For repair stations

Part 145 Document Management Software: Requirements and Workflow

A requirements-driven guide to software for current maintenance data, signed work evidence, access, retention, and customer records.

For repair stations 11 sections · 7 min read Published July 27, 2026 · Updated July 27, 2026

In brief

Part 145 document software should implement the approved organization’s procedures and jurisdiction-specific requirements. The system must keep required data current and accessible, protect signed maintenance evidence, control changes, retain records, and deliver a complete customer package.

Tools for this decision

Run the numbers while you read.

See all aircraft tools
Part 145 Document Management Software: Requirements and Workflow editorial illustration

“Part 145” can refer to an FAA-certificated repair station under 14 CFR part 145, an EASA Part-145 approved maintenance organization, or another authority’s similarly named framework. These approvals are not interchangeable.

Start a software project by mapping the authority, ratings, operations specifications or terms of approval, repair-station or exposition procedures, customer/operator rules, and contracts that apply to each site and work type.

Build a jurisdiction and approval matrix

Build a jurisdiction and approval matrix
QuestionWhy the system needs the answer
Which authority issued each approval?Determines governing requirements and oversight
Which ratings and limitations apply?Prevents work outside authorized capability
Which locations and line stations are covered?Controls data, privileges, and availability by site
Which customers operate under Parts 91, 121, 135, or another system?Adds operator-specific record and program requirements
Which bilateral procedures apply?May add supplement, release, or audit controls
Which manual revision is approved or accepted?Connects workflows to controlled procedures
Which records must be delivered and retained?Defines package, format, retention, and access

A dual-release work order may require more evidence and certification logic than a domestic component job. Configure by rule and scope; do not rely on staff memory.

Control current maintenance data

Under 14 CFR 145.109, an FAA repair station must maintain current and accessible documents and data needed for the work, including applicable ADs, instructions for continued airworthiness, manuals, service bulletins, and other accepted or approved data. EASA Part-145 likewise controls applicable maintenance data.

The software should:

  • Identify the controlling publication and revision for every task.
  • Show effectivity and applicability before work begins.
  • Prevent unintentional use of superseded data and route any exceptional use through the applicable approved or accepted process.
  • Capture the revision actually used in the work record.
  • Control customer-supplied and locally stored data.
  • Record temporary revisions and technical queries.
  • Preserve evidence of data review and distribution.
  • Work at the point of maintenance, including degraded-connectivity procedures.

A PDF library with search is useful, but it is not revision control unless users can prove which data governed the accomplished work.

Create the work record as work happens

The work order should connect:

  1. Customer request and contracted scope.
  2. Article identity, incoming condition, and eligibility.
  3. Planning, data, parts, tools, and personnel requirements.
  4. Task accomplishment and independent inspections where required.
  5. Findings, non-routines, approved repairs, and scope changes.
  6. Parts removed and installed, with trace and release documents.
  7. Measurements, test results, and calibrated equipment.
  8. Deferred or excluded work communicated to the customer.
  9. Final review and authorized release.
  10. Customer records package and retained copy.

Keep signed source evidence at task level. A billing summary or high-level work-order close screen cannot replace the details needed to demonstrate what was done.

Protect certification and electronic signatures

An electronic signature must be attributable to the authorized person and bound to the exact record signed. A mature design includes:

  • Unique identity and strong authentication.
  • Role and authorization checks at signing time.
  • Meaning of the signature: perform, inspect, supervise, or release.
  • Timestamp and record version.
  • Protection against reuse or repudiation.
  • Visible changes after signature and controlled re-signing.
  • Audit trail for failed, withdrawn, and superseded signatures.
  • Emergency and system-outage procedures.

FAA AC 120-78B provides an acceptable, non-exclusive means for electronic signatures, records, and manuals under applicable U.S. rules. The organization still needs the procedures and acceptance appropriate to its operation.

Configure retention by record class

Do not set one deletion rule for everything.

Configure retention by record class
Record classExample basisSystem control
FAA maintenance records14 CFR 145.219: at least two yearsRetain from return-to-service date; produce for FAA/NTSB
EASA detailed maintenance records145.A.55: three yearsRetain release, work details, and associated data
EASA management/contract records145.A.55: generally five years for specified classesSeparate schedule and ownership
Personnel authorization/trainingApproval-specific rules and post-employment periodsEffective dates, scope, expiry, restricted access
Customer/operator recordsContract and operator programDeliver and retain as agreed
Litigation, investigation, or holdLegal directionSuspend ordinary destruction

The system should calculate the trigger correctly, document any longer controlling period, place holds, and prove destruction approval. Never infer that the repair station’s minimum retention period tells the aircraft owner how long to keep its separate continuing-airworthiness records.

