Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
ARO.GEN.205 Allocation of tasks
Available versions for ERULES-1963177438-11741
Regulation (EU) 2023/203
found in: Air Operations (965/2012) Part-ARO Part-ORO Part-CAT Part-SPA Part-NCC Part-NCO Part-SPO (Sep 2023)
From
Air Operations Rev... (Mar 2026)
Air Operations (96... (Feb 2025)
Air Operations (96... (Sep 2023)
From section
To
Air Operations Rev... (Mar 2026)
Air Operations (96... (Feb 2025)
Air Operations (96... (Sep 2023)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
ARO.GEN.205 Allocation of tasks to qualified entities Regulation (EU) 2023/203 *[applicable until 21 February 2026 — Regulation (EU) No 379/2014*] ARO.GEN.205 Allocation of tasks *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]* (a) Tasks related to the initial certification, specialised operation authorisation or continuing oversight of persons or organisations subject to Regulation (EC) No 216/2008 and its Implementing Rules shall be allocated by Member States only to qualified entities. When allocating tasks, the competent authority shall ensure that it has: (1) put a system in place to initially and continuously assess that the qualified entity complies with Annex V to Regulation (EC) No 216/2008. This system and the results of the assessments shall be documented. (2) established a documented agreement with the qualified entity, approved by both parties at the appropriate management level, which clearly defines: (i) the tasks to be performed; (ii) the declarations, reports and records to be provided; (iii) the technical conditions to be met in performing such tasks; (iv) the related liability coverage; and (v) the protection given to information acquired in carrying out such tasks. (b) The competent authority shall ensure that the internal audit process and safety risk management process required by [ARO.GEN.200(a)(4)](#_DxCrossRefBm318085157) covers all certification, authorisation or continuing oversight tasks performed on its behalf. (c) For the certification and oversight of the organisation’s compliance with point [ORO.GEN.200A](#_DxCrossRefBm318085177), the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point [ARO.GEN.200(e)](#_DxCrossRefBm318085157) covers all the certification and continuing oversight tasks performed on its behalf. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*
ARO.GEN.205 Allocation of tasks to qualified entities Regulation (EU) 2023/203 *[applicable until 21 February 2026 — Regulation (EU) No 379/2014*] ARO.GEN.205 Allocation of tasks *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]* (a) Tasks related to the initial certification, specialised operation authorisation or continuing oversight of persons or organisations subject to Regulation (EC) No 216/2008 and its Implementing Rules shall be allocated by Member States only to qualified entities. When allocating tasks, the competent authority shall ensure that it has: (1) put a system in place to initially and continuously assess that the qualified entity complies with Annex V to Regulation (EC) No 216/2008. This system and the results of the assessments shall be documented. (2) established a documented agreement with the qualified entity, approved by both parties at the appropriate management level, which clearly defines: (i) the tasks to be performed; (ii) the declarations, reports and records to be provided; (iii) the technical conditions to be met in performing such tasks; (iv) the related liability coverage; and (v) the protection given to information acquired in carrying out such tasks. (b) The competent authority shall ensure that the internal audit process and safety risk management process required by [ARO.GEN.200(a)(4)](#_DxCrossRefBm927677521) covers all certification, authorisation or continuing oversight tasks performed on its behalf. (c) For the certification and oversight of the organisation’s compliance with point [ORO.GEN.200A](#_DxCrossRefBm927677541), the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point [ARO.GEN.200(e)](#_DxCrossRefBm927677521) covers all the certification and continuing oversight tasks performed on its behalf. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*
#### ARO.GEN.205 Allocation of tasks *Regulation (EU) 2023/203* (a) Tasks related to the initial certification, specialised operation authorisation or continuing oversight of persons or organisations subject to [Regulation (EC) No 216/2008](https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1474978980580&uri=CELEX%3A32008R0216) and its Implementing Rules shall be allocated by Member States only to qualified entities. When allocating tasks, the competent authority shall ensure that it has: (1) put a system in place to initially and continuously assess that the qualified entity complies with Annex V to [Regulation (EC) No 216/2008](https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1474978980580&uri=CELEX%3A32008R0216). This system and the results of the assessments shall be documented. (2) established a documented agreement with the qualified entity, approved by both parties at the appropriate management level, which clearly defines: (i) the tasks to be performed; (ii) the declarations, reports and records to be provided; (iii) the technical conditions to be met in performing such tasks; (iv) the related liability coverage; and (v) the protection given to information acquired in carrying out such tasks. (b) The competent authority shall ensure that the internal audit process and safety risk management process required by [ARO.GEN.200(a)(4)](#_DxCrossRefBm523087030) covers all certification, authorisation or continuing oversight tasks performed on its behalf. (c) For the certification and oversight of the organisation’s compliance with point [ORO.GEN.200A](#_DxCrossRefBm523087050), the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point [ARO.GEN.200(e)](#_DxCrossRefBm523087030) covers all the certification and continuing oversight tasks performed on its behalf.