Insights7 min read
The Part 5 SMS deadline and what it asks of Part 135 operators
Existing Part 135 certificate holders must implement a safety management system and declare compliance by May 28, 2027. What the rule requires in hazard identification, risk management and safety assurance, and where day-to-day trip monitoring fits.

On April 26, 2024, the FAA published its final rule on safety management systems, extending the requirements of 14 CFR Part 5 to every Part 135 certificate holder, to commercial air tour operators holding a Letter of Authorization under 14 CFR 91.147, and to certain manufacturers [1]. The rule took effect on May 28, 2024. For operators already certificated at that date, the more important date is still ahead: May 28, 2027.
With a little more than seven months remaining, many directors of operations and safety managers are moving from planning to implementation. This article summarizes what Part 5 asks of a Part 135 operator, drawing on the regulation and the FAA's advisory circular, and considers where routine trip monitoring can contribute evidence to a working system.
The rule and the deadline
The FAA described the rule as responding to a Congressional mandate and to recommendations from the National Transportation Safety Board and two aviation rulemaking committees, and as aligning the United States more closely with Annex 19 to the Chicago Convention [1]. The NTSB had recommended in 2016 that all Part 135 operators be required to establish SMS programs; in its 2024 special investigation of Part 135 accidents, it classified that recommendation as closed with acceptable action in light of the final rule [2].
Under 14 CFR 5.9, a person authorized to conduct Part 135 operations before May 28, 2024, must develop and implement an SMS that meets Part 5, and submit a declaration of compliance to the FAA, no later than May 28, 2027 [3]. Applicants for new authority must also develop and implement an SMS, and the SMS must be maintained for as long as the authority is held [3]. Organizations in which a single pilot performs all functions are excepted from a defined list of provisions [3].
The FAA's Advisory Circular 120-92D explains that the declaration of compliance is a legal document, signed by the accountable executive or another senior manager, stating that the organization has developed and implemented an SMS meeting Part 5 [4]. It also makes clear that the declaration is the beginning of oversight rather than the end: validation of SMS performance will occur as part of routine surveillance [4]. An operator must also make available to the FAA, on request, the information and data that demonstrate its SMS meets the requirements [3].
Four components, scaled to the operation
Part 5 requires an SMS to include four components: safety policy, safety risk management, safety assurance and safety promotion, each appropriate to the size, scope and complexity of the organization [3]. The advisory circular describes Part 5 as a performance-based rule that sets out a desired end state without prescribing the means of reaching it, and notes that while an operator may scale its methods, "this scalability does not allow the aviation organization to set aside any sections of part 5" [4].
Two of the four components carry most of the day-to-day operational work.
Safety risk management
Safety risk management begins with understanding the system. Part 5 requires it to be applied to new systems, revisions of existing systems, the development of operational procedures, and hazards or ineffective controls identified through safety assurance [3]. Each system analysis must consider the system's function and purpose, its operating environment, its processes and procedures, the personnel, equipment and facilities it relies on, and its interfaces, and the operator must maintain processes to identify hazards within that analysis [3]. The operator must then analyze the associated risk, define how acceptable risk is determined, develop controls, and evaluate whether the risk will be acceptable with a control in place before implementing it [3].
The advisory circular lists operational control, specifically dispatch and flight following, among the broad systems an operator might analyze, with crew scheduling among the subsystems [4]. It also gives a practical example of risk acceptance: dispatching a flight that presents a medium or high risk might require approval from the chief pilot or director of operations [4]. For many Part 135 operators, the trip itself is therefore the point at which risk controls are applied most often and most visibly.
Safety assurance
Safety assurance is where an operator demonstrates, with data, that its controls work. Part 5 defines it as the processes that ensure the performance and effectiveness of safety risk controls through the collection, analysis and assessment of information [3]. Section 5.71 requires processes and systems to acquire data that include, at a minimum, monitoring of operational processes, monitoring of the operational environment to detect changes, auditing, evaluations, investigations, a confidential employee reporting system, and investigation of hazard notifications from outside the organization, together with processes to analyze that data [3].
Section 5.73 then requires assessments of safety performance against safety objectives, including reviews by the accountable executive, to ensure compliance with risk controls, evaluate the effectiveness of those controls, identify changes in the operational environment and identify new hazards [3]. Where an assessment finds ineffective controls or new hazards, the operator must return to safety risk management, and Section 5.75 requires processes to correct the deficiencies found [3].
The advisory circular offers a modest example of what monitoring can look like in a smaller organization: regularly reviewing the flight dispatch logs and crewmember duty records is itself a form of monitoring that can be done in the normal course of duties [4]. It also observes that seasonal weather may require an organization to change its scheduling, routes and aircraft utilization, which is the kind of environmental change that monitoring is intended to detect [4].
Records matter as much as activity. Outputs of safety risk management must be kept for as long as the control remains relevant to the operation, and outputs of safety assurance for a minimum of five years [3].
Where trip monitoring fits
Much of the information that safety assurance depends on is generated, and too often lost, in daily operations. A revised forecast below a company minimum, a delay that brings a crew close to its duty limit, a notice that closes the planned runway, an arrival that drifts outside a customs window: each is a change in the operating environment, and each tests a risk control the operator has already written down.
When trips are monitored continuously and the results are recorded in a structured way, those events become evidence. A consistent record of what changed, which flights were affected, which control applied, who reviewed the situation and what was decided can support the monitoring of operational processes and of the operational environment under Section 5.71 [3]. Over months, the same record can inform the assessments required by Section 5.73: how often a given control is triggered, whether trips are regularly planned close to a limit, and whether a particular airport, season or route is producing a recurring hazard that belongs back in safety risk management [3].
It is important to be precise about what such a record is. It is evidence that a process is operating and data that an operator can analyze. It does not constitute an SMS, it does not replace the operator's safety policy, risk assessments or accountable executive review, and it cannot by itself make an operator compliant. The SMS, and the declaration that it meets Part 5, remain the operator's.
Preparing for May 2027
For operators still building their systems, a few practical steps follow from the rule's structure.
- Describe operational control as a system. Document who follows flights, with what tools, at what hours, and how changes after release are handled, so that hazards can be identified within that description.
- Write the controls you already apply. Company minimums, duty buffers and international procedures are risk controls; recording them as such allows their effectiveness to be measured.
- Decide what evidence assurance will use. Identify which records will show that controls are applied and working, and how they will be retained for five years.
- Close the loop. Make sure that recurring findings from trip monitoring reach the safety manager and the accountable executive, and lead to changes where needed.
SAIKER is decision support for the operations team, not a safety management system. Every finding it raises, and every decision recorded against it, is kept with its source and time, which gives a department a structured record it can draw on in its own safety assurance work.
Sources
- "Safety Management Systems," Final rule, 89 FR 33068, Federal Aviation Administration, Federal Register, April 26, 2024. https://www.federalregister.gov/documents/2024/04/26/2024-08669/safety-management-systems
- "Safety and Industry Data Improvements for Part 135 Operations," Special Investigation Report AIR-24-03, National Transportation Safety Board, July 24, 2024. https://www.ntsb.gov/investigations/AccidentReports/Reports/AIR-24-03.pdf
- "14 CFR Part 5, Safety Management Systems," Electronic Code of Federal Regulations, Office of the Federal Register, current text accessed October 7, 2026. https://www.ecfr.gov/current/title-14/chapter-I/subchapter-A/part-5
- "Advisory Circular 120-92D, Safety Management Systems for Aviation Service Providers," Federal Aviation Administration, May 21, 2024. https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf
