Part 145 record-keeping starts with one date. Under EASA 145.A.55, a shop keeps its detailed maintenance records for three years from the day it issues the certificate of release to service (CRS). Arrival day and the day the work finished don’t count. The operator or CAMO also keeps its own records under M.A.305.
Why record-keeping liability lands harder on component shops
In an airline MRO, record gaps pass through several quality layers first. In a small component shop, however, the chain is shorter. The approved maintenance organisation (AMO) issues the CRS. That record then feeds the continuing airworthiness records that the operator or CAMO keeps under M.A.305. If it’s wrong, the error travels with the component.
Certifying staff sign the CRS on behalf of the organisation (145.A.50(a)). Each of them holds an individual authorisation under 145.A.35, and the person who signs is the one who checked the work. Now an auditor asks which component maintenance manual (CMM) revision you used on a brake overhaul 18 months ago. If the work order doesn’t show it, that person has nothing to point to.
Most of these gaps start on a Friday afternoon, when the job is done and the paperwork waits for Monday.
EASA vs. FAA: the retention minimums side by side
Both frameworks count retention from the release. The minimums differ, and for a shop with both approvals the EASA standard is the safe floor to build around.
| Requirement | EASA 145.A.55 (Reg. EU 1321/2014, amended by EU 2021/1963) | FAA 14 CFR 145.219 |
|---|---|---|
| Minimum retention | 3 years from CRS issue date | 2 years from date approved for return to service |
| What to retain | All detailed maintenance records and associated maintenance data | Records demonstrating compliance with 14 CFR Part 43 |
| Staff records | Duration of employment + 3 years after leaving or after the authorisation is withdrawn (145.A.55(d)(4)) | Training records: at least 2 years (14 CFR 145.163(c)) |
| On closure | Transfer the last 3 years to the last customer or owner, or store them as the competent authority specifies | Not specified in § 145.219 |
| Record language | Not specified for records (the EASA Form 1 itself should be in English) | English required |
If your shop holds both approvals, apply the EASA three-year standard across the board. Running two retention periods by regulator creates an audit risk that isn’t worth managing.
The work order behind every CRS
The work order is the document that justifies every CRS signature. On the FAA side, 14 CFR 43.9 sets the minimum content. It asks for a description of the work (or a reference to acceptable data), the completion date and the name of the person who did the work. It also asks for the signature, certificate number and kind of certificate of the person who approves return to service.
EASA goes further. AMC1 145.A.55(a)(3) (ED Decision 2023/013/R) says maintenance records should refer to the revision status of the data used. The manual title alone isn’t enough. In a wheel and brake shop, the task card or work order should show the CMM revision that was current on the day of the work. Suppose a newer revision already existed and the shop’s data control under 145.A.45 missed it. That finding can put the whole release in question.
The work order also links everything else. Incoming material certifications, the CRS number and the certifying staff authorisation reference all connect to it. The Part 145 workflow runs from receiving and preliminary inspection to job tasks, then to the EASA Form 1 or FAA 8130-3 release and shipping. Every stage leaves a record, and each record hangs off the work order.
Incoming material certifications
Every replacement part that enters a job arrives with a release document. A brake disc, an O-ring kit and a piston seal all come with one. Depending on the source, it’s an EASA Form 1, an FAA Form 8130-3 or a certificate of conformity (C of C). These documents belong to the detailed maintenance record, and the shop keeps them for three years under 145.A.55(a)(3).
EASA FAQ 19042 covers what goes to the customer. The shop doesn’t have to pass on incoming certificates of conformity, batch number references or individual task card sign-offs. Information on configuration, status or future maintenance is the exception, and dimensional data in task cards may need to go. The shop keeps the rest. The same FAQ calls recording batch numbers against the job best practice, and some competent authorities require it. A certificate in a general filing bin with no job reference helps nobody.
An unlinked certificate costs money later. Say an airworthiness directive (AD) comes out against a part number after release. If you can’t show which batch or serial number went into which job, the operator may face a re-overhaul. That cost traces back to your intake record. Give incoming certificates a work order reference at goods receipt. By the time a technician fits the part, half the paperwork is somewhere else.
Shelf-life and consumable traceability
Seals, O-rings, greases, hydraulic fluids and thread-locking compounds have shelf-life limits. They come from the OEM, through the CMM or the material specification. AMC1 145.A.42(a)(v) says the documentation or packaging should state any life limitation. An expired consumable in a build is an airworthiness nonconformance. Certifying staff who skip the lot number field should hear it put that way.
For every consumable on a job, record four things at the time of use. Those are the lot number, the manufacture or cure date (for elastomers), the shelf-life expiry and the quantity. EASA treats recording batch numbers as best practice and some authorities require it. Picture someone rebuilding an O-ring’s cure date from memory during an audit, six months after it went in. That record is already worthless.
For a small shop, a shelf-life card or consumables log clipped to the work order docket works fine. It takes two minutes during the job, because the lot number is in your hand. Rebuilding it afterwards can take an hour, if anyone can rebuild it at all.
