The safety management framework is not the hard part. ICAO wrote it down years ago: four components, twelve elements, one manual. The hard part is turning that framework into a management system that actually runs inside a maintenance organisation — where hazards look like task interruptions and shift handovers rather than abstract risk categories, and where a compliance monitoring function already exists and must work with, not against, safety assurance. This article walks the framework from its international source down to the documents and routines of an EASA Part-145 or CAMO organisation.
The regulatory chain: from Annex 19 to your exposition
Safety management enters the system at the top. ICAO Annex 19 (Safety Management, second edition, 2016) consolidates the international standards; the Safety Management Manual (Doc 9859, fourth edition, 2018) is the accompanying guidance that structures an SMS into four components and twelve elements.
The European Union transposed that framework into the continuing airworthiness domain in two steps. For continuing airworthiness management organisations, Commission Implementing Regulation (EU) 2019/1383 created Part-CAMO, whose point CAMO.A.200 requires a management system embedding safety management. For maintenance organisations, Commission Implementing Regulation (EU) 2021/1963 amended Regulation (EU) No 1321/2014 to introduce the equivalent requirements into Part-145 — applicable from 2 December 2022, with the transition window under Article 4(7) of Regulation (EU) No 1321/2014 closing on 2 December 2024.
The chain ends in your own documentation: the maintenance organisation exposition or continuing airworthiness management exposition, where the management system described on paper must match the one operating on the floor. Organisations take different documentation routes — some integrate the management system description fully into the exposition, others maintain a referenced safety management manual alongside it. Both can work; what does not work is duplication that drifts, where the exposition says one thing and the safety manual another. Pick one authoritative home for each process and cross-refer everything else to it. That correspondence between the documented system and the operating one — not the elegance of the manual — is what your competent authority assesses.
Four components, twelve elements: the architecture
Doc 9859 structures every SMS on the same skeleton. Safety policy and objectives: management commitment; safety accountability and responsibilities; appointment of key safety personnel; coordination of emergency response planning; and SMS documentation. Safety risk management: hazard identification, and safety risk assessment and mitigation. Safety assurance: safety performance monitoring and measurement; the management of change; and continuous improvement. Safety promotion: training and education, and safety communication.
The EASA rules do not copy this list verbatim — they distribute it. Point 145.A.200 carries the management system requirements, 145.A.202 the internal safety reporting scheme, 145.A.205 the control of contracting and subcontracting, and 145.A.30(ca) the nomination of the person responsible for the safety management processes. When you map your system, map against both: the twelve elements give you the logic, the rule points give you the compliance reference your authority will audit against.
Safety policy and objectives in a maintenance organisation
Component one is where commitment becomes structure. The accountable manager holds ultimate responsibility for the management system; safety accountabilities must be defined down through the organisation, not parked with the safety manager; and the key safety personnel — the safety manager under 145.A.30(ca) and the compliance monitoring manager — must be nominated and accepted by the competent authority, with sufficient time to discharge their functions.
In a maintenance context, the safety policy earns its keep in specifics: an explicit commitment to the internal reporting scheme and its just culture, safety objectives that relate to the organisation’s actual risk picture rather than generic aspirations, and documentation integrated into the exposition so the system has one authoritative description.
The test of a safety objective is whether it could fail. “Improve safety culture” cannot fail and therefore commits you to nothing. Objectives tied to your risk picture can: raising the proportion of hazards identified through voluntary reports rather than audits, closing corrective actions within their assigned deadlines, or reducing a specific recurring occurrence type your data actually shows. Objectives of that kind give the safety assurance component something real to monitor — which is the point of having them.
Safety risk management on the hangar floor
Hazard identification in a maintenance organisation is not a brainstorming exercise — the data already exists. The internal safety reporting scheme required by 145.A.202 is the primary feed; occurrence reports raised under Regulation (EU) No 376/2014, audit and survey findings, reliability data and the results of maintenance error investigations (methods such as Boeing’s MEDA) complete the picture. The discipline lies in routing all of it into one hazard register instead of five parallel lists.
