At 0528 on 20 November 2021, a De Havilland Canada DHC-8, registered VH‑QQD, departed on a charter flight from Perth to Port Hedland, Western Australia.
As the aircraft approached 10,000 ft, the flight crew carried out transition altitude checklist items and observed that the cabin had not pressurised. The flight crew decided to return to Perth and the aircraft landed uneventfully.
What the ATSB found
The aircraft had been undergoing maintenance on the day prior to the occurrence, and for operational reasons the recirculation fan had been removed for fitment to another aircraft. VH‑QQD had not been removed from the schedule as the assigned aircraft for the flight, and its unserviceability was not detected prior to flight. The absence of the recirculation fan on the occurrence flight prevented the aircraft from pressurising.
The operator’s operations department incorrectly interpreted a message from its engineering department regarding the serviceability status of VH‑QQD, and it remained assigned to the charter flight. This allocation remained on the flight crew’s roster and the flight manifest, which contributed to the flight crew’s confidence that the aircraft was serviceable.
As there were no allowable defects against the aircraft, the captain did not check the maintenance log prior to flight and, as a result, did not detect that the recirculation fan had been removed. However, during pre-flight activities the captain observed the circuit breaker that had been opened to facilitate the recirculation fan removal. The captain reset the circuit breaker without reviewing the maintenance log for recent or open defects as per the operator’s flight crew operating manual.
What has been done as a result
After the occurrence, the operator took the following actions:
refined the terminology used by engineering to communicate aircraft serviceability, and reviewed internal communication methods
distributed an internal memo to all staff advising that if the aircraft technical logs were not located in the crew room when receiving the aircraft, it was to be considered unserviceable
distributed an internal memo to flight crews to reiterate existing paperwork and circuit breaker resetting requirements
incorporated a dedicated compartment for each aircraft’s documents in the crew room with a placard instructing flight crews to contact maintenance watch if the scheduled aircraft’s documents were not in their compartment.
Safety message
Any task, including those that may seem innocuous, should be performed as though it is the last defence to ensure safe operation. The aircraft documents contain the only reliable records of airworthiness that a pilot should trust, and this occurrence shows that thoroughly checking them remains an important control to determine if the aircraft can be operated.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
Aircraft assignment to the flight
On 15 November 2021, Maroomba Airlines received a request to carry out a charter flight from Perth Airport to Port Hedland Airport, Western Australia, scheduled to depart at 0600 on 20 November 2021. The flight was entered into the operator’s operations management system (AvSys[1]), with an assigned aircraft (VH‑QQD, a De Havilland Canada DHC-8) along with an assigned flight crew. The flight and assigned aircraft information was then added to the crew’s roster.
VH‑QQD was operated on a scheduled flight on Friday 19 November 2021. After the flight, at about 1500, that flight crew made an entry in the maintenance log regarding a propeller de-ice defect, which made the aircraft unserviceable.
Another of the operator’s 4 DHC-8s, VH‑QQK, was reaching the end of the period it could operate with a permissible unserviceability[2] for its recirculation fan. As the operator did not have engineering personnel rostered on evenings or weekends, it was decided to use the fan from VH‑QQD and leave VH‑QQD unserviceable. The removal of the recirculation fan from VH‑QQD was entered into its maintenance log at 1700 (Figure 1).
Figure 1: Aircraft maintenance log entry for recirculation fan removal
Source: Maroomba Airlines, modified by the ATSB
Meanwhile, at 1625, the departure time for the Port Hedland charter flight on 20 November was changed in AvSys to 0500, and the assigned flight crew were made aware.
At 1812 on 19 November, the operator’s duty engineering supervisor used an instant messaging program to communicate the following message about fleet status in accordance with normal protocols:
QQD and QQP in maintenance. AEP, QQK, CWO, NYA Serviceable. QQK MEL [minimum equipment list] 21-10 cleared. Recirc fan serviceable
This message was promulgated to a group that included the operations department. A member of the operations department acknowledged receipt of the status message and updated AvSys. For reasons that could not be determined, the status of VH‑QQD was not updated, and VH‑QQD remained the assigned aircraft for the charter flight on the following morning.
Pre-flight preparation
The operator’s facilities at Perth Airport consisted of a maintenance hangar, an administration and operations building, and an apron area. On 20 November 2021, the captain arrived at 0330 and logged onto AvSys. After confirming the aircraft assigned to the charter was VH‑QQD, the captain saw that the aircraft was positioned on the operator’s apron area, close to the terminal.
The operator's flight crew operating manual required the flight crew to check aircraft documentation when accepting the aircraft. The operator stated that this meant that each document needed to be checked. The manual did not assign this responsibility to either flight crew member in particular.
The captain found that the aircraft documents (see Aircraft documentation suite) for VH‑QQD were not in the crew room as they normally would be for flight crews to review prior to accepting an aircraft. The captain checked the aircraft’s registration on the flight manifest, reconfirming the flight had been assigned to VH‑QQD.
The captain recalled that on a previous occasion prior to flight, the operator’s engineers had not placed the aircraft documents in the crew room after completing maintenance, unintentionally leaving them in the adjacent hangar. As a result, on the present occasion, the captain entered the hangar and located VH‑QQD’s documents on a workbench.
The captain stated that the presence of a pink duplicate maintenance log page, indicating permissible unserviceabilities, would normally prompt them to examine the maintenance log. On this occasion, there were no permissible unserviceabilities, and the captain left the maintenance log in its sleeve. At that time, the maintenance log contained the open entries that made the aircraft unserviceable (that is, the propeller de-ice defect and the absence of the recirculation fan).
The operator required flight and cabin crew members to arrive 1 hour prior to their flight’s scheduled departure time (which was now 0500). The first officer arrived shortly before 0400, while the captain was in the hangar. However, although the assigned cabin crew member had acknowledged the departure time change, they mistakenly thought the flight was scheduled to depart at 0600, in part because the automated rostering system had not updated correctly. At 0415, in an attempt to maintain schedule since the cabin crew member had not yet arrived, the captain and first officer carried out some of the cabin crew’s pre-flight tasks, such as security checks and stowage of catering.
From about 0430, the captain and first officer continued the flight crew pre-flight tasks. To facilitate the removal of the recirculation fan the previous day, engineers had opened its relevant circuit breaker (see Aircraft circuit breakers). The captain re-set it, believing that (based on their knowledge of the system) the circuit breaker had tripped.
At 0440, the flight crew called the fuel provider to find out when they would arrive to refuel the aircraft (the flight crew expected an earlier refuelling, having advised the fuel provider of the flight’s requirements at 0410). Refuelling commenced at 0445 and was completed just before 0500. The cabin crew member arrived at 0500. The 7 passengers boarded the aircraft and taxi commenced at 0519.
Occurrence flight
The aircraft took-off at 0528, just after sunrise, and both pilots later reported that there was significant glare at this time. Additionally, the captain reported the flight crew workload during the departure was high due to the aircraft’s high rate of climb, radio calls, and radar vectoring[3] from air traffic control (ATC). The absence of the recirculation fan prevented the aircraft from pressurising; however, this would not have been known to the crew at the time.
At 0534, as the aircraft approached 10,000 ft and continued to climb, the flight crew carried out transition altitude checklist items. They observed the cabin differential pressure (the difference in pressure between inside the aircraft cabin and the local external atmosphere) to be 0 pounds per square inch (psi), indicating that the cabin had not pressurised. They observed the cabin altitude to be approaching 10,000 ft.
There were no cabin altitude warnings, and the flight crew did not consider it necessary to use supplementary oxygen. Generally, aircraft can operate up to 10,000 ft without the occupants requiring the use of supplementary oxygen or the aircraft being pressurised.
The captain selected the autopilot to altitude hold and requested descent to 10,000 ft from ATC. Once clearance was received, the flight crew commenced descent. The crew carried out the cabin pressurisation failure checklist, but the cabin pressure and altitude indications showed that the aircraft remained unpressurised.
After confirming the relevant circuit breaker was correctly set, the flight crew decided to return to Perth. The cabin crew member was briefed on the nature of the defect and instructed to prepare the cabin for a normal landing. The aircraft returned to Perth and landed uneventfully. The crew and passengers were assigned another aircraft for the flight to Port Hedland.
Context
Aircraft documentation suite
The Maroomba Airlines aircraft documentation suite consisted of a:
flight log – a history of the aircraft’s flights
maintenance release – the controlling document that released the aircraft for service, valid for a set period
maintenance due list – maintenance requirements that were due to be carried out during the maintenance release period
maintenance log – a history of the aircraft’s maintenance activity and certification (engineers made entries in the maintenance log to record the maintenance requirement, as well as a second entry to detail the work carried out and to certify it had been complete)
summary of deferred defects card – a list of permissible unserviceabilities.
The maintenance release, maintenance due list, and deferred defects card were individual sheets. The flight and maintenance logs were books. All were typically stored in a folder with an internal sleeve for the maintenance log. Engineers would normally record maintenance activities in the maintenance log only. For the aircraft to be airworthy, all of the documents needed to be actioned appropriately; that is, the maintenance release could be current (as it was in this case) but the aircraft could not be operated on the basis of entries in the maintenance log.
For flights departing from Perth Airport, all the aircraft document folders were normally placed in the crew room prior to flight crew arrival, and then carried on board the aircraft. Prior to accepting an aircraft, the flight crew operating manual required the flight crew to review them to ensure that:
the aircraft was airworthy
the flight could be conducted without any scheduled maintenance falling due
the flight crew were aware of any operational limitations arising from permissible unserviceabilities.
The captain previously flew for a high-capacity airline that kept most aircraft documentation in a single book, and maintenance history or open defects were visible concurrently with the flight log. They had recently been trained and checked to line as a direct entry captain on the operator’s DHC‑8 fleet. The captain recalled that during this training it ‘wasn’t normal procedure’ to review the recent maintenance history.
Aircraft circuit breakers
An aircraft circuit breaker connects or isolates electrical power to a system. They can be opened (‘pulled’) intentionally, such as to facilitate maintenance, or they can trip to protect a system in an overload situation.
Circuit breakers incorporate a white band as a visual indicator to show that the relevant electrical system has been intentionally or unintentionally isolated (Figure 2).
Figure 2: Exemplar aircraft circuit breakers
Source: Maroomba Airlines, annotated by the ATSB
A transient overload in an aircraft system may trip a circuit breaker, but not necessarily be a defect. As a result, operators establish guidelines, based on those from the aircraft manufacturer, for flight crews to re-set circuit breakers and continue operations.
The operator’s guidelines for re-setting after a cooling period were:
only reset if the aircraft is on the ground
only reset if there is no recent history of reported defects with the effected or a related system and there is no evidence of anomalies with these systems
should the breaker trip again, the cause of the trip must be rectified before another attempt to reset.
Recirculation fan
The aircraft’s air-conditioning and pressurisation systems were designed to maintain a safe and comfortable environment within the flight deck, cabin, and cargo bay (collectively known as the flight compartment) during all phases of flight. The recirculation fan is located outside the flight compartment in the rear fuselage and is not visible externally (Figure 3).
The flight compartment is pressurised by maintaining a balance between airflow entering and airflow leaving the flight compartment. On the occurrence flight, the absence of the recirculation fan allowed airflow to leave the flight compartment at a rate greater than what could be supplied, so the aircraft could not be pressurised.
Figure 3: Flight compartment recirculation fan installation
Source: De Havilland Aircraft of Canada Limited, modified by the ATSB
Safety analysis
On the day of the occurrence, the aircraft was not serviceable because it had no recirculation fan fitted, which prevented it from pressurising. The removal of the fan the day before was entered into the maintenance log. However, the unserviceable status of VH‑QQD was not entered into the operations management system (AvSys) by the operations department, so the aircraft remained assigned to the flight and on the flight manifest visible by the flight crew.
The flight manifest was among the items for the flight crew to check during their pre-flight preparations. At this point, there was no reason for the flight crew to believe the aircraft was not serviceable. Although operations planning is not a means to control airworthiness, the omission on this occasion contributed to the flight crew’s confidence that VH‑QQD had been assigned to the flight and was serviceable.
Airworthiness is controlled through the use of the document suite kept on board the aircraft. This is of particular importance when a discrepancy is not obvious, such as the absence of the recirculation fan in this instance (as it was not visible during an external inspection). On the morning of the occurrence, the document suite’s unusual location provided an indication that something was wrong but would not normally be interpreted as indicating that the aircraft was unserviceable. Also, the captain likely experienced expectation bias resulting from the initial information that showed VH-QQD assigned to the flight, which would not normally occur unless the aircraft was serviceable.
The first real opportunity for the flight crew to discover the problem was the presence of unserviceabilities in the maintenance log. The operator’s flight crew operating manual required the flight crew to check the document suite when accepting the aircraft. The captain would not normally check the maintenance log unless there was a pink page present that showed permissible unserviceabilities. As there were none, the captain did not check the maintenance log. As a result, the entries for the propeller de-ice defect and the circulation fan removal were not detected.
Other documents would not have showed that the aircraft was not serviceable. For example, the maintenance release being current was not the only requirement for airworthiness. This is because the documentation suite as a whole is used to manage airworthiness rather than through individual documents.
In addition, the first officer did not check the aircraft documentation, as there was no requirement to do so. Finally, the circuit breaker that had been opened to facilitate the recirculation fan removal was another prompt for the captain to review the maintenance log for recent or open defects. However, probably due to expectation bias, the prompt was not successful on this occasion.
Ultimately, the flight crew detected the problem when they conducted the transition altitude checklist, demonstrating the importance of checklist items. Had that not occurred, the crew would have subsequently been alerted to the situation by a cabin altitude warning. Nevertheless, even though this particular occurrence was unlikely to result in an adverse outcome, it demonstrated the importance of having rigorous processes for ensuring an aircraft was serviceable prior to being used for a flight.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the cabin pressurisation issue involving a De Havilland Canada DHC-8, registered VH‑QQD, 30 km north of Perth Airport, Western Australia, on 20 November 2021.
Contributing factors
The flight was commenced without a recirculation fan fitted to the aircraft, preventing the aircraft from pressurising.
When reviewing the aircraft documents prior to accepting the aircraft, and after resetting a circuit breaker, the captain did not check the maintenance log for open entries. As a result, the open entry showing the recirculation fan removal was not detected.
The operations department did not remove the aircraft from its assigned flight after receiving a message from the engineering department about the status of multiple aircraft, including that the assigned aircraft was unserviceable.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by Maroomba Airlines
After the occurrence, the operator took the following actions:
refined the terminology used by engineering to communicate aircraft serviceability, and reviewed internal communication methods
distributed an internal memo to all staff advising that if the aircraft technical logs were not located in the crew room when receiving the aircraft, it was to be considered unserviceable
distributed an internal memo to flight crews to reiterate existing paperwork and circuit breaker resetting requirements
incorporated a dedicated compartment for each aircraft’s documents in the crew room with a placard instructing flight crews to contact maintenance watch if the scheduled aircraft’s documents were not in their compartment.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] AvSys was a third-party software system to manage the daily operational aspects of the airline’s operations, such as flight scheduling, bookings, freight management, crew scheduling, and duty times. It was not used to control aircraft serviceability.
[2] Permissible unserviceability: a defect or other issue which does not prevent aircraft operation (sometimes requiring certain conditions to be met).
[3] Radar vectoring: air traffic control provision of track bearings and altitudes used to guide and position an aircraft.
Occurrence summary
Investigation number
AO-2021-050
Occurrence date
20/10/2021
Location
30 km north of Perth Airport
State
Western Australia
Report release date
20/01/2023
Report status
Final
Investigation level
Short
Investigation type
Occurrence Investigation
Investigation status
Completed
Mode of transport
Aviation
Aviation occurrence category
Air/pressurisation
Occurrence class
Incident
Highest injury level
None
Aircraft details
Manufacturer
De Havilland Canada/De Havilland Aircraft of Canada
On the morning of 22 November 2021, a Network Aviation Fokker Aircraft F100, registered VH‑NHV, operating from Perth Airport to Paraburdoo Airport, Western Australia, encountered unforecast weather on arrival at Paraburdoo. Low cloud had developed below the landing minima, which resulted in 3 missed approaches. On the fourth approach, the aircraft fuel state was near the minimum fixed reserve, so the flight crew continued the approach below landing minima without visual reference and landed without further incident.
What the ATSB found
The ATSB found that, after having completed 2 missed approaches at Paraburdoo, the flight crew had lost confidence in their flight plan weather forecasts and were reluctant to attempt a diversion to an alternate airport without current weather information. After the third missed approach, the aircraft did not have sufficient fuel to reach a suitable alternate and the flight crew were committed to landing at Paraburdoo.
The flight crew’s flight plan for Paraburdoo indicated the lowest cloud would be above their landing minima, with deteriorations in the weather lasting for up to 60 minutes. However, the actual conditions encountered were below their landing minima and continued to deteriorate. This was difficult to forecast by the Bureau of Meteorology as detection of low cloud was obscured by higher level cloud. The development of low cloud at Paraburdoo contrasted with the expectation that surface heating would lift the existing cloud base.
After the second missed approach at Paraburdoo, the flight crew attempted to obtain an updated forecast for Newman Airport from air traffic control, but they did not express any urgency with this request. This, in combination with air traffic control workload at the time, resulted in a delay of 15 minutes before an update was offered. By that time, it was no longer required as they had insufficient fuel remaining to divert to Newman. Further, the aircraft was not fitted with an operational aircraft communications addressing and reporting system (ACARS), and they were beyond the range of the nearest automatic en route information service (AERIS). Therefore, the flight crew had no other means for obtaining updated weather forecasts for potential alternate aerodromes.
Paraburdoo Airport had an automatic weather station, which could measure the relative humidity at the surface. However, there were no means for measuring atmospheric data above the surface, which is one of the elements used to forecast cloud bases. In addition, the nearest weather balloon stations were more than 160 NM (300 km) from Paraburdoo, and therefore, the Bureau of Meteorology relied on cloud observations at nearby aerodromes to verify the expected conditions for Paraburdoo. Also, as the Newman automatic weather station was not recording the cloud or weather data groups, it was unknown if a SPECI report should have been issued for Newman for low cloud conditions, as it was for Paraburdoo.
Other than a procedure that limited the number of missed approaches to 2, Network Aviation did not provide flight crew with diversion decision-making procedural guidance when encountering unforecast weather at a destination.
In addition, Network Aviation had not included the threat of weather below the landing minima in their risk assessments for controlled flight into terrain. Consequently, these risk assessments did not include risk controls to address this threat. Without the identification of this threat and associated controls, their safety assurance team would not have had oversight of how effectively this was managed.
What has been done as a result
Following this incident, Network Aviation have implemented several proactive safety actions, which included:
An amendment to their flight plans to include diversion calculations for 2 alternate aerodromes. This was provided pre-incident for flights that required an alternate and amended post-incident to provide it for all flights.
Their arrival briefing procedure was amended to require flight crew to brief the minimum fuel required to divert to an alternate for all flights.
Introduced a Fokker Aircraft F100 company procedures manual with pre-populated diversion information for each of their F100 destinations.
Re-issued an updated internal safety advisory notice for their flight crew about the limitations of automatic weather information services.
Updated their Paraburdoo Airport risk assessment to capture this incident as a risk and their safety action as controls.
Updated their risk assessments for controlled flight into terrain to include adverse weather as an environmental threat.
Amended their company fuel policy to mandate additional alternate fuel requirements for nominated airports (operator approved variations). Airport classification is assessed based on alternate availability, instrument approach availability, aerodrome forecast reporting and historical accuracy, local mesoscale weather phenomena, and topography/terrain.
Established access for flight crew to obtain expanded briefings on ports (with operator fuel policy approved variations) from internal company meteorologists.
Updated the company’s Aerodrome and Route Data Manual to provide a new section on weather planning tools and resources, and a new section explaining the limitations of ceilometers and visibility meters installed in automatic weather information stations throughout the company network.
Enhanced the company’s training reference library for flight crew to support pilot knowledge and decision making. Additional content in the library is focused on company learnings from QF1616, which includes:
fuel management
threat management and contingency planning
time management in areas of vulnerability
pilot in command responsibilities.
Updated their take-off and landing data cards to provide a dedicated section for recording the alternate aerodrome, estimated time interval, fuel burn and fuel on arrival.
Safety message
Adverse weather conditions may not be experienced in the Australian environment to the same extent as they are in other countries. However, these events have been identified as contributing factors to incidents and accidents throughout aviation history and have been a driver for numerous safety initiatives. Therefore, it is important for all operators to consider how unforecast weather will be managed and ensure it is reflected in their risk management so that safety assurance activities can review how effectively it is managed and provide feedback for management review.
The occurrence
Overview
On 22 November 2021, at about 0746 Western Standard Time,[1] a Network Aviation Fokker Aircraft F100, registered VH‑NHV, operating flight QF1616 from Perth Airport to Paraburdoo Airport (YPBO), Western Australia, encountered unforecast low cloud on arrival at Paraburdoo. Three missed approaches were conducted during which time the flight crew considered diversion options to Karratha Airport (YPKA), Newman Airport (YNWN), and Solomon Airport (YSOL) (Figure 1). On the fourth approach, the aircraft fuel state was near the minimum fixed reserve, so the flight crew continued the approach below the minimum descent altitude (MDA)[2] without visual reference to the runway. The aircraft landed without further incident.
Figure 1: Incident flight path from Perth to Paraburdoo
Source: Google Earth, annotated by the ATSB
Pre-flight and departure
On the morning of 22 November 2021, the captain and first officer (FO) for flight QF1616 arrived at the airport and proceeded directly to their aircraft for a planned 0600 departure. Their flight was the first of 3 Network Aviation F100 flights from Perth to Paraburdoo, with the second and third flights scheduled to depart at 0630 (QF1618) and 0700 (QF1840). The flight time to Paraburdoo was scheduled to be 1 hour 29 minutes.
Once on board the aircraft, the flight crew downloaded and reviewed their flight plan on their electronic flight bags. The flight plan indicated a direct flight to Paraburdoo with the minimum required fuel, which included a 10% flight fuel variable reserve, 60 minutes of holding fuel for arrival at Paraburdoo, and 30 minutes of fixed fuel reserve. The additional 10-minute company fuel reserve was recorded on the flight plan as removed due to the forecast payload.
The mean weather conditions for arrival at Paraburdoo from the aerodrome forecast[3] included scattered[4] cloud at 1,000 ft and broken cloud at 3,000 ft with visibility greater than 10 km.[5] There was also a TEMPO[6] period for broken cloud at 1,000 ft and visibility reduced to 4,000 m, valid for their arrival time, which required 60 minutes holding fuel. The TEMPO conditions were forecast to be above their landing minima,[7] so while they departed with minimum fuel, the flight crew expected visual conditions at Paraburdoo before reaching the MDA. The captain recalled that the other inland airports in the Pilbara region had similar forecasts with TEMPO or INTER[8] periods, and that Karratha ‘was bad, but forecast to improve’.
At about 0553, the flight crew received a last-minute change on their flight plan, which reduced the planned take-off and landing weights by 847 kg. At this time, the fuel truck had departed, and the captain elected not to delay the flight by recalling the refueller to load additional fuel.
The flight data recorder indicated the aircraft departed at 0619:32 and reached its cruise altitude of flight level (FL)[9] 350 at 0646:05. The FO was designated as the pilot flying (PF) and the captain was the pilot monitoring (PM) at the start of the flight.[10] The PF had loaded Paraburdoo into the flight management computer (FMC) as route 1 and YPKA as route 2. Therefore, the FMC was calculating the fuel required for both destinations.
Arrival at Paraburdoo
The cockpit voice recorder indicated that at about 1 hour after take-off, at 0719 and FL 350, the flight crew listened to the Paraburdoo automated weather information service (AWIS).[11] The AWIS indicated the wind was from 050° at 6 kt, the cloud was scattered at 2,100 ft, broken at 4,800 ft, overcast at 6,700 ft, QNH[12] 1012, temperature and dewpoint[13] were 20 °C and 19 °C respectively, and relative humidity 94%. The flight crew discussed the weather and noted there was no rainfall reported and that the wind favoured runway 06. As the operator had a requirement for an instrument approach to be flown for arrivals at Paraburdoo, they commenced preparations for the area navigation (RNAV) approach to runway 06, which included their arrival briefing.
At about 0724, the PM contacted their ground station at Paraburdoo to advise them of their 0745 estimated time of arrival and their ground handling requirements. At 0725:41, the descent was commenced, and the PM advised Melbourne Centre air traffic control (ATC) of their estimated time of arrival at Paraburdoo. At about 0730, while on descent through FL 240, the flight crew listened to the Paraburdoo AWIS a second time.[14] The PM then verbalised ‘1013’[15] to the PF, who acknowledged the change in QNH, and they noted that the reported rainfall was less than moderate.
At interview, the captain (PM) recalled only noting the change in QNH and expected the visual conditions for landing to remain the same after listening to the AWIS.[16] The FO (PF) did not recall this second instance of listening to the AWIS.
First approach (runway 06)
At about 0731, the flight crew selected the Paraburdoo common traffic advisory frequency (CTAF) and turned on the pilot activated lighting (PAL),[17] which provided precision approach path indicators (PAPI)[18] for each runway and low intensity runway edge lighting. At about 0736, the flight crew completed their approach checklist for the runway 06 RNAV approach and noted their estimated time of arrival was 0744. As the aircraft descended through 5,500 ft, the flight crew observed extensive cloud. At 0741:43, just after passing the initial approach fix, the PF decided to configure the aircraft early due to a tailwind on the approach. At 0743:28, the flight crew changed the autopilot vertical mode from altitude hold to vertical speed and commenced their final descent to runway 06.[19]
At about 0744, the PF called for the before landing checklist, which the PM reported as completed as the aircraft descended through 3,000 ft towards the MDA of 1,960 ft. During the approach, the PM verbalised the aircraft’s vertical position relative to a 3° descent path and each subsequent distance-altitude step in the procedure as required. At 0746:01, the PM reported they were 100 ft above the minima, which was acknowledged by the PF. Shortly after, the PM announced ‘minima’, followed by ‘no contact’. The PF then announced that they were going around, and the PM commented that they were too high. The flight crew reported at interview that they sighted the runway with the PAPI indicating 4 white lights and were therefore too high to safely land from the first approach.
The aircraft was climbed to 5,200 ft in the missed approach, and while on climb, the flight crew briefly discussed the first missed approach. They concluded that they were too high on the approach due to a tailwind and decided to conduct an approach to runway 24. At 0747, the PM notified ATC of the missed approach and that they would make an approach to runway 24 and requested an operations normal[20] time of 0815.
Second approach (runway 24)
At 0752:46, while setting up for an approach to runway 24, the PM commented that the weather at all the surrounding airports was unsuitable, and then listened to the AWIS. The AWIS broadcast indicated the cloud was broken at 800 ft, overcast at 1,500 ft, and visibility had reduced to 5,000 m. Between 0753:20 and 0756, the flight crew had several conversations about the weather. This included that they could see ‘holes’ in the cloud where they were holding, that they were too steep when they became visual on the first approach, and that they expected to have a headwind on the approach to runway 24.
At about 0757, the flight crew activated the PAL, and the PM made a CTAF call to announce their intention to conduct an approach to runway 24. At about the same time, the flight crew of QF1618 contacted ATC for their clearance to leave controlled airspace on descent to Paraburdoo. At about 0758, the PM of QF1616 reported to QF1618 that they had commenced the runway 24 RNAV approach. This was followed 1 minute later by a broadcast from the flight crew of another aircraft (QF1802) to ATC that they had landed at Newman.
At 0802:43, the PM announced that they were 100 ft above the minima (of 2,040 ft) on the runway 24 RNAV approach, followed by ‘minima’. At 0802:53, the PF announced they were going around. At interview, the flight crew explained that they became visual with the ground on the approach to runway 24, but low cloud in front of them obscured the runway, which required a missed approach.
At 0805, while holding at 4,100 ft, the flight crew again discussed the weather and the PF commented that an aircraft had landed at Newman. They were uncertain of the actual weather conditions at that location and the PM noted they only had about 40 minutes of holding fuel remaining. At interview, the flight crew reported that, following the second missed approach, they noted that the FMC indicated they were at minimum fuel to divert direct to Karratha from their present position. However, the PM was cognisant of the fact that the FMC calculation did not account for the actual wind conditions they might experience en route or allow for an instrument approach on arrival. As Newman was closer than YPKA, they considered potentially diverting there with a fuel reserve on arrival for an approach.
At 0806, the PM contacted ATC to notify them of their second missed approach due to low cloud and requested the latest weather for Newman. Melbourne Centre acknowledged the request. However, there was no urgency conveyed by the PM nor was the aircraft’s fuel status relayed with this request. The flight crew and ATC then diverted their attention to their other tasks, which included traffic inbound to Paraburdoo.
