Safety · Part 5

Part 5 SMS for Part 135 operators: what is required by May 28, 2027

SG5 Intelligent Solutions · September 26, 2026

The short answer

If you held a Part 135 certificate before May 28, 2024, you must have a safety management system that meets 14 CFR Part 5 implemented, and a declaration of compliance submitted to the FAA, no later than May 28, 2027 (§ 5.9).

Part 5 has four working components — safety policy, safety risk management, safety assurance and safety promotion — plus documentation and records. There is no exemption for small operators.

The declaration is the finish line, not the start. It says the SMS is already running, and the FAA can ask you to show the data that proves it.

Who has to comply, and by when

Part 5 applies to anyone who holds or applies for a certificate under Part 119 to conduct Part 135 operations, and to § 91.147 letter of authorization holders (§ 5.1). The dates are in § 5.9.

  • Operators authorized before May 28, 2024 must develop and implement an SMS that meets Part 5, and submit a declaration of compliance, no later than May 28, 2027.
  • Anyone applying on or after May 28, 2024 must have the SMS in place before the authorization is issued.
  • Once in place, the SMS has to be maintained for as long as you hold the authority, and you must make the information that demonstrates it available to the FAA on request.

For comparison, Part 121 carriers that already had an accepted SMS had until May 28, 2025 to revise it to the amended rule (§ 5.7). The Part 135 deadline is the one still ahead.

What “implemented” means

The most common misreading is that the requirement is a manual. It is not. The rule says develop and implement, and the declaration of compliance states that the system is operating. An SMS that exists only as a document will not survive the first time an inspector asks to see last quarter’s hazard reports, the risk assessments that came out of them, and what the accountable executive did about it.

Working backwards from May 2027, that means the processes need to be running early enough to have produced records: reports received, risks assessed, controls put in place, and assessments of whether those controls worked.

Safety policy (Subpart B)

§ 5.21 lists what the safety policy must contain. It must be signed by the accountable executive, documented, communicated throughout the organization, and regularly reviewed.

  • Your safety objectives, and your commitment to fulfil them.
  • A statement that you will provide the resources needed to implement the SMS.
  • A safety reporting policy that defines requirements for employees to report hazards or issues.
  • A policy that defines unacceptable behaviour and the conditions for disciplinary action.
  • An emergency response plan for the safe transition from normal to emergency operations.
  • A code of ethics, applicable to everyone including management, that makes safety the organization’s highest priority.

§ 5.23 requires you to define safety accountability for management and employees and to identify which levels of management can accept safety risk. § 5.25 requires an accountable executive — the person with final authority over operations and control of the financial and human resources — and enough management personnel to run the SMS day to day.

Safety risk management (Subpart C)

Safety risk management is triggered by four things (§ 5.51): implementing a new system, revising an existing one, developing operational procedures, and hazards or ineffective controls found through safety assurance.

  • Analyse the system — its purpose, environment, procedures, people, equipment, facilities and interfaces — and identify hazards within it (§ 5.53).
  • Assess the risk of each hazard with a defined process that determines what is acceptable, design controls, and check the risk is acceptable with the control applied before you implement it (§ 5.55).
  • Notify interfacing persons — the people who contribute to the safety of your operation, such as a maintenance provider or a handler — of hazards they could address (§ 5.57).

Safety assurance (Subpart D)

This is where most small SMS programmes are thinnest, and where an inspector will look hardest. § 5.71 requires processes to acquire data on safety performance, including:

  • Monitoring operational processes and the operating environment.
  • Auditing, and evaluations of the SMS itself.
  • Investigating incidents, accidents and reports of non-compliance with your risk controls.
  • A confidential employee reporting system where people can report hazards, issues, occurrences and incidents, and propose improvements, without concern of reprisal.
  • Investigating hazard notifications from outside the company.

You must also analyse that data (§ 5.71(b)), assess safety performance against your objectives with reviews by the accountable executive (§ 5.73), and correct the deficiencies you find (§ 5.75). Where an assessment turns up ineffective controls or new hazards, it feeds back into safety risk management.

Safety promotion (Subpart E)

Train the people with SMS responsibilities to the competency their duties need (§ 5.91). Communicate safety information so that employees know the policies and tools relevant to them, receive the hazard information that affects their work, and are told why safety actions were taken and why procedures changed (§ 5.93).

Documentation and records (Subpart F)

Document the safety policy and the SMS processes and procedures (§ 5.95). Keep records for the periods in § 5.97:

  • Safety risk management outputs: for as long as the control remains relevant.
  • Safety assurance outputs: at least 5 years.
  • SMS training records: for as long as the individual is employed.
  • Safety communications and hazard notifications: at least 24 consecutive calendar months.

Where small operators struggle

The rule is written to scale; a ten-aircraft operator is not expected to run the safety department of an airline. But the obligations are the same, and three of them tend to cause most of the trouble.

  • Reporting that nobody uses. A reporting form buried in a shared drive produces no reports, and no reports means no evidence the system runs. Reporting has to be quicker than not reporting.
  • Reports that go nowhere. Every report needs an owner, a risk assessment and an outcome, and the person who reported it needs to hear what happened (§ 5.93(c)).
  • Safety data held separately from operational data. The hazards live in the trip records, the squawks and the crew schedule. An SMS kept apart from them has to be fed by hand, and usually isn’t.

Where software helps, and where it must not

Software is good at intake, routing and memory: getting a report in from a phone on the ramp, putting it in front of the right person with a clock on it, drafting a severity and a corrective action from the text, and keeping the record for as long as § 5.97 requires.

It must not close a hazard report, accept a risk or declare a control effective. Part 5 puts those decisions with people who have the authority to make them (§ 5.23). The way we build SMS tooling, the software prepares the decision and a named person makes it.

If you want to see where you stand, work through our Part 5 SMS readiness checklist below. It follows the rule section by section.

Related

Read next.

Charter ops

Charter Operations Platform

Request to invoice on one live mission record — quote, crew, release and billing that never disagree about the same trip.

How we help

The work behind this.

AI & agents

AI and agentic workflows for aviation

AI agents that read requests, squawks and reports, work the steps across your systems and prepare the answer for a person to approve — measured against your own traffic before anyone writes production code.

Advise

Consulting & strategy

Build-versus-buy, vendor selection, data architecture and the roadmap that survives an audit. Short engagements, written conclusions.

Get started

Bring us one real problem.

Not a requirements document — one thing that costs you money every week. We will tell you in writing whether it is worth building.