My bookmarksSign up free

Commission Implementing Regulation (EU) 2017/373 ANNEX II

Commission Implementing Regulation (EU) 2017/373 ANNEX II

ANNEX IISupplementary provisions

ANNEX II REQUIREMENTS FOR COMPETENT AUTHORITIES — OVERSIGHT OF SERVICES AND OTHER ATM NETWORK FUNCTIONS (Part-ATM/ANS.AR) SUBPART A — GENERAL REQUIREMENTS ATM/ANS.AR.A.001 Scope This Annex establishes the requirements for the administration and management systems of the competent authorities responsible for certification, oversight and enforcement in respect of the application of the requirements set out in Annexes III to XIII by the service providers in accordance with Article 6. ATM/ANS.AR.A.005 Certification, oversight and enforcement tasks (a) The competent authority shall exercise certification, oversight and enforcement tasks in respect of the application of the requirements applicable to service providers, monitor the safe provision of their services and verify that the applicable requirements are met. (b) The competent authorities shall identify and exercise the responsibilities for certification, oversight and enforcement in a manner which ensures that: (1) specific points of responsibility exist to implement each provision of this Regulation; (2) they are aware of the safety oversight mechanisms and their results; (3) relevant information exchange is ensured between competent authorities. The competent authorities concerned shall regularly review the agreement on the supervision of the service providers providing air navigation services in functional airspace blocks (FABs) that extend across the airspace falling under the responsibility of more than one Member States referred to in Article 2(3) of Regulation (EC) No 550/2004 and, in the case of cross-border provision of air navigation services, the agreement on the mutual recognition of supervisory tasks referred to in Article 2(5) of Regulation (EC) No 550/2004, as well as the practical implementation of those agreements, in particular in the light of achieved safety performance of the service providers under their supervision. (c) The competent authority shall establish coordination arrangements with other competent authorities for notified changes to functional systems involving service providers under the oversight of the other competent authorities. Those coordination arrangements shall ensure the effective selection and review of those notified changes, in accordance with point ATM/ANS.AR.C.025. ATM/ANS.AR.A.010 Certification, oversight and enforcement documentation The competent authority shall make available the relevant legislative acts, standards, rules, technical publications and related documents to its personnel in order to perform their tasks and to discharge their responsibilities. ATM/ANS.AR.A.015 Means of compliance (a) The Agency shall develop acceptable means of compliance (AMC) that may be used to establish compliance with the requirements of this Regulation. When AMC are complied with, the applicable requirements of this Regulation shall be deemed to have been met. (b) Alternative means of compliance (AltMOC) may be used to establish compliance with the requirements of this Regulation. (c) The competent authority shall establish a system to consistently evaluate that all AltMOC used by itself or by the service providers under its oversight allow the establishment of compliance with the requirements of this Regulation. (d) The competent authority shall evaluate all AltMOC proposed by a service provider in accordance with point ATM/ANS.OR.A.020 by analysing the documentation provided and, if considered necessary, conducting an inspection of the service provider. When the competent authority finds that the AltMOC are sufficient to ensure compliance with the applicable requirements of this Regulation it shall without undue delay: (1) notify the applicant that the AltMOC may be implemented and, if applicable, amend the certificate of the applicant accordingly; (2) notify the Agency of their content, including copies of all relevant documentation; (3) inform other Member States about the AltMOC that were accepted. (e) When the competent authority itself uses AltMOC to achieve compliance with the applicable requirements of this Regulation, it shall: (1) make them available to all service providers under its oversight; (2) notify the Agency without undue delay. The competent authority shall provide the Agency with a full description of the AltMOC, including any revisions to procedures that may be relevant, as well as an assessment demonstrating that the applicable requirements of this Regulation are met. ATM/ANS.AR.A.020 Information to the Agency (a) The competent authority shall without undue delay notify the Agency in case of any significant problems with the implementation of the relevant provisions of Regulation (EC) No 216/2008 and its implementing rules or of Regulations (EC) No 549/2004, (EC) No 550/2004, (EC) No 551/2004 and Regulation (EC) No 552/2004 of the European Parliament and of the Council  ( 1 ) applicable to service providers. (b) Without prejudice to Regulation (EU) No 376/2014 of the European Parliament and of the Council  ( 2 ) , the competent authority shall provide the Agency with safety-significant information stemming from the occurrence reports it has received. ATM/ANS.AR.A.025 Immediate reaction to safety problem (a) Without prejudice to Regulation (EU) No 376/2014, the competent authority shall implement a system to appropriately collect, analyse, and disseminate safety information. (b) The Agency shall implement a system to appropriately analyse any relevant safety information received from the competent authorities and without undue delay provide to Member States and the Commission, as appropriate, any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to a safety problem involving the service providers. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the safety problem, including the issuing of safety directives in accordance with point ATM/ANS.AR.A.030. (d) Measures taken under point (c) shall immediately be notified to the service providers concerned to comply with them, in accordance with point ATM/ANS.OR.A.060. The competent authority shall also notify those measures to the Agency and, when combined action is required, the other competent authorities concerned. ATM/ANS.AR.A.030 Safety directives (a) The competent authority shall issue a safety directive when it has determined the existence of an unsafe condition in a functional system requiring immediate action. (b) The safety directive shall be forwarded to the service providers concerned and contain, as a minimum, the following information: (1) the identification of the unsafe condition; (2) the identification of the affected functional system; (3) the actions required and their rationale; (4) the time limit for completing the actions required; (5) its date of entry into force. (c) The competent authority shall forward a copy of the safety directive to the Agency and any other competent authorities concerned within one month from its issuance. (d) The competent authority shall verify the compliance of service providers with the applicable safety directives. SUBPART B — MANAGEMENT (ATM/ANS.AR.B) ATM/ANS.AR.B.001 Management system (a) The competent authority shall establish and maintain a management system, including, as a minimum, the following elements: (1) documented policies and procedures to describe its organisation, means and methods to achieve compliance with Regulation (EC) No 216/2008 and its implementing rules as necessary for the exercise of its certification, oversight and enforcement tasks under this Regulation. The procedures shall be kept up to date and serve as the basic working documents within that competent authority for all related tasks; (2) a sufficient number of personnel, including inspectors, to perform its tasks and discharge its responsibilities under this Regulation. Such personnel shall be qualified to perform their allocated tasks and have the necessary knowledge, experience, initial, on-the-job and recurrent training to ensure continuing competence. A system shall be in place to plan the availability of personnel, in order to ensure the proper completion of all related tasks; (3) adequate facilities and office accommodation to perform those allocated tasks; (4) a process to monitor compliance of the management system with the relevant requirements and adequacy of the procedures, including the establishment of an internal audit process and a safety risk management process. Compliance monitoring shall include a feedback system of audit findings to the senior management of the competent authority to ensure implementation of corrective actions as necessary; (5) a person or group of persons ultimately responsible to the senior management of the competent authority for the compliance monitoring function. (b) The competent authority shall, for each field of activity included in the management system, appoint one or more persons with the overall responsibility for the management of the relevant task(s). (c) The competent authority shall establish procedures for participation in a mutual exchange of all necessary information and assistance with other competent authorities concerned, including exchange of all findings raised and follow-up actions taken as a result of certification and oversight of service providers exercising activities in the territory of a Member State, but certified by the competent authority of another Member State or the Agency. (d) A copy of the procedures related to the management system and their amendments shall be made available to the Agency for the purpose of standardisation. ATM/ANS.AR.B.005 Allocation of tasks to qualified entities (a) The competent authority may allocate its tasks related to the certification or oversight of service providers under this Regulation, other than the issuance of certificates themselves, to qualified entities. When allocating such tasks, the competent authority shall ensure that it has: (1) a system in place to initially and continuously assess that the qualified entity complies with Annex V to Regulation (EC) No 216/2008. This system and the results of the assessments shall be documented; and (2) established a documented agreement with the qualified entity, approved by both parties at the appropriate management level, which clearly defines: (i) the tasks to be performed; (ii) the declarations, reports and records to be