Third approach (runway 06)
Between 0807 and 0809, the flight crew discussed their options, which included a preference to remain at Paraburdoo and that they had enough fuel for 2 more approaches. The PM then broadcast their intentions to QF1618. The flight crew of QF1618 reported that they had sufficient fuel for 35-40 minutes holding and then a diversion to Karratha.[21] At 0810:32, the PM contacted the Paraburdoo safety car officer and asked if the cloud overhead the airport was ‘sitting still or moving through’. The officer reported that it was coming from the north-west and was ‘moving through’. The flight crew briefly discussed this observation and then elected to make another approach to runway 06. The PF commented that the weather felt like it was persistent and that they did not have any options.
At about 0813, the PM provided ATC with a new operations normal time of 0830 and they commenced their third approach. At 0816:33, the PM announced ‘minima’ and 5 seconds later the PF announced that they were going around. During the missed approach, the PF reported that the runway 24 approach was better, and the PM noted that the wind was getting worse.
Fourth approach and landing (runway 24)
The aircraft climbed to 5,200 ft after the third missed approach and entered a holding pattern for the runway 24 RNAV approach. At about 0819, the flight crew noted they had 1.8 tonne of fuel on board and decided to hold while QF1618 conducted an approach to runway 24. The PM then advised QF1618 of their intention to hold until minimum fuel and offered them an approach while they were holding.
At about 0821, ATC contacted QF1616, and the PM notified them that they were manoeuvring to allow QF1618 to make an approach and provided a new operations normal time of 0840. This was acknowledged by ATC with the additional query as to whether the flight crew still required the weather forecast for Newman. The PM responded that it was no longer required (due to their fuel state).
At about 0822, the PF commented that Solomon was directly ahead (55 NM to the north), and the flight crew then discussed Solomon as a divert option and the need to obtain updated weather while they were holding. However, the PF then noted the lowest MDA at Solomon was about 800 ft above the aerodrome elevation (2,800 ft MDA), which was about 200 ft higher than at Paraburdoo. There were no further discussions of Solomon given the lower probability of establishing visual reference from an approach with a higher MDA.
At about 0825, the flight crew listened to the Paraburdoo AWIS, which reported the cloud was broken at 400 ft and 800 ft, visibility was 4,200 m, wind from 270° at 6 kt, QNH 1013 and relative humidity was 93%. At about 0826, QF1618 notified QF1616 they were going to start their approach and queried how long QF1616 would hold before diverting. The PM replied that they could not divert and would hold until they were ready to make a final approach. At about 0827, QF1840 broadcast that they were inbound to Paraburdoo and ATC notified them that QF1616 and QF1618 were traffic for them. At about 0828, the PM remarked that they had 12 minutes fuel remaining before landing with a 1.1 tonne fuel reserve.
At 0828:49, the captain and FO exchanged roles, the captain became the PF, and the FO became the PM for the final approach. The flight crew then discussed their options, which were to either comply with the missed approach criteria and declare a MAYDAY[22] fuel situation if not visual at the missed approach point or continue below MDA for a landing if they were not visual at the minima. They agreed to continue below the MDA for a landing.
At about 0834, ATC broadcast a SPECI alert for Paraburdoo, which was followed by a CTAF call from QF1618 to report their missed approach from runway 24, and then another ATC broadcast for a SPECI alert for Solomon. At 0834:48, the PM of QF1616 made a CTAF call that they were commencing the runway 24 RNAV approach. The PF then emphasised to the PM that they both needed to be prepared to call a go-around if either of them sensed the approach was becoming unsafe. At about 0837, ATC contacted QF1616 for an update and the PM reported that they had commenced the approach.
At 0841:51, the ground proximity warning system[23] announced ‘1,000 ft’, which was followed shortly after by the PM stating they were at 3 NM and ‘on profile’. Ten seconds later, at 844 ft above ground level and 273 ft above the MDA, the PM remarked the cloud was starting to break up. The PM called ‘minima’ at 0842:25. The ground proximity warning system then announced ‘500 ft’, ‘400 ft’, and ‘300 ft’. At 0842:50, the autopilot was disconnected, and the PM announced that they had sighted the runway and were on profile, at which stage they were 293 ft above ground level and 291 ft below the MDA. The flight crew reported they were slightly left of centreline, but on glideslope with the PAPI when they became visual with the runway. This was consistent with the flight data recorder information, which indicated a steady descent profile on the approach and a maximum of 5° heading change between the autopilot disconnect and landing.
At 0843:23, the aircraft landed without further incident. During the landing roll, the captain recalled noting that their fuel on board indicated 0.96 tonne.[24] Following the landing, the PM made a CTAF broadcast that there were some very low patches of cloud at 250-300 ft above ground level. Figure 2 depicts the weather during the landing roll.
Figure 2: Weather at Paraburdoo during the landing roll of flight QF1616
Source: Aerodrome Management Services, annotated by the ATSB
Context
Personnel information
Captain
The captain held a valid Air Transport Pilot Licence (Aeroplane) with a multi‑engine aeroplane instrument rating, type ratings for the Fokker FK70/100 (F100) and De Havilland Canada DHC-8 aircraft, and a Class 1 Aviation Medical Certificate. They had accrued 6,698 hours total flying experience with 2,641 hours on the F100. The captain reported being awake for about 5 hours at the time of the incident, having slept 7 hours the previous night, and recorded a mental fatigue score of 3 (‘Okay, somewhat fresh’) for the time of the occurrence.
First officer
The first officer (FO) held a valid Air Transport Pilot Licence (Aeroplane) with a multi-engine aeroplane instrument rating, type ratings for the Airbus A320, Fokker FK70/100, Embraer EMB 120 and Dornier DO328-100 aircraft, and a Class 1 Aviation Medical Certificate. They had accrued 6,735 hours total flying experience with 1,556 hours on the F100. The FO reported being awake for 5 hours at the time of the incident, having slept 8 hours the previous night and recorded a mental fatigue score of 2 (‘Very lively. Responsive, but not at peak’) for the time of the occurrence.
Aircraft information
Fuel requirements and weight limits
In accordance with the forecast conditions, the QF1616 flight plan fuel for take-off from Perth comprised of 89 minutes flight fuel (3,614 kg), 11 minutes variable reserve (361 kg), 60 minutes holding fuel (1,733 kg) and 30 minutes fixed reserve (962 kg). This resulted in a minimum take-off fuel load of 6,670 kg. In addition, the aircraft was loaded with 36 kg of tanker fuel[25] and 100 kg of taxi fuel, resulting in a flight plan fuel load at engine start of 6,806 kg.
The operator’s fuel requirements included the option for an additional 10 minutes holding fuel (equating to about 290 kg), payload permitting. The flight plan indicated that this was removed due to the forecast payload. To allow for last minute, minor payload variations without exceeding maximum landing weight, flight dispatch was required to plan a tanker fuel limit that ensured a 300 kg buffer on maximum landing weight. Consistent with these requirements, the flight plan landing weight at Paraburdoo was 39,615 kg and the maximum landing weight was 39,915 kg.
At about 0553 (7 minutes prior to the scheduled departure), there was a last-minute change to the passenger and freight loads. This resulted in a reduced planned landing weight of 38,768 kg, which would have permitted the captain to take an additional 1,147 kg of tanker fuel. However, the aircraft had already been refuelled and the refueller had departed when the flight crew received their last-minute change.
Navigation system information
The aircraft was equipped with a flight management system (FMS), with an associated flight management computer (FMC). The FMS navigation source was the global navigation satellite system (GNSS). In GNSS mode, the FMS was certified for RNP[26] 2, RNP 1 and RNP 0.3 operations but the vertical navigation (VNAV) function was not certified. Therefore, Network Aviation could conduct RNAV approaches to the LNAV landing minima but did not have approval to conduct them to the LNAV/VNAV minima.
Aircraft communications addressing and reporting system
The incident aircraft was fitted with a non-operational aircraft communications addressing and reporting system (ACARS). The ACARS is a digital datalink system used for transmitting messages between the aircraft and ground stations via very high frequency (VHF) radio or satellite. This system provides another mechanism for flight crews to obtain weather information.
The Network Aviation Group-A F100 aircraft, which included the incident aircraft, were not fitted with satellite communications. Without satellite communications, the ACARS was limited to VHF line of sight with the ground stations.
According to the operator, the F100 fleet had a mixture of ACARS hardware units, and they were originally acquired without ground station connectivity and had no service provider. In 2016, 2 aircraft were selected for a feasibility study to test the technical viability and likely cost for activating the ACARS, which was then projected out to the remainder of the fleet. A business case, which included the activation of ACARS across the F100 fleet, was submitted in 2016 and the decision was made not to proceed with implementation at that point in time. This decision was based on a consideration of the range of projects underway across Network Aviation and a benefits analysis of implementing the solution. They had not considered including satellite communications in their ACARS business case and believed that most of their operational requirements could be met with VHF ground station connectivity. Network Aviation continues to operate the F100 aircraft and are not currently planning to implement ACARs on the fleet, however, they have not ruled out implementation of ACARs in the future.
Airport information
Paraburdoo Airport was an uncontrolled aerodrome with an elevation of 1,406 ft. The town of Paraburdoo is located about 5 NM west of the airport and lower terrain is located to the west of the town along a north-west to south-east divide (Figure 3). The airport had one runway, runway 06/24 (2,132 m long and 45 m wide), which had low intensity runway lighting installed and precision approach path indicator lighting set at a 3.0° slope for a threshold height of 50 ft, which were serviceable. The instrument approaches available included RNAV using GNSS for runways 06 and 24.
Figure 3: Paraburdoo (YPBO) terrain map
Source: Topographic-map.com, annotated by the ATSB
The LNAV landing minima for the RNAV approach was the minimum descent altitude (MDA) of 2,010 ft for runway 06 (604 ft above aerodrome level (AAL)) and 2,090 ft (684 ft AAL) for runway 24. The MDA could be reduced by 100 ft if an accurate QNH was obtained within 15 minutes of arrival, which reduced it to 504 ft AAL for runway 06 and 584 ft for runway 24. For the flight crew of QF1616, when flying a constant descent profile, they were required to add 50 ft to the MDA for the missed approach commencement altitude. Therefore, the flight crew operated to a minima of 1,960 ft (554 ft AAL) for runway 06 and 2,040 ft (634 ft AAL) for runway 24.
The aerodrome was equipped with an automatic weather station (AWS), which provided an automatic weather information service (AWIS) to flight crew, and meteorological METAR and SPECI reports to the Bureau of Meteorology (BoM) and Airservices Australia (air traffic services provider). Local radio traffic was conducted on a common traffic advisory frequency and air traffic services were provided by a Melbourne Centre flight information area (FIA) frequency.
Automatic weather station
A basic AWS has sensors for the temperature, dewpoint,[27] wind, QNH and rainfall data groups. At aerodromes, these basic AWS sensors are supplemented with a ceilometer and visibility meter. The ceilometer estimates cloud height by sending a laser light pulse near vertically through the atmosphere and using the back scatter[28] to measure cloud height. The AWS algorithm processes the raw sensor data every minute. While the current ceilometer data is used by the AWIS, the METAR and SPECI reports use the 30-minute average of data, but with the last 10 minutes given a double weighting to improve the response time to changing conditions. The BoM provided the following explanation for the difference between a ceilometer and human observer:
The ceilometer is an estimate based on the continuous sampling of a single point over a period of time (30 minutes for the ceilometer); whereas a human observer produces an estimate based on a view of the whole airfield and the whole sky over a short time prior to the observation.
According to the BoM, the AWS will trigger a SPECI report if the 10-minute average for the cloud base is below the highest alternate minimum[29] (1,664 ft at Paraburdoo) or 1,500 ft. A SPECI is also triggered if the 10-minute average for the visibility is below the highest alternate minimum (7,000 m at Paraburdoo) or 5,000 m.
If a data group is not available when a METAR or SPECI report is produced by the AWS, then this is indicated by solidi; ‘////’ for visibility, ‘//’ for weather and ‘//////’ for cloud. This is broadcast by the AWIS as ‘[data group] not available’.
Meteorological information
The flight plan for QF1616 provided the flight crew with the aerodrome forecasts (TAFs) for their departure, destination, and company approved alternate aerodromes. The FO programmed Karratha Airport as route 2 in the FMS and the flight crew discussed Karratha, Newman Airport and Solomon Airport as divert options after the second and third missed approaches at Paraburdoo. Therefore, the investigation of meteorological information focussed on the forecast and actual conditions for these aerodromes.
Flight plan forecast conditions
Paraburdoo
At the scheduled departure time from Perth of 0600, the forecast mean conditions for Paraburdoo were light rain with scattered cloud at 1,000 ft AAL, broken cloud at 3,000 ft, and visibility greater than 10 km with a TEMPO period until 1100 for broken cloud at 1,000 ft and visibility reduced to 4,000 m with moderate rain showers. The Paraburdoo METAR conditions, issued at 0430, reported rain, scattered cloud at 4,500 ft, 5,700 ft and 6,700 ft, wind from 060° at 8 kt, and the temperature and dewpoint were 20 °C and 19 °C respectively.
Newman
The forecast cloud and visibility conditions for Newman were the same as Paraburdoo with the exception that the TEMPO period extended until 1400. The Newman METAR conditions, also issued at 0430, reported cloud overcast at 11,000 ft and the weather data group was not available.
Karratha
The forecast mean conditions for Karratha were light showers of rain with scattered cloud at 2,000 ft, broken cloud at 5,000 ft, and visibility greater than 10 km. The conditions were forecast to improve at 0900 to no significant weather with scattered cloud at 5,000 ft. There was an intermittent period of variation from the prevailing conditions on the forecast that ended at 0400 for broken cloud at 1,500 ft and visibility reduced to 3,000 m in showers of rain. The METAR conditions, also issued at 0430, reported scattered cloud at 7,900 ft, overcast cloud at 11,000 ft, greater than 10 km visibility and the weather data group was not available. The flight plan did not include a forecast for Solomon.
Aerodrome weather reports
Paraburdoo
The Paraburdoo AWS issued the following observation reports on the morning of the incident (Table 1). For each of the times provided below, the QNH was 1013 and there were light rain showers, except for 0930 when the weather data group was not available.
Table 1: Aerodrome weather reports for Paraburdoo
Time
Type
Wind
Visibility
Cloud (above ground level)
Temp. (°C)
Dewpoint (°C)
0730
METAR
040° at 4 kt
>10 km
scattered at 500 ft
broken at 1,500 ft and 2,400 ft
21
20
0731
SPECI
040° at 4 kt
>10 km
scattered at 600 ft
broken at 1,500 ft and 2,400 ft
21
20
0751
SPECI
340° at 3 kt
reduced to 6,000 m
broken at 800 ft
overcast at 1,500 ft
21
19
0800
SPECI
330° at 4 kt, varying from 290° to 350°
reduced to 3,000 m
broken at 800 ft
overcast at 1,000 ft
21
20
0830
SPECI
260° at 7 kt
7,000 m
broken at 400 ft, 1,000 ft, and 1,300 ft
21
20
0839
SPECI
250º at 7 kt
7,000 m
broken at 500 ft and overcast at 1,600 ft
21
20
0845
SPECI
240º at 8 kt
6,000 m
broken at 400 ft, 700 ft and overcast at 1,700 ft
21
20
0900
SPECI
240° at 7 kt
>10 km
broken at 400 ft
overcast at 900 ft and 1,700 ft
21
20
0930
SPECI
250° at 5 kt
>10 km
scattered at 600 ft overcast at 1,100 ft and 1,500 ft
22
19
1056
SPECI
300° at 4 kt
>10 km
scattered at 1,300 ft
broken at 1,800 ft
overcast at 3,200 ft
24
20
1100
The aerodrome exited SPECI conditions.
The period in which the cloud base was broken below 1,000 ft extended from 0751 until 0930. Scattered cloud at 500–600 ft buffered this period. The actual conditions recorded by the AWS indicated a cloud base lower than the forecast conditions, which extended beyond the 30‑60‑minute duration for TEMPO conditions. According to the BoM’s analysis of the meteorological conditions at the time of the incident, the TAF for Paraburdoo was amended to alternate conditions in low cloud at 0834, which was 4 minutes after the TEMPO holding period of 60 minutes was no longer satisfying the observed conditions. Overall, the observed weather reports included a cloud base below the highest alternate minima of 1,664 ft for 3 hours 26 minutes, from 0730 to 1056.
Newman
The reports for Newman indicated the AWS weather and cloud data groups were not available for the period 0600-1000. In this period, 11 reports were issued, 9 METAR and 2 SPECI reports. The SPECI reports were for a reduction and subsequent improvement in the visibility at 0934 and 0944 respectively. As the cloud data group was not available, it could not be determined if Newman was suitable at the time the captain requested the latest weather from air traffic control for this location.
Karratha
The reports for Karratha indicated the cloud base was above 10,000 ft from 0730–1000, and the visibility was greater than 10 km for the period 0600-1000. Therefore, the weather reports for Karratha indicated it was a suitable diversion option during the period of the incident.
Solomon
From 0600-1000, 16 reports were issued for Solomon, which consisted of 12 SPECI and 4 METAR reports. At 0804, the lowest cloud was broken at 600 ft, which was below the lowest landing minima, and therefore it was unsuitable at the time the flight crew were considering it. At 0841, the cloud was scattered at 500 ft and 1,400 ft, and broken at 2,100 ft with 5,000 m visibility. The weather data group was not available for this period.
Development of low cloud base at Paraburdoo
The BoM noted that Paraburdoo was outside the optimal range[30] for the nearest weather radar stations, located at Learmonth (210 NM) and Dampier (162 NM). At these distances, any echoes appearing on the weather radar displays would be from clouds higher up in the atmosphere and thus not representative of conditions closer to the surface. So, while Paraburdoo appeared clear of rain on the weather radars at the time of the incident, light showers of rain reported on the METARs indicated that this was not the case. Nearby weather stations all recorded rainfall and it was likely that the light rain or drizzle was widespread due to a rainband over the area. The BoM further stated that the period of low visibility leading up to the incident further supported the presence of precipitation.[31] It was likely that the rainfall provided extra moisture through evaporative processes as it fell into unsaturated air, which is known as the wet bulb effect.
The BoM also reported that the wind direction was likely a contributing factor for the low cloud base, which backed from the north-east at 0730 to the north-west at 0751 and around to the west at 0830. When the wind blows from the west, the local terrain surrounding Paraburdoo forces the air to rise. Rising air cools, while the amount of moisture remains constant, thus reducing the dewpoint depression[32] and promoting the development of low cloud as the air becomes saturated. This process is known as orographic uplift and results in upslope stratus[33] cloud. Therefore, the BoM concluded that the mechanisms that produced the low cloud at Paraburdoo were a combination of the wet bulb effect due to moistening of the airmass from rainfall and the orographic uplift provided by the terrain.
On their first approach at Paraburdoo, the flight crew noted they had a tailwind component to runway 06, despite the AWIS indicating the surface wind was north-easterly. The BoM reported that the winds described by the flight crew indicated the layer of wind above the surface layer would have been ascending as it flowed over the terrain. If this layer was close to saturation, then this could have promoted the formation of low cloud. The BoM indicated that ‘meteorological theory supports this conclusion if all factors were to line up, but it can’t be stated for certain.’
Forecasting for Paraburdoo
The Paraburdoo TAF used by the flight crew during pre-flight planning was issued at 0208 with a validity period from 0200 to 2000. The BoM reported that, at 0200, there had been observations of scattered cloud at 1,000 ft at nearby airports, which supported the TEMPO forecast for broken cloud at 1,000 ft at Paraburdoo. Early in the morning, broken cloud at about 1,000 ft was observed at various locations, mostly for periods of less than 1 hour at a time. Meteorological model guidance was forecasting the low cloud would lift at around 0800. However, from the duty forecaster’s experience, low cloud would persist in the Paraburdoo area longer than what the modelling generally indicated. As a result, a conservative approach was taken regarding the timing of the TEMPO and the Paraburdoo TAF issued at 0208 retained the TEMPO for broken cloud at 1,000 ft until 1100.
The BoM’s model traces had indicated saturated levels through to near to the surface. However, modelling in northern Australia was subject to false alarms for widespread low cloud. Therefore, some form of surface verification and/or satellite observations were required for them to have confidence in the modelling. They noted that the lifting trend in the modelling did not occur, and cloud bases dropped further below the highest alternate minima after 0700 and persisted for longer than the 1-hour TEMPO periods. They reported that, this event was difficult to forecast accurately, given modelling false alarms and the lack of observed lower cloud and satellite imagery available prior to the onset of very low cloud at Paraburdoo. The cloud that lowered significantly after 0700 contrasted with what they would normally expect, where the surface heating would lift the cloud base rather than for it to lower further.
The 0208 TAF forecast the temperature to rise throughout the morning. However, the AWS recordings indicated a slower temperature rise than what was forecast and a small dewpoint depression. The following table presents the TAF forecast temperatures and the recorded AWS temperatures and dewpoints on the morning of the incident.
Table 2: Aerodrome forecast (TAF) and automatic weather station (AWS) temperatures and dewpoints
Time
0200
0500
0800
1100
TAF temperature (°C)
20
22
23
25
AWS temperature (°C)
20
20
21
24
AWS dewpoint (°C)
19
19
20
21
Sources of atmospheric moisture
The BoM reported that the depth of moisture through the atmosphere is important in determining the potential for low cloud development. There are not many observation sources that indicate the depth of moisture in an airmass, except for balloon soundings and aircraft meteorological data relay (AMDAR). There were no weather balloons or AMDAR profiles available at Paraburdoo to provide atmospheric data, including the depth of moisture in an airmass and there is currently no plan to install a weather balloon station, or a weather radar, at Paraburdoo.
Weather balloons and radar
Balloon-based weather observations provide precise measurements of temperature, pressure, humidity, wind speed and direction. The BoM released about 56 balloons each day from 38 locations.The main items attached to the balloon are a foil-coated cardboard target used to slow the descent of the balloon and track it with radar, and a small white plastic box known as a radiosonde, which has the sensors used to measure meteorological variables.
During the radiosonde’s flight it is constantly transmitting the meteorological data to ground equipment, which processes and converts the data into weather messages and is displayed as an aerological diagram for use by forecasters. The aerological diagram allows forecasters to obtain a snapshot of the atmosphere above a specific location to determine the atmosphere’s stability and forecast the lower and upper levels of clouds and their types.
The nearest weather balloon stations were Port Hedland, Learmonth, and Meekatharra. These locations were 175-210 NM from Paraburdoo and not guaranteed to be representative of the conditions at Paraburdoo. Figure 4 depicts the nearest weather balloon stations to Paraburdoo (blue) and the nearby airports (West Angelas (YANG), Barimunya (YBRY), Eliwana (YEWA) and Christmas Creek (YCHK), in green) where the 0200 observation of scattered cloud at 1,000 ft was used to support the incident TAF conditions.
Figure 4: Weather balloon stations relative to Paraburdoo
Source: Google Earth, annotated by the ATSB
According to the BoM, the spatial distribution of the upper air network is designed to meet the requirements of national and regional numerical weather prediction models. The spatial density was reviewed in 2022 and found to meet the requirements set by the World Meteorological Organization for numerical weather prediction. The weather radars are targeted to areas where significant or hazardous weather intersect with areas of highest community need. While this covers 98% of the population, much of inland Australia, such as Paraburdoo, are not covered. Consequently, no precipitation was detected at Paraburdoo by the nearest weather radar stations at Learmonth and Dampier at the time of the incident.
Aircraft meteorological data relay
The World Meteorological Organization, in cooperation with some international airlines, has established the aircraft meteorological data relay program (AMDAR). The AMDAR system predominantly utilises existing aircraft onboard sensors, computers, AMDAR software and communications systems to collect and transmit meteorological data to ground stations via satellite or radio links using ACARS. This data is then relayed to national meteorological and hydrological services. These observations supplement the data gathered by other meteorological instruments and help to improve the accuracy of forecasts.
Vertical profiles of the atmosphere are taken when the aircraft climbs or descends during the departure or arrival phase of flight. According to the World Meteorological Organization guide to aircraft-based observations (ABO):
Vertical profiles derived from ABO should be considered as being very similar in character and application to those derived from meteorological radiosondes. AMDAR and other ABO generally provide an improvement in forecasting ability through a reduction in NWP [numerical weather prediction] forecast error of 10%–20% over the first 24 hours of the forecast period.
The AMDAR profiles coverage for Western Australia throughout the month of November 2021 is shown in Table 3 (fractional profiles are the result of averaging over multiple weeks). Paraburdoo was not part of the AMDAR network.
Table 3: AMDAR profiles Western Australia in November 2021
Airport name
Profiles taken (per week)
Broome International
1.69
Christmas Creek Station
6.52
Fortescue Dave Forrest
2.90
Ginbata
9.41
Newman
4.10
Karratha
13.03
Kalgoorlie Boulder
5.55
Port Hedland International
14.48
Perth International
125.52
Sources of in-flight weather updates
Air traffic control
According to the Airservices Australia Aeronautical Information Publication (AIP) section GEN 3.3.4, air traffic control provides pilots with pertinent information that will affect flight within one hour’s flight time. At the time the information is identified, it will be directed to pilots maintaining continuous communications and broadcast on appropriate air traffic services frequencies.
In November 2018, a new filtering system for SPECI reports was launched by Airservices Australia. The new system assessed SPECI reports for all locations and provided more specific filtering to identify significant SPECIs. Air traffic control then directed these SPECI reports to affected pilots within one hour’s flight time. However, SPECIs were only disseminated if they differed from the associated TAF.
For example, the Paraburdoo SPECI issued at 0731 was for the cloud base below the highest alternate minima, which was expected with the TEMPO forecast on the TAF. Therefore, there was no requirement to disseminate this SPECI. However, the 0830 SPECI with broken cloud at 400 ft differed significantly from the TAF conditions and was therefore broadcast by ATC at 0834.
Automatic en route information service
The automatic en route information service (AERIS) continuously broadcasts METAR, SPECI and TAF information from a network of VHF transmitters installed around Australia. However, there are many gaps in the coverage provided across Australia. The nearest AERIS station to Paraburdoo was Meekatharra. This station broadcasted information for several airports, which included Paraburdoo and Karratha. However, as Paraburdoo was located about 210 NM north of Meekatharra and, disregarding any local terrain shielding effects, an aircraft would have to be at an altitude of about 36,500 ft overhead Paraburdoo for AERIS reception. Therefore, while holding and conducting missed approaches at Paraburdoo, the aircraft was too low to receive Meekatharra AERIS broadcasts.
The flight from Perth to Paraburdoo passed through the Meekatharra AERIS coverage and could have been used to update the actual weather conditions for Karratha, which was route 2 in the FMC. However, the flight crew were operating with holding fuel for Paraburdoo and no expectation that they would need to consider Karratha.
Aircraft communication addressing and reporting system
The ATSB discussed the potential use of ACARS for weather updates in-flight with the flight crew. The captain reported no previous experience with ACARS, but provided the following comments about its potential benefit in this incident:
Had we been able to utilise the ACARS for weather information it may have further allowed us to also get weather for other aerodromes and perhaps with that information have gone somewhere else.
The FO, who had previous experience using ACARS, provided the following comments about its potential benefit:
The Fokker have ACARS in them, but they’re not connected, whereas with other aircraft we could just dial it into the computer and request the ATIS or the TAF on any airport and get an automatic update – we don’t have to rely on anyone. It was busy that day, you could tell the controllers were working hard, when I said we waited for the weather for 15 minutes, he was busy, it wasn’t like he was ignoring us.
According to the Société International de Télécommunications Aeronautiques, who are the ACARS ground station gateway service provider in the Australian region, the nearest VHF datalink ground station to Paraburdoo was located at Newman, which was about 115 NM to the east. Disregarding any local terrain shielding effects, without a satellite connection the aircraft would have required an altitude of about 11,000 ft overhead Paraburdoo to receive weather information via the ACARS.
Diversion options
The captain reported that their nearest preferred diversion airports were Karratha and Newman. The Karratha AWS was reporting a cloud base above 10,000 ft, whereas Newman had the same TEMPO forecast as Paraburdoo, and the cloud base was unknown. While they considered Solomon after their third missed approach, a SPECI was subsequently issued with cloud below the landing minima.
The ATSB used the fuel figures reported by the flight crew at interview and on the cockpit voice recorder to estimate the fuel on board (excluding fixed reserve) and potential diversion range of the aircraft after each missed approach, with reference to the airports of Karratha, Newman and Solomon.
