sms-fundamentals

SMS Fundamentals — FlyWise SMS
FlyWise SMS FlyWise SMS
Start Here

SMS Fundamentals

What SMS actually is, why it exists, what the FAA is looking for, and how FlyWise fits in — in plain English.

If you’ve been told you need an SMS and you’re not sure where to start, this is the place. No jargon. No acronyms without explanation. Just the big picture so you can make sense of the rest.

1 What is an SMS, really?

The Short Answer

An SMS is just a documented, disciplined way of finding the things in your operation that could hurt someone, deciding what to do about them, and proving you did.

That’s it. Everything else is details.

You already do most of this informally. When you notice a worn tire and get it replaced, you’re managing risk. When you tell a pilot to skip a flight because the weather looks bad, you’re managing risk. When someone comes to you with a concern and you think about it, you’re managing risk.

The problem is that informal risk management has three big weaknesses:

  • Nothing gets written down. When you leave, the next person has no idea what you’ve been worried about or what you’ve already fixed.
  • Nothing gets checked. You fix a problem once, but you never verify that the fix held or that the problem doesn’t come back.
  • Nothing gets learned. Every time something goes wrong, you’re figuring it out from scratch because nobody wrote down what happened the last time.

An SMS is just the disciplined version of what you already do. It says: let’s write down what we’re worried about, decide what we’re going to do about it, verify the fix worked, and keep a record so we can learn.

The single most important thing to understand: An SMS is not a new job you have to do on top of running your business. It’s a better way of doing the job you’re already doing. If it feels like extra work bolted on, something’s wrong with how it’s being implemented.

The FAA has a formal name for this: Safety Management System, and a formal regulatory document (14 CFR Part 5) that tells you what it has to include. But the underlying idea is simple: organized, written-down, verified safety thinking.

2 Why is the FAA making you do this?

Because accidents keep happening for the same reasons, and they’re all preventable.

When the NTSB investigates a fatal accident, they rarely find one single catastrophic failure. They find a chain of small things that lined up wrong. A tired pilot, a rushed preflight, a maintenance item that got deferred too long, a piece of information that didn’t get passed on, a warning sign that everyone saw but nobody raised. Any one of those alone would have been survivable. Together they killed someone.

In every one of those accidents, someone — probably several people — had a hunch that something wasn’t quite right. And nothing happened. Nobody knew how to report it. Or they reported it and nothing came of it. Or they didn’t want to be the person who raised the concern.

The FAA’s conclusion was: if we can get operators to (a) encourage people to raise concerns and (b) act on those concerns systematically, we’ll prevent a lot of accidents.

The regulatory trigger: The FAA published 14 CFR Part 5 in 2015, which initially required Part 121 certificate holders to have an SMS. In May 2024, the rule was amended to extend the requirement to Part 135 operators and 14 CFR § 91.147 air tour operators with an LOA. The compliance deadline for these newly-covered operators is May 28, 2027.

What the FAA is NOT doing

A lot of operators assume the FAA is trying to catch them doing something wrong, or add paperwork as punishment. That’s not what’s happening. The FAA’s own inspector guidance (FAA Order 8900.1, Volume 17) is explicit about this:

  • The FAA is not evaluating your SMS by comparing it to some ideal template
  • The FAA does not require your SMS to look like anyone else’s
  • The FAA does not prescribe specific processes or formats
  • The FAA will not approve your SMS — they’ll acknowledge that you submitted a Declaration of Compliance

The rule is what’s called performance-based. That means the FAA tells you what outcome your SMS has to achieve, not how to achieve it. A one-person operation and a 200-pilot airline can both have compliant SMS programs, and they’ll look completely different. That’s by design.

This is good news. You don’t have to guess what the FAA wants. You have to run a disciplined safety process that fits your operation. If it works for you, it works.

3 The four pieces of an SMS

Every SMS in the world — whether it belongs to a two-person helicopter tour company or Delta Airlines — is built from the same four pieces. The FAA calls them the four components. You’ll hear them described by their formal names. Here’s what each one actually is.

📋
Safety Policy
Subpart B • §5.21-5.27

What it is: Written leadership commitment that says “we take safety seriously, here’s what we’re trying to achieve, and here’s who’s responsible for what.”

What it really means: This is the part where your company stops treating safety as something that just happens and starts treating it as something leadership actively owns. The most important piece of Safety Policy is that one person — the Accountable Executive — is on the hook for the whole thing. That person has to be real and identified by name, not a committee or a department.

