Skip to content

Compliance matrix

Compliance matrix evidence review for quality teams

This review reads a compliance matrix the way an authority reviewer will, checking that each row still points to evidence that actually supports the compliance claim. A certification specialist works with your quality function to confirm coverage against the certification basis, the means of compliance recorded per requirement, and the currency of the cited evidence. It runs before a data submittal, while a finding is being answered, or when a design change touches rows the matrix already shows as closed. You receive a gap list, an evidence map keyed to each matrix entry, and a closure sequence quality leadership can hand to the responsible engineers.

When this review is needed

  • A data package is about to leave the building and quality wants the matrix pressure-tested before it does.
  • A reviewer's finding disputes whether a specific row is actually supported or only marked complete.
  • A design change reopens requirements the matrix still presents as fully compliant.
  • The matrix was assembled by several engineers and no one has read every row against its evidence.

The problem

A compliance matrix ages badly. A row gets a means of compliance early, the requirement wording shifts, the substantiating report is revised twice, and the matrix still reads compliant because the cell was filled months ago. Quality inherits a document that looks finished, but the link from claim to evidence lives in an engineer's memory rather than in the record, and that engineer has moved to the next project.

What gets reviewed

  • Every requirement in the certification basis reconciled against a matrix row so no basis item is silently uncovered
  • The means of compliance recorded for each row checked against what the cited evidence actually demonstrates
  • Cited evidence located and opened rather than accepted on the strength of a filename
  • Rows marked compliant sorted into supported, partially supported, and unsupported
  • Currency confirmed so each row points to the released revision, not a superseded draft
  • Cross-references between related rows checked so a shared piece of evidence closes each claim it is cited for

What gets validated

  • Each basis requirement maps to at least one matrix row and each row maps back to a basis requirement
  • The means of compliance stated in a row matches the method the evidence documents rather than an aspiration
  • Every cited artifact opens to the revision the matrix names, not an earlier or later one
  • Rows touched by the most recent change show re-verified evidence or a written rationale for why none was needed
  • No two rows cite the same evidence to close claims that piece of evidence cannot both support

Evidence normally required

  • The compliance matrix as currently maintained, with its column definitions
  • The certification basis and any issue papers or special conditions that shaped it
  • The reports, analyses, and test records the matrix cites, at their released revisions
  • The means-of-compliance agreement for the project
  • Change records for any requirement or evidence altered since the matrix was last reconciled

Common discrepancies

  • A basis requirement with no matrix row, uncovered because coverage was tracked by requirement count rather than by requirement
  • A row citing a report revision the configuration process later superseded
  • A means of compliance that reads as test in the matrix but is actually satisfied by analysis in the evidence
  • A shared analysis cited to close two rows when it substantiates only one

What is at stake

A matrix that reads closed but does not resolve to evidence hands a reviewer an easy finding. They ask for the report behind one row, the report is not the revision the matrix cites, and a submittal that quality already blessed goes back into rework. Each disputed row pulls its dependent rows into question, and the schedule the program committed to slips while the trail is rebuilt.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Reconcile against the basis

Map every certification basis requirement to a matrix row and every row back to the basis so uncovered requirements surface.

02

Open the cited evidence

Follow each compliant row to its report and open it, confirming method and revision rather than trusting the citation.

03

Sort by support

Separate rows into supported, partially supported, and unsupported so quality sees the real state at a glance.

04

Sequence the closures

Order the gaps by dependency and effort so the team fixes enabling rows before the ones built on them.

What the buyer receives

  • A gap list naming each row whose evidence is missing, stale, or mismatched to its claim
  • An evidence map tying every compliant row to the artifact and revision that supports it
  • A closure sequence ordering the gaps so enabling items are cleared before the rows that depend on them

Who uses the output

  • Quality leadership deciding whether the matrix is fit to sign before the package ships
  • Certification engineers who need a concrete list of rows to re-evidence or re-verify
  • The team writing finding responses that must cite a row a reviewer can open and confirm

How the work fits into the transaction or program

The compliance matrix is the index a reviewer reads the whole data package through, so a weak matrix undermines evidence that is otherwise sound. This review sits between the engineering that produced the substantiation and the quality sign-off that releases it, catching detached rows while there is still time to reconnect them rather than after a reviewer has reached the same verdict.

Start with a single asset

Confirm requirements trace through verification.

Jurisdiction-specific considerations

FAA and EASA both expect the matrix to trace to the certification basis, but they arrive through different mechanisms: FAA project-specific certification plans and delegated findings on one side, EASA certification review items and means-of-compliance acceptance on the other. The same matrix often has to answer both, so the review reads each row against whichever basis and finding path the project is actually running under.

Regulatory limits

This review reads your own compliance matrix and reports where each row holds and where it breaks. It does not make an airworthiness determination, does not issue or accept a compliance finding, and does not replace the authority's or the delegate's review of the substantiating data.

What this review does not cover

  • Authoring the missing reports or analyses a gap calls for
  • Re-running the tests or analyses behind a row
  • Rendering the compliance finding an authority or delegate reserves

Specific to this review

  • Coverage gaps hide most easily when a matrix is checked by counting filled cells, because a missing requirement leaves no empty cell to notice.
  • The most common failure is not an absent report but a report pinned to a requirement wording that has since been revised, which no cell count reveals.
  • A row can read compliant and still fail review when the means of compliance in the matrix does not match the method the evidence used.
  • Rows that share one piece of substantiation are a recurring trap, because a single analysis gets cited to close more claims than it actually supports.

Sources

Frequently asked questions

How is this different from the internal audit our quality group already runs on the matrix?

An internal audit usually confirms the matrix is filled in and formatted to procedure. This review goes past the cell and opens the evidence each row cites, checking the revision and the means of compliance against what the artifact actually shows. It finds the rows that pass a completeness check but would fail a reviewer's read.

Can you review the matrix while the design is still changing?

It gives the cleanest result against a fixed baseline, since a moving requirement set produces gaps that are really just timing. If the design is still settling, the review runs on the stable rows and flags the volatile requirements as a separate watch list quality can track to closure.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.