AMC & GM to Part-ORO — Issue 2, Amendment 29
Acceptable Means of Compliance and Guidance Material to Part-ORO Issue 2, Amendment 29 Annex I to ED Decision 2025/020/R ‘AMC and GM to Part-ORO — Issue 2, Amendment 29’ The text of the amendment is arranged to show deleted, new or amended text as follows: — deleted text is struck through; — new or amended text is highlighted in blue; — an ellipsis ‘[…]’ indicates that the rest of the text is unchanged.
N o t e t o t h e r e a d e r
In amended, and in particular in existing (i.e. unchanged), text, ‘Agency’ is used interchangeably with ‘EASA’. The interchangeable use of these two terms is more apparent in the consolidated versions. Therefore, please note that both terms refer to the ‘European Union Aviation Safety Agency (EASA)’.
Annex I to ED Decision 2025/020/R Page 1 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
The Annex to Decision 2014/017/R of the Executive Director of the Agency of 24 April 2014 (‘AMC & GM to Part-ORO — Issue 2’) is amended as follows:
SUBPART GEN: GENERAL REQUIREMENTS SECTION 2 — MANAGEMENT
AMC1 ORO.GEN.200(a)(1) Management system
COMPLEX OPERATORS — ORGANISATION AND ACCOUNTABILITIES […] (a) Safety manager […] (2) The functions of the safety manager should be to: […] (vi) provide advice on safety matters; and (vii) ensure initiation and follow-up of internal occurrence/accident investigations.; and (viii) ensure the effective use of the flight data monitoring (FDM) programme for safety risk management, if such an FDM programme is required. […] (b) Safety review board […] (3) The safety review board should monitor: […] (iii) the effectiveness of the operator’s safety management processes, including those related to the FDM programme, if such a programme is required. […]
GM2 ORO.GEN.200(a)(2) Management system
SAFETY POLICY REGARDING THE USE OF DATA FOR PURPOSES OTHER THAN SAFETY RISK MANAGEMENT If a data source that is needed to support safety risk management is required to be protected, then it is recommended that the safety policy required by point ORO.GEN.200 provide for consistent protection of this data source when it is used for purposes other than safety risk management. An example is using flight data for a flight data monitoring programme (protection of the data source is required by points ORO.AOC.130 and SPA.HOFO.145) and for other programmes, such as a fuel efficiency programme or a preventive maintenance programme. In this example, the safety policy consistently addresses the protection of flight crew identity across all the programmes in which flight data is used.
Annex I to ED Decision 2025/020/R Page 2 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
AMC1 ORO.GEN.200(a)(3) Management system
COMPLEX OPERATORS — SAFETY RISK MANAGEMENT (a) Hazard identification processes (1) Reactive and proactive schemes for hazard identification should be the formal means of collecting, recording, analysing, acting on and generating feedback about hazards and the associated risks that affect the safety of the operational activities of the operator. Such schemes should include the flight data monitoring programme when such a programme is required. [...] (d) Safety performance monitoring and measurement […] (2) This process should include: (i) safety reporting, addressing also the status of compliance with the applicable requirements; (ii) the flight data monitoring programme, for those aircraft required to be included in such a programme; (iii)(ii) safety studies, that is, rather large analyses encompassing broad safety concerns; (iv)(iii)safety reviews including trends reviews, which would be conducted during introduction and deployment of new technologies, change or implementation of procedures, or in situations of structural change in operations; (v)(iv) safety audits focussing on the integrity of the operator’s management system, and periodically assessing the status of safety risk controls; and (vi)(v) safety surveys, examining particular elements or procedures of a specific operation, such as problem areas or bottlenecks in daily operations, perceptions and opinions of operational personnel and areas of dissent or confusion.
AMC1 ORO.GEN.200(a)(6) Management system
COMPLIANCE MONITORING — GENERAL [...] (b) […] (4) management system procedures and manuals, including procedures applicable to the flight data monitoring programme, when such a programme is required;
Annex I to ED Decision 2025/020/R Page 3 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
SUBPART AOC: AIR OPERATOR CERTIFICATION
AMC1 ORO.AOC.130 Flight data monitoring –— aeroplanes
ORGANISATION OF THE FLIGHT DATA MONITORING (FDM) PROGRAMME (a) Safety manager’s responsibilities: The the safety manager, as defined under AMC1- ORO.GEN.200(a)(1), should be responsible for the identification and assessment of issues and their transmission to the manager(s) responsible for the process(es) concerned. The latter should be responsible for taking appropriate and practicable safety action within a reasonable period of time that reflects the severity of the issue. (b) Contribution to the management system: An an FDM programme should support the identification and evaluation of safety hazards and the management of their associated risks, as required by point ORO.GEN.200, by allowing the an operator to: (1) identify areas of operational risk and quantify current safety margins; (2) identify and quantify operational risks by highlighting occurrences of non-standard, unusual or unsafe circumstances; (3) estimate use the FDM information on the frequency of such occurrences, combined with an estimation of the level of severity, to assess the safety risks and to determine which risks are unacceptable or may become unacceptable if the discovered trend continues; (4) put in place appropriate procedures for remedial action once an unacceptable risk, either actually present or predicted by trending, has been identified inform the definitions of remedial actions with accurate and current safety data; and (5) confirm the effectiveness of any remedial action by continued monitoring. (c) FDM analysis techniques: FDM analysis techniques should comprise the following: (1) Exceedance detection (‘FDM event’): searching for deviations from aircraft flight manual limits and standard operating procedures. A set of core events should be selected to cover the main areas of interest to the operator and as much as possible, the most significant risks identified by the operator. The event definitions should be continuously reviewed to reflect the operator’s current operating procedures. (2) All flights measurement (‘FDM measurement’): a system defining what is normal practice. This may be accomplished by retaining various snapshots of information from each flight. (3) Statistics — a series of data collected to support the analysis process: FDM-based statistics this technique should include distributions and rate and trend information where the number of flights flown is per aircraft and sector details sufficient to reliably generate rate and trend such information. (d) FDM analysis, assessment and process control tools: the effective assessment of information obtained from digital flight data should be supported by dependent on the provision of appropriate information technology tool sets capabilities. These capabilities should include specialised software (‘FDM software’) or a specialised service (‘FDM service’) to process the
Annex I to ED Decision 2025/020/R Page 4 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
flight data. In addition, to facilitate linking flight data with occurrence reports and other data, such as traffic data and weather data, these capabilities should include: (1) the automatic identification of individual flights in the data files collected for FDM; and (2) if the necessary data is collected, the provision of the following information for each detected FDM event: (i) the aircraft’s geographical position and altitude, (ii) coordinated universal time (UTC) date and time, (iii) information that identifies the flight, and (iv) aircraft registration. (e) Education and publication Safety information and promotion: should be a fundamental principle of aviation safety in helping to reduce accident rates. The operator should pass on the lessons learnt to all relevant personnel and, where appropriate, industry. FDM programme output should be used, in compliance with the procedure specified in point (k), to support the sharing of safety information with flight crew members and all other relevant personnel. For this purpose, the operator should provide, upon request by its competent authority, documentation on the principles it follows to ensure the adequate quality of FDM events, FDM measurements and FDM-based statistics used for safety information sharing. It should also demonstrate that FDM-based safety information provided to individual flight crew members is clear and relevant. (f) Accident and incident data requirements: Accident and incident data requirements requirements regarding the preservation of flight recorder recordings after accidents and serious incidents specified in CAT.GEN.MPA.195 take precedence over the requirements of an FDM programme. In these cases the FDR data should be retained as part of the investigation data and may fall outside the de-identification agreements. (g) Incident reporting: Every crew member should be responsible for reporting events. Significant significant risk-bearing incidents detected by FDM should therefore normally be the subject of mandatory occurrence reporting by the crew. If this is not the case, then they should submit a retrospective report that should be included under the normal process for reporting and analysing hazards, incidents and accidents, in accordance with Regulation (EU) No 376/2014. (h) Data recovery and validation: The the data recovery and validation strategy should ensure a sufficiently representative capture of flight information to maintain an overview of operations and that data is recovered from all aeroplanes that are within the scope of point ORO.AOC.130. Data analysis In addition, the validation of FDM events and measurements should be performed sufficiently frequently to enable action to be taken on significant safety issues. Data recovery and validation should incorporate all the points below. (1) To ensure that a sufficiently representative subset of flights is monitored by the FDM programme, the number of flights available for processing by the FDM programme and that contain valid data should amount to: (i) at least 60 % of the total number of flights performed in the past 12 months by aeroplanes that are within the scope of point ORO.AOC.130, if the operator operates fewer than 20 such aircraft; or
Annex I to ED Decision 2025/020/R Page 5 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(ii) at least 80 % of the total number of flights performed in the past 12 months by aeroplanes that are within the scope of point ORO.AOC.130, if the operator operates 20 or more such aircraft. This condition is not applicable to aeroplanes that performed fewer than 50 flights in the previous 12 months. (2) To limit the maximum duration during which no flight data may be received from an individual aeroplane, the operator should: (i) have means and procedures to identify a failure of the means to collect data from any individual aeroplane that is within the scope of point ORO.AOC.130 either within 22 calendar days after the failure occurs or before 10 more flights are performed after the failure occurs; and (ii) correct any failure of the means to collect data from any individual aeroplane that is within the scope of point ORO.AOC.130 within 120 days of being made aware of the failure. (3) To ensure that significant FDM events (FDM events that correspond to the most significant deviations from the SOPs and circumstances potentially affecting the airworthiness of the aircraft) can be identified without unnecessary delays, the flights for which flight data is collected within the FDM programme (hereafter called ‘collected flights’) should be processed in a timely manner. At least 80 % of the collected flights that were performed in the previous 12 months should have been processed by the FDM software either within 22 calendar days after completion of the collected flight or before 10 flights following the collected flight were performed by the same aircraft. (4) For each aeroplane that is within the scope of point ORO.AOC.130 and that is first issued with an individual certificate of airworthiness (CofA) on or after 1 January 2029: (i) the operator should ensure that, within 90 calendar days after it starts operating the aeroplane, the data collected for processing by the FDM software include all the flight parameters required to be recorded by a flight data recorder in accordance with AMC1.2 CAT.IDE.A.190; and (ii) the operator should verify, within 90 calendar days after it starts operating the aeroplane, that the flight parameters specified in point (i) meet the performance specifications (range, sampling intervals, accuracy limits and resolution in readout) as defined in EUROCAE Document 112A or any later equivalent standard produced by EUROCAE — this verification may be based on the documentation provided by the aircraft manufacturer or the installer of the airborne systems used to collect the flight data. (5) The operator should explain, upon request by its competent authority, the principles it uses for validating an FDM event, that is, how it determines whether an FDM event genuinely reflects a deviation that is considered abnormal for the flight in which the FDM event was triggered. (6) The operator should validate significant FDM events as a matter of priority. At least 80 % of significant FDM events should be validated within 15 calendar days after their first detection by the FDM software. (i) Data retention strategy: The the data retention strategy should aim at providing the greatest safety benefits practicable from the available data. For this purpose: (1) A full dataset All raw or decoded flight data should be retained at least until valid significant FDM events have been analysed the action and review processes are
