If you run a Part-145 business, January 2028 is a date you should have on your radar. From 1 January 2028, information about Part-145 Maintenance Organisation Approvals will be in EASA’s aviation information repository – a shared electronic system used by EASA and national aviation authorities to exchange and manage specific civil-aviation information.
In practical terms, this means the approval details held for your organisation need to be accurate and up to date. Your approval key details should match your current records and the information held by the authority.
Are the details of your Part-145 approval correct, current, and consistent with what the authority has on record? For MROs, it is a time to look at how this information is stored, updated, and controlled.
It is important to understand what this does—and does not—mean. Firstly, this is not a complete move from paper to digital. It does not mean that every record must suddenly become electronic.
For a large MRO, this information may already be managed through dedicated software and established procedures. Smaller MROs may be maintaining across the MOE, folders, spreadsheets, or paper files.
What is Changing?
Commission Implementing Regulation (EU) 2023/2117 has introduced rules for a shared information system used by aviation authorities. The system is intended to keep certain information about approved aviation organizations in one place so that the relevant authorities can access and exchange it.
Part-145 maintenance organisation approvals are included in the information, with the relevant Group B requirements applying from 1 January 2028.
This date does not mean that every Part-145 maintenance record must become electronic. It is not a general requirement to replace paper job cards, worksheets, or other maintenance records with digital versions. The focus is on specific information connected to an organisation’s approval and how that information is managed and made available.
However, the date is an opportunity to review how information is managed by MRO operators, including Part-145 businesses.
Is the information you have accurate and up to date? Do you know where it is store? Who is responsible for it? If you use digital systems, can you show that the records are properly controlled and protected?
These are questions that can help identify audit issues. A sign-off process that does not control who can make or change is just one example of outdated process.
Step One: Check Your Approval Information
Make sure your information is correct and up to date. Your records should match what the authority has on file. If something mismatches, update that records.
You don't need a big compliance team to handle this. Assign someone the task to keep data up to date. Set the review date, you can utilize digital system for timely reminders.
When someone has an ownership, it will prevent from small issues, which may later become audit issues if not prevented.
Focus on current information before scanning archives. Check the approval certificate and capability list first. Then check certifying staff authorisations and nominated postholder records. Finally, confirm that everyone uses the current MOE revision.
A simple mismatch can later become an issue. For example, a capability list may show a withdrawn task. Meanwhile, an old version could still appear in a shared folder. That issue is easy to prevent with controlled access and clear revision labels.
Step Two: Make Electronic Records Reliable
Once you have checked that your current information is accurate and up to date, the next step is to look at how your electronic records are handled.
An electronic file is not automatically a controlled record. It should show who made an entry and when it was made. It should also keep a clear history of any corrections or changes.
Someone looking at it later should be able to see what work was carried out. If an entry needs to be corrected, the original information should not disappear.
It is important to have a trace a record, showing that it is genuine. It helps MRO shops understand the types of controls an authority may look for.
If you are moving from paper to electronic, it is also sensible to discuss the change with your authority before making the switch.
The controls do not have to be complicated. Each person carrying out authorised work should have their own account, rather than using a shared username and password for maintenance sign-offs. Once a record is completed, it should also be protected from normal editing.
Your system should keep a history of changes, showing what was changed, who made the change, and when it happened. Backups are just as important. There is little value in having an electronic record if you cannot recover it after a system failure or outage.
The same care applies to electronic signatures. A username and password may be suitable for some internal systems, while systems that allow external access or are hosted by another company may need additional safeguards. The important thing is to choose controls that are appropriate for the system, the risks involved, and your organisation's procedures.
Step Three: Align the MOE With Daily Work
There is another part that is easy to overlook: the MOE needs to reflect how the work is done.
If your team has moved part of a process from paper to an electronic system, the MOE should explain that process. This includes how records are created and signed, who has access, what training is needed, and how records are kept.
This is where problems can appear. A procedure may say one thing while the team follows a slightly different process. Perhaps a technician uses an electronic form that is not mentioned in the MOE, or a supervisor has a different way of reviewing corrections. These differences may seem minor, but they can make the process harder to control.
The best procedures are straightforward. Someone reading the MOE should be able to understand the maintenance process. It does not depend on one person knowing all the details.
Here’s what you should follow. Choose something your technicians do regularly and follow it from the beginning to the final sign-off. Then look at the completed record as if you were seeing it for the first time.
Can you see what work was carried out, who completed it, what information was used, and whether anything was changed along the way? If the system stopped working, could you recover the record?
That simple exercise can tell you a lot. It can show where the process works well and where a procedure, training point, or system control needs to be improved. Keep the evidence from the test as well. It gives you something useful to refer to during an internal review and, if needed, when discussing the process with your competent authority.
When a Simple System Starts Making a Big Difference
For some MROs, these checks may be easy to manage with the systems already in place. For others, they may expose a problem. Because their information is maintained in spreadsheets, shared folders, paper files, emails, and different systems.
That is usually where a simple MRO maintenance software can be useful, and dramatically improve productivity.
Modern MRO SaaS platforms make day-to-day work easier. They make controls effortless. They provide operators with information when they need in no time with in-built features used to connect and centralised information in a role-based manner. They provide a real-time status of a task without opening a separate spreadsheet.
They include in-built feature to track who created it? Who approved it? Was anything changed? Can the record still be retrieved months or years later? And if the system goes down, can the information be recovered?
They are decent alternatives to large and complicated systems for small MRO operators.
The important thing is to solve the problem first and choose the technology around it—not the other way around.
A Proportionate Way Forward
For a small MRO, there is no need to rush into major software changes simply because January 2028 is approaching. The date is important for Part-145 approval information under EASA’s repository rules, but it does not mean that every maintenance document needs to be digitised.
A better approach is to use the time to look at what you already have and improve it where needed.
Start by making sure your approval information is current and consistent. Then look at your electronic records and make sure they can be traced, are protected from unauthorised changes, and can be recovered if something goes wrong. Finally, check that your MOE describes the process your team actually follows.
This does not have to become a major project. For many smaller MROs, a focused review of existing information, systems, and procedures may be enough to identify and fix the gaps.
The aim is simple: know what you have, keep it under control, and be able to show that it works.

