The structure of the rule
The four pillars and twelve elements of an FAA SMS
Every safety management system under 14 CFR Part 5 is built on four pillars. Understanding what each one is actually asking for is the difference between a compliant system and a folder of documents.
Pillar 1 — Safety Policy (§ 5.21–5.27)
The organisational foundation. This pillar establishes that safety is a management responsibility with a name attached to it, not a diffuse aspiration.
- Safety policy. A documented policy, signed by the accountable executive, stating your safety objectives and your commitment to them.
- Safety accountabilities. Who is responsible for what, defined and communicated. Includes designating an accountable executive with final authority.
- SMS documentation. A description of the system itself, and records demonstrating it operates.
- Emergency preparedness and response. A plan for the transition to and from emergency operations, kept current.
Where operators go wrong: writing an excellent policy and never distributing it, or never updating it. A policy nobody has read is not a policy.
Pillar 2 — Safety Risk Management (§ 5.51–5.55)
The engine. This pillar is about finding hazards before they hurt you, understanding how bad they could be, and doing something proportionate about it.
- Hazard identification. A process for identifying hazards — reactive, from reports and events, and proactive, from analysis of your operation.
- Safety risk assessment. Analysing each hazard for likelihood and severity using a defined methodology, conventionally the FAA 5×5 matrix.
- Safety risk control. Deciding and applying controls, with a named owner, and scoring residual risk once they have taken effect.
- Management of change. Applying the same process when your operation changes — a new aircraft type, a new base, a new contract, a key departure.
Where operators go wrong: relying entirely on reactive identification. If every hazard in your register came from something that already happened, you are running an incident log, not risk management.
Pillar 3 — Safety Assurance (§ 5.71–5.75)
The feedback loop, and reliably the weakest pillar in small operations. Assurance asks whether the system is working — not whether it exists.
- Safety performance monitoring and measurement. Tracking indicators you defined in advance against targets, so "we're doing fine" becomes a measurement.
- Control effectiveness verification. Going back to a control you applied and establishing whether it changed anything.
- Internal evaluation and auditing. Periodically examining your own system for gaps.
- Continuous improvement. Acting on what monitoring and evaluation tell you.
Where operators go wrong: treating mitigation as the end of the process. Applying a control closes the task; verifying the control closes the risk. Only the second one satisfies § 5.75.
Pillar 4 — Safety Promotion (§ 5.91–5.97)
The cultural pillar. A system nobody in the operation participates in produces no hazard reports, and a system with no hazard reports has nothing to manage.
- Competency and training. Ensuring people are trained on the SMS and their role in it.
- Safety communication. Making safety information flow both ways — out to your people, and back from them.
Where operators go wrong: one-way communication. Sending bulletins is promotion. Creating conditions where a first officer will report something that reflects badly on a captain is safety culture, and it is what the pillar is really after. A confidential reporting channel is the precondition.
How this platform maps to the twelve elements
We publish a coverage map showing which elements are carried by shipped features and which are still in development — including the three that are not implemented yet. It is on the home page, and it is deliberately honest, because you will be asked this in an evaluation.
See whether it fits your operation
Twenty minutes, no card. Tell us what certificate you hold and where your implementation plan stands, and we will show you the parts that apply to you.