Trim runaway

The ATSB is advising Pilatus PC-12 operators to review their pitch trim system training and checking processes to ensure pilots are adequately prepared to manage a trim runaway emergency.

The advice forms part of an ATSB investigation report into a pitch trim runaway and partial loss of control incident experienced by a Royal Flying Doctor Service (RFDS) Pilatus PC-12 aircraft near Merredin, in Western Australia, in April 2019. 

The investigation describes how shortly after midnight and approximately 90 seconds after departing Merredin, the PC-12/47E, with a pilot, flight nurse, doctor and patient on board, was climbing about 1,400 ft above ground level when the Pitch Trim Runaway warnings activated and the aircraft started to nose over.

The pilot initiated the Pitch Trim Runaway emergency procedure from memory but the investigation found that the pilot inadvertently moved the Flap Interrupt switch instead of selecting the Trim Interrupt switch. Both switches are located in close proximity to each other on the PC-12’s centre console, which the investigation found to be a safety issue.

Consequently, the pitch trim runaway continued uninterrupted with full nose-down reached 16 seconds after the warning message activations, with the aircraft pitch attitude moving from +9.5 degrees nose-up down to -7.5 degrees.

As a result of the abnormal trim setting and aircraft airspeed, the nose-down control forces were excessively high. Despite exerting maximum effort with both hands on the control column, the pilot was unable to fully counteract the nose-down force and there were times when the aircraft developed high rates of descent, descending to a minimum height of 400 ft above ground level.  

The ATSB advises PC-12 operators to review their training and checking processes related to the pitch trim system to ensure that pilots are adequately prepared to manage a trim runaway emergency.

The report describes how the pilot continued with the emergency procedure from memory but was unable to resolve the full out-of-trim condition and serious control difficulties. With the assistance of the doctor who pulled on the other control column, the pilot was able to return to Merredin for a flap-less landing. The aircraft was undamaged and the occupants uninjured.

ATSB Executive Director Transport Safety Director Nat Nagy said the cause of the pitch trim runaway was a malfunctioning relay in the manual stabiliser trim system. (At the time of the incident Pilatus was progressing the development of a replacement relay for the manual and autopilot stabiliser trim systems.)

“The ATSB advises PC-12 operators to review their training and checking processes for the aircraft’s pitch trim system to ensure that pilots are adequately prepared to manage a trim runaway emergency,” Mr Nagy said.

“The similarities between the Trim Interrupt and Flap Interrupt switches and their co-location unnecessarily continues to increase the risk of mis-selection and contributed to the excessive out-of-trim condition in this incident”, he noted.

In this incident, after selecting the wrong switch, the pilot pulled the Pitch Trim Circuit Breaker, in line with the checklist, but only after the trim had reached the full nose down position so there was no noticeable change in the controllability of the aircraft.

“More broadly this incident also reminds pilots and operators of all aircraft types to understand the expected system behaviour from switch and other control selections.”

Mr Nagy also reinforced that for flight control emergencies such as out-of-trim conditions, maintaining control of the aircraft while resolving technical issues is imperative.

“A critical consideration for pilots during flight control emergencies is the control of airspeed and engine power,” he said.

“In this incident, as the pitch trim runaway progressed, the reinforcing cycle of increasing control loads, forced descent, and increasing airspeed was initially exacerbated by high engine torque. The airspeed reached 210 kt with an increasing risk of descent into terrain before the pilot reduced engine torque and airspeed to partially alleviate control loads and to arrest the descent.” 

The ATSB found that the emergency procedures and systems information in the PC-12 Pilot Operating Handbook/Airplane Flight Manual and Quick Reference Handbook did not provide effective guidance or sufficient information for pilots contending with a pitch trim runaway.

The investigation also notes that incomplete systems knowledge and unrealistic practice exercises undermined the effectiveness of RFDS training and checking processes for a pitch trim runaway.

Read the report: Pitch trim runaway and partial loss of control involving Pilatus PC-12/47E, VH-OWJ, near Merredin, Western Australia, on 14 April 2019

Undetected track failure

The derailment of five freight train wagons highlights the importance of robust network rules that provide guidance for degraded condition operations, an ATSB investigation found.

During the 31 March 2019 incident, SCT Logistics freight train 7MB9 was exiting a refuge loop at Goulburn, New South Wales, when the five wagons derailed and obstructed both the Up and Down main lines.

Prior to the derailment, the driver of the train had been authorised to pass a signal at Stop, since the signal could not be cleared due to a track circuit fault. The fault had occurred the evening before, when another train passed through the refuge. At the time, the network controller and the on-call signal electrician had consulted on the problem, and agreed that trains could continue by passing the Stop signal.

A transport safety investigation into the incident, conducted on behalf of the Australian Transport Safety Bureau by NSW’s Office of Transport Safety Investigation (OTSI), found that the wagons had derailed due to a broken rail, which had likely broken under the previous train. The break, which had probably caused the signal to be stuck at Stop, had gone undetected.

Personnel need suitable guidance in assessing when it is safe to continue operating trains, and to judge under what conditions operations can continue safely.

Examination of the track identified that a crack had likely initiated from a lack of weld fusion at the foot of the rail in an aluminothermic junction weld. This defect area was located in a portion of rail not easily detectible through continuous ultrasonic testing and was not detected during routine maintenance.

“It is critical that areas of the rail that cannot be easily inspected during scheduled continuous ultrasonic testing are tested thoroughly at the time of welding to ensure that the weld is free from defects,” OTSI COO and Deputy Chief Investigator Kevin Kitchen said.

The investigation’s findings also noted other factors that increased risk in relation to this occurrence, in particular regarding the network rules in place by rail infrastructure manager ARTC.

“Network rules that permit degraded operations must be assessed to ensure that the application of these rules do not increase risk to an unacceptable level,” Mr Kitchen said.

“Personnel responsible for implementing these rules should have sufficient guidance to assess when it is safe to continue operating trains, or under what conditions operations can continue.”

Read the final report: Derailment of freight train 7MB9, Goulburn, New South Wales, on 31 March 2019

Main rotor blade crack

A large crack across the width of a Robinson Helicopter Company R22 helicopter’s main rotor blade demonstrates that unexpected fatigue cracking can occur on critical flight components, and serves as a reminder to pilots and maintainers of the importance of vigilance during pre-flight and daily inspections, an ATSB investigation notes.

The R22 Beta helicopter, registered VH-HPH, was conducting mustering at Labelle Downs Station in the Northern Territory on 16 December 2016 when the pilot noted the onset of vibrations. In response, the pilot successfully conducted a precautionary landing and shut down the helicopter. A subsequent ground inspection revealed a significant crack had progressed almost entirely through the cross-section of a main rotor blade.

“Technical analysis of the main rotor blade at the ATSB’s facilities in Canberra identified that a significant fatigue crack had propagated almost entirely through the blade chord,” said ATSB Director Transport Safety Stuart Macleod. “This led to instability and vibrations of the aerofoil structure during the occurrence flight.”

If main rotor vibration rapidly increases or becomes severe during flight, make an immediate precautionary landing.

The analysis identified that the fatigue crack initiated at the trailing edge bond line and propagated through both the upper and lower blade skins until terminating at the leading edge D-spar.

The ATSB’s investigation was unable to determine conclusively which factors – either individually or in combination – contributed to the crack initiation, but said it was possible a number of variables influenced the initiation of the blade cracking, including the component’s design, manufacture and operation.

“This incident reinforces to helicopter pilots, operators and maintainers that they should be particularly vigilant during the daily or pre-flight inspections,” Mr Macleod said. “Inspections represent important opportunities to detect cracking that may not be obvious. Any form of damage such as paint blistering, denting and corrosion to the main rotor blade surfaces is cause for further investigation.”

Following the occurrence, Robinson issued a safety alert to all R22 operators detailing the crack location and recommended particular attention from pilots and maintainers when visually examining the trailing edges of blades during the daily or pre-flight inspection.

“Robinson warns that if main rotor vibration rapidly increases or becomes severe during flight, make an immediate precautionary landing,” Mr Macleod said. “Do not attempt to continue flight to a convenient destination.”

