When I speak with Quality Directors and Compliance Managers in the field, the assessment is almost always the same: Risk-Based Oversight (RBO) is on everyone's lips, but very few organizations have actually made the leap.
On paper, the approach appeals to everyone. In practice, however, implementation hits a pragmatic wall: teams are already overwhelmed by daily operations and heavy documentation. Here is my field analysis of the roadblocks to RBO and a step-by-step method to turn it into a true management tool.
1. Twenty years of regulatory evolution meets the wall of daily operations
RBO is not a new idea. Gradually introduced by ICAO (Doc 9859), formalized by EASA in 2012, and adopted by IATA (IOSA standards), the principle relies on an obvious fact: move away from rigid calendar-based audits (systematic checks every 12 or 24 months) to focus resources where risks are highest.
Yet, across most airlines, MROs, and airports, oversight remains heavily focused on formal, "tick-the-box" compliance. The prescriptive approach offers a reassuring, predictable framework that is easy to justify to authorities during approval renewals. But it maintains a form of illusion of safety. European regulatory frameworks (via the SSP, EPAS plan, or MSAT evaluation grids) are pushing the industry toward measuring actual safety performance, but on the ground, the gap is widening. Moving from a fixed schedule to dynamic risk-based tracking requires two prerequisites that most aviation organizations lack: a perfectly structured volume of incident data and available expert time to analyze it.
2. Internal and external oversight: the need for fine granularity
To move past theory without building a bureaucratic nightmare, we favor a pragmatic method, built on the field experience accumulated at Time to Fly, that allows organizations to launch RBO immediately, even with limited historical data and resources.
The approach relies on two operational pillars:
- Internal oversight (sub-topic breakdown): Instead of auditing an entire domain (e.g., Flight Operations) as a single block once a year, the method breaks processes down into finer sub-topics (aerodrome selection, operating minima, performance, fuel scheme, etc.). Each sub-topic is evaluated using an accessible grid combining recent changes in that area, safety events, and audit finding history.
- External oversight (subcontractor management): Treating all providers equally is a waste of resources. An individual risk score is calculated by weighting simple criteria: task criticality, frequency of use, geographic/geopolitical risk, dependency on the provider, held approvals, etc. A critical subcontractor undergoes a full audit, while a low-stake provider is monitored via a desktop review or questionnaire.
3. The real bottleneck: daily operational saturation
Why is this methodology still struggling to become standard practice?
Because operational reality quickly catches up with the best intentions. Today, management system managers and their teams are already 100% mobilized responding to mandatory regulatory requirements and managing daily emergencies.
Feeding a risk profile requires constantly cross-referencing manuals, analyzing finding histories, and processing data. Lacking the time and bandwidth to add this extra layer of analysis, RBO falls to the background. Organizations stick to what is immediately required: traditional oversight schedules.
What this changes for your compliance processes
My experience alongside aviation stakeholders has confirmed one thing: you cannot ask teams to adopt Risk-Based Oversight if you don't first give them back time and capacity.
This is precisely why RegUp was created. By automating the pre-analysis of your manuals against regulatory requirements, the tool frees your teams from the most time-consuming tasks, allowing them to focus on high-value initiatives like deploying RBO!
And that's just the beginning. We are already working on the next step: integrating RBO logic directly into the heart of RegUp. Stay tuned!





