BOP.ADD.030 Management system
Regulation (EU) 2018/395
The operator shall establish, implement and maintain a management system that includes all of the following:
clearly defined lines of responsibility and accountability throughout the organisation of the operator, including a direct safety accountability of the accountable manager;
a description of the overall philosophies and principles of the operator with regard to safety, which shall be known as the safety policy;
the identification of aviation safety hazards entailed by the activities of the operator, the evaluation of those hazards and the management of associated risks, including by taking actions to mitigate those risks where necessary and verifying the effectiveness of those actions;
maintaining personnel trained and competent to perform their tasks;
documentation of all key processes of the management system, including a process for making personnel aware of their responsibilities and the procedure for amending that documentation;
a function to monitor compliance of the operator with the requirements of this Annex. Such compliance monitoring shall include a feedback system of findings to the accountable manager of the operator to ensure effective implementation of corrective actions as necessary;
-
The management system shall correspond to the size of the operator and the nature and complexity of its activities, taking into account the hazards and associated risks of those activities.
AMC1 BOP.ADD.030(a)(2) Management system
SAFETY POLICY
The safety policy should include a commitment to improve towards the highest safety standards, comply with all applicable legal requirements, meet all applicable standards, consider best practices, and provide appropriate resources.
AMC1 BOP.ADD.030(a)(3) Management system
ED Decision 2018/004/R
Hazard identification and safety risk management should:
be performed using internal safety or occurrence reports, hazard checklists, risk registers or similar risk management tools or processes, integrated into the activities of the operator;
in particular address safety risks related to a change; by making use of the existing hazard identification, risk assessment and mitigation tools or processes; and
include provisions for emergency response or a formal emergency response plan (ERP) to define the actions to be taken by the operator or specified individuals in an emergency.
GM1 BOP.ADD.030(a)(4) Management system
TRAINING ON SAFETY
The safety training programme may consist of self-instruction via the media (newsletters, flight safety magazines, etc), classroom training, e-learning or similar training provided by training service providers.
AMC1 BOP.ADD.030(a)(5) Management system
ED Decision 2018/004/R
MANAGEMENT SYSTEM DOCUMENTATION
The operator’s management system documentation should at least include the following information:
a statement signed by the accountable manager to confirm that the operator will continuously work in accordance with the applicable requirements and the operator’s documentation, as required by this Annex;
the operator’s scope of activities;
the titles and names of persons referred to in
BOP.ADD.040(a) and (c);
an organisation chart showing the lines of responsibility among the persons referred to in
BOP.ADD.040;
a general description and location of the facilities referred to in
BOP.ADD.045;
procedures specifying how the operator ensures compliance with the applicable requirements;
the amendment procedure for the operator’s management system documentation.
The operator’s management system documentation may be included in a separate manual, or in (one of) the manual(s) required in this Annex. A cross reference should be included.
AMC1 BOP.ADD.030(a)(6) Management system
COMPLIANCE MONITORING — AUDIT AND ORGANISATIONAL REVIEW
Methodology
The operator should accomplish the compliance monitoring by means of internal auditing.
Notwithstanding (1), an operator with five or less full-time equivalents (FTEs), involved in the activity subject to this Subpart, may choose to accomplish compliance monitoring through an organisational review.
General provisions for compliance monitoring
The operator should specify the basic structure of the compliance monitoring function applicable to the activities conducted.
The operator should ensure that personnel performing an audit or an organisational review, either internal to the operator or external, have relevant knowledge, background and experience as appropriate to the activities being audited or reviewed, including knowledge and experience in compliance monitoring.
The operator should monitor compliance with the procedures it has designed to ensure safe activities. In doing so, the operator should as a minimum, and where appropriate, monitor compliance with:
all activities for which the declaration is required;
manuals, logs and records;
training standards;
management system procedures; and
standard operating procedures (
SOPs).
The operator should ensure that the status of all corrective and preventive actions is monitored and that these actions are implemented within a specified time frame. Action closure should be recorded along with a summary of the action taken.
Based on the results of the audit or the organisational review, the accountable manager should determine the need for and initiate, as appropriate, further actions to address deficiencies or to further improve the operator’s management system.
Provisions, in addition to (b), for auditing
The independence of the audit function should be ensured, in particular in cases where those performing the audit are also responsible for other functions for the operator.
The operator should establish a compliance monitoring programme, defining a calendar for the audits to be performed. The frequency and depth of such audits should be determined with due regard to:
the volume and complexity of operations;
results of the safety risk management processes;
results of past compliance monitoring;
findings raised by the competent authority; and
the scope of changes not requiring prior competent authority approval.
Provisions, in addition to (b), for the organisational review
The organisational review should be performed at intervals not exceeding 12 months.
As part of the management system documentation, the operator should describe the organisational review programme and related responsibilities.
The organisational review programme may consist of:
checklist(s) covering all items necessary to be addressed in order to demonstrate that the operator ensures effective compliance with the applicable requirements; \\and
a schedule for the accomplishment of the different checklist items, where each item should be checked at least at intervals not exceeding 12 months.
GM1 BOP.ADD.030(a)(6) Management system
COMPLIANCE MONITORING — AUDIT AND ORGANISATIONAL REVIEW
‘audit’ means a systematic, independent and documented process for obtaining evidence and evaluating it objectively to determine the extent to which requirements are complied with.
‘organisational review’ means a systematic and documented process for obtaining evidence and evaluating it to determine the extent to which requirements are complied with.
GM2 BOP.ADD.030(a)(6) Management system
COMPLIANCE MONITORING CHECKLIST
Compliance monitoring audits or organisational reviews may be documented using a compliance monitoring checklist. The following provides a basic checklist, to be adapted as necessary to address the particular type of operations and to cover all relevant procedures described in the management system documentation and operations manual.
Each checklist item may be addressed using an appropriate combination of:
review of records and documentation;
interview of the personnel involved; and
feedback provided by contractors.
bop.add.030compliance_monitoring_checklist.pdf
BOP.ADD.035 Contracted activities