Mr Macleod noted that during the incident flight, the pilot’s action to land the helicopter prevented further deterioration of the main rotor blade surface and removed the potential for an in-flight blade separation and subsequent loss of control.

Robinson subsequently implemented a minor design change to the A016-6 blade design, extending the length of the trailing edge metal doubler to eliminate potential stress gradients. The revised blade entered production in February 2017.

Separately, the Civil Aviation Safety Authority issued an Airworthiness Bulletin to alert all R22 operators and maintainers to the occurrence, and to provide advice on how to avoid future occurrences.

Read the final report: Main rotor blade crack and precautionary landing involving Robinson R22 Beta, VH-HPH, 12 km south-west of Labelle Downs Station, Northern Territory, on 16 December 2016

Automatic ignition systems

A turboprop airliner’s automatic ignition systems performed as designed, successfully relighting the aircraft’s engines after they separately flamed out in heavy rainfall when the aircraft was on descent to land at Canberra Airport, an ATSB investigation has found.

The Virgin Australia ATR72-212A (ATR72-600), registered VH-FVN, was operating a scheduled passenger flight from Sydney to Canberra on 13 December 2018. Due to thunderstorm activity, the pilots were cleared by air traffic control to divert left of their planned track and subsequently held to the south-east of Canberra before tracking south then west to fly around the weather and then tracking back to land.

Shortly after commencing the descent into Canberra, passing 11,000 feet in heavy rain, the aircraft’s right engine flamed out*. The engine’s automatic ignition system engaged and the engine relighted within five seconds without pilot input. Then, approximately one minute later, passing 10,000 feet, the left engine flamed out and it too automatically recovered within five seconds, again without pilot input.

The ATR72’s automatic ignition system worked as designed, correctly detecting the loss of engine power, initiating ignition and successfully relighting the engines without pilot input.

The incident highlights that while engine flameouts are not common in modern turboprop aircraft, they are still possible, according to ATSB Director Transport Safety Dr Stuart Godley.

“The ATR72’s automatic ignition system worked as designed, correctly detecting the loss of engine power, initiating ignition and successfully relighting the engines without pilot input,” Dr Godley said.

After the second engine flameout, the captain selected engine ignition to ‘manual’ in order to provide continuous ignition in an attempt to prevent any further flameouts.

“However, the selection of manual ignition potentially reduces the effectiveness of flameout recoveries, and should only be used when directed by checklists or a minimum equipment lists,” Dr Godley said.

The ATR72’s Pratt & Whitney Canada PW127M engines have a high-energy ignition system which is automatically disengaged following engine start, but in the event of a flameout, will automatically deliver a spark rate of between five and six sparks per second for 25 seconds before reducing to once per second until the engine relights.

Selecting manual ignition would also deliver an initial spark rate of between five and six sparks per second for 25 seconds before reducing to once per second. Consequently, if manual ignition has been ON for more than 25 seconds at the time of a flameout, it would not provide the high initial spark rate of automatic ignition, potentially delaying the relight process.

“This investigation highlights that reliable and effective systems and procedures exist to protect and recover from flameouts and it is important that pilots follow manufacturer procedures,” Dr Godley said.

The investigation noted that ATR’s Flight Crew Operating Manual did not prohibit the use of manual ignition in situations other than where the Electronic Engine Control unit was malfunctioning, and had no explicit direction for ignition to remain set to automatic.

Since the incident, ATR has ensured all operators of the ATR72-600 are aware of the appropriate use of the manual ignition, and is also reviewing operational documentation to determine whether this requirement could be explicitly included.

* A flameout is an unintentional extinguishing of the flame in the engine. This may result from interruption of any of the requirements for sustaining combustion, being fuel, air and heat.

Read the final report: Engine flameouts on descent involving GIE Avions De Transport Regional ATR72-212A, VH-FVN, near Canberra Airport, Australian Capital Territory, on 13 December 2018

Simulated engine failure

A twin-engine Cessna 441 Conquest collided with the ground shortly after take-off following a simulated engine failure at about 400 feet when the aircraft did not achieve the expected single-engine climb performance or target airspeed.

