Manav.id
Vertical · 5 min read

625 stolen engine parts and a paper tag: binding release certificates to a named human

625 stolen engine parts and a paper tag: binding release certificates to a named human

Every part on a commercial aircraft carries a piece of paper asserting it is what it claims to be. The paper is an FAA Form 8130-3 or an EASA Form 1. Verifying it means calling the organisation that issued it and trusting whoever answers.

What proves an aircraft part is airworthy?

A release certificate, which is physically a document with a signature block. Verification means telephoning the issuer. EASA warned in March 2026 that hundreds of stolen engine parts were likely heading for the open market, each of which will arrive with a certificate that looks correct.

Key takeaways
  • Release certificates were designed for slow, high-trust bilateral supply chains. Independent distribution and grey-market sourcing broke that assumption while the document format stayed the same.
  • EASA's March 2026 warning about stolen engine parts and the FAA's standing unapproved-parts notifications describe the same failure: provenance that cannot be checked at the point of receipt.
  • A release certificate receipt binds part, serial, work scope, approval basis and the named authorised signatory — verifiable offline, decades later.

Prerequisites for this procedure

Part receivedwith paper taglooks correctCertificate reviewedvisuallyforgeableVerification = phone the issuerrarely doneper partInstalledairworthiness assumed
The certificate is the control. Verifying it is a phone call nobody has time to make on every part.

Before you can improve parts provenance you need three things in hand. Teams that skip this step build a verification scheme for a problem they have not sized.

That third number is almost always close to zero outside of high-value rotables, and it is the number that frames everything else.

Step 1 — Understand what the certificate is and is not

An FAA Form 8130-3 is an airworthiness approval tag. An EASA Form 1 is its European counterpart. Both identify the part, describe the work performed or the conformity being certified, cite the approval basis, and carry the signature and authorisation number of an individual authorised by the issuing organisation.

The signature block is the load-bearing element. It attests that a specific authorised person, at an approved organisation, certified this part. Everything downstream relies on it.

It is also ink or a scanned image, on a document that is routinely emailed as a PDF.

Step 2 — Locate where verification actually fails

Verification effort versus exposure at each point in the chain.
PointWhat is checkedWhat is not checked
Franchised distributor to airlinePurchase order, approved source listSignatory authority; the certificate is taken as given
Independent distributorApproved vendor status, visual tag inspectionWhether the tag corresponds to a real release
Broker or surplus marketVisual inspection, sometimes a phone callSignatory authority at the originating organisation
Teardown and parted-out materialTrace documentationWhether the trace documents were produced by whom they claim

The pattern is that verification effort falls as you move toward the sources where the risk is highest, because those are also the sources where verification is hardest.

Step 3 — Read the 2026 signals

In March 2026 EASA issued safety information concerning several hundred stolen engine parts considered likely to reach the open market. The FAA maintains a continuing programme of unapproved parts notifications. Separately, the industry has already experienced a major falsified-records episode affecting titanium material supplied into both major airframers' supply chains.

None of these are exotic. They are the predictable output of a provenance system whose verification step is a telephone call.

Step 4 — Specify the receipt

The design goal is that any downstream holder can verify the release without contacting anyone, for as long as the part is in service — which for an engine component may be thirty years.

{
  "type": "manav-stmt/1",
  "action": "airworthiness_release",
  "render": [
    "Part number: [pn]   Serial: [sn]   Qty: [n]",
    "Description: [nomenclature]",
    "Work performed: [overhaul | repair | inspection | new]",
    "Approval basis: [regulation, approval number]",
    "Organisation: [name, approval reference]",
    "Authorised signatory: [name, authorisation number]"
  ]
}

The receipt does not replace the 8130-3 or the Form 1. Those remain the regulatory documents. The receipt accompanies them and makes the signature block verifiable.

Step 5 — Handle the long horizon

This is the step most schemes get wrong. A part in service in 2056 needs its 2026 release to still verify. That requires the issuer's public keys to be published with validity periods and retained historically, so a verifier checks the signature against the key that was valid at issuance rather than the key that is current.

It also requires the verification tooling to be open source, because a proprietary verifier is a dependency on a company that may not exist. Apache-2.0 licensing is not an ideological preference here; it is a records-retention requirement.

Step 6 — Deal with bilateral acceptance

Release documents are exchanged under bilateral aviation safety agreements and their maintenance implementation procedures. Those instruments recognise specific document forms, and a cryptographic receipt is not among them.

Design accordingly: the receipt is additive. It changes what a receiving organisation can verify for its own purposes. It does not alter what is regulatorily acceptable, and any implementation claiming otherwise should be treated with suspicion.

Failure trap

The obvious mistake is to verify the organisation rather than the signatory. An organisational signature proves the certificate came from a company; it does not prove that the individual whose authorisation number appears on it held that authorisation on that date. Authorisation lists change constantly and are published nowhere. Bind the individual, or you have built a slower version of the current problem.

Why the certificate is the whole control

What the receiving organisation can actually check
CheckStrength
Document appearanceWeak — templates are replicable
Certificate number formatWeak — formats are published
Cross-reference to a purchase orderModerate — confirms the transaction, not the part
Telephone the issuing organisationStrong, and not done per part
Verify a signature against a published keyStrong, and takes milliseconds

Objections and honest limits

“Our suppliers are approved, so the risk is low.” Stolen parts enter through approved channels with correct paperwork; that is what makes them saleable. Approval of the supplier is not verification of the part.

“The industry would need to adopt this together.” An issuing organisation can start signing unilaterally. Receiving organisations who can verify do so; those who cannot still receive a normal certificate.

Making a release certificate verifiable

  1. Publish a key at a stable, well-known location. And retain old keys for the life of the parts.
  2. Sign the certificate contents. Part number, serial, work performed, the named certifying individual.
  3. Travel the signature with the part. As a companion file or an embedded attachment; the paper stays unchanged.
  4. Verify on receipt. A check that takes milliseconds and requires no phone call.

Terms used here

Release certificate
The document attesting that a part has been maintained and released to service by an approved organisation.
Certifying individual
The named person whose authorisation the release rests on, as distinct from the organisation.
Unapproved part
A part that does not meet the requirements for installation, including one with falsified documentation.

Frequently asked questions

Does a receipt prevent a counterfeit part? No. A legitimate organisation can certify counterfeit stock, and the receipt would verify correctly. It prevents forged certificates and unauthorised signatories, which is a large share of the documented cases but not all of them.

Would this replace the 8130-3? No. The regulatory document is unchanged. The receipt accompanies it and makes the signature independently checkable.

How do small repair stations participate? Issuance requires a published key and a signing gesture by the authorised signatory. There is no platform to buy and no integration with the customer's systems.

What about parts already in service with paper-only trace? They stay as they are. This changes provenance for parts released from the point of adoption forward; retroactive coverage is not achievable and should not be claimed.

Why is telephoning the issuer not a practical control? It does not scale to every part on every receipt, so it is reserved for suspicion — and a good forgery does not raise suspicion.

Can an issuer adopt this alone? Yes. Signing is unilateral. Receivers who can verify do; others see an unchanged paper certificate.

What should the signature cover? Part number, serial number, work performed and the named certifying individual — not just the certificate number.

Where this fits in Manav

Manav binds an airworthiness or operational signature to the exact record it certifies, on a credential under one individual's sole control, and produces a receipt an auditor or a regulator can verify years later without access to the operator's systems.

See signature binding →

Sources and further reading