
Landing Aero Article
Part 135 SMS Recordkeeping Requirements and Retention Rules
Summary
- 01Retention follows the evidence category: SRM outputs remain while controls are relevant, assurance outputs have a five-year minimum, training follows employment, and specified communications have a calendar-month minimum.
- 02Covered existing certificate holders must implement SMS and declare compliance by May 28, 2027. Applicant status can require implementation upon certification, so establish the applicable pathway first.
- 03Link each retained output to its authoritative source, owner, decision history, control and retention basis. Closing a hazard does not itself permit deletion of its risk assessment.
- 04Test exports for readable relationships, historical versions, attachments, permissions, corrections, retention and recovery. A spreadsheet or export feature alone does not demonstrate a complete evidence chain.
- 05Evaluate packaged software and integration through representative operator records. Supplier capabilities support the process, while the operator retains responsibility for evidence and compliance.
Inside this article
- 01Executive Summary
- 02Introduction and Background
- 03Key Changes and Applicable Timing
- 04Implementation Considerations and Process Changes
- 05Provenance, Access and Correction Controls
- 06Export and Retrieval Tests
- 07Packaged SMS Versus Integration Decisions
- 08Data Analysis and Evidence
- 09Case Studies and Real-World Examples
- 10Implications and Future Directions
- 11Frequently Asked Questions (FAQs)
- 12Conclusion
Executive Summary
Part 135 SMS recordkeeping requirements in the United States use different retention rules for different evidence. Under 14 CFR ยง5.97, safety risk management (SRM) outputs remain available while the control remains relevant [1] [2]; safety assurance (SA) outputs have a five-year minimum [3] [4]; individual SMS training records last for the person's employment [5]; and specified safety communications have a 24-consecutive-calendar-month minimum, subject to applicable exceptions. [6] Treating all records as short-lived reports would miss the continuing relationship between a hazard, its control and the operation.
For existing certificate holders covered by ยง5.9(a), the implementation and declaration deadline is May 28, 2027. [7] [8] The Federal Aviation Administration (FAA) publishes separate applicant-status timelines, including implementation upon certification for new applications submitted on or after May 28, 2024. [9] Operators should establish their applicable certification pathway before making the existing-holder date their project deadline. The narrowly defined sole-individual exception also requires examination; operating with one pilot does not itself establish eligibility. [10]
This report proposes a source-to-retention map linking reporting, operational references, risk decisions, controls, assurance findings, learning records and communications. It is an evidence design, not a mandated database schema: the final rule leaves implementation methods to the organization. [11] A useful acceptance test retrieves a complete hazard history, shows the version of each decision and control, explains each record's retention basis, and produces an export another person can understand. SMS Pro publicly documents safety-data export, but that feature alone does not demonstrate preservation of an operator's entire evidence chain. [12]
Access should follow purpose. Confidential reporting, general management dashboards and raw flight-data access need separate decisions. Advisory Circular (AC) 120-82 addresses voluntary Flight Operational Quality Assurance (FOQA) programs; the operator's approved program governance must determine what can leave that environment. [13] Backup and recovery demonstrations are equally practical: the Cybersecurity and Infrastructure Security Agency (CISA) recommends testing backup availability and integrity. [14] Flight Safety Foundation distinguishes implementing an SMS framework from showing that it functions as intended. [15] The purchasing decision should therefore turn on traceable evidence, demonstrated retrieval and accountable ownership, with software features supporting the operator's safety processes.
Introduction and Background
A safety manager may have a reporting application, flight and dispatch records, learning records, manuals and shared folders, yet still struggle to assemble the evidence behind a closed hazard. The central question is whether those sources preserve the decisions and outputs that the operator must retain. Section 5.95 addresses the maintained safety policy and SMS processes and procedures; ยง5.97 addresses process-output, training and communication records. They are related obligations, but a current manual does not substitute for the history of its application. [16]
The jurisdiction here is United States federal aviation regulation. The retention analysis concerns FAA Part 5 as applied to Part 135 operations. Canadian and European operators need their own applicable framework; the US dates and clocks should not be transplanted into another jurisdiction. FAA AC 120-92D, issued May 21, 2024 and listed as active when researched, provides implementation guidance for aviation service providers. [17]
The record-level approach complements practitioner advice. The National Air Transportation Association (NATA) encourages reuse of existing processes where practical, while the National Business Aviation Association (NBAA) describes SMS around hazard identification and a process for managing those hazards. (Source: nata.aero) [18] Start with what each process actually produces, then identify the authoritative source, responsible person and means of retrieval. This inventory-first approach follows NATA's advice to reuse existing processes. (Source: nata.aero)
This also explains where custom integration fits. LANDING.AERO describes applications built around individual operational needs rather than an off-the-shelf solution. (Source: www.landing.aero) For this subject, that is an integration perspective, not evidence that a particular SMS configuration meets Part 5. Apply this evidence checklist through the operator's approved procedures, manuals, operations specifications and SMS expertise.