Annex I to ED Decision 2025/020/R Page 6 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
complete. In addition, 80 % or more of the raw or decoded flight data files of aircraft required to be part of the FDM programme should remain available for processing with the FDM software for at least 2 years; however, retaining a lower proportion of these flight data files is acceptable until 2 years after installing new FDM software or until 2 years after the start of a contract with a new FDM service provider. (2) thereafter, A reduced dataset relating to closed issues de-identified analyses of significant FDM events should be maintained for a time that is consistent with the operator’s record-keeping for management-system-related activities (refer to point ORO.GEN.220). longer-term trend analysis. Programme managers may wish to retain samples of de-identified full-flight data for various safety purposes (detailed analysis, training, benchmarking, etc.). (3) The data retention strategy should include measures to ensure the security of stored data. (j) Data access and security policy: The the data access and security policy should restrict information access to authorised persons. When This policy should specifically address the case of a data access request is required for airworthiness and or maintenance purposes, a procedure should be in place to prevent disclosure of crew identity. (k) Procedure to prevent disclosure of crew identity: The the procedure to prevent disclosure of crew identity should be written in a document, which should be signed by all parties (airline management, flight crew member representatives nominated either by the union or the flight crew themselves). This procedure should, as a minimum, define: (1) the aim of the FDM programme; (2) a data access and security policy that should restrict access to information to specifically authorised persons identified by their position (refer to point (j)); (3) the method to obtain de-identified crew feedback on those occasions that require specific flight follow-up for contextual information; where such crew contact is required the authorised person(s) need not necessarily be the programme manager or safety manager, but could be a third party (broker) mutually acceptable to unions or staff and management; (4) the a data retention strategy (refer to point (i)) policy and data accountability, including the measures taken to ensure the security of the data; (5) the conditions under which advisory briefing or remedial training should take place; this should always be carried out in a constructive and non-punitive manner; (6) the conditions under which the confidentiality may be withdrawn for reasons of gross negligence or significant continuing safety concern the conditions under which the identity of a crew member may be disclosed, which should be consistent with the provisions laid down in Regulation (EU) No 376/2014 and the operator’s safety risk management procedures; (7) the participation of flight crew member representative(s) in the assessment of the data, the action and review process and the consideration of recommendations; and (8) the policy for publishing the findings resulting from sharing safety information based on FDM (refer to point (e)).
Annex I to ED Decision 2025/020/R Page 7 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(l) Access to information on flight parameters and FDM algorithms: the operator should have unhindered access to information on the flight parameters and the algorithms used to produce FDM events and measurements. For aircraft required to be part of the FDM programme and first issued with an individual CofA on or after 1 January 2029, the operator should, within 90 calendar days after it starts operating these aircraft, be able to provide the following documentation upon request by its competent authority: (1) documentation of the data source and the performance (at least the recording resolution and recording rate) of all the flight parameters collected and used by the FDM software to produce FDM events and measurements; (2) documentation on the algorithms used to produce FDM events or FDM measurements, which should include the following: (i) a description of the logic of each algorithm, which should be sufficiently detailed to verify consistency with the applicable flight manual limitations or standard operating procedures, as applicable; in the case of an FDM event algorithm, the event trigger conditions and the trigger threshold values should be specified; (ii) for each algorithm, the list of flight parameters needed by the algorithm. (l)(m) Airborne systems and equipment: for all aircraft required to be part of the FDM programme and that are first issued with an individual CofA on or after 1 January 2029 , Airborne airborne systems and equipment used to obtain FDM flight data should range from a quick access recorder (QAR) in an aircraft with digital systems, to a crash-protected flight recorder in an older or less sophisticated aircraft continuously collect the data throughout the flight, including when the aircraft is moving on the ground under its own power. The analysis potential of the reduced data set available in the latter case may reduce the safety benefits obtainable. The operator should ensure that FDM use The use of such airborne systems and equipment, including retrieval of data from the aircraft, does should not adversely affect the availability or the serviceability of flight recorders equipment required for accident investigation.
AMC2 ORO.AOC.130 Flight data monitoring — aeroplanes
SCOPE OF THE FLIGHT DATA MONITORING (FDM) PROGRAMME (a) A set of core FDM events or FDM measurements should be selected to cover, as far as possible, the most significant risks identified by the operator. The definitions of FDM events and FDM measurements in this core set should be designed to help identify deviations from the standard operating procedures that are beyond what is considered normal practice and not only occurrences that require reporting to the competent authority or unscheduled continued airworthiness activity. The definitions of FDM events and FDM measurements in this core set should be continuously reviewed to reflect the operator’s current operating procedures and any newly identified safety risks. (b) For all aeroplanes that are within the scope of point ORO.AOC.130 and first issued with an individual certificate of airworthiness (CofA) on or after 1 January 2016, the FDM programme should monitor, to the extent possible with the available flight data and without requiring overly complex algorithms, precursors of the following key risk areas:
Annex I to ED Decision 2025/020/R Page 8 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(1) risk of runway excursion during take-off or landing, (2) risk of airborne collision, (3) risk of aircraft upset, and (4) risk of collision with terrain. (c) If the necessary flight parameters are collected by the airborne systems used to obtain flight data, the FDM programme should monitor: (1) exceedances indicating that the airworthiness of the aircraft may be affected and that are related to any of the following parameters: (i) speed and configuration; (ii) altitude; (iii) accelerations; (iv) attitude angles; (v) engine limitations (e.g. those related to thrust parameters, exhaust gas temperature, vibration levels and reverse thrust versus aircraft speed); (vi) aircraft weight; and (2) caution and warning alerts to the flight crew, indicating that the airworthiness of the aircraft may be affected. (d) Upon request by its competent authority, the operator should provide documentation identifying which types of occurrences are monitored with the FDM programme. This documentation should cover at least the occurrences subject to mandatory reporting and listed in Section 1 (excluding paragraph 1.5, point (3)) and Section 5 of Annex I to Commission Implementing Regulation (EU) 2015/1018. This documentation should include a short description of the applicable FDM event(s) or FDM measurement(s) for each type of occurrence monitored by the FDM programme.
GM1 ORO.AOC.130 Flight data monitoring –— aeroplanes
IMPLEMENTATION OF A FLIGHT DATA MONITORING AN (FDM) PROGRAMME ‘Flight data monitoring’ (FDM) is defined in Annex I to this Regulation. It should be noted that the requirement to establish a FDM programme is applicable to all individual aircraft in the scope of ORO.AOC.130, not to a subset selected by the operator. (a) FDM analysis techniques (1) Exceedance detection / FDM event (i) FDM programmes are used for detecting exceedances what are known as ‘FDM events’, such as deviations from flight manual limits, standard operating procedures (SOPs), or good airmanship. Typically, a set of core events establishes the main areas of interest that are based on a prior assessment of the most significant risks by the operator. It is advisable to monitor deviations from the SOPs in all phases of the flight, including when the aircraft is on the ground. In addition,
Annex I to ED Decision 2025/020/R Page 9 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
it is advisable to consider the following risks: risk of runway excursion or abnormal runway contact at take-off or landing, risk of loss of control in flight, risk of airborne collision, and risk of collision with terrain. Examples of FDM events for aeroplanes: low or high lift-off rotation rate, stall warning, ground proximity warning system (GPWS) warning, flap limit speed exceedance, fast approach, high or low on glideslope, heavy landing. (ii) Trigger conditions logic expressions of FDM event algorithms may be as simple as detecting that a ‘redline value’ was exceeded exceedances such as redline values. The majority, however, are composites that define a certain flight mode, aircraft configuration or payload-related condition. Analysis software can also assign different sets of rules dependent on airport or geography. For example, noise sensitive airports may use higher than normal glideslopes on approach paths over populated areas. In addition, it might be valuable to define several levels of FDM eventexceedance severity (such as low, medium and high severity). While such severity levels can help identify significant FDM events and relevant trends, they should not be considered safety risk levels; assessing the safety risk level associated with an occurrence or a trend usually requires a more thorough assessment and consideration of all the relevant data available to the operator. Example of composite trigger conditions for aeroplanes: conditions dependent on airport or geography — for example, the instrument-landing-system-based guidance of noise-sensitive airports may use higher-than-normal glideslopes over densely populated areas. Examples of significant (high-severity) FDM events for aeroplanes: stall warning, terrain awareness warning system ‘PULL UP’ warning. Example illustrating the difference between FDM event severity level and safety risk level: an FDM event algorithm detects a longer-than-normal landing-thresholdto-touchdown horizontal distance. The analysis of an occurrence detected with this algorithm may conclude that the level of safety risk associated with this occurrence was low, for instance because the landing distance available was significantly greater than the computed landing distance and the runway friction coefficient was high (dry runway) at the time of landing. For the same landing-threshold-totouchdown horizontal distance and the same runway, the analysis could conclude that the level of safety risk was high due to a reduced landing distance available on the day (e.g. construction works on the runway) and because the runway friction coefficient was low (contaminated runway) at the time of landing. (iii) Exceedance detection FDM events provide useful information, which can complement that provided in crew reports. Examples for aeroplanes: reduced flap landing, emergency descent, engine failure, rejected take-off, go-around, airborne collision avoidance system (ACAS) or GPWS warning, and system malfunctions. (iv) The operator may also modify the standard set of core FDM events to account for unique situations they regularly experience, or the SOPs they use.
