Quick answer
The block above the contents list is the short version. Below: the element to evidence map as a table, the four questions audits usually open with, what a defensible audit trail looks like on one record, and the difference between being ready and preparing. If you need the framework itself rather than its evidence, start with the four components of an SMS, which owns that ground. For standing an SMS up in the first place, see Annex 19 in 90 days.
Element to evidence map
ICAO Annex 19 organises an SMS into four components holding twelve elements. An audit does not grade the elements in the abstract; it asks what each one produced. The table maps them to the artefact an auditor expects and to the shape that survives a sample trace.
| Element | Evidence an auditor expects | The shape that survives a sample trace |
|---|---|---|
| Management commitment | Signed safety policy, resourcing decisions | A controlled document with revision history and named acknowledgement |
| Accountability and responsibilities | Accountability map, per-record owners | The owner and verifier recorded on each occurrence, finding and action |
| Key safety personnel | Appointment records, competency validity | Training records with validity windows tied to the appointment |
| Emergency response planning | The plan, the roles, the drill record | Drill outcomes recorded against the plan they exercised |
| Hazard identification | Hazard register, occurrence and audit intake | Reactive and proactive sources landing as records on one spine |
| Risk assessment and mitigation | Risk assessments, matrix scores, barriers | Bow-tie models with named barriers and their assessed condition |
| Performance monitoring | Indicator definitions, charts, underlying data | Control charts with the rule that tripped and the data behind it |
| Management of change | Change assessments and their approvals | Change routed by assessed risk band with the approval on the record |
| Continuous improvement | Audit findings, corrective actions, effectiveness | Closure gated on verification by someone other than the owner |
| Training and communication | Competency records, bulletins, acknowledgements | Acknowledgement per person, not a distribution list |
The third column is where audits are won or lost. Most operations can produce the artefact in column two. Fewer can produce it with the link that shows which hazard the occurrence belonged to, or which person verified that the action worked. See the closure gate for why the verification link is the one most often missing.
The four questions
Audits vary, auditors do not vary much. Four questions do most of the work, and each one tests a different joint in the system.
Show me the hazard this occurrence belongs to. This tests whether hazard identification is a live register or a document written once. If the link has to be reconstructed by a person who remembers, the register is not doing its job. The answer should be a navigation, not a search.
Prove this corrective action worked. This tests safety assurance, and it is the most common source of findings. Implementation is not effectiveness. Both EASA Part-ORO and FAA 14 CFR Part 5 expect verification that the risk actually fell, by someone other than the person who owned the action.
Your system classified this. Justify it. Increasingly asked now that classification is often AI-assisted. The defensible answer has three parts: the proposal and its confidence, the person who accepted or changed it, and a version pin on the taxonomy so the same record reads the same way in three years. See AI in aviation safety management.
Who saw the confidential report? This tests whether Annex 19 confidentiality protection is enforced by the system or promised by a policy. A convincing answer shows access control at the data layer and a record of every read, which is also what makes a just culture survivable when a report is uncomfortable.
What a good audit trail looks like
A defensible trail on one occurrence reads as a sequence of stamped events with an actor on each: the report as filed, the reference minted, the classification proposed with its confidence, the person who accepted it and what they changed, the barrier assessment that followed, and the indicator that moved. Each line carries a time in UTC, an actor, and a change.
What makes it defensible is not that it is long. It is that it is continuous: no step in the story is missing, and no step was written after the fact. An audit trail assembled during audit preparation is a document. One written as the work happened is evidence. For the full path a record takes, see what happens after an occurrence report.
Being ready instead of preparing
The cost of an audit is set long before it is scheduled. Where occurrence, hazard, indicator, action and audit records live in separate systems, the links between them exist only in the heads of the people who made them, so audit preparation is a reconstruction project. Where those links are structural, preparation is a query and the time goes into the findings instead.
This is also why IOSA preparation tends to expose the same weakness twice: the evidence exists, but proving which requirement it satisfies is manual. The fix is not a better folder structure. It is attaching evidence to the requirement when the evidence is produced.
Frequently asked questions
What evidence does an SMS audit require?
An SMS audit asks for the records each part of the system produces, not for the system description. Expect to show the signed safety policy and accountability map, appointment records for key safety personnel, the emergency response plan, the SMS documentation set, the hazard register with risk assessments, occurrence reports and their investigations, safety performance indicators with their underlying data, internal audit findings with corrective actions and evidence of effectiveness, management-of-change assessments, and training and competency records. Auditors sample: they pick one record and follow it end to end, so the connections between those artefacts matter as much as the artefacts.
What do auditors usually ask first in an SMS audit?
Most SMS audits open by sampling. An auditor picks one recent occurrence or finding and asks to see what happened to it: which hazard it belongs to, which barrier failed, what action was raised, who verified that action worked, and who was accountable for the residual risk. That single trace tests the whole system at once, because a record that cannot be followed from report to closure indicates that the components are running as separate archives rather than one system.
How long does it take to prepare evidence for an SMS audit?
It depends entirely on whether the evidence is assembled continuously or at audit time. Operations that keep occurrence, hazard, indicator, action and audit records in separate systems typically spend weeks reconciling them into an audit folder, because the links between records exist only in people memory. Operations where those records are connected when they are created spend that time on the findings instead, since the evidence is a query rather than a collection exercise.
What is the difference between compliance evidence and safety assurance evidence?
Compliance evidence shows that a required activity happened: the policy is signed, the training was delivered, the audit was scheduled. Safety assurance evidence shows that the activity worked: the indicator moved, the barrier was verified as effective, the corrective action was checked by someone other than its owner. ICAO Annex 19 and rules such as EASA Part-ORO and FAA 14 CFR Part 5 require both, and effectiveness verification is where most audit findings actually land, because closing an action is easy and proving it reduced risk is not.
How do you prove an AI-assisted classification to an auditor?
By showing that a person decided and that the reasoning is reproducible. An auditable AI classification keeps three things on the record: the proposal with its confidence, the identity of the person who accepted, edited or rejected it, and a version pin on the taxonomy used, so the same occurrence classifies the same way when the audit revisits it years later. If an AI value can enter a safety record without a human acceptance on the trail, the classification is not defensible when an auditor asks who decided.