IATA IOSACritical InfrastructureGlobalAviation

IATA Operational Safety Audit (ISM v16)

International standard for airline operational safety management. Required for IATA membership and accepted by aviation authorities worldwide.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

IATA IOSAORG 3.1.1Least privilege and privileged useAttribution to an individual

Safety Data Protection

Operators MUST implement measures to protect safety databases from unauthorized access or modification.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

IATA IOSAFLT 3.11.1A record of access

Flight Data Monitoring

REQUIRES audit trails for flight manifest, weight/balance, and operational databases.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

IATA IOSAMNT 1.10.3A record of access

Maintenance Records

Maintenance databases MUST have complete audit trails to reconstruct any safety-data change.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

IATA IOSASEC 3.1.1A record of access

Security Management

Security-related data MUST be protected with access logging and monitoring.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

What IATA IOSA covers

This instrument defines no data category of its own. An operational safety AUDIT programme. Its scope is the operator’s processes against the ISM standards, not a class of data.

How IATA IOSA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by IATA, through the audit programme and the conditions of membership.

A scheme rule or contract, not law. Enforced by the counterparty.

IOSA is an industry audit programme, not a regulation. Registration is a condition of IATA membership and is written into a great many codeshare and interline agreements, so losing it removes commercial relationships rather than triggering a penalty.

Several national authorities reference IOSA in their own oversight, which converts a private scheme into a regulatory expectation in those jurisdictions.

Uncapped exposure that sits outside this instrument

These come from company law rather than from IATA IOSA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for IATA IOSA,
not configured for it afterwards

Policy Template

Aviation Safety Data Monitoring

Track access to flight, maintenance, and safety databases

Report

IOSA Audit Evidence

Safety data reconstruction capability for IOSA audits

Classification

Aviation Data Patterns

Identify flight manifests, MEL, and airworthiness data

Alert

Safety Data Modification

Alert on changes to safety-critical aviation data

Walk into the IATA IOSA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment