Navigate / EASA
AMC1 ORO.AOC.130 Flight data monitoring – aeroplanes

ED Decision 2025/020/R

FLIGHT DATA MONITORING (FDM) PROGRAMME

(a) The safety manager, as defined under AMC1 ORO.GEN.200(a)(1), should be responsible for the identification and assessment of issues and their transmission to the manager(s) responsible for the process(es) concerned. The latter should be responsible for taking appropriate and practicable safety action within a reasonable period of time that reflects the severity of the issue.

(b) An FDM programme should allow an operator to:

(1) identify areas of operational risk and quantify current safety margins;

(2) identify and quantify operational risks by highlighting occurrences of non-standard, unusual or unsafe circumstances;

(3) use the FDM information on the frequency of such occurrences, combined with an estimation of the level of severity, to assess the safety risks and to determine which may become unacceptable if the discovered trend continues;

(4) put in place appropriate procedures for remedial action once an unacceptable risk, either actually present or predicted by trending, has been identified; and

(5) confirm the effectiveness of any remedial action by continued monitoring.

(c) FDM analysis techniques should comprise the following:

(1) Exceedance detection: searching for deviations from aircraft flight manual limits and standard operating procedures. A set of core events should be selected to cover the main areas of interest to the operator and as much as possible, the most significant risks identified by the operator. The event definitions should be continuously reviewed to reflect the operator’s current operating procedures.

(2) All flights measurement: a system defining what is normal practice. This may be accomplished by retaining various snapshots of information from each flight.

(3) Statistics — a series of data collected to support the analysis process: this technique should include the number of flights flown per aircraft and sector details sufficient to generate rate and trend information.

(d) FDM analysis, assessment and process control tools: the effective assessment of information obtained from digital flight data should be dependent on the provision of appropriate information technology tool sets.

(e) Education and publication: sharing safety information should be a fundamental principle of aviation safety in helping to reduce accident rates. The operator should pass on the lessons learnt to all relevant personnel and, where appropriate, industry.

(f) Accident and incident data requirements specified in CAT.GEN.MPA.195 take precedence over the requirements of an FDM programme. In these cases the FDR data should be retained as part of the investigation data and may fall outside the de-identification agreements.

(g) Every crew member should be responsible for reporting events. Significant risk-bearing incidents detected by FDM should therefore normally be the subject of mandatory occurrence reporting by the crew. If this is not the case, then they should submit a retrospective report that should be included under the normal process for reporting and analysing hazards, incidents and accidents.

(h) The data recovery strategy should ensure a sufficiently representative capture of flight information to maintain an overview of operations. Data analysis should be performed sufficiently frequently to enable action to be taken on significant safety issues.

(i) The data retention strategy should aim at providing the greatest safety benefits practicable from the available data. A full dataset should be retained until the action and review processes are complete; thereafter, a reduced dataset relating to closed issues should be maintained for longer-term trend analysis. Programme managers may wish to retain samples of de-identified full-flight data for various safety purposes (detailed analysis, training, benchmarking, etc.).

(j) The data access and security policy should restrict information access to authorised persons. When data access is required for airworthiness and maintenance purposes, a procedure should be in place to prevent disclosure of crew identity.

(k) The procedure to prevent disclosure of crew identity should be written in a document, which should be signed by all parties (airline management, flight crew member representatives nominated either by the union or the flight crew themselves). This procedure should, as a minimum, define:

(1) the aim of the FDM programme;

(2) a data access and security policy that should restrict access to information to specifically authorised persons identified by their position;

(3) the method to obtain de-identified crew feedback on those occasions that require specific flight follow-up for contextual information; where such crew contact is required the authorised person(s) need not necessarily be the programme manager or safety manager, but could be a third party (broker) mutually acceptable to unions or staff and management;

(4) the data retention policy and accountability, including the measures taken to ensure the security of the data;

(5) the conditions under which advisory briefing or remedial training should take place; this should always be carried out in a constructive and non-punitive manner;

(6) the conditions under which the confidentiality may be withdrawn for reasons of gross negligence or significant continuing safety concern;

(7) the participation of flight crew member representative(s) in the assessment of the data, the action and review process and the consideration of recommendations; and

(8) the policy for publishing the findings resulting from FDM.

(l) Airborne systems and equipment used to obtain FDM data should range from a quick access recorder (QAR) in an aircraft with digital systems, to a crash-protected flight recorder in an older or less sophisticated aircraft. The analysis potential of the reduced data set available in the latter case may reduce the safety benefits obtainable. The operator should ensure that FDM use does not adversely affect the serviceability of equipment required for accident investigation.