Annex I to ED Decision 2025/020/R Page 10 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Example for aeroplanes: to avoid nuisance FDM events exceedance reports from a non-standard instrument departure unique approach procedure. (v) The operator may also define new FDM events to address specific problem areas. Example for aeroplanes: an restrictions on the use of certain flap settings to increase component lifeFDM event measuring the flap extension rate to monitor the reliability of the flap system on a given aircraft model. (vi) Being able to easily adjust the variables of FDM event algorithms can be advantageous, as it allows an FDM event definition to be adapted to new operational conditions. (vii) The choice of appropriate trigger conditions and severity level threshold values for all FDM events is very important for an effective FDM programme. In particular, it is important that the trigger conditions of an FDM event algorithm are set so that it detects not only the most severe deviations (which are subject to mandatory occurrence reporting or require unscheduled inspection or maintenance) but also deviations that are beyond normal piloting practice. This is important for the effective and timely detection of outliers and unsafe trends. It is advisable to document how trigger conditions and severity level threshold values are determined. (2) All-flights measurements / FDM measurements FDM data are retained from all flights, not just the ones producing significant FDM events. A selection of parameters is retained that is sufficient to characterise each flight and allow a comparative analysis of a wide range of operational variability. The distributions of flight parameter values, which can typically be produced with FDM measurements, may contain a wealth of information on common piloting practices and outliers. By analysing such distributions, emerging Emerging trends and tendencies may be identified and monitored before the trigger conditionslevels associated with exceedances anFDM event are reached. Examples of parameters monitored for aeroplanes: take-off weight, flap setting, temperature, rotation and lift-off speeds versus scheduled speeds, maximum pitch rate and attitude during rotation, and gear retraction speeds, heights and times. Examples of comparative analyses for aeroplanes: pitch rates from high versus low takeoff weights, good versus bad weather approaches, and touchdowns on short versus long runways. (3) Statistics Series of data are collected to support the analysis process: these usually include the numbers of flights flown per aircraft and sector details sufficient to generate rate and trend information. (4) Investigation of incidents flight data by the operator Recorded flight data provides valuable information for follow-up to incidents and other technical reports. They are It is useful in adding to the impressions and information recalled by the flight crew. They It also provides an accurate indication of system status and performance, which may help in determining cause and effect relationships. Examples of incidents where recorded data could be useful:
Annex I to ED Decision 2025/020/R Page 11 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
— high cockpit workload conditions as corroborated by such indicators as late descent, late localizer and/or glideslope interception, late landing configuration; — unstabilised and rushed approaches, glide path excursions, etc.; — exceedances of exceeding prescribed operating limitations (such as flap limit speeds, engine overtemperatures); and — wake vortex encounters, turbulence encounters or other events causing significant vertical accelerations. It should be noted that recorded flight data have limitations, e.g. not all the information displayed to the flight crew is recorded, the source of recorded data may be different from the source used by a flight instrument, the sampling rate or the recording resolution of a parameter may be insufficient to capture accurate information. (5) Continuing airworthiness Data of all-flight FDM measurements and FDM events exceedance detections can be utilised to assist the continuing airworthiness function. For example, engine-monitoring programmes look at measures of engine performance to determine operating efficiency and predict impending failures. Examples of continuing airworthiness uses for aeroplanes: engine thrust level and airframe drag measurements, avionics and other system performance monitoring, flying control performance, and brake and landing gear usage. (b) FDM equipment, FDM software and FDM service (1) General FDM programmes generally involve systems that capture flight data, transform the data into an appropriate format for analysis, and generate reports and visualisation to assist in assessing the data. Typically, the following equipment capabilities are are needed for effective FDM programmes: (i) an on-board device to capture and record data on a wide range of in-flight parameters; (ii) a means to transfer the data recorded on board the aircraft to a secure repository where it can be processed and analysed a ground-based processing station; and (iii) a ground-based computer system software or a service to process and analyse the data, identify deviations from expected performance, generate reports to assist in interpreting the read-outs, etc.; and (iv) optional software for a flight animation capability to integrate all data, presenting them as a simulation of in-flight conditions, thereby facilitating visualisation of actual events. (2) Airborne equipment (i) The flight parameters and recording capacity required for flight data recorders (FDR) to support accident investigations may be insufficient to support an effective
Annex I to ED Decision 2025/020/R Page 12 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
FDM programme. Other Several technical solutions are available, including the following: (A) Quick access recorders (QARs). QARs Some systems are installed in the aircraft and record flight data onto a low-cost removable medium. (B) Some systems automatically download transmit the recorded data information via secure wireless systems after completion of the flight when the aircraft is in the vicinity of the gate. (C) There are also Some systems that enable preprocess the recorded data to be analysed on board while the aircraft is airborne. Whatever the flight data processing performed by such systems, a complete set of raw flight data still needs to be recovered after the flight, as this is needed for in-depth analysis by the FDM team. (ii) Fleet composition, route structure and cost considerations will determine the most cost-effective method of removing the data from the aircraft. (3) Ground replay and analysis equipment FDM software or service (i) Data are downloaded from the aircraft recording device into a ground-based processing station, where the data are held securely to protect this sensitive information. (ii)(i) FDM programmes generate large amounts of Processing and analysing flight data requiring require specialised analysis FDM software or a specialised FDM service. (iii)(ii) The analysis FDM software or service typically converts the raw flight data into flight parameters expressed in engineering units and textual interpretation (‘flight parameter decoding’) and applies FDM algorithms to the flight parameters (refer to points (a)(1) and (a)(2)) checks the downloaded flight data for abnormalities. (iv)(iii)The analysis FDM software or service may include: typically includes the capability to produce parameter plots and parameter tables, the capability to drill down and visualise flight parameter values for the portion of the flight during which an event was detected annotated data trace displays, engineering unit listings, visualisation for the most significant incidents, access to interpretative material, links to other safety information and statistical presentations. (iv) For the FDM software or service, the following additional capabilities are advantageous. (A) In the case of FDM software, the capability to program FDM algorithms, and the capability to interface with advanced processing tools or to access advanced functions libraries beyond those offered as part of the FDM software. (B) The capability to link flight data with other data sources (e.g. occurrence reports or weather data) to facilitate the analysis of events and trends. This capability should be used in accordance with data protection policies and procedures, and its output should be restricted to authorised users.
Annex I to ED Decision 2025/020/R Page 13 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(C) The capability to export outputs (e.g. FDM event and measurement data) in a standard electronic format that is compatible with business intelligence tools. (D) The capability to export outputs in formats compatible with geographical information systems. (E) The capability to replay flight data in a flight animation, thereby facilitating visual reconstruction of an occurrence. (F) The capability to design and provide individual FDM summary reports or dashboards that can be confidentially consulted by flight crew members. It is more safety-relevant that such reports focus on compliance with the SOPs and aircraft flight manual limits rather than on comparing the performance of an individual pilot with that of their peers. (G) The capability to export the information related to flight parameter decoding into a file format that: (a) complies with an electronic documentation standard that has a general public licence policy; and (b) includes means to retain the history of changes to the decoding information. An example of an applicable standard is ARINC specification 647A (Flight Recorder Electronic Documentation). (H) In the case of FDM software, the capability to generate documentation on the flight parameters that are used to produce FDM events and measurements, and the capability to generate documentation describing the logic of the algorithms used to produce FDM events and measurements, and for which type of reportable occurrences these algorithms are relevant. (v) In case of a change of FDM software or FDM service provider, it is advisable to keep the previous FDM software or service operative for several months to ensure business continuity and validate the outputs of the new FDM software or service. (c) FDM in practice (1) FDM process Typically, operators follow a closed-loop process in applying an FDM programme, for example: (i) Establish a baseline: initially, operators establish a baseline of operational parameters against which changes can be detected and measured. They also determine ranges of flight parameter values that correspond to normal operations, which facilitates the determination of the appropriate trigger conditions for an FDM event definition. Examples for aeroplanes: rate of unstable approaches or hard landings. (ii) Highlight unusual or potentially unsafe circumstances: the user determines when non-standard, unusual or basically potentially unsafe circumstances occur; by comparing them with to the baseline margins of safety, the changes can be quantified.