provided; (iii) the technical conditions to be met when performing such tasks; (iv) the related liability coverage; (v) the protection given to information acquired when carrying out such tasks. (b) The competent authority shall ensure that the internal audit process and the safety risk management process required by point ATM/ANS.AR.B.001(a)(4) cover all tasks performed on its behalf by the qualified entity. ATM/ANS.AR.B.010 Changes in the management system (a) The competent authority shall have a system in place to identify changes that affect its capability to perform its tasks and discharge its responsibilities under this Regulation. This system shall enable it to take action, as appropriate, to ensure that the management system remains adequate and effective. (b) The competent authority shall update its management system to reflect any change to this Regulation in a timely manner, so as to ensure effective implementation. (c) The competent authority shall notify the Agency of significant changes affecting its capability to perform its tasks and discharge its responsibilities under this Regulation ATM/ANS.AR.B.015 Record-keeping (a) The competent authority shall establish a system of record-keeping providing for adequate storage, accessibility, and reliable traceability of: (1) the management system's documented policies and procedures; (2) training, qualification, and authorisation of personnel as required by point ATM/ANS.AR.B.001(a)(2); (3) the allocation of tasks, covering the elements required by point ATM/ANS.AR.B.005, as well as the details of tasks allocated; (4) certification and/or declaration processes; (5) designations of air traffic services and meteorological services providers, as appropriate; (6) certification and oversight of service providers exercising activities within the territory of the Member State, but certified by the competent authority of another Member State or the Agency, as agreed between those authorities; (7) the evaluation and notification to the Agency of AltMOC proposed by service providers and the assessment of AltMOC used by the competent authority itself; (8) compliance of service providers with the applicable requirements of this Regulation after the issuance of the certificate or, where relevant, submission of a declaration, including the reports of all audits, covering findings, corrective actions, and date of action closure, and observations as well as other safety-related records; (9) enforcement measures taken; (10) safety information, safety directives and follow-up measures; (11) the use of flexibility provisions in accordance with Article 14 of Regulation (EC) No 216/2008. (b) The competent authority shall maintain a list of all service provider certificates issued and declarations received. (c) All records shall be kept for a minimum period of 5 years after the certificate ceases to be valid or the declaration is withdrawn, subject to the applicable data protection law. SUBPART C — OVERSIGHT, CERTIFICATION AND ENFORCEMENT (ATM/ANS.AR.C) ATM/ANS.AR.C.001 Monitoring of safety performance (a) The competent authorities shall regularly monitor and assess the safety performance of the service providers under their oversight. (b) The competent authorities shall use the results of the monitoring of safety performance in particular within their risk-based oversight. ATM/ANS.AR.C.005 Certification, declaration, and verification of service providers' compliance with the requirements (a) Within the framework of point ATM/ANS.AR.B.001(a)(1), the competent authority shall establish a process in order to verify: (1) service providers' compliance with the applicable requirements set out in Annexes III to XIII, and any applicable conditions attached to the certificate before the issue of that certificate. The certificate shall be issued in accordance with Appendix 1 to this Annex; (2) compliance with any safety-related obligations in the designation act issued in accordance with Article 8 of Regulation (EC) No 550/2004; (3) continued compliance with the applicable requirements of the service providers under its oversight; (4) implementation of safety objectives, safety requirements and other safety-related conditions identified in declarations of verification of systems, including any relevant declaration of conformity or suitability for use of constituents of systems issued in accordance with Regulation (EC) No 552/2004; (5) the implementation of safety directives, corrective actions and enforcement measures. (b) The process referred to in point (a) shall: (1) be based on documented procedures; (2) be supported by documentation specifically intended to provide its personnel with guidance to perform their tasks related to certification, oversight and enforcement; (3) provide the organisation concerned with an indication of the results of the certification, oversight and enforcement activity; (4) be based on audits, reviews and inspections conducted by the competent authority; (5) with regard to certified service providers, provide the competent authority with the evidence needed to support further action, including measures referred to in Article 9 of Regulation (EC) No 549/2004, Article 7(7) of Regulation (EC) No 550/2004, and by Articles 10, 