The Network Aviation F100 aircraft performance manual indicated FL 160 was the optimum level for a diversion of 150 NM (Karratha was 157 NM) and FL 110 for 100 NM (Newman was 115 NM). The FL 150 performance table figures were the closest to FL 160 and indicated the range from the first missed approach was about 242 NM,[34] and about 155 NM from the second missed approach. The A100 (10,000 ft) table figures were the closest to FL 110 and indicated the range from the third missed approach was about 84 NM (Solomon was 55 NM).
The captain recalled that they did not consider diverting after the first missed approach and that the FMC indicated they were at the minimum fuel for a diversion to Karratha after the second missed approach. The FO had set route 2 in the FMC to Karratha, and it was calculating the fuel direct to Karratha from their present position. However, the captain recalled that the FMC calculation did not consider the actual winds that would be experienced en route, or the additional fuel for an instrument approach if it was required at the destination.
The captain and FO reported that they decided minimum fuel was insufficient to divert to Karratha after the second missed approach without current weather, noting they would be committed to a landing on arrival. The captain recalled that they had looked at the forecast but were not aware of the actual weather conditions at Karratha. Consequently, they considered Karratha to be a ‘worse choice than staying at Paraburdoo where we did have the fuel to hold’. The FO also recalled that they had a discussion after the second and third missed approaches but concluded that they did not have enough fuel to divert anywhere safely without an updated weather forecast.
The flight crew subsequently decided to request a weather update for Newman as they heard QF1802 reporting to ATC at 0759 that they had landed at Newman, which occurred between their first and second missed approach. However, the captain reported that a diversion to Newman would have only been considered if ATC had reported significantly better weather as it also had TEMPO holding on the forecast and they had insufficient fuel to comply with that requirement. The use of Solomon was considered after the third missed approach, but then dismissed as the landing minima there was higher than the minima at Paraburdoo. Figure 5 depicts the estimated nil wind diversion range from each missed approach (242 NM, 155 NM, and 84 NM) and the airports that were under consideration by the flight crew.
Figure 5: Approximate nil wind diversion range from each missed approach
Source: Google Earth, annotated by the ATSB
Organisational and management information
Diversion decision-making guidance
According to the Network Aviation Aerodrome and Route Data Manual, the preferred alternates for Paraburdoo were Karratha or Port Hedland. The flight crew had Karratha loaded in the FMC as route 2, but they did not obtain a weather update for Karratha before arriving at Paraburdoo. Their flight plan weather forecast and AWIS at top of descent indicated they would be visual before reaching the MDA. The operator noted that the weather forecast for Karratha was well above landing minima with no expectation of deterioration, and that ATC would broadcast if a SPECI was issued. Consequently, there was no company expectation or requirement for the flight crew to obtain updated weather for Karratha while en route to Paraburdoo.
According to the International Civil Aviation Organization (ICAO) Doc 8168 (2018), Aircraft Operations (Vol 3) – Aircraft operating procedures, standard operating procedures ‘provide guidance to flight operations personnel to ensure safe, efficient, logical and predictable means of carrying out flight operations’. Therefore, the ATSB asked the operator if they had considered a diversion decision-making procedure.[35],[36] They did not consider a prescriptive procedure necessary but had published a standard operating procedure to limit the number of missed approaches. The Network Aviation Flight Administration Manual provided the following information:
8.59.2 Multiple Missed Approaches
Multiple Missed Approaches are not only distressing to passengers, but can also increase the risk of incident or accident. Therefore, during normal operations, Flight Crew should limit the number of weather-related Missed Approaches to two. A third approach in these circumstances should not be immediately attempted unless the Pilot In Command believes there is a high probability of a successful approach and landing, or greater emergency or operational requirement exists.
With respect to procedure 8.59.2, the captain reported that it was not weather-related or considerate of a fuel-critical state and the FO indicated there was insufficient fuel to divert after 2 missed approaches. The captain further stated that their interpretation of the procedure was that it was intended for the benefit of the passengers and to only continue if confident a landing would be made from the third approach. The chief pilot noted that, while it was worded from the perspective of passenger comfort, it did have a secondary intent of not continuing to conduct approaches in unsuitable conditions, and the 2 missed approaches were a limit unless there was an expectation that a landing would be made from the third approach.
The operator did not consider a prescriptive diversion decision-making procedure necessary. However, after the incident, they noted flight crew could benefit with better tools to assist their diversion decision-making process. For example, company flight plans included a summary on the possible diversion locations only when the flight legally required an alternate.
The operator also noted that they did not have a requirement for their flight crews to brief their minimum divert fuel at the top of descent. They had not provided a procedural expectation that this would be briefed, although it was a common practice for one of their management pilots in their previous employment. The operator considered that, if the flight crew had briefed their minimum divert fuel for Karratha as part of their arrival briefing for Paraburdoo, it might have influenced their decision-making.
The operator’s observations were consistent with ICAO Doc 8168 (2018), which stated that ‘Crew briefings communicate duties, standardize activities, ensure that a plan of action is shared by crew members and enhance crew situational awareness’. The objectives for flight crew briefings for safety-critical actions included:
a) refreshing prior knowledge to make it more readily accessible in real-time during flight;
b) constructing a shared mental picture of the situation to support situational awareness;
c) building a plan of action and transmitting it to crew members to promote effective error detection and management; and
d) preparing crew members for responses to foreseeable hazards to enable prompt and effective reaction.
The section for arrival briefings in ICAO Doc 8168 (2018) also provided the following information:
3.5.4 Flight crew arrival briefings should prioritize all relevant conditions that exist for the descent, approach and landing. They should include, but not be limited to:
…
h) alternate aerodromes and fuel considerations;
While this incident involved unforecast low cloud, and alternate aerodromes were not required for the flight plan, the operator noted, that even on a clear weather day, a preceding aircraft could have an accident at the destination airport, which could require a diversion.
Risk management
Bowtie risk assessments
Network Aviation, a subsidiary of Qantas, used the Qantas Group safety management system Risk assessment procedure and risk assessment guide for their risk management processes. Among their various tools was a bowtie risk assessment software. According to the software user manual (2019):
Risk in bowtie methodology is elaborated by the relationship between hazards, top events, threats and consequences. Barriers [also known as controls or defences] are used to display what measures an organization has in place to control the risk.
The top event represents the loss of control of the hazard (undesired aircraft state), and damage or injury is represented by the consequence(s). A threat is a factor that ‘itself should have the ability to cause the top event’ (Figure 6). While aviation traditionally distinguishes between threat and error, the software program used threat as the descriptor for both.
When the risk assessment is constructed with multiple threats on the left side and consequences on the right side of the top event, a bowtie like structure appears. Between the threats and the top event are the preventive controls, to reduce the likelihood of the top event occurring. Between the top event and the consequences are the recovery controls, to reduce the likelihood and/or severity of the consequences.
Figure 6: Example bowtie structure
Source: ATSB
United Kingdom Civil Aviation Authority bowties
The United Kingdom (UK) Civil Aviation Authority (CAA) initiated a ‘Significant Seven’ task force in 2009. From this they then developed a series of bowtie risk assessments, known as the ‘Significant Seven’, with 3 bowties for each of the 7 risks. They were published on their website in their software file format so that they could be downloaded and customised by industry. According to the CAA website the scope of the Significant Seven project was focussed on the risks that contribute to UK commercial air transport fixed-wing operations. The operating environment and equipment were generic but UK oriented, therefore they recommended the following:
Aircraft operators can be expected to encounter operating environments outside the scope of the bowtie templates during international operations and these conditions are an example of issues that should be addressed when customising the bowties.
Their Significant Seven included controlled flight into terrain (CFIT) with the 3 bowties CFIT 3.1, CFIT 3.2 and CFIT 3.3, with revision dates 2013-2014. The CAA website provided the following information about their CFIT risk assessments:
The structure of the CFIT bowties is such that generic issues related to arrivals and departures are considered in bowtie 3.1 'Large CAT fixed-wing arrival or departure (general)/ Terrain separation deteriorating below normal requirements'.
Issues specific to non-precision or precision approaches have been addressed in their own bowties 3.2 and 3.3 respectively (e.g. both of these bowties should be considered in conjunction with the generic issues).
International Air Transport Association report
In 2018, the International Air Transport Association (IATA) published their CFIT research and analysis report for the period 2008-2017. They found that the highest frequency of accidents occurred in the approach phase of flight (24 from 47 accidents) and that ‘adverse weather’ was cited as a contributing factor in 51% of CFIT accident reports, ‘poor visibility / IMC’[37] in 46%, and ‘lack of visual reference including darkness and black hole effect’ in 33%. In addition, their report made the following observation about the role of situational awareness:
It is evident that most of the CFIT accidents result from a pilot’s breakdown in situational awareness (SA) instead of aircraft malfunction or a fire. In other words, these accidents are, for the most part, entirely preventable by the pilot. SA refers to the accurate perception by flight crew of the factors and conditions currently affecting the safe operation of the aircraft, and their vertical and/or horizontal position awareness in relation to the ground, water, or obstacles. The data shows that 49 percent of CFIT accidents had vertical, lateral or speed deviations as a contributing factor to CFIT accidents.
Network Aviation bowties
In 2019-2020, the Qantas Group Flight Operations Steering Committee (FOSC) downloaded, reviewed and amended the UK CAA bowties for CFIT 3.1, 3.2 and 3.3. After completing each review, the bowties were amended to ‘QF Group FOSC’ as the author and distributed to the operators within the group. The operators had the software and therefore could customise the bowties to their own operation if required. Network Aviation retained the FOSC copies of CFIT 3.1, 3.2 and 3.3 without amendment.
Following the incident, the ATSB asked the operator if they had a risk assessment relating to flight crews experiencing weather below the landing minima. They did not have a specific risk assessment for this scenario but provided a copy of their CFIT 3.1 with threat 8: Flt [flight] crew operate below the appropriate minimum altitude (exc. instrument approach) leading to the top event of terrain separation deteriorating below normal requirements during arrival or departure with the consequence of CFIT leading to hull loss. They considered this to be the closest risk assessment to the incident under investigation. On review of the CAA CFIT 3.1, it was noted that the original threat 8 was Flt crew continue approach below the MDA/DH without visual reference, with the note Commonly exposed. The remaining 7 threats were unchanged between the CAA bowtie and operator’s bowtie.
The operator’s bowtie preventive controls included Visual reference and Flt crew detect and recognise error via maintaining SA [situational awareness] … In addition, while their threat 8 captured their altimetry procedures as a control, it omitted some of their other existing procedural controls, such as their arrival briefing and approach checklist.
The CAA CFIT 3.1 threat 8 did not use Visual reference or Flt crew detect and recognise error via maintaining SA… as controls. However, situational awareness was used as a control by the CAA for other threats in CFIT 3.1 and in other bowties. This included CFIT 3.2, where Flt crew maintain SA via effective monitoring was included as one of the controls for the threat of Flt crew loss of Situational Awareness (SA) during a NPA [non-precision approach] and was reproduced in the operator’s CFIT 3.2 bowtie.
At interview, the operator acknowledged that they had treated Visual reference as a control, rather than as an aspect of the threat. On consideration of why threat 8 had been changed, they reported that CFIT 3.1 was considered from the arrival perspective – from the top of descent to the relevant lowest safe altitude, followed by a visual approach – and that CFIT 3.2 and 3.3 dealt with threats specific to an instrument approach. However, while the operator’s CFIT 3.2 and 3.3 were amended from the CAA versions, neither of them included the CAA CFIT 3.1 threat 8 of Flt crew continue approach below the MDA/DH without visual reference.
According to the Qantas Group Safety Management System Manual, the risk owner/risk assessment owner/risk register owner was responsible for:
ensuring that a comprehensive risk assessment is performed, and the progress and implementation of risk treatment plans is monitored
confirming that existing controls are fit for purpose and operating, designed, and periodically monitored.
Therefore, the ATSB queried the operator’s safety assurance, specifically whether the bowtie risk controls were subject to audit as part of their risk management review process. The operator reported that, in the design of their system-based audit of consequences, they utilised the bowtie as an audit tool, so the bowtie controls will be assessed as part of the audit. This was consistent with the ICAO Safety Management Manual, Doc 9859 (2013), which included the following:
The safety assurance process complements that of quality assurance, with each having requirements for analysis, documentation, auditing and management reviews to assure that certain performance criteria are met. While quality assurance typically focuses on the organization’s compliance with regulatory requirements, safety assurance specifically monitors the effectiveness of safety risk controls.
System safety design order of precedence
According to Stolzer et al. (2008), the field of system safety provided a categorisation scheme for evaluating hazard (risk) controls, and that it was important for the safety practitioner to understand this scheme so that appropriate decisions could be made. This scheme was the system safety design order of precedence (also known as the hierarchy of hazard control) and was described in the United States Department of Defence System Safety Standard Practice Manual (MIL-STD-882E)[38] in the following manner:
The goal should always be to eliminate the hazard if possible. When a hazard cannot be eliminated, the associated risk should be reduced to the lowest acceptable level within the constraints of cost, schedule, and performance by applying the system safety design order of precedence. The system safety design order of precedence identifies alternative mitigation approaches and lists them in order of decreasing effectiveness.
From MIL-STD-882E, the system safety design order of precedence was as follows:
eliminate hazards through design selection
reduce risk through design alteration
incorporate engineered features or devices
provide warning devices
incorporate signage, procedures, training, and personal protective equipment.
The use of humans to monitor, detect and correct problems, are not risk controls within the design order of precedence. Rather, it is the incorporation of controls in accordance with this scheme that shapes the required level of safety and human performance within the system. This is described in the ICAO Human Factors Training Manual, Doc 9683 (1998), as follows:
The control of human error requires two different approaches. First, it is necessary to minimize the occurrence of errors by: ensuring high levels of staff competence; designing controls so that they match human characteristics [reduce risk through design]; providing proper checklists, procedures, manuals, maps, charts, SOPs [procedural controls] … Training programmes aimed at increasing the co-operation and communication between crew members will reduce the number of errors [training controls] ... The second avenue to the control of human error is to reduce the consequences of the remaining errors by cross-monitoring and crew co-operation [procedural and training controls]. Equipment design which makes errors reversible and equipment which can monitor or complement and support human performance also contribute to the limitation of errors or their consequences [engineered features and warning devices].
The description for managing the risk of human error in ICAO Doc 9683 (1998) included design to reduce risk, procedural and training controls, and the incorporation of engineered features and warning devices. A similar approach was employed by IATA (2018) in their CFIT research and analysis report section on mitigation strategies, which targeted the 3 categories of human, procedural and technological. They included the following explanation for the meaning of human‑related mitigation strategies:
The available human mitigations involve improving and maintaining pilots’ knowledge, their awareness and their competence, and each of these can be achieved by a comprehensive training program embracing classroom, simulator and flight training.
Hence, the level of safety and human performance is managed by the design of the system, which is consistent with the approach suggested by Stolzer et al. (2008).
Similar occurrences
A search of the ATSB’s database for the period 2012-2021 for unforecast weather and low fuel events in the air transport high-capacity sector found 114 occurrences, of which 10 involved both events in the same occurrence. For unforecast weather events, this involved 67 occurrences (64 incidents, 2 serious incidents and 1 accident), and low fuel events found 57 occurrences (53 incidents and 4 serious incidents). There were no previous incidents reported for Paraburdoo Airport within this 10-year dataset.
The following is a summary of previous destination weather related occurrences, both in Australia and overseas.
On 18 August 2015, a Boeing 737-800, departed Doha, Qatar, for Cochin, India. On arrival at Cochin, the weather had deteriorated, and 3 missed approaches were conducted. The fuel reserve fell below the minimum required alternate of Bangalore during the third missed approach and the flight crew redesignated Trivandrum as their alternate. However, the weather conditions deteriorated at Trivandrum when they arrived, and a missed approach was conducted. This was followed by a MAYDAY fuel declaration and a request to attempt a visual approach. Three visual approaches were attempted with a landing made from the third. The fuel on shut down, after 7 approaches, was 349 kg, which was insufficient for any further approaches.
On 23 August 2013, a Eurocopter AS332 L2 Super Puma helicopter, collided with water while the flight crew were attempting to gain visual reference after reaching their MDA on approach to Sumburgh Airport, UK. The actual cloud base was lower than the original TAF forecast and the cloud base at their nominated alternate had also deteriorated, which probably would have precluded the flight crew from making a successful approach at their alternate.
On 18 June 2013, 2 Boeing 737 aircraft were on scheduled flights to Adelaide, South Australia. On nearing Adelaide, the forecast improvement in weather conditions had not occurred and as a result, both aircraft diverted to Mildura, Victoria. Upon arrival at Mildura, the actual weather conditions were significantly different to those forecast, with visibility reduced in fog. The flight crew of the first aircraft conducted an instrument approach and landed below the minima. The flight crew of the second aircraft also conducted an instrument approach and landed below the minima in fog with fuel below the fixed reserve.
On 18 November 2009, an Israel Aircraft Industries Westwind 1124A aircraft was operated on an air ambulance flight from Apia, Samoa to Norfolk Island, Australia. When the flight was planned, the aerodrome forecast for Norfolk Island indicated the weather conditions at the time of arrival would be above the alternate minima. However, on arrival at Norfolk Island, there was low cloud and the aircraft had insufficient fuel to divert to another airport. After 4 unsuccessful approaches, the flight crew ditched the aircraft 6.4 km west-south-west of the airport.
On 25 January 1990, a Boeing 707 flight from Bogota, Columbia, to New York, United States, was placed in a holding pattern 3 times due to poor weather conditions in the north‑eastern part of the United States for a duration of about 1 hour and 17 minutes. During the third period of holding, the flight crew reported they could not hold longer than 5 minutes, that they were running out of fuel, and could not reach their alternate airport. Subsequently, they executed a missed approach and then lost power to all engines due to fuel starvation and collided with terrain while attempting a second approach.
Safety analysis
Introduction
On the morning of 22 November 2021, a Network Aviation Fokker Aircraft F100, registered VH‑NHV and operating as flight QF1616, departed Perth Airport on a scheduled passenger service to Paraburdoo Airport, Western Australia. On arrival at Paraburdoo, the flight crew conducted 3 missed approaches due to unforecast low cloud. On the fourth approach, the flight crew continued the approach below the landing minima without visual reference to the runway due to the aircraft’s fuel state.
This analysis will discuss the flight crew’s decision not to divert, the eventual landing below minima, and the reason for the unforecast low cloud. The delay in an air traffic control weather update, and limitations associated with in-flight access to weather while holding at Paraburdoo and weather forecasting at the airport, will also be discussed. It will also consider the operator’s procedural guidance and risk management for unforecast weather.
Decision not to divert
After downloading and reviewing their flight plan before take-off, the flight crew noted they had a 60-minute holding fuel requirement for Paraburdoo. However, both the mean and holding weather conditions indicated the lowest cloud was forecast to be above their landing minima. Therefore, they departed Perth with the expectation of landing from their first approach. This expectation was likely reinforced by the automatic weather information service (AWIS) broadcast prior to top of descent, which indicated the lowest cloud was 2,100 ft above the airport. Consequently, their first missed approach at Paraburdoo was unexpected.
The 0730 AWIS update during the descent indicated that low cloud had started to develop at 500 ft above the aerodrome, which was below their landing minima. However, the concurrent air traffic broadcasts on the other radio may have interfered with the flight crew hearing this information as the captain reported that the QNH was the only change noted. Since an accurate QNH must be obtained within 15 minutes of commencing an approach for the minima to be reduced by 100 ft, it was likely that this was their reason for listening to the AWIS during the descent.
When they conducted their first approach, the flight crew momentarily became visual with the runway but realised they would have been too steep to attempt the landing. However, the combination of the visual contact and tailwind on the first approach, provided them with confidence that a second approach to the opposite runway would be successful. Further, the cloud they encountered on the first approach was lower than forecast, which suggested to them that the first approach was likely flown in the worst of the expected conditions. They did not consider at this stage that the conditions might worsen. Therefore, they elected to immediately conduct a second approach, which was also unsuccessful due to low cloud obscuring the runway.
It was after the second missed approach that the flight crew realised the weather was more concerning than expected. At this stage, the deterioration in the actual conditions at Paraburdoo likely resulted in them losing confidence in their flight plan weather forecasts for decision-making purposes.
The weather reports for the airports under consideration for diversion by the flight crew indicated that Karratha Airport was the only suitable diversion. After the second missed approach, the flight management computer (FMC) indicated they were at minimum fuel to divert to Karratha, but the captain was cognisant that this did not allow for the winds they might experience or for an instrument approach on arrival at Karratha if required. In this case, they could not determine if they could reach Karratha with their fixed fuel reserve remaining. Consequently, without knowledge of the actual weather conditions, they elected to disregard Karratha as an option.
Instead, the flight crew requested a weather update for Newman Airport since it was closer, and another aircraft had landed there recently. However, the captain was aware the forecast had a holding requirement and was reluctant to commit to a diversion unless the actual conditions were better than forecast. Solomon Airport was also considered after the third missed approach but was disregarded due to having a higher landing minima than Paraburdoo.
Therefore, as they were still within their 60-minute holding fuel period and did not have immediate access to actual improved weather conditions elsewhere, the flight crew elected to conduct further approaches at Paraburdoo.
Landing below minima
The ATSB’s review of their estimated fuel load found that the flight crew likely had sufficient fuel to divert to Karratha or Newman immediately after their second missed approach, but not after their third missed approach. According to the forecasts and actual conditions, Karratha was suitable, but Newman was not, and an immediate decision was required to divert to Karratha. However, it was only after the second missed approach that the flight crew started to discuss diversion options and the fuel consumption during this period consequently precluded Karratha as an option.
After their third missed approach, a diversion to Solomon was their only other option. However, as the lowest landing minima at Solomon was higher than at Paraburdoo, they disregarded it. At the time, the cloud base at Solomon was below the minima and therefore it would not have been a suitable diversion if the flight crew had received the latest actual weather. Consequently, the flight crew were committed to conducting a fourth approach at Paraburdoo.
Before they commenced their fourth approach the flight crew briefed their plan and duties, and their contingency plan if the approach became unsafe. They subsequently descended below the runway 24 MDA of 584 ft above aerodrome level without visual reference on the approach. On achieving their visual reference at about 293 ft, the aircraft was stable on the glidepath and close to the extended runway centreline, which enabled them to land without further incident, 57 minutes after their first missed approach.
Cloud base
On the night prior to the incident flight, there were no meteorological observations from the Pilbara region of persistent low cloud. In addition, there was a layer of mid-level cloud overnight that should have limited the overnight surface cooling and had also obscured satellite imagery of any low-level cloud. Therefore, the presence of scattered cloud at 1,000 ft above aerodrome level at the surrounding aerodromes at 0200 was used as the justification for forecasting mean conditions at Paraburdoo of scattered cloud at 1,000 ft, with TEMPO conditions for broken cloud at 1,000 ft. This was above the flight crew’s landing minima for runway 06 and 24 of 604 ft and 684 ft respectively.
There was also an expectation that surface heating would lift the cloud base after sunrise. However, the lifting trend in the modelling did not occur and the cloud base lowered, remaining below the highest alternate minima from 0730 for 3 hours 26 minutes.
Distinct from the forecast conditions, at 0730, 16 minutes before the first missed approach, scattered cloud at 500 ft was reported by the automatic weather station (AWS). This deteriorated to broken cloud at 400 ft before the last approach. The AWS was still reporting broken cloud at 400 ft at 0900, 17 minutes after the aircraft landed. This deterioration was consistent with the flight crew’s observations that they experienced low cloud at the approach minima for all 4 approaches, and broadcast after landing that patches of low cloud were present at 250-300 ft.
It was likely that evaporation of rainfall added moisture to the atmosphere (wet bulb effect), as indicated by a reduction in the reported visibility from greater than 10 km at 0730 to 6,000 m at 0751. While the surface wind had not yet backed around to the west, the tailwind component reported by the flight crew on their first approach to runway 06 suggested the winds above the surface already had a westerly component. Airflow from the west is forced to rise over the terrain to the west of the airport and will cool, which results in the development of low cloud if the air becomes saturated (orographic uplift). Therefore, the low cloud that developed below the forecast conditions, was likely a combination of moistening of the airmass from rainfall and orographic uplift from the local terrain.
These conditions were considered difficult to forecast due to the absence of low cloud observed on the evening prior, any low-level cloud being obscured on the satellite imagery, and the lifting trend in the modelling not occurring. This discrepancy between the forecast and actual conditions resulted in the flight crew losing confidence in their flight plan aerodrome forecasts for diversion decision-making purposes, and initially misled them to believe that conditions would not deteriorate further after their first missed approach.
In-flight access to weather information
A decision to divert is a procedure-based decision-making exercise, which is also known as rule‑based decision-making. This is dependent on the situational awareness or knowledge of the problem, and knowledge of options (Flin, O’Connor, Crichton, 2008). When the flight departed Perth, the flight crew had incorrect knowledge of the weather situation that would unfold at Paraburdoo when they arrived. Although they passed within range of the Meekatharra automatic en route information service (AERIS), which would have provided them with the current weather for Karratha, there was no operational need for it at that stage, based on their assessment of the forecast conditions.
After the second missed approach, the flight crew’s discussions and actions indicated they had updated their assessment of the situation and were now actively seeking additional information about the weather conditions. This included the Paraburdoo AWIS (which was checked before each approach), air traffic control, and the Paraburdoo safety car officer. At this stage, they were holding at about 4,100 ft, which meant they were out of range of the Meekatharra AERIS, which required an altitude of about 36,500 ft to receive the broadcast.
The aircraft was fitted with the hardware for the aircraft communications addressing and reporting system (ACARS), which could be used to immediately access current weather information. However, the system was not operational, and therefore could not be used. If the system had been operative, they would have required a satellite link to use it, as they were holding below the required altitude of at least 11,000 ft to receive information from the nearest VHF datalink service at Newman. Therefore, with no other means to obtain current weather information while holding at Paraburdoo, the flight crew were reliant on air traffic control (ATC) to access weather information for alternate aerodromes.
If the flight crew had access to updated weather information using the AERIS or ACARS, it would have informed them that the cloud base was above 10,000 ft and visibility was greater than 10 km at Karratha. This would have indicated that Karratha was a suitable diversion location. However, without current weather information for alternative aerodromes, the flight crew elected to remain at Paraburdoo.
Atmospheric data
During the incident, a rain band and associated middle and high-level cloud was observed across north-western Australia by the Bureau of Meteorology (BoM). Their model traces had indicated saturated levels through to near to the surface. However, modelling in northern Australia was subject to false alarms for widespread low cloud. Therefore, some form of surface verification and/or satellite observations were required for the BoM to have confidence in the modelling. On the night prior to the incident, mid-level cloud made it difficult to utilise satellite observations to observe low cloud and confirm the modelling.
Light rain or drizzle had been falling at Paraburdoo. However, the extent of the rain was uncertain as Paraburdoo was outside the optimal range for the nearest weather radar stations. Therefore, it appeared clear on their weather radars at the time of the incident, despite the presence of low cloud and rain.
According to the BoM, the depth of moisture through the atmosphere is important in determining the potential for low cloud development. The sources available to indicate the depth of moisture are weather balloons and aircraft meteorological data relay (AMDAR). Data obtained from weather balloons allow forecasters to plot an aerological diagram and forecast cloud bases and tops. However, the nearest weather balloon stations were more than 160 NM from Paraburdoo and may not necessarily be representative of the conditions experienced at Paraburdoo. Furthermore, as Paraburdoo was not part of the AMDAR network, no AMDAR profiles were available to support the BoM forecasts for Paraburdoo.
The accuracy of forecasting is dependent on the data available. As Paraburdoo did not have the means to provide forecasters with a vertical profile of the moisture through the atmosphere, and satellite imagery was not available due to being obscured by mid-level cloud, the forecast was dependent on observations at other airports in the region. Therefore, the lack of atmospheric measurements increased the risk of an inaccurate projection of the conditions for Paraburdoo including unforecast low cloud below the instrument approach landing minima. While the current BoM plans for upgrading weather balloon and weather radar stations around Australia do not include Paraburdoo Airport, the ATSB did not identify a trend from the last 10-years of data associated with this airport to warrant a safety issue at this stage.
Diversion procedure
The forecast conditions for Paraburdoo required 60 minutes TEMPO holding fuel, but no alternate was required. Despite this, the flight crew were expecting to obtain visual reference with the runway before reaching their minimum descent altitude for the approach. This expectation was likely reinforced by the AWIS recording before top of descent, which indicated the lowest cloud base was 2,100 ft above the aerodrome. However, on arrival, the flight crew were confronted with 2 unforecast weather hazards. The cloud base had deteriorated below their landing minima, and it did not lift within the 60-minute TEMPO period.
