European aviation consulting, SORA, risk, audits and compliance

How to prepare your operation for an EASA SMS compliance audit

A practical checklist for aviation safety managers conducting pre-audit document reviews, gap analyses, and operational sampling.

By Stian Lindberg·September 24, 2026·3 min read
What matters here
  1. Document reviews must verify that written SMS procedures match everyday operational records and risk logs.
  2. Internal gap analyses fail when safety managers audit their own departments without independent oversight.
  3. Sampling frontline hazard reports reveals whether your safety reporting culture satisfies EASA inspectors.

The reality of EASA SMS audits

Inspectors do not check your manual for literary quality. They look for proof of active risk management. Under EASA regulations and Norwegian aviation law, a Safety Management System (SMS) must function as a living operational routine, not a binder gathering dust on a shelf.

When regulators schedule an audit, quality managers often scramble to update documentation. That is a mistake. Patching manuals two weeks before an inspection creates clear contradictions between paper policy and daily flight or maintenance operations. To pass an EASA SMS audit without major non-conformities, you need a systematic pre-audit preparation strategy.

Step 1: Execute a comprehensive documentation review

Start your preparation by cross-referencing your core SMS documentation with current regulation. EASA requires four core components: safety policy, safety risk management, safety assurance, and safety promotion.

Review your SMS Manual, Emergency Response Plan, and safety risk registers. Check that every role defined in your manual currently exists and that the assigned personnel carry out those duties. In operations across Norway, Sweden, and Denmark, organizational shifts frequently leave manuals out of date.

Look specifically at how hazards are recorded. If your risk assessment process uses customized risk matrices, ensure the scoring methods align with your real-world operating conditions. For operators handling challenging terrain or maritime weather, reviewing how to build an aviation risk classification matrix for Nordic terrain helps ensure your risk scales remain defensible during regulatory review.

Step 2: Conduct an objective gap analysis

A gap analysis identifies missing elements between EASA requirements and your actual practices. The biggest mistake safety teams make is letting department heads audit their own processes. Self-auditing produces blind spots.

Structure your gap analysis around three core questions:

  • Requirement: What specific EASA regulation applies to this process?
  • Implementation: Do we have a documented procedure that fulfills this requirement?
  • Evidence: Can we prove frontline staff follow this procedure every day?

If a procedure exists on paper but lacks physical records—such as completed safety committee minutes, closed-out corrective actions, or safety monitoring reports—mark it as a gap. EASA auditors treat unevidenced processes as non-compliant.

Step 3: Test frontline safety reporting culture

An SMS lives or dies by its reporting culture. Auditors will not just interview the Accountable Manager; they will talk to pilots, technicians, and dispatchers. They want to know if staff feel safe reporting errors without fear of reprisal.

Pull a random sample of safety reports from the previous 12 months. Evaluate the following metrics:

  • Time elapsed between report submission and initial safety review.
  • Percentage of reports that resulted in root-cause analysis.
  • Feedback delivered back to the reporting employee.

If your hazard log shows zero reported errors over six months, regulators will not assume your operation is perfect. They will assume your reporting system is broken.

Step 4: Perform operational sampling and mock interviews

Do not wait for the regulator to ask staff hard questions. Conduct internal interviews with key post-holders and operational personnel before the audit team arrives.

Ask line personnel basic questions about emergency procedures and hazard submission. Can an engineer locate the safety report portal in under two minutes? Can a flight coordinator explain how risk controls apply to their shift?

Verify that corrective and preventive action plans from previous internal or regulatory audits are closed out. Open findings from prior years are an immediate red flag for inspectors.

Step 5: Bring in independent compliance advisory

Internal safety managers are often too close to daily operations to spot systematic defects. Engaging external compliance advisory provides an impartial review of your system before official inspectors arrive.

Experienced air traffic controllers and aviation safety specialists can run full-scale mock audits, testing both document integrity and operational execution. Working with specialized advisors who understand both EASA standards and local civil aviation requirements across Norway, Sweden, and Denmark helps bridge the gap between regulatory theory and practical airspace operations. With over 30 years of experience and more than 20 successful aviation projects delivered, independent compliance reviews consistently catch critical findings before official audits begin.

Final audit readiness checklist

Before opening your doors to EASA inspectors, confirm that:

  1. Your Safety Policy is signed by the current Accountable Manager.
  2. The hazard register is updated with recent operational changes.
  3. All safety committee meetings have documented, signed minutes.
  4. Prior audit findings have verified corrective actions attached.
  5. Staff across all departments can demonstrate how to file a hazard report.
  6. Rule-based compliance advisory and thorough pre-audit checks ensure your organization meets regulatory requirements while maintaining safe, efficient operations.
More from North Sky Aviation Consultancy News