25, and 68 of Regulation (EC) No 216/2008 in situations where requirements are not complied with; (6) with regard to service providers making declarations, provide the competent authority with the evidence to take, if appropriate, remedial action which may include enforcement actions, including, where appropriate, under national law. ATM/ANS.AR.C.010 Oversight (a) The competent authority, or qualified entities acting on its behalf, shall conduct audits, in accordance with Article 5. (b) The audits referred to in point (a) shall: (1) provide the competent authority with evidence of compliance with the applicable requirements and with the implementing arrangements; (2) be independent of any internal auditing activities undertaken by the service provider; (3) cover complete implementing arrangements or elements thereof, and processes or services; (4) determine whether: (i) the implementing arrangements comply with the applicable requirements; (ii) the actions taken comply with the implementing arrangements and the applicable requirements; (iii) the results of actions taken match the results expected from the implementing arrangements. (c) The competent authority shall, on the basis of the evidence at its disposal, monitor the continuous compliance with the applicable requirements of this Regulation of the service providers under its oversight. ATM/ANS.AR.C.015 Oversight programme (a) The competent authority shall establish and update annually an oversight programme taking into account the specific nature of the service providers, the complexity of their activities, the results of past certification and/or oversight activities and shall be based on the assessment of associated risks. It shall include audits, which shall: (1) cover all the areas of potential safety concern, with a focus on those areas where problems have been identified; (2) cover all the service providers under the supervision of the competent authority; (3) cover the means implemented by the service provider to ensure the competency of personnel; (4) ensure that audits are conducted in a manner commensurate with the level of the risk posed by the service provider operations and services provided; and (5) ensure that for service providers under its supervision, an oversight planning cycle not exceeding 24 months is applied. The oversight planning cycle may be reduced if there is evidence that the safety performance of the service provider has decreased. For a service provider certified by the competent authority, the oversight planning cycle may be extended to a maximum of 36 months if the competent authority has established that, during the previous 24 months: (i) the service provider has demonstrated an effective identification of aviation safety hazards and management of associated risks; (ii) the service provider has continuously demonstrated compliance with the change management requirements under points ATM/ANS.OR.A.040 and ATM/ANS.OR.A.045; (iii) no level 1 findings have been issued; (iv) all corrective actions have been implemented within the time period accepted or extended by the competent authority as defined in point ATM/ANS.AR.C.050. If, in addition to the above, the service provider has established an effective continuous reporting system to the competent authority on the safety performance and regulatory compliance of the service provider, which has been approved by the competent authority, the oversight planning cycle may be extended to a maximum of 48 months; (6) ensure follow-up of the implementation of corrective actions; (7) be subject to consultation with the service providers concerned and notification thereafter; (8) indicate the envisaged interval of the inspections of the different sites, if any. (b) The competent authority may decide to modify the objectives and the scope of pre-planned audits, including documentary reviews and additional audits, wherever that need arises. (c) The competent authority shall decide which arrangements, elements, services, functions, physical locations, and activities are to be audited within a specified time frame. (d) Audit observations and findings issued in accordance with point ATM/ANS.AR.C.050 shall be documented. The latter shall be supported by evidence, and identified in terms of the applicable requirements and their implementing arrangements against which the audit has been conducted. (e) An audit report, including the details of the findings and observations, shall be drawn up and communicated to the service provider concerned. ATM/ANS.AR.C.020 Issue of certificates (a) Following the process laid down in point ATM/ANS.AR.C.005(a), upon receiving an application for the issuance of a certificate to a service provider, the competent authority shall verify the service provider's compliance with the applicable requirements of this Regulation. (b) The competent authority may require any audits, inspections or assessments it finds necessary before issuing the certificate. (c) The certificate shall be issued for an unlimited duration. The privileges of the activities that the service provider is approved to conduct shall be specified in the service provision conditions attached to the certificate. (d) The certificate shall not be issued where a level 1 