TSO authorization
Instructions for continued airworthiness support in a TSO program
This review readies the Instructions for Continued Airworthiness that ship with a TSO article, so the maintenance a purchaser will perform matches the article that was approved. It is run for an equipment or avionics supplier as the authorization data package comes together. The work checks that maintenance tasks, life limits, and part references describe the released configuration, and that nothing in the ICA promises coverage the design data does not support. You receive a gap assessment against the approved article, an evidence map linking each ICA task to its source, and a closure plan for the sections that lag the configuration.
When this review is needed
- The design has stabilized and the ICA now has to catch up to the configuration the authorization will cover.
- A late design change altered a life limit or a maintenance task and the ICA still reflects the earlier build.
- An installer will rely on the ICA to keep the article airworthy and the tasks have to be executable as written.
- The article carries software or complex hardware whose maintenance provisions must appear in the ICA rather than only in internal data.
The problem
The ICA is usually the last document to settle, so it inherits every change the design made along the way. A part gets a new number, a life limit shifts after a test result, a task is added to address a finding, and the ICA is updated last or not at all. What ships to the installer then describes an article slightly older than the one that was approved, and the mismatch is invisible until someone in the field tries to perform a task that no longer fits the hardware.
What gets reviewed
- Maintenance tasks and intervals reconciled to the approved article's design and test data
- Life limits and time-controlled provisions matched to the values the certification substantiates
- Part numbers and configuration references aligned to the released build standard
- Software and complex-hardware maintenance provisions carried through where the design requires them
- Airworthiness limitations stated separately and traceable to their substantiation
- ICA sections that lag the configuration collected into a closure plan
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- Each maintenance task in the ICA traces to a design or test basis that supports the interval it states
- Life limits in the ICA match the values the qualification and analysis substantiate
- Part numbers and effectivity in the ICA correspond to the released configuration for the article
- Airworthiness limitations are segregated and each carries a traceable substantiation
- No ICA task calls for an action the article's design data does not actually support
Evidence normally required
- The draft ICA and any predecessor maintenance documentation for the article
- The released design definition, part list, and configuration for the approved article
- Life-limit and time-control substantiation from analysis and test
- The finding register entries that drove ICA content changes
- The certification basis identifying which limitations must appear
Common discrepancies
- A maintenance interval in the ICA that no test or analysis result supports
- A life limit carried forward from an earlier build that a later result changed
- A part called out in a task by a number the released configuration superseded
- An airworthiness limitation buried in a general task instead of stated as a limitation
What is at stake
An ICA that lags the approved configuration puts maintenance error into the field: a task performed against the wrong interval, a part called out by a superseded number, or a life limit tracked to a value the design no longer holds. Those errors surface as service difficulties and warranty exposure, and correcting an ICA after articles are already installed means a revision that has to reach every operator who holds one.
How the work runs
Freeze the configuration reference
Pin the released build standard and part list the ICA must describe.
Trace tasks to basis
Confirm each task, interval, and life limit is supported by the design or test data it cites.
Segregate the limitations
Separate airworthiness limitations from routine tasks and tie each to its substantiation.
Close the lag
List the sections behind the configuration and plan the substantiation to bring them current.
What the buyer receives
- A gap assessment listing each ICA section that does not match the approved article
- An evidence map linking every task, limit, and part reference to its design or test source
- A closure plan for the lagging sections with an owner and the substantiation each needs
Who uses the output
- Certification engineers finalizing the ICA for inclusion in the data package
- Publications staff who convert the substantiation into the delivered maintenance document
- Program managers confirming the ICA is ready before the package moves to review
How the work fits into the transaction or program
The ICA is the article's continued-airworthiness contract with every operator who installs it, so the review runs once the design is stable enough that the tasks and limits can be trusted. It sits after conformity and qualification are settled and feeds the completed data package, since an ICA that lags the approved configuration is a finding an authority will raise before authorization.
Start with a single asset
Reduce finding cycles by checking the package first.
Jurisdiction-specific considerations
Under the FAA article-approval framework, the airworthiness limitations section carries a different status from ordinary maintenance tasks, so the review keeps limitations segregated and separately traceable rather than folded into general instructions where their standing would be lost.
Regulatory limits
The review prepares and reconciles the ICA so it matches the approved article and can be evaluated. It does not approve the ICA, set airworthiness limitations on the authority's behalf, or grant the authorization.
What this review does not cover
- Authoring the underlying maintenance program an operator will build around the article
- Setting or approving life limits or airworthiness limitations
- Any authority acceptance of the ICA or the article
Specific to this review
- The ICA settles last and therefore absorbs every late design change, which is exactly why it is the document most likely to describe an article a step behind the approved one.
- Airworthiness limitations have a distinct regulatory standing, so an ICA that folds a limitation into a routine task can weaken its enforceability even when the words are present.
- Correcting an ICA after articles ship means a revision that must reach every holder, so catching the lag before authorization is far cheaper than after.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
RTCA. Environmental qualification test categories and procedures referenced by TSO and equipment qualification.
RTCA. Objectives and lifecycle data for airborne software assurance, by design assurance level (DAL A-E).
RTCA. Design assurance objectives and lifecycle data for airborne electronic hardware (FPGA/ASIC/PLD).
Federal Aviation Administration. STC application process, certification basis, and continued airworthiness obligations of an STC holder.
Frequently asked questions
Why review the ICA separately from the rest of the data package?
The ICA is the one document the field actually uses, and it is written last, so it drifts from the approved configuration more than any other part of the package. Reviewing it on its own catches interval, life-limit, and part-number lag before an authority raises it and before installers are working from tasks that no longer fit the article.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.