A practical inventory should identify:
- Process outputs: the evidence produced by reporting, risk decisions, assurance, training and communication.
- Authoritative source: where the maintained original or controlled version resides.
- Responsible owner: who verifies completeness and interprets retention.
- Reference links: how supporting operational data connect to the retained output.
- Access purpose: who needs identifiers, detailed evidence or only summaries.
- Retrieval route: how the organization furnishes the evidence outside the application's normal screens.
These are proposed inventory fields. Operators should adapt them to their approved procedures and actual responsibilities, taking account of organization size and complexity. (Source: nata.aero)
Key Changes and Applicable Timing
Establish the certificate or application pathway
The SMS final rule became effective May 28, 2024. [19] For existing Part 135 holders within ยง5.9(a), developing and implementing SMS and submitting a declaration of compliance are due by May 28, 2027. [20] An implementation plan built around that date should include the ability to demonstrate completed processes, not merely purchase an application.
The FAA's published timeline distinguishes applicants in the Initial Certification Phase before the rule's effective date, applicants on the Applicant List before January 21, 2025, new submissions and preapplication cases. [21] The listed Applicant List group receives the May 28, 2027 date. [8] The table also assigns implementation upon certification to applications in the Preapplication Phase on or before May 28, 2024. [22] These distinctions make applicant status a fact to document with the responsible FAA office.
Do not infer an exemption from fleet size or a marketing description of the business. Section 5.9(e) identifies organizations in which a single pilot is the sole individual performing all necessary functions related to, or directly supporting, safe operation, and excepts specified provisions including ยง5.93 and ยง5.97(d). [10] The operator should record the applicability decision before configuring retention rules.
Separate documentation from accumulated evidence
The maintained policy and procedures belong to the documentation layer. Process outputs belong to the evidence layer. Their connection should be explicit: a risk assessment should identify the method applied, and a communication should identify the procedure version being explained. This implements the distinction between documentation under ยง5.95 and records under ยง5.97 without pretending that Part 5 prescribes a particular data model. [16] [11]
An existing manual repository can remain authoritative if the evidence system points to an identifiable version. A copied attachment is useful only if the operator can explain whether it is the controlled source, a snapshot or a convenience copy. NATA's emphasis on organizational size and complexity supports choosing an arrangement suited to the actual operation. (Source: nata.aero)
Capture interface communications as evidence
The communications category extends to the required hazard notifications under ยง5.57, as well as internal safety communications under ยง5.93. [23] The final-rule explanation emphasizes that hazard information in SRM outputs is not limited to the communications retention period. [24] A sent notice and the assessment behind it may consequently have different retention bases.
The resulting process change is straightforward: preserve the actual notice, its intended recipient, its issue date and the evidence of transmission available to the operator. Keep the underlying hazard and control relationship independently. Closing the correspondence thread should not automatically close the control or start a deletion timer for its risk-management record.
The SMS final rule became effective on this date.
Existing Part 135 holders within ยง5.9(a) must develop and implement SMS and submit a declaration of compliance.
