Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
ATM/ANS.EQMT.AR.A.020 Allocation of tasks to qualified entities
Available versions for ERULES-1963177438-22734
Regulation (EU) 2023/1768
found in: ATM/ANS Equipment (2023/1769 and 2023/1768) Part-DPO Part-ATM/ANS.EQMT (Nov 2024)
Version
ATM/ANS Equipment ... (Nov 2024)
Section
Share
Version
Show details
Hide details
Version
ATM/ANS.EQMT.AR.A.020 Allocation of tasks to qualified entities Regulation (EU) 2023/1768 (a) When the Agency decides to allocate tasks related to the certification of ATM/ANS equipment subject to this Regulation, the approval or the continuing oversight of organisations subject to Implementing Regulation (EU) 2023/ 1769 to qualified entities, it shall ensure that it has established and documented an agreement with the qualified entity(ies), approved by both parties to that agreement at the appropriate management level, which clearly defines: (1) the tasks to be performed; (2) the declarations, reports and records to be provided; (3) the technical conditions to be met when performing the tasks; (4) the related liability coverage; (5) the protection given to information acquired when carrying out the tasks. (b) The Agency shall ensure that the internal audit process and the safety risk management process required by point [DPO.AR.B.001](#_DxCrossRefBm1741288259) (a)(5) of Implementing Regulation (EU) 2023/1769 cover all the tasks performed on its behalf by the qualified entity(ies). (c) With regard to the approval and oversight of the organisation’s compliance with point [DPO.OR.B.001](#_DxCrossRefBm1741288294) (d) of Implementing Regulation (EU) 2023/1769, the Agency may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Union. When allocating tasks, the Agency shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the approval and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point [DPO.AR.B.001](#_DxCrossRefBm1741288259) (d) of Implementing Regulation (EU) 2023/1769 covers all the certification and continuing oversight tasks performed on its behalf.