Audit methodology · Last verified

IATA Operational Safety Audit

IOSA is IATA's operational safety audit program: airlines are registered on the IOSA Registry, and IATA membership requires staying registered. The IOSA Standards Manual contains 916 standards, and in 2024 the program moved to a risk-based audit model that focuses on each airline's specific safety risks.

Class
Audit methodology
Owner
International Air Transport Association (IATA)
Last verified

What it is

The IATA Operational Safety Audit (IOSA) Program is, in IATA's own words, "an internationally recognized and accepted evaluation system designed to assess the operational management and control systems of an airline."

IOSA is a condition of IATA membership: "All IATA members are IOSA registered and must remain registered to maintain their IATA membership."

Terminology note (class honesty): the program's operative status is IOSA Registration, and IATA builds its own language around audit and registry, not certification. That said, the IOSA Program Manual itself is not absolute on this point — it uses the phrase "IOSA certificates" once, in the context of usage rules for the registration document: "These and related usage rules are usually provided alongside IOSA certificates." This page therefore does not claim IATA never issues anything called a certificate; it reports what IATA's own terminology consistently emphasizes (registration, registry, audit) alongside that one documented exception.

IATA describes the current scale of the registry: "Check out the IOSA Registry with over 450 registered airlines on the IATA Connect platform." The June 2026 fact sheet gives a dated figure: "As of May 2026, 449 airlines are listed on the IOSA registry, including 94 that are not IATA members."

In 2024, IOSA moved to a risk-based audit model. IATA's own page: "In 2024, IOSA transitioned into a risk-based model, focusing on safety risks, specific to the auditee, rather than applying a 'one-size-fits-all' approach." The fact sheet dates the start of that evolution earlier: "In 2022, IATA began evolving IOSA to a risk-based model under which audits are tailored to the operator's profile and focus on high-risk areas," and reports that "In 2025, 229 risk-based audits were conducted."

Scope: the fact sheet states IOSA "is the global industry standard for airline operational safety auditing and is also the established standard for codeshare, wet-lease, and charter operations," and that "There are 916 standards in the IOSA Standards Manual (ISM)."

Who owns it

IOSA is owned and run by IATA (International Air Transport Association, Montreal–Geneva).

Who assesses it

The IOSA Program Manual defines who may audit: "IOSA Audits will only be conducted either by Audit Organizations (AOs) that have been accredited by IATA, or by IATA."

Who asks for it

IATA membership itself requires IOSA registration (see above). Beyond membership, the June 2026 fact sheet names specific regulators that use IOSA in their own oversight processes — described as use, not a mandate: "Among others, the following aviation regulatory authorities use IOSA in their safety oversight programs: – The FAA for the approval process of non-US codeshare operators. – EASA (spanning 27 EU Member States) for their Third Country Operator (TCO) authorization process. IOSA is an acceptable means of compliance for EU third country operator codeshares … – Civil Aviation Administration of China (CAAC) embedded IOSA in the Advisory Circular for codeshare safety audits of non-Chinese codeshare operators." No state's own legal text requiring IOSA registration was opened and confirmed in the sources reviewed as of 31 August 2026 — a country-specific "IOSA is required in country X" claim is not published until that state's own instrument is verified.

Validity

24 months. IPM 7.3.1: "The IOSA registration period shall be twenty four (24) months and, if not successfully renewed, expire at 23:59 local time on the expiry date at the location of the Operator as specified on the AOC." IPM 7.5.2 adds that a renewed registration "shall expire exactly twenty-four (24) consecutive months following the current expiry date."

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"IATA Operational Safety Audit." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/iata-iosa

All frameworks & audits →