An ATSB investigation into the 30 May 2017 accident, near Renmark, South Australia, which resulted in the deaths of the three pilots on board, found the lack of expected performance was likely due to the method of simulating the engine failure, pilot control inputs or a combination of both. The investigation also established that normal power on both engines was not restored when the expected single engine performance and target airspeed were not attained.

“That was probably because the degraded aircraft performance, or the associated risk, were not recognised by the pilots occupying the control seats,” said ATSB Executive Director Transport Safety Nat Nagy.

“Consequently, about 40 seconds after commencing the simulated engine failure exercise, the aircraft experienced an asymmetric loss of control, and impacted the ground about four kilometres west of Renmark Airport.”

If one engine inoperative training sequences are conducted close to the ground, then effective risk controls need to be in place to prevent a loss of control, as recovery at low height will probably not be possible.

The aircraft, operated by Adelaide-based Rossair, was conducting a check flight on the Cessna 441 for Rossair’s chief pilot by a Civil Aviation Safety Authority (CASA) flight operations inspector (FOI). In turn, the chief pilot was conducting a check of an experienced Cessna 441 pilot who was rejoining Rossair after a period away from the company. The inductee pilot was the pilot flying and was seated in the aircraft’s front left control seat, the chief pilot was seated in the front right seat, and the CASA FOI was observing and assessing the flight from the first passenger seat directly behind the left-hand pilot seat.

They were operating a return flight from Adelaide Airport via Renmark, with a number of flight exercises planned as part of the inductee’s check flight, including the simulated engine failure after take-off on departure from Renmark.

“Conducting the engine failure exercise after the actual take-off meant that there was insufficient height to recover from the loss of control before the aircraft impacted the ground,” said Mr Nagy.

Noting that there is no Cessna Conquest simulator in Australia, the investigation highlights that one engine inoperative training should follow the manufacturer’s guidance and, where it is possible, be conducted in an aircraft simulator.

Mr Nagy said if one engine inoperative (OEI) training sequences are conducted close to the ground, then effective risk controls need to be in place to prevent a loss of control, as recovery at low height will probably not be possible.

“These risk controls can include defined OEI performance criteria that, if not met, require immediate restoration of normal power; use of the appropriate handling techniques to correctly simulate the engine failure and ensuring that aircraft drag is minimised/OEI performance is maximised; and ensuring that the involved pilots have the appropriate recency and skill to conduct the exercise and that any detrimental external factors, such as high workload or pressure, are minimised.”

The investigation also identified a number of safety factors, although they did not necessarily contribute to the accident flight. These included:

  • The operator’s training and checking manual procedure for simulating an engine failure in a turboprop aircraft was inappropriate and increased the risk of asymmetric control loss;
  • The CASA flying operations inspector was not in a control seat and was unable to share the headset system used by the inductee and chief pilot;
  • The inductee and chief pilot, while meeting recency requirements, had limited recent experience in the Cessna 441;
  • The chief pilot and other key operational managers within Rossair were experiencing high levels of workload and pressure; and
  • CASA’s method of oversighting Rossair increased the risk that organisational issues would not be identified and addressed.

Mr Nagy also noted a lack of recorded data from the aircraft reduced the amount and type of evidence available to investigators about handling aspects and cockpit communications, as the aircraft was not fitted with a cockpit voice recorder or flight data recorder, and nor was it required to be.

“This limited the extent to which potential factors contributing to the accident could be analysed.”

Read the final report: Loss of control and collision with terrain involving Cessna 441, VH-XMJ, 4 km west of Renmark Airport, South Australia, on 30 May 2017

Observe safety markings

A child fell between a railway station platform and a departing suburban passenger train at Gosnells Station in Perth, highlighting the need to observe platform safety markings, an ATSB investigation into the incident notes.

On 26 October 2019, a Transperth passenger train arrived at platform 2 at Gosnells Railway Station. As passengers left the train, a young child separated from his family when they stopped to look after a sibling. The child walked among passengers as he wandered towards the edge of the platform and the side of the stationary railcar.

As the railcars’ doors closed, after the train driver had viewed the Driver Assist Video monitor to determine passengers had completed boarding and alighting, the child crossed the platform’s painted safety line and neared the edge of the platform. As the child turned and looked back at his family, he stumbled against the side of the train’s third railcar, stepped off the platform, fell between the railcar and platform.  