Serialised component tracking through overhaul
Some components have life or overhaul limits in the maintenance data. On a wheel and brake bench that can include bearings, brake heat packs and some fasteners, depending on the aircraft type. For those, we recommend the work order holds the part number (P/N) and serial number (S/N). Add the life accumulated at induction and the life remaining against the limit at release. No regulation lists these fields, but the operator’s records depend on them.
M.A.305(d) sets what the aircraft continuing airworthiness records show. For life-limited parts, that’s the life each part has accumulated against its limitation parameter. For time-controlled components, it’s the life since their last scheduled maintenance. The owner or CAMO keeps those records, and the numbers come from the AMO’s CRS and work order. A lot of downstream trouble from component shops starts like this. The maintenance was right and one number on the release was wrong.
EASA doesn’t use the term “back-to-birth” in its regulations, as its FAQ 19043 confirms. The requirements are M.A.305(d) and (e), or ML.A.305(e) for Part-ML aircraft. In practice each life-limited part needs an in-service history showing its current status against its limit. M.A.305(e) also covers the CRS and detailed records of the last scheduled maintenance and any unscheduled maintenance after it. Those stay until scheduled maintenance of equivalent scope replaces them, and for at least 36 months. Each overhaul’s CRS becomes the next shop’s incoming documentation.
EASA Form 1 and FAA 8130-3, the records that leave the shop
A component maintained off the aircraft needs a CRS for that maintenance. It needs another CRS when someone installs it on the aircraft (AMC2 145.A.50(d)). That’s two releases and two documents, even when one certifying staff member signs both.
A shop maintaining a component for its own use may not need an EASA Form 1. That works if the internal release procedures in its maintenance organisation exposition (MOE) allow it (145.A.50(d)). Once a component goes to a customer, the EASA Form 1 is the standard release. The narrow exceptions sit in M.A.502 and ML.A.502.
Block 5 of the Form 1 carries a work order, contract or invoice reference, which ties the certificate back to the job. Record the Form 1 tracking number in the work order as well. No rule demands it. But without it, matching the two by hand during a surveillance audit can take a full day.
Certifying staff records
AMC1 145.A.55(d) (ED Decision 2022/011/R) lists the minimum record for each certifying staff or support staff member. It covers, as applicable:
- name and date of birth
- basic training, task or product/type training, and recurrent training
- experience, and qualifications relevant to the authorisation
- scope of the authorisation, date of first issue and expiry date (if appropriate)
- the authorisation’s identification number
These records back every CRS that person signs. If a field is missing, every release they signed becomes questionable.
The same AMC puts the compliance monitoring function in control of these records. The compliance monitoring manager doesn’t have to run the system. Somebody also has to check each CRS against the authorisation of the person who signed it, for that component type. An authorisation with the wrong scope is as bad as none, and the release is invalid either way.
Keep an authorisation matrix up to date and cross-referenced to MOE section 1.6, the list of certifying staff. Auditors check it against CRS samples. If the matrix is out of date, every release signed since the last update is a potential finding.
Tool calibration records and the work orders that used the tools
Under 145.A.40(b), the organisation controls and calibrates tools, equipment and particularly test equipment to an officially recognised standard. It keeps records of the calibrations and of traceability to the standard used. Most shops get the calibration itself right, so the problem is rarely there. The weak point is the link between a calibration record and the work orders that used the tool.
Say a torque wrench turns up past its calibration due date. Every work order that used it since the last valid calibration may need review, and that can be hundreds of records. The calibration record has to carry tool IDs and valid-from and valid-to dates in a form that makes those work orders searchable. Paper binders sorted by calibration date can’t do that, and the middle of an audit is a bad time to build it.
Digital records and electronic signatures under EASA
AMC1 145.A.55 allows records on paper, in electronic format or a mix of the two. A computer record system should have at least one backup, updated within 24 hours of any new entry. The backup hardware should sit in a different location from the working data. The system also needs safeguards that stop unauthorised people altering the data. FAA AC 120-78B gives the equivalent guidance for Part 145 repair stations. They also need OpSpec A025 authorisation to use electronic records or signatures. Paper stays acceptable under both frameworks.
Signatures inside the shop and on the certificate
EASA published Guidelines on the use of electronic documents, records and signatures on 4 May 2023. They separate two kinds of signature, and a component shop uses both.
Inside the organisation, §4.5.2 says a username and password is enough: “For the purpose of person identification to access to information provided by an internal-only tool and/or to provide attestation of steps completion, it is sufficient that user identification is achieved by means of a combination of username and password.” That covers sign-offs such as task cards and incoming inspection. The same paragraph attaches conditions. The organisation should control how it hands out usernames and passwords. At every login, the tool should show users when they last logged in, and users should report any anomalous access internally. Where the tool relies on hardware or connections the organisation doesn’t control, it should consider one-time passwords or two-factor authentication.