Implementation Considerations and Process Changes
Build the source-to-retention and access matrix
Table 1 translates the record classes into a proposed operating inventory. Rule text supplies the retention minima; owner, trigger implementation, access and export design are recommendations to be established in operator procedures. Calendar calculations and disposal decisions need a documented method.
| Record type | Rule or source | Suggested owner and authoritative source | Trigger and minimum retention | Access design | Export evidence |
|---|---|---|---|---|---|
| SMS policy and procedures | ยง5.95 requires maintained documentation. [25] | Safety manager; controlled manual repository | Maintain applicable documentation; this section does not give a numerical archive period for superseded versions | Controlled staff readership; document approval roles | Applicable version, approval and effective-status record |
| SRM outputs | ยง5.97(a) | Process owner and safety manager; hazard/risk register | Retain while the control remains relevant; reassess relevance before disposal. [2] | Authorized assessors and approvers; limited reporter identifiers | Hazard, analysis, decision, control versions and continuing relevance |
| SA outputs | ยง5.97(b) | Assurance owner; audit, monitoring and assessment repositories | At least five years [4]; use a defined record date and examine any overlapping basis | Reviewers and accountable management; restricted detailed evidence where appropriate | Findings, monitoring basis, assessments, corrective action and follow-up |
| SMS training | ยง5.97(c), referring to ยง5.91 | Training owner; learning records linked to employment status | Retain throughout the individual's employment [26]; latest completion does not replace the retained history | Training administrators and authorized managers | Individual, course/version, completion evidence and employment-status basis |
| Internal safety communication | ยงยง5.93 and 5.97(d) | Communication owner; notice repository or controlled distribution system | At least 24 consecutive calendar months [27]; preserve provision date and apply applicable exceptions | Intended audience; restricted underlying confidential material | Actual message/version, audience and available distribution evidence |
| Hazard notice to an interfacing person | ยงยง5.57 and 5.97(d). [24] | Interface owner; correspondence linked to hazard | Communications minimum applies; preserve SRM outputs independently while relevant | Authorized external recipients and internal interface owner | Notice, addressee, transmission evidence and linked hazard/control |
The matrix should be populated with actual source names, not generic application categories. Where an output serves several purposes, preserve its connections and apply all applicable retention bases before releasing it for disposal. This is a conservative design recommendation, rather than a new retention period attributed to the FAA.
Decide which operational material becomes an SMS output
An operations log, maintenance reference or flight-data trend may support an assessment without making every source row a permanent SMS record. Identify the evidence used, preserve the decision-bearing output, and decide which supporting snapshot or reference is necessary to reproduce its reasoning. Section 5.71 requires data acquisition to monitor safety performance and expressly includes auditing operational processes and systems. [28] [29]
The record map should answer these questions:
- Input provenance: which report, source file or operational reference informed the assessment?
- Assessment basis: which method, assumptions and evidence were available?
- Decision authority: who accepted or returned the assessment?
- Control responsibility: who implements and monitors the control?
- Assurance dependency: which findings will test whether it works?
- Communication dependency: which people need the result or changed procedure?
- Retention dependency: which linked records must survive closure?
- Source stability: can the operator still resolve the reference after an application migration?
A map of links is useful only if the referenced material remains accessible for its required purpose. SMS Pro's documented safety-document version control is one capability to examine when references point into a manual repository. [30] An export capability should therefore be tested against real dependencies. AviSMS, for example, describes an Excel workbook separating occurrences, hazards, audits and findings; that describes output organization, not proof that attachments and relationships survive an operator's export. (Source: www.avisms.aero)
- SRM outputs remain while the control remains relevant. Reassess relevance before disposal.
- SMS training records remain throughout the individual's employment. A latest completion does not replace retained history.
- Safety assurance outputs have a five-year minimum. Define the record date and examine overlapping retention bases.
- Specified safety communications have a minimum of 24 consecutive calendar months, subject to applicable exceptions.
Where an output serves several purposes, preserve its connections and apply all applicable retention bases before releasing it for disposal.
A current policy, a reporting inbox and a dashboard become useful together when those relationships can be retrieved.
Provenance, Access and Correction Controls
Preserve the history needed to explain a decision
A recommended evidence record identifies its source, creation time, responsible role, version, decision status and links to predecessor records. A correction should identify what changed, who changed it and why. Do not overwrite the earlier basis when a later observation changes the assessment. Ideagen's documented audit trails and validation workflows are examples of features to demonstrate against this requirement in the operator's design. [31]
The National Institute of Standards and Technology (NIST) provides a useful security design reference: SP 800-171 Revision 3 describes audit-record content and protection from unauthorized access, modification and deletion. [32] [33] Its scope concerns controlled unclassified information in nonfederal systems; this report borrows concepts as design references and does not make that publication an additional Part 5 obligation.