Annex I to ED Decision 2025/020/R Page 14 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Example for aeroplanes: increases in unstable approaches (or other unsafe events) at particular locations. (iii) Identify potentially unsafe trends: based on the frequency and severity of FDM events occurrence, trends are identified. Combined with an estimation of the level of severity, the risks are assessed to determine which may become unacceptable if the trend continues. If a trend shows a significant increase in the frequency and/or severity of FDM events, a safety risk assessment may be necessary, as part of the operator safety risk management. More guidance on the identification of trends can be consulted in the European Operators Flight Data Monitoring forum (EOFDM) document Flight Data Monitoring — Analysis techniques and principles. Example for aeroplanes: a new procedure has resulted in high rates of descent that are nearly triggering GPWS warnings. (iv) Mitigate risks: once an unacceptable risk has been identified, appropriate risk mitigation actions are decided on and implemented. Example: having found high rates of descent, the SOPs are changed to improve aircraft control for optimum/maximum rates of descent. (iv) Monitor the effectiveness of corrective actions, if the FDM programme is relevant for that purpose: once a remedial action has been put in place in the framework of the operator’s safety risk management, its effectiveness is monitored, confirming that it has reduced the identified risk and that the risk has not been transferred elsewhere. At this stage, the operator typically evaluates whether the FDM programme can contribute to this monitoring. Example for aeroplanes: confirm that other safety measures at the aerodrome with high rates of descent do not change for the worse after changes in approach procedures. (v) Adapt the FDM programme to monitor new risks stemming from operational changes. Example for aeroplanes: significant changes to the area of operation or business model. (2) Analysis and follow-up (i) FDM data is are typically processed compiled every month or at shorter intervals. The data is are then reviewed to identify and validate specific FDM events exceedances and emerging undesirable trends and to disseminate the information to flight crews. Validating an FDM event means determining whether it corresponds to a genuine and abnormal event. It does not include analysing the possible causes or consequences of the event or assessing its safety risks. (ii) If deficiencies in pilot handling technique deviations from the SOPs are evident detected, motivating an analysis of the causes and circumstances, the information is usually de-identified in order to protect the identity of the flight crew. The information on specific about these deviations is passed (in accordance with point (k) of AMC1 ORO.AOC.130) on to the person responsible exceedances is passed to a person (safety manager, agreed flight crew representative, honest
Annex I to ED Decision 2025/020/R Page 15 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
broker) assigned by the operator for flight crew contact confidential discussion with the pilot. The decision to initiate flight crew contact (e.g. notification, request for additional information or confidential discussion) should be made after an initial assessment that takes contextual information into account. If a confidential discussion with the flight crew is deemed necessary, the responsible person assigned by the operator provides the necessary contact with the pilot in order to clarify the circumstances, and obtain feedbackand give advice and recommendations for appropriate action for a more thorough safety assessment. Such appropriate action could include re-training (carried out in a constructive and non-punitive way), revisions to manuals, changes to ATC and airport operating procedures. (iii) Follow-up monitoring enables the effectiveness of any corrective actions to be assessed. Flight crew feedback is essential for the identification and resolution of safety problems and could be collected through interviews, for example by asking the following: (A) Are the desired results being achieved soon enough? (B) Have the problems really been corrected, or just relocated to another part of the system? (C) Have new problems been introduced? (iiiiv) All FDM events are usually archived in such a way that they can be sorted, validated and presenteddatabase. The database is used to sort, validate and display the data in easy-to-understand management reports. Over time, this archived data can provide a picture of emerging trends and hazards that would otherwise go unnoticed. In addition, the FDM team may wish to retain samples of de-identified full-flight data for various safety purposes (detailed analysis, training, benchmarking, etc.). (iv) Sharing safety information is necessary to maintain a competent workforce and support an effective management system (refer to point ORO.GEN.200). Therefore, lessons Lessons learnt from the FDM programme may warrant inclusion in the operator’s safety promotion programmes. Safety promotion media may include newsletters, flight safety magazines, emails, video recordings and information on the company’s intranet, highlighting examples in training and simulator exercises, periodic reports to industry and the competent authority. Care is required, however, to ensure that any information acquired through FDM is deidentified before using it in any training or promotional initiative. In addition, it is recommended to not provide individual flight crew members with personalised access to FDM-based information (e.g. individual FDM summary reports or the possibility of replaying one’s flight) without support from an FDM specialist on how to use these systems and correctly interpret the information provided. The safety manager is normally responsible for the transmission of FDM-based information (refer to AMC1 ORO.AOC.130), which includes defining processes to ensure that
Annex I to ED Decision 2025/020/R Page 16 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
such information is validated, clear and relevant to the recipient and provided in accordance with the procedure to prevent disclosure of crew identity. (vi) All successes and failures are recorded, comparing planned programme objectives with expected results. This provides a basis for review of the FDM programme and the foundation for future programme development. (d) Preconditions for an effective FDM programme (1) Protection of FDM data and related crew reports The integrity of FDM programmes rests upon protection of the FDM data. Any disclosure for purposes other than safety management can compromise the voluntary provision of safety data, thereby compromising flight safety. It is also advisable to consider Regulation (EU) 2016/679 (General Data Protection Regulation), where applicable. In addition, the inherent protection of reporters and of persons mentioned in occurrence reports under Regulation (EU) No 376/2014 applies to flight crew members, whether their reports are voluntarily provided or retrospectively requested by the operator after an FDM event. Note that, after an official safety investigation of an accident or serious incident is initiated, the data recorded on a crash-protected flight data recorder should be preserved as part of the investigation data (point CAT.GEN.MPA.195). 2) Essential trust The trust established between management and flight crew is the foundation for a successful FDM programme. This trust can be facilitated by: (i) early participation of the flight crew representatives in the design, implementation and operation of the FDM programme; (ii) a formal agreement between management and flight crew, identifying the procedures for the use and protection of data; and (iii) data security, optimised by: (A) adhering to the agreement; (B) the operator strictly limiting data access to selected individuals; (C) maintaining tight control to ensure that identifying data is kept securely; and (D) ensuring that operational problems are promptly addressed by management. (3) Requisite safety culture Indicators of an effective a positive safety culture within an FDM programme typically include: (i) top management’s demonstrated commitment to promoting a proactive positive safety culture; (ii) a non-punitive operator policy that covers the FDM programme; (iii) FDM programme management by dedicated staff under the authority of the safety manager, with a high degree of specialisation and logistical support; (iv) involvement of persons with appropriate expertise when assessing FDM events, FDM measurements and trends when identifying and assessing the risks (refer to point (e)(3))for example, pilots experienced on the aircraft type being analysed;
Annex I to ED Decision 2025/020/R Page 17 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(v) monitoring fleet trends aggregated from numerous operations, not focusing only on specific events; (vi) a well-structured system to protect the confidentiality of the data; and (vii) an efficient communication system for disseminating hazard information (and subsequent risk assessments) internally and to other organisations to permit timely safety action. communicating relevant information on the general trends identified by and lessons learnt from the FDM programme in the communications on safety matters specified in AMC1 ORO.GEN.200(a)(4). (4) Integration with the operator’s management system Point ORO.AOC.130 requires the integration of the FDM programme with the operator’s management system. Because of this, FDM programme outputs are expected to be used together with other relevant data sources to support safety risk management (SRM). The SRM process is not an internal process within the FDM programme but part of the operator’s management system. AMC1 ORO.AOC.130 specifies that the safety manager should be responsible for identifying and assessing issues, which are the first steps of the SRM process. The European Operators Flight Data Monitoring Forum document Breaking the Silos details industry good practices regarding integration of the FDM programme in the management system. (5) Complete access to flight parameter decoding information (i) The flight parameter decoding information is the information sufficient for extracting flight parameter values from the recorded data files and decoding them into values expressed in engineering units or textual interpretation. This information, which is usually provided by the installer of the airborne systems used to collect the flight data, is essential for programming the FDM software to decode the flight parameters. (ii) Therefore, it is recommended that complete access to the flight parameter decoding information is obtained at the time of aircraft delivery and that unhindered access is maintained. To facilitate the management of this information, it is recommended that it is consigned in documentation that complies with an electronic documentation standard and has a general public licence policy. In addition, it is advisable to have a versioning system that allows quick identification of the applicable documentation for any individual aircraft and any time period. Such documentation could be fully or partially generated by the FDM software if the software has this capability. (iii) When the airborne equipment used for FDM purposes records a copy of the flight data recorder data stream, the flight data recorder decoding documentation that must be retained in accordance with point CAT.GEN.MPA.195 could be used. (6) Objectives to ensure a good overview of operations Internal objectives regarding the proportion of collected flights, the time from performing the flight to processing its data with the FDM software or the time to detect that no flight data is being collected any more from an individual aeroplane are important to ensure a good overview of operations. It is advisable to set targets that are ambitious enough for this purpose. Examples of internal targets:
Annex I to ED Decision 2025/020/R Page 18 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(i) collect data from at least 90 % of the total number of flights performed in the past 12 months by aeroplanes that are within the scope of point ORO.AOC.130; (ii) identify within 10 calendar days a failure of the means to collect data from any individual aeroplane that is within the scope of point ORO.AOC.130; (iii) process the data of at least 90 % of the collected flights that were performed in the past 12 months within 10 calendar days of the flights’ completion. (e) Implementing an FDM programme (1) General considerations (i) Typically, the following steps are necessary to implement an FDM programme: (A) implementation of a formal agreement between management and flight crew; (B) establishment and verification of operational and security procedures; (C) installation of equipment; (D) selection and training of dedicated and experienced staff to operate the programme; and (E) commencement of data analysis and validation. (ii) An operator with no FDM experience may need a year to achieve an operational FDM programme. Another year may be necessary before any safety and cost benefits appear. Improvements in the analysis software, or the use of outside specialist service providers, may shorten these time frames. (2) Aims and objectives of an FDM programme (i) As with any project there is a need to define the direction and objectives of the work. A phased approach is recommended so that the foundations are in place for possible subsequent expansion into other areas. Using a building block approach will allow expansion, diversification and evolution through experience. Example: with a modular system, begin by looking at basic safety-related issues only. Add engine health monitoring, etc. in the second phase. Ensure compatibility with other systems. (ii) A staged set of objectives starting from the first week’s replay and moving through early production reports into regular routine analysis will contribute to a sense of achievement as milestones are met. Examples of short-term, medium-term and long-term goals: (A) Short-term goals: — establish an FDM team (refer to point (e)(3) below); — establish data download procedures and test replay FDM software, and identify aircraft defects; — verify for all aircraft in the FDM programme that the flight parameters used for FDM events and measurements are valid and correctly decoded — GM1 CAT.GEN.MPA.195(b) contains guidance on evaluating the validity of flight parameters;
Annex I to ED Decision 2025/020/R Page 19 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
— verify that the flight parameter decoding information (see point (d)) is complete and correct; — design and/or adapt FDM algorithms and test them, and validate and investigate FDM events data — for an FDM event algorithm, this includes verifying that the event trigger conditions and the severity level threshold values take into account any applicable aircraft flight manual limit, the SOPs and the distribution of values collected from all operations; and — establish a user-acceptable routine report format to highlight individual FDM events exceedances and facilitate the acquisition of relevant statistics. (B) Medium-term goals: — ensure that the FDM programme meets the minimum data recovery and validation objectives and the data retention objectives; — produce reports and dashboards an annual report — that include key performance indicators in accordance with an established schedule and at a frequency that is sufficient for the proactive handling of safety risks; — add other modules to the analysis (e.g. continuing airworthiness); and — plan for the next fleet to be added to the FDM programme. (C) Long-term goals: — network FDM information across all of the operator’s safety information systems; and — ensure FDM provision for any proposed alternative training and qualification programme (ATQP).; and — use utilisation and condition monitoring to reduce spares holdings. (iii) Initially, focusing on a few known areas of interest will help prove the system’s effectiveness. In contrast to an undisciplined ‘scatter-gun’ approach, a focused approach is more likely to gain early success. Examples for aeroplanes: rushed approaches, or rough runways at particular aerodromes. Analysis of such known problem areas may generate useful information for the analysis of other areas. (3) The FDM team (i) Experience has shown that the ‘team’ necessary to run an FDM programme could vary in size from one person for a small fleet, to a dedicated section for large fleets. The descriptions below identify various functions to be fulfilled, not all of which need a dedicated position. As the safety manager should be responsible for the FDM programme, and FDM outputs should, as much as possible, be analysed in
Annex I to ED Decision 2025/020/R Page 20 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
relation to other safety data sources, the FDM team leader is expected to be part of the safety manager’s team. (A) Team leader: it is essential that the team leader earns the trust and full support of both management and flight crew. The team leader acts independently of others in line management to make recommendations that will be seen by all to have a high level of integrity and impartiality. The individual requires good analytical, presentation and management skills. (B) Flight operations interpreter: this person is usually a current qualified pilot (or perhaps a recently retired senior captain or instructor), who knows the operator’s route network and aircraft. This team member’s in-depth knowledge of SOPs, aircraft handling characteristics, aerodromes and routes is used to place the FDM data in a credible context. (C) Technical interpreter: this person interprets FDM data with respect to the technical aspects of the aircraft operation and is familiar with the information required by the departments in charge of power plant, structures and systems departments’ requirements for information and with any other engineering monitoring programmes in use by the operator. (D) Gate-keeperGatekeeper: this person provides the link between the fleet or training managers and flight crew involved in events highlighted by FDM. The position requires good people skills and a positive attitude towards safety education. The person is typically a representative of the flight crew association or an ‘honest broker’ and is the only person permitted to connect the identifying data with the event. It is essential that this person earns the trust of both management and flight crew. (E) Engineering technical support: this person is usually an avionics specialist, involved in the supervision of mandatory serviceability requirements for FDR systems. This team member is knowledgeable about FDM and the associated systems needed to run the programme. (F) FDM analyst: this person is responsible for the design and validation of FDM algorithms and the analysis of FDM outputs. This usually requires at least basic knowledge of statistics; basic programming skills; detailed knowledge of FDM data flows from the data collection on board the aircraft to the production of FDM-based indicators and dashboards; and in-depth knowledge of the FDM software or service. If the processing of data or the validation of FDM events is subcontracted to a service provider, the FDM analyst should have the necessary skills to effectively control and direct the work performed by that service provider. Replay operative and administrator: this person is responsible for the day-to-day running of the system, producing reports and analysis. (G) FDM administrator: this person is responsible for the day-to-day recovery and processing of the flight data by the FDM software.
Annex I to ED Decision 2025/020/R Page 21 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(ii) All FDM team members need appropriate training or experience for their respective area of data analysis. Each team member is allocated a realistic amount of time to regularly spend on FDM tasks. (f) Other uses of flight data It is recommended to establish a written procedure to prevent the disclosure of crew identity whenever access to flight data or flight data-based information is requested to meet operational needs, such as fuel use optimisation, aircraft performance and preventive maintenance. As a minimum, it is advisable that such a procedure contains: (1) the aim of the programme in which flight data or flight data-based information is to be used; (2) clear data access and security principles regarding access to flight data and flight-databased information by staff members and service providers; (3) data and information retention principles; and (4) the method to obtain de-identified flight crew feedback on those occasions that require specific flight follow-up for contextual information. In case a service provider is granted frequent access to flight data, a non-disclosure agreement is also advisable. (g) The FDM programme and large data exchange programmes Some States and organisations have set up so-called large data exchange programmes, in which very large amounts of data (including FDM data) provided by many operators and by other industry stakeholders are gathered, centrally processed and analysed. Participation in a large data exchange programme may offer an operator various benefits, such as the ability to compare its safety performance with that of comparable operators or access to other types of data (weather, traffic, etc.) or to advanced data integration capabilities. In addition, if an operator with a small fleet produces small amounts of flight data that do not allow reliable trend identification, joining a large data exchange programme may help to overcome this limitation. However, taking part in a large data exchange programme does not in itself satisfy point ORO.AOC.130, and every operator remains responsible for implementing its FDM programme. In addition, the FDM programme needs to be well integrated into the operator’s management system for it to benefit from a large data exchange programme.
GM2 ORO.AOC.130 Flight data monitoring — aeroplanes
EXAMPLES OF FDM METHODSEVENTS Table 1 of this GM provides examples of precursors of incidents that could be monitored through an FDM programme, by means of FDM events or FDM measurements. It is acknowledged that monitoring some of these example precursors may be very complex or the necessary flight parameters may not always be recorded. Methods to monitor these example precursors may be further developed using operator- and aeroplane-specific limits. Therefore, Table 1 is considered illustrative and not exhaustive. Note 1: Key risk areas, as described in the Annex to Commission Delegated Regulation (EU) 2020/2034, correspond to the aviation occurrence categories defined by the Commercial
Annex I to ED Decision 2025/020/R Page 22 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Aviation Safety Team / International Civil Aviation Organization Common Taxonomy Team, as follows: — ‘excursion’ corresponds to ‘runway excursion’ (RE); — ‘aircraft upset’ corresponds to ‘loss of control in flight’ (LOC-I); — ‘terrain collision’ corresponds to ‘controlled flight into or toward terrain’ (CFIT); — ‘airborne collision’ corresponds to ‘aircraft proximity / TCAS alert / loss of separation / near midair collision / midair collision’ (MAC). Note 2: Please refer to the European Operators Flight Data Monitoring forum (EOFDM) document Guidance for the implementation of flight data monitoring precursors for further details on methods to monitor the example precursors of incidents provided in Table 1. Note 3: The far-right column of Table 1 only indicates the occurrence types directly related to the precursors of incidents among those listed in Annex I ‘Occurrences related to the operation of the aircraft’ to Commission Implementing Regulation (EU) 2015/1018. The precursors listed in Table 1 may also be used to detect occurrence types other than those indicated in the far-right column. Note 4: In addition to the precursors of incidents in Table 1, operators may need to monitor caution and warning alerts displayed to the flight crew and other indications that the airworthiness of the aircraft may be affected. FDM events or measurements that monitor significant deviations from the standard operating procedures (SOPs) in all phases of flight, including when the aircraft is on the ground, are also advisable. For brevity, Table 1 does not include such events.
