top of page

The SMS Compliance Monitoring Trap (And How Part 135 Operators Avoid It)

Updated: 45 minutes ago


Written by: Douglas Spanier


If you’ve ever sat across the table from an IS-BAO, Wyvern, or ARGUS auditor, you know how the standard interview question goes:

Auditor: "How does your organization identify, evaluate, and incorporate updates to regulations and commercial safety standards?" Operator: "Oh, we get email alerts from the FAA and IBAC. We check the websites regularly, and if something changes that affects us, we deal with it and update our manuals."

In many routine audits, that quick verbal answer is accepted. The auditor checks "Satisfactory," nods, and moves on.

Because of this, most Part 135 flight departments genuinely believe they have a working Compliance Monitoring Program. They have a pristine policy written into their GOM or SMS manual that says all the right things. In reality, though, they aren't actually doing it, at least not in a structured, documented way.

Then comes the audit that changes everything.

You get an auditor who doesn't just listen to your answer, they test it:

Auditor: "Great. Show me the paper trail. Show me the specific email alert you received for a recent FAR Part 135 or ARG/US update, show me the entry where you logged it, show me your gap analysis evaluating its impact on your operation, and show me the EFB read-and-sign receipt proving your pilots were notified." Silence………

That is the exact moment most operators realize they don't have a compliance monitoring process; they have a promise of a compliance monitoring process.

The Missing Link in Safety Assurance

Under modern aviation standards, such as FAA Part 5, EASA, and IS-BAO Section 3.5, compliance monitoring isn't meant to be a theoretical policy that lives in a binder. It is the diagnostic baseline for your Safety Assurance (SA) pillar.

While Safety Risk Management (SRM) asks, "Are our operational processes safe enough?", Compliance Monitoring asks the diagnostic question: "Are we actually doing what we said we would do, and can we prove our manual policies are up to date with any updated FAA regulations or third-party standards?"

The issue isn't that flight departments don't care about compliance. It's that no one has given them a simple, step-by-step operational blueprint to document it without adding hours of daily paperwork.

Here is how to move your flight department from "verbal hand-waving" to an airtight, bulletproof evidence trail in 5 simple steps.

Step 1: Inventory Your "Watchlist" & Mark Your Calendar

You cannot monitor what you don't track. Most Part 135 operators fail at compliance monitoring simply because they lack a clear inventory of every external entity that governs their operation.

Your monitoring input strategy must track at least these three distinct tiers:

  • Tier 1: Mandatory Regulatory Standards (FAA 14 CFR Parts 1, 5, 61, 91, 119, 135; ACs; SAFOs; DRS updates; OpSpecs/WebOPSS revisions; plus international items if applicable)

  • Tier 2: Framework & Process Standards (IS-BAO annual Standard & Protocols cycle; monitor Operator Portal and IBAC newsletters)

  • Tier 3: Commercial & Marketability Standards (Wyvern, ARGUS, and major charter partner/vendor standards)

Step 2: Automate Your Feeds & Establish Your Review Routine

Relying on someone to manually "remember" to check websites every week is a single point of failure. Automation provides the unassailable timestamp auditors want to see.

  1. Automate regulatory feeds (eCFR & Federal Register) for Title 14 updates.

  2. Schedule the mid-to-late January IS-BAO Operator Portal check-in.

  3. Use the January to June 30 grace period to complete gap analysis and MoC if triggered, issue bulletins, and push updates to EFBs.

  4. Monitor IBAC email newsletters where revisions are highlighted.

Step 3: Establish a Master Regulatory Register

When an email alert arrives, where does it go? If it stays in your inbox, it doesn't exist to an auditor.

Establish a centralized Master Regulatory Register, using a simple digital SMS module or a structured Excel sheet. Every monitored feed update gets logged with fields such as:

  • Log ID (unique tracking reference)

  • Date researched & reviewer name

  • Source & summary

  • Operational impact? (Yes/No)

  • Action required / owner

  • Status (Open / In Progress / Closed)

Pro-Tip: Always log "No Impact" items too. It proves you are running an active monitoring engine.

Step 4: Execute Gap Analysis & Issue Manual Bulletins

When a rule or standard update triggers Operational Impact = Yes, your compliance monitoring process moves into quick execution:

  1. Gap analysis: compare your manuals/programs against the new requirement.

  2. Check MoC triggers in your SMS manual; run a formal MoC risk assessment if triggered.

  3. Issue a Manual Bulletin / Safety Bulletin immediately if a manual change is required.

  4. Queue the bulletin for incorporation into the next scheduled manual revision cycle.

Pro-Tip: For complex updates, AI tools can accelerate initial gap analysis by cross-referencing large manual systems quickly.

Step 5: Push to EFBs & Complete the Paper Trail

A bulletin or manual revision sitting on a manager's hard drive does not protect a flight crew.

Publish the Manual Bulletin or updated manual revision directly to flight crew EFBs. Enforce digital Read-and-Sign acknowledgments before pilots are assigned to flight duty.

The Monthly Workflow (Your Compliance Workhorse)

The biggest mistake operators make is trying to fill out comprehensive audit checklists every single month. Don't do that.

Split your compliance monitoring into two clean rhythms:

  • Monthly / Continuous (The Workhorse): check automated alerts, maintain the Master Regulatory Register, issue bulletins when required, and push read-and-sign EFB updates. Total time: ~15 to 30 minutes per month.

  • Annually (The Program Audit): execute your formal Compliance Audit Checklist once per year and attach it to your annual SMS Management Review package.

Need a Ready-To-Use Master Register & Audit Checklist?

Don't waste time building these compliance tracking documents from scratch. If you'd like generic, pre-formatted templates for both the Master Regulatory Register and the Annual Compliance Audit Checklist, reach out to me directly, I’d be happy to send them over and walk you through setting them up for your operation.


Download templates:





Douglas Spanier

Living SMS every day!

 
 
 

Comments


bottom of page