As discussed previously, a diversion is a procedural decision-making exercise, which requires knowledge of both the problem and the options available (Flin, O’Connor, Crichton, 2008). Therefore, a diversion decision-making procedure should serve the purposes of guiding the flight crew to correctly assess the problem and then select an appropriate course of action.
The operator had published a procedure, which limited the number of missed approaches to 2, but they did not believe a prescriptive decision-making procedure was necessary. However, even after the first missed approach, the flight crew were expecting to land from their second approach and there was no discussion of the limits to conducting missed approaches nor consideration of their fuel reserve for a diversion.
After the second missed approach, the flight crew only had a few minutes in which to decide to divert to Karratha, which was the nearest suitable alternate airport. However, they had not briefed this option. Therefore, instead of committing to a diversion after the second missed approach, they entered a holding pattern and started to diagnose the actual weather conditions and their options.
The operator’s limit to missed approaches did not provide guidance for flight crew to brief their divert options before arrival or on encountering unforecast weather at their destination. The arrival briefing procedural guidance from the International Civil Aviation Organization (Doc 8168, 2018) included ‘alternate aerodromes and fuel considerations’, and while this was within the context of ‘relevant conditions’, unforecast weather is a hazard frequently reported to the ATSB and that has been the subject of previous accident and incident investigations. In this case, if the flight crew had briefed their divert options before arrival, they would have been better placed to manage the unforecast weather conditions they encountered at Paraburdoo. Therefore, a diversion procedure should be considered within an organisation’s risk controls and the absence of this decision‑making guidance increased the risk that flight crew would not be prepared for a diversion.
Risk management
The 3 United Kingdom Civil Aviation Authority’s (CAA) bowtie risk assessments for controlled flight into terrain (CFIT) were largely retained by the Qantas Group Flight Operations Steering Committee (FOSC) and subsequently Network Aviation, with minor amendments. One of the notable amendments was the replacement of the CAA CFIT 3.1 threat 8: Flt crew continue approach below the MDA/DH without visual reference with the FOSC CFIT 3.1 threat 8: Flt crew operate below the appropriate minimum altitude (exc. instrument approach). This was considered by the operator to be the closest risk assessment to the incident.
It was also noted that the operator’s CFIT 3.2 and 3.3 risk assessments for instrument approaches had not captured CAA CFIT 3.1 threat 8. Consequently, there were no weather-related threats identified in the operator’s CFIT bowties. In which case, there was no requirement to identify controls or treatment plans to manage these threats, despite a recent CFIT research and analysis report finding that adverse weather was cited as a contributing factor in 51% of accidents (IATA, 2018).
The operator’s CFIT threats relied on preventive risk controls such as visual reference and human performance for monitoring, detecting and correcting problems to maintain situational awareness. While the latter appeared to be inherited from the UK CAA bowties, research conducted by the International Air Transport Association indicated that operating in adverse weather conditions, poor visibility, and a lack of visual reference were considered contributing factors or threats to CFIT rather than risk controls. It was also noted that other procedural controls were used by the operator, but not included in the bowtie risk assessment. These included their arrival briefing and approach checklist, which, according to International Civil Aviation Organization (ICAO) Doc 8168 (2018), are designed to enhance situational awareness and therefore reduce the likelihood of an unintentional descent below the minimum altitude.
A reliance on human performance as a control to monitor, detect and correct problems within a risk assessment can result in an inherently unsafe system. If there is a human performance safety requirement associated with a specific threat, then this should be managed with the appropriate controls, such as training, procedures, and warning devices, as indicated by the International Air Transport Association CFIT mitigation strategies (2018) and ICAO (Doc 9683, 1998). They would then be subject to the safety assurance activities for that risk assessment.
The key environmental threat from this investigation that operators and flight crew need to manage is unforecast instrument meteorological conditions below minima at the destination. While forecast weather below minima is routinely effectively managed with a prescriptive ruleset, unforecast weather may be more likely to result in the need for an approach below minima without visual reference due to the development of a fuel-critical situation. Therefore, the absence of this threat from the operator’s CFIT risk assessment increased the risk that controls required to manage this threat would not be developed, monitored, and reviewed at a management level.
Weather update delay
Although the flight crew were aware that Newman had similar conditions to the Paraburdoo forecast, including a 60-minute holding fuel requirement, another aircraft had landed there between QF1616’s first and second missed approaches. This suggested to the flight crew that Newman might be a suitable diversion. As such, the captain informed ATC that they had conducted a second missed approach due low cloud at Paraburdoo and requested the latest weather for Newman. However, there was no urgency associated with this request and ATC asked them to standby for a response. Following this request, the flight crew and ATC diverted their attention to their other tasks, which included traffic inbound to Paraburdoo.
There was a delay of about 15 minutes before ATC queried if the flight crew still required the weather for Newman. At this stage, they had conducted a third missed approach and were likely below the minimum fuel required to divert to Newman, therefore the captain declined. While this delay precluded the flight crew considering the option of a diversion to Newman, both the cloud and weather data groups for Newman were not available for the period from 0600-1000. Without a meteorological observer at Newman, the latest METAR was the only current weather ATC could have provided the flight crew. In addition, the captain was reluctant to divert to another airport that had a holding fuel requirement they could not meet and might be subject to a similar weather pattern as Paraburdoo, unless the actual weather was better than forecast. As the current METAR did not provide an improvement to the forecast, it was unlikely that the provision of the latest weather information would have influenced the flight crew to divert to Newman and the delay was not considered contributory to the incident.
Despite this, ATC was the only option for the flight crew to obtain current weather for an alternate airport and the report of missed approaches at Paraburdoo associated with the request for the latest weather for Newman suggested this was likely a time-critical request. While the flight crew were within their TEMPO fuel holding period at Paraburdoo, they were approaching a fuel critical situation for a diversion to Newman. In this scenario, the inclusion of ‘minimum fuel’ with their request for the latest Newman weather could have reduced the likelihood of a delay, but probably would not have changed the outcome.
Newman automatic weather information service
The Airservices Australia new filtering system for SPECI reports was dependent on the conditions that trigger such reports being detected at the aerodrome. On the morning of the incident flight, there were 11 weather reports issued from the Newman AWS from 0600-1000. This included 2 SPECI reports for a reduction and subsequent improvement in visibility at 0934 and 0944. However, the cloud and weather data groups were not available throughout this period, which meant that Newman could have entered SPECI conditions undetected during this period.
As there was a delay in the information and the captain subsequently declined the weather update for Newman, this did not influence their decision to remain at Paraburdoo. However, if a SPECI condition is not detected at the source by an AWS, unforecast weather conditions may not be captured and disseminated by ATC to airborne aircraft as a hazard. While this is not a substitute for flight planning and in-flight weather update requests before reaching a point-of-no-return, the broadcast of unforecast SPECI conditions may provide a timely alert to flight crew to avoid a fuel-critical situation developing.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the unforecast weather and flight below minimum altitude involving Fokker Aircraft F100, registration VH-NHV, at Paraburdoo Airport, Western Australia, on 22 November 2021.
Contributing factors
The flight crew lost confidence in their flight plan weather forecasts after two missed approaches at Paraburdoo Airport. Without immediate access to actual weather information, they elected to conduct further approaches instead of diverting.
After the third missed approach, the flight crew had insufficient fuel to divert to a suitable airport and were committed to landing in conditions below their landing minima due to the continuing deteriorating cloud base.
The actual weather conditions encountered by the flight crew on arrival at Paraburdoo Airport were worse than the flight plan forecast, below the landing minima and deteriorating. This event was difficult to forecast accurately due to the lack of observed lower cloud, satellite imagery and meteorological modelling limitations.
The aircraft was not fitted with an operational aircraft communications addressing and reporting system (ACARS) and was out of range of the Meekatharra automatic en route information service (AERIS) while holding at Paraburdoo Airport. Therefore, the flight crew were reliant on air traffic control to access actual weather information for alternate aerodromes.
Paraburdoo Airport did not have a means of detecting the moisture content in the atmosphere above the surface. This increased the risk that low cloud below the instrument approach landing minima might not be forecast.
Network Aviation did not provide their flight crew with a diversion decision-making procedure for the circumstances where their flights encountered unforecast weather below landing minima. This increased the risk that their flight crew would not anticipate and be adequately prepared for a diversion. (Safety issue)
Network Aviation did not include the threat of unforecast weather below landing minima in their controlled flight into terrain risk assessments. This increased the risk that controls required to manage this threat would not be developed, monitored, and reviewed at a management level. (Safety issue)
Other factors that increased risk
The flight crew did not convey a sense of urgency to air traffic control when they requested the actual weather information for Newman Airport. This, combined with the controller's workload at the time, resulted in a delay of about 15 minutes before the information was offered. However, Newman Airport had a holding fuel requirement the flight could not comply with and as the actual weather did not include an improvement of conditions it was unlikely that this information would have influenced their decision to divert.
The Newman Airport automatic weather station cloud and weather data groups were not available at the time the flight crew requested the latest weather from air traffic control. While this did not influence the flight crew’s decision to remain at Paraburdoo, it increased the risk that a deterioration in the cloud base below the forecast conditions at Newman would not be broadcast by air traffic control to airborne aircraft as a hazard.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: Network Aviation did not provide their flight crew with a diversion decision-making procedure for the circumstances where their flights encountered unforecast weather below landing minima. This increased the risk that their flight crew would not anticipate and be adequately prepared for a diversion.
Safety issue description: Network Aviation did not include the threat of unforecast weather below landing minima in their controlled flight into terrain risk assessments. This increased the risk that controls required to manage this threat would not be developed, monitored, and reviewed at a management level.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Network Aviation
Internal safety advisory notice
Network Aviation issued an updated internal safety advisory notice to their flight crew, which highlighted the operating parameters and limitations associated with automatic weather information services (AWIS).
Airport risk assessment
Network Aviation updated their Paraburdoo Airport risk assessment to capture the risk of variable weather conditions and the procedural risk controls introduced in response to this incident.
Company fuel policy
Network Aviation amended their company fuel policy to mandate additional alternate fuel requirements for nominated airports (operator approved variations). Airport classification is assessed based on alternate availability, instrument approach availability, aerodrome forecast reporting and historical accuracy, local mesoscale weather phenomena, and topography/terrain.
Access to expanded port briefings
Network Aviation established access for flight crew to obtain expanded briefings on ports (with operator fuel policy approved variations) from internal company meteorologists.
Update to the Aerodrome and Route Manual
Network Aviation updated the company’s Aerodrome and Route Data Manual to provide a new section on weather planning tools and resources, and a new section explaining the limitations of ceilometers and visibility meters installed in automatic weather information stations throughout the company network.
Enhanced training reference library
Network Aviation enhanced the company’s training reference library for flight crew to support pilot knowledge and decision making. Additional content in the library is focused on company learnings from QF1616, which includes:
fuel management
threat management and contingency planning
time management in areas of vulnerability
pilot in command responsibilities.
Update to take-off and landing data cards
Network Aviation have updated their take-off and landing data cards to provide a dedicated section for recording the alternate aerodrome, estimated time interval, fuel burn and fuel on arrival.
Glossary
AAL Above aerodrome level
ACARS Aircraft communications addressing and reporting system
AIP Aviation information publication
AMDAR Aircraft meteorological data relay
ATC Air traffic control
AWIS Automatic weather information service
AWS Automatic weather station
BoM Bureau of Meteorology
CAA Civil Aviation Authority (UK)
CFIT Controlled flight into terrain
DH Decision height
FL Flight level
FMC Flight management computer
FMS Flight management system
FO First officer
GNSS Global navigation satellite system
IATA International Air Transport Association
ICAO International Civil Aviation Organization
LNAV Lateral navigation
MDA Minimum descent altitude
METAR Meteorological aerodrome report
PAPI Precision approach path indicator
PF Pilot flying
PM Pilot monitoring
RNAV Area navigation
SA Situational awareness
SPECI Special meteorological aerodrome report
TAF Aerodrome forecast
UK United Kingdom
VHF Very high frequency (radio frequency in the range 30-300 MHz)
VNAV Vertical navigation
YMEK Meekatharra Airport
YNWN Newman Airport
YPBO Paraburdoo Airport
YPKA Karratha Airport
YSOL Solomon Airport
Sources and submissions
Sources of information
The sources of information during the investigation included:
Aerodrome Management Services
the Bureau of Meteorology
Civil Aviation Safety Authority
data from the cockpit voice recorder and flight data recorder
Australian Transport Safety Bureau (2017) Fuel planning event, weather-related event and ditching involving Israel Aircraft Industries Westwind 1124A, VH-NGA, 6.4 km WSW of Norfolk Island Airport on 18 November 2009 (AO-2009-072 reopened). Retrieved from /publications/investigation_reports/2009/aair/ao-2009-072
Australian Transport Safety Bureau (2016) Landing below minima due to fog involving Boeing 737s, VH-YIR and VH-VYK, Mildura Airport, Victoria on 18 June 2013 (AO-2013-100). Retrieved from /publications/investigation_reports/2013/aair/ao-2013-100
Civil Aviation Safety Authority (2015) Extended Diversion Time Operations (EDTO) (Civil Aviation Advisory Publication 82-1(1), January 2015, Canberra.
Stolzer AJ, Halford CD and Goglia JJ (2008) Safety management systems in aviation, Ashgate, Aldershot.
United States Department of Defence (2012) System safety standard practice (MIL-STD-882E), United States Department of Defence, Washington DC.
World Meteorological Organization (2017) Guide to aircraft-based observations (WMO-No. 1200), World Meteorological Organization, Geneva.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
flight crew
Network Aviation management personnel
Civil Aviation Safety Authority
Bureau of Meteorology
Airservices Australia
Air Accidents Investigation Branch (United Kingdom).
Submissions were received from:
the United Kingdom Air Accidents Investigation Branch
Airservices Australia
Civil Aviation Safety Authority
Bureau of Meteorology
Network Aviation Management.
The submissions were reviewed and, where considered appropriate, the text of the draft report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.
[2] Minimum descent altitude (MDA) is the minimum altitude for a non-precision approach to obtain visual reference and decision altitude (DA) is the altitude at which a missed approach must be commenced from a precision approach if visual reference is not obtained.
[3] Aerodrome forecast (TAF): a statement of meteorological conditions expected for a specific period of time in the airspace within a radius of 5 NM (9 km) of the aerodrome reference point.
[4] Cloud cover is reported using words that denote the extent of the cover – ‘few’ indicates that up to a quarter of the sky is covered, ‘scattered’ indicates that cloud is covering between a quarter and a half of the sky, ‘broken’ indicates that more than half to almost all the sky is covered, and ‘overcast’ indicates that all the sky is covered.
[5] Cloud data is height above aerodrome elevation.
[6] TEMPO: a temporary deterioration in the forecast weather conditions, during which significant variation in prevailing conditions are expected to last for periods of between 30 and 60 minutes.
[7] Landing minima: specified meteorological conditions of cloud ceiling and visibility. For an aircraft to land at an aerodrome, the actual weather conditions need to be at or above the landing minima.
[8] INTER: an intermittent deterioration in the forecast weather conditions, during which a significant variation in prevailing conditions is expected to last for periods of less than 30 minutes duration.
[9] Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 350 equates to 35,000 ft.
[10] Pilot Flying (PF) and Pilot Monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
[11] Automated weather information service (AWIS): actual weather conditions, provided via telephone or radio broadcast, from Bureau of Meteorology (BoM) automatic weather stations, or weather stations approved for that purpose by the BoM.
[12] QNH: the altimeter barometric pressure subscale setting used to indicate the height above mean seal level.
[13] Dewpoint: the temperature at which water vapour in the air starts to condense as the air cools. It is used, among other things, to monitor the risk of aircraft carburettor icing or the likelihood of fog.
[14] On the cockpit voice recorder, most of the broadcast was inaudible due to traffic on the ATC frequency, except for the wind 040° at 4 kt and QNH 1013.
[15] A QNH obtained from an approved source within 15 minutes of conducting an instrument approach may be used to lower the MDA by 100 ft if the procedure is in a grey shaded box. Network Aviation standard operating procedures require their flight crew to fly a continuous descent profile for non-precision approaches and add 50 ft to the MDA.
[16] Due to the Melbourne Centre flight information area frequency volume, some of the flight crew discussions and automated weather information service broadcasts during the flight were inaudible due to concurrent radio traffic on the Melbourne Centre frequency.
[17] Pilot activated runway and taxiway lighting (PAL): PAL is activated by a series of timed transmissions using the aircraft’s very high frequency radio on a designated frequency.
[18] Precision Approach Path Indicator (PAPI): a ground-based system that uses a system of coloured lights used by pilots to identify the correct glide path to the runway when conducting a visual approach.
[19] In accordance with the Network Aviation Flight Administration Manual standard operating procedure 8.50: Automatic flight shall be used when possible for all instrument approaches when Instrument Meteorological Conditions (IMC) exist. Vertical speed mode (vertical navigation) and NAV mode (lateral navigation) were used for all approaches as per company recommendation for an RNAV approach.
[20] The operations normal call time provided the next expected transmission time from this aircraft to indicate operations were normal.
[21] QF1618 flight plan fuel load had 1,694 kg more than QF1616.
[22] MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.
[23] The ground proximity warning system is intended to alert the flight crew to a situation that could lead to ground contact and to warn of impending ground contact. During the incident flight, the system provided callouts to the flight crew on each approach, commencing from 2,500 ft above ground level.
[24] The aircraft’s flight data recorder did not record either fuel flow or fuel load parameters. Therefore, the flight data could not be used to analyse this information, which was the critical parameter for the flight crew in this incident.
[25] Tanker fuel is extra fuel uplifted from airports with a lower fuel price, such as capital city airports.
[26] Required navigation performance (RNP) levels refer to the performance required from the navigation system. RNP 0.3 means the aircraft navigation system must be able to calculate its position to within a circle with a radius 0.3 NM.
[27] The temperature to which air must be cooled, at constant pressure and water vapour content, in order for saturation to occur. If the air is cooled further, some of the water vapour will condense to liquid.
[28] The light pulse is scattered by aerosols including water droplets (clouds), and the component of light scattered back towards the ceilometer is measured.
[29] When operating instrument flight rules, the instrument approach chart will show the ceiling (cloud base height) and visibility minima to be compared with the meteorological forecasts and reports to determine both the need to provide for an alternate aerodrome and the suitability of that aerodrome as an alternate (ENR 1.5 section. 6: Alternate weather minima).
[30] The optimal range is generally within 110 NM of the weather radar station, terrain dependent, to capture rainfall echoes from clouds about 10,000 ft above mean sea level.
[31] Precipitation: Any product of the condensation of atmospheric water vapour that falls under gravity.
[32] Dewpoint depression: The difference between the temperature and dewpoint temperature at certain height in the atmosphere.
[33] A principal cloud type, forming in the low levels of the troposphere (the lowest layer of the atmosphere) and normally existing as a flat layer that does not exhibit individual elements.
[34] Calculations are based on nil wind from the start of the take-off roll with anti-icing on.
[35] A diversion decision-making procedure is a requirement for extended diversion time operations, but this was not applicable to the operator’s F100 fleet. Refer Civil Aviation Advisory Publication 82-1(1): Extended Diversion Time Operations (EDTO); ‘6.6.1 The operator’s operations manual must establish procedures for flight crew outlining the criteria that indicate when a diversion or change of routing is recommended whilst conducting an EDTO’.
[36] On 2 December 2021, 10 days after the incident, the new Civil Aviation Safety Regulations flight operations regulations commenced. This required all Part 121 operations to plan at least one destination alternate aerodrome when the relevant forecast weather was: less than 1,000 ft above the landing minima determined by the operator under regulation 121.185, or when the forecast visibility was less than the greater of 5km, or the landing visibility determined by the operator under regulation 121.185 plus 2 km.
[37] Instrument meteorological conditions (IMC): weather conditions that require pilots to fly primarily by reference to instruments, and therefore under instrument flight rules (IFR), rather than by outside visual reference. Typically, this means flying in cloud or limited visibility.
[38] While MIL-STD-882E, dated 2012, was the current version at the time of this incident, the original version was issued in 1969.
On 8 October 2021, a Kavanagh Balloons E-240 balloon, registered VH-LUD and operated by Floating Images Aust. Pty Ltd was conducting a morning scenic flight about 45 km south‑west of Brisbane, Queensland. On board was a pilot and 9 passengers. About 55 minutes into the flight, the pilot commenced a descent to locate a suitable landing area. During the descent, the balloon entered an area of localised fog where visibility reduced to 10 m.
The pilot continued the descent into the fog until a tree was observed in the path of the balloon. The pilot attempted to avoid the tree by initiating a climb, but the balloon collided with, and came to rest on the side of the tree, damaging the lower part of the balloon envelope. The pilot subsequently climbed the balloon off the tree and above the fog. The flight continued to an uneventful landing in a nearby paddock that was clear of fog. There were no injuries.
What the ATSB found
The ATSB found that, contrary to the visual flight rules visibility requirement, the pilot entered an area of reduced visibility in which the visibility was 10 m. This did not allow sufficient time to complete an avoidance manoeuvre when an obstacle was observed, as a result the balloon collided with a tree and the balloon envelope was damaged.
Safety message
In some circumstances, balloons are permitted to fly in significantly lower visibility than other types of aircraft. While this is mainly due to their inherently low flight speed, it also considerably reduces the available time to see obstacles. Additionally, as balloons can only manoeuvre vertically and significant time may be required to transition from a descent to a climb, they have limited capability to avoid obstacles.
Therefore, to reduce the collision risk if a balloon enters an area of visibility less than that permitted by the visual flight rules, pilots should ensure that an immediate recovery is commenced.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
On 8 October 2021, the pilot of a Kavanagh Balloons E-240 balloon, registered VH-LUD, was preparing for a morning scenic charter flight for 9 passengers from a location 45 km south‑west of Brisbane, Queensland. The pilot reported releasing a small helium balloon from the Ipswich Visitor Information Centre, located about 6 km to the east of RAAF Base Amberley (Figure 1), at 0425 Eastern Standard Time,[1] to observe wind speed and direction. The pilot also checked the wind observations recorded at the nearby RAAF Base, which were variable[2] at 3 knots.
Following an assessment, via the observation balloon, that the wind was from the west‑north‑west, the pilot planned the flight to commence at Rosewood Golf Club with an intent to track south-east, to the south of RAAF Base Amberley, and continue towards Yamanto (Figure 1). The pilot commented that there was no fog present at the departure time.
The 9 passengers arrived at the Ipswich Visitor Information Centre at about 0425 and they were taken to Rosewood Golf Club. The passengers were briefed on the 3 stages of balloon flying: inflation, flight, and landing. The pilot then inflated the balloon, and the passengers were boarded.
Although the pilot planned the flight in non-controlled Class G airspace[3] around RAAF Base Amberley, they made a telephone call to RAAF Amberley air traffic control and left a message on their answering machine with details of the balloon flight. The pilot reported that this was in case RAAF Amberley airspace became active during the period of the balloon flight and the airspace reverted to military Class C airspace[4] (see the section titled Airspace).
The balloon took off at around 0520 and tracked towards the east-south-east as expected from the wind observations. The pilot reported clear skies with some localised fog present to the south‑east of the RAAF base. The pilot estimated the fog to be from the surface to a height of 500 ft.
Figure 1: Flight path of VH-LUD
Source: Google Earth, annotated by the ATSB
After about 55 minutes of flight time the pilot commenced a descent to visually identify and select a suitable landing area. As the balloon descended below 1,000 ft the wind backed[5] to a south‑westerly. As a consequence of that wind change, the balloon began tracking north-east towards the previously‑identified fog bank (Figure 2).
The pilot approached the fog expecting to be able to maintain visual requirements for landing. However, upon entering the fog, the pilot recalled observing that it was significantly thicker than they expected or had flown in before with visibility of about 10 m. The pilot continued to descend at approximately 200 feet per minute into the fog until they sighted a tree directly ahead of them. In response, the pilot immediately commenced burning on all 3 burners to arrest the descent and transition to a climb, but the balloon collided with the tree at a speed of about 4 knots. The balloon came to rest on the side of the tree at a height of about 60 ft above the ground.
Figure 2: Descent of VH-LUD to Yamanto
Source: Google Earth, annotated by the ATSB
The pilot continued operating the burners and the balloon commenced a climb away from the tree. The pilot climbed the balloon until they were out of the fog and conducted an uneventful landing in a nearby paddock, clear of the fog. There were no injuries to the pilot or passengers, however multiple sections of the lower portion of the balloon envelope required repair or replacement due to damage by tree branches. The balloon returned to service 7 days later.
Context
Pilot experience
The pilot held a Civil Aviation Safety Authority (CASA) Commercial Pilot Licence (Balloon) that was issued in January 1995. At the time of the occurrence the pilot had accrued a total flying time of 2,904 hours with approximately 2,000 hours on type. The pilot held a current CASA class 2 aviation medical certificate.
The pilot also held a CASA Maintenance Authority to conduct maintenance on the Kavanagh balloon.
Balloon information
VH-LUD was a Kavanagh Balloons E-240 manned free balloon manufactured as serial number E24-527 in 2016 by Kavanagh Balloons Australia Pty Ltd. The E‑240 balloon has an envelope capacity of 240,000 cubic feet and a maximum take-off weight of 2,000 kg. It is powered by three burners connected to two independent fuel systems. At the time of the occurrence VH‑LUD had accumulated a total time of 492.8 hours in service.
Flight conditions
The pilot obtained weather observations, noting isolated fog was forecast and that the wind was variable at 3 knots. The pilot also commented that if there was visible fog at their nearby residence prior to departure, as a general practice they would reschedule the flight.
An Amberley terminal area forecast (TAF) was issued at 0209 EST for the 24 hours from 0300 with an amendment issued at 0318 (Figure 3). A further TAF was issued at 0515, about the same time the balloon took off. All 3 forecasts predicted variable winds at 3 knots and a 30% probability of fog, in which visibility would reduce to 500 m.
Figure 3: RAAF Amberley terminal area forecast
Source: Airservices Australia, annotated by the ATSB
Airspace requirements
RAAF Base Amberley is surrounded by Class G non-controlled airspace, which allows aircraft to operate without air traffic control (ATC) permission. This airspace becomes military Class C when the air traffic control tower is active. Permission is required from Amberley ATC to operate in Class C airspace. At the time of the flight, the air traffic control tower was not active, therefore, Class G airspace procedures applied.
The pilot reported telephoning RAAF Base Amberley air traffic control and leaving a message on their answering machine with the balloon flight details. The pilot had conducted this process for a number of years. The pilot also reported monitoring the Amberley common traffic advisory frequency for traffic during the flight.
In Class G airspace, the required visibility for a balloon operating below 1,500 ft above ground level and clear of cloud, is 5,000 m. However, a balloon operating below 500 ft above ground level and beyond 10 NM of an aerodrome with an approved instrument approach procedure only requires 100 m visibility.
On this occasion, as this flight was conducted within 10 NM of RAAF Base Amberley, an aerodrome having approved instrument approach procedures, the balloon was required to maintain at least 5,000 m visibility and remain clear of cloud irrespective of its operating height.
Balloon performance
The pilot reported that at the time the tree was observed the balloon was descending at a rate of about 200 feet per minute and was flying at a velocity of about 4 knots. As soon as the pilot saw the tree, they commenced burning on all three burners.
The pilot stated the balloon took 20-30 seconds to arrest the descent and commence climbing. The pilot reported the balloon ‘settling’ on the side of the tree in a slow speed collision.
Damage to balloon
The balloon envelope consisted of a total of 460 sewn panels in a combination of four differing sizes. A total of 19 panels were damaged during the occurrence. These panels were either repaired or replaced by the operator in accordance with the Kavanagh Balloons maintenance manual.
Safety analysis
The RAAF Base Amberley TAF listed a 30% probability that fog would be present in the area, in which visibility would be 500 m. The pilot reported that during flight preparation there was no fog present. During the flight, fog was observed in a localised area to the south-east of RAAF Base Amberley.
The flight was conducted in Class G airspace within 10 NM of the RAAF Base. Due to the RAAF Base having an approved instrument approach procedure, the balloon operating under the visual flight rules was required to remain clear of cloud and maintain a minimum visibility of 5,000 m.
The pilot commenced a descent with the intention of locating a suitable landing area. During this descent, the wind backed, and the balloon began tracking towards the area of localised fog. Instead of remaining above the localised fog and descending in the clear air beyond, the pilot continued the descent and entered the fog believing that adequate visibility would exist for the landing. The visibility subsequently reduced to 10 m.
The pilot observed a tree, and in an attempt to prevent a collision, lit the burners to transition to a climb. However, due to the 20-30 seconds required before the descent could be arrested and a climb commence, there was insufficient time for the tree to be avoided due to the limited visibility. Given the climb performance of the balloon, even if the circumstances around the airspace allowed for the flight to be conducted in visibility conditions down to 100 m, the collision would still have occurred.
