5.2 Aircraft Maintenance Programmes (AMP) & Maintenance Data
Key Takeaways
- Under M.A.302, every civil aircraft registered in an EU Member State must be maintained in accordance with an approved Aircraft Maintenance Programme (AMP) that integrates TC holder Instructions for Continuing Airworthiness (ICA).
- The baseline AMP for transport category aircraft is derived using MSG-3 decision logic from Maintenance Review Board Reports (MRBR) and Maintenance Planning Documents (MPD).
- Mandatory continuing airworthiness limitations within the AMP include the Airworthiness Limitations Section (ALS), Certification Maintenance Requirements (CMR), Critical Design Configuration Control Limitations (CDCCL), and EWIS EZAP tasks.
- Reliability monitoring programmes under M.A.302(g) are legally mandatory for commercial air transport and complex motor-powered aircraft to continuously assess and validate AMP task effectiveness.
- The AMP must be directly approved by the National Aviation Authority (NAA) or indirectly approved by a Part-CAMO holding indirect approval privileges in its CAME, and must undergo a mandatory review at least annually.
Purpose and Statutory Obligation: M.A.302
The Aircraft Maintenance Programme (AMP) is the foundational operational document governing all preventive maintenance performed on an aircraft. Under M.A.302, the continuing airworthiness of every aircraft must be ensured by compliance with an approved AMP. Operating an aircraft without an approved, valid AMP—or failing to accomplish maintenance tasks within the prescribed time limits—renders the Certificate of Airworthiness (CofA) invalid and grounds the aircraft as a matter of law.
The primary objective of an AMP is to maintain the inherent design safety and reliability levels of the aircraft, its engines, propellers, and associated systems throughout its operational lifecycle. It prevents progressive mechanical degradation, identifies latent functional failures before they compromise flight safety, and complies with all mandatory certification mandates imposed by the Type Certificate (TC) holder and civil aviation authorities.
Derivation of the Baseline AMP: MSG-3, MRBR, and MPD
For modern transport category aircraft (such as Airbus, Boeing, ATR, and Embraer fleets), an operator's customized AMP does not originate in a vacuum. It is the end product of a standardized international engineering methodology developed through the Maintenance Steering Group (MSG) process.
| Source Document / Methodology | Governing Entity | Primary Function & Content | Legal Status in AMP Derivation |
|---|---|---|---|
| MSG-3 Decision Logic | Industry Steering Committee (A4A / OEMs / Regulators) | Top-down, task-oriented failure analysis assessing safety, operational, and economic failure consequences. | Analytical methodology establishing task selection logic. |
| Maintenance Review Board Report (MRBR) | Regulatory Board (EASA, FAA, TCCA) + Industry | Contains the baseline minimum scheduled maintenance requirements for the aircraft type. | Initial regulatory minimum standard for type certification. |
| Maintenance Planning Document (MPD) | Type Certificate Holder (OEM) | Translates MRBR tasks into check packages (A, C checks), adds man-hours, access panels, and vendor ICA. | Recommended manufacturer planning baseline. |
| Customized Operator AMP | Operator / Part-CAMO (M.A.302) | Tailors MPD tasks to operator utilization, route profile, ALS limits, CDCCL, STCs, and modifications. | Legally binding approved operational maintenance standard. |
1. MSG-3 Decision Logic Philosophy
Developed by the Air Transport Association (ATA, now Airlines for America) in collaboration with manufacturers and airworthiness authorities, MSG-3 (Maintenance Steering Group - 3) represents a "top-down, task-oriented" methodology. Unlike older bottom-up approaches (such as MSG-1 and MSG-2) that focused on individual component overhauls, MSG-3 analyzes failure consequences at the system and aircraft level.
MSG-3 categorizes all functional failures into distinct consequence levels:
- Category 1: Safety (Evident) — Failures having a direct adverse effect on operating safety.
- Category 2: Operational (Evident) — Failures that do not compromise safety but impose flight delays, cancellations, or economic penalties.
- Category 3: Economic (Evident) — Failures involving direct repair or replacement costs without operational penalties.
- Category 4: Safety (Hidden) — Latent failures of unmonitored or backup safety systems that, when combined with an active subsequent failure, lead to a catastrophic event.
- Category 5: Non-Safety (Hidden) — Latent failures of systems having no direct safety impact.
2. Maintenance Task Categories in MSG-3
Under MSG-3 logic, maintenance tasks are selected to mitigate these failure consequences. The three classic maintenance processes are:
- Hard Time (HT): A preventive process requiring scheduled replacement, overhaul, or structural rework of an item at or before a specified operating limit (expressed in flight hours, flight cycles, or calendar months). HT applies to components exhibiting known, predictable wear-out characteristics (e.g. landing gear assemblies, engine life-limited rotating discs);
- On-Condition (OC): A preventive process requiring repetitive scheduled inspections, dimensional measurements, or non-destructive testing (NDT) to evaluate the physical condition of an item against defined wear limits. The item is allowed to continue in service until the inspection reveals degradation approaching the failure boundary (e.g. brake disc wear pin measurement, control cable tension checks, structural crack inspections);
- Condition Monitoring (CM): A management process where items operate to failure without scheduled preventive maintenance tasks. CM is permissible only for items where functional failure has no direct safety consequences (Categories 2, 3, and 5). Fleet reliability data, pilot defect logs, and component removal rates are monitored statistically to identify emerging failure trends.