Risk assessment then needs a defined, documented method — whatever matrix or model you adopt, it must be applied consistently, produce decisions traceable to risk level, and drive mitigations that someone owns with a deadline. A register full of assessments and empty of completed actions is the most common form of paper SMS, and experienced inspectors look for exactly that gap.
Safety assurance and the compliance monitoring interface
Safety assurance asks a different question than compliance monitoring, and the difference is worth stating plainly. Compliance monitoring — the function that under 145.A.200 continues the role of the former quality system — verifies that the organisation meets the applicable requirements and its own procedures. Safety assurance verifies that the management system is actually delivering safety performance: it monitors indicators, evaluates the effect of changes, and drives continuous improvement.
In an integrated management system the two feed each other. Audit findings are an input to hazard identification; risk assessments shape the audit programme; management review looks at both compliance status and safety performance together. Safety performance indicators should come from your own operation — reporting rates, closure of corrective actions, trends in occurrences by type or by station are common examples — and be chosen because they inform decisions, not because they are easy to count.
The management of change belongs here too: new capability, new customer, new facility, staffing change — each passes through a documented assessment of what hazards the change introduces before it takes effect, proportionate to its scale.
Interfaces: contracted work and the CAMO–145 boundary
No maintenance organisation manages safety inside its own walls only. Point 145.A.205 requires the organisation to control contracted and subcontracted work, and the management system must reach across that boundary: hazards arising from a subcontractor’s work belong in your risk picture, and your reporting scheme must be able to receive what their staff encounter on your jobs.
The same logic applies at the CAMO–145 interface. A continuing airworthiness management organisation under CAMO.A.200 and the maintenance organisations it contracts each hold their own management system, but the hazards do not respect the contractual line — a recurring defect trend visible to the CAMO may originate in a maintenance practice only the 145 can see, and vice versa. Mature systems define this interface deliberately: what safety data flows in each direction, who attends whose reviews, and how a risk identified on one side triggers action on the other. For organisations holding both approvals, the integrated management system should demonstrate one coherent risk picture, not two parallel ones. This interface is also where audit programmes earn their keep — it features prominently in industry audit frameworks such as IOSA’s maintenance chapters, and it is a recurring source of findings precisely because it belongs to everyone and therefore, too often, to no one.
Safety promotion: making the system visible
Component four is the one that determines whether the other three live. Safety training must match roles — from the accountable manager’s awareness of his or her accountabilities to technicians’ human factors continuation training — and safety communication must close the loop: reporters hear what happened to their reports, lessons from investigations reach the floor, and the safety objectives are known beyond the management meeting. An SMS nobody hears about is indistinguishable from no SMS at all.
Measuring maturity: the EASA Management System Assessment Tool
You do not have to invent your own yardstick. EASA publishes the Management System Assessment Tool (MSAT, Edition 2.0, September 2023), used by competent authorities in assessing organisations’ management systems and equally available to organisations for self-assessment. Working through its assessment items against your own system — honestly, with evidence — is the closest thing to a rehearsal of your next authority audit, and a natural follow-up to a structured gap analysis.
Two habits make self-assessment worth the time. First, insist on evidence for every item scored: a claim without a record, a report, a minute or a register entry is scored down until the evidence exists. Second, repeat the exercise on a cycle and track the movement — a maturity assessment done once is a snapshot; done annually, it becomes one of the most honest safety performance indicators the organisation owns.
After the transition: what “implemented” means now
The transition window closed on 2 December 2024. For Part-145 organisations the SMS is no longer a project with a deadline — it is business as usual, and oversight has shifted from “do you have one” to “does it work”. The organisations that do well from here are the ones treating the framework as a living system: a register that changes because reports arrive, indicators that provoke decisions, and a management review that would notice if either stopped. If your system would not pass that description today, a structured gap analysis against the twelve elements is the place to start.