After the collision, the pilot climbed the balloon off the tree and up into clear air. The balloon was then flown to the edge of the localised fog and an uneventful landing was carried out.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following finding is made with respect to the collision with terrain involving Kavanagh E-240 Balloon, VH-LUD, at Yamanto, Queensland.
Contributing factors
Contrary to the visibility requirement for visual flight rules flight, the pilot entered an area of fog that did not permit sufficient time to see and avoid obstacles. As a result, the balloon collided with a tree, damaging the balloon's envelope.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the pilot of VH-LUD
Civil Aviation Safety Authority
RAAF Base Amberley air traffic control.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the pilot of VH-LUD
Civil Aviation Safety Authority.
Submissions were received from:
the pilot of VH-LUD
Civil Aviation Safety Authority
The submissions from those parties were reviewed however, they did not result in any amendment to the text of the draft report.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours
[2] Variable: used when the forecasting of mean wind direction is not possible. Usually due to low wind velocity.
[3] Class G: This airspace is not subject to air traffic control (ATC). Both instrument flight rules and visual flight rules aircraft are permitted and neither require ATC clearance.
[4] Class C airspace: Controlled airspace surrounding major airports. Both instrument flight rules and visual flight rules aircraft are permitted, but pilots must obtain a clearance to operate and maintain continuous radio contact with air traffic control.
[5] Backed: A counter‑clockwise shift in the wind direction.
On 4 November 2021, a Boeing B737-36E SF, registered ZK-FXK, was being operated on a scheduled freight flight from Darwin, Northern Territory, to Brisbane, Queensland. After take-off, the flight crew observed that the aircraft did not pressurise as expected and the indicated cabin altitude was climbing much quicker than normal.
As the cabin altitude kept increasing, the crew stopped the aircraft’s climb at 11,000 ft and soon after commenced descent to 10,000 ft. As the aircraft passed 10,300 ft on descent, a cabin altitude warning alert occurred. The crew completed the required checklist actions but were unable to establish control of the pressurisation. Subsequently, the equipment cooling fan failed, the electronic flight information system reverted to a monochrome display output, and the weather radar failed.
The crew decided to return to Darwin. On arrival they identified that the guarded cargo/depress switch was on. This switch was normally only used in the event of a main cargo deck smoke event, when it will depressurise the aircraft to assist smoke removal. Switching this off returned the aircraft to serviceability.
What the ATSB found
The ATSB found that the cargo/depress switch had been turned on by the engineer as a means to cool the flight deck during pre-flight preparation. However, the engineer had omitted to turn it off prior to completing their duties, which prevented the aircraft from pressurising. Using the cargo/depress switch in this manner was not authorised but it had become normalised by the operator’s staff in Darwin, who were not aware that this practice would not be effective on the B737-36E SF aircraft in their fleet.
Although the cargo conversion operations manual supplement required the switch to be checked, this information was not incorporated into the operator’s flight crew operating manual, nor was the supplement information otherwise available to the flight crew. As a result, the crew did not identify that the switch was on during pre-flight activities. The operator also did not provide sufficient training during the introduction of the B737-36E SF to its fleet to ensure its personnel understood the differences of these aircraft to the rest of their B737 fleet.
The flight crew were accustomed to checking pressurisation after take-off to ensure the aircraft was pressurising as expected. As a result, the flight crew identified the pressurisation problem early, which enabled prompt action and prevention of a more serious incident.
What has been done as a result
The operator issued communications to its staff to immediately cease the unauthorised practice and remind staff to only operate equipment in accordance with approved documentation. Additionally, they commenced a review of operational documentation and completed incorporating the requirements of the operations manual supplement.
The operator also commenced a review of its training and aircraft induction processes to ensure sufficient staff and documentation were available to conduct support these processes.
Safety message
This incident highlights the risks associated with undertaking unauthorised practices and using equipment in a manner other than for its intended purpose. Without formal assessment of its efficacy or its potential for unintended consequences, combined with no documentation or training, there is no assurance that an unauthorised practice would be carried out consistently or safely.
This incident also demonstrated how essential training and up-to-date documentation is in ensuring correct understanding and operation of an aircraft.
The occurrence
On 4 November 2021, a Boeing B737-36E SF, registered ZK-FXK and operated by Airwork Flight Operations, was scheduled for a freight flight from Darwin, Northern Territory, to Brisbane, Queensland. The aircraft was crewed by 2 pilots.
The engineer assigned to prepare the aircraft commenced their tasks at about 1615 local time. The flight crew arrived at about 1630. At this time, the engineer was inside the flight deck conducting their pre-flight procedures but vacated to allow the crew to commence their aircraft preparation. The first officer commenced pre-flight procedures inside the flight deck and the captain commenced the external inspection. No anomalies were identified with the aircraft or its systems.
The aircraft departed Darwin at about 1754. Following the after take-off checks, the flight crew identified that the aircraft was not pressurising as expected. They noted that the cabin pressure differential[1] was lower than normal and that the cabin altitude was increasing at a higher than expected rate of 2,000 ft/minute.
The crew monitored the pressurisation and, as the aircraft was nearing 10,000 ft, noted the cabin altitude was about 8,000 ft and increasing. (Above cabin altitudes of 10,000 ft, flight crew are required to use supplemental oxygen to avoid the possibility of hypoxia.)
The crew attempted contact with air traffic control in order to stop the aircraft’s climb at 10,000 ft, but they were unable to due to radio congestion. After contact was made, the controller cleared the crew to stop the climb at flight level (FL)[2] 110, and subsequently to descend to 10,000 ft. The cabin altitude was below 10,000 ft at this stage, but still climbing.
At about 1800, while passing 10,300 ft on descent, a cabin altitude warning occurred. The alert consisted of the master caution light and a warning horn, and indicated that the cabin altitude was above 10,000 ft. The crew commenced the required immediate actions in response to this warning, which included the use of supplemental oxygen. However, very soon after the aircraft reached 10,000 ft, at which time supplemental oxygen was no longer required.
The cabin altitude warning checklist required changing the pressurisation mode to manual and selecting the outflow valve to fully closed.[3] The crew recalled that the outflow valve was already closed and completing the checklist actions did not establish positive control of the pressurisation.
At about this time, the master caution alert on the overhead panel presented. Looking at the overhead panel, the crew identified the equipment cooling fan(s) had failed. The crew selected the alternate fans in accordance with the quick reference handbook (QRH) procedure, but this did not restore the operation of the equipment cooling fans. Subsequently, the electronic flight information system (EFIS) reverted to monochrome display output, which was a system design feature to reduce heat output.
A short time later the weather radar also failed. The crew stated that, although they were visual at the time, there were thunderstorms in the area, for which the weather radar was a required system. With numerous systems malfunctioning, the crew decided to return to Darwin. The crew conducted a normal approach and landed at 1915.
After shutting down the aircraft, the captain moved to the jump seat to complete the post-flight log. In the darker ambient conditions compared to departure, the captain noticed an unexpected amber light on the aft overhead panel. The light was from the guarded cargo/depress switch, indicating it was in the ON position. The flight crew realised that this was the reason why the aircraft did not pressurise, as the switch was normally only used in the event of smoke in the main cargo deck.[4]
The crew discussed the occurrence with the engineer, who advised that they had selected the cargo/depress switch to ON with the intention of cooling airflow into the flightdeck while the aircraft was on the ground. The engineer stated they had omitted to select the switch off prior to completing their duties, nor had they informed the crew of the switch selection.
After turning the switch off, the aircraft was considered serviceable, and it was operated on its freight service. The systems malfunctions did not occur again nor was there any further incident.
Context
Personnel information
Captain
The captain held an Air Transport Pilot Licence (Aeroplane) and Class 1 aviation medical certificate. They had flown for the operator for about 4 years and had previously flown the B737 for 2 other airlines. The captain had also flown a variety of aircraft with regular public transport, charter and general aviation operators. They had 12,150 flight hours in total, with 3,500 hours on B737 aircraft.
First officer
The first officer (FO) held an Air Transport Pilot Licence (Aeroplane) and a Class 1 aviation medical certificate. They had been at the operator for about 1 year on the B737 but had also flown the B737 for other operators in Australia and overseas. Their previous experience included various aircraft types in regular public transport and regional operations. The FO had 17,300 flight hours in total, with 13,000 hours on B737 aircraft.
Engineer
The engineer was a licensed aircraft maintenance engineer with over 30 years' experience maintaining B737 aircraft. The engineer stated that they had only maintained B737 aircraft but had also held a maintenance manager’s position prior to commencing at the operator about 4 months prior to the occurrence.
Aircraft information
General
ZK-FXK was a Boeing B737-36E Special Freighter (SF) aircraft. It was manufactured in 1991 as a passenger aircraft with serial number 25256. It was then modified for freight operations in 2004 by Israel Aircraft Industries Limited (IAI). The aircraft was acquired by the operator in 2019.
Cargo/depress switch
The cargo/depress switch was part of the main deck smoke detection system. It was on the main deck cargo smoke detector panel, which was located on the aft overhead panel of the flight deck (Figure 1, Figure 2). The panel was located behind the flight crew seats and was not within normal line of sight for a flight crew.
Figure 1: Main deck cargo smoke detector panel
Source: Airwork
The cargo/depress switch was a push-button type switch that illuminated when selected ON. It was guarded by a clear, flat plastic cover. The switch could be on or off with the guard in place (Figure 2). This was in contrast to other guarded switches on the aircraft, where the guard had to remain raised to allow the toggle type switch to be on. The only indication that the switch had been selected ON was the illumination of the switch itself.
Figure 2: Main deck cargo smoke detector panel (view from left seat)
Source: Captain of ZK-FXK, modified by the ATSB
The only situation for which the switch was to be used was if smoke was detected within the main cargo deck. The flight crew operating manual (FCOM) stated that when the switch was:
Depressed:
Will depressurize aircraft and provide limited ventilation to flight deck.
closes right and left main deck airflow shutoff valves
right pack valve closes
left pack valve closes to low flow (15-18% of normal output)
R/H flow control valve will be closed
forward outflow valve opens
The main deck cargo smoke, fire or fumes checklist further explained that:
Selecting this switch will depressurize the airplane and provides restricted heat and ventilation for exclusion of fumes and smoke from the cockpit.
As the aircraft departed with the cargo/depress switch on, ZK-FXK was prevented from pressurising.
No problems were identified with the weather radar or electronic flight information system (EFIS). Changes to the status of these systems during the flight was consistent with them being exposed to increased heat due to the cooling fan failure. The quick reference handbook explains that a cooling fan failure may be an indicator of a cabin pressurisation problem.
Operational manual supplement
An operational manual supplement (OMS) was produced by IAI to reflect all changes to the configuration and operation of the aircraft following its conversion from a passenger aircraft to a freighter. The OMS included a requirement that some of its pages must be inserted into the FCOM adjacent to their respective pages. This was to ensure the FCOM was fully amended with the latest information and procedures.
The operational manual supplement stated:
Depressing this switch will depressurize the aircraft to minimize airflow to the main cabin. The following valves will be activated.
both left and right air condition shutoff valves will close
right pack control flow valve will close
left pack control flow valve will drive to low flow
forward outflow valve will drive to open
In the preliminary flight deck preparation section of the normal procedures, the OMS required the main deck cargo smoke detector control panel to be checked as follows:
Main deck cargo smoke detector control panel – check
Check detector lights (12) – extinguished
Check detector fault light – extinguished
Check smoke light – extinguished
Main smoke no flow light – extinguished
Check depress switch, normal extinguished position, plastic cover stowed.
Both pilots stated that, after identifying the incorrect switch position on return to Darwin, they reviewed the FCOM and noted that it did not include any reference to pre-flight check requirements for the panel. During interview, the FO stated they were not aware of the OMS requirement and therefore they did not check the panel or switch during their pre-flight checks.
The ATSB reviewed the FCOM and confirmed that it had not been amended with the changes to the pre-flight procedures for checking the cargo/depress switch, as required by the OMS.
Flight crew pre-flight procedures
The FO conducted the flight deck preparation at the same time as the captain conducted the external inspection. The FO recalled that, while they were seated in the jump seat, they had looked at the overhead panel. However, rather than looking vertically up at where the cargo/depress switch was located, they looked across the panel at eye level, paying specific attention to various switches for correct positions. They described Boeing switches as being toggle types, all operating in the same direction to easily identify if they were on or off.
The FO stated that during this scan, in the bright ambient conditions, they did not notice that the cargo/depress switch was illuminated. As the clear plastic guard was able to be closed when the switch was on, and as this was different to the guard on the toggle type switches, the ability to visually determine its state was reduced. The FO recalled that at no stage was the main deck cargo smoke detector panel specifically checked. Following this activity, the FO continued the next section of pre-flight scans from their FO seat on the right side of the flight deck. From this seat, the cargo/depress switch was now behind their head and out of view.
When returning to the flight deck after the external inspection, the captain did not notice that the cargo/depress switch was on, nor were they required to check that panel. Both pilots mentioned conducting the light test to determine if lights were functional on the front, lower console and overhead panels. This test illuminated all lights but was not able to assist the pilots in visually identifying that the cargo/depress switch was on.
Prior to taxiing, the crew conducted the recall check of the master caution system annunciator panel during the before taxi checklist.[5] They also conducted this check again while attempting to establish the reason for the aircraft not pressurising. They received no alerts at those times. The crew and operator later identified that the cargo/depress switch was not connected to this system. This was not the crew’s expectation, given what systems the cargo/depress switch would affect and that it was outside of their normal line of sight.
The captain stated that the only training they received on ZK-FXK’s differences to the operator’s other B737 aircraft was related to operation of the main deck cargo door.
Cooling the flight deck
The engineer arrived at the aircraft about 1.5 hours prior to the scheduled departure time of 1745 to prepare the aircraft. They noted it was a very hot day and the aircraft interior had also become quite hot as a result. After turning the air conditioning on, the engineer then selected the cargo/depress switch to ON. The aircraft operator did not supply ground support equipment (GSE) capable of providing external air-conditioning.
At that time, the engineer believed that selecting the cargo/depress switch to ON would shut off airflow to the main deck and increase airflow to the flight deck to accelerate cooling there. The engineer stated that using the cargo/depress switch on the ground for cooling was not a documented procedure. They had learned to do this practice in Darwin from other engineers but had also seen some pilots do it. The engineer explained that they had not received any formal training on the differences between the operator’s 737 aircraft when they commenced employment with the operator.
The engineer explained that they would normally select this switch to ON, complete their aircraft preparation duties, then turn the switch to OFF prior to leaving the aircraft. On this occasion, the engineer felt that they needed to vacate the flight deck when the flight crew arrived earlier than expected. In doing so, they forgot to turn the switch off.
The operator identified that the same practice of cooling the flightdeck was used on all of their B737 aircraft by the engineers at Darwin.
Operator’s other 737 aircraft
The operator had 14 B737 freighter aircraft:
12 aircraft that had been modified by Aeronautical Engineers, Inc (AEI)
2 aircraft that had been modified by IAI (including ZK-FXK).
The AEI-modified aircraft were also fitted with a smoke detection system for the main cargo deck, however that system operated differently from that on the IAI-modified aircraft like ZK-FXK. On the AEI-modified aircraft, there was a cabin air shut-off switch that, when selected on, worked like the system on ZK-FXK to shut off air to the main deck, but it differed from ZK-FXK in that this system did not restrict air flow to the flight deck. Instead, all airflow was redirected to the flight deck to exclude smoke from the flight deck via positive pressure. This switch to control this system was the guarded toggle type and in the same position on the aft overhead panel as the cargo/depress switch on ZK-FXK.
Both pilots stated that the FCOM for the AEI-modified aircraft included a pre-flight operational check of the cabin air shut-off switch. The FO explained that the check required the guard to be lifted and the switch turned on to check the system operation. They explained there would be a very noticeable increase in air flow into the flight deck. The switch was then turned off and the guard closed.
The captain noted that the flow of air into the flight deck of the AEI-modified aircraft was significant to the point of distracting, and they would switch the system off if it was on. They did not notice any such air flow in ZK-FXK.
Pressurisation monitoring
The FCOM did not require that the aircraft pressurisation (cabin altitude and cabin pressure differential) be checked during flight. However, the FO stated they were in the habit of doing so due to experiences with B737 simulator instructors at a previous airline who would fail a student if they had not detected a pressurisation problem before the aircraft’s cabin altitude warning presented. The captain had a similar mindset with regard to checking the aircraft pressurisation.
It is likely that the cabin altitude warning would have presented while the aircraft was still climbing, however this did not occur because the flight crew had identified the pressurisation problem, monitored the cabin altitude, and then took action to avoid the cabin altitude rising above 10,000 ft.
Operator comments
The operator’s investigation report noted that the OMS for the IAI-modified aircraft was received by its maintenance control department when the aircraft was acquired. However, this manual was not provided to the engineering, flight operations or training departments prior to the aircraft entering service.
The report also identified that the training provided to flight crew was limited and focused on the operation of the main cargo door and escape slides. Engineers were not provided any formal training on the aircraft to identify the differences from other B737 aircraft in its fleet.
In summary, the operator identified that there were insufficient procedures as part of its aircraft induction process to ensure that all operational documentation was correctly distributed and that staffing deficiencies within the training department had impacted the oversight and delivery of training.
Safety analysis
Introduction
During pre-flight preparation, the engineer turned on the cargo/depress switch in an attempt to cool the flightdeck of ZK-FXK. The engineer omitted to turn the switch off prior to completing their duties and this was not identified by the flight crew. This prevented the aircraft from pressurising as expected and the cabin altitude subsequently rose above 10,000 ft.
The use of the cargo/depress switch in this manner was not authorised but had become normalised by the operator’s staff in Darwin.
The analysis will examine the issues related to unauthorised procedures and how documentation and training are essential for correct aircraft operations.
Normalised, unauthorised procedure
‘Normalisation of deviance’ was a process defined by Dianne Vaughan (1996) during the Space Shuttle Challenger investigation whereby unacceptable practices become accepted as the norm. The unacceptable practice is repeated without catastrophic results, reinforcing its normalisation.
Although the occurrence involving ZK-FXK did not have the same potential for a catastrophic outcome, it was an example of normalised deviance. The operator’s staff were using an aircraft system in a manner for which it was not designed (that is, using the cargo/depress switch on the ground). This practice was not authorised but had become accepted because of the perceived benefit of cooling the flight deck of its B737 aircraft in Darwin while working on the aircraft.
The engineer believed that in doing so they would be forcing air into flight deck but did not realise that this would not occur on ZK-FXK. It was identified that limited training on the B737-36E SF aircraft’s differences with the operator’s other type meant that operator’s staff were not aware that the desired result would not be achieved.
There was no evidence to suggest that anyone conducting this practice had undertaken a formal assessment of its efficacy or its potential for unintended consequences. The absence of formal documentation, procedures or training meant there was no assurance that the practice would be carried out consistently or safely. This was demonstrated by the engineer forgetting to deselect the switch, which is likely to have been a result of their normal routine being interrupted by the earlier than expected arrival of the flight crew. Lapses are common when interruptions occur and the absence of controls such as a documented procedure meant that the lapse was not recognised.
The absence of ground support equipment to provide external cooling appears to have instigated the unauthorised practice and it is likely that the practice may have continued given the frequently hot conditions in Darwin.
Aircraft documentation
Although the cargo conversion had taken place prior to the operator acquiring the aircraft, the operator did not ensure that all the aircraft documentation was adequately reviewed prior to entry into service. As a result, the flight crew operating manual (FCOM) had not been amended to include all changes detailed in the operational manual supplement (OMS), notably the requirement to check the main deck cargo smoke detector panel. The pilots were not aware of this requirement, thus removing a defence against the unauthorised use or incorrect position of the cargo/depress switch. Not checking the system also increased the risk of not detecting potential issues in the system.
The B737 is a very common aircraft but can be operated in various configurations which may differ between numerous operators. It is essential that aircraft documentation adequately reflect the correct aircraft configuration and procedures to prevent the aircraft being operated incorrectly.
Training on aircraft differences
Although the pilots had some training on the newly introduced aircraft, it was focused on the cargo door itself and not on all of the new procedures or systems following the cargo conversion. The engineer did not receive any formal training on the differences between the operator’s B737 aircraft. As such, the pilots and engineer were not provided with the opportunity to become fully aware of the aircraft they were required to operate.
In this occurrence, the limited training on aircraft differences reinforced the unauthorised use of the cargo/depress switch. Had the correct system knowledge been provided, it may have discouraged its use if it was known it would not work in the desired manner (at least on the B737-36E SF aircraft). The absence of training on required procedures also removed a defence against departure with an incorrect configuration.
Pilot vigilance
The pressurisation problem was identified early, enabled by the flight crew having developed the habit of monitoring pressurisation during their previous B737 experience. As the FCOM did not require a specific check of pressurisation during the after-take-off checks or climb phase, the pressurisation problem would still have triggered the cabin altitude warning albeit later in the climb. The crew’s heightened vigilance of pressurisation allowed them to identify and monitor the situation, take appropriate action promptly and thus avoid a more serious pressurisation incident.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the incorrect configuration and cabin pressurisation issue involving the Boeing B737-36E SF, registered ZK-FXK, near Darwin Airport, Northern Territory, on 4 November 2021.
Contributing factors
While preparing the aircraft for flight, the engineer selected the aircraft’s cargo/depress switch to ON then omitted to switch it off prior to leaving the aircraft.
During their pre-flight activities, neither of the flight crew identified that the cargo/depress switch had been selected ON. Although the aircraft operational manual supplement required this switch to be checked, neither pilot was aware of this requirement.
During the aircraft’s climb, the cargo/depress switch was in the ON position. This prevented the aircraft from pressurising as expected and the cabin altitude subsequently rose above 10,000 ft, triggering the cabin altitude warning.
The aircraft system to be used in the event of a main deck cargo smoke event on the operator’s B737 fleet was being routinely used by the operator’s engineering personnel in Darwin as a means to cool the flight deck. This practice had become normalised as a result of the perceived benefit of doing so, but there were insufficient risk controls in place to ensure that the aircraft would be returned to the correct configuration prior to departure. (Safety issue)
The operator did not provide sufficient training during the introduction of the B737-36E SF to its fleet to ensure its personnel understood the differences between these aircraft and the rest of its B737 fleet.
The operator’s flight crew operating manual for the B737-36E SF aircraft had not been fully amended to incorporate all revisions as detailed in the cargo conversion operational manual supplement.
Other findings
The flight crew were accustomed to checking cabin pressurisation during climb to ensure the aircraft was pressurising as expected. As a result, the flight crew identified the pressurisation problem involving ZK-FXK early, which enabled prompt action and prevention of a more serious incident.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The aircraft system to be used in the event of a main deck cargo smoke event on the operator’s B737 fleet was being routinely used by the operator’s engineering personnel in Darwin as a means to cool the flight deck. This practice had become normalised as a result of the perceived benefit of doing so, but there were insufficient risk controls in place to ensure that the aircraft would be returned to the correct configuration prior to departure.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Airwork Flight Operations Limited
Airwork advised that:
A review of the B737-36E SF flight crew operations manual and quick reference handbook was completed to ensure full compliance with the operations manual supplement. Work was in progress to implement an application in conjunction with the flight crew’s electronic flight bag to allow aircraft specific tail number data to be provided immediately to crew.
Training packages for both flight crew and engineering staff were developed, and a training manager/coordinator will be introduced to oversee flight operations and maintenance training.
The aircraft induction process was reviewed, and an improved induction checklist was created to ensure data is transferred between engineering and flight operations.
Glossary
AEI Aeronautical Engineers, Incorporated
ATC Air traffic control
EFIS Electronic flight information system
FCOM Flight crew operations manual
FDR Flight data recorder
FL Flight level
FO First officer
GSE Ground support equipment
IAI Israel Aircraft Industries Limited
OMS Operations manual supplement
QRH Quick reference handbook
SF Special freighter
Sources and submissions
Sources of information
The sources of information during the investigation included the:
the flight crew of ZK-FXK
the engineer
Airwork Flight Operations Limited (the operator).
References
Vaughan, D. (1986) The Challenger Launch Decision: Risky Technology, Culture and Deviance at NASA. University of Chicago Press; 1st edition.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the flight crew of ZK-FXK
the engineer
Airwork Flight Operations Limited (the operator)
the Civil Aviation Safety Authority
the Civil Aviation Authority of New Zealand
the Transport Accident Investigation Commission (New Zealand)
the National Transportation Safety Board (United States of America).
Submissions were received from:
the captain of ZK-FXK
the engineer
Airwork Flight Operations Limited.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Cabin pressure differential was the difference between cabin pressure and atmospheric pressure.
[2] Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 110 equates to 11,000 ft.
[3] The normal mode for pressurisation is AUTO, whereby the system will automatically adjust the position of the outflow valve in order to modulate cabin pressure. Manual mode will give full control of the system to the flight crew.
[4] The passenger area of ZK-FXK’s cabin had been converted to a cargo compartment and was known as the main cargo deck.
[5] The recall check is used to verify if a master caution condition exists. Pushing the system annunciator panel will illuminate the appropriate system annunciator and master caution light. These systems will have their control/display panels out of the flight crew’s normal line of sight. If this occurs, the flight crew will be required to take further action to verify correct system operation.
On the 26 October 2021, a Beech Aircraft Corp. 58, registered VH-NSK, operated by Little Wings Limited, was prepared for a private flight from Bankstown Airport, New South Wales. The purpose of the flight was to test the stall warning system following maintenance. The pilot was the sole person on board.
The aircraft was cleared to enter and line up on runway 29 right (29R) however, the pilot crossed the runway and entered occupied runway 29 centre (29C) without a clearance. As the pilot was cleared to take-off, the controller identified the error and instructed the pilot to hold position on the runway. At the same time, the pilot detected an Embraer 190, which was conducting high power engine runs on the upwind end of runway 29C and did not commence the take‑off.
What the ATSB found
The ATSB found that the pilot typically departed Bankstown from the centre runway, under the instrument flight rules procedures. This likely created an expectation that they were using this runway, despite reading back the correct runway to the controller. This resulted in them crossing runway 29R and entering runway 29C without a clearance.
Additionally, while the air traffic controller watched the aircraft enter 29R, due to subsequent focused attention on two helicopters in the vicinity of the airport, they did not identify its continued movement on to the occupied runway 29C.
Safety message
This incident illustrates the importance of pilots focusing on the specific instructions given by air traffic controllers. In 2012, the United States Federal Aviation Administration Safety Team (FAASTeam) released notice NOT4214 Pilot safety tip – Expectation biasstating that ‘analysis of runway incursion data shows that expectation bias is one of the most common causal factors for pilot deviations’.
The notice went on to say that pilots ‘need to understand that expectation bias often affects the verbal transmission of information. When issued instructions by air traffic control, pilots should “focus on listening and repeat to yourself exactly what is said in your head — and then apply that information actively”.’
Runway incursions remain an ongoing safety concern globally. In October 2016, Airservices Australia released A pilot’s guide to Runway Safety. This guide focused on seven important areas in surface operations and identified safety measures to help reduce the errors that lead to runway incursions. In addition, Airservices Australia have released specific guidance for pilots flying at Bankstown Airport Tips for flying at Bankstown, along with tips for flying at other metropolitan airports: Moorabbin, Parafield, Jandakot and Archerfield.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
On the morning of 26 October 2021, a Beech Aircraft Corp. 58, registered VH-NSK and operated by Little Wings Ltd, was prepared for a private flight under the visual flight rules (VFR) from Bankstown Airport, New South Wales (Figure 1). The purpose of the flight was to test the aircraft’s stall warning system following maintenance. The pilot was the sole person on board.
Figure 1: VH-NSK
Source: JETPHOTOS, Gavin Louis, modified by the ATSB
The operator had requested that the pilot conduct the test flight prior to conducting an instrument flight rules (IFR) flight, later that day. The pilot advised that they had not flown under the VFR or to the Bankstown training area for over 40 years. As such, they prepared themselves by researching the airspace around Bankstown Airport and revising the procedures for the flight test.
The next morning, the pilot conducted their normal pre-flight checks and started the engines. As the pilot taxied across the apron, they contacted the Bankstown surface movement controller (SMC), to obtain their taxi clearance. The SMC instructed them to taxi to holding point A8 for runway 29R[1] (Figure 2). This clearance automatically included an approval for the aircraft to enter a run-up bay to conduct the pre-flight engine checks and then taxi to the runway holding point. The pilot was not aware of this and advised the SMC that they needed to taxi to the run-up bay, which the SMC advised they were cleared to do. During this exchange, the pilot advised the SMC that they had not been to the Bankstown training area for over 40 years.