[applicable until 31 December 2027 — ED Decision 2021/005/R]

AMC1 ORO.AOC.130 Flight data monitoring — aeroplanes

ORGANISATION OF THE FLIGHT DATA MONITORING (FDM) PROGRAMME

(a) Safety manager’s responsibilities: the safety manager, as defined under AMC1 ORO.GEN.200(a)(1), should be responsible for the identification and assessment of issues and their transmission to the manager(s) responsible for the process(es) concerned. The latter should be responsible for taking appropriate and practicable safety action.

(b) Contribution to the management system: an FDM programme should support the identification and evaluation of safety hazards and the management of their associated risks, as required by point ORO.GEN.200, by allowing the operator to:

(1) identify areas of operational risk and quantify current safety margins;

(2) identify and quantify operational risks by highlighting occurrences of non-standard, unusual or unsafe circumstances;

(3) estimate the frequency of such occurrences, assess the safety risks and determine which risks are unacceptable or may become unacceptable if the discovered trend continues;

(4) inform the definitions of remedial actions with accurate and current safety data; and

(5) confirm the effectiveness of any remedial action by continued monitoring.

(c) FDM analysis techniques: FDM analysis techniques should comprise the following:

(1) Exceedance detection (‘FDM event’): searching for deviations from aircraft flight manual limits and standard operating procedures.

(2) All flights measurement (‘FDM measurement’): a system defining what is normal practice. This may be accomplished by retaining various snapshots of information from each flight.

(3) Statistics — a series of data collected to support the analysis process: FDM-based statistics should include distributions and rate and trend information where the number of flights flown is sufficient to reliably generate such information.

(d) FDM analysis, assessment and process control tools: the assessment of information obtained from flight data should be supported by the provision of appropriate information technology capabilities. These capabilities should include specialised software (‘FDM software’) or a specialised service (‘FDM service’) to process the flight data. In addition, to facilitate linking flight data with occurrence reports and other data, such as traffic data and weather data, these capabilities should include:

(1) the automatic identification of individual flights in the data files collected for FDM; and

(2) if the necessary data is collected, the provision of the following information for each detected FDM event:

(i) the aircraft’s geographical position and altitude,

(ii) coordinated universal time (UTC) date and time,

(iii) information that identifies the flight, and

(iv) aircraft registration.

(e) Safety information and promotion: FDM programme output should be used, in compliance with the procedure specified in point (k), to support the sharing of safety information with flight crew members and all other relevant personnel. For this purpose, the operator should provide, upon request by its competent authority, documentation on the principles it follows to ensure the adequate quality of FDM events, FDM measurements and FDM-based statistics used for safety information sharing. It should also demonstrate that FDM-based safety information provided to individual flight crew members is clear and relevant.

(f) Accident and incident data requirements: requirements regarding the preservation of flight recorder recordings after accidents and serious incidents specified in CAT.GEN.MPA.195 take precedence over the requirements of an FDM programme.

(g) Incident reporting: significant risk-bearing incidents detected by FDM should be the subject of reporting by the crew. If this is not the case, then they should submit a retrospective report that should be included under the normal process for reporting and analysing hazards, incidents and accidents, in accordance with Regulation (EU) No 376/2014.

(h) Data recovery and validation: the data recovery and validation strategy should ensure a sufficiently representative capture of flight information to maintain an overview of operations and that data is recovered from all aeroplanes that are within the scope of point ORO.AOC.130. In addition, the validation of FDM events and measurements should be performed sufficiently frequently to enable action to be taken on significant safety issues. Data recovery and validation should incorporate all the points below.

(1) To ensure that a sufficiently representative subset of flights is monitored by the FDM programme, the number of flights available for processing by the FDM programme and that contain valid data should amount to:

(i) at least 60 % of the total number of flights performed in the past 12 months by aeroplanes that are within the scope of point ORO.AOC.130, if the operator operates fewer than 20 such aircraft; or

(ii) at least 80 % of the total number of flights performed in the past 12 months by aeroplanes that are within the scope of point ORO.AOC.130, if the operator operates 20 or more such aircraft.

This condition is not applicable to aeroplanes that performed fewer than 50 flights in the previous 12 months.

(2) To limit the maximum duration during which no flight data may be received from an individual aeroplane, the operator should:

(i) have means and procedures to identify a failure of the means to collect data from any individual aeroplane that is within the scope of point ORO.AOC.130 either within 22 calendar days after the failure occurs or before 10 more flights are performed after the failure occurs; and

(ii) correct any failure of the means to collect data from any individual aeroplane that is within the scope of point ORO.AOC.130 within 120 days of being made aware of the failure.

(3) To ensure that significant FDM events (FDM events that correspond to the most significant deviations from the SOPs and circumstances potentially affecting the airworthiness of the aircraft) can be identified without unnecessary delays, the flights for which flight data is collected within the FDM programme (hereafter called ‘collected flights’) should be processed in a timely manner. At least 80 % of the collected flights that were performed in the previous 12 months should have been processed by the FDM software either within 22 calendar days after completion of the collected flight or before 10 flights following the collected flight were performed by the same aircraft.

