Comparison
Can you run an FAA Part 5 SMS on spreadsheets?
Technically, yes. Nothing in 14 CFR Part 5 requires software. The question is not whether it is permitted but where it stops being defensible — and that point arrives earlier than most operators expect.
The honest answer first
A very small operation, run by a disciplined person, can satisfy Part 5 with a spreadsheet, a shared drive and a calendar. The rule specifies outcomes and records, not tooling. If you are a single-aircraft operator who genuinely will maintain it, you can make this work.
Most operators who intend to do this do not. Not through carelessness — because the spreadsheet has no way to make you.
Five places it breaks
1. Confidential reporting
A shared spreadsheet cannot take an anonymous report. Everyone with access sees who wrote what, and everyone knows it. That suppresses exactly the reports Part 5 is designed to surface. You can bolt on a paper box or a generic form, and now your hazard data lives in two places that do not reconcile.
2. Nothing chases you
The hardest element to satisfy is safety assurance — showing that controls actually worked. That requires going back weeks or months after applying a mitigation and recording a residual score. A spreadsheet will never remind you. A calendar entry might, until the week it gets dismissed during a busy period and never returns.
3. No audit trail
A cell can be changed and there is no record it ever held a different value. When an inspector asks when a risk score was assigned, or who closed a hazard and on what basis, "the spreadsheet says 12" is not an answer. Status history with actor and timestamp is the thing being asked for.
4. Evidence of receipt
Safety promotion asks you to communicate safety information. Demonstrating that means showing it reached people. An email to a distribution list shows you sent something. Per-person acknowledgment with a timestamp shows it was received.
5. Trends stay invisible
Three separate reports over four months, written by three different pilots in three different styles, describing the same underlying problem. In a spreadsheet those are three rows. Nobody reads rows 14, 31 and 47 together. Consistent categorisation and tagging is what turns them into a pattern you can act on before the fourth one is an incident.
Where the line actually falls
Spreadsheets tend to stop being viable when any of these becomes true:
- More than one person needs to file a report and expects it to stay confidential.
- You have more than a handful of open hazards with controls awaiting verification.
- You cannot answer "what was the residual risk on that, and when did we check?" from memory.
- You are within eighteen months of filing and cannot produce a clean export of your risk register.
A fair comparison
| Spreadsheet | Purpose-built SMS | |
|---|---|---|
| Cost | Effectively free | From $99/month |
| Setup time | An afternoon | Guided, with onboarding |
| Anonymous reporting | No | Yes |
| Change history | No | Status history with actor and timestamp |
| Control validation reminders | No | Automated |
| Acknowledgment tracking | No | Per user, timestamped |
| Redacted export for the FAA | Manual, error-prone | One click |
| Discipline required | Total | Ordinary |
That last row is the real one. Both approaches can satisfy the regulation. One of them depends entirely on you never getting busy.
See whether it fits your operation
Twenty minutes, no card. Tell us what certificate you hold and where your implementation plan stands, and we will show you the parts that apply to you.