Deliver a complete customer package

For an FAA repair station, 14 CFR 145.219 requires a copy of the maintenance release to the owner or operator. EASA 145.A.55 requires the release plus copies of detailed records necessary to demonstrate the relevant continuing-airworthiness requirements.

Define the package for each work type:

  • Certificate or approval for return to service.
  • Signed task cards and inspection evidence.
  • Findings and corrective actions.
  • Component release and trace documents.
  • Approved repair or modification data references.
  • Measurements, test results, and status changes.
  • Updated configuration, weight and balance, or ICA material where applicable.
  • Open work, exclusions, and customer notifications.

Generate a package manifest. Reconcile expected and delivered documents, obtain receipt, and retain exactly what was transmitted.

Control personnel, authorizations, and permissions

The system should not allow a valid login to imply unlimited certification privilege. Model:

  • Approval and location.
  • Product, rating, task, and aircraft type.
  • Perform, inspect, support, and certify roles.
  • Training, experience, continuation, and recency.
  • Authorization issue, restriction, suspension, and expiry.
  • Temporary, contracted, and agency personnel.

At the work step, evaluate the authorization effective at that time. Preserve historic privileges so an auditor can reconstruct why a signature was allowed.

Build quality and safety evidence into the system

Document management also supports:

  • Internal audits and findings.
  • Corrective actions and effectiveness reviews.
  • Occurrence and voluntary reporting.
  • Supplier, subcontractor, and contracted-maintenance control.
  • Capability-list changes.
  • Tool calibration and shelf-life control.
  • Manual revision and staff acknowledgement.
  • Human-factors and recurrent training.

Keep sensitive safety and personnel information partitioned from broad customer access. “One source of truth” does not mean every user can see or change every record.

Software evaluation scorecard

Run live scenarios, not slideware demos:

  • [ ] A planner can prove the manual revision used.
  • [ ] An expired authorization blocks the relevant signature.
  • [ ] A non-routine preserves the finding, approval, work, and inspection chain.
  • [ ] A serialized part connects to its release and installation record.
  • [ ] A customer package exports with a reconciled manifest.
  • [ ] A signed task changed after release is visibly controlled.
  • [ ] An auditor can retrieve a two-year-old record promptly.
  • [ ] A site outage follows a tested continuity process.
  • [ ] Access termination removes privileges without erasing history.
  • [ ] Migration preserves versions, signatures, links, and audit trails.

Score configuration effort, offline operation, API access, export, portability, backup, recovery, cyber controls, and vendor exit alongside features.

Implementation and validation workflow

  1. Inventory approvals, manuals, forms, interfaces, and record classes.
  2. Convert requirements into traceable system controls.
  3. Clean identity, authorization, publication, customer, and asset master data.
  4. Configure one representative workstream.
  5. Test normal, exception, outage, and audit scenarios.
  6. Obtain required internal and authority acceptance.
  7. Train by role and verify proficiency.
  8. Run parallel controls for a defined period.
  9. Reconcile migrated records and customer exports.
  10. Monitor control performance after launch.

Acceptance testing should include maintenance, quality, records, IT security, and actual certifying personnel. A technically successful import can still fail if reviewers cannot retrieve the source evidence during an audit.

Sources and further reading

Common questions

Frequently asked questions

What is Part 145 document management software?

It is a controlled system for the manuals, maintenance data, work records, release documents, personnel authorizations, quality evidence, and customer handover records used by an approved maintenance organization or repair station. The configured process must match the applicable authority approval and the organization's approved manuals.

Are FAA Part 145 and EASA Part-145 record requirements the same?

No. They are different regulatory systems with different language and detailed obligations. A dual-approved organization must map each requirement, approval, manual procedure, and customer obligation rather than applying one generic Part 145 template.

Can Part 145 maintenance records be electronic?

Electronic systems can be acceptable when the applicable requirements and the organization's procedures support their use, including any required authority acceptance. Controls commonly address identity, signatures, authorized changes, confidentiality, integrity, backup, availability, legibility, retention, and production of readable copies.

How long must a Part 145 organization retain maintenance records?

The answer depends on the approval. Current 14 CFR 145.219 requires an FAA-certificated repair station to retain required records for at least two years from approval for return to service. Current EASA 145.A.55 specifies three years for detailed maintenance records and certificates of release to service, with different periods for certain other record classes. Contracts or operator rules may require longer.

Does buying compliant software make an MRO compliant?

No. Compliance depends on the organization's approval, manuals, procedures, trained personnel, data, configuration, operation, monitoring, and authority acceptance. Software supports the process; it does not replace accountable decisions or certification privileges.

Deliver a cleaner record with every event

Connect the work package to the aircraft history.

Radar organizes work orders, task cards, parts evidence, approvals, and return-to-service records into a source-linked customer deliverable.

Talk to our teamSee how Radar works