What it looks like in practice: A short written Safety Policy Statement, a signed Commitment Letter from the executive, and an organizational chart showing who owns what.

🔍
Safety Risk Management
Subpart C • §5.51-5.55

What it is: A process for identifying hazards and deciding what level of risk you’re willing to accept.

What it really means: Before you do something new — fly a new route, buy a new aircraft, hire a new pilot, change a procedure — you stop and ask “what could go wrong here?” Then you decide whether it’s safe enough or needs to be changed. And when hazards get reported by your team, they go through the same process.

What it looks like in practice: A hazard reporting system that employees actually use, a risk matrix (usually 5×5) for assessing severity and likelihood, and a documented decision process for accepting or mitigating risk.

✓
Safety Assurance
Subpart D • §5.71-5.75

What it is: The process for checking whether your safety controls are actually working.

What it really means: It’s not enough to put a safety procedure in place. You have to verify that people are following it, that it’s achieving what you intended, and that new risks aren’t sneaking in. This is where audits, training tracking, and monitoring come in.

What it looks like in practice: Internal audits (annual or semi-annual), data analysis of hazard trends, safety performance monitoring, and a formal change-management process when things in your operation change.

📢
Safety Promotion
Subpart E • §5.91-5.93

What it is: Training and communication that keeps your team informed and engaged with safety.

What it really means: An SMS only works if people know about it, understand it, and believe in it. Safety Promotion is how you get the word out: initial and recurrent training, safety newsletters, safety briefings, and consistent messaging from leadership.

What it looks like in practice: Documented training on the SMS for everyone (including the executives), periodic safety communications, and a safety-focused culture that encourages reporting.

How they work together: Safety Policy sets the direction. Safety Risk Management identifies and handles risks. Safety Assurance checks that the risk handling is working. Safety Promotion keeps everyone aware. Remove any one of the four and the whole thing falls apart.

You’ll also hear about a fifth concept called Safety Culture — shared values and behaviors around safety. It’s not a separate component, but the FAA looks at it closely because a good safety culture is what makes the other four actually work. If your people don’t trust the system, they won’t report hazards. And if they don’t report hazards, none of the rest matters.

4 The words you need to know

Every industry has its own language, and SMS is no exception. The problem is that if you don’t know the words, it’s easy to feel like you’re missing something fundamental. You’re not. Here are the ones that matter, in plain English.

SMS (Safety Management System)
The whole thing. The documented, disciplined way you manage safety across your operation.
FAA definition: “The formal, top-down, organization-wide approach to managing safety risk and assuring the effectiveness of safety risk controls.”
Hazard
Anything that could cause harm. A worn part, an icy runway, a tired pilot, a confusing procedure. Hazards exist whether or not anyone has noticed them yet.
FAA definition: “A condition or an object that could foreseeably cause or contribute to an incident or aircraft accident.”
Risk
How bad the hazard would be, times how likely it is to happen. A hazard is a thing; risk is the danger it represents.
FAA definition: “The composite of predicted severity and likelihood of the potential effect of a hazard.”
Risk Control
What you do about a risk. Change a procedure, add training, install equipment, or just decide the risk is acceptable. Any action that reduces or manages a risk.
FAA definition: “A means to reduce or eliminate the effects of hazards.”
Accountable Executive
The one person who owns the SMS. Usually the owner, CEO, or top manager — whoever has real authority over how the operation runs. The FAA requires this to be a single named individual, not a committee.
FAA definition: “A single, identifiable individual having ultimate responsibility for the aviation organization’s SMS.” (14 CFR § 5.25)
SRM (Safety Risk Management)
The process of looking at hazards, assessing their risk, and deciding what to do. One of the four components.
FAA definition: “A process within the SMS composed of analyzing the system, identifying the hazards, and analyzing, assessing, and controlling safety risk.”
SA (Safety Assurance)
The process of checking whether your safety measures are actually working. Audits, monitoring, trend analysis. Another of the four components.
FAA definition: “The processes within the SMS that function systematically to ensure the performance and effectiveness of safety risk controls.”
Declaration of Compliance
A signed legal document you send to the FAA saying “we have an SMS that meets the requirements of Part 5.” This is the deliverable. This is what you’re ultimately working toward.
Per FAA Order 8900.1 Volume 17-2-1-3, it must include: the organization name and certificate number, physical address, a statement of compliance, and a signature from the Accountable Executive or another senior manager.
Safety Policy
Your written commitment to safety, including objectives and who’s responsible for what. The first of the four components.
FAA definition: “The aviation organization’s documented commitment to safety, which defines its safety objectives and the accountabilities and responsibilities of its employees in regard to safety.”
Safety Objective
A specific, measurable thing you’re trying to achieve. Not “be safe” but “reduce ramp incidents by 20% this year.” The FAA expects these to be real goals, not vague slogans like “zero accidents.”
FAA definition: “A measurable goal or desirable outcome related to safety.”
Corrective Action
Fixing something that went wrong so it doesn’t happen again. The specific steps you take in response to an identified problem.
FAA definition: “An action to eliminate or mitigate the cause or reduce the effects of an identified nonconformity or other undesirable condition to prevent its recurrence.”
Safety Culture
How your people actually behave around safety, as opposed to what’s written in a policy. The FAA measures this on a scale from “Present” to “Effective” during oversight.
FAA definition: “The shared values, actions, and behaviors that demonstrate a commitment to safety over competing goals and demands.”
Just Culture
A culture where people feel safe reporting mistakes, as long as they weren’t being reckless. The idea is that you want to hear about problems, not have people hide them out of fear.
Scalability
The principle that your SMS should be sized to fit your operation. A one-pilot company doesn’t need the same SMS as a regional airline. Smaller operations can have simpler systems.
SMSVP (SMS Voluntary Program)
An FAA program for operators who aren’t required by regulation to have an SMS but want one anyway. If you’re a Part 135 or 91.147 operator, you won’t use this — you’re required to have an SMS by 2027.
Part 5
Short for 14 CFR Part 5, the regulation that defines what an SMS has to include. This is the rule everyone is talking about when they say “you need an SMS.”
Part 135
The regulation for commuter and on-demand air carriers. If you carry passengers or cargo for hire in smaller aircraft, this is likely your operating rule.
Part 91.147
The regulation for commercial air tour operators. If you do sightseeing flights for compensation, this is likely your operating rule.

Don’t try to memorize all of these. Learn the four components, the Accountable Executive role, and the words “hazard” and “risk.” Those will get you through almost every conversation. Everything else you’ll pick up over time, or you can come back to this glossary when you need it.

5 What the FAA is actually looking for

This is the part that makes a lot of operators nervous. The FAA is going to come around and start asking questions about your SMS. What are they going to ask?

Here’s the thing that will relieve you: the FAA is not inspecting your SMS design. They’re not grading your paperwork. They’re watching how your operation actually behaves.

FAA inspectors have an internal framework called the SMS Maturity Level Model that they use to rate an SMS on a scale from 1 to 4:

Level What it looks like
Level 1
Present
The SMS exists on paper but isn’t really working. Employees don’t know their safety role. Documentation is confusing. The organization is reactive — the FAA finds problems before the operator does.
Level 2
Suitable
It’s starting to work. Employees are beginning to understand their roles. Managers are making risk-based decisions. The operator is starting to find some problems on its own.
Level 3
Operating
It’s working well. Processes are in place. Safety objectives are being used. The organization applies risk management when required. Evidence exists of controls being checked.
Level 4
Effective
It’s mature and proactive. The organization manages emerging risks before they become problems. Employees see safety as everyone’s responsibility. Continuous improvement is the norm.

Most operators start around Level 1 and hope to be at Level 2 or Level 3 within a few years. Level 4 is a long-term goal, not an initial requirement. The FAA knows this. The regulation’s own guidance says “for most organizations, SMS will take time to implement and several years to mature.”

The questions you’ll actually be asked

When an inspector comes around after you’ve submitted your Declaration of Compliance, they’re typically trying to figure out:

  • Do your employees know they can report hazards? And do they actually do it?
  • When a hazard gets reported, does something happen? Is it looked at, tracked, resolved?
  • Do you know what your top safety risks are? Not the ones the FAA would list — the ones specific to your operation.
  • When something changes in your operation, do you think about risk before you do it?
  • Are your people current on training? Including SMS training, not just flight training.
  • Is there a record of all this? If you were asked to show the trail, could you?

Notice that none of these questions are about the format of a document or the language in a policy. They’re all about whether the discipline is actually happening.

The thing to remember: The FAA is not looking for a perfect SMS. They’re looking for evidence that you’re running an SMS. A messy, working system beats a beautiful, unused one. Every time.

What happens if they find a problem

If an inspector notices something not working, they’ll ask a specific question that captures the whole spirit of SMS oversight:

“Why did the aviation organization’s SMS processes not identify this problem, and, if it was identified, why did the aviation organization not contain and/or correct the problem?”

— FAA Order 8900.1, Volume 17-5-1-1

What they want to see is that you have a system that would catch a problem like this, and if it didn’t, that you can explain why. A business that says “we didn’t know about this” isn’t in trouble as long as they can then show they learned from it and are fixing it. What gets you in trouble is having no system at all.

6 How FlyWise does it for you

You could build all of this from scratch with Word documents and Excel spreadsheets. Some operators do. FlyWise is the alternative: a pre-built SMS platform that has the four components already in place, tailored to your operation.

Here’s what each piece of the FAA framework maps to in the platform:

FAA Requirement What FlyWise does for you
Safety Policy
Commitment, roles, responsibilities
Generates your Commitment Letter and Safety Policy Statement using AI, based on your company profile. You review, sign, and publish.
Safety Risk Management
Hazard identification and risk assessment
Provides a Hazard Reporting system employees use to submit concerns, a 5×5 risk matrix, a 6-stage workflow (acknowledge, investigate, apply correction, re-evaluate, close), and a FRAT for pre-flight risk assessment.
Safety Assurance
Monitoring, audits, corrective actions
Includes an Internal Audit generator, a Health Check dashboard, Management of Change tracking, ERP Drills log, and automatic pulling of statistics into audit reports.
Safety Promotion
Training and communication
Provides an annual training system with tracking, a Safety Newsletter generator, and a document repository that feeds into training.
Documentation
SMS documents, procedures, records
Generates the SMS Procedures Manual, stores your company documents, and maintains timestamped audit trails for every action.
Declaration of Compliance
Signed submission to the FAA
Generates the Declaration of Compliance document, ready for signature and submission.

What you have to do yourself

FlyWise handles the structure and generates most of the documents. But there are three things you have to do that no software can do for you:

  1. Run the SMS. The platform gives you the tools. You have to actually use them — encourage employees to report hazards, process reports when they come in, run drills, conduct audits. FlyWise won’t do the work for you, it just makes the work structured and documented.
  2. Be the Accountable Executive. The FAA requires a named individual to own the SMS. That person has to be real, has to actually engage with the system, and has to sign the documents. This is not a delegation to a subordinate.
  3. Sign and submit. The Declaration of Compliance has to be signed by your Accountable Executive and sent to your local Flight Standards office. FlyWise generates it; you submit it.

The value of the platform: Instead of building all four components from scratch in Word and Excel, you get a working system in a few hours. You still have to run it — but you don’t have to invent the structure, and you don’t have to figure out what the FAA wants. That’s the shortcut.

7 Your first 90 days

If you’re starting from zero and have to be compliant by May 28, 2027, here’s the sequence that makes sense. Don’t try to do this all at once. Build it in the order the FAA expects to see it.

A practical starting sequence

  1. Week 1: Complete your company profile. Every document and form pulls from it. This is the foundation. Enter your operations, aircraft, personnel, and the Accountable Executive.
  2. Week 1-2: Generate your Commitment Letter and Safety Policy Statement. Review them. Have your Accountable Executive sign them.
  3. Week 2-3: Generate your SMS Procedures Manual. This is the how-to document that describes how your SMS works. Review it and adjust anything that doesn’t fit.
  4. Week 3-4: Set up your Hazard Reporting form. Use the AI wizard to generate it based on your operations, then edit as needed. Publish it.
  5. Week 4-5: Set up your FRAT if you have pilots. Same approach — AI generate, review, publish.
  6. Week 5-6: Turn on the Training system. Employees need annual SMS training. This runs automatically once you upload your core documents.
  7. Week 6-8: Train yourself and your managers on how the system works. Read the guides. Practice submitting a hazard, processing it through the workflow, closing it out. You need to know what you’re asking your employees to do.
  8. Week 8-10: Train your employees. Use the training system and the Email Templates in the Admin Dashboard to onboard everyone.
  9. Week 10-12: Start using it for real. Log hazards. Log changes. Run a drill. Do a Health Check. Let the system start collecting data.
  10. Month 3-6: Generate your first Internal Audit. Sign the Declaration of Compliance. Submit it to your Flight Standards office.
  11. Ongoing: Keep using the system. Every month check the Health Check. Every quarter send a Safety Newsletter. Every year run an audit and refresh your training.

Some operators will go faster. If you have a simple operation and you’re already disciplined about safety, you could be compliant in six weeks. The point isn’t to check boxes as fast as possible — it’s to have a system that’s genuinely working when you sign the Declaration.

