ARP4754B evidence
Safety program plan review for new development program kickoff
For safety managers, systems engineering managers, and program managers, this page is used this page when New development program kickoff depends on records that have moved across revisions, suppliers, or workstreams. EE checks safety program plan, development plan, FHA schedule, PSSA and SSA plan against the applicable basis, plan language, and source records. Findings are written as evidence gaps, not approval decisions. The deliverable is a ranked discrepancy log with the evidence trail needed for closure.
When this review is needed
- New development program kickoff has created a gate where document titles are no longer enough.
- Leaders need a ranked list of plan blockers rather than another unfiltered file dump.
- The review notes that evidence was copied from earlier work and its applicability must be tested.
- Authority, DER, ODA, or internal reviewers are expected to sample the record trail.
The problem
Teams usually know the files exist, but they do not always know whether safety program plan still agrees with PSSA and SSA plan. That uncertainty burns review time when a sampled citation fails.
What gets reviewed
- Inventory safety program plan and record its source, owner, and controlled revision.
- Match development plan against the current baseline and the applicable plan language.
- Follow FHA schedule through downstream reports, summaries, and closure notes.
- Flag PSSA and SSA plan when it refers to a superseded configuration or unresolved deviation.
- List missing source records needed before reviewers can rely on the package.
What gets validated
- A cited record passes only if its identifier, title, and revision match the controlled index.
- Configuration alignment is tested between safety program plan and PSSA and SSA plan; conflicting serials, drawings, or baselines fail.
- The review notes that evidence type is checked against the claim, so analysis cannot silently replace a promised test or inspection.
- Open exceptions fail the gate when they have no owner, due path, or technical disposition.
- Downstream documents are sampled for references that still point to superseded material.
Evidence normally required
Common discrepancies
What is at stake
Late discovery turns a records problem into a program problem. Reviewers may pause sampling, ask for a corrected baseline, or require new evidence before the package can move forward.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Frame Safety Program
Confirm the exact event, affected file set, buyer role, and decision standard before any program safety plan is treated as sufficient.
Trace Review New
Walk the named evidence from index entry to source artifact and mark where the trail supports, conflicts with, or fails to answer the page-specific question.
Sort Kickoff Arp4754b
Group exceptions by closure route: document retrieval, data correction, engineering disposition, authority response, or contractual decision.
Package Activities Scheduled
Deliver the exception list, evidence map, and owner sequence in a form that can move directly into remediation, submittal cleanup, or transaction negotiation.
What the buyer receives
- Gap log for safety program plan review
- Cross reference table
- Document retrieval list
- Disposition worksheet
- Submittal readiness note
Who uses the output
- safety manager decides which exceptions block the next gate.
- systems engineering manager updates the plan, matrix, or report index.
- program manager tracks owner responses through closure.
How the work fits into the transaction or program
Does the safety program plan sequence FHA, PSSA, SSA, and CCA so their outputs can still influence design, or is safety scheduled as documentation after the fact. The evidence set centers on scope and timing of each safety analysis, interfaces to the development plan and item DALs, criteria for updating analyses after change, and responsibilities across suppliers. The likely weak points are SSA scheduled after design freeze so findings cannot change anything, no trigger for re-running analyses after modification, and supplier safety data arriving in formats the integrator cannot use. The output gives the safety manager a cleanup register for Safety program plan review for new development program kickoff before new development program kickoff.
Start with a single asset
Confirm requirements trace through verification.
Regulatory limits
The review is an evidence and consistency check only. EE does not approve data, accept certification credit, make airworthiness determinations, or act for FAA, EASA, a DER, a DAR, or an ODA unit member.
What this review does not cover
- Design approval
- Regulatory acceptance decisions
- Laboratory testing or retesting
- Acting as DER, DAR, ODA unit member, or authority
Specific to this review
- PSSA and SSA plan is often where stale evidence surfaces first, because reports preserve old titles long after plans change.
- A complete index is weaker than a resolved index; the review asks whether each citation can actually be used.
- Supplier or lab records need the same baseline discipline as internal certification data.
- A discrepancy should name the blocked decision, not merely the document where the problem was found.
- The scope uses the Safety Program Plan Review question as the control point, so the review stays tied to New development program kickoff and the buyer decision behind it.
- The evidence starts with program safety plan and follows New Development Kickoff Arp4754b references until every exception has a source location and a reason code.
- The finding logic separates missing paperwork, conflicting status, stale revision data, and unsupported disposition because each class closes through a different owner.
- The timing matters for safety manager: the output is useful only if the unresolved items are visible before acceptance, submittal, handback, or negotiation pressure fixes the sequence.
- The boundary control keeps Evidence Activities Scheduled Design questions in the records or certification lane and sends technical acceptance issues to the authorized people who own them.
- The handoff value comes from Gap log for safety program plan review; it gives the next reviewer a precise map instead of another broad request for a better file.
Sources
SAE International. Safety assessment methods (FHA, PSSA, SSA, FTA, FMEA) supporting development assurance level assignment.
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
Frequently asked questions
What makes this evidence review different from a general file audit?
The scope is tied to safety program plan review and to the decision named in the request. A general audit can list weak records; this pass ranks the gaps by whether they block new development program kickoff or can be closed later without changing the decision.
What evidence has to be available before this work starts?
The starting point is program safety plan, the current status source, and any index or matrix that tells reviewers where the supporting artifact should live. Missing inputs are logged as findings rather than filled with assumptions.
Who decides whether an open item is acceptable?
The review explains what the evidence supports and gives safety manager a closure path. Acceptance remains with the buyer, operator, authority, delegated engineer, or authorized person responsible for the underlying airworthiness or certification decision.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.