For a risk assessment, distinguish draft, reviewed, accepted and superseded states using the operator's own terminology. Identify both the original control and its replacement. Ideagen documents version control and approval chains, illustrating capabilities to ask a supplier to demonstrate against that workflow. [34] Public feature text does not establish how an operator's imported historical records will behave.
Separate confidential intake from broad analysis
For applicable organizations, ยง5.71(a)(7) requires confidential employee reporting without concern of reprisal. [35] Confidentiality should drive access decisions at intake: an analyst may need the hazard description while a designated follow-up role needs the reporter's identity. The final rule did not make anonymous reporting universally mandatory. [36]
Use a permission model with a stated purpose for each access class:
- Reporter follow-up: access to contact details where authorized and needed.
- Risk assessment: access to relevant operational facts and supporting evidence.
- Control ownership: access to assigned actions and implementation requirements.
- Management oversight: access to status, decisions and performance summaries.
- Record administration: access to controlled correction and retention functions.
- External production: a reviewed export appropriate to the request and applicable obligations.
NIST's least-privilege concept ties access to assigned tasks. [37] SMS Pro documents role-based permissions, but the operator should test whether those roles cover attachments, search results, exports and administrative functions, not only the main screen. [38]
Keep FOQA and external reporting boundaries explicit
AC 120-82 describes removal of crew-identifying information from view and a gatekeeper's limited access to identifying information for follow-up. [39] [40] Its illustrative plan also addresses destruction after the program retention period. [41] These provisions concern FOQA governance; they do not establish a universal raw-data retention period under ยง5.97.
The safe architectural question is what approved, appropriately de-identified FOQA output may support an SMS assessment. Preserve a reference to the governed source and approved output. Do not copy protected raw flight traces or re-identification keys into a general SMS table by default. The operator's approved FOQA plan and agreements control that boundary.
Likewise, NASA's Aviation Safety Reporting System (ASRS) is an external program where NASA processes reports as a third party. [42] Its participation does not replace other required reports. [43] An internal confidential SMS record should not be described as having ASRS program protections merely because its subject matter concerns aviation safety. The program's published participation policy is the reference for assessing its separate scope. [42]
Export and Retrieval Tests
Define a complete evidence package
A recommended hazard evidence package combines the retained outputs with a readable index. It should identify the hazard, versions of the assessment, accepted control, owner, assurance follow-up, relevant training and communication evidence. The purpose is to make the package understandable without reconstructing relationships through personal recollection.
FAA AC 120-78B, issued December 11, 2024 and listed as active, supplies electronic-record and signature guidance. [44] Its discussion includes Operations Specification (OpSpec) A025 authorization for electronic recordkeeping and signatures for covered operators. [45] A Part 135 operator should check its actual authorization and records scope with the FAA before relying on a new electronic arrangement.
The following tests are proposed acceptance criteria:
- Relationship test: export a hazard with its risk assessment, controls and follow-up; verify that links remain intelligible.
- Version test: retrieve the accepted version and an earlier superseded version with their separate status.
- Attachment test: open supporting files from the exported package without the live application's session.
- Access test: compare authorized and restricted exports, including search and bulk-download paths.
- Correction test: reproduce the before-and-after record and the documented reason for the change.
- Retention test: show how different bases prevent premature removal of linked outputs.
- Recovery test: restore the package from backup and verify its contents.
An export label is insufficient evidence for these tests. AviSMS describes an administrator-readable log of every write; the demonstration should show whether relevant history can also be furnished outside the administrative screen. (Source: www.avisms.aero) NIST's guidance about preserving original audit content and time ordering is a useful reference for the review. [46]
Test loss of access, not just normal operation
Backup coverage should include records, attachments, relationships and the means of interpreting them. CISA recommends offline encrypted backups of critical data and testing their availability and integrity during recovery. [47] [14] FAA electronic-record guidance also discusses maintaining record access during system failure. [48] The operator should document who performs the restore and who signs off that the restored evidence is usable.
A supplier change is another retrieval test. Request a sample exit package before committing to the arrangement. Determine whether it contains stable identifiers, readable files, historical versions, approvals, distribution evidence and an explanation of the exported fields. A machine-readable extract and a human-readable index serve different purposes and can complement one another.