Annex I to ED Decision 2025/020/R Page 23 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Table 1 — Examples of potential precursors of incidents that could be monitored through an FDM programme
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 1 RE01 — Engine power Develop means to detect engine power changes during Excursion (at take-off and landing) No direct link to a specific type of changes during take-off take-off that may lead to a runway excursion occurrence 2 RE02 — Inappropriate Develop means to detect inappropriate aircraft Excursion (at take-off and landing) 1.3(6) Actual or attempted take-off, aircraft configuration configuration (lifting devices, pitch trim) that could cause approach or landing with incorrect take-off and landing performance problems; not all configuration setting aircraft are equipped with take-off configuration warning systems and some of these systems cannot detect all types of configuration errors 3 RE03 — Monitoring the Develop means to detect CG out of limits on take-off or Excursion (at take-off and landing) No direct link to a specific type of centre-of-gravity (CG) not consistent with the pitch trim settings occurrence position 4 RE04 — Reduced elevator Develop means to detect abnormal rotation in response Excursion (at take-off and landing) 2.1(7) Abnormal functioning of flight authority to elevator inputs, reduced elevator movement or controls, such as asymmetric or excessive force required to move the elevator surfaces stuck/jammed flight controls (e.g. lift (flaps/slats), drag (spoilers), attitude control (ailerons, elevators, rudder) devices) 5 RE05 — Slow acceleration Develop means to measure the acceleration during the Excursion (at take-off and landing) 1.3(5) Inability to achieve required or take-off roll and to detect abnormal values, taking into expected performance during take-off, account the various factors that affect the take-off go-around or landing performance 6 RE06 — Aircraft Develop means to detect aircraft malfunctions that are Excursion (at take-off and landing) No direct link to a specific type of malfunction likely to cause rejected take-offs (e.g. ‘master warning’ occurrence
Annex I to ED Decision 2025/020/R Page 24 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor and ‘master caution’ alerts and airspeed indication disagreements) 7 RE07 — Late rotation Develop means to detect rotations conducted after the Excursion (at take-off and landing) No direct link to a specific type of rotation speed or beyond the expected distance (or time) occurrence after the start of the take-off roll 8 RE08 — Slow rotation Develop means to detect slow rotation Excursion (at take-off and landing) No direct link to a specific type of occurrence 9 RE09 — No lift-off Develop means to detect late lift-off (in time and/or Excursion (at take-off and landing) 1.3(5) Inability to achieve required or distance) after rotation or start of the take-off roll expected performance during take-off, go-around or landing 10 RE10 — Rejected take-off Develop means to identify rejected take-off Excursion (at take-off and landing) 1.3(4) Any rejected take-off 11 RE11 — Runway Develop means to estimate the runway remaining ahead Excursion (at take-off and landing) No direct link to a specific type of remaining after rejected of the aircraft after the start of the rejected take-off and occurrence take-off to estimate the ground distance spent during the rejected take-off 12 RE12 — Inadequate use of Develop means to identify late or inadequate activation of Excursion (at take-off and landing) No direct link to a specific type of stopping devices thrust reverser, brakes, airbrakes or other stopping occurrence devices during rejected take-offs and landings 13 RE13 — Insufficient Develop means to detect slow deceleration after landing Excursion (at take-off and landing) No direct link to a specific type of deceleration or rejected take-off, taking into consideration the various occurrence factors that affect the landing and the rejected take-off performance
Annex I to ED Decision 2025/020/R Page 25 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 14 RE14 — Incorrect input Develop means to detect erroneous data entry or Excursion (at take-off and landing) 1.1(1) Use of incorrect data or performance data calculation errors that could lead to incorrect thrust erroneous entries into equipment used settings, incorrect V speeds or incorrect target approach for navigation or performance speeds calculations that has or could have endangered the aircraft, its occupants or any other person 15 RE15 — Runway Develop means to estimate the runway remaining ahead Excursion (at take-off and landing) No direct link to a specific type of remaining at lift-off of the aircraft at the moment of lift-off and to detect occurrence abnormal values 16 RE16 — Aircraft handling Develop means to monitor the use of aircraft controls Excursion (at take-off and landing) No direct link to a specific type of (rudder and nose-wheel steering) and brakes during take- occurrence off, rejected take-off and landing, and to detect nonstandard cases. In addition, monitor simultaneous control inputs of both flight crew and analyse their potential negative influence on safety 17 RE17 — Crosswind Develop means to estimate the crosswind during take-off, Excursion (at take-off and landing) No direct link to a specific type of approach and landing and to detect abnormal values occurrence 18 RE18 — Forward thrust Develop means to identify forward thrust asymmetry Excursion (at take-off and landing) No direct link to a specific type of asymmetry during the take-off roll occurrence 19 RE19 — Steering system Develop means to identify problems with the steering Excursion (at take-off and landing) No direct link to a specific type of malfunction system, which could affect lateral controllability occurrence 20 RE20 — Lateral deviation Develop means to identify excessive lateral deviations or Excursion (at take-off and landing) No direct link to a specific type of oscillations during take-off, rejected take-off and landing, occurrence taking into consideration the runway width
Annex I to ED Decision 2025/020/R Page 26 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 21 RE21 — Reverse thrust Develop means to identify reverse thrust asymmetry Excursion (at take-off and landing) No direct link to a specific type of asymmetry during a rejected take-off or landing occurrence 22 RE22 — Braking Develop means to identify braking asymmetry during a Excursion (at take-off and landing) No direct link to a specific type of asymmetry rejected take-off or landing (possibly in combination with occurrence RE12 ‘Inadequate use of stopping devices’) 23 (Reserved) 24 RE24 — Tailwind Develop means to estimate the tailwind during take-off, Excursion (at take-off and landing) No direct link to a specific type of approach and landing occurrence 25 RE25 — Excessive engine Develop means to monitor the engine power reduction Excursion (at take-off and landing) No direct link to a specific type of power before touchdown and to identify abnormal engine occurrence utilisation in this phase of the flight 26 RE26 — Unstable Develop means to identify and quantify unstable Excursion (at take-off and landing) 1.3(8) Approach continued against air approach approaches, regardless of whether they result in go- operator stabilised approach criteria around manoeuvres 27 RE27 — High energy over Develop means to estimate the height, airspeed and Excursion (at take-off and landing) No direct link to a specific type of the threshold ground speed while crossing the runway threshold occurrence 28 RE28 — Long flare Develop means to detect the start of the flare and to Excursion (at take-off and landing) No direct link to a specific type of estimate the ground distance the aircraft has covered occurrence from the start of the flare until touchdown 29 RE29 — Deep landing Develop means to estimate the distance from the runway Excursion (at take-off and landing) No direct link to a specific type of threshold until the touchdown point and also the runway occurrence length available after touchdown
Annex I to ED Decision 2025/020/R Page 27 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 30 RE30 — Abnormal runway Develop means to identify and quantify bounced (main or Excursion (at take-off and landing) 1.3(7) Tail, blade/wingtip or nacelle contact nose wheels), off-centre, nose-first or asymmetrical strike during take-off or landing landings as well as tail and wingtip strikes 1.3(12) Hard landing 31 RE31 — Go-around Develop means to identify go-arounds and balked Excursion (at take-off and landing) No direct link to a specific type of landings occurrence 32 RE32 — Excessive energy Develop means to correctly identify the touchdown Excursion (at take-off and landing) No direct link to a specific type of at touchdown instant, to measure airspeed and ground speed and to occurrence) identify cases of excessive energy 33 RE33 — Wrong runway or The difference between actual and planned runway or Excursion (at take-off and landing) No direct link to a specific type of wrong runway entry point runway entry point used should be monitored occurrence used 34 RE34 — Erroneous Develop means to detect cases of erroneous guidance Excursion (at take-off and landing) No direct link to a specific type of guidance during approach and landing occurrence 35 LOC01 — Fire, smoke and Develop means to detect the presence of fire, smoke or Aircraft upset 4(2) Any burning, melting, smoke, fumes fumes in the cabin, cargo compartment, engines and fumes, arcing, overheating, fire or landing gear bay explosion 36 LOC02 — Pressurisation Develop means to identify malfunctions of the Aircraft upset 4(7) Uncontrollable cabin pressure system malfunction pressurisation system that could cause crew incapacitation or discomfort. System malfunctions could cause abnormal or unexpected rates of cabin pressure, inability to cope with transients in engine regime, abnormal cabin altitude (not necessarily high enough to trigger alerts for the crew) or reversion from automatic control to manual. There might be scope for integration
Annex I to ED Decision 2025/020/R Page 28 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor with the aircraft health monitoring systems and support for continued airworthiness 37 LOC03 — Pressurisation Develop means to identify the situations where the Aircraft upset No direct link to a specific type of system misuse pressurisation system is not used correctly, for example occurrence failure to turn on the bleed pressure after take-off, failure to set the landing pressure altitude or inadequate use of the manual control mode 38 (Reserved) 39 LOC05 — High cabin Develop means to identify situations of abnormal cabin Aircraft upset No direct link to a specific type of altitude altitude, including but not limited to values that would occurrence trigger cabin altitude alerts (possibly in combination with LOC02 ‘Pressurisation system malfunction’) 40 LOC06 — Oxygen (O2) Develop means to identify situations where the crew Aircraft upset 4(9) Any use of crew O2 system by the masks not deployed and failed to deploy and use the O2 masks in response to real crew not used by the crew or nuisance situations 41 LOC07 — Supplementary Develop means to identify the failure of or leaks in the Aircraft upset 4(9) Any use of crew O2 system by the O2 system failure flight crew supplementary O2 system crew 42 LOC08 — Centre of Develop means to estimate the CG position and to detect Aircraft upset No direct link to a specific type of gravity (CG) out of limits situations where it is beyond the limits or not consistent occurrence with the pitch trim settings as a result of load shifts, incorrect loadings or fuel imbalance 43 LOC09 — Abnormal Develop means to identify operations at or beyond the Aircraft upset 1.4(6) Exceedance of aircraft flight operations edges of the operating envelope or not in compliance manual limitation with SOPs. This should cover all airframe and engine
Annex I to ED Decision 2025/020/R Page 29 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor limitations (as specified in the aircraft flight manual, 2.2(4) Engine operating limitation including but not limited to indicated airspeed/Mach exceedance, including overspeed or versus altitude, vertical speed, G limits, flap speed limits, inability to control the speed of any speed brake limits, tyre speed limits, landing gear limits, high-speed rotating component (e.g. temperature limits, manoeuvrability speeds, engine auxiliary power unit, air starter, air parameters, tailwind, crosswind, excessive rudder inputs) cycle machine, air turbine motor, propeller or rotor) 44 LOC10 — Incorrect Develop means to detect erroneous data entry or Aircraft upset 1.1(1) Use of incorrect data or performance calculation calculation errors that could lead to incorrect thrust erroneous entries into equipment used settings, incorrect V speeds or incorrect target approach for navigation or performance speeds (to be reconciled with recommendation RE01 for calculations that has or could have runway excursions) endangered the aircraft, its occupants or any other person 45 LOC11 — Overweight Develop means to identify overweight take-off situations Aircraft upset No direct link to a specific type of take-off that could have an adverse effect on the climb occurrence performance and obstacle clearance for performancelimited departures (possibly in combination with LOC10 ‘Incorrect performance calculation’) 46 LOC12 — Envelope Develop means to detect in-flight activation of the Aircraft upset 1.4(4) Activation of any flight envelope protection systems envelope protection systems of the aircraft protection, including stall warning, stick shaker, stick pusher and automatic protections 47 LOC13 — Inadequate Develop means to identify situations of inadequate Aircraft upset No direct link to a specific type of aircraft energy aircraft energy (speed and/or altitude and/or thrust) for occurrence each phase of the flight
Annex I to ED Decision 2025/020/R Page 30 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 48 LOC14 — Inadequate Develop means to identify cases of excessive angles of Aircraft upset No direct link to a specific type of aircraft attitude pitch and roll. The identification should take into occurrence consideration the range of values acceptable for each phase of flight 49 LOC15 — Loss of lift Develop means to identify situations of actual loss of lift Aircraft upset 1.4(4) Activation of any flight envelope and cases of operation close to the edges of the lift protection, including stall warning, stick envelope shaker, stick pusher and automatic protections 50 (Reserved) 51 LOC17 — Electromagnetic Develop means to identify cues that could suggest Aircraft upset No direct link to a specific type of interference situations of electromagnetic interference (possibly in occurrence combination with LOC24 ‘Instrument malfunction’) 52 LOC18 — Adverse Develop means to identify the presence of adverse Aircraft upset 5(9) A lightning strike which resulted weather weather in the vicinity of the aircraft in damage to the aircraft or loss or
malfunction of any aircraft system
Annex I to ED Decision 2025/020/R Page 31 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 53 LOC19 — Wind shear Develop means to identify situations of wind shear Aircraft upset 5(12) A significant wind shear or (reactive and predictive) thunderstorm encounter that has or could have endangered the aircraft, its occupants or any other person 54 LOC20 — Severe Develop means to identify situations of severe turbulence Aircraft upset 5(7) Wake-turbulence encounters turbulence caused by different sources (clear-air turbulence, wake 5(11) Severe turbulence encounter or vortex, mountain waves, etc.) any encounter resulting in injury to occupants or deemed to require a ‘turbulence check’ of the aircraft 55 LOC21 — Icing conditions Develop means to identify situations of extremely cold Aircraft upset 5(13) Icing encounter resulting in conditions or icing of the engines, nacelles, propellers, handling difficulties, damage to the wings and airframe. Operation in cold or icing conditions aircraft or loss or malfunction of any is frequent for most aircraft operations; therefore, they aircraft system should not be considered abnormal. The objective is to develop a set of measurements to enable a better
Annex I to ED Decision 2025/020/R Page 32 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor understanding of such environmental conditions in order to assess the response of the aircraft ice detection systems and to support recommendation LOC22 ‘De-icing system failure’ 56 LOC22 — De-icing system Develop means to identify failure, ineffectiveness or Aircraft upset No direct link to a specific type of failure incorrect utilisation (e.g. late activation) of de-icing and occurrence anti-icing systems 57 LOC23 — Engine failure Develop means to identify situations of latent or active Aircraft upset 2.2(5) Failure or malfunction of any part engine failure, including foreign object damage and of an engine, power plant, APU or hardware degradation and failure. There might be scope transmission resulting in any one or for integration with engine health monitoring and more of the following: continued airworthiness (a) thrust-reversing system failing to operate as commanded; (b) inability to control power, thrust or rpm (revolutions per minute); (c) non-containment of components/debris 58 LOC24 — Instrument Develop means to identify situations of instrument Aircraft upset 2.1(6) Malfunction or defect of any malfunction malfunction (possibly in combination with LOC17 indication system when this results in ‘Electromagnetic interference’) misleading indications to the crew 59 (Reserved)
Annex I to ED Decision 2025/020/R Page 33 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 60 LOC26 — Loss of thrust Develop means to identify situations of unintended loss of Aircraft upset 2.2(1) Failure or significant malfunction thrust, or reduced engine performance, taking into of any part or controlling of a propeller, consideration (but not only) the range of values rotor or power plant acceptable for each phase of flight and fuel flow 2.2(3) Flameout, in-flight shutdown of any engine or auxiliary power unit when required (e.g. extended range twin engine aircraft operations, minimum equipment list) 61 LOC27 — Hardware Develop means to identify cues that could suggest the Aircraft upset No direct link to a specific type of failure existence of latent failures in safety-critical components occurrence (including but not limited to landing gears, doors, brakes, wheels and hydraulic systems). There might be scope for integration with the aircraft health monitoring systems and continued airworthiness 62 LOC28 — Flight control Develop means to identify cues that could suggest failure Aircraft upset 2.1(7) Abnormal functioning of flight failure or ineffectiveness of the flight controls controls such as asymmetric or stuck/jammed flight controls (e.g. lift (flaps/slats), drag (spoilers), attitude control (ailerons, elevators, rudder) devices) 63 LOC29 — Develop means to identify situations of inadequate or Aircraft upset 1.4(9) Misinterpretation of automation Mismanagement of unexpected use of automation or unexpected mode or of any flight deck information automation disconnection of automation provided to the flight crew that has or could have endangered the aircraft, its occupants or any other person
Annex I to ED Decision 2025/020/R Page 34 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 64 LOC30 — Abnormal flight Develop means to identify situations of abnormal inputs Aircraft upset No direct link to a specific type of control inputs into thrust controls, control surfaces and lifting devices, occurrence taking into consideration the range of values acceptable for each phase of flight 65 LOC31 — Fuel exhaustion Develop means to identify situations of low fuel Aircraft upset 4(8) Critically low fuel quantity or fuel quantity — by comparison with the planned fuel quantity at destination below required quantity — as the flight proceeds to its destination final reserve fuel. 66 LOC32 — Incorrect Develop means to identify situations of incorrect or Aircraft upset 1.3(6) Actual or attempted take-off, aircraft configuration unusual aircraft configuration for each phase of the flight approach or landing with incorrect configuration setting 67 CFIT01 — Poor visibility Develop means to identify present visibility conditions Collision with terrain No direct link to a specific type of conditions (e.g. instrument meteorological conditions or visual occurrence meteorological conditions 68 CFIT02 — Wrong Develop means to identify wrong altimeter settings Collision with terrain 1.4(7) Operation with incorrect altimeter settings altimeter setting 69 CFIT03 — Flight below Develop means to identify situations of aircraft that fly Collision with terrain 1.3(9) Continuation of an instrument minimum sector altitude below the minimum sector altitude approach below published minimums with inadequate visual references 70 CFIT04 — Deviation below Develop means to identify (severe) deviations below the Collision with terrain 1.3(8) Approach continued against air the glideslope glideslope that increase the controlled flight into terrain operator stabilised approach criteria risk
Annex I to ED Decision 2025/020/R Page 35 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 71 CFIT05 — Flight Develop means to identify errors in the flight Collision with terrain No direct link to a specific type of management system management system settings, especially those associated occurrence incorrectly set with close-to-terrain operations (e.g. approach in a mountainous area) 72 CFIT06 — Inadequate Develop means to identify inadequate vertical mode Collision with terrain 1.4(9) Misinterpretation of automation vertical mode selections selections of the aircraft flight control systems, especially mode or of any flight deck information of the aircraft flight those associated with close-to-terrain operations (e.g. provided to the flight crew that has or control system approach in a mountainous area) could have endangered the aircraft, its occupants or any other person 73 CFIT07 — Incorrect Develop means to identify incorrect descent points Collision with terrain No direct link to a specific type of descent point occurrence 74 CFIT08 — Inadequate Develop means to identify escape manoeuvres after a Collision with terrain 5(3) Activation of genuine ground terrain awareness and triggered TAWS alert that are non-compliant with the collision system such as ground warning system (TAWS) correct manoeuvre or airline SOPs. Approaches with proximity warning system (GPWS) / escape manoeuvre repeated TAWS soft warnings (or just one TAWS warning) terrain awareness and warning system should be monitored. Repeated TAWS soft warnings (TAWS) ‘warning’. during an approach can evidence that either the aircraft was not safe with regard to the terrain potentially due to the approach procedure design, or that the TAWS needs to be adjusted for that particular approach 75 CFIT09 — Inadequate Develop means to identify missed approach and go- Collision with terrain No direct link to a specific type of missed approach and go- around flight paths that are non-compliant with published occurrence around flight path information or airline SOPs
