A gap analysis is often treated as a project: compare the organisation with the applicable requirements, record the differences, assign actions and close the file. That approach is useful only until the next meaningful change occurs. Regulations are amended, aircraft and routes change, accountable managers delegate work, suppliers become part of the process and procedures evolve under operational pressure. A report that was accurate at the time of assessment can therefore become misleading without containing a single false statement. The operational point is simple: a gap analysis describes a relationship between requirements and controls at a particular time, so its validity depends on both sides of that relationship remaining current.
For an operator working under an approved safety management system, the assessment should be connected to the organisation’s compliance monitoring and management-of-change processes. ICAO Annex 19 and the operator’s approved SMS establish the broader expectation that hazards, risks, changes and safety performance are managed systematically. For an EASA operator, the relevant Part-ORO arrangements, including flight-time limitation requirements where applicable, must be considered alongside the operator’s approved procedures and applicable national authority decisions. A Part-145 organisation has a different regulatory perimeter, but the same discipline applies: its procedures, competence arrangements, records and contracted activities must continue to match the applicable continuing-airworthiness requirements and approved exposition.
The original report is a baseline, not a guarantee
The first quality test is to define what the analysis actually assessed. The scope should identify the regulatory framework, operational activity, sites, aircraft or maintenance capabilities, organisational roles, procedures and evidence sampled. It should also record the assessment date and the version or source of the requirements used. Without that information, a later reviewer cannot tell whether a new finding represents a changed requirement, a changed operation or a weakness that was present from the beginning.
It is important to separate four records that are frequently blended together. The requirement register states what applies. The gap analysis compares those requirements with the organisation’s arrangements. The corrective action record explains how an identified shortfall will be addressed. The verification record demonstrates that the action worked in practice. Updating one does not automatically update the others. A revised procedure, for example, does not prove that personnel use it, that records are generated, or that the revised control has reduced the original risk.
This distinction matters during an audit. An inspector may ask not only when the last assessment was completed, but what caused it to be revisited, which requirements were checked, what evidence was examined and who accepted the residual risk. A document showing that an action was marked complete is weaker than a controlled sample of recent records, an interview with the responsible staff member and evidence that the compliance owner reviewed the result.
Set both a calendar and a change trigger
A regular review should not rely on a single annual reminder. A calendar review provides a minimum discipline, while change triggers prevent the organisation from waiting for that date when the underlying assumptions have already moved. The interval should be defined in the management system according to the organisation’s risk, regulatory obligations and authority expectations; it should not be presented as a universal period applicable to every operator.
Useful triggers include a change to an applicable regulation or authority interpretation, a new aircraft type or maintenance capability, a new operating base, significant changes to crew scheduling or flight-time limitation arrangements, a new supplier, an occurrence trend, an internal audit finding, a change in accountable or nominated personnel, and a major revision to an operations or maintenance manual. A trigger does not always require a complete assessment of every requirement. It does require a documented decision on what was screened, what was affected and why the remaining scope was not reopened.
The decision trail is itself evidence. The compliance manager or nominated post holder should be able to show the trigger, the initial screening, the affected requirements, the people consulted and the disposition: full reassessment, targeted review or no further action with justification. That record prevents a common failure mode in which a change is discussed informally but never enters the controlled compliance system.
The relationship between a trigger, the responsible person and the evidence can be kept concise. The following structure is more useful than a generic statement that the gap analysis is reviewed periodically.
| Review driver | Primary owner | Evidence to retain | Typical result |
|---|---|---|---|
| Regulatory change | Compliance manager | Applicability assessment | Updated gap register |
| Operational change | Process owner | Change and risk review | Targeted reassessment |
| Occurrence or trend | Safety manager | Investigation and risk record | Control effectiveness review |
| Scheduled review | Accountable manager | Approved review record | Baseline confirmation |
Revisit the control, not just the wording
A weak periodic review consists of reading the previous report and confirming that the procedures have not changed. A stronger review tests whether the control still works. For flight operations, that may include sampling rostering decisions, duty records, commander reports, fatigue reports and deviations against the operator’s approved flight-time limitation scheme. For a Part-145 organisation, it may involve work-pack records, certifying-staff authorisations, training and competence evidence, tooling or material controls, and contracted maintenance interfaces. The exact sample depends on the approved system and the risk, but the principle is consistent: the evidence should come from current operational records, not only from controlled manuals.
Responsibilities should be explicit. The accountable manager owns the effectiveness of the management system, but does not personally perform every compliance check. A compliance or quality function may maintain the requirement register and conduct the assessment. Safety personnel should assess whether a shortfall creates or changes a hazard or risk. Process owners must provide evidence and implement actions. Independent verification should be performed by someone with sufficient competence and appropriate separation from the work being verified. Where the same person designs a corrective action, implements it and closes it without objective review, the record may show activity but not assurance.
Reassessment should also be risk-based after a finding is closed. A control that has been implemented once may still be fragile: staff may not understand it, the system may not produce the expected record, or an outsourced provider may apply a different interpretation. Closure criteria should therefore state what will be checked, over what operational sample and by whom. If the result is unsatisfactory, the organisation should reopen the action or raise a new finding rather than quietly revise the original conclusion.
The practical discipline is to give every gap analysis an owner, scope, source date, review date and trigger logic. Maintain the link between requirements, risks, actions and sampled evidence, and record decisions when a change does not require a full reassessment. That turns the document from a one-time compliance photograph into a controlled part of the SMS and compliance monitoring system. It also gives an auditor a defensible answer to the most important question: how does the organisation know that its controls still match the operation it is actually conducting?