{
 "slug": "release-certificate-receipt",
 "topic_id": "TOPIC-137",
 "cluster": "Aviation, MRO & Aerospace Airworthiness Identity",
 "tier": "Tier A",
 "title": "625 stolen engine parts and a paper tag: binding release certificates to a named human",
 "summary": "A part's airworthiness rests on a release certificate that is, physically, a document with a signature block. Verification means telephoning the issuer. EASA warned in March 2026 that hundreds of stolen engine parts were likely heading for the open market.",
 "lede": "Every part on a commercial aircraft carries a piece of paper asserting it is what it claims to be. The paper is an FAA Form 8130-3 or an EASA Form 1. Verifying it means calling the organisation that issued it and trusting whoever answers.",
 "date": "2026-01-09",
 "category": "Vertical",
 "author_id": "nadia-ferreira-strand",
 "tags": [
  "8130-3",
  "EASA Form 1",
  "suspect unapproved parts",
  "parts traceability",
  "MRO",
  "supply chain"
 ],
 "image": "https://cdn.twc.sh/images/igcache/Release%20Certificate%20Receipt/1500_900/blog.jpg",
 "schema": "Article",
 "key_takeaways": [
  "Release certificates were designed for slow, high-trust bilateral supply chains. Independent distribution and grey-market sourcing broke that assumption while the document format stayed the same.",
  "EASA's March 2026 warning about stolen engine parts and the FAA's standing unapproved-parts notifications describe the same failure: provenance that cannot be checked at the point of receipt.",
  "A release certificate receipt binds part, serial, work scope, approval basis and the named authorised signatory — verifiable offline, decades later."
 ],
 "body": [
  {
   "type": "h2",
   "text": "Prerequisites for this procedure"
  },
  {
   "type": "diagram",
   "kind": "chain",
   "alt": "A part, a tag and a phone call",
   "caption": "The certificate is the control. Verifying it is a phone call nobody has time to make on every part.",
   "nodes": [
    {
     "label": "Part received",
     "sub": "with paper tag",
     "note": "looks correct"
    },
    {
     "label": "Certificate reviewed",
     "sub": "visually",
     "note": "forgeable",
     "bad": true
    },
    {
     "label": "Verification = phone the issuer",
     "sub": "rarely done",
     "note": "per part",
     "bad": true
    },
    {
     "label": "Installed",
     "sub": "airworthiness assumed",
     "note": "",
     "bad": true
    }
   ]
  },
  {
   "type": "p",
   "html": "Before you can improve parts provenance you need three things in hand. Teams that skip this step build a verification scheme for a problem they have not sized."
  },
  {
   "type": "ul",
   "items": [
    "Twelve months of receiving records: part numbers, serial numbers, source, and whether the source was franchised distribution, an independent distributor or a broker.",
    "Your current incoming inspection procedure, specifically what is done with the release certificate.",
    "A count of how many release certificates were verified with the issuer in the last year, by any means."
   ]
  },
  {
   "type": "p",
   "html": "That third number is almost always close to zero outside of high-value rotables, and it is the number that frames everything else."
  },
  {
   "type": "h2",
   "text": "Step 1 — Understand what the certificate is and is not"
  },
  {
   "type": "p",
   "html": "An FAA Form 8130-3 is an airworthiness approval tag. An EASA Form 1 is its European counterpart. Both identify the part, describe the work performed or the conformity being certified, cite the approval basis, and carry the signature and authorisation number of an individual authorised by the issuing organisation."
  },
  {
   "type": "p",
   "html": "The signature block is the load-bearing element. It attests that a specific authorised person, at an approved organisation, certified this part. Everything downstream relies on it."
  },
  {
   "type": "p",
   "html": "It is also ink or a scanned image, on a document that is routinely emailed as a PDF."
  },
  {
   "type": "h2",
   "text": "Step 2 — Locate where verification actually fails"
  },
  {
   "type": "table",
   "caption": "Verification effort versus exposure at each point in the chain.",
   "head": [
    "Point",
    "What is checked",
    "What is not checked"
   ],
   "rows": [
    [
     "Franchised distributor to airline",
     "Purchase order, approved source list",
     "Signatory authority; the certificate is taken as given"
    ],
    [
     "Independent distributor",
     "Approved vendor status, visual tag inspection",
     "Whether the tag corresponds to a real release"
    ],
    [
     "Broker or surplus market",
     "Visual inspection, sometimes a phone call",
     "Signatory authority at the originating organisation"
    ],
    [
     "Teardown and parted-out material",
     "Trace documentation",
     "Whether the trace documents were produced by whom they claim"
    ]
   ]
  },
  {
   "type": "p",
   "html": "The pattern is that verification effort falls as you move toward the sources where the risk is highest, because those are also the sources where verification is hardest."
