IATA Operational Safety Audits program transformation into a Risk-Based framework represents an advancement in the effectiveness of the audit process. This approach delivers critical insights that empower IATA and non-IATA members to enhance their safety management maturity. Thanks to this evolution, the aviation industry takes a step toward improving safety in an ever-changing environment.

As of May 2025, more than 200 Risk-Based audits have been completed. The SMS maturity assessments have revealed important areas for improvement that must be addressed to ensure continuous improvement in safety management. One such area is outsourcing management, especially regarding the processes for selecting service providers to handle operational functions. Addressing these issues will be essential for improving safety standards across the industry. 

The standard IOSA ORG 1.6.1 requires air operators to implement a process to ensure they select service providers for operational functions based on relevant safety and security criteria. The selection process should aim to mitigate associated operational risks, considering the following range of challenges affecting providers:

  • Supply Chain Disruptions.  It leads to delays in parts delivery, equipment, and materials, which affect MRO and ground handling providers. 

  • Labor Shortages and Skill Gaps. The industry faces a shortage of skilled aviation personnel, especially in areas like maintenance, ground handling, and security. Therefore, service providers may struggle to maintain qualified staff, impacting service quality and safety.

  • Inconsistent Safety and Quality Standards. The variability in SMS maturity as well as regulatory compliance across regions and providers, makes difficult assessing key aspects such as safety culture and performance history during the selection process.

  • Integration issues. Such as integrating provider systems with airline IT, SMS, and ERP.

  • Cost vs. Quality Trade-offs. The increasing operational costs may push service providers to cut corners, affecting the balance between cost-efficiency and safety/reliability.

  • Geopolitical and Economic Instability. The regional conflicts, inflation, and currency volatility may affect provider stability and reliability.

What are the most common outsourced operational functions in the aviation industry?

  • Maintenance, Repair, and Overhaul (MRO). Line maintenance (Routine checks, daily inspections), Heavy maintenance (C-checks and D-Checks), Component repair and overhaul (engine, avionics, landing gear, etc)

  • Ground Handling Services. Passenger check-in and boarding, Ramp services, Baggage handling, aircraft marshalling, gate services. Aircraft cleaning and lavatory servicing. Specialized activities such as de-icing, anti-icing, aircraft dispatch, Flight planning, load control, and weight and balance documentation.

  • Cargo Handling. ULD management, dangerous goods handling, Customs clearance, Warehousing, and logistics.

  • Aviation Security Services. Passenger and baggage screening, aircraft guarding, access control, and perimeter security. Even though oversight remains with the state authority per ICAO Annex 17.

  • IT and Operational Support. Flight planning and dispatch systems, Reservation and ticketing platforms, EFB Solutions, A/C health monitoring and predictive maintenance tools, Cybersecurity and data management.

  • Training services. Initial and recurrent flight, cabin, ground, and maintenance crew training.

  • In-Flight Catering. Meal delivery and loading, Galley equipment handling.

Given the wide range of operational functions that commercial aviation outsources today. Service providers may bring hazards to airlines' operations and eventually increase the risk of experiencing non-desired outcomes when the control and management of these outsourced operational functions are overlooked.

What are the Safety and security-related criteria an AOC should incorporate to inform the service provider selection process?

The following criteria list is not exhaustive. However, it may help to outline the basic aspects to consider when assessing a service provider’s suitability to fit the AOC safety and security requirements.

Safety Criteria

  • Regulatory Compliance: The service provider should hold valid certifications (e.g., AMO, GSP) and comply with ICAO, EASA, FAA, or local CAA regulations, as required.

  • SMS Implementation: The service provider should have a functional SMS with hazard/incident reporting, risk assessment, and safety assurance processes. When applicable, considering the operational activity to be outsourced and local regulations.

  • Safety Performance Indicators (SPIs): The provider should have historical safety data, such as incident/accident rates and audit findings. When applicable, considering the operational activity to be outsourced and local regulations.

  • Training and Competency: The provider should be able to demonstrate staff qualifications, recurrent training programs, and their level of compliance with AOC’s training requirements.

  • Equipment and Infrastructure: The service provider should have a ground support equipment maintenance program and a business continuity plan to mitigate supply chain disruptions, IT systems disruptions, and labor shortages.

  • Emergency Response Capability: The service provider should be able to align with the operator’s ERP and participate in joint drills.