Family members and those nearby reacted almost immediately and reached between the platform and train to rescue the child as well as alerting onboard passengers. As the train began to move, an onboard passenger, alerted to the situation by those on the platform, used the emergency passenger intercom to contact the driver.

The driver immediately applied full service braking.

While unsure of the exact nature of the emergency, the driver immediately applied full service braking to stop the train. The train soon came to a stop and the family was able to recover the child.

Police reports indicated the child was uninjured; however, a family member was reported to have sustained injuries and was taken to hospital for treatment.

“The ATSB safety message reinforces that passengers at a railway station platform must observe the markings on its surface that specify the required separation from the platform edge,” ATSB Director Transport Safety, Dr Stuart Godley said.

Dr Godley noted that the quick reaction by the driver to stop the train in response to the onboard passenger’s emergency intercom message likely prevented serious injuries to the young child and family members.

Read the final report: Passenger injury at Gosnells Railway Station, Perth, Western Australia, on 26 October 2019

Loss of engine power

The importance of having a clear, defined emergency plan for critical stages of flight is highlighted by a Cessna 172’s loss of control and collision with terrain in a residential street near Melbourne’s Moorabbin Airport, an ATSB investigation notes.

Cessna 172S, registration VH-EWE, was returning to land at Moorabbin Airport on 8 June 2018. The private flight was being conducted following maintenance, which included a scheduled engine change. The pilot, and sole occupant, was also one of the licenced aircraft maintenance engineers that had conducted some of the recent maintenance on behalf of the aircraft owner.

While the aircraft was on final approach to runway 35 Left, and at about the time it was cleared to land, witnesses on the ground observed the aircraft a little lower than expected and described hearing the engine ‘spluttering’, ‘struggling’, and that it ‘sounded like a lawn mower struggling to start’.

The pilot transmitted a MAYDAY call, stating ‘we’ve got engine failure.’ Witnesses observed the aircraft’s nose and left wing drop, consistent with an aerodynamic stall. The aircraft collided with terrain in a residential street about 680 metres from the airport. The pilot was fatally injured and a post-impact fuel-fed fire destroyed the aircraft. There was minor damage to a house perimeter fence and a parked car. No one on the ground was injured.

Taking positive action and ensuring that control is maintained has a much better survivability potential than when control of the aircraft is lost.

“The loss of engine power while on final approach presents a scenario where there may be limited forced landing options, especially when there is insufficient height to glide to the airport,” said ATSB Director Transport Safety Stuart Macleod.

“This is particularly relevant where the approach is over built-up areas, such as at Moorabbin Airport.”

The investigation found that when control of the aircraft was lost, there was insufficient height to recover.

“Having a clear, defined emergency plan prior to the critical stages of the flight removes indecision and reduces pressure on the pilot while in a high-stress situation,” Mr Macleod said.

“Proficiency in in-flight emergencies can be improved by regularly practicing these emergencies. Additionally, flying the approach as per manufacturer and airport procedures places the aircraft in the optimum configuration and position.”

Mr Macleod noted that the ATSB publication Managing partial power loss after take-off in single-engine aircraft provides guidance that is also applicable to an engine failure occurring at low-level during an approach.

“Taking positive action and ensuring that control is maintained has a much better survivability potential than when control of the aircraft is lost,” he said. “In addition, using the aircraft structure and surroundings to absorb energy and decelerate the aircraft can assist in minimising injury.”

The investigation examined the aircraft’s engine and fuel system, and did not identify any failures or issues that may have contributed to the loss of engine power.

Read the final report: Loss of control and collision with terrain involving Cessna 172, VH-EWE, near Moorabbin Airport, Victoria, on 8 June 2018

Fuel drum contamination

The origin of a white, rubbery contaminant discovered in Jet A1 fuel drums was determined to be sealant used on drum lids and bases, an ATSB investigation has found.

In September of 2016, the ATSB received a report from a helicopter operator in Cloncurry, Queensland, that while inspecting one of several recently arrived drums, a pilot had discovered white particles floating in the Jet A1 fuel. The same material, described as small pieces of white debris that tended to settle at the base of the drum, was subsequently found in all seven of the drums that were opened and inspected.

The same operator would subsequently report further instances of fuel drum contaminants, from a second location in Queensland and two remote sites in Western Australia on separate occasions in 2016, 2017 and 2019.  

The operator advised that the contaminated drums had been filled by different refuelling companies but all had been manufactured the same company, VIP Packaging. Batch numbers and manufacturing dates on the drums across the incidents did not show any correlation.

There are a number of ways to minimize the likelihood of using contaminated fuel.

The ATSB determined that the contaminant was a sealant used by the drum manufacturer on the lid and base of the drums. The sealant’s mechanical properties were found to degrade when exposed to Jet A1 fuel. This, in combination with vibration and drum deformation during transport to remote locations over rough roads, likely resulted in pieces of sealant entering the fuel within the drum.

“Fuel sourced from drum stock is particularly susceptible to contamination. However, there are a number of ways to minimise the likelihood of using contaminated fuel,” ATSB Director Transport Safety Stuart Macleod said.

“These include applying appropriate drum handling and storage methods; visually inspecting drums for contaminants prior to refuelling activities; regularly inspecting fuel pump filters; and conducting fuel drains from the aircraft after each refuel for visual inspection.”

Mr Macleod noted that the investigation established that no contaminants were found in any aircraft exposed to the fuel.

“Filtration during the refuelling process appears to be effective in preventing these contaminants from reaching the aircraft and there was no evidence that the sealant dissolved in the fuel.”

The report notes it is possible that the sealant may break down into small enough pieces to pass through a fuel transfer pump’s micronic pre-filter and reach the aircraft’s fuel tank, and from there pass through the aircraft’s fuel filtration system and enter the engine.

“However, if that was to occur, the particles would be in minor quantities and too small to affect engine operation,” Mr Macleod said.

“As long as fuel is filtered as required under the regulations, and in accordance with best practice, harmful contaminants should not be able to reach the aircraft.”

Read the final report: Drum stock fuel contamination, Cloncurry Airport, Queensland, on 7 September 2016

New safety measures

A signal maintenance mechanic working on crossover points at Clyde rail yard, western Sydney, entered the danger zone before being struck by a passenger train and sustaining fatal injuries in the early morning of 18 June 2016.

A transport safety investigation into the accident, conducted on behalf of the Australian Transport Safety Bureau by NSW’s Office of Transport Safety Investigation (OTSI), determined that two signal maintenance team workers (a mechanic and an electrician) had assumed their worksite was within the protective limits of a Track Occupancy Authority (TOA) established for a civil maintenance team tasked to replace sleepers under the crossover at 64 points.

However, the protective limits of the TOA extended only to defined clearance points on either side of 64 points and did not include the 63B points, on the Up main line, where the signal maintenance team entered the danger zone.

The accident highlights the importance of planning and integrating safety across the entire scope of work.

“The investigation found that Sydney Train’s work-planning process, involving multiple work groups, did not assure the consideration of worksite safety for all tasks undertaken by each party over the duration of the work and when returning the rail infrastructure into service,” said OTSI Deputy Chief Executive Officer Kevin Kitchen.

The civil maintenance team’s Protection Officer (PO) was aware of the signal team’s work tasks but did not consider these in his worksite protection arrangements. The PO had not been briefed on the scope of the signal team’s work, and so did not provide protection at 63 points.

The investigation also identified that the network communications by various parties in Sydney Trains were not in accordance with the principles underpinning the network rules.

“This accident highlights the importance of planning and integrating safety across the entire scope of work,” said Mr Kitchen. “It also highlights the importance of briefing all workers, and of all workers seeking a safety briefing about the worksite protection plans before work commences and when circumstances change.”

Following the accident, Sydney Trains implemented a number of safety actions and delivered on safety commitments. These included requiring proposed worksite protection plans be reviewed and validated by Sydney Trains’ Corridor Safety Centre; appointing additional rail safety coaches and mentors, with a required coaching session for all Protection Officers at least once per year; and requiring Protection Officers implement a form of worksite protection at least once every quarter to remain eligible to be re-certified as a Protection Officer.

Additionally, Sydney Trains established a Post-Incident Assurance Group to respond to the accident. This Group established key focus areas to promote the safety of workers and avoid future incidents. These areas included worksite protection, culture, planning for maintenance work, and safety-critical communications.

The Group later established the Safety Focus Program, whose initiatives include safety focus sessions, a safety culture program, improvements to protection officer selection and training, a signal key switch project, safety-critical communication enterprise-wide program, and a maintenance access planning project.

Read the final report: Track worker fatally injured when struck by train W510, Clyde, New South Wales, on 18 June 2016

HUET contributes to survivability

A helicopter crew has credited their surviving a collision with water with skills learned and practised as part of Helicopter Underwater Escape Training (HUET).

The 28 January 2019 accident occurred when Sikorsky S-64E Skycrane helicopter, registration N173AC, was conducting firebombing operations to the west of Thomson Dam in Victoria’s Yarra Ranges National Park. All three crewmembers were highly experienced, and twice during the day, they had utilised the nearby Wood Creek Dam to fill the helicopter’s tank using its pond snorkel.

On the day’s third visit to Wood Creek Dam, while descending with a nose-high attitude, the helicopter’s tail struck the water, which then submerged and resulted in the tail rotor detaching. The helicopter then rotated rapidly, its main rotor blades separated as they contacted water, the right cockpit door separated from the fuselage, and the helicopter came to rest on its left side, submerging the cockpit.

The crew would recall that it was not possible to see anything underwater, and that jet fuel contamination was present. Each recalled the rehearsed drills from their helicopter underwater escape training, and they identified their harnesses and nearest exit to orientate themselves in the aircraft. They all waited until the last moment to draw a breath, and did not unbuckle and attempt to exit the helicopter until motion had ceased.

One crewmember sustained a knee injury while the other two were uninjured. All three crew successfully exited the aircraft, inflated their life jackets, and swam to shore. The aircraft was substantially damaged.

Helicopters excel in confined areas, but are vulnerable when operating within them.

“The ATSB has previously emphasised the importance of helicopter underwater escape training,” ATSB Director Transport Safety Stuart Macleod said. “Indeed, in the wake of a separate, sadly fatal, accident the ATSB released a Safety Advisory Notice highlighting the importance of HUET regular training. This accident demonstrates the value of that training in saving lives.”

Mr Macleod noted that accident highlighted another survivability consideration, as neither pilot unplugged their helmet. However, the extension cords from the aircraft to the helmet plug allowed the plug to release, preventing the helmets from snaring them.

“Following an accident, it is common for air crew to overlook the need to unplug their helmet,” he said. “Using a good quality extension cable that will maintain the integrity of communications and release under tension in the event of an emergency can also save lives.”

The ATSB investigation into the accident established that, over the course of the day’s operation, the helicopter’s approach path to the dam was incrementally shortened. The length of the final approach was considerably shorter than earlier approaches.

ATSB investigators determined that it was likely that the final tight approach path was at the upper margins of allowable speed and angle of bank. This would have required a steep flare on arrival and likely resulted in the rapid onset of vortex ring* state.

“When performing aerial work, it is easy to accept incremental changes that gradually reduce margins. While these changes often increase efficiency, it is worth checking how much a sequence has deviated from earlier versions and re-evaluating elements if they appear less stable,” Mr Macleod said.

“Helicopters excel in confined areas, but are vulnerable when operating within them. In this case, the shape of the dam and surrounds of the site reduced the opportunity for recovery. Periodic reassessment of confined areas, and approach and departure profiles should be done throughout the duration of an operation.” 

*Vortex ring state occurs when a helicopter descends into its downwash, where air recirculates back up and over the rotors instead of flowing down and away. This causes the same parcel of air to circulate around the rotor. As a result, the rotor system no longer has the steady stream of air required to produce lift and the helicopter will descend despite the application of additional power.

Read the final report: Collision with water involving a Sikorsky S-64E Skycrane helicopter, N173AC, near Jericho, Victoria, on 28 January 2019