There is also a distinction between giving the FAA direct application access and furnishing required records. Section 5.9(d) requires necessary SMS information and data upon request; AC 120-78B distinguishes voluntary direct system access from provision of the records themselves. [49] [50] Design a reviewed production route that supports the request without treating unrestricted application access as the default.
- 01Assemble an indexed package
Include the hazard, assessment versions, accepted control, owner, assurance follow-up, relevant training and communication evidence.
- 02Verify relationships and versions
Export linked risk assessments, controls and follow-up. Retrieve accepted and superseded versions with their separate status.
- 03Open files and test access
Open supporting files without the live application session. Compare authorized and restricted exports, search and bulk downloads.
- 04Check corrections and retention
Reproduce the record before and after correction, including the reason. Show how different retention bases prevent premature removal.
- 05Restore and verify the package
Restore the evidence package from backup and verify its contents.
- 06Request a supplier exit package
Check stable identifiers, readable files, historical versions, approvals, distribution evidence and explanations of exported fields.
Packaged SMS Versus Integration Decisions
A packaged SMS product may cover much of the workflow. Public documentation provides examples: Ideagen describes audit trails with validation workflows; ARC describes checking receipt of current document versions; and SMS Pro describes initial and recurring SMS training records. [31] [51] [52] These are supplier statements about capabilities, not independent demonstrations that an operator meets its obligations. No jurisdictional equivalence or operator authorization is inferred from the feature examples.
An integration project becomes useful when the required evidence spans applications. The question is whether references, versions, ownership and retention decisions can be maintained across those sources. FAA guidance recommends specifying the record types maintained in each system where multiple systems are used. [53] The operator should be able to explain that arrangement to both its own staff and a reviewer.
Table 2 lists proposed request for proposal (RFP) questions. The questions focus on observable behavior; they should also be applied to internal builds.
| Question | Demonstration to request | Acceptance decision |
|---|---|---|
| Can retention follow control relevance? | Keep SRM outputs when a case is closed but a control remains active | Operator can explain the continuing relevance and block premature deletion |
| Can records have overlapping retention bases? | A communication attachment also supporting an assessment | Every applicable basis remains visible and governs disposal |
| How are versions and approvals exported? | Accepted and superseded versions with approval history | Reviewer can reconstruct what was decided and when |
| How are permissions applied outside the screen? | Restricted user search, attachment access and bulk export | Confidential detail follows the intended access purpose |
| What does communication evidence contain? | Actual notice, document version, audience and receipt evidence where available | Operator can show what was provided and to whom |
| What survives recovery and supplier exit? | Restored sample and independent export package | Relationships and files remain readable without undocumented reconstruction |
| How are migrations and corrections controlled? | Imported record linked to source and a later explained correction | Source identity, history and responsibility remain traceable |
The preferred answer is a demonstration using representative operator records, appropriately handled, rather than a general promise of compliance. ARC documents individual performance reports from quizzes, while Ideagen documents approval chains. Ask to see how those specific outputs enter the retained evidence package. [54] [34]
A custom software supplier can support data integration without replacing SMS expertise. LANDING.AERO's first-party description includes integrating disparate sources, automating workflows and building dashboards. (Source: www.landing.aero) That describes the engineering scope; it is not a packaged SMS claim or a statement of FAA approval.
ARC's description of checking receipt of current document versions illustrates why the acceptance exercise should include distribution history as well as document storage. [51]
Keep the decision criteria parallel:
- Process fit: the operator's actual workflow can be represented.
- Evidence completeness: required outputs and relationships are retrievable.
- Retention control: distinct legal bases can be implemented and explained.
- Access control: identifiers and supporting files follow authorized purposes.
- Operational ownership: people remain responsible for assessment and action.
- Migration control: imported and corrected records preserve provenance.
- Exit capability: evidence survives a supplier or application change.
- Demonstrated behavior: acceptance rests on a reproducible test.