Security Criteria

  • Security Program: The service provider should comply with ICAO Annex 17 and national security programs, where applicable, depending on the operational activity being outsourced.

  • Access Control: The service provider should demonstrate procedures for ID checks, restricted area access control, and background checks.

  • Cargo and Baggage Screening: The service provider should demonstrate adherence to screening protocols and secure supply chain practices.

  • Incident Reporting: The service provider should have mechanisms for reporting and investigating security breaches.

These criteria should be tailored to the AOC operational needs and the scope of outsourced operational functions, depending on the level of specialization and requirements in terms of training and standard operating procedures. 

What if there is only one service provider available?

When there is only one available service provider, it is crucial to manage the associated risks using a structured approach. The first step is to document the justification for selecting a single source, explaining why no alternative providers are feasible. The second step is to create a comprehensive risk assessment to identify and address potential safety, operational, or compliance risks that may arise due to the lack of competition.

To maintain high standards, the air operator should enhance oversight by increasing the frequency of audits, inspections, and performance evaluations. Additionally, the agreement should include exit clauses that allow for contract termination if the provider fails to meet established safety or security expectations, ensuring accountability and operational resilience.

How can the service provider continuously fulfil safety and security requirements?

The safety and security requirements are important not only for the selection process but also for ensuring these requirements are fulfilled during the agreement period. This is critical to effective outsourcing management.

The agreement with service providers should then incorporate means to monitor the provider's safety performance. To achieve a good level of monitoring, it is advisable to include:

  • Defined Safety and Security KPIs: E.g., incident rates, audit scores, training completion.

  • Safety Management System (SMS), requirements to maintain a functional SMS aligned with ICAO Annex 19. Include obligations for:

    • Hazard identification and risk assessment

    • Safety/security reporting obligation

    • Safety performance monitoring

    • Facilitating information and evidence to investigate incidents conducted by the operator

    • Conduct joint safety review meetings with the provider

    • Discuss performance, incidents, and improvement plans

In scenarios where the service provider does not have an SMS because regulations do not require it, The provider may require to incorporate some of the operator's SMS process, for instance, use the operator’s reporting channels and develop the capacity to conduct or support safety investigations in the scope of the outsourced operational function. 
  • Include Safety Performance Indicators (SPIs) such as:

    • Number of relevant safety reports submitted

    • Incident/accident rates

    • Define acceptable thresholds and penalties for non-compliance.

  • Quality management system (QMS) requires maintaining a functional QMS aligned with local regulations. Include obligations for:

    • Give the operator the right to conduct audits and inspections. 

    • Include requirements for notification of regulatory changes or findings.

    • Corrective Action Requirements, timelines, and responsibilities for addressing and escalating findings.

  • Include Key performance indicators (KPIs) such as:

    • Audit findings and closure rates

    • Time to close safety findings

    • Training completion rates

    • Audit scores and trends

  • Training Standards. Minimum training requirements for provider personnel.

    • Define minimum training standards and recurrent training intervals.

    • Require evidence of staff qualifications and training records.

  • Emergency Coordination: Joint response protocols and communication channels.

  • Include Termination Clauses: For non-compliance with safety/security standards.

When should the service provider selection process be triggered?

The selection process for a service provider should be formally initiated under several operational circumstances. These triggers include:

  • Operating a New Destination. It often requires new ground handling, maintenance, or security services.

  • Outsourcing an Operational Function. When a function previously managed internally is outsourced, it is essential to evaluate external capabilities thoroughly. 

  • Contract Expiration. When the term of an existing service provider’s contract is nearing its end, a review or re-tendering process should be initiated. 

  • Change in Scope of Services. Any expansion or reduction in services necessitates a reassessment to ensure the provider can meet new requirements.

  • Performance Issues. Recurrent safety or security non-conformities or negative audit findings should prompt a reconsideration of the provider relationship.

  • Regulatory Changes. New laws or standards may require evaluating the provider's compliance and capabilities.

  • Mergers or Acquisitions. Changes in the provider’s structure or service quality due to mergers or acquisitions make it necessary to reassess their suitability.

These circumstances relate to significant operational changes. Therefore, the operator’s management of change procedure to conduct a risk assessment is a complementary activity to drive decision-making when selecting or retaining a service provider. 

What are some specific challenges you've encountered when selecting service providers in your own operations, and how did you address those challenges to ensure safety and quality?