ATM/ANS.AR.B.001
Management system
Regulation
(EU) 2023/203
(a) The competent authority shall establish
and maintain a management system, including, as a minimum, the following
elements:
(1) documented policies and
procedures to describe its organisation, means and methods to achieve
compliance with Regulation (EU) 2018/1139 and the delegated and implementing
acts adopted on the basis thereof, as necessary, for the exercise of its
certification, oversight and enforcement tasks. The procedures shall be kept
up to date and serve as the basic working documents within that competent
authority for all related tasks;
(2) a sufficient number of personnel,
including inspectors, to perform its tasks and discharge its responsibilities
under this Regulation. Such personnel shall be qualified to perform their
allocated tasks and have the necessary knowledge, experience, initial,
on-the-job and recurrent training to ensure continuing competence. A system
shall be in place to plan the availability of personnel, in order to ensure
the proper completion of all related tasks;
(3) adequate facilities and office
accommodation to perform those allocated tasks;
(4) a process to monitor compliance of the
management system with the relevant requirements and adequacy of the
procedures, including the establishment of an internal audit process and a
safety risk management process. Compliance monitoring shall include a feedback
system of audit findings to the senior management of the competent authority
to ensure implementation of corrective actions as necessary;
(5) a person or group of persons ultimately
responsible to the senior management of the competent authority for the
compliance monitoring function.
(b) The competent authority shall, for each
field of activity included in the management system, appoint one or more
persons with the overall responsibility for the management of the relevant
task(s).
(c) The competent authority shall establish
procedures for the participation in a mutual exchange of all necessary
information and assistance with other competent authorities concerned, whether
from within the Member State or in other Member States, including the
following information:
(1) the relevant findings raised and follow-up
actions taken as a result of oversight of ATM/ANS providers exercising
activities in the territory of a Member State, but certified by the competent
authority of another Member State or the Agency; and
(2) stemming from mandatory and voluntary
occurrence reporting as required by point ATM/ANS.OR.A.065.
(d) A copy of the procedures related to the
management system and their amendments shall be made available to the Agency
for the purpose of standardisation.
(e) In addition to the requirements
contained in point (a), the management system established and maintained by
the competent authority shall comply with Annex I (Part-IS.AR) of Implementing
Regulation (EU) 2023/203 in order to ensure the proper management of
information security risks which may have an impact on aviation safety.
[applicable
from 22 February 2026 - Regulation (EU) 2023/203]
Loading collections...