STANREC 4739
STANREC 4739 risk management recommendation (ARAMP-1)
NATO nations and NATO bodies deciding whether to apply ARAMP-1's risk management practice on a systems life cycle programme
STANREC 4739 is NATO's non-binding recommendation that nations use ARAMP-1's risk management practice within systems life cycle management; adoption is voluntary, not required.
- Edition
- 1
- Published
- 2013-04-11
What it is
STANREC 4739 is a NATO Standardization Recommendation, Edition 1, on risk management. A STANREC is built the same way a STANAG is, with one difference that matters: a STANAG is an agreement nations ratify, a STANREC is a recommendation they are free to take up. The document says so directly - it "is a non-binding document employed on a voluntary basis and does not require commitment of the Nations to implement the standards which are listed in it."
What it recommends
STANREC 4739 carries no risk management requirements of its own. Its aim, in its own words, is "to list recommended practices regarding: implementation of risk management within the NATO systems life cycle management framework." The one thing it recommends is a single document: "ARAMP-1 Edition 1, 14 February 2012." Everything else in the STANREC is context around that recommendation, not additional substance. It also names ARAMP-1 training slides, held on the AC/327 website, and two further NATO publications, AAP-48 and AAP-20, as related reading.
Who is behind it, and how it is kept current
The tasking authority is the CNAD Life Cycle Management Group (AC/327); the custodian named in the document is Belgium. The STANREC "is to be reviewed at least once every three years," with the result "recorded within the NSDD," and "Nations and NATO Bodies may propose changes, through a standardization proposal at any time to the tasking authority (TA)." This is the first edition - SUPERSEDED DOCUMENTS reads "nil" - and the letter of promulgation dates it to 11 April 2013 (NSA/0496(2013)STR-CDS/4739), the same year the ARAMP-1 edition it points to (14 February 2012) had already been published.
Where it has force, and where it does not
STANREC 4739 addresses "the Nations" (NATO member states) and NATO bodies, not a supplier or manufacturer directly. It binds nobody by itself: whatever obligation an organisation meets comes from a nation's own procedure, a NATO programme office, or a contract that separately invokes ARAMP-1 - not from this document existing. It is a NATO non classified document, free of charge, and the reproduction restriction that applies to third parties is explicitly lifted for "member nations and Partnership for Peace countries, or NATO commands and bodies."
How it is checked
STANREC 4739 names no certification body, no government quality assurance arrangement, no notified body, and no self-declaration scheme. The only assessment it describes is aimed at the document itself - the periodic review above - not at an organisation, a product, or a risk management practice. Whatever review a supplier's risk management actually gets is set by whichever nation, customer or contract requires ARAMP-1 on a given programme, and that review sits outside this STANREC entirely.
How we help
STANREC 4739 is a cover document. The risk management practice it points to lives in ARAMP-1, and the work of running it happens in a programme's own risk register, mitigation tracking and life cycle reviews - not inside a compliance tool. What ComplyTrain supports is the documentation trail that any risk management practice needs, whichever method a programme is required to follow: the procedure describing how risk is identified, assessed and reviewed; the training record showing the people running it were briefed (including, where a nation uses them, the ARAMP-1 training slides this STANREC points to); and the audit trail of when reviews happened and what changed as a result.
ComplyTrain does not perform risk assessments, does not implement ARAMP-1's specific method, and does not decide whether a programme has managed its risk adequately. The applicable requirement on any given contract is set by the customer's quality clause, not by us - explore the related standards this STANREC sits alongside, or talk to us about the documentation a risk management practice needs to hold up under review.
Questions
Is STANREC 4739 mandatory?
No. It is a recommendation, not an agreement nations ratify. The document states that it "is a non-binding document employed on a voluntary basis and does not require commitment of the Nations to implement the standards which are listed in it." Any obligation a supplier meets comes from a contract or a nation's own procedure that separately requires ARAMP-1, not from the STANREC itself.
What is the difference between a STANREC and a STANAG?
A STANAG is an agreement NATO nations ratify, with reservations possible on implementation. A STANREC recommends a practice without asking for that commitment. STANREC 4739 recommends ARAMP-1; it does not ratify it.
What does STANREC 4739 actually recommend?
One document: "ARAMP-1 Edition 1, 14 February 2012," for risk management practice within NATO's systems life cycle management framework. It also points to ARAMP-1 training slides and two related publications, AAP-48 and AAP-20, as further reading.
Is there a certification for STANREC 4739 or ARAMP-1?
No certification, government surveillance, or notified-body scheme is named in the document. The only review it describes is of the STANREC's own currency, at least once every three years, not an assessment of an organisation or a product.
Does STANREC 4739 cost anything to obtain?
No. NATO standardization documents are free of charge; STANREC 4739 is not sold by NATO or by us.
