Quick answer
See the highlighted block above. The model builds directly on the rest of this cluster: it is the staged path from safety management to safety intelligence, with each level defined by how much of the operation the safety function can actually see.
Why a maturity model
A maturity model is useful for one reason: it replaces a vague feeling, “we should be doing more with our safety data”, with a located position and a specific next step. It is not a ranking to brag about or a certification to chase. Used well, it is a mirror.
Two principles keep it honest. First, the levels describe posture, not tools. A level is about what the safety function can see and act on, not which software is installed; it is entirely possible to own advanced technology and operate at a low level because the data never comes together. Second, maturity is bounded by the weakest core link. An operation is only as mature as its ability to read across itself, because emerging risk lives in the connections, a point established in why mature SMS programs miss emerging risk. A brilliant capability in one corner does not raise the level if the corners cannot talk.
The five levels
Each level is described by its dominant posture, what becomes true at that level, and what is still missing. The verbs map onto the positioning that separates safety management from safety intelligence.
Level 1, Reactive. The system records. Safety activity is triggered by events. Reports are captured and filed, often in separate registers that do not reference each other. Measurement is almost entirely lagging, counts of what already went wrong. Compliance is the organising goal. The operation learns only from things that have already hurt it. Missing: any forward view at all.
Level 2, Managed. The system tracks. A structured SMS is in place and disciplined. Occurrences are classified consistently; corrective actions are tracked to closure with effectiveness verification; audits run on schedule; conformance is strong. This is a genuinely good safety program by conventional measures, and it still processes events one at a time. Missing: the cross-operation view; the picture is module-deep, not operation-wide.
Level 3, Connected. The system connects. The silos start to dissolve. An occurrence updates the hazard it relates to; the hazard recalculates the barriers it depends on; a finding, a training gap and an event touching the same barrier become visible together. A consistent taxonomy lets records be read as one. This is the threshold of safety intelligence, the first level at which the operation can be read as a whole. Missing: systematic interpretation of what the connected picture is forming.
Level 4, Predictive. The system interprets and detects. On top of connection sits interpretation. The operation is actively read for what is forming: weak signals are aggregated against the structures they touch; operational drift is checked deliberately; a balanced set of leading indicatorswatches trends toward thresholds, not only breaches. The safety review board's question becomes “what is forming, and what are we doing about it?” Missing: continuity, interpretation still happens in cycles rather than constantly.
Level 5, Anticipatory. The system anticipates. Sensing is continuous and operation-wide. The risk picture updates in near real-time as the operation moves; emerging risk is surfaced early enough to act while intervention is cheap; the safety function informs operational decisions before events rather than explaining them after. The capability is also, almost incidentally, exactly what risk-based oversight asks an operator to demonstrate. Missing: nothing structural, the work at this level is sustaining and refining, not building.
Locating yourself honestly
The temptation with any maturity model is to locate yourself by your best example. Resist it. The useful position is set by the weakest core capability, because that is where emerging risk will exploit the gap. A few honest diagnostic questions:
- The two-click trace. Pick a real recent occurrence. Can you walk from it to the hazard, the barriers, the related findings and the indicators it should have moved, quickly, without exporting four systems into a spreadsheet? If not, you are below Connected.
- The forming question. At your last safety review board, was the conversation mostly about what happened and what you closed, or about what is forming and where? The honest answer places you below or above Predictive.
- The leading balance. Are your indicators dominated by counts of past events, or do you carry credible leading indicators with a real causal story? An all-lagging dashboard caps you at Managed.
- The drift check. Do you look for operational drift on purpose, comparing work-as-done with work-as-imagined, or do you wait for it to produce an event? Only the former reaches Predictive.
Most operators who run this honestly find they are a strong Level 2 with islands of higher capability, which is not a failure. It is the normal, expected starting point, and it names the work precisely: reach Connected across the core, not just in the impressive corner.
Moving up a level
Each transition has a characteristic demand, and knowing which one you face keeps effort from going to the wrong place.
- Reactive to Managed is a discipline problem. It is solved by building the structured SMS: a consistent taxonomy, real action tracking, effectiveness verification, a healthy reporting culture. Most regulated operators have done this or are doing it. The roadmap is well-trodden, see implementing an Annex 19 SMS.
- Managed to Connected is a structural problem, and the hardest jump in the model. It is not solved by trying harder within the existing silos; it requires the modules to actually reason about each other, to share a taxonomy and update one another so the operation can be read as one picture. This is where many programmes stall, because effort alone cannot cross it. The mechanics of linking occurrence, CAPA, SPI and risk profile are covered in connecting occurrence, CAPA, SPI and SRP.
- Connected to Predictiveis an interpretation problem. With the data connected, the work becomes reading it for what is forming: aggregating weak signals, checking for drift, balancing the indicator set, and changing the board's central question.
- Predictive to Anticipatory is a continuity problem. The interpretation that happens in cycles becomes constant and operation-wide, so the risk picture is live rather than periodic.
Two things hold across every transition. The destination is defined in what aviation safety intelligence is, and the practical methods that carry an operation through Levels 3 to 5 are set out in how airlines detect emerging risk before incidents occur. The model tells you where you are; those articles tell you what to do about it.
Frequently asked questions
What is the aviation safety intelligence maturity model?
It is a five-level framework describing an organisation's journey from reactive, record-keeping safety toward anticipatory safety intelligence. The levels are Reactive, Managed, Connected, Predictive and Anticipatory. Each level describes a posture, what the safety function can see and do, rather than a set of features. The model is a tool for honest self-assessment and for deciding what the next improvement should be, not a scorecard to be maximised for its own sake.
What are the five levels?
Level 1 Reactive: safety records events after they happen, in siloed registers, measured mostly by lagging counts. Level 2 Managed: a structured SMS with strong conformance, tracked actions and scheduled audits, still event-by-event. Level 3 Connected: modules are linked, so an occurrence updates the hazard and barrier it touches and cross-module patterns become visible. Level 4 Predictive: the operation is read for what is forming, weak signals, drift and balanced leading indicators. Level 5 Anticipatory: continuous, operation-wide sensing keeps a live risk picture that informs decisions before events occur.
How do I know which level my organisation is at?
Use the honest rule: you are at the lowest level that any of your core safety capabilities sits at, not the highest level you can point to somewhere. An organisation with an advanced flight-data programme but siloed occurrence, audit and training data is Connected at best in the area that matters, regardless of how sophisticated one corner is. The diagnostic is whether you can read across the operation as one picture, not whether any single module is impressive.
Is level 5 the goal for every operator?
Not necessarily, and not all at once. The right target depends on the size, complexity and risk exposure of the operation. For many operators the immediate, high-value goal is reaching Connected, dissolving the silos, because most of the cost of missed emerging risk comes from data that was never brought together. Anticipatory safety is a direction of travel; the practical question is usually "what is the next level up from where we honestly are?" rather than "how do we leap to five?"
What is the hardest transition?
The jump from Managed to Connected, from a well-run but siloed SMS to a genuinely connected operational picture. It is the hardest because it is not an effort or process change but a structural one: the modules have to actually reason about each other, share a taxonomy and update one another. Most organisations can reach Managed with discipline alone; passing into Connected usually requires changing how the data is held, which is why it is where many programmes stall.