finding remains open. In exceptional circumstances, finding(s), other than level 1, shall be assessed and mitigated as necessary by the service provider and a corrective action plan for closing the finding(s) shall be approved by the competent authority prior to the certificate being issued. ATM/ANS.AR.C.025 Changes (a) Upon receiving a notification for a change in accordance with point ATM/ANS.OR.A.045, the competent authority shall comply with points ATM/ANS.AR.C.030, ATM/ANS.AR.C.035 and ATM/ANS.AR.C.040. (b) Upon receiving a notification for a change in accordance with point ATM/ANS.OR.A.040(a)(2) that requires prior approval, the competent authority shall: (1) verify the service provider's compliance with the applicable requirements before issuing the change approval; (2) take immediate appropriate action, without prejudice to any additional enforcement measures, when the service provider implements changes requiring prior approval without having received competent authority approval referred to in point (1). (c) To enable a service provider to implement changes to its management system and/or safety management system, as applicable, without prior approval in accordance with point ATM/ANS.OR.A.040 (b), the competent authority shall approve a procedure defining the scope of such changes and describing how such changes will be notified and managed. In the continuous oversight process, the competent authority shall assess the information provided in the notification to verify whether the actions taken comply with the approved procedures and applicable requirements. In case of any non-compliance, the competent authority shall: (1) notify the service provider of the non-compliance and request further changes; (2) in case of level 1 and level 2 findings, act in accordance with point ATM/ANS.AR.C.050. ATM/ANS.AR.C.030 Approval of change management procedures for functional systems (a) The competent authority shall review: (1) change management procedures for functional systems or any material modification to those procedures submitted by the service provider in accordance with point ATM/ANS.OR.B.010(b); (2) any deviation from the procedures referred to in point (1) for a particular change, when requested by a service provider in accordance with point ATM/ANS.OR.B.010(c)(1). (b) The competent authority shall approve the procedures, modifications and deviations referred to in point (a) when it has determined that they are necessary and sufficient for the service provider to demonstrate compliance with points ATM/ANS.OR.A.045, ATM/ANS.OR.C.005, ATS.OR.205, and ATS.OR.210, as applicable. ATM/ANS.AR.C.035 Decision to review a notified change to the functional system (a) Upon receipt of a notification in accordance with point ATM/ANS.OR.A.045(a)(1), or upon receipt of modified information in accordance with point ATM/ANS.OR.A.045(b), the competent authority shall make a decision on whether to review the change or not. The competent authority shall request any additional information needed from the service provider to support this decision. (b) The competent authority shall determine the need for a review based on specific, valid and documented criteria that, as a minimum, ensure that the notified change is reviewed if the combination of the likelihood of the argument being complex or unfamiliar to the service provider and the severity of the possible consequences of the change is significant. (c) When the competent authority decides the need for a review based on other risk based criteria in addition to point (b), these criteria shall be specific, valid and documented. (d) The competent authority shall inform the service provider of its decision to review a notified change to a functional system and provide the associated rationale to the service provider upon request. ATM/ANS.AR.C.040 Review of a notified change to the functional system (a) When the competent authority reviews the argument for a notified change, it shall: (1) assess the validity of the argument presented with respect to point ATM/ANS.OR.C.005(a)(2) or ATS.OR.205(a)(2); (2) coordinate its activities with other competent authorities whenever necessary. (b) The competent authority shall, alternatively: (1) approve the argument referred to in point (a)(1), with conditions where applicable, when it is shown to be valid and so inform the service provider, (2) reject the argument referred to in point (a)(1) and inform the service provider together with a supporting rationale. ATM/ANS.AR.C.045 Declarations of flight information services providers (a) Upon receiving a declaration from a provider of flight information services intending to provide such services, the competent authority shall verify that the declaration contains all the information required by point ATM/ANS.OR.A.015 and shall acknowledge receipt of the declaration to that service provider. (b) If the declaration does not contain the required information, or contains information that indicates non-compliance with the applicable requirements, the competent authority shall notify the provider of flight information services concerned about the non-compliance and request further information. If necessary, the competent authority shall carry out an audit of the provider