ATM/ANS.AR.B.005
Allocation of tasks to qualified entities
Regulation
(EU) 2023/203
[applicable until 21
February 2026 - Regulation (EU) 2017/373]
ATM/ANS.AR.B.005 Allocation of
tasks
[applicable
from 22 February 2026 - Regulation (EU) 2023/203]
(a) The competent authority may allocate its
tasks related to the certification or oversight of service providers under
this Regulation, other than the issuance of certificates themselves, to
qualified entities. When allocating such tasks, the competent authority shall
ensure that it has:
(1) a system in place to
initially and continuously assess that the qualified entity complies with Annex
V to Regulation
(EC) No 216/2008. This system and the results of the assessments shall be
documented; and
(2) established a documented agreement with
the qualified entity, approved by both parties at the appropriate management
level, which clearly defines:
(i) the tasks to be performed;
(ii) the declarations, reports and records to
be provided;
(iii) the technical conditions to be met when
performing such tasks;
(iv) the related liability coverage;
(v) the protection given to information
acquired when carrying out such tasks.
(b) The competent authority
shall ensure that the internal audit process and the safety risk management
process required by point ATM/ANS.AR.B.001(a)(4)
cover all tasks performed on its behalf by the qualified entity.
(c) With
regard to the certification and oversight of the organisation’s compliance
with point ATM/ANS.OR.B.005A, the competent authority may
allocate tasks to qualified entities in accordance with point (a), or to any
relevant authority responsible for information security or cybersecurity
within the Member State. When allocating tasks, the competent authority shall
ensure that:
(1) all aspects related to aviation safety are
coordinated and taken into account by the qualified entity or relevant
authority;
(2) the results of the certification and
oversight activities performed by the qualified entity or relevant authority
are integrated in the overall certification and oversight files of the
organisation;
(3) its own information security management
system established in accordance with point ATM/ANS.AR.B.001(e) covers all the certification and continuing
oversight tasks performed on its behalf.
[applicable
from 22 February 2026 - Regulation (EU) 2023/203]
Loading collections...