If you sign off on airworthiness documentation in 2026, you have one decision to make this year: keep accepting certificates whose integrity you cannot check, or require that every safety-critical document you issue and receive be independently verifiable. The evidence below — a convicted parts forger, a fresh EASA warning, and the aviation aftermarket's incumbents rebuilding their records on verifiable rails — says the waiting option is gone; the ten-question audit and the test case that follow let you act on it this quarter.
The decision on the table
Strip away the technology vocabulary and the choice is simple. Every regulated aviation document — an Authorised Release Certificate, a training certificate, a maintenance sign-off — is today verified in one of three ways: you trust the paper, you call the issuer, or you audit after the fact. All three fail the same way: trusting the paper is what forged-paperwork brokers exploit, calling the issuer does not scale and fails exactly when the issuer is the fraud, and auditing after the fact detects forgery only after aircraft have flown.
The alternative is architectural: make each document's integrity provable by anyone, at the moment of receipt, without permission from whoever issued it. That option existed in theory for a decade. What changed in the last twelve months is that the market started paying for it — and regulators started asking for it. Your decision is no longer *whether* verifiable records become the norm, but whether your organization gets ahead of that norm or is audited against it.
The economics of the two options are asymmetric. Waiting costs nothing this quarter and exposes you to the full blast radius of the next documentation fraud: grounded aircraft, quarantined inventory, customer audits, and a regulator asking why your receiving process accepted documents it could not check. Moving first costs a procurement clause and a verification habit. The clause is one sentence — "safety-critical documents must be verifiable independently of the issuer" — and it is already the direction of the coalition members' pilots and GA Telesis's platform strategy. The habit is cheaper still: a verification step at receiving that takes less time than the visual inspection it complements.
One clarification before the evidence: this decision is not about buying a specific platform, and it is definitely not about cryptocurrency. The aviation use case has converged on a single, boring pattern — hash the document, anchor the hash on an immutable ledger, let anyone recompute and compare — because that pattern is the one compatible with regulated data. What you are deciding is whether your document flows get that property, from whichever vendor or standard provides it.
The evidence: three signals that moved in twelve months
Signal one: certificate forgery is prosecuted — and still active
The reference case is AOG Technics, the broker whose forged release certificates ran undetected for four and a half years across the global fleet: its director was sentenced to four years and eight months in prison in February 2026, and weeks later EASA warned airlines and MROs of a new engine-parts fraud. For the full case study — the scandal, the trial, the regulatory aftermath — see AOG Technics, three years on. What matters for your decision is the pattern: prosecution punishes yesterday's fraud while the next one is already in motion, because the gap it exploited — documents nobody can check — is unchanged.
Signal two: the industry's response is now a standard you can be scored against
The Aviation Supply Chain Integrity Coalition — founded by Airbus, American Airlines, Boeing, Delta Air Lines, GE Aerospace, Safran, StandardAero and United Airlines — has published its recommendations: supplier accreditation to FAA Advisory Circular 00-56B or equivalent, digitized 8130-3 and EASA Form 1 release certificates with digital signatures, receiving-inspector training, scrap control and feedback channels for bad actors. The case-study article above details the coalition's report and its implementation progress; what matters here is that these recommendations are concrete enough to be scored line by line — which is exactly what the ten-question audit below does.
Signal three: the aftermarket's incumbents are rebuilding records on verifiable rails
On January 22, 2026 — updated July 8, 2026 — GA Telesis, a global independent MRO and aviation aftermarket group, published How Blockchain Technology Is Transforming Aircraft Parts Traceability, a structured doctrine covering decentralized ledgers, cryptographic hashing of airworthiness paperwork, vendor accreditation, immutable recordkeeping and regulatory compliance. This is not an isolated essay: GA Telesis announced its WILBUR provenance platform in July 2024 and launched the platform's public website in March 2026. When an intermediary that coordinates manufacturers, lessors, suppliers, airlines and maintenance organizations publishes its architecture openly, it is bidding to set the reference model — and it explicitly frames AOG Technics as the proof that documentation trust is the weak link.
One number needs correcting along the way. GA Telesis cites a PwC estimate that blockchain could cut aviation operational costs by 5–10% — about $3.5 billion in MRO. The primary source, PwC's own 2019 analysis in strategy+business, states the more conservative figure: efficiency gains enabled by blockchain could cut MRO costs by about 5 percent annually, or $3.5 billion, while increasing industry revenue by as much as 4 percent, or $40 billion. Treat the 10% as an optimistic rounding; even the conservative 5% is a structural cost case, not a pilot budget.
The tool: a certificate-integrity audit in ten questions
This is the checklist a quality or MRO director can put on the table on Monday. Score each question yes or no; every "no" is a named, ownable gap. Run it with three people in the room — quality, procurement and receiving — because the honest answers live at the boundaries between them, and budget ninety minutes: the checklist is short precisely so the discussion around it can be honest.
- Independent verifiability. Can every safety-critical document you accept be verified without contacting the party that issued it? If verification requires a phone call to the issuer, the check will be skipped under time pressure — which is precisely when forged documents arrive.
- Detection time. If a forged release certificate entered your system today, how long until someone would detect it? "At the next audit" means months of exposure; the industry's reference parts forgery ran undetected for four and a half years.
- Supplier accreditation. Are your parts suppliers accredited to FAA Advisory Circular 00-56B or an equivalent EASA/international standard — the coalition's first-line recommendation?
- Receiving inspection. Do receiving inspectors have a documented red-flag list for paperwork anomalies, and were they trained on it in the last twelve months? The coalition explicitly recommends training best practices for receiving and inspecting parts.
- Document format. Are the release certificates you issue still editable artifacts (PDF, paper) whose integrity rests on a logo and a signature? A PDF is a picture of a certificate, not a verifiable certificate.
- Digital signatures. Where your authority or OEM partners offer digitally signed 8130-3 or EASA Form 1 documents, do you accept and check the signature — or print and file them, discarding the verifiable layer?
- Scrap and non-usable material. Do you control the documentation path of scrapped parts, so that destroyed material's certificates cannot re-enter the supply chain attached to different metal?
- Feedback channel. Do you have a defined route to report a suspected bad actor to accreditors and authorities — and has anyone used it? The coalition found these channels missing or unused across much of the industry.
- Your own issuance. If a customer, lessor or authority wanted to verify a certificate *you* issued, could they do it in under a minute without emailing your quality department? Your exposure runs both directions.
- Ownership. Is certificate-integrity risk assigned to a named owner at management level, with detection time measured? A risk with no owner and no metric is an accepted risk.
Eight or more "yes" answers puts you ahead of most of the industry as it stands in 2026. Five or fewer means a motivated broker with a laptop can put a forged document past your receiving dock.
The test case: a brokered CFM56 purchase, run through the audit
Make it concrete. Your MRO wins a contract that requires 40 used serviceable CFM56 components within six weeks. OEM lead times are quoted in months, so procurement turns to the broker market — exactly the environment where, per the SFO's case, forged-paperwork brokers thrived during the post-2021 parts shortage.
Scenario A — the paper system. The broker sends scanned ARCs. Your receiving inspector compares part numbers and serial numbers against the purchase order, checks the paperwork visually, and shelves the parts. Question 1 fails: verifying a certificate means emailing the alleged issuing shop, which may be invented. Question 2 fails: detection, if it comes, arrives when CFM International or an authority traces serials — after installation. Every question about format and signatures fails because the artifacts are scans of scans. You have accepted the documents on trust, and your only defense was the inspector's eye.
Scenario B — the same purchase, after the audit. Suppliers are filtered on accreditation (question 3). Each ARC must be verifiable at the dock: a digitally signed form whose signature is checked, or a hash-anchored certificate whose hash is recomputed against a public ledger in seconds (questions 1, 5, 6). A certificate that verifies against no issuer and no ledger is quarantined before the part leaves receiving — detection time drops from an audit cycle to ninety seconds. The broker relationship now has a feedback channel behind it (question 8): one flagged document protects every other operator on the channel.
Notice what did not change: the parts are the same, the broker is the same, the inspector is the same. What changed is that the *document* can no longer lie silently. That is the entire thesis of the coalition's digitization track and of GA Telesis's doctrine — and it applies identically to the certificates that qualify people, not just parts.
Run the same test case one level up and it bites your own organization. A lessor's technical representative audits your hangar and asks you to prove the training certificates of the mechanics who signed off the last C-check. In Scenario A you produce PDFs and offer the training organization's phone number; the lessor's representative now knows your certificates are exactly as checkable as the broker's ARCs were — which is to say, not at all without a week of emails. In Scenario B each certificate verifies on the spot. The audit question that used to take a week takes an afternoon, and the difference is visible to the customer, not just to your quality department.
