An operator does not run on one manual. It runs on a stack of them, each one governing a different layer of the operation, each one revised on its own schedule, and each one subject to the same rule: only the current version may be in use. This is what that stack looks like, what a "controlled" document actually means in practice, and what an auditor is checking when they ask you to prove it.
The Operations Manual is not one document
The Operations Manual (OM) is usually issued as four parts, each with its own audience and its own revision cycle. The regulator approves the manual, and approves every revision to it.
- OM-A: General/Basic. Policy and procedure that applies across the whole operation regardless of aircraft type: safety policy, organisational structure, operational control, crew responsibilities.
- OM-B: Aircraft Operating Matters. Type-specific procedures: normal, abnormal and emergency checklists, performance data, limitations for the aircraft actually being flown.
- OM-C: Route and Aerodrome Instructions. What applies to a specific route or a specific airport: approach restrictions, minimums, local notes.
- OM-D: Training. The training programme that puts A, B and C into practice for flight crew, cabin crew and other operational staff.
Documentation Controllers deal with this stack differently to how a Quality Manager does. Each part has a different owner inside the airline, a different revision trigger, and a different distribution list. Treating the OM as a single file with one expiry date is the first thing that goes wrong.
What "controlled" means
A controlled document is not just a document that is kept somewhere safe. It is a document with four things attached to it, at all times:
- A version. A number that increases every time the content changes, no exceptions.
- An owner. The person or role responsible for the content being correct.
- An expiry date, where one applies. Some documents run indefinitely under revision control; others (certificates, approvals) have a hard expiry.
- A change log. A record of what changed, when, and who approved it.
Miss any one of the four and the document stops being controlled, even if the content itself is correct. This is the distinction an auditor is trained to look for: not "is the information right", but "can you show me the version is current, and can you show me why".
Revision control is a chain, not a folder
The word "control" carries the weight here. A shared drive full of PDFs, each one a slightly newer save than the last, is not revision control. It is a folder that happens to contain revisions. Real revision control means: only one version is ever marked current, every prior version stays retrievable, and every step from one version to the next has an owner and a reason attached to it. Rule one, in plain terms: only the current version may be in use. Everything else in a document control system exists to make that one rule enforceable.
Why the trail has to be tamper-evident, not just present
When an auditor asks to see the record, having a record is the minimum bar. What they are actually testing is whether the record could have been altered after the fact without leaving a trace. A change log that anyone with edit access could rewrite is not evidence. It is a claim. A tamper-evident record is different: every entry is dated, attributed to whoever made it, and chained to the entry before it, so that altering an old entry breaks the chain and becomes visible.
It is worth being precise about what that does and does not promise. Tamper-evident is not tamper-proof. The system does not claim that a record can never be changed. It claims that if a record is changed, the change is visible. That is a smaller promise than "unchangeable", and it is the honest one: it is also the one an experienced auditor is actually checking for, because they know unchangeable is not a real property of any digital record.
What "show me" actually asks for
In practice, an auditor working through document control asks some version of the same four questions, regardless of which manual is on the table:
- Which version is current, and how do I know the person using it has that version and not an older one?
- Who approved the last revision, and when?
- What changed between this version and the one before it?
- If this document expires or needs periodic reapproval, when is that due, and who is tracking it?
None of these are hard questions to answer if the document has been under real control the whole time. They become hard, or unanswerable, when the answer depends on someone's memory of an email thread from eighteen months ago.
Karutek is the official partner in Vietnam for AviSuite's document control systems, which apply this model to the operator's manual set: version, owner, expiry, tamper-evident change log.