Don’t sign the Declaration until the system is actually working. The Declaration is a legal document. It says you have developed and implemented an SMS that meets Part 5 requirements. If the system exists on paper but isn’t being used, you’ve signed something that isn’t true. The FAA will figure that out during follow-up surveillance.

8 Questions everyone asks

How long does this really take?

Building the SMS in FlyWise takes a few hours of setup — profile, document generation, form setup. Getting it actually working takes longer, because the platform needs real data from real use to be useful. The most common timeline for a small operator is 3 to 6 months from starting to submitting the Declaration of Compliance.

The deadline is May 28, 2027. If you’re reading this in 2026 or early 2027, you have time. Don’t panic and don’t rush a system that isn’t ready.

What if I don’t have any employees?

If you’re a sole individual performing all functions — you’re the pilot, the mechanic, the scheduler, everything — there are simplified requirements under 14 CFR § 5.9(e). You still need an SMS, but the FAA acknowledges that some of the four components are handled differently when there’s only one person.

In FlyWise, the platform can support this, but you should talk to your local Flight Standards office about what specifically applies to your situation.

Do I have to hire a safety manager?

No, not necessarily. The FAA requires an Accountable Executive, but that’s a role, not a hire. In a small operation, the Accountable Executive is often the owner or CEO, and they might also be the de facto Safety Manager. You may want to designate someone as your Safety Manager, but it’s not mandated by Part 5.

For larger operations, having a dedicated Safety Manager makes sense because someone needs to be running the day-to-day SMS work. For small operations, the Accountable Executive can wear that hat.

What happens if I don’t do this?

Part 135 certificate holders and 91.147 LOA holders are required by regulation to comply. The deadline is May 28, 2027. Failure to develop and implement an SMS by then could affect your operating authority. That’s the worst case.

The more practical concern: if you don’t have a real SMS and an incident happens, you’ll have a much harder time defending your operation. Investigators will ask how you managed safety, and “we just do it informally” isn’t going to hold up.

Do I need to submit my SMS manual to the FAA?

No. This is one of the surprises for new operators. The FAA does NOT require you to submit your SMS manual or documentation with the Declaration of Compliance. Per FAA Order 8900.1 Volume 17-2-1-17: “There is no requirement for an SMS manual or documentation to be submitted with the declaration of compliance.”

If you do submit one, the inspector isn’t required to evaluate it initially — that happens during routine follow-up oversight (Continued Operational Safety).

How do I know if my SMS is good enough?

Ask yourself three questions:

  1. Do my people report hazards? Not “can they” — “do they?”
  2. When something changes in my operation, do I think about the risk first? Not every time — but usually.
  3. If an incident happened, could I show a trail of how we managed safety?

If the answer to all three is yes, you’re on the right track. If the answer to any of them is no, that’s where to focus.

What’s the difference between an SMS and a safety program?

An SMS is a specific regulatory framework, defined by Part 5. A “safety program” is a looser term that could mean anything. If you already have a safety culture, safety training, or safety meetings, that’s great — but it’s not automatically an SMS. The SMS adds the documentation, the structure, the hazard tracking, and the verification that goes with it.

Does FlyWise replace the FAA’s SAS system?

No. SAS is the FAA’s internal system for tracking their oversight of your operation. You don’t interact with it directly. FlyWise is your SMS platform — the system you use to run your SMS. They’re different tools for different purposes. The FAA uses SAS to record what they observe about your SMS. You use FlyWise to run it.

What if I already had an SMSVP acknowledgment letter?

If you were in the SMS Voluntary Program before the rule change, your acknowledgment letter remains valid until May 28, 2027 — or until you revise your SMS and submit a Declaration of Compliance, whichever comes first. Once the rule applies to you, you’re no longer in the voluntary program; you’re in the regulated one. You need to submit a Declaration of Compliance by the deadline.

Where do I go from here?

If you’ve read this and feel like you understand the big picture, you’re ready for the next step. Here’s where to go:

  • If you want to start building your SMS: open the Getting Started Guide in the dashboard.
  • If you want to understand the documents you need: read the SMS Documents guide.
  • If you want to understand how the hazard system works: read the Hazard Dashboard guide.
  • If you want to understand the FRAT: read the FRAT Dashboard guide.
  • If you have a specific question: every major feature in the platform has its own guide. Look for the small indigo “Guide” button on each page.

You don’t have to read all of them. Read what you need, when you need it. The goal isn’t to memorize the platform — it’s to run your operation safely and be able to prove it.

Debug Info