of flight information services. If the non-compliance is confirmed, the competent authority shall take action provided for in point ATM/ANS.AR.C.050. (c) The competent authority shall keep a register of the declarations of providers of flight information services which were made to it in accordance with this Regulation. ATM/ANS.AR.C.050 Findings, corrective actions, and enforcement measures (a) The competent authority shall have a system to analyse findings for their safety significance and decide on enforcement measures on the basis of the safety risk posed by the service provider's non-compliance. (b) In circumstances where no or very low additional safety risk would be present with immediate appropriate mitigation measures, the competent authority may accept the provision of services to ensure continuity of service whilst corrective actions are being taken. (c) A level 1 finding shall be issued by the competent authority when any serious non-compliance is detected with the applicable requirements of Regulation (EC) No 216/2008 and its implementing rules as well as Regulations (EC) No 549/2004, (EC) No 550/2004, (EC) No 551/2004, and (EC) No 552/2004 and their implementing rules, with the service provider's procedures and manuals, with the terms of conditions of certificate or certificate, with the designation act, if applicable, or with the content of a declaration which poses a significant risk to flight safety or otherwise calls into question the service provider's capability to continue operations. Level 1 findings shall include but not be limited to: (1) promulgating operational procedures and/or providing a service in a way which introduces a significant risk to flight safety; (2) obtaining or maintaining the validity of the service provider's certificate by falsification of submitted documentary evidence; (3) evidence of malpractice or fraudulent use of the service provider's certificate; (4) the lack of an accountable manager. (d) A level 2 finding shall be issued by the competent authority when any other non-compliance is detected with the applicable requirements of Regulation (EC) No 216/2008 and its implementing rules as well as Regulations (EC) No 549/2004, (EC) No 550/2004, (EC) No 551/2004, and (EC) No 552/2004 and their implementing rules, with the service provider's procedures and manuals or with the terms of conditions or certificate, or with the content of a declaration. (e) When a finding is detected, during oversight or by any other means, the competent authority shall, without prejudice to any additional action required by Regulation (EC) No 216/2008 and this Regulation, as well as Regulations (EC) No 549/2004, (EC) No 550/2004, (EC) No 551/2004 and (EC) No 552/2004 and their implementing rules, communicate the finding to the service provider in writing and require corrective action to address the non-compliance(s) identified. (1) In the case of level 1 findings, the competent authority shall take immediate and appropriate action, and may, if appropriate, limit, suspend or revoke in whole or in part the certificate while ensuring the continuity of services provided that safety is not compromised, and in the case of the Network Manager, it shall inform the Commission. The measure taken shall depend upon the extent of the finding and shall remain until successful corrective action has been taken by the service provider. (2) In the case of level 2 findings, the competent authority shall: (i) grant the service provider a corrective action implementation period included in an action plan appropriate to the nature of the finding; (ii) assess the corrective action and implementation plan proposed by the service provider and, if the assessment concludes that they are sufficient to address the non-compliance(s), accept them. (3) In the case of level 2 findings, where the service provider fails to submit a corrective action plan that is acceptable to the competent authority in light of the finding, or where the service provider fails to perform the corrective action within the time period accepted or extended by the competent authority, the finding may be raised to a level 1 finding, and action taken as laid down in point (1). (f) For those cases not requiring level 1 and 2 findings, the competent authority may issue observations. ( 1 )   Regulation (EC) No 552/2004 of the European Parliament and of the Council of 10 March 2004 on the interoperability of the European Air Traffic Management network (the interoperability Regulation) ( OJ L 96, 31.3.2004, p. 26 ). ( 2 )   Reulation (EU) No 376/2014 of the European Parliament and of the Council of 3 April 2014 on the reporting, analysis and follow-up of occurrences in civil aviation, amending Regulation (EU) No 996/2010 of the European Parliament and of the Council and repealing Directive 2003/42/EC of the European Parliament and of the Council and Commission Regulations (EC) No 1321/2007 and (EC) No 1330/2007 ( OJ L 122, 24.4.2014, p. 18 ).

Read the full instrument →

Other provisions in Commission Implementing Regulation (EU) 2017/373

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationANNEX II of Commission Implementing Regulation (EU) 2017/373 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next