3. MRB Report (MRBR) vs Maintenance Planning Document (MPD)
- Maintenance Review Board Report (MRBR): The official document containing the initial minimum scheduled maintenance tasks developed by the Industry Steering Committee (comprising operators and the manufacturer) and formally approved by the regulatory Maintenance Review Board (EASA and the FAA). It defines the baseline inspection intervals;
- Maintenance Planning Document (MPD): Produced by the Type Certificate holder, the MPD takes the raw tasks approved in the MRBR and adds manufacturer service recommendations, zonal inspection criteria, access panel requirements, and man-hour estimates. It groups tasks into practical maintenance check packages (e.g., Daily, Transit, A-Checks, and C-Checks).
Mandatory Continuing Airworthiness Data: Non-Escalatable Tasks
While an operator has flexibility to customize certain commercial inspection tasks within its AMP, European law strictly identifies several categories of mandatory continuing airworthiness data that can never be escalated, altered, or omitted without explicit approval from EASA or the competent authority:
1. Airworthiness Limitations Section (ALS)
Pursuant to Part-21 (CS-25.1529 and Appendix H), the Airworthiness Limitations Section (ALS) is a legally binding part of the Instructions for Continuing Airworthiness (ICA) approved directly by EASA. The ALS contains:
- Mandatory structural inspection thresholds and repeat intervals derived from damage-tolerance assessments;
- Mandatory retirement limits for structural life-limited parts (Safe Life limits);
- Fuel airworthiness limitations and EWIS limitations. Compliance with the ALS is mandatory under both Part-21 and M.A.302. Exceeding an ALS interval is a criminal and regulatory violation.
2. Certification Maintenance Requirements (CMR)
Certification Maintenance Requirements (CMRs) are scheduled maintenance tasks resulting from design-phase System Safety Assessments (SSA) conducted under CS-25.1309. CMRs are specifically designed to detect latent (hidden) failures of critical standby systems that, if left undetected, would compromise aircraft safety when combined with another independent failure (e.g., verifying the operational availability of a secondary emergency hydraulic shut-off valve that is never energized in normal flight).
- One-Star CMR ($\star$): Non-escalatable task; intervals cannot be altered under any circumstances without direct EASA approval;
- Two-Star CMR ($\star\star$): Escalatable task; intervals may be adjusted if the operator's reliability monitoring programme demonstrates equivalent safety, subject to National Aviation Authority approval.
3. Critical Design Configuration Control Limitations (CDCCL)
Introduced globally following the catastrophic in-flight explosion of TWA Flight 800 (and codified in Europe via CS-25 Appendix H and EASA Fuel Tank Safety rules):
- CDCCL mandates the identification and preservation of critical design features that prevent the creation of ignition sources within fuel tanks and associated fuel systems;
- Examples include: lightning protection bonding jumpers, transient suppression units (TSUs), physical separation between fuel quantity indication system (FQIS) low-voltage wiring and high-voltage electrical buses, and flame arrestor screens in fuel tank vent pipes;
- Any maintenance task, alteration, or wiring repair within a CDCCL zone must strictly preserve the exact engineering configuration. Installing non-conforming hardware or altering wire routing voids aircraft airworthiness.
4. Electrical Wiring Interconnect System (EWIS) & EZAP Tasks
Under CS-25 Appendix H, the Enhanced Zonal Analysis Procedure (EZAP) requires specific scheduled maintenance tasks dedicated to the cleaning, inspection, and contamination removal of electrical wiring harnesses (EWIS). These tasks aim to prevent catastrophic electrical arcing caused by accumulation of combustible dust, hydraulic fluid leaks, or wire insulation chafing.
| Mandatory Data Category | Originating Regulation | Primary Airworthiness Objective | Escalation Permissible? |
|---|---|---|---|
| ALS (Structural Limits) | Part-21 / CS-25.1529 | Prevent structural fatigue failure & loss of primary airframe | No (Direct EASA approval required) |
| ALS (Life-Limited Parts) | Part-21 / CS-E (Engines) | Mandatory retirement of rotating discs, shafts, & gearboxes | Strictly Prohibited (Hard Limit) |
| CMR (One-Star $\star$) | CS-25.1309 SSA | Detect latent failures in safety-critical redundant systems | No (Direct EASA approval required) |
| CMR (Two-Star $\star\star$) | CS-25.1309 SSA | Detect unannounced system failures | Permissible with NAA approval |
| CDCCL (Fuel Tank Safety) | CS-25 Appendix H | Eliminate ignition sources (sparks, heat) inside fuel tanks | Strictly Prohibited (Design standard) |
| EWIS / EZAP | CS-25 Appendix H | Prevent wiring harness arcing, chafing, and dust fire | Only via approved AltMoC / AMP revision |
Programme Customization, Bridging, and Reliability Monitoring
Programme Customization: Utilization and Operational Profiles
Every operator must adapt baseline MPD intervals to its unique operational environment:
- Flight Hours (FH): Directly relates to system operating time and engine wear;
- Flight Cycles (FC): Relates to pressurization cycles, landing gear stress, and engine thermal shock;
- Calendar Time (Cal): Relates to corrosion, seal aging, lubrication dry-out, and environmental degradation.