What verifiable records do not solve
Intellectual honesty matters here, because overselling verification is how trust in it dies.
- Garbage in, garbage out. Anchoring a hash proves a document was not altered *after* anchoring. It says nothing about whether the content was true at issuance. An insider at the issuing shop can anchor a false certificate with perfect cryptographic integrity. Anchoring must be combined with issuer identity, accreditation and audit — it raises the cost of forgery from "a laptop" to "compromising an accredited issuer," but it does not make fraud impossible.
- The document is not the part. A perfectly verified ARC does not prove the metal in the box matches the paper. Physical authentication — part marking, surface fingerprinting such as the Alitheon technology GA Telesis paired with WILBUR, and old-fashioned receiving inspection — remains a separate, necessary layer.
- The adoption gap. A verifiable document only protects you if issuers anchor and receivers actually check. Until verification is contractually required — as it already is in the coalition members' pilots — the honest answer to question 1 for most of your inbound paperwork will remain "no."
- Privacy and regulation. Putting document content on a public ledger is a non-starter under GDPR and basic commercial confidentiality. Only hash anchoring — where the chain stores a fingerprint, not the document — is compatible with regulated aviation data, which is why the industry is converging on that pattern rather than on on-chain documents.
The correct mental model: verifiable records close the *silent forgery* channel — the one behind every major parts-documentation scandal. They do not replace supplier accreditation, physical inspection or law enforcement; they make each of those layers checkable.
AeroCert's take
AeroCert's take: read the GA Telesis paper as a procurement signal, not a technology essay. When the aftermarket's incumbents publish their verification architecture openly, the quality director's question stops being "is verifiable integrity real?" and becomes "how long before my customers, lessors and authorities score me against it?" — and the honest answer is months, not years. Our advice is the audit above: run it this quarter, fix independent verifiability first, and write the one-line procurement clause before a customer or a regulator writes it for you.
That is the property we build into the certificates that qualify people, where the same shift arrives next. AeroCert anchors the SHA-256 hash of each issued certificate on Avalanche and makes verification permissionless — a scan recomputes the hash client-side and reads the on-chain registry directly, no account, no AeroCert server in the loop — so question 9 of the audit answers itself for every document you issue. See how AeroCert works, or integrate verification into your own systems with the developer platform.
Frequently asked questions
What should a quality director do about certificate integrity in 2026?
Run a structured audit of how your organization issues, receives and verifies safety-critical documents: can each certificate be verified without contacting the issuer, are suppliers accredited to FAA AC 00-56B or equivalent, and how long would it take to detect a forged document today? Then close the biggest gap first — usually independent verifiability of the documents themselves.
What did GA Telesis publish about blockchain traceability?
GA Telesis published a position paper, 'How Blockchain Technology Is Transforming Aircraft Parts Traceability', on gatelesis.com on January 22, 2026 (updated July 8, 2026). It covers decentralized ledgers, cryptographic hashing of airworthiness paperwork, vendor accreditation, immutable recordkeeping and regulatory compliance, building on its WILBUR provenance platform announced in July 2024.
What is the PwC estimate for blockchain in aviation MRO?
In a 2019 analysis published in strategy+business, PwC estimated that efficiency gains enabled by blockchain could cut global MRO costs by about 5 percent annually, or $3.5 billion, while increasing industry revenue by as much as 4 percent, or $40 billion. Some later industry citations round the MRO figure up to 5-10 percent; the primary PwC source states about 5 percent.
Does blockchain anchoring guarantee a certificate is genuine?
No. A hash anchor on an immutable ledger proves two things only: the anchored document has not been altered since, and when it was recorded. Whether the content was true at issuance is a separate question — an insider at the issuing organization can anchor a false certificate with perfect cryptographic integrity. Pair anchoring with issuer identity checks, accreditation and physical inspection.
How does AeroCert verify an aviation certificate?
AeroCert anchors each certificate's SHA-256 hash on the Avalanche blockchain at issuance. Anyone scanning the certificate's QR code recomputes the hash client-side and reads the on-chain registry directly — anonymously, with no account and no call to any AeroCert server. A hash match proves integrity and issuance time; a mismatch exposes alteration instantly.
Make your certificates independently verifiable
AeroCert anchors SHA-256 certificate hashes on Avalanche and lets anyone verify them instantly by QR code — no account, no backend call, no trust required.