Ask five safety managers to define “SMS” and simply count the different answers you get back. That ambiguity is precisely what an EASA oversight auditor is trained to probe on day one of an inspection.
Here is the detail that catches most operators off guard: EASA's own rulebook does not use the term “Safety Management System.” Regulation (EU) No 965/2012, Annex III (Part-ORO), ORO.GEN.200 calls it a “management system.” ICAO Annex 19 uses “SMS.” The two describe the same obligation, but the EASA wording is deliberate — the management system has to cover compliance across the whole operation, not safety risk in isolation. Getting this distinction right in your documentation is the first item on our gap-analysis checklist, and it is the first thing that tells an auditor whether an organisation actually understands what it built.
1. The Four Components, Twelve Elements
Whether an organisation calls it SMS or a management system, the architecture EASA expects to see traces directly back to ICAO Annex 19:
- Safety Policy and Objectives — management commitment, safety accountabilities, appointment of key safety personnel, coordination of emergency response planning, and SMS documentation.
- Safety Risk Management — hazard identification, and safety risk assessment and mitigation.
- Safety Assurance — safety performance monitoring and measurement, the management of change, and continuous improvement of the management system.
- Safety Promotion — training and education, and safety communication.
That is twelve distinct elements. Most operators can produce a manual chapter for each one. Far fewer can produce evidence that each element is functioning as a living process rather than a paperwork exercise.
2. Where First Audits Go Wrong
In our audit and gap-analysis work, the same handful of weaknesses recur regardless of operator size:
- Hazard registers that were written once and never revisited. A hazard log with entries from three years ago and nothing since is not evidence of a mature system — it is evidence that the reporting culture has gone quiet.
- Risk matrices copied from a template. A 5×5 risk matrix taken from a training course, with no adjustment for the operator's actual fleet, route network, or maintenance arrangement, does not satisfy AMC1 ORO.GEN.200(a)(3) — the requirement that the system reflect the size of the organisation and the nature and complexity of its activities.
- Management of change treated as a one-off form. A genuine management-of-change process has to trigger every time something material shifts: a new destination, a new ground handler, a fleet type change, a restructuring of the operations department. If the form is only ever completed during audit preparation, the process does not exist in any meaningful sense.
- Safety promotion measured by training hours alone. Safety communication is a two-way element. If safety bulletins go out but nothing comes back — no questions, no feedback, no evidence staff read them — the promotion component is incomplete.
3. The Proportionality Test
AMC1 ORO.GEN.200(a)(3) is doing more work in an audit than most operators realise. Auditors are not checking whether an organisation has a management system manual — they are checking whether the system built matches its risk profile. A five-aircraft charter operator and a national flag carrier will both need all twelve elements, but the depth, tooling and resourcing behind each element should look very different. A management system over-engineered for a small AOC holder is almost as telling to an auditor as one under-engineered for a large one: both suggest the organisation copied a template rather than built a system around its own operation.
4. Building a Management System That Survives Oversight
A management system that holds up under scrutiny is built, not assembled. In practice that means:
- Running a documented gap analysis against ORO.GEN.200 and its AMC/GM material before the regulator does it.
- Populating the hazard register from real data sources — occurrence reports, flight data monitoring, line audits and crew feedback — not a workshop brainstorm that never gets updated.
- Calibrating the risk matrix to the operation: route structure, fleet complexity, subcontracted maintenance and ground-handling arrangements.
- Making management of change a standing agenda item at the safety review board, not a form that surfaces once a year.
- Evidencing safety promotion with two-way records: acknowledgements, toolbox-talk minutes, safety survey results — not just a training attendance sheet.
The organisations that pass their first EASA audit comfortably are not the ones with the thickest manual. They are the ones that can produce evidence, on request, that all twelve elements are functioning together as a system.
Conclusion
AeroLex's Assure and Improve services are built around exactly this distinction — closing the gap between a management system that exists on paper and one that would survive an unannounced audit. If your organisation is heading into its first EASA oversight visit, or you suspect your management system has quietly gone stale, that is precisely the conversation to have before the regulator has it.