An operator flying short-haul sectors (e.g. 1 flight hour per cycle) accumulates cycle-governed structural wear much faster than a long-haul operator flying 10 flight hours per cycle. The AMP must be structured accordingly.
Bridging Maintenance Programmes
When an aircraft transitions between operators (e.g. upon lease return or fleet acquisition), its existing maintenance schedule does not match the new operator's approved AMP check package intervals. The acquiring CAMO must develop a Bridging Programme:
- Conducts an item-by-item comparison between the previous operator's check intervals and the new AMP;
- Determines the elapsed time since each task was last performed;
- Packages bridging inspection tasks to align the incoming aircraft onto the new operator's maintenance schedule without exceeding any maximum allowable MPD or ALS task limits.
Reliability Monitoring Programme (M.A.302(g))
For Commercial Air Transport and Complex Motor-Powered Aircraft, the AMP must incorporate an approved Reliability Programme. The reliability programme acts as the primary feedback loop validating AMP effectiveness:
- Tracks key safety indicators: Pilot Defect Reports (PIREPs), Technical Delays > 15 minutes, In-Flight Engine Shut-Downs (IFSD), Unscheduled Component Removal Rates (MTBUR), and shop teardown findings;
- Uses statistical process control (Upper Alert Levels based on standard deviations $\mu + 2\sigma$ or Poisson distribution);
- When an alert threshold is breached, the operator must conduct root-cause investigation and adjust the AMP (e.g. de-escalating task intervals, introducing new NDT inspections, or modifying component overhaul limits).
AMP Approval Architecture & Annual Review
Direct vs Indirect Approval Procedures
Under M.A.302, the AMP must be formally approved before implementation:
- Direct Approval: The complete AMP and all subsequent amendments are submitted directly to the competent National Aviation Authority (NAA) for review and written approval;
- Indirect Approval: Under CAMO.A.125(d)(1), the competent authority may grant a Part-CAMO the privilege to approve amendments to the AMP indirectly, without prior authority submission. To exercise indirect approval:
- The CAMO must have an approved indirect approval procedure documented in its Continuing Airworthiness Management Exposition (CAME);
- The procedure applies only to non-complex revisions (e.g. incorporating standard OEM MPD updates);
- Baseline changes affecting mandatory airworthiness limitations (ALS, CMR, CDCCL) or initial AMP approval can never be approved indirectly.
Mandatory Annual Review of the AMP
Pursuant to M.A.302, the AMP must be reviewed at least annually (once every 12 months) by the CAMO. This review verifies that the programme remains effective in light of fleet operating experience, latest TC holder ICA revisions, Airworthiness Directives, and internal reliability data trends.
Practical Maintenance Scenario & Module 10 Exam Tips
Maintenance Practical Example: A Part-CAMO managing an Airbus A320 fleet receives a new revision of the Airbus MPD that escalates the zonal visual inspection of the lower fuselage bilge from 24 months to 36 months. However, the airline's reliability data over the past 12 months shows three separate instances of intergranular corrosion discovered in that exact bilge area. If the CAMO holds indirect approval privileges, can it automatically adopt the 36-month escalation? Absolutely not. Under M.A.302 and AMC M.A.302, an operator cannot escalate a maintenance interval if operational reliability data indicates that the current interval is already marginal or inadequate. The CAMO must retain the 24-month interval (or even de-escalate it) to maintain airworthiness.
Module 10 Exam Tips:
- MSG-3 is top-down and task-oriented; MSG-2 was bottom-up and component-oriented.
- The three maintenance processes: Hard Time (HT), On-Condition (OC), and Condition Monitoring (CM). CM is permissible only when failure has no direct safety consequences.
- ALS, CMR (One-Star), and CDCCL are strictly non-escalatable by the operator without direct EASA/NAA approval.
- The AMP must be reviewed at least once every 12 months (annually).
- Indirect approval of the AMP is an optional privilege granted to a Part-CAMO and detailed in its CAME.
In accordance with MSG-3 maintenance task derivation logic, which statement correctly defines the On-Condition (OC) maintenance process?
What is the primary regulatory purpose of Critical Design Configuration Control Limitations (CDCCL) embedded within an approved AMP?
Which statement accurately describes the function and origin of Certification Maintenance Requirements (CMR)?
Under M.A.302, what are the primary legal requirements governing the approval and periodic evaluation of an Aircraft Maintenance Programme?