  },
  {
   "type": "h2",
   "text": "Step 3 — Read the 2026 signals"
  },
  {
   "type": "p",
   "html": "In March 2026 EASA issued safety information concerning several hundred stolen engine parts considered likely to reach the open market. The FAA maintains a continuing programme of unapproved parts notifications. Separately, the industry has already experienced a major falsified-records episode affecting titanium material supplied into both major airframers' supply chains."
  },
  {
   "type": "p",
   "html": "None of these are exotic. They are the predictable output of a provenance system whose verification step is a telephone call."
  },
  {
   "type": "h2",
   "text": "Step 4 — Specify the receipt"
  },
  {
   "type": "p",
   "html": "The design goal is that any downstream holder can verify the release without contacting anyone, for as long as the part is in service — which for an engine component may be thirty years."
  },
  {
   "type": "code",
   "text": "{\n  \"type\": \"manav-stmt/1\",\n  \"action\": \"airworthiness_release\",\n  \"render\": [\n    \"Part number: [pn]   Serial: [sn]   Qty: [n]\",\n    \"Description: [nomenclature]\",\n    \"Work performed: [overhaul | repair | inspection | new]\",\n    \"Approval basis: [regulation, approval number]\",\n    \"Organisation: [name, approval reference]\",\n    \"Authorised signatory: [name, authorisation number]\"\n  ]\n}"
  },
  {
   "type": "p",
   "html": "The receipt does not replace the 8130-3 or the Form 1. Those remain the regulatory documents. The receipt accompanies them and makes the signature block verifiable."
  },
  {
   "type": "h2",
   "text": "Step 5 — Handle the long horizon"
  },
  {
   "type": "p",
   "html": "This is the step most schemes get wrong. A part in service in 2056 needs its 2026 release to still verify. That requires the issuer's public keys to be published with validity periods and retained historically, so a verifier checks the signature against the key that was valid at issuance rather than the key that is current."
  },
  {
   "type": "p",
   "html": "It also requires the verification tooling to be open source, because a proprietary verifier is a dependency on a company that may not exist. Apache-2.0 licensing is not an ideological preference here; it is a records-retention requirement."
  },
  {
   "type": "h2",
   "text": "Step 6 — Deal with bilateral acceptance"
  },
  {
   "type": "p",
   "html": "Release documents are exchanged under bilateral aviation safety agreements and their maintenance implementation procedures. Those instruments recognise specific document forms, and a cryptographic receipt is not among them."
  },
  {
   "type": "p",
   "html": "Design accordingly: the receipt is additive. It changes what a receiving organisation can verify for its own purposes. It does not alter what is regulatorily acceptable, and any implementation claiming otherwise should be treated with suspicion."
  },
  {
   "type": "h2",
   "text": "Failure trap"
  },
  {
   "type": "p",
   "html": "The obvious mistake is to verify the organisation rather than the signatory. An organisational signature proves the certificate came from a company; it does not prove that the individual whose authorisation number appears on it held that authorisation on that date. Authorisation lists change constantly and are published nowhere. Bind the individual, or you have built a slower version of the current problem."
  },
  {
   "type": "h2",
   "text": "Why the certificate is the whole control"
  },
  {
   "type": "table",
   "caption": "What the receiving organisation can actually check",
   "head": [
    "Check",
    "Strength"
   ],
   "rows": [
    [
     "Document appearance",
     "Weak — templates are replicable"
    ],
    [
     "Certificate number format",
     "Weak — formats are published"
    ],
    [
     "Cross-reference to a purchase order",
     "Moderate — confirms the transaction, not the part"
    ],
    [
     "Telephone the issuing organisation",
     "Strong, and not done per part"
    ],
    [
     "<strong style=\"font-weight:600\">Verify a signature against a published key</strong>",
     "<strong style=\"font-weight:600\">Strong, and takes milliseconds</strong>"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Our suppliers are approved, so the risk is low.”</strong> Stolen parts enter through approved channels with correct paperwork; that is what makes them saleable. Approval of the supplier is not verification of the part."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“The industry would need to adopt this together.”</strong> An issuing organisation can start signing unilaterally. Receiving organisations who can verify do so; those who cannot still receive a normal certificate."
