AviationBot
Navigate / EASA / Aircrew Aug 2023 / ANNEX VI (Part-ARA) / SUBPART GEN - GENERAL REQUIREMENTS / SECTION II - Management /

ARA.GEN.200 Management system

EASA aviation authorities must implement a management system ensuring regulatory compliance. This includes documented procedures, qualified personnel, adequate facilities, and compliance monitoring with internal audits and risk management. Information security risks impacting aviation safety must be managed. Information exchange with other authorities is mandatory.

Frequently Asked Questions

Documented policies and procedures, sufficient qualified personnel, adequate facilities, compliance monitoring, and a designated person or group responsible for compliance monitoring.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The competent authority shall establish and maintain a management system to achieve compliance with Regulation (EU) 2018/1139 and related acts.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

The requirements are applicable from 22 February 2026.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

Annex I (Part-IS.AR) to Implementing Regulation (EU) 2023/203 to ensure the proper management of information security risks which may have an impact on aviation safety.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

A mutual exchange of all necessary information and assistance with other competent authorities concerned, including information on findings, corrective actions, enforcement measures, and occurrence reporting.

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

22 February 2026

* Aviation.Bot's Suggestion - Always consult the original regulation for confirmation

EASA Logo

ARA.GEN.200 Management system

Regulation (EU) 2023/203

(a)     The competent authority shall establish and maintain a management system, including as a minimum:

(1)     documented policies and procedures to describe its organisation, means and methods to achieve compliance with Regulation (EU) 2018/1139 and the delegated and implementing acts adopted on the basis thereof. The procedures shall be kept up to date and serve as the basic working documents within that competent authority for all related tasks;

(2)     a sufficient number of personnel to perform its tasks and discharge its responsibilities. Such personnel shall be qualified to perform their allocated tasks and have the necessary knowledge, experience, initial and recurrent training to ensure continuing competence. A system shall be in place to plan the availability of personnel, in order to ensure the proper completion of all tasks;

(3)     adequate facilities and office accommodation to perform the allocated tasks;

(4)     a function to monitor compliance of the management system with the relevant requirements and adequacy of the procedures including the establishment of an internal audit process and a safety risk management process. Compliance monitoring shall include a feedback system of audit findings to the senior management of the competent authority to ensure implementation of corrective actions as necessary; and

(5)     a person or group of persons, ultimately responsible to the senior management of the competent authority for the compliance monitoring function.

(b)     The competent authority shall, for each field of activity including management system, appoint one or more persons with the overall responsibility for the management of the relevant task(s).

(c)      The competent authority shall establish procedures for participation in a mutual exchange of all necessary information and assistance with other competent authorities concerned, whether from within the Member State or in other Member States, including the following information:

(1)     on all findings raised, corrective follow-up actions taken pursuant to such findings and enforcement measures taken as a result of oversight of persons and organisations exercising activities in the territory of a Member State but certified by or having made declarations to the competent authority of another Member State or the Agency;

(2)     stemming from mandatory and voluntary occurrence reporting as required by point ORA.GEN.160 of Annex VII.

(d)     A copy of the procedures related to the management system and their amendments shall be made available to the Agency for the purpose of standardisation.

(e)     In addition to the requirements contained in point (a), the management system established and maintained by the competent authority shall comply with Annex I (Part-IS.AR) to Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.

[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]

Related

AI for Aviation Professionals

Aviation.Bot is an AI tool that assists you with aviation compliance.