official sources. Illustrative examples do not represent authority or independent expert approval.