Health-monitoring TSO
Health-monitoring equipment evidence support for TSO authorization
Health-monitoring TSO evidence readiness gets the certification data for aircraft health and usage monitoring equipment into a state an authority can accept, where the pivotal question is what the monitoring function is allowed to influence. A certification engineer runs it for the supplier once the design is set but the data integrity, sensor interface, and software evidence sit apart from the classification that governs them. The work confirms how the function is classified, checks data integrity end to end, verifies the sensor interfaces the monitoring depends on, and matches the software life-cycle to the assigned level. You get an evidence gap list anchored to the function classification, a trace map from classification to verified data path, and a closure sequence that resolves the classification-driven items first.
When this review is needed
- Health-monitoring equipment is heading for a TSO authorization and no one has confirmed how the monitoring function is classified.
- The data integrity argument spans sensors, acquisition, and processing that were evidenced by different teams.
- The software life-cycle level was set before the function classification was settled and the two may not agree.
- A prior submission questioned whether the monitoring output could influence a maintenance or operational action.
The problem
Health-monitoring equipment lives or dies on classification. If its output only advises and cannot influence airworthiness or an operational decision, the assurance burden is modest; if it feeds a maintenance credit or a crew action, the burden climbs sharply, and the software level and data integrity evidence have to follow. In practice the data integrity story is stitched together from sensor interfaces, acquisition, and processing built by different teams, and the classification that should govern all of it is often decided last, after the evidence is already shaped around a lighter assumption.
What gets reviewed
- The monitoring function classification and what its output is permitted to influence
- Data integrity along the sensor-to-output path, including acquisition and processing
- Sensor interface evidence for the inputs the monitoring depends on
- The DO-178C software life-cycle at the level the classification assigns
- DO-160G environmental coverage for the installation environment
- Deviations from the standard identified with the classification basis behind each
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- The software life-cycle level follows from the function classification, not an earlier lighter assumption
- Data integrity is demonstrated end to end from the sensor to the monitoring output
- Sensor interface evidence exists for each input the monitoring relies on
- The claimed influence of the monitoring output matches how the function is actually classified
- DO-160G coverage reflects the installation environment rather than a generic profile
Evidence normally required
- The function classification and the basis for what the output may influence
- The data integrity architecture from sensor through acquisition to output
- Sensor interface and input definition documentation
- The DO-178C software life-cycle data and its assigned level
- DO-160G environmental qualification results for the equipment
Common discrepancies
- A software level set below what the function classification actually requires
- A data integrity break somewhere along the sensor-to-output path
- A sensor input the monitoring relies on with no interface evidence
- A claimed monitoring influence that exceeds what the classification supports
What is at stake
A function classified too lightly leaves the software level and data integrity evidence below what the authorization needs, and correcting the classification late reopens the whole life-cycle. A data integrity gap along the sensor-to-output path undermines every claim the monitoring makes, and an authority that doubts the classification will hold the authorization until it is resolved.
How the work runs
Settle the classification
Establish how the monitoring function is classified and what its output is permitted to influence, as the basis for everything else.
Reconcile the software level
Confirm the DO-178C level follows from the classification and flag any mismatch with the current life-cycle.
Trace data integrity
Walk the sensor-to-output path and verify integrity at each interface and processing stage.
Sequence classification-first closure
Order the gaps so the classification-driven items resolve before dependent evidence is relied on.
What the buyer receives
- An evidence gap list anchored to the function classification
- A trace map from the classification to the verified data path
- A closure sequence that resolves the classification-driven items first
Who uses the output
- Certification engineers assembling the health-monitoring TSO data package
- Software and systems leads confirming the level and data integrity match the classification
- Program managers judging which classification-driven gaps must close before submission
How the work fits into the transaction or program
This readiness pass fixes the function classification and reconciles the software and data integrity evidence to it before the health-monitoring package reaches the authority. Because everything downstream depends on the classification, settling it here keeps a later installation approval from inheriting an assurance level that no longer fits what the monitoring is used for.
Start with a single asset
Confirm requirements map to substantiating evidence.
Jurisdiction-specific considerations
FAA and EASA both scrutinize what a health-monitoring output is permitted to influence, but they differ in how a maintenance credit or usage-based action tied to the monitoring is substantiated. The gap list notes where a classification argument framed for one authority will need reframing for the other.
Regulatory limits
The work checks and organizes the supplier's evidence against the classification and the standard. It does not classify the function on the authority's behalf, approve any maintenance credit, assign the software level, or grant the TSO authorization. Those judgments rest with the applicant and the authority.
What this review does not cover
- Authoring the software life-cycle data or raising the assigned level
- Substantiating a maintenance credit or usage-based operational action
- Submitting the package or negotiating its acceptance
Specific to this review
- Health-monitoring evidence is governed by function classification above all, because whether the output may influence an airworthiness or operational action sets the entire assurance burden.
- The costliest defect is a classification decided after the evidence was shaped, since correcting it upward reopens the software life-cycle and the data integrity case.
- Data integrity has to hold along the full sensor-to-output path, and the break, when there is one, usually sits at a sensor interface rather than in the processing.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
Frequently asked questions
Why does the function classification drive so much of the evidence?
The classification sets what the monitoring output is allowed to influence, and that determines the software level and the data integrity rigor required. A function that only advises carries a light burden; one that feeds a maintenance credit or a crew action carries a heavy one. Settling the classification first keeps the rest of the evidence from being built to the wrong level.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.