(4) For each aeroplane that is within the scope of point ORO.AOC.130 and that is first issued with an individual certificate of airworthiness (CofA) on or after 1 January 2029:

(i) the operator should ensure that, within 90 calendar days after it starts operating the aeroplane, the data collected for processing by the FDM software include all the flight parameters required to be recorded by a flight data recorder in accordance with AMC1.2 CAT.IDE.A.190; and

(ii) the operator should verify, within 90 calendar days after it starts operating the aeroplane, that the flight parameters specified in point (i) meet the performance specifications (range, sampling intervals, accuracy limits and resolution in
read-out) as defined in EUROCAE Document 112A or any later equivalent standard produced by EUROCAE — this verification may be based on the documentation provided by the aircraft manufacturer or the installer of the airborne systems used to collect the flight data.

(5) The operator should explain, upon request by its competent authority, the principles it uses for validating an FDM event, that is, how it determines whether an FDM event genuinely reflects a deviation that is considered abnormal for the flight in which the FDM event was triggered.

(6) The operator should validate significant FDM events as a matter of priority. At least 80 % of significant FDM events should be validated within 15 calendar days after their first detection by the FDM software.

(i) Data retention strategy: the data retention strategy should aim at providing the greatest safety benefits practicable from the available data. For this purpose:

(1) All raw or decoded flight data should be retained at least until valid significant FDM events have been analysed. In addition, 80 % or more of the raw or decoded flight data files of aircraft required to be part of the FDM programme should remain available for processing with the FDM software for at least 2 years; however, retaining a lower proportion of these flight data files is acceptable until 2 years after installing new FDM software or until 2 years after the start of a contract with a new FDM service provider.

(2) A dataset relating to de-identified analyses of significant FDM events should be maintained for a time that is consistent with the operator’s record-keeping for management-system-related activities (refer to point ORO.GEN.220).

(3) The data retention strategy should include measures to ensure the security of stored data.

(j) Data access and security policy: the data access and security policy should restrict information access to authorised persons. This policy should specifically address the case of a data access request for airworthiness or maintenance purposes.

(k) Procedure to prevent disclosure of crew identity: the procedure to prevent disclosure of crew identity should be written in a document, which should be signed by all parties (airline management, flight crew member representatives nominated either by the union or the flight crew themselves). This procedure should, as a minimum, define:

(1) the aim of the FDM programme;

(2) a data access and security policy that should restrict access to information to specifically authorised persons identified by their position (refer to point (j));

(3) the method to obtain de-identified crew feedback on those occasions that require specific flight follow-up for contextual information; where such crew contact is required the authorised person(s) need not necessarily be the programme manager or safety manager, but could be a third party (broker) mutually acceptable to unions or staff and management;

(4) a data retention strategy (refer to point (i)) and data accountability;

(5) the conditions under which advisory briefing or remedial training should take place; this should always be carried out in a constructive and non-punitive manner;

(6) the conditions under which the identity of a crew member may be disclosed, which should be consistent with the provisions laid down in Regulation (EU) No 376/2014 and the operator’s safety risk management procedures;

(7) the participation of flight crew member representative(s) in the assessment of the data, the action and review process and the consideration of recommendations; and

(8) the policy for sharing safety information based on FDM (refer to point (e)).

(l) Access to information on flight parameters and FDM algorithms: the operator should have unhindered access to information on the flight parameters and the algorithms used to produce FDM events and measurements. For aircraft required to be part of the FDM programme and first issued with an individual CofA on or after 1 January 2029, the operator should, within 90 calendar days after it starts operating these aircraft, be able to provide the following documentation upon request by its competent authority:

(1) documentation of the data source and the performance (at least the recording resolution and recording rate) of all the flight parameters collected and used by the FDM software to produce FDM events and measurements;

(2) documentation on the algorithms used to produce FDM events or FDM measurements, which should include the following:

(i) a description of the logic of each algorithm, which should be sufficiently detailed to verify consistency with the applicable flight manual limitations or standard operating procedures, as applicable; in the case of an FDM event algorithm, the event trigger conditions and the trigger threshold values should be specified;

(ii) for each algorithm, the list of flight parameters needed by the algorithm.

(m) Airborne systems and equipment: for all aircraft required to be part of the FDM programme and that are first issued with an individual CofA on or after 1 January 2029, airborne systems and equipment used to obtain flight data should continuously collect the data throughout the flight, including when the aircraft is moving on the ground under its own power. The use of such airborne systems and equipment, including retrieval of data from the aircraft, should not affect the availability or the serviceability of flight recorders required for accident investigation.

[applicable from 1 January 2028 — ED Decision 2025/020/R]