Software certification
AI assistance and DO-330 tool qualification decisions
AI assistance in certification work has to be described by its actual use, not by the vendor label on the tool. This review looks at the PSAC or PHAC wording, the tool workflow, the claimed credit, and the human review records that accept or reject each AI output. The result is a qualification scoping memo that says whether DO-330 is implicated, what plan language should change, and which verification records prove the team kept responsibility for the output.
When this review is needed
- A team plans to use AI to sort, summarize, or cross-reference software lifecycle data before an SOI review.
- A PSAC is being updated and the authority may ask how AI-generated organization was controlled.
- A supplier wants to avoid qualifying a helper tool whose output is fully reviewed before use.
- Review records must show who checked the AI-organized material and what acceptance decision was made.
The problem
Teams often adopt AI for sorting, drafting, or cross-reference checks before anyone writes down whether the output is verified. That ambiguity is what creates tool qualification risk. A workflow that merely helps a reviewer find evidence is different from a workflow whose output is relied on for compliance credit, and the certification plan has to make that boundary visible.
What gets reviewed
- Identify each AI-assisted activity and the lifecycle data it touches.
- Map whether AI output is used directly for verification credit or only as an input to specialist review.
- Review PSAC and PHAC text for clear tool usage descriptions and retained human responsibility.
- Trace sample AI outputs to reviewer comments, corrections, and final accepted records.
- Check whether configuration control captures prompts, input sets, outputs, and dispositions where needed.
- Prepare authority-facing wording that avoids claiming credit from unverified AI output.
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- Each AI use has an owner, purpose, input set, and review step; fail if the workflow is described only as general assistance.
- Accepted outputs are backed by human review evidence; fail if summaries or classifications are copied into certification data with no reviewer action.
- Plan language matches the actual workflow; fail if the PSAC is silent while teams use AI on lifecycle data.
- Unqualified tool boundaries are documented; fail if the workflow depends on AI judgment for verification credit.
- Sample outputs show corrections when AI extraction was wrong; fail if review records never record a disposition.
Evidence normally required
Common discrepancies
- The plan says tools are manually verified, but the project folder has no evidence of that review.
- AI-generated trace suggestions were accepted into a matrix without a named software reviewer.
- Certification plans describe conventional tools but omit AI-assisted sorting of lifecycle data.
- Teams keep prompts and outputs outside configuration control even though they support review decisions.
What is at stake
If the boundary is unclear, an authority or delegate can treat the workflow as an unqualified tool late in the program. The team then has to defend past use, rewrite plan language, or add verification evidence after the fact, all while the certification schedule is already under review pressure.
How the work runs
Define the AI use
Identify the exact task, output, user, program phase, and certification credit the workflow may affect.
Read the plan language
Compare the PSAC, PHAC, tool list, and development procedures against how the tool is actually being used.
Test the verification boundary
Check whether human reviewers independently verify the AI output before it supports a compliance claim.
Write the qualification position
Deliver the scoping memo, plan edits, and evidence records needed to defend the chosen treatment.
What the buyer receives
Who uses the output
- Software leads use the scoping memo to decide which AI uses remain reviewed assistance.
- Certification engineers use the evidence map to update plans before SOI activity.
- DERs use the review trail to evaluate whether tool qualification questions are answered cleanly.
How the work fits into the transaction or program
This belongs before an AI workflow becomes normal practice on a DO-178C, DO-254, or systems certification program. The review gives software, hardware, and certification leads a written position on tool use, human verification, and evidence retention. It does not approve the tool or make a finding. It gives the program a defensible record before the workflow appears in submitted data.
Start with a single asset
Confirm requirements map to substantiating evidence.
Regulatory limits
EE does not qualify tools, approve certification plans, make compliance findings, or determine regulatory acceptance. The review organizes the tool-use rationale and evidence so the applicant, authorized representatives, and authorities can make their own decisions.
What this review does not cover
- DO-330 qualification package development
- Selection or validation of a software vendor
- Approval of PSAC or PHAC content
- Independent software verification
Specific to this review
- The key question is whether AI output is independently verified before it supports a certification claim.
- PSAC, PHAC, tool lists, and review records have to describe the same workflow.
- A fully reviewed assistant can still need procedural control, even when DO-330 qualification is not required.
- A tool used for credit without verification can create qualification exposure under DO-330.
- The memo separates plan-language fixes from workflow changes and from evidence-retention gaps.
Sources
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
Federal Aviation Administration. FAA type certification process, certification basis establishment, and compliance findings.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
Does every AI tool used on a certification program need DO-330 qualification?
No. The question is how the output is used. A tool whose output is independently verified is a different case from a tool whose output is relied on for credit without verification.
Who decides the final tool qualification position?
The review frames the evidence and the risk. The applicant, authorized representatives, and the authority retain the decision on certification treatment.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.