Congratulations on your appointment as Compliance Monitoring Manager (CMM).
And now what?
You have been appointed as the Nominated Person for the Compliance Monitoring function in an organisation holding AOC (Part-ORO), CAMO (Part-CAMO), and AMO (Part-145) approvals under EASA regulations.
This is a critical and independent role. You provide objective oversight to ensure the organisation complies with all applicable requirements, both regulatory and its own procedures. You report directly to the Accountable Manager (AM), maintain full independence from operational functions, and are responsible for the effective operation of the Compliance Monitoring System (CMS).
Remember: the Accountable Manager holds the ultimate accountability, you run the CMS on their behalf.
The plan below is practical, risk-based, and aligned with current EASA AMC/GM requirements (including AMC1 ORO.GEN.200(a)(6), AMC1 CAMO.A.200(a)(6), AMC1 145.A.30(c) and (ca), and related guidance). It is designed for a typical integrated organisation; adjust it according to your organisation’s size, complexity, and the current maturity of the CMS.
Core Principles for Success
Independence & Access — Audits must be performed by competent personnel who are not responsible for the area being audited. You must have unrestricted access to all parts of the organisation and its contracted parties.
Value-Add Mindset — Position yourself as a supportive partner for safe and compliant operations, not merely a “policeman”.
Documentation & Traceability — Every activity, decision, finding, and action must be fully documented and auditable.
Integration with SMS — Work closely with the Safety Manager. The CMS is a key component of the overall Management System and feeds directly into the Safety Management System.
Proactive & Risk-Based Approach — Focus on risk-based auditing, trend analysis, and preventive actions rather than purely reactive compliance.
Competence — Ensure you and your audit team maintain the necessary knowledge, skills, and experience (regulatory, auditing techniques, human factors, etc.).
Day 1: Orientation and Establish Your Position
Focus on settling in and securing visible support from the top.
Meet the Accountable Manager first. Discuss expectations, priorities, reporting lines and frequency, any urgent issues, confirmation of direct access, independence safeguards, and resource allocation.
Complete HR and administrative onboarding (system access, security, IT, etc.).
Review your job description and the evidence package that was (or will be) submitted to the competent authority for your nomination/acceptance.
Obtain a high-level overview of the organisation (organisation chart, key contacts, facility layout if relevant).
Begin high-level familiarisation with the core Compliance Monitoring procedures and the Organisation Management Manual (OMM) (or equivalent overarching manual).
Review the following key documents:
Declaration of Compliance
Full compliance checklists
Current annual audit plan and its status
Open findings (internal and external)
Existing audit checklists and templates
Confirm that a Management of Change (MoC) process was followed for your appointment and that any identified safety/control measures have been implemented.
Goal: Leave Day 1 with clear top-level support, confirmed independence, and basic operational access.
Week 1: Deep Immersion and Current-State Assessment
Build a clear picture of the current situation and identify immediate priorities. People hate surprises, value transparency.
Conduct one-to-one meetings with other Nominated Persons, department heads, and existing auditors. Introduce yourself positively and listen carefully to their observations on compliance culture and inter-departmental interfaces (AOC–CAMO–AMO).
Perform a detailed review of the existing CMS:
Confirm location, validity, and currency of all AOC, CAMO, and AMO certificates and approvals.
Review the current full compliance checklist, Declaration of Compliance, and annual audit plan.
Examine recent audit reports and the status of all open findings.
Review the status of open and closed remedial/corrective and preventive action plans (RAPs/CAPs).
Assess allocated resources (man-hour plan, including leave and bank holidays).
Review oversight arrangements for contracted organisations (especially important for CAMO oversight of Part-145 organisations).
Familiarise yourself with all tools and systems (audit software, document control, occurrence reporting, etc.).
Review key regulatory references at a high level (essential requirements, Part-ORO, Part-CAMO, Part-145, relevant AMCs/GMs) and map them to the organisation’s activities.
Identify quick wins and any red flags (e.g., overdue actions, coverage gaps).
Goal: Obtain a comprehensive understanding of the current strengths, weaknesses, and immediate priorities of the CMS.