The FAA does not preapprove specific SMS services as satisfying the requirements, and using outside assistance does not transfer the operator's responsibility. [55] [56]
Data Analysis and Evidence
The quantitative core is a set of different clocks, not a market-growth forecast. Current ยง5.97 distinguishes a relevance-based period [2], a five-year floor [57], an employment-duration period [26] and 24 consecutive calendar months. [27] The open-ended categories require status information; a date field alone cannot determine when retention ends.
For implementation, record the underlying event and the method used to calculate the retention boundary. The communications wording should be implemented using calendar-month logic, not silently converted into a fixed number of days. For assurance, define the relevant record date in procedures and preserve that date through migration. The regulation supplies the minimum; the proposed calculation method must be documented rather than attributed to text that does not specify every software detail.
The publication-date interval from October 9, 2026 to the covered existing-holder deadline of May 28, 2027 is 231 days, calculated as the difference between those dates, not a separate FAA allowance. [8] It is a planning interval for the stated publication date. An operator's applicable pathway can instead require implementation upon certification. [9]
The final-rule analysis estimated approximately 1,848 Part 135 operators would be required to implement SMS. This is the FAA's 2024 rulemaking estimate, not a measured count of compliant operators or a current software market size. [58] No adoption percentage, vendor performance ranking or time-saved claim is inferred from that population.
Use internal acceptance measurements with explicit definitions:
- Retrieval completeness: count required output categories present in the tested package against those expected for the selected workflow.
- Link integrity: identify references that resolve and those requiring corrective work.
- Version completeness: compare the retained decision history with the history expected under the operator's process.
- Permission behavior: document which tested roles can view, change and export each evidence class.
These are proposed local measures, with no invented benchmark or promised result. They should supplement qualitative review of the evidence, rather than replace judgment with a dashboard score. Flight Safety Foundation emphasizes whether safety processes influence decisions and improvements. [59]
External evidence needs its own limitations. NASA's public ASRS narratives are sanitized for identifying details, and NASA states that it does not verify or validate the reports. [60] [61] Such material can inform questions and context, but should not be represented as verified operator performance or substituted for the operator's own traceable assurance outputs.
Case Studies and Real-World Examples
Report-to-export lifecycle (Hypothetical Example)
Consider an unnamed charter operator receiving a report that a handover workflow leaves uncertainty over who acknowledges a revised operational document. This is a hypothetical process-design example, with no claimed event, measured risk rating or demonstrated outcome.
The record starts as an intake item with a restricted reporter-contact link. It becomes a hazard record after the safety team applies the operator's assessment process. The proposed control assigns acknowledgement responsibility and makes the relevant document version visible. Before implementation, the operator evaluates the proposed control through its risk process; ยง5.55(d) requires that acceptability evaluation before implementing a safety risk control. [62]
Table 3 shows the proposed linked history. Version letters are illustrative identifiers, not regulatory fields or claimed product behavior.
| Stage | Record and version | Control status | Suggested owner | Retained evidence and access |
|---|---|---|---|---|
| Intake | Report A; source reference | Proposed | Intake reviewer | Original report; reporter identifiers restricted to authorized follow-up |
| Assessment | Hazard A; assessment A | Evaluated | Risk assessor and approval role | System context, assumptions, decision and proposed control |
| Implementation | Control A; changed procedure A | Active | Operational process owner | Assignment, acceptance, implementation evidence and applicable procedure |
| Assurance | Follow-up A | Active pending review | Assurance reviewer | Observation basis, findings and assessment of control performance |
| Communication | Notice A; procedure A reference | Active | Communication owner | Issued message, audience and available transmission or receipt evidence |
| Revision and export | Assessment B; control B; indexed package | A superseded; B active | Process owner and records administrator | Preserve predecessor links, approvals, status and retention bases |
The useful outcome of the exercise is an inspectable chain, not an asserted improvement in safety. The assurance review may confirm the control, identify a new hazard or determine that it is ineffective; ยง5.73(b) sends ineffective controls or new hazards back into SRM. [63] A case-status change should therefore preserve the history and any continuing control-relevance decision.
Communication evidence could include attendance rosters or read-and-initial records, examples discussed in AC 120-92D. [64] [65] The exported package should show the actual evidence used by this hypothetical process rather than imply that every notice must use either mechanism. A return to assessment should create an identifiable new decision, while leaving the earlier reasoning available.