A certificate that leaves the organisation is a different case. Under §4.4, an organisation that may issue a certificate such as a CRS can sign it electronically. It uses an eIDAS advanced electronic signature or advanced electronic seal, or a higher standard, and a third party should be able to verify it online. The older AMC to Appendix II to Part-M (ED Decision 2015/029/R) covers an electronically signed EASA Form 1 in similar terms. It expects a personal electronic signature based on a cryptographic algorithm, linked only to the signatory and under their sole control. It also expects secure access for each certifying staff member and a high degree of assurance that nobody changed the data after signature. The shop documents that procedure and sends it to the competent authority with its exposition.
Both documents use “should”, not “shall”. EASA also expects the competent authority to accept the move from paper before it happens, and the exposition to describe the electronic tools, forms and signatures.
Information security under Part-IS
From 22 February 2026, point 145.A.200A requires Part-145 organisations to establish an information security management system under Commission Implementing Regulation (EU) 2023/203, Annex II (Part-IS.I.OR). The regulation leaves out organisations that only maintain Part-ML aircraft. Its scale follows the nature and complexity of the organisation’s activities, based on its own information security risk assessment. The competent authority may also let an organisation skip most of the requirements. For that, a documented risk assessment has to show no information security risk with a potential impact on aviation safety, to itself or to other organisations. For everyone else it applies now, whatever the renewal date.
When you compare shop management features, ask how each system supports your Part-IS risk assessment. Ask the same about the measures you define under it, such as access control and change traceability. Part-IS doesn’t prescribe software features.
Five record failures that keep showing up in audits
These findings come up again and again in component-shop audits. A well-structured work order and a consistent intake process prevent every one of them.
- Work orders citing no CMM revision, or an old revision that the shop’s technical data control missed.
- Incoming material certifications (EASA Form 1s, 8130-3s, C of Cs) not linked or filed against the relevant work order.
- Shelf-life consumable lot numbers and expiry dates not recorded at the time of use, so nobody can verify them afterwards.
- A certifying staff member’s authorisation not covering the component type on the CRS they signed.
- Calibration records with no cross-reference to the tool IDs on the work orders.
Most shops that find these in a dry run had the information somewhere. What failed was the filing.
Practical record-keeping checklist for a component shop
Complete every item before anyone signs the CRS. Then check the CRS and Form 1 cross-references before you close the work order.
- Work order opened with P/N, S/N and received condition documented.
- CMM chapter and revision cited for each task, and the revision confirmed current on the date of work.
- Task cards completed and signed by people whose authorisation covers the component type.
- Incoming certifications (EASA Form 1, 8130-3, C of C) filed under the work order number at goods receipt.
- Consumables logged at the time of use: lot number, cure or manufacture date, shelf-life expiry, quantity used.
- CRS number recorded in the work order, and the work order traceable from the Form 1 (Block 5) or 8130-3.
- Certifying staff authorisation reference noted in the work order record.
Retention trigger: the EASA three-year clock starts on the CRS issue date. The FAA two-year clock starts on the date of approval for return to service. Neither starts at induction or on the day work began.
Closure planning: write down now where your records would go if the organisation stopped operating. Under 145.A.55(a)(4) you transfer the last three years of records to the last customer or owner. The other option is to store them as the competent authority specifies. A buyer or successor will ask about it early.
Built on a real shop floor
AirOne MRO by V1AeroSolutions is shop management software. We built it inside a working EASA Part-145 wheel and brake shop. It doesn't yet show users their last login or offer two-factor login, and we've started building both. The first 10 Founding Shops get a full year free in exchange for honest feedback.
Under 145.A.55(a)(3), as amended by Regulation (EU) 2021/1963, the organisation keeps all detailed maintenance records for at least three years. That includes certificates of release to service and any associated maintenance data. The clock starts on the CRS date. The date the work began and the date the component arrived don’t count.
We’d record at least the part number, serial number and received condition, and a description of all work performed. Add task references with the CMM chapter and the revision current on the day of work, and the incoming certification references (EASA Form 1, 8130-3 or C of C). Then the consumable lot numbers and expiry dates, the CRS number and the certifying staff member’s authorisation reference. AMC1 145.A.55(a)(3) says maintenance records should refer to the revision status of the data used.
From the CRS issue date. 145.A.55(a)(3) counts the three years from the day the aircraft or component received its certificate of release to service. If an overhaul takes several weeks, the clock starts on the date written on the CRS.
Under 145.A.55(a)(4), an organisation that stops operating transfers the records covering the last three years to the last customer or owner of each aircraft or component. Or it stores them the way the competent authority specifies. It’s worth deciding which before it happens.
Yes. AMC1 145.A.55 allows electronic records, with a backup updated within 24 hours in a different location and safeguards against unauthorised changes. EASA’s 2023 guidelines say a username and password is enough for sign-offs inside the organisation (§4.5.2). A certificate such as a CRS can carry an eIDAS advanced electronic signature or seal, or higher (§4.4). The competent authority should accept the change before you move off paper, and the exposition should describe it. Since 22 February 2026, point 145.A.200A also requires an information security management system under Regulation (EU) 2023/203. Shops that only maintain Part-ML aircraft are outside it, and others can hold an approved derogation.