Month 1: Gap Analysis, Programme Design, and Initial Execution
Move from assessment to structured action.
Conduct a formal gap analysis of the current CMS against applicable EASA/ICAO requirements (annual coverage, independence, feedback to the AM, contractor monitoring, etc.).
Develop or significantly refine the Annual Audit Plan:
Risk-based schedule covering all AOC, CAMO, and AMO activities, interfaces, and contracted work.
Balanced mix of document reviews, interviews, observations, and product/process audits.
Include unannounced audits where appropriate.
Define clear responsibilities, checklists, and reporting templates.
Update or create supporting documentation (audit procedures, CAP tracking system, and any necessary manual amendments — coordinate with Document Control).
Begin executing or shadowing audits (start with lower-risk areas).
Establish regular routines: 1:1 meetings with the AM, coordination with the Safety Manager, Part-IS NP and input into Management/Safety Review processes.
Identify and plan any personal or team competence development (audit techniques, regulatory updates, human factors, etc.).
Assess resource needs (auditor time, tools, training, or external support) and present proposals to the AM.
Verify with the competent authority the organisation’s current position under Performance-Based Oversight (PBO).
Goal: A documented, regulator-aligned audit programme with clear momentum on execution and follow-up.
First 6 Months: Implementation, Relationship Building, and Momentum
Focus on delivery, culture, and measurable progress.
Execute the audit plan progressively, prioritising high-risk areas (maintenance control, airworthiness reviews, contracted maintenance, flight operations/training/ground interfaces, etc.).
Drive rigorous RAP/CAP follow-up: ensure proper root cause analysis, realistic timescales, verification of implementation, and effectiveness checks. Escalate unresolved issues to the AM when necessary.
Build strong cross-departmental relationships through constructive, transparent engagement. Always explain findings in the context of safety and compliance benefits.
Integrate CMS outputs with the SMS (share data, trends, and lessons learned).
Define and monitor key performance indicators (audit completion rate, CAP closure time and trends, repeat findings, etc.).
Address any resource or competence gaps and develop the internal audit team where applicable.
Prepare inputs for Management Review and Safety Review Board (SRB) meetings and any upcoming authority oversight activities.
Document all processes thoroughly to ensure traceability and enable future self-audits of the CMS.
Goal: Visible improvement in compliance posture, timely closure of findings, strong stakeholder trust, and a “surprise-free” CMS.
First Year: Full Cycle, Maturity, and Continuous Improvement
Achieve a robust, sustainable, and effective system.
Complete at least one full annual cycle of audits covering all relevant areas for AOC, CAMO, and AMO (including subcontracted activities).
Conduct a comprehensive effectiveness review of the CMS: analyse trends, CAP effectiveness, stakeholder feedback, regulatory changes, and alignment with the SMS.
Drive continuous improvement: update procedures, refine the risk-based approach, explore digital tools, and implement lessons learned.
Develop a longer-term CMS strategy (e.g., 3-year roadmap aligned with organisational objectives).
Maintain and demonstrate personal and organisational competence (update evidence as required and ensure adequate deputy arrangements).
Strengthen regulatory liaison and maintain high readiness for authority audits and inspections.
Contribute to broader safety culture initiatives (compliance awareness, recognition of positive behaviours, etc.).
Deliver a formal and effective Annual Compliance Status Report to the Accountable Manager and senior management.
Goal: A mature, effective, and continuously improving CMS that demonstrably supports safe operations and regulatory compliance.
Additional Tips and Best Practices
Common pitfalls to avoid: Insufficient resources, weak or delayed RAP/CAP follow-up, poor communication leading to resistance, and any compromise of true independence.
Key interfaces: Pay special attention to AOC–CAMO–AMO hand-offs and the oversight of contracted Part-145 organisations, including conracted maintenance.
Resources: Latest EASA Rules, AMC/GM on the EASA website, your competent authority’s guidance material, and approved training providers.
Flexibility: In smaller or non-complex organisations, some flexibility exists, but independence and competence must always be demonstrable.
If you need auditor training, compliance monitoring courses, manual templates, or additional support, feel free to contact mycs.swiss:
+41 79 287 80 99 or sms@mycs.swiss