Implications and Future Directions
The immediate priority is a records capability review against the operator's actual SMS processes. The absence of a mandated database schema gives flexibility, but it increases the importance of documenting why the chosen arrangement preserves usable evidence. The final rule explicitly allows solutions suited to organizational size and complexity. [66] A small operation and a larger multi-source operation can use different tools while explaining the same retention categories.
A records review should finish with concrete ownership decisions:
- Safety ownership: approve the classification of outputs and their relationship to controls.
- Operations ownership: maintain the implementation evidence and operational references.
- Training ownership: connect individual learning history with employment status.
- Information ownership: document permissions, correction, retrieval and recovery.
- Management oversight: review whether the evidence demonstrates functioning processes.
Training integration deserves particular care. AC 120-92D describes SMS training records as additional to other required training records. [67] Reuse of a learning system should preserve the SMS history needed for its own retention basis, rather than assume that another training schedule resolves the question.
Future automation should assist indexing, reconciliation and evidence-package preparation. Any AI-generated summary should remain visibly distinct from the accepted assessment and point to its sources. The operator should require human review of risk decisions and controlled changes, rather than treat generated text as proof that a control works. This is a proposed governance boundary, not a claim about a product's certified capability.
The same discipline applies to migration. Record which system owns each output, document transformations and test the resulting package. CISA's recovery-testing recommendation provides a practical external reference for preserving evidence access. [14] The goal is continuity of understandable records through normal changes in people, systems and suppliers.
Frequently Asked Questions (FAQs)
Does every SMS record have a five-year retention period?
No. ยง5.97 sets the assurance minimum at five years [4], while SRM outputs follow control relevance [1], training follows employment [5] and specified communications follow their calendar-month minimum. [6] Classify each retained output and examine overlapping bases before setting disposal rules.
Does closing a hazard allow deletion of its risk assessment?
Closure is not the rule's retention trigger. The operative condition for SRM outputs is continuing control relevance. [2] The operator should document the relevance decision and keep relationships to any replacement control.
Can a training system hold the SMS history?
It can form part of the proposed records arrangement, provided the operator establishes its completeness and retention behavior. SMS Pro documents initial and recurring SMS training, but that feature statement does not establish an operator's employment-linked retention configuration. [52]
Is exporting a spreadsheet enough for audit evidence?
Test it against the evidence expected from the operator's process. AviSMS documents a multi-sheet export; the operator must still verify relationships, attachments, approvals and readable history. (Source: www.avisms.aero) An export demonstration answers more than the file extension.
Conclusion
Part 135 SMS recordkeeping is an exercise in preserving understandable process evidence. The operator needs to explain the hazard, the accepted decision, the control that remains relevant, the assessment of its performance, the people trained and the safety information provided. A current policy, a reporting inbox and a dashboard become useful together when those relationships can be retrieved.
The report's proposed matrix separates maintained documentation, SRM outputs, assurance outputs, individual training and communications. It then connects each category to its authoritative source, owner, access purpose and retention basis. The hazard lifecycle adds the missing practical question: can a reviewer follow a change without losing the preceding decision?
For a purchasing or integration decision, start with a representative evidence package. Demonstrate retrieval, versions, permissions, correction, calendar calculations, recovery and supplier exit. Document what the test establishes and what still requires an operator-specific policy decision. These checks should be part of accepting the records arrangement, not a promise inferred from a feature list.
Packaged software, controlled documents and custom integration can each support that arrangement when matched to the operation. The decisive requirement is that the operator maintains the relevant evidence and can explain it. Software selection should follow that evidence model, with approved procedures, applicable authorizations and accountable safety expertise governing its use.
External Sources (67)
About
Landing Aero
We Build Flight Operations Software - custom applications designed for aviation.
Disclaimer
This document is provided for informational purposes only. No representations or warranties are made regarding the accuracy, completeness, or reliability of its contents. Any use of this information is at your own risk. Landing Aero shall not be liable for any damages arising from the use of this document. This content was generated with assistance from artificial intelligence tools, which may contain errors or inaccuracies. Readers should verify critical information independently. All product names, trademarks, and registered trademarks mentioned are property of their respective owners and are used for identification purposes only. Use of these names does not imply endorsement. This document does not constitute professional or legal advice. For specific guidance related to your needs, please consult qualified professionals.