Annex I to ED Decision 2025/020/R Page 36 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 76 CFIT10 — Loss of Develop means to identify loss of communication Collision with terrain, airborne 3(2) Prolonged loss of communication communication collision with air traffic service or air traffic management unit 77 CFIT11 — Low-energy Develop means to identify low-energy states during Collision with terrain No direct link to a specific type of state during approach / approach and unstable approach occurrence unstable approach 78 CFIT12 — Inadequate Develop means to detect inadequate response to wind Collision with terrain 5(12) A significant wind shear or response to wind shear shear warnings, especially in situations close to terrain thunderstorm encounter that has or warnings (e.g. approach in a mountainous area) could have endangered the aircraft, its occupants or any other person 79 CFIT13 — Reduced Develop means to identify scenarios of reduced horizontal Collision with terrain No direct link to a specific type of horizontal distance to distance to terrain occurrence terrain 80 CFIT14 — Reduced time Develop means to identify scenarios of reduced time to Collision with terrain No direct link to a specific type of to terrain impact terrain impact assuming the aircraft maintains current occurrence track and speed 81 CFIT15 — Low climb Develop means to identify scenarios of a reduced climb Collision with terrain No direct link to a specific type of gradient gradient. occurrence 82 MAC01 — Incorrect Develop means to detect incorrect altimeter settings or Airborne collision 1.4(7) Operation with incorrect altimeter setting or incorrect transition timing, which could lead to situations altimeter setting incorrect transition timing of increased mid-air collision risk
Annex I to ED Decision 2025/020/R Page 37 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 83 MAC02 — Lateral Develop means to detect situations where the actual Airborne collision 1.4(5) Unintentional deviation from deviation flight trajectory deviates from the published, cleared or intended or assigned track of the lowest intended trajectory of twice the required navigation performance or 10 nautical miles 84 MAC03 — Flight-level Develop means to identify flight-level busts, that is, Airborne collision 1.4(3) Level bust bust situations where the cleared and intended altitude or flight level is overshot during climb or undershot during descent 85 MAC04 — High rate of Develop means to identify climbs and descents with high Airborne collision No direct link to a specific type of climb/descent rates. Due to the trigger logic of airborne collision occurrence avoidance system (ACAS) alerts, high rates can lead to the generation of nuisance alerts (see MAC08 ‘Airborne collision avoidance system (ACAS) alerts’) 86 MAC05 — Inadequate use Develop means to identify situations of inadequate use of Airborne collision 1.4(9) Misinterpretation of automation of automation automation related to the aircraft trajectory mode or of any flight deck information provided to the flight crew that has or could have endangered the aircraft, its occupants or any other person 87 MAC06 — Automatic Develop means to identify situations of inappropriate Airborne collision No direct link to a specific type of altitude control system settings of the automatic altitude control system in occurrence OFF in reduced vertical reduced vertical separation minima conditions separation minima conditions 88 (Reserved)
Annex I to ED Decision 2025/020/R Page 38 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
No Number and title of the Description of the precursor as per EOFDM Relevant key risk area as described Occurrence types as defined in Annex I precursor as per EOFDM documentation in the Annex to Commission to Commission Implementing documentation Delegated Regulation Regulation (EU) 2015/1018 that are (EU) 2020/2034 directly related to the precursor 89 MAC08 — Airborne Monitor all safety-relevant information with respect to Airborne collision 5(2) ACAS RA (Airborne Collision collision avoidance the ACAS that is available within the FDM. In particular, Avoidance System, Resolution system (ACAS) alerts resolution advisories should be identified and further Advisory). investigated in detail 90 MAC09 — Inappropriate Develop means to monitor the settings of the ACAS and to Airborne collision No direct link to a specific type of airborne collision verify their suitability occurrence avoidance system (ACAS) settings
Annex I to ED Decision 2025/020/R Page 39 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
The following table provides examples of FDM events that may be further developed using operator and aeroplane specific limits. The table is considered illustrative and not exhaustive. Other examples may be found in the documents published by the European Operators Flight Data Monitoring (EOFDM) forum.
Event Group Description Rejected take-off High speed rejected take-off Take-off pitch Pitch rate low or high on take-off Pitch attitude high during take-off Unstick speeds Unstick speed high Unstick speed low Height loss in climb-out Initial climb height loss 20 ft above ground level (AGL) to 400 ft above aerodrome level (AAL) Initial climb height loss 400 ft to 1 500 ft AAL Slow climb-out Excessive time to 1 000 ft AAL after take-off Climb-out speeds Climb-out speed high below 400 ft AAL Climb-out speed high 400 ft AAL to 1 000 ft AAL Climb-out speed low 35 ft AGL to 400 ft AAL Climb-out speed low 400 ft AAL to 1 500 ft AAL High rate of descent High rate of descent below 2 000 ft AGL Missed approach Missed approach below 1 000 ft AAL
Annex I to ED Decision 2025/020/R Page 40 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Event Group Description Missed approach above 1 000 ft AAL Low approach Low on approach Glideslope Deviation under glideslope Deviation above glideslope (below 600 ft AGL) Approach power Low power on approach Approach speeds Approach speed high within 90 seconds of touchdown Approach speed high below 500 ft AAL Approach speed high below 50 ft AGL Approach speed low within 2 minutes of touchdown Landing flap Late land flap (not in position below 500 ft AAL) Reduced flap landing Flap load relief system operation Landing pitch Pitch attitude high on landing Pitch attitude low on landing Bank angles Excessive bank below 100 ft AGL Excessive bank 100 ft AGL to 500 ft AAL Excessive bank above 500 ft AGL Excessive bank near ground (below 20 ft AGL)
Annex I to ED Decision 2025/020/R Page 41 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Event Group Description Normal acceleration High normal acceleration on ground High normal acceleration in flight flaps up (+/- increment) High normal acceleration in flight flaps down(+/- increment) High normal acceleration at landing Abnormal configuration Take-off configuration warning Early configuration change after take-off (flap) Speed brake with flap Speed brake on approach below 800 ft AAL Speed brake not armed below 800 ft AAL Ground proximity warning Ground proximity warning system (GPWS) operation - hard warning GPWS operation — soft warning GPWS operation — windshear warning GPWS operation — false warning Airborne collision avoidance ACAS operation — Resolution Advisory system (ACAS II) warning Margin to stall/buffet Stick shake False stick shake Reduced lift margin except near ground Reduced lift margin at take-off
Annex I to ED Decision 2025/020/R Page 42 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
Event Group Description Low buffet margin (above 20 000 ft) Aircraft flight manual limitations Maximum operating speed limit (VMO)exceedance Maximum operating speed limit (MMO)exceedance Flap placard speed exceedance Gear down speed exceedance Gear selection up/down speed exceedance Flap/slat altitude exceedance Maximum operating altitude exceedance
Annex I to ED Decision 2025/020/R Page 43 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
SUBPART FC: FLIGHT CREW SECTION 2 — ADDITIONAL REQUIREMENTS FOR COMMERCIAL AIR TRANSPORT OPERATIONS
AMC1 ORO.FC.A.245 Alternative training and qualification programme
COMPONENTS AND IMPLEMENTATION (a) Alternative training and qualification programme (ATQP) components The ATQP should comprise the following: […] (5) A feedback loop for the purpose of curriculum validation and refinement, and to ascertain that the programme meets its proficiency objectives. (i) The feedback should be used as a tool to validate that the curricula are implemented as specified by the ATQP; this enables substantiation of the curriculum, and that proficiency and training objectives have been met. The feedback loop should include data from operations flight data monitoring, the advanced flight data monitoring (FDM) programme and LOE/LOQE programmes. In addition, the evaluation process should describe whether the overall targets/objectives of training are being achieved and should prescribe any corrective action that needs to be undertaken. […] (7) An data monitoring FDM/analysis programme consisting of the following: (i) A flight data monitoring (FDM) programme, as specified described in AMC1 ORO.AOC.130. Data collection should reach a minimum of 60 % of all relevant flights conducted by the operator before ATQP approval is granted. This proportion may be increased as determined by the competent authority. (ii) An advanced FDM when an extension to the ATQP is requested: an advanced FDM programme is determined by the level of integration with other safety initiatives implemented by the operator, such as the operator’s safety management system. The programme should include both systematic evaluations of data from an FDM programme and flight crew training events for the relevant crews. Data collection should reach a minimum of 80 % of all relevant flights and training conducted by the operator. This proportion may be varied as determined by the competent authority. The purpose of an FDM or advanced FDM programme for ATQP is to enable the operator to: (i) The FDM programme should be used to:
Annex I to ED Decision 2025/020/R Page 44 of 45
AMC & GM to Part-ORO Issue 2, Amendment 29
(A) provide data to support the ATQP’s programme’s implementation and justify any changes to the ATQP; […] (iii) Data gathering: The FDM programme should provide the person responsible for ATQP with the information they need. Subject to the procedure to prevent disclosure of crew identity (refer to point (k) of AMC1 ORO.AOC.130), the information should be sufficiently detailed to allow targeted changes to the training programme to be defined. the data analysis should be made available to the person responsible for ATQP within the organisation. The data gathered by the FDM programme for this purpose should: […] (iiiiv) Data handling: the The operator should establish a procedure to ensure the confidentiality of individual flight crew members, as described by AMC1 ORO.AOC.130. FDM-based information transmitted to the person responsible for ATQP, which should be consistent with the procedure to prevent disclosure of crew identity specified in AMC1 ORO.AOC.130. (ivv) […] […]
Annex I to ED Decision 2025/020/R Page 45 of 45