  }
 ],
 "faq": [
  {
   "q": "Does a receipt prevent a counterfeit part?",
   "a": "No. A legitimate organisation can certify counterfeit stock, and the receipt would verify correctly. It prevents forged certificates and unauthorised signatories, which is a large share of the documented cases but not all of them."
  },
  {
   "q": "Would this replace the 8130-3?",
   "a": "No. The regulatory document is unchanged. The receipt accompanies it and makes the signature independently checkable."
  },
  {
   "q": "How do small repair stations participate?",
   "a": "Issuance requires a published key and a signing gesture by the authorised signatory. There is no platform to buy and no integration with the customer's systems."
  },
  {
   "q": "What about parts already in service with paper-only trace?",
   "a": "They stay as they are. This changes provenance for parts released from the point of adoption forward; retroactive coverage is not achievable and should not be claimed."
  },
  {
   "q": "Why is telephoning the issuer not a practical control?",
   "a": "It does not scale to every part on every receipt, so it is reserved for suspicion — and a good forgery does not raise suspicion."
  },
  {
   "q": "Can an issuer adopt this alone?",
   "a": "Yes. Signing is unilateral. Receivers who can verify do; others see an unchanged paper certificate."
  },
  {
   "q": "What should the signature cover?",
   "a": "Part number, serial number, work performed and the named certifying individual — not just the certificate number."
  }
 ],
 "sources": [
  {
   "t": "EASA — document library and safety publications",
   "u": "https://www.easa.europa.eu/en/document-library"
  },
  {
   "t": "Federal Aviation Administration regulations and policies",
   "u": "https://www.faa.gov/regulations_policies"
  },
  {
   "t": "Reported cases of falsified parts documentation in commercial aviation supply chains."
  },
  {
   "t": "FAA — aircraft repair and bilateral agreement resources",
   "u": "https://www.faa.gov/aircraft/repair"
  }
 ],
 "related": [
  {
   "slug": "rts-signature-uniqueness-test",
   "title": "Unique to one individual",
   "category": "Vertical"
  },
  {
   "slug": "signatory-authority-attestation",
   "title": "Third-country repair stations",
   "category": "Vertical"
  },
  {
   "slug": "conformance-receipt",
   "title": "Counterfeit parts and supplier identity",
   "category": "Compliance"
  },
  {
   "slug": "mission-authorization-receipt",
   "title": "BVLOS drone operations: who authorized the flight?",
   "category": "Vertical"
  }
 ],
 "wordcount": 1103,
 "url": "/blog/release-certificate-receipt.html",
 "reading_time": "5 min read",
 "image_title": "Release Certificate Receipt",
 "seo_title": "Binding aviation release certificates to a human",
 "meta_description": "A part's airworthiness rests on a release certificate that is, physically, a document with a signature block.",
 "hub": {
  "slug": "topics/airworthiness-identity",
  "title": "Aviation and airworthiness identity"
 },
 "answer": "A release certificate, which is physically a document with a signature block. Verification means telephoning the issuer. EASA warned in March 2026 that hundreds of stolen engine parts were likely heading for the open market, each of which will arrive with a certificate that looks correct.",
 "answer_q": "What proves an aircraft part is airworthy?",
 "glossary": [
  {
   "term": "Release certificate",
   "def": "The document attesting that a part has been maintained and released to service by an approved organisation."
  },
  {
   "term": "Certifying individual",
   "def": "The named person whose authorisation the release rests on, as distinct from the organisation."
  },
  {
   "term": "Unapproved part",
   "def": "A part that does not meet the requirements for installation, including one with falsified documentation."
  }
 ],
 "checklist": {
  "title": "Making a release certificate verifiable",
  "id": "verifiable",
  "desc": "Four steps an issuing organisation can take alone.",
  "steps": [
   {
    "name": "Publish a key at a stable, well-known location.",
    "text": "And retain old keys for the life of the parts."
   },
   {
    "name": "Sign the certificate contents.",
    "text": "Part number, serial, work performed, the named certifying individual."
   },
   {
    "name": "Travel the signature with the part.",
    "text": "As a companion file or an embedded attachment; the paper stays unchanged."
   },
   {
    "name": "Verify on receipt.",
    "text": "A check that takes milliseconds and requires no phone call."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav binds an airworthiness or operational signature to the exact record it certifies, on a credential under one individual's sole control, and produces a receipt an auditor or a regulator can verify years later without access to the operator's systems.",
  "href": "../docs.html",
  "label": "See signature binding"
 }
}