As the pilot was conducting their engine checks in the run-up bay, the crew of an Embraer 190 (Embraer) requested, and received, clearance to taxi to holding point A2 (Figure 2), the upwind end of runway 29C, to conduct high power engine runs for maintenance purposes.
When the pilot of NSK completed their checks in the run-up bay, they clarified with SMC that they were approved to taxi to holding point A8. The SMC confirmed they were approved and instructed them to contact Bankstown Tower at the holding point.
Figure 2: Bankstown Airport showing the route NSK took to the holding point
Source: Google Earth, annotated by ATSB
At 1114, the crew of the Embraer contacted Bankstown Tower and was cleared to enter runway 29C.
On reaching holding point A8, the pilot of NSK changed frequency to Bankstown Tower. At 1117, they contacted the Tower controller and advised they were ‘on A8 holding short of runway 29R ready for an upwind departure’. The Tower controller instructed them to hold position.
At 1118, the Tower controller instructed ‘NSK runway 29R line up and wait’. The pilot read back ‘line up and wait right NSK’. The Tower controller advised that aircraft would initially taxi along the same path if they were crossing runway 29R or lining up on that runway to depart.
After watching NSK commence taxiing, the Tower controller directed their attention to two helicopters. One helicopter was operating north of Bankstown Airport, with a second departing to the north. The Tower controller passed traffic information to both helicopter pilots, to assist them to identify each other. During the period the Tower controller’s attention was diverted, NSK crossed runway 29R, then entered and lined up on runway 29C.
At 1119:23, after the helicopter pilots advised they had each other sighted, the Tower controller instructed ‘NSK runway right clear for take-off’. As they were finishing the instruction, they detected that NSK was on 29C and immediately instructed ‘NSK hold position, hold position you are lined up on Centre, hold position’. The controller then instructed NSK to ‘Stop, hold position’. At 1119:35 the controller again instructed ‘NSK Stop, hold position’ and 5 seconds later stated ‘NSK Stop, stop, stop, hold position’.
At this time, the Bankstown tower frequency had at least one occasion, where a pilot over transmitted while the controller was broadcasting on the radio.
The pilot of NSK advised that as they were turning to line up on the runway, the controller cleared them to take-off. They immediately detected an Embraer at the other end of the runway and reported they advised the controller that there was a jet on the runway and they would hold position, however this was not heard by the controller. This was likely the over transmission on the frequency. At 1119:42 the pilot of NSK read back ‘NSK Stop, stop, stop, holding position’.
At 1121, after giving instructions to a number of other aircraft in the area, the controller instructed the pilot of NSK to hold short of runway 29R. The pilot of NSK responded by stating ‘I am holding at the threshold 29’. The controller then advised ‘NSK you are currently lined up on 29C hence why I told you to hold position. Vacate to the right and hold short of runway 29R’. NSK responded ‘Roger, vacating to the right hold short of 29R, NSK’.
The Embraer completed their engine runs and exited the runway onto taxiway A1, taxiing around runway 29R (Figure 2).
The controller then cleared NSK to enter and take off from runway 29R. The pilot advised they observed the Embraer taxiing at the end of the runway, but they were unsure if the Embraer was on the runway or was on the taxi way behind the runway. They advised that they waited until the Embraer had cleared the take-off overrun, before commencing the departure. The test flight and return to Bankstown were conducted without issue.
Context
Pilot
The pilot held an Air Transport Pilot’s Licence (Aeroplane) with over 23,500 hours of aeronautical experience.
They were volunteering their time to fly for the operator while they were stood down from an airline which had reduced international flights due to COVID 19 restrictions. The pilot had been flying the Beech Aircraft Corp. 58 regularly on IFR flights for the previous 18 months, with their most recent flight being circuits on the night before the incident.
They advised that they felt uncomfortable doing a VFR flight to the training area due to the different procedures and had never departed from runway 29R prior to that day. They reported that they thought the controller had instructed them to use runway 29C and had no recollection of reading back 29R.
They advised they had slept well and were fit and healthy.
Air traffic controller
The controller had almost 20 years experience, with around 14 years at Bankstown Airport. They advised they were feeling ‘fine’ at the time, having received their normal amount of sleep over the previous days. They had been operating as the tower controller for about 15 minutes prior to the occurrence and advised that they did not consider the workload to be high.
Bankstown Airspace
Bankstown Airport uses Class D airspace procedures. It has three parallel runways aligned in the 29/11 direction (Figure 2). When runway 29 was the operational runway:
runway 29R was used for departing and arriving VFR aircraft
29C was used for departing and arriving IFR aircraft and overflow if 29R was busy
29L was used mainly for circuits.
When the airport was busy, 29L was controlled by one controller and 29 R and C were controlled by a second controller. When it was quiet, a single controller controlled all three runways.
On this morning, the tower controller was controlling all three runways. There were two aircraft in the circuit area, two aircraft inbound, a helicopter operating north of the airport and another helicopter departing to the north.
Safety analysis
The experienced pilot had been conducting IFR flights for the operator on a regular basis over the previous 18 months. On these flights, they had only conducted IFR departures using the centre runway. This most likely led to them having an expectation they were going to depart from runway 29C. According to Skybrary Flight crew expectation bias:
Expectation bias occurs when a pilot hears or sees something that he or she expects to hear or see rather than what actually may be occurring. That expectation often is driven by experience or repetition. For example, if a pilot is regularly cleared to cross a particular runway during operations at a familiar aerodrome, he/she may come to “expect” the clearance. This could cause a potentially dangerous situation if on a particular day, the pilot actually is instructed not to cross the runway in question due to another aircraft landing or taking off.
Despite confirming the instruction to line up and wait on runway 29R, the pilot reported no recollection of this. It is likely the pilot was thinking ahead to conducting the VFR departure, narrowing their focus to their actions after the departure. Consequently, their attention was probably not on the clearance to enter the runway, rather reverting to what they had done previously.
The controller had no indication from the pilot’s readback that the pilot had a different understanding of what was instructed. Therefore, when the aircraft commenced taxiing as expected, they diverted their attention to other tasks.
Both the pilot and the controller detected an issue and stopped the departure prior to the aircraft commencing the take-off run, although at this stage the pilot was still unaware, they were not on their cleared runway.
The air traffic control system is dependent on radio communication which requires both pilots and controllers to clearly and accurately articulate what they are doing. An analysis of runway incursion data conducted by the United States Federal Aviation Administration Safety Team in 2012, found that expectation bias is one of the most common contributing factors to pilots deviating from a clearance instruction.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the runway incursion involving Beech Aircraft Corp. 58, VH-NSK at Bankstown Airport, New South Wales, on 26 October 2021.
Contributing factors
Despite correctly acknowledging the clearance to enter and line up on runway 29R, the pilot crossed runway 29R and entered runway 29C without a clearance, probably due to expectation bias associated with previous operation only from 29C.
The controller watched VH‑NSK enter 29R however, due to subsequent focused attention on two helicopters in the vicinity of the airport, they did not identify its continued movement on to the occupied runway 29C.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
pilot
controller
Airservices Australia
Little Wings Limited
No submissions were received.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
In the early hours of 20 October 2021, NSW Trains’ passenger train service (C012) collided with an abandoned motor vehicle on the rail line south of the West Dapto Road level crossing and Kembla Grange railway station.
The collision with the motor vehicle caused the first carriage of the train to derail and separate from the rest of the train. The front carriage collided with a high voltage stanchion, then tipped on its side, sliding into the adjacent land of the rail corridor.
The driver received serious injuries and two passengers in the lead carriage were also injured. They and the guard were taken to hospital for observation. The other eight passengers were assessed on site and medically cleared.
There was significant damage to the rolling stock, rail infrastructure and overhead wiring as a result of the collision.
What the ATSB found
On 27 October 2021, NSW Police charged an individual with endangering passengers on a railway and obstructing a railway. On 15 November 2022, the individual pleaded guilty to these offences and eight other separate offences. The actions of the individual directly contributed to the collision when the motor vehicle was abandoned after it was driven onto the railway tracks and became stuck.
This individual was captured on Kembla Grange railway station’s closed-circuit television (CCTV). They moved the level crossing cameras away from the level crossing to face directly downwards about 45 minutes before the collision. Sydney Trains Security did not detect camera tampering at this time. A CCTV Upgrade Project was scoped to install and commission tamper alarms on high‑risk CCTV cameras, but the alarms were not operating on these cameras at the time. If the tamper alarm functionality on the CCTV cameras was activated and working as intended, security may have detected the camera tampering.
A member of the public called triple zero, alerting police of the motor vehicle on the rail line about 4 minutes prior to the collision. The call was not treated as an emergency by all parties involved, and the actions taken to alert the train crew of the motor vehicle on the rail line did not allow the train crew time to act and avoid the collision.
After the incident, the guard tried to make an emergency call on the Digital Train Radio System (DTRS) located at the guard’s workstation. The DTRS was not working as it had gone into standby mode as a result of the control circuit breaker tripping – which likely occurred during the separation of carriages.
The guard's training and the other available resources did not provide the guard the knowledge to reboot the DTRS. In this instance, mobile phone coverage was available and the lack of knowledge about the DTRS was not a factor in being able to communicate. The use of a work issued mobile phone allowed the guard to report the incident to Network Control in a timely manner.
The Sydney Trains’ Security Control Centre Standard Operating Procedure contained conflicting instruction for incident response. It referred to the Train Services Delivery Manager (TSDM) in the Incident Response Checklist in addition to the Network Incident Manager (NIM). This potentially added an additional step in communications during incident response before the information reached someone with the ability to warn or stop train services.
The derailment brought down potentially live 1,500 V overhead wires to ground level and whilst the guard and first responders were moving around the wreckage to help passengers, this overhead wiring had not been confirmed as isolated. While this presented a risk to the guard and first responders attending to the driver and injured passengers, the guard had identified the potential sources of electricity and informed the first responders to stay clear.
This investigation also reviewed the status of the remaining open recommendations and actions from the Special Commission of Inquiry into the Waterfall Rail Accident. This was to determine if any outstanding actions had influence and/or importance to the outcomes of this investigation. The review found there were no outstanding actions that influenced or had importance to the outcomes of this incident.
What has been done as a result
Sydney Trains conducted post‑incident technical and systemic investigations and made 14 internal recommendations for their organisation to address key safety issues from this incident. Sydney Trains reported all recommendations of its internal report were completed and closed.
Key actions taken to address the safety issues raised in this report and the 14 recommendations of Sydney Trains’ internal report are detailed below.
To address the safety issues raised in this investigation, the Security Control Centre Standard Operating Procedure was aligned with the Sydney Trains Network Incident Management Plan with Security Control Centre Operators required to contact NIMs rather than TSDMs.
Security Control Centre Operators' initial training in responding to emergencies was upgraded to improve communications during emergencies and a recertification module was developed to be provided as refresher training.
CCTV software was upgraded to allow use of a centralised server-based analytics engine to provide alarm functionality. At the time of publication, Sydney Trains was in the process of development, testing and trialling alarm functionality to enable detection of incidents such as the tampering at the West Dapto Level Crossing while reducing the false alarm rate.
The additional actions taken by Sydney Trains to address their internal recommendations included sharing of learnings with other key stakeholders, assessing feasibility of improving emergency lighting circuitry on Tangara Sets, reviewing actions of key personnel to ensure alignment with emergency procedures and reviewing and updating risk registers and procedures to account for learnings from this incident.
Safety message
All obstructions reported on the rail line should be treated as an emergency, and priority given to urgently stopping trains on the network to avoid collision by the most effective means available.
Rail operators should assess their risk exposure in circumstances where they have been unable to implement planned controls. They should consider implementing alternative or short-term controls to reduce the risk exposure until the agreed controls are in place.
The processes and procedures that are established by accredited rail operators are the mechanisms by which the accredited operator has provided assurance they are able to manage risks safely. Rail operators should regularly review their controls to ensure they remain effective and continue to achieve their intended purpose.
When introducing new or changing existing procedures, change control processes should consider the impact on other related procedures to ensure the integrity of risk controls is maintained. Consistency in these procedures throughout the organisation should be confirmed to ensure controls remain effective.
The occurrence
On 20 October 2021, NSW Trains’ passenger service (C012) departed Kiama at 0339 en route to Central Station in Sydney. As the train approached Kembla Grange Station at approximately 0409 it collided with an abandoned motor vehicle on the rail line. This motor vehicle had been left on the rail track approximately 68 m on the south-west side of West Dapto Road level crossing at Kembla Grange.
When the first carriage of the train struck the motor vehicle, it derailed and separated from the other carriages, collided into a high voltage stanchion, tipped onto its side, and slid into the adjacent land of the rail corridor. The driver and two passengers in the first carriage were injured and required hospitalisation. The guard was also taken to hospital for further observation. The remaining eight passengers were assessed on site and medically cleared. There was no-one in the motor vehicle at the time of the collision.
Police were onsite within minutes of the incident, having received an earlier notification of a motor vehicle on track from a member of the public via triple zero. The police assisted with the injured driver and passengers who were taken to hospital.
There was significant damage to the rolling stock, rail infrastructure and high voltage overhead wiring as a result of the collision.
Motor vehicle on the rail line
At 0313 (EDT)[1] a Sydney Trains’ security camera located on the Kembla Grange Station platform recorded an individual moving the security camera. The camera was moved to focus away from the West Dapto Road level crossing towards the ground. There was no mechanism to alert the Security Control Centre Operators (SCCO)[2] at the Sydney Trains Security Control Centre to this event.
At 0326 a second security camera, also located on the Kembla Grange Station platform, recorded being moved from its focus on the West Dapto Road level crossing towards the ground. This movement was also not alerted to or detected by the SCCO at the Sydney Trains Security Control Centre.
Likely between 0326 and 0405, when police received the first report of a motor vehicle on track, a vehicle was driven onto the railway tracks and abandoned after it became stuck on the rail.
Police forensics marked the location of the motor vehicle at 91.732 km, 68 metres from the West Dapto Road Level Crossing (see Marker A in Figure 3).
Train service C012
At 0339 C012, a 4‑carriage Tangara passenger train service departed Kiama Station en route to Sydney Central Station. As part of the scheduled stops, the train arrived at Dapto Station to pick up passengers and departed shortly after at 0407. The driver gradually accelerated the train to the track speed limit of 100 km/h.
At 0408:40, the driver moved the power notch to the off position and allowed the train to coast (from a speed of 103 km/h) as the train passed the Area 013 transponder (Wollongong South)[3] located at 93.400 km.
At 0409:06, the train passed the track circuit that activated the West Dapto Road Level Crossing warning bells and lights (92.672 km). 26 seconds later, at 0409:32, the driver made an initial brake application (91.944 km). It was estimated the train was approximately 200 m from the motor vehicle at this time. Three seconds later the driver applied full braking (91.860 km) and within the second after, applied emergency braking.
Figure 1: Approach to level crossing
Front of train footage taken from a subsequent train journey at the same time of day. The location of the motor vehicle was 268 m beyond the 92 km posts. At this time the motor vehicle was likely in relative darkness.
Source: Sydney Trains
Notification to Network Control
At 0405:52 police received a triple zero phone call and were notified of a motor vehicle on the rail line just off the Racecourse and West Dapto Road, near Kembla Grange Station.
At 0407:37, Sydney Trains Security Control Centre received a call from police.
At 0408:47, after confirming the location of the motor vehicle on track from police, the Sydney Trains SCCO called the Train Services Delivery Manager – South West (TSDM)[4].
At 0409:08, the TSDM called the Wollongong Coast Panel Signaller (WCP Signaller)[5] advising them there was a report of a motor vehicle on track and to stop all services immediately.
At 0409:35, 2 minutes from when Sydney Trains received the call from police, the WCP Signaller made a point to point (direct not emergency) call to C012 using the Digital Train Radio System (DTRS), however the call was not answered.
The collision and derailment
At 0409:36, the driver of C012, travelling at approximately 90 km/h, applied emergency braking on the train. Over the next 4 seconds, the train collided with the abandoned motor vehicle on track and derailed to the left of the track in the direction of travel.
The front carriage travelled approximately 125 m upright in a derailed state before the right side of the carriage impacted and flattened a stanchion supporting overhead high voltage wire.
The first carriage tipped onto its right side and jack-knifed so that the rear of the carriage separated from the second carriage, and then slid a further 25 m off to the side of the rail track. The remaining 3 carriages stayed upright with the second carriage derailing and the third and fourth carriages remaining on track and alongside Kembla Grange Station platform (Figure 2).
Figure 2: C012 after the collision and derailment
C012 alongside Kembla Grange Station after collision and subsequent derailment
Source: Sydney Trains, annoted by ATSB
Post occurrence
Thirty seconds after the WCP Signaller had attempted to reach the driver of C012, they attempted to reach the driver with a second point-to-point call which was also unsuccessful. Shortly after, the WCP Signaller received a call from the TSDM. The WCP Signaller initially told the TSDM, C012 had gone through Kembla Grange.
When the TSDM said they could see the track was occupied, they asked if the driver had reported seeing a motor vehicle. The WCP Signaller told the TSDM that they had a few attempts to contact the driver of C012, however each attempted call kept terminating. The WCP Signaller then commented that it appeared now that C012 was not moving.
The TSDM directed the WCP Signaller to make an emergency call to the driver which differed from a point-to-point call as it would be broadcast in the cab on the radio and to all other trains in the area. The WCP Signaller made the Rail Emergency Call (REC) using the emergency function of the DTRS, but there was no response.
At 0411:56, 2 minutes and 16 seconds after the collision, the signaller on the adjacent Wollongong panel (WP Signaller)[6] received a call from the guard of C012, from the guard’s work‑issued mobile phone. The guard told the WP Signaller that the train had been in an accident at the level crossing. The train radio was not working, and they were going to check on the welfare of the driver. The WP Signaller then told the guard to check on the welfare of any passengers. The guard confirmed there were passengers on board, and they would walk through the train to check on the welfare of the passengers and the driver.
As the guard checked the train, they remained on the call to the WP Signaller and confirmed that the second car had derailed and was leaning to the side with lights out and that the lead car had derailed and was lying on its side. The guard also requested an ambulance for the driver.
During this call, the guard told the WP Signaller that the police were onsite. The guard spoke with the police, which could be heard in the background. The police asked the guard about passengers and if the train was live. The guard responded, ‘stay away from the overhead, and that portion of the train is still live’.
The guard then resumed conversation with the WP Signaller. The WP Signaller told the guard that they would advise the Network Incident Manager South (NIM)[7] and the TSDM so that they could arrange for a power outage.
The WP Signaller then informed the TSDM that C012 had derailed, and they had received the call from the guard on C012. The TSDM confirmed with the WP Signaller that protecting signals had been placed at STOP with blocking facilities applied[8].
At 0412:55, 3 minutes and 15 seconds after the collision, the TSDM informed the NIM of the incident. Approximately a minute later, the Electrical Operations Centre (EOC)[9] informed the NIM of a sustained fault on the overhead wire supply from Unanderra to the countryside of Dapto Station, which included the incident site. The NIM then advised the EOC of the incident they had just been informed of by the TSDM.
The NIM then received a call from the WP Signaller who relayed information they had received from the guard on C012.
Next the NIM received a call from the SCCO who said they had received news of the derailment from the NSW Police Radio Operations Group (ROG)[10] and would confirm that all rescue personnel had been contacted regarding the potential for fallen overhead wires to be live. The SCCO also stated the ROG advised that passengers were injured.
At 0415 the NIM called the Incident Rail Commander (IRC) South Coast[11] and requested they attend Kembla Grange.
At 0416:23, in a three-way call between the NIM, EOC and WCP Signaller, the NIM confirmed with the EOC that power would remain off and that the power outage was from Coniston to the countryside of Dapto Station. The NIM then confirmed with the WCP Signaller that signals were at STOP with blocking facilities applied. After speaking with the NIM, the EOC requested the Work Group Leader (WGL) Traction[12] to attend Kembla Grange to verify the power outage. The WGL advised the workgroup would be there in 30 minutes.
At 0419, 9 minutes and 20 seconds after the collision, a Level 2 incident[13] was declared by the NIM. The NIM also updated the Duty Control Manager (DCM)[14] and advised a sustained overhead wire fault from Unanderra to Dapto Station was reported at 0413. The NIM then advised the SCCO of the sustained fault and that a Rescue Power Outage (RPO)[15] was to be issued. Until the RPO was issued, wires were to be treated as live. The SCCO then called the ROG directing to inform emergency personnel onsite to treat the wires as live.
At 0435 the IRC arrived onsite at Kembla Grange and took charge as the Rail Commander under Sydney Trains’ Command and Control structure. At this time a Level 3 Crisis[16] had been declared.
The RPO was issued by the EOC to the NIM at 0444, approximately half an hour after the event, which confirmed the power outage. The EOC then informed the IRC that while the RPO had been issued to the NIM, personnel onsite were still to treat all wiring as live. The EOC also stated that an Emergency Authority[17] was in process and once completed, the Emergency (electrical) Authority would be conveyed to the IRC to enable workers to sign on to it.
The NIM then informed the WCP Signaller, WP Signaller and the TSDM of the RPO details. Both signallers confirmed that blocking facilities had been applied.
At 0524 hours the incident location was declared a crime scene by police.
At 0550 hours Electrical Authority E62/21 was issued for Kembla Grange K171 to ensure power remained isolated in the incident area during incident recovery. The NIM informed the TSDM that the RPO would be overlapped with the Electrical Authority and power would be formally removed.
The NIM was informed by the IRC onsite there was a total of 12 people on board: 2 NSW Trains’ crew, one off-duty guard travelling as a passenger and 9 other passengers. The train crew and 2 passengers with minor injuries were conveyed to hospital. A bus was arranged to transport the remaining passengers to their home.
By 0600 all uninjured passengers were on a bus and departed Kembla Grange Station.
NSW Police maintained control of the site until 11:00 at which time the site was handed to the ATSB.
By 12:00, the site was handed back to Sydney Trains to allow infrastructure repairs and train recovery to commence.
Figure 3: Point of collision and abandoned motor vehicle
The motor vehicle was abandoned on the rail line at yellow marker A and pushed by the train to the location in the picture.
Source: OTSI
Context
Criminal act
On 27 October 2021, NSW Police charged an individual with endangering passengers on a railway and obstructing a railway amongst other charges.
On 15 November 2022, the individual pleaded guilty to 8 separate offences, including endangering passengers on a railway and obstructing a railway.
The actions of this individual were key contributing factors to the collision of C012.
In the individual’s attempts to steal a go-kart from the Wollongong Kart Raceway, located close to the West Dapto Road level crossing, they undertook a series of activities which led to the motor vehicle being stuck on the rail line and abandoned.
At 0313 and again at 0326 on 20 October 2021, a Sydney Trains CCTV recorded the individual moving cameras to face away from the West Dapto Road level crossing (Figure 4).
Figure 4: Level crossing cameras at Kembla Grange Station
CCTV cameras facing the ground and away from the level crossing, moved by the convicted felon as captured on CCTV.
Source: OTSI
Security cameras
CCTV Upgrade Project
Sydney Trains operated a CCTV camera network system with approximately 13,000 cameras to cover the rail network which extends over 800 km of rail track and 170 stations.
Sydney Trains highlighted in their internal investigation that the tamper alarm functionality on Sydney Trains’ network of CCTV cameras was not activated on all cameras as part of the CCTV Upgrade Project contract that commenced in 2015.
The contract required tamper alarms to be installed on all cameras. However, the cameras were prone to vibration caused by passing freight trains and other anomalies resulting in high false alarm rate. Security Control Centre staff could not manage the excessive number of tamper alarms being generated causing installation to be stalled.
The requirement of the contract was subsequently amended so that the tamper alarm functionality was activated only on “high risk” cameras (including cameras that monitored level crossings) but at the time of this incident the functionality had not been activated on the West Dapto Road Level Crossing.
The Sydney Trains Network Maintenance group took charge of the project in December 2020 and a CCTV Operational Working Group was formed to continue progress from February 2021.
To make changes to the CCTVs on the network, the Sydney Trains Security Group had to submit a request to the CCTV Operational Working Group to get the tamper functionality installed.
Following this incident, Sydney Trains Security group worked with the contractor to find out what was stopping the implementation of the tamper alarm functionality. An issue raised was poor detection on outdoor cameras due to lighting conditions. At the time of authoring this report, other solutions were still under consideration such as electro-mechanical tamper alarms and/or more bespoke high‑end video analytics were being trialled on cameras used to monitor level crossings.
Location
Kembla Grange Station
The station is located 91.586 km from Central Station on the South Coast rail line. It is within the Sydney Trains’ electrified network, which extends as far south as Kiama Station. Kembla Grange is a single platform station situated on the SSE side of the bi-directional rail line.[18]
There were multiple CCTV security cameras at the station, including security cameras mounted on a pole on the western point of the platform intended to face towards the West Dapto Road Level Crossing (Figure 4). These cameras were able to be viewed by staff at Sydney Trains Security Control Centre.
Kembla Grange Station was not staffed but was fitted with a customer access point where the travelling public could reach NSW Trains’ customer service attendants at any time of the day or night. The station is located along the coast between Wollongong and Shellharbour, as seen in Figure 5. The South Coast rail line skirts the west of Lake Illawarra.
Figure 5: Kembla Grange Station
Source: Google Maps
West Dapto Road Level Crossing
The West Dapto Road level crossing was located approximately 150 m west along the West Dapto Road from The Princes Highway. Approximately 20 m from the western most point of Kembla Grange Station platform.
It was a Type F level crossing with boom gates, audible warning devices and roadside flashing lights. These safety features activate automatically when a train approaches and were designed to be failsafe. The level crossing was functional and operating as required at the time of the incident.
Figure 6 shows the level crossing and how its design affords access into the rail corridor. The individual likely accessed the rail corridor in their motor vehicle from the southwest entry on the downside (left side) of the railway line.
The individual likely drove the motor vehicle along the side of the track until they reached the high voltage stanchion. They then attempted to drive the motor vehicle over the rail track onto the upside (right side). This is when the motor vehicle got stuck on the rail line.
Figure 6: West Dapto Road Level Crossing
View in both directions, Southwest is down direction away from Sydney, Northeast is up direction towards Sydney
Source: Google Maps
Rolling stock
The passenger train was a Tangara (Set T42) en route to Sydney from Kiama as service C012. There were 4 carriages in the train consist. The lead carriage was 6212, followed by 5213, 5211 and 6211.
The Tangara train set was a double-deck 4-carriage set with 2 motor carriages in the centre and 2 driving control trailer carriages at each terminal end. All carriages were built by A Goninan & Co at Broadmeadow NSW between 1987 and 1997 and were first introduced into service on 12 April 1988.
The control trailer carriage had a compartment for the driver at the front and pantographs[19] on top of the carriage at the rear. The seating capacity of the control trailer carriage was 98 and it weighed 42 tonnes. The motor carriage had a seating capacity of 112 and weighed 50 tonnes.
The Tangara trains were made in two sub classes, the "T sets" for the suburban lines and the "G sets" for the outer-suburban lines. They could run as a set of 4 carriages, or 2 sets could be coupled together to run as an 8‑carriage set. On this morning, train C012 was running as a 4‑carriage Tangara set and was a substitute for the usual Oscar train set (H set) that was regularly servicing the South Coast rail line.
Figure 7: Tangara four-car set
Source: Sydney Trains
Digital Train Radio System
Sydney Trains had a Digital Train Radio System (DTRS) for meeting its train radio communication requirements on its rail network. DTRS was the primary train radio system providing voice and data services to the Sydney Trains electric passenger fleet for day-to-day train operations. It enabled communications between train crews, network controllers, mechanical control and other rail staff.
The DTRS on Set T42 did not work for the guard when they attempted to call the signaller after the incident. The WCP Signaller also attempted to contact the driver on the DTRS after the incident, but was unsuccessful.
Sydney Trains investigated the functionality of the DTRS after the incident. They found the DTRS was working. However, the guard was unable to contact the signaller using the radio as the radio unit had gone into standby mode. Likely as a result of a short circuit tripping the guard’s Control Circuit Breaker unit when the first carriage separated from the train.
The event recorder data revealed unexpected voltage spikes on the unpowered trainline ‘Door Open’ wires at the time that Car 1 (6212) was separating from Car 2 (5213). Sydney Trains concluded that the powered ‘Door Close’ trainline wire suffered a short circuit during the separation which tripped the guard’s Control Circuit Breaker in Car 4 (6211).
For the DTRS to work again, it required the guard to reset it.
DTRS instructions
NSW Trains had a train working procedure NTTWP 182 Digital Train Radio System. This working procedure provided instruction on how to use the system including how to Start Up and conduct a Network Audio Test and how to identify cab radio and Transponder faults during start‑up. The procedure did not cover how to reset the system and in which situations the DTRS would need to be reset.
The quick guide to the DTRS for guards ‘how to’ video, available on Sydney Trains Intranet provided instructions on how to use the various functions of the DTRS, including how to start up, conduct the various tests, and make emergency calls. There was no instruction on what to do if the DTRS went into standby mode.
Other procedures that provided instruction to train crew on how to respond to an incident, such as, the Operator Specific Procedure NTOSP 12 Responding to an incident and NTTWP 154 Responding to an incapacitated Driver or Guard/Passenger Service Supervisor, focus on what information to provide when reporting an incident, not how to operate the device used to report the incident.
Rail Operations Centre (ROC)
The Rail Operations Centre (ROC) was a purpose-built operations centre for running the Sydney Trains Rail Network. The goal of the ROC was to enable the network to run more efficiently, improve punctuality and achieve faster incident recovery. Teams from Sydney Trains and NSW TrainLink worked together to manage all aspects of the network.
The ROC Control Room Floor (CRF) was established in March 2019, and Security, Operations, Customer Information and NSW TrainLink all began operating from the site. Signal Box Operations later joined the CRF from July 2019. While most signal operations were managed from the ROC, a few signal operations still operated from external signalling control complexes. For instance, Wollongong Signalling Complex controlled the signals on the south coast rail line.
The CRF at the ROC comprised of the following directorates and agencies: Engineering and Maintenance (ICON), Operations Delivery (Service Delivery and Security), Customer Service (Customer Information Unit and Customer Operations), Train Crewing and Support (TCO), and NSW TrainLink.
Network Operations Reform
Prior to the ROC, Sydney Trains’ rail network operations was primarily managed from the Rail Management Centre (RMC). Commencing in late 2018, Sydney Trains changed its operating model to prepare for the future move into the ROC.
A key objective of the new operating model was to improve the way incidents and service disruptions were managed. The operating model previously used by Sydney Trains had been the same for almost a century, with the role of the Train Controller historically managing both ‘Train Service Delivery’ and ‘Incidents’ across the rail network.
During this reform, Sydney Trains broke up the key functions of the Train Controller and introduced two new roles:
Train Service Delivery Manager (TSDM), whose role would be to focus on managing train services across the network.
Network Incident Manager (NIM), whose focus would be to manage incidents on the rail network and any unplanned possessions and work on track authorities.
During this transition, several communications were released to ensure staff understood the scope of the changes. A summary of the changes was provided in the document ‘Network Operations Changes’ and specific information on the Network Operation Reform was provided to stakeholders, such as Security and Train Crewing, so they could understand how the changes affected them.
A key change included defining where responsibilities lay with the new roles. A table comparing responsibilities from the old Train Controller to the new TSDM and NIM was provided to all\\stakeholders.
The table of responsibilities below was provided to Security:
Table 1 – NOR Stakeholder Information – Security
Train Controller, TSDM and NIM responsibilities
Today
As of 2 December 2018
Train Controller
TSDM
NIM
Receives all calls from Security
Manage incidents
Receives all initial calls from Security, if Security not already dealing with an incident
TSDM will escalate the call to the NIM if required
Receives follow up calls from Security or escalated from the TSDM regarding incident
Manage incidents
The stakeholder communication stated all initial calls needed to go to the TSDM which contradicted Sydney Trains’ overarching Command and Control structure.
The stakeholder information also clarified the new network control boundaries and who was responsible for the area.
The previous Train Controller boundaries had broken the rail network into 6 train control areas.
New boundaries for the TSDM were broken into 5 train control areas, with 2 NIM areas to cover the entire rail network, a North and South, which overlaid the TSDM boundaries (Table 2).
Table 2 – NIM and TSDM area boundaries
NIM North
NIM South
TSDM Main
TSDM North
TSDM Central Coast
TSDM Illawarra
TSDM South-West
Involved parties in the ROC
Key roles located in the ROC who were involved in this incident included the Duty Control Manager (DCM), Network Incident Manager (NIM), Train Services Delivery Manager (TSDM), and the Security Control Centre Operator (SCCO).
Duty Control Manager (DCM)
The DCM oversees the daily operations for everyone on the CRF. As the lead for Service Delivery and Customer Operations on the CRF, their role was described in the Sydney Trains document Control Room Floor Roles, as responsible for creating a collaborative work environment to support and empower others to make informed decisions promptly. They drive continuous improvement, encourage technology adoption including systems and procedures, and aimed to achieve improved operational efficiencies while building customer advocacy, amongst other responsibilities.
The DCM was also responsible for managing Level 2 – Critical incidents on the rail network. This is further explained below in Network Incident Management Plan.
Figure 8: ROC Control Room Floor
Source: Sydney Trains
Network Incident Manager (NIM)
The NIM was responsible for end-to-end management of operational rail incidents that happen on the network. They played a key role in communicating with operational employees and updating internal and external stakeholders about incidents. The decisions they made were focused on providing a safe process for people on and about the track and safe transportation of customers.
The NIM was responsible for managing Level 1 – Routine incidents on the rail network. This is further explained below in Network Incident Management Plan.
As their primary role was managing routine rail incidents, the NIM was provided access to the DTRS which enabled them to communicate directly with train services on the rail network.
Train Services Delivery Manager (TSDM)
The TSDM was responsible for the day-to-day management of train service delivery and ensuring smooth running of services on the Sydney Trains network.
They provided thorough communication of real-time information of service status updates and changes to train plans to other business areas.
TSDMs did not have direct access to the DTRS. To pass information to train crew, the TSDM would need to go through the NIM or a Signaller.
The Security Control Centre Operator (SCCO)
The SCCO is part of Rail Network Securityand is discussed later in the report.
Other involved parties
Signallers
Signallers are responsible for the control and supervision of rail traffic movements, the operation of signalling equipment and coordinating train movements within their area of control in accordance with safeworking regulations.
Train operations at Kembla Grange were controlled by a signaller located at the Wollongong Signalling Complex who operated points[20] and signals[21] to permit rail traffic movements. The complex was located approximately 12km from Kembla Grange Station and the location of the incident.
Signallers used a push button panel which allowed the control and interaction with signalling infrastructure from a remote location. The signallers used the panel to set start and stop points for the intended routes. As the train enters the controlled area, lights illuminate on a large visual display board indicating the location of the train. This allowed the signaller visibility of trains within their designated area.
They could communicate with trains in their area using the DTRS. This communication could occur through either point-to-point calls to specific trains, or emergency broadcasts to all trains on the local network.
Wollongong Coast Panel Signaller (WCP Signaller)
The WCP Signaller involved in this incident was located at the Wollongong Signalling Complex. They were responsible for operation of the track circuited territory on the South Coast rail line from Berry to Kembla Grange (Figure 9).
In this incident, the TSDM made a call to the WCP Signaller to request all trains be stopped once they learned there was a motor vehicle on track.
Wollongong Panel Signaller (WP Signaller)
The WP Signaller was also located at the Wollongong Signalling Complex and seated alongside the WCP Signaller. As both signallers were in the same room, it was easier for them to communicate about the incident.
The WP Signaller was responsible for operation of the track circuited territory from Port Kembla to Wollongong, including Port Kembla Yards and Inner Harbour (Figure 9).
The WP Signaller received the emergency call from the Guard at 0411:56 from the guard’s work‑issued mobile phone. At this time, the TSDM and the WCP Signaller were also on a call, which was when the TSDM requested the WCP Signaller to make an emergency call to stop all services.
Figure 9: Signalling Panel Boundaries
The boundary of responsibility for the Wollongong Coast Panel Signaller in Orange, Wollongong Panel Signaller in Purple.
Source: Sydney Trains
Incident Rail Commander (IRC)
IRCs provided 24/7 operational response coverage for all major rail incidents on the Sydney Trains network (area bounded by Newcastle, Lithgow, Macarthur, Nowra).
The role of the IRC was to provide onsite incident management for rail incidents within Sydney Trains’ network to ensure effective and timely resolution of operational problems, and safety of all staff, contractors, commuters, and emergency services personnel.
Electrical Operations Centre (EOC)
The EOC was one of 6 maintenance operations centres that combined to form the Infrastructure Control Centre (ICON). The EOC was responsible for high voltage supply control, 1,500 V traction supply control, emergency repair coordination and electrical incidents.
A call from the EOC was made to the NIM when they detected a sustained fault of the high voltage supply between Unanderra and Dapto Stations.
Police Radio Operations Group (ROG)
The ROG was the radio dispatch and contact centre providing 24/7 assistance and service to the NSW Police Force and members of the community.
The ROG had Communications Officers who were responsible for processing incoming calls from police and the community, including emergency triple zero calls.
The ROG also had Radio Dispatch Channel (RDC) Operators who were responsible for tasking and coordinating activities of police resources responding to incidents, using both the police radio network and the Computer Aided Dispatch (CAD) system. They provided timely information to operational police to enable appropriate action to be taken.
The Communications Officers and RDC Operators were required to complete training in telephony and police dispatch business systems. They and other general duties police officers did not receive specific training in managing emergencies and other risks on the rail network.
In this incident, communication about the motor vehicle on the rail line between the ROG and Sydney Trains occurred between an Assistant RDC Operator and the SCCO. The sequence of communication from the emergency triple zero call is described in Incident Communication and Timelines.
Driver
The driver commenced working on the New South Wales railways in 2011. They worked in the south and west region, South Coast area as part of the Wollongong crew. Review of the driver’s training records indicated they were appropriately qualified, with the most recent competence assurance assessment conducted in November 2020.
The driver was on their third shift after 4 days off. The 3 shifts were all early starts, with the earliest start of 0200 on the morning of this incident.
At interview the driver stated they felt alert while driving, the early start was a regular starting time and they had adjusted to the early starts. The investigation did not find fatigue to be a contributing factor to the collision.
Guard
The guard had worked on the rail since 2006. They also worked in the south and west region and South Coast area as part of the Wollongong crew. Review of the guard’s training records indicated they were appropriately qualified with the most recent competence assurance assessment conducted in December 2020. The guard completed Digital Train Radio System Cab User training in July 2016. They had not received any refresher training or additional training in the use of the DTRS.
The guard was on their third shift after 2 days off. The 3 shifts were all early starts, with the earliest start of 0154 on the morning of this incident. The investigation did not find fatigue to be a contributing factor to the collision.
Security
Since the opening of the ROC in 2019, Security merged its two functions of the Security Control Centre and the Security Monitoring Facility and both share a location on the CRF (Figure 8).
Security Control Centre
The Security Control Centre (SCC) provided the security incident command and control function and liaised with the NSW Police and emergency services to manage real-time response to incidents on the rail network. The SCC acted as a communication bridge between external stakeholders and internal stakeholders within the ROC as well as Sydney Trains and NSW Trains employees.
The Security Control Centre was tasked with real‑time monitoring of security cameras on the network.
Security Monitoring Facility
The Security Monitoring Facility (SMF) was a security support operation. The SMF provided CCTV footage when requested from authorised GIPA staff from NSW Police, Media Unit, Workplace Conduct Unit, and NSW TrainLink. They were the only approved provider of CCTV for Sydney Trains.
The two functions, the SCC & SMF, were led by one supervisor at the ROC.[22]
SCC Supervisor
The Supervisor of the Security section at the ROC was called the Security Control Centre Supervisor (or SCC Supervisor). This supervisor was responsible for managing and directing the activities of the Security section during the course of a shift whilst managing a team of security operators as the first line of supervision.
In emergency or crisis situations, the SCC Supervisor assisted the Rail Operations Centre and external Security Services in coordinating appropriate emergency responses. This was done in accordance with Sydney Trains’ procedures and response frameworks.
Security Control Centre Operator (SCCO)
The SCCO was responsible for utilising systems deployed within Sydney Trains Security Control Centre, to provide real time responses to security incidents and other emergencies on the rail network.
They assisted the SCC Supervisor to achieve the functions of the Security Control Centre, such as ensuring passenger safety, preventing equipment damage and theft to assist in improving the customer experience and the overall operations of Sydney Trains.
Amongst the stated responsibilities and operational duties in the Security Control Centre standard operating procedures, the SCCO had a duty to proactively monitor live CCTV cameras across the rail network. This was over 13,000 station-based CCTV cameras and 12,000 train‑based cameras. They were also required to monitor over 800 Help Points, the Alarm Management System and the Injury Hotline.
Emergency response
At the time of this incident, the Sydney Trains emergency response processes had changed from the Incident Management Framework Parts 1, 2 and 3 to the Emergency Preparedness Framework and the Network Incident Management Plan. These documents were developed and implemented in April 2021 to accommodate the Command and Control System that Sydney Trains was adopting for management of emergencies.
Emergency Preparedness Framework
This document described the process for developing and implementing both strategic and local incident management plans to ensure Sydney Trains responded effectively and safely to critical and other emergency situations.
The framework provided the need for the development of an Incident Response Guide and Network Incident Management Plan.
Incident Response Guide
This document contained instructions for first actions to be taken when responding to an incident. It covered a number of scenarios, including train collision/derailment and security threat amongst 15 other scenarios.
On the opening page it clearly defined contact points for rail and non-rail incidents. For rail incidents the 2 key contact points were the local area controller (signaller) and/or Security Control Centre.
Network Incident Management Plan
The Sydney Trains’ Network Incident Management Plan (NIMP) established the appropriate response measures, command and control structure, roles, responsibilities, and functions to be implemented in case of an incident within the Sydney Trains Network.
The NIMP recognised incidents range in severity and must be continually monitored and assessed. They were categorised based on impact and severity before being escalated accordingly through the hierarchy of management/command in the ROC.
As stated in the NIMP, Sydney Trains used a Command and Control System that established strategic, tactical and operational hierarchy to manage rail operations. The ROC Control Room Floor (CRF) created an environment of central coordination, led by the Duty Control Manager (DCM), drawing on the knowledge and experience of key Subject Matter Expert (SME) teams.
The NIMP divided incidents into 2 categories: rail incidents and non-rail incidents.
For managing rail incidents, Sydney Trains has a 3‑tier incident management process, categorised into:
Routine Incident – Level 1
Critical Incident – Level 2
Crisis Event – Level 3.
As per the NIMP, a Critical Incident (Level 2) was defined as the following;
…any threat, act, event or incident, the acute impact of which severely disrupts business or causes a sustained disruption to Sydney Trains business efforts or reputation. This category includes situations where Sydney Trains may be supporting a State response to a wider disaster or emergency.
The NIMP also stated that incidents that escalate to the Critical level must be raised with the DCM for awareness and monitoring. During a Critical Incident the NIM would maintain their primary functions as indicated in the Routine incidents category, supporting the incident tactically in collaboration with the DCM. The NIM must deploy an IRC to the incident site to assume the role of Rail Commander.
This incident was escalated to a Level 2 incident at 0419, at which point the NIM informed the DCM as required. The NIM had deployed an IRC to the incident at 0415.
Section 4 of the NIMP detailed Incident Response. In the Initial Incident Response, Sydney Trains stated:
Once an incident is imminent or occurs, the alarm should be raised as soon as reasonably practicable so that assistance can be given to protect life, property and the environment. Often this means that first contact needs to be made to workers controlling train movements on the affected track section, the contact points are: • Local Area Controller (Signaller); or • Security Control Centre (SCC)
It also states the SCC can contact the police ROG and triple zero directly and is an efficient and timely reporting strategy. In other situations, a member of the public or an emergency service communication centre could raise the alarm.
In this incident, an alarm was raised by a member of the public calling triple zero which started a chain of communications commencing with the police ROG, to the SCCO, the TSDM, then to a Signaller and NIM and eventually through to the DCM.
Security Control Centre Standard Operating Procedures
The Security Control Centre (SCC)’s standard operating procedures (SOP) was a single document of 119 pages. Version 1.3 dated June 2021 consisted of 10 different sections. The tenth section contained 16 separate miscellaneous procedures.
The first 9 sections contained information that was duplicated from other Sydney Trains documentation.
Duplications included Section 5 Chain of Command and Key Relationships, Section 6 The Rail Operations Centre, Section 7.1 General Control Room procedures, 7.2 Emergency communications, 7.3 Network Rules and Procedures, and Section 8 Command and Control Incident Management System. These sections covered parts of the Sydney Trains documentation that were most relevant to Security.
In Section 8, the SCC SOP recognised the command and control responsibilities with section 8.1 specifically highlighting the NIM managing incident response for Level 1 – Routine Incidents, the DCM responsible for managing Level 2 – Critical Incidents and the Crisis Event Chair (CEC) managing Level 3 – Crisis Events.
Section 9 of the SOP covered Dispatching and Coordinating Incident Response. It stated that, ‘for ALL incidents managed by the SCC, the ‘Incident Response Checklist should be used…’
In section 9.2 the Incident Response Checklist for incidents that have an effect/impact on the rail network, the procedure prompted the SCCO to inform relevant TSDM/ NIM – MAKE SAFE. There was no reference to the Incident Response Guide developed as part of the overarching emergency management framework.
Communications
NTOSP12 – Responding to an Incident
This NSW Trains document provided the instructions for workers who became aware of or were involved in an incident. The worker was required to report the incident immediately to the relevant Network Control Officer and provide sufficient detail for the NCO to assess the severity of the incident and decide on a response.
The guard reported the incident to the Wollongong Panel Signaller at 0411:56, which they did with a work‑issued mobile phone. The guard said the train had derailed at the level crossing after colliding with a car on the tracks. The guard confirmed that there were passengers on the service and that they would walk through the train to check the welfare of passengers and the driver. The guard confirmed that the second car had derailed and was leaning to the side with lights out and that the lead carriage had derailed and was lying on its side. The guard also requested an ambulance for the driver.
NGE 206 Reporting and responding to a Condition Affecting the Network
This Sydney Trains document prescribed the rules for reporting and responding to unsafe conditions affecting or potentially affecting the network.
The rule stated conditions that can or do affect the safety of operations in the network must be reported promptly to the Signaller responsible for the affected portions of line. The rule further stated the signaller must promptly report the details of the Condition Affecting the Network (CAN) to the Network Controller and tell other affected Signallers.
Network Controllers are defined as qualified workers who on a day-to-day basis manage the safe and efficient operation of the Network. This includes the TSDM and the NIM.
The Signaller in this incident responsible for the affected portion of line was the WCP Signaller.
The report of the motor vehicle on track, which was the CAN, started from a triple zero call, which passed to the Police, the SCCO, the TSDM and then the WCP Signaller. It was highlighted in the Sydney Trains Investigation that all parties involved in the initial report of the motor vehicle on the rail line treated the incident as a routine Condition Affecting the Network (CAN) instead of an emergency.
Incident Communication and Timelines
When the emergency triple zero call was made by a member of the public, the call was initially received by a telecommunications officer who diverted the call to the Police as requested by the triple zero caller.
This happened at 0405:52, 3 minutes and 43 seconds before the WCP Signaller made the call to the driver of C012.
The call was then received by an ROG Communications Officer who recorded relevant information and started a CAD incident which was then sent onto the relevant Radio Dispatch Channel (RDC) Operator. The RDC Operator reviewed the CAD incident and broadcast over the radio channel for in field police units to respond. The RDC Operator also arranged for an assistant RDC Operator to call the Sydney Trains SCCO.
This call happened at 0407:37, 1 minute and 58 seconds before the WCP Signaller made the call to the driver of C012.
As per the SCC SOP, the SCCO called the TSDM at 0408:47, 48 seconds before the WCP Signaller made a call to the driver of C012.
The TSDM called the WCP Signaller at 0409:08, 27 seconds before the WCP Signaller made the call to the driver of C012.
By the time the WCP Signaller was told to stop all train services, then acted to call C012 directly to tell them to stop, it was 0409:35. Only 1 second before the driver of C012 applied emergency brakes.
Waterfall recommendations
The train set involved in this incident was the same type and configuration of the train that was involved in the 2003 Waterfall Rail Accident. As some recommendations from the Special Commission of Inquiry (SCOI) had actions against them that had not yet been completed and/or closed, they were reviewed as part of this investigation.
The review was to determine any influence and/or importance to the outcomes of this incident. While each recommendation and the associated actions are discussed below, the investigation concluded that the outcomes from this incident were not directly influenced by the status of the actions to address the Waterfall SCOI recommendations.
The Special Commission of Inquiry (SCOI) into the Waterfall rail accident released its final report on 17 January 2005. The report, titled the Final Report of the Special Commission of Inquiry into the Waterfall Rail Accident, made 177 recommendations (127 recommendations and 50 sub‑elements).
The implementation of these recommendations from this significant SCOI have been monitored by the Rail Regulator since 2005.
As specified in the Waterfall SCOI Annual Status Reports published on the Office of the National Rail Safety Regulator (ONRSR) website, ONRSR will continue to provide the Minister with annual reports for tabling in the NSW Parliament, in relation to the SCOI Final Report. ONRSR’s public reporting will continue until all recommendations are implemented, with reports being published on ONRSR’s website. At the time of authoring this report, 3 documents on ONRSR’s website provided the status of the recommendations. These were:
Waterfall Report No 39 2019
Waterfall Annual Status Report – All open and closed recommendations – April 2018 to March 2019
Waterfall Rail Accident Recommendations – Closed Subject to Implementation of an Approved Program or Plan – April 2018 to March 2019
These documents reported that all recommendations from the SCOI report were considered closed except for two. These recommendations had an acceptable response or acceptable alternative response. Six other recommendations were closed subject to implementation of an approved program or plan. That is, the Rail Regulator had agreed that the planned action or alternative action, when completed would meet the recommendation or satisfy the objective of the recommendation.
Open recommendations
No.32 – RailCorp should progressively implement, within a reasonable time. Level 2 automatic train protection (ATP), and
No.38 – There must be compatibility of communications systems throughout the rail network. It is essential that all train drivers, train controllers, signallers, train guards and supervisors of trackside work gangs in New South Wales be able to communicate using the same technology.
Recommendation No.32 – Automatic Train Protection
At the time of authoring this report, Transport for NSW (TfNSW) had implemented ATP (European Train Control System Level 1 Limited Supervision) on the Sydney Trains Network (excluding Erskineville to Bondi Junction and the Sydenham-Bankstown Line).
TfNSW was in process of implementing the ‘Digital Systems Program’ (DSP) which upgrades the technology to European Train Control System Level 2 (ETCS L2).
This program introduces the ETCS L2 and Traffic Management System (TMS) to parts of the T4 Line from Sutherland to Cronulla and from Redfern to Bondi Junction (Tranche 1). It will then be rolled out on North Shore, City Circle, City Area and Sydney Terminal (Tranche 2), as indicated inFigure 10.
System integration testing commenced in December 2023 and would be run in 3 phases and is planned for completion by end 2024.
ETCS L2 and TMS will replace current signalling and train control technology and allows trackside equipment to communicate with trains constantly. This provides better location and train information, to better manage train movements across the network.
The relationship to Recommendation No.4 – Precise Location is discussed below.
DSP rollout was planned in stages (tranches) and will cover the entire network including the South Coast rail line. The future tranches will be aligned with asset replacement (conventional signalling) and network needs and is subject to funding approval.
Figure 10: ETCS Level 2 rollout
Source: Transport for NSW
Recommendation No.38 – Digital Train Radio System
It was noted, the action to address Recommendation 38 became the focus of implementing a Digital Train Radio System (DTRS). A DTRS was installed in the incident train and serving as the main means of communications between the train crew and network control.
When the guard attempted to contact Network Control after the collision and derailment, the DTRS did not work. However, post‑incident testing of the DTRS established the DTRS had become inoperable due to a short-circuit tripping the guard’s Control Circuit Breaker likely because of the collision and derailment. The DTRS returned to “stand‑by mode” which required the system to be reset to be operable again. This could have been done by the guard, however the guard called Network Control using a work‑issued mobile phone.
In Sydney Trains’ investigation, a safety action was taken to communicate to train crew that the DTRS can be made operable by resetting the guard’s Control Circuit Breaker switch. However, in this incident, the decision by the guard to use the secondary mechanism of communication (the mobile phone) was likely a quicker and just as effective method of contacting Network Control due to the time required to restart the system.
Had the incident occurred on a part of the network with poor mobile reception, then the guard would need to rely on the DTRS being operable. So, the safety action to remind train crew the DTRS can be reset was relevant. Additionally, the same reset function applied to the public announcement (PA) system, which had also been tripped and rendered inoperable.
The focus of recommendation 38 was to ensure compatibility of communication systems throughout the rail network. While the DTRS was not used by the guard to contact Network Control, it was not due to incompatibility of communication systems.
To ensure the intent of this recommendation is met, the Regulator will continue to ensure functionality and compatibility requirements are met across the rail networks in New South Wales.
Closed recommendations subject to implementation of an approved program or plan
No. 4 The Rail Management Centre should be equipped by RailCorp with a transcriber system, or mimic board, or such other system as is necessary to enable identification of the precise location at any time of any train on the RailCorp network.
No.88 The RailCorp passenger containment policy must be abandoned. (RailCorp: Implemented – containment policy abandoned). Note: This recommendation will be finalised once Sydney Trains completes the rollout of its Internal Emergency Door Release (IEDR) retrofit program.
No.89 There must be a minimum of two independent methods of self-initiated emergency escape for passengers from all trains at all times.
No. 90 All passenger trains must be fitted with an internal passenger emergency door release.
No. 92 The internal passenger emergency door release should be fitted with a facility which prevents it from operating unless the train is stationary.
No. 93 The operation of train doors should have an override facility whereby the driver or the guard can override an internal passenger emergency door release system if the door release is interfered with when there is no emergency. There should be an alarm, together with an intercom, in the guard’s compartment so that, if a passenger attempts to initiate an emergency door release, there is an appropriate delay during which time an alarm sounds in the guard’s compartment and the guard can then, after first attempting to speak via the intercom to the individual concerned, if necessary, override the door release, and make an appropriate announcement over the intercom system in the train.
Recommendation No.4 – Precise Location
At the time of this incident, the South Coast Branch Line, where Kembla Grange Station is located, was in a track circuited territory where the system of safe working relied on track circuits to detect the presence of rail traffic.
As a train traverses a track circuited area, it disrupts the electrical currents flowing through the rails which can then be used to indicate the position of the train. Lights are illuminated on a train location board (see Figure 11) to allow the network controller to get an indication of the location of the train.
The distance between Dapto Train Station and Kembla Grange Train Station is 3.4 km and the network controller has several location indicator lights between these 2 stations to provide an indication of where the train is located.
While this by no means provides a precise location of a train, it could be argued that this is a reasonable indicator for the network controller to know where a train is at a given time.
This was evidenced in this incident when the WCP signaller was aware C012 was in the track section between Dapto and Kembla Grange and was able to respond to the TSDM by saying they would make direct contact with C012, when the TSDM said to stop all services.
Source: Sydney Trains. Kembla Grange located top left, Dapto located top right. C012 was travelling from Dapto towards Kembla Grange at the time of the incident.
The ability for network controllers to identify the precise location of a train on the rail network has been further enhanced as Sydney Trains continues to improve train position reporting.
The implementation of ETCS involves the installation of balises (electronic transponders) that are placed along the rail line and communicate with the train’s onboard system to provide location information.
The ETCS onboard system continuously estimates the current location of the train based on the distance travelled since the last balise was read using onboard odometry information and sends this position information to the ETCS trackside. A Network Controller can review an ETCS fitted trains’ reported location; however, this information is not presented on the Traffic Management System (TMS) screen in real time. The reported location information is limited by odometry accuracy.
The ETCS L2 system will enhance the train location information available to network controllers by
• Enabling smaller sections
• Providing more granular estimated train location information
Note – Track circuits are replaced by axle counters in ETCS L2 areas.
Recommendation No.88 – Containment
The train in this incident had not been retrofitted with the Internal Emergency Door Release (IEDR). At the time of this incident, a project aimed at enhancing the existing Tangara Fleet of trains in Sydney had commenced. The Tangara Technology Upgrade (TTU) Project was a collaborative endeavour, with TfNSW, Sydney Trains, contractors, and industry experts working together to enhance the Tangara trains. It was scheduled to be completed by 2025.
At the time of authoring, the current TTU project scope did not include internal emergency release mechanisms. However, internal emergency door release mechanisms would be installed as part of another project being managed and delivered by Sydney Trains, the Tangara Fleet Life Extension (TFLE) project. In the upgraded Tangara trains, passengers would have the ability to manually release doors from the inside, allowing for swift evacuation if needed. This enhancement aligned with modern safety standards and provided an additional layer of security for commuters.
It was however, noted that extraction of the passengers from the first carriage, that had tipped over, was completed by entry and exit through the rear of the carriage where there remained an opening from the first and second carriages separating. This opening provided a more accessible means of entering and exiting the carriage, compared to opening a side door and having to climb up and out.
The driver was also able to be rescued from the front cab of the carriage as the front emergency door could be opened (Figure 12).
Recommendation No.89 – Emergency escape
On the Tangara the 2 independent methods were the external sliding doors and the intercar doors into the next carriage. In the Kembla Grange incident as there was a separation between the first and second carriages as a result of the derailment, the intercar doors served as the means of entry and exit for the passengers from these carriages.
As the IEDR had not been installed on these carriages at the time of the incident, the second independent method of self-initiated emergency escape for passengers was not available.
The driver was extricated from the emergency door at the front of the train.
Figure 12: Emergency door at front of train
Source: OTSI
The other 3 closed recommendations (90, 92, and 93) all relate to the installation and functionality of an internal emergency door release. As mentioned above, this train set had not yet had the IEDR retro fitted.
Similar related incident
Collision of NSW Trains Intercity train N169 with abandoned motor vehicle Woy Woy, NSW 19 April 2024
At approximately 1756 hours on Friday 19 April 2024 at Rawson Road level crossing Woy Woy, New South Wales, an eastbound motorist turned left at the level crossing and accidentally drove their motor vehicle into the railway corridor. The driver exited the motor vehicle after it became stuck on the railway tracks.
Two witnesses arrived at the scene at approximately 1757 and reported they observed the motorist exiting the vehicle and a bystander getting into the vehicle to assist the driver to move it.
At around this time Witness 1 called a tow truck driver.
Witness 2 tried to confirm with bystanders onsite whether triple zero had been called. When they did not receive a response, they called triple zero, confirmed from phone records to have been at 1759.
Witness 2 reported experiencing delays through the triple zero triage process as the operator appeared to have difficulty comprehending the situation and the location. When eventually dispatched through to the police the witness reported the car stranded on the tracks.
After the phone call to the tow truck driver was completed, Witness 1 contacted the Network Incident Manager (NIM) by dialling the phone number displayed on the lineside signage and level crossing identification number for fault reporting. This call was received by the NIM at 1802:04.
An approaching train activated the Rawson Road level crossing at 1802:30, which was heard in the background of the phone call between the NIM and the witness. This call was terminated and the NIM placed a priority call to both the Central Coast and Hornsby North Signalling panel operators, to initiate an emergency “All Stop” message through the Digital Train Radio System (DTRS).
Central Coast issued an emergency all stop at 1802:55. The train driver reported hearing the broadcast just prior to the vehicle being struck.
At 1803:22 approximately 4 minutes after the triple zero call was made, and after the vehicle had been struck, the Police Radio Operations Group (ROG) Operator contacted Sydney Trains SCCO with the first notification of the motor vehicle on the tracks at Rawson Road level crossing. The ROG Operator conveyed police patrols had reached the site and the train had just collided with the car and that the car was unoccupied.
In social media footage of the collision police sirens can be heard in the background indicating police had been despatched to the incident prior to the ROG Operator reporting the obstruction to the SCCO. It is possible that had Sydney Trains received a call advising of the track obstruction from:
Witness 1 before they rang the tow truck driver
the ROG Operator immediately after the triple zero call from Witness 2,
the train driver of N169 may have received advice of the vehicle on the rail line in time to slow or stop short and prevent the collision.
Sydney Trains investigated this incident. During their investigation they found the NIM was unable to make Rail Emergency Calls (RECs) using their DTRS as the function was not switched on. This decision was made at the time the ROC commenced operations. It was noted that the NIM DTRS could still make point to point calls to trains.
Sydney Trains commented, given the NIM’s span of management over the network, point to point calls may not be practical in an emergency situation, hence the decision made by the NIM, in the Woy Woy incident, to bring in the Area Controllers was the best method of stopping trains at that time.
Rail Operations Management in Sydney Trains were not aware of the REC facility not being available to NIM terminals and this was not detected in their investigation of the Kembla Grange incident.
Safety analysis
Trespassing in the rail corridor and abandoning a motor vehicle on the rail line led to the collision and derailment of train C012 just south of the West Dapto Road Level Crossing at Kembla Grange.
The incident presented some opportunities which may have led to mitigation of the incident, and these have been discussed below.
Opportunities to mitigate risk
There were 2 opportunities which may have led to train C012 being stopped before it collided with the abandoned motor vehicle.
The first was when the individual who abandoned the motor vehicle tampered with the security CCTV cameras. The cameras were located on the Kembla Grange Station platform and positioned at the West Dapto Road Level Crossing. The individual tampered with the CCTV cameras approximately 45 minutes before the collision occurred.
The second opportunity to mitigate the event arose when a member of the public called triple zero to notify the police of the abandoned motor vehicle on the rail line approximately 4 minutes before the collision occurred.
Both opportunities are discussed further below.
After the collision and derailment occurred, there was a risk of further escalation of the incident. The Digital Train Radio System was not available for the guard to report the incident and there was potentially live 1,500 V overhead wires at ground level post‑incident on the accident site.
These issues are also discussed further below.
Security Control Centre operators unaware of camera tampering
On the morning of the incident at 0313 a Sydney Trains’ security camera located on the Kembla Grange Station platform recorded an individual moving the security camera. CCTV then captured images of the same individual moving the level crossing cameras away from the level crossing to face directly downwards at 0326, approximately 45 minutes before the collision.
Sydney Trains Security Control Centre was not aware the camera had been moved until 0412:57, 3 minutes 17 seconds after the collision. The SCCO identified the camera movement during the phone conversation with the ROG, which occurred after the collision and derailment.
There was an opportunity for Sydney Trains to detect a security risk at 0313 and 0326, and perhaps stop the sequence of events which led to the vehicle on the track.
Had the camera movements been detected there may have been an opportunity for the Security Control Centre to deploy rail security or police to the scene. These responders may have stopped the individual from attempting to cross the track or detected the presence of a vehicle on the tracks.
While it cannot be said with certainty that events after the detection of a camera being tampered with would have prevented the motor vehicle being stuck, early detection of, and proactive response to camera tampering may provide the opportunity to intervene when security risks such as this occur.
CCTV monitoring
The Security Control Centre’s Standard Operating Procedures (SCC SOP) suggested the Security Control Centre provides proactive monitoring of the entire Sydney Trains rail network. Page 10 states that operators proactively monitor over 13,000 station‑based CCTV cameras and 12,000 train‑based cameras, over 25,000 cameras in total.
The SCC SOP detailed the floor plan and desk set‑up for the Security Control Centre operators and provided the minimum staffing levels for given shifts. While much of the time 4 Security Control Centre operators were rostered to live monitor the rail network, there could be up to 5 Security Control Centre operators on some shifts or during night shifts as few as 3 operators.
The task of monitoring some 25,000 station and train‑based cameras was, therefore, as detailed in the SCC SOP, expected to be effectively managed by 3 to 5 individual operators depending on the numbers on shift.
The Security Control Centre operators were each assigned a particular area to monitor e.g. Console 4 live monitors the Illawarra and Bankstown Lines. This operator was responsible for live monitoring over 3,000 cameras.
This monitoring involves an individual overseeing many cameras on monitors at a desk. As a result, it is not possible to effectively monitor all assigned cameras at the same time, or reliably monitor camera changes, as in this incident where camera tampering was not detected.
Tamper alarms
Installation of tamper alarms on cameras was identified and agreed to by Sydney Trains as a reasonable measure to improve the security of the rail network. Tamper alarms provide an opportunity to improve proactive live monitoring as Security Control Centre operators in principle should be immediately alerted to a tampering event. This would then enable the Security Control Centre operator to act expeditiously.
A CCTV Upgrade Project to install tamper alarms on all cameras across the rail network was started in 2015. The scope of the CCTV Upgrade Project was amended during implementation, when excessive false alarms were encountered. The scope was amended to place tamper alarms on all cameras that were under 2.4m in height or were covering specific assets, such as level crossings, or any camera with a history of vandalism. Sydney Trains identified in their investigation of this incident that the revised tamper alarm functionality had not yet been fully implemented. Including activation of the tamper alarms on the West Dapto Road Level Crossing, even though it was identified for activation.
The Sydney Trains Network Maintenance group took charge of the project in December 2020 and a CCTV Operational Working Group was formed to continue progress from February 2021. Progress on installing these tamper alarms was continuing at the time of publishing this report.
The opportunity for detecting these types of events remains significantly lower while the installation of tamper alarms or alternative solutions remained outstanding.
No alert to train crew
In this incident, the train crew was not alerted to the abandoned motor vehicle on the track in time for them to slow or stop the train to avoid a collision or mitigate the outcomes. The recorded radio call from the WCP Controller to C012, highlighted the WCP Controller attempting to call C012 at 0409:35 and there was no response.
There was an opportunity for the collision and derailment to be avoided when a report of a motor vehicle on track came from a triple zero call from a member of the public at 0405:52. Sydney Trains was not alerted to this until 0407:37, which meant there remained approximately 2 minutes for a message to be provided to C012 to stop prior to the collision at approximately 0409:35.
This time was taken up with the passing of information from the SCCO to the TSDM and then to the WCP Signaller, who then made the call to C012 via the DTRS at about the same time the driver of C012 applied emergency brakes on the train.
The audio recording of these calls highlighted emergency awareness as an area for improvement. If the message had reached the driver of C012 in time, they could have slowed or stopped the train which could have prevented the collision from occurring or lessened the outcome.
Rail emergencies
The definition of an emergency in the railways is essentially any incident requiring urgent action which might involve death or serious injury, health and safety effects and/or significant damage to property or infrastructure[23].
A vehicle obstructing the rail line presents an immediate threat to the safety of train crew and the travelling public and therefore requires immediate action to stop all train services in the vicinity to prevent collision and escalation.
There is a level of understanding about rail operations that the ROG would glean over time through the interactions they have with the Sydney Trains Security Control Centre, however a firm understanding of what constituted an emergency on the rail line would not be expected to be known by the ROG without clear instruction or rail emergency training. As the ROG is the first contact point from a triple zero call about a rail emergency, it would be reasonable to review whether rail emergency awareness training should be provided to ROG Communications Officers and RDC Operators.
The SCCO is the first point of call into Sydney Trains from the ROG for these types of emergencies.
As a rail employee, the SCCO receives relevant training to identify rail emergencies. However, Sydney Trains stated in its internal investigation that the SCCO had not received any training in responding to emergencies since 2017.
Emergency situations are times when people are required to make fast and deliberate decisions and take actions to mitigate further escalation of consequences. As the SCCO had not received regular emergency refresher training in the preceding 4 years, their appreciation and understanding of how to react in an emergency was likely not at a competency level required for an effective response.
The SCCO’s response reflects this as they took considerable time to verify and confirm with the Assistant RDC Operator that there was a motor vehicle stuck on the rail line before they made the call to the TSDM. The Assistant RDC Operator stated there was a report of a car stuck on the rail line 19 seconds into the conversation with the SCCO. Valuable time was used up and at 47 seconds into the conversation the SCCO asked if it is confirmed a motor vehicle is on the train tracks? Then at 58 seconds asks, are “they” inside the corridor? To which the Assistant RDC Operator needs to confirm if the SCCO means the deployed NSW Police. All taking up critical time to potentially stop a collision and further escalation.
It took 1 minute and 10 seconds before the SCCO made a call to the TSDM.
Without suitable training and practice exercises in emergency situations, the SCCO was possibly slower to respond to the information given to them by the Assistant RDC Operator. In a role that is required to understand and act expeditiously when emergencies arise, the level of training and exercising of the appropriate response for SCCOs is important.
Performing well in a situation that arises on rare occasions is not guaranteed when that individual has not been provided training in emergency response for many years.
A report of a motor vehicle stuck or any significant object on the rail line poses an immediate threat to life and the safety of train services and should be treated as an emergency. With appropriate training and/or instruction the reaction to this information should be to take immediate action to stop train services to avoid collision and prevent escalation.
Management of rail emergencies
As discussed previously, there was inconsistency between the SCC SOP and NIMP.
The NIMP required all incidents to be reported to the NIM or the DCM to be managed, however the report from the SCCO of the incident was directed to the TSDM.
An explanation for this was presented in Sydney Trains’ internal investigation, that being, the SCCO perceived the situation as a routine Condition Affecting the Network (CAN), rather than as an Emergency (which is a type of CAN requiring a more urgent response).
This incident was an emergency as defined by the NIMP and therefore needed to be treated in accordance with the NIMP. The NIMP required that once the incident is imminent or occurs, first contact needs to be made with workers controlling train movements on the affected track section.
This is the accepted and accredited process for Sydney Trains Network Incident Management.
When the SCCO called the TSDM after they were informed of a motor vehicle on the track, the incident was not managed in accordance with the requirements of the NIMP. This incident required a call to the NIM or the DCM to manage. That said, the TSDM in this instance acted quickly to advise the signaller to stop all trains.
Procedure with conflicting instructions
The Sydney Trains Security Control Centre Standard Operating Procedure (SCC SOP) contained conflicting instructions for incident response. While referencing the Command and Control System as the new Incident Management System that is detailed in the Network Incident Management Plan (NIMP), the SCC SOP also introduced the TSDM to the incident response process.
Page 59 of the SCC SOP contained the 'Incident response checklist'. This checklist is to be used for all incidents managed by the Security Control Centre.
Its purpose, to provide prompts for the SCCO in the event of an incident that may have an effect or impact on the rail network. The SCCO is instructed to "Inform relevant TSDM/NIM - MAKE SAFE."
The SCC SOP introduced the TSDM as a point of contact in an incident, however, the Sydney Trains NIMP only states the NIM and DCM, as the points of contact, for Level 1 and 2 incidents.
The NIMP provides a clear statement of roles and their responsibilities for managing network incidents. There is no mention in the NIMP of a role for the TSDM in the command and control system.
Sydney Trains also identified in their internal investigation an issue with inclusion of the TSDM in the Security Control Centre procedures.
Page 30 of the Sydney Trains Investigation report stated:
The current SCC Standard Operating Procedure v1.3 and informal procedure allowed for the TSDM to be informed of the motor vehicle on the running line to determine the response, instead of specifying only the NIM, introducing an additional line of communication with no access to the DTRS.'
This highlighted that inclusion of the TSDM in the lines of communication slows response to an individual that has access to the DTRS (and hence an ability to STOP train services). Sydney Trains also highlighted in their investigation that an alternative solution to getting the SCC SOP and Sydney Trains NIMP processes consistent, would be to consider the processes that are occurring already as embedded and instead provide the TSDM with the ability to stop all train services when an incident such as this one occurs.
Given the competence displayed by the TSDM in this incident, the alternative solution proposed by Sydney Trains, to give the TSDM access to the DTRS and the ability to stop all train services when required is worthy of assessing for feasibility of implementation.
In the related Woy Woy incident, the NIM still opted to call the signaller to place an emergency broadcast, rather than placing a point to point call themselves, as they determined that this was the most effective means to stop the train. This was required as the REC functionality on the NIM’s DTRS had been turned off. NIMs could still make point to point calls to trains but not emergency broadcasts. This was the status of the NIM DTRS functionality at the time of the Kembla Grange incident, and this status was unknown to Sydney Trains Rail Operations Management.
However, awareness of the issue has led to further technical advice being sought regarding the practicality of switching on the REC facility on NIM DTRS terminals, with a view to determining the best method/ shortest practical communication chain to stop trains in emergency situations.
Digital Train Radio System
The DTRS on Set T42 did not work when the guard attempted to call the Signaller after the train had collided with the motor vehicle, derailed, and separated. After the derailment and separation, the Signaller made attempts to contact the driver on the DTRS but was unsuccessful.
Sydney Trains investigated the functionality of the DTRS after the incident. They found the DTRS was working as required. The radio unit on the train had gone into stand‑by mode likely because of a short circuit in the guard’s control circuit breaker unit, which occurred when the train collided, and the first carriage separated.
For the guard to be able to use the DTRS again, it required the guard to reset it.
In post‑incident testing of the DTRS, a reset of the unit was conducted, and it took approximately 30 seconds for the radio to restart after the guard key in and another 50 seconds to get through the service menu to make an emergency call.
In this emergency where the guard was in a heightened state of arousal, 80 seconds is a considerable time to wait for the radio to be usable again. Had there been no other option, then the DTRS would have been available for the guard to use after a reset, provided they had appropriate instruction on how to reset it.
In this instance the guard had a second option available which was to use a mobile phone to contact the network controller. This option was a quick and effective way of reporting the situation.
High voltage risk
As a consequence of the collision and derailment, the front carriage collided with a high voltage stanchion, bringing it to the ground along with 1,500 V overhead wires.
The Electrical Operations Centre (EOC) was alerted to a sustained fault between Unanderra and Dapto and notified the NIM approximately 4 minutes after the collision. It is highly probable the sustained fault was caused by the front carriage bringing down the high voltage stanchion. This sustained fault meant the power through the overhead wires in this section had been cut off however, verification of power being cut from the overhead had not been conducted.
Instruction from the NIM was for everyone to treat the overhead wires as live until the Rescue Power Outage (RPO) was issued.
At 0411:56, 2 minutes 16 seconds after the collision, the guard was reporting the incident to the WP Signaller. During this call the guard tells the WP Signaller that the police are onsite.
At this point, the Incident Rail Commander (IRC) had not made it to site to take control and there had been no verification of high voltage power being cut out. With no other qualified person onsite, the guard had assumed the role of Site Controller.
It is important to highlight the competence of the guard, and their training, as it enabled them to inform the police and other first responders to watch out for the high voltage danger of the overhead wires and live portion of the train.
Additionally, a secondary avenue of mitigating risk exposure to the police was in action through the communication chain between the SCCO and Assistant RDC Operator informing emergency personnel on site to treat the wires as live.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the collision between passenger train C012 and a motor vehicle on track near West Dapto Road level crossing, Kembla Grange, New South Wales, on 20 October 2021.
Contributing factors
An individual abandoned a motor vehicle on the rail line south of West Dapto Road Level Crossing, Kembla Grange.
Train C012 collided with the abandoned motor vehicle south of West Dapto Road Level Crossing and derailed.
The driver of C012 was not alerted to the abandoned motor vehicle on the rail line in time to stop the train prior to colliding with the vehicle and derailing.
Other factors that increased risk
An Individual tampered with CCTV cameras monitoring the West Dapto Road level crossing at Kembla Grange Station without being detected.
Sydney Trains Security Control Centre Operator was not alerted to tampering of the cameras at Kembla Grange Station that monitored the West Dapto Road level crossing.
Sydney Trains Security Control Centre Standard Operating Procedure contained conflicting instructions on incident response, which were not aligned with the Sydney Trains Network Incident Management Plan (NIMP).
Report of a motor vehicle stuck on the rail line was not treated as an emergency.
There was a risk to the guard and first responders who attended to the driver and injured passengers, when the potentially live 1,500 V overhead wires came down to ground level.
When the guard tried to make an emergency call on the Digital Train Radio System, they could not use it to contact Network Control in a timely manner.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the [aviation, marine, rail] industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Sydney Trains Security Control Centre Operator unaware CCTV cameras tampered with at Kembla Grange Station
Safety issue description: Sydney Trains Security Control Centre Operator was not alerted to tampering of the cameras at Kembla Grange Station that monitored the West Dapto Road Level crossing.
Response by Sydney Trains: CCTV software has been recently upgraded to allow use of a centralised server-based analytics engine to provide alarm functionality. Additionally, Sydney Trains has purchased software licenses to allow development / testing / trialling of this software. It is believed that the more sophisticated analytics available will allow detection of incidents such as the tampering at the West Dapto Level Crossing while reducing the false alarm rate.
ATSB comment: This action is appropriate to ensure a risk control for trespassers on the rail line being detected is in place. In the interim period, while the control is being developed, tested and trialled, without any other control for tamper detection, the trespasser risk remains untreated.
Sydney Trains Security Control Centre Operator procedure contains conflicting instructions on incident response
Safety issue description: Sydney Trains Security Control Centre Standard Operating Procedure contained conflicting instructions on incident response, which were not aligned with the Sydney Trains Network Incident Management Plan (NIMP).
Response by Sydney Trains: The Security Control Centre Standard Operating Procedure has now been aligned with the Sydney Trains Network Incident Management Plan with Security Control Centre Operators required to contact NIMs rather than TSDMs, and, Security Control Centre Operators' initial training in responding to emergencies has been upgraded (initial training module - STSCC02C - Knowledge & Skills) so that initial training around communicating during emergencies is improved and a recertification module (STSCC07A - SCC - Competency Assurance Assessment) is currently under development and will be provided as refresher training.
It is expected that the refresher training will be provided to operators every 12 months.
ATSB comment: The actions taken by Sydney Trains as described above addresses the inconsistencies previously in the safety management system. The safety issue is considered closed adequately addressed.
Glossary
CAD
Computer Aided Dispatch
CCTV
Closed Circuit Television
CRF
Control Room Floor
DCM
Duty Control Manager
DTRS
Digital Train Radio System
EOC
Electrical Operations Centre
ETCS
European Train Control System
IEDR
Internal Emergency Door Release
IRC
Incident Rail Commander
NIM
Network Incident Manager
NIMP
Network Incident Management Plan
ONRSR
The Office of the National Rail Safety Regulator. Administered and enforced compliance with the Rail Safety National Law and Regulations.
RDC
Radio Dispatch Channel
REC
Rail Emergency Call
ROC
Rail Operations Centre
ROG
Radio Operations Group
RPO
Rescue Power Outage
RISSB
Rail Industry Safety and Standards Board. Responsible for the provision of standards, codes of practice, guidelines, rules, safety data and analysis for the Australian rail industry.
SCCO
Security Control Centre Operator
SOP
Standard Operating Procedure
TSDM
Train Services Delivery Manager
WCP
Wollongong Coast Panel
WP
Wollongong Panel
Sources and submissions
Sources of information
The sources of information during the investigation included:
the Driver of C012
the Guard of C012
Train data logger from D6212 and D6211
Sydney Trains CCTV cameras
Sydney Trains audio communication systems
Sydney Trains documented management systems
NSW Trains documented management systems
Transport for NSW
NSW Police Investigation
References
ONRSR annual implementation reports on the NSW Government response.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any individual whom the ATSB considers appropriate. That section allows an individual receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Driver of C012
Guard of C012
NSW Trains
Sydney Trains
Transport for NSW
ONRSR
NSW Police
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Rail safety investigations in New South Wales
Most transport safety investigations into rail accidents and incidents in New South Wales (NSW) and Victoria are conducted in accordance with the Collaboration Agreement for Rail Safety Investigations and Other Matters between the Commonwealth Government of Australia, the State Government of NSW and the State Government of Victoria. Under the Collaboration Agreement, rail safety investigations are conducted and resourced in NSW by the Office of Transport Safety Investigations (OTSI) and in Victoria by the Chief Investigator, Transport Safety (OCI), on behalf of the ATSB, under the provisions of the Transport Safety Investigation Act 2003.
The Office of Transport Safety Investigations (OTSI) is an independent statutory body which contributes to improvements in the safety of bus, ferry and rail passenger and rail freight services in NSW by investigating safety incidents and accidents, identifying system-wide safety issues and sharing lessons with transport operators, regulators and other key stakeholders. Visit www.otsi.nsw.gov.au for more information.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1]EDT: Coordinated Universal Time (UTC) + 11 hours.
[2]The SCCO was responsible for utilising systems to provide real time responses to security incidents and other emergencies on the rail network (see The Security Control Centre Operator (SCCO) page 17).
[3]Electronic transponders are located at various locations on the Sydney Trains Network to monitor train speeds.
[4]The TSDM is responsible for the day-to-day management of train service delivery (see Train Services Delivery Manager (TSDM) page 14).
[5]The WCP Signaller was responsible for signalling operations on the South Coast rail line from Berry to Kembla Grange (see Wollongong Coast Panel Signaller (WCP Signaller) page 14).
[6]The WP Signaller was responsible for signalling operations from Port Kembla to Wollongong and sat adjacent to the WCP Signaller in the Wollongong signalling complex (see Wollongong Panel Signaller (WP Signaller) page 15).
[7]The NIM is responsible for managing operational rail incidents that happen on the network (see Network Incident Manager (NIM) page 14).
[8]Signals placed at STOP with blocking facilities applied prevents other rail traffic from entering the area.
[9]The EOC is responsible for the monitoring and repair of overhead wiring systems (see Electrical Operations Centre (EOC) page 16).
[10]Radio Operations Group (ROG) is NSW Police communications (see Police Radio Operations Group (ROG) page 15).
[11] IRCs provide onsite incident management for significant and major rail incidents within Sydney Trains network (see Incident Rail Commander (IRC) page 15).
[12]The Work Group Leader Traction was the Supervisor of the maintenance team responsible for work on Train Traction Systems.
[13] A Level 2 incident is a Critical event which severely disrupts the business (see Network Incident Management Plan page 18).
[14]The DCM leads the day of operations for all people on the Control Room Floor (CRF) and is also responsible for managing Level 2 – Critical incidents on the rail network.
[15] A Rescue Power Outage (RPO) temporarily removes power from the overhead lines for rescue of injured persons where contact with 1500 V overhead wire is a risk.
[16]A Level 3 incident is a Crisis event and considered an emergency, in line with the State Emergency and Rescue Management Act 1989 definition (see Network Incident Management Plan page 18).
[17] The emergency authority was the Electrical Authority for Removal of Supply from 1500 V overhead wiring system.
[18]A bi-directional rail line allows trains to travel, at different times, in both directions on the same rail line.
[19]A pantograph is a device mounted on the roof of an electric train, tram, or electric bus. It collects power by contacting an overhead wire or line which allows the vehicle to draw electrical energy to operate.
[20]A track component consisting of paired pieces of tapered rail that can be moved and set to allow tracks to diverge or converge.
[21]A fixed signal placed near a running line to authorise and control running movements.
[22]The Security section in the ROC is referred to as the ‘Security Control Centre’ by Sydney Trains and this report will use the term SCC to refer to the entirety of the Security section at the ROC.
On 30 October 2021, empty coal train 9QJ5 travelling west to Moura mine, derailed at the 99.270 km point between Mount Rainbow and Dumgree, Queensland. A total of 20 wagons and 2 remote locomotives (mid-train) derailed.
The derailment occurred following ballast undercutting work that had been completed 2 days prior. Two empty coal trains heading west had travelled over the section, without incident, prior to train 9QJ5.
What the ATSB found
The ATSB found that train 9QJ5 derailed likely due to a track irregularity following track disturbance works between Mount Rainbow and Dumgree. The track irregularity likely developed under the passage of the train.
The rail stress-free temperature, near the point of derailment, was not adjusted following the track work as planned. Consequently, the track was likely left in a stressed condition when the track was handed back fit for service.
It was also established that temporary track monuments had not been regularly placed throughout the worksite, being only used for about the final 200 m of work. While this was not considered contributory to the derailment, this increased the risk of the track not being returned to the correct position following track disturbance work.
Further, after the track disturbance works had been completed, a temporary speed restriction of 40 km/h was not applied to assure safe passage over that section of track. This was particularly important given that the rail stress-free temperature was unknown at that time.
What has been done as a result
Aurizon has implemented various safety actions, including developing and implementing a rail stress worker course, conducting roadshows to discuss the Track Stability Manual, reviewing and updating the manual, and creating a rail stress appreciation course. In addition, they have updated the site assessment walkout templates with rail stress information and issued a toolbox talk to infrastructure workers, reinforcing procedural requirements during track-disturbing work to maintain track stability.
Safety message
This accident highlights the importance of assuring track stability following disturbance work through having a correct rail stress‑free temperature, which is critical to rail safety. Likewise, track stability assurance also relies on the use of accurate track offsets, during, and temporary speed restrictions, following, track disturbance work.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
Scheduled maintenance
On 27 October 2021, at about 1230 local time, Aurizon’s RM902 ballast cleaning machine began ballast undercutting work along a section of track between Dumgree and Mount Rainbow, Queensland, from 99.800 km to 98.300 km. The work was part of planned track maintenance on Aurizon Network’s Moura system, integrated possession number 75, between Graham and Dumgree (Figure 1).
Due to operational considerations, ballast undercutting work concluded early at about 2020, completing 554 m between 99.840 km and 99.286 km. The RM902 ballast cleaning machine departed the site at 2255.
On 28 October 2021, ballast resurfacing was conducted over the same section and was completed at 1140. Following this, local level crossings were re-established and, at 2245, the SW05 form (the authority for the work between Mount Rainbow and Dumgree) was provided to the integrated possession protection officer.
On 30 October 2021, at about 0847, the work between Graham and Dumgree was completed, and the track section was re-opened without speed restrictions.
Figure 1: Location of the track works Mount Rainbow – Dumgree, Queensland
Source: Aurizon, annotated by the ATSB
The occurrence
At about 1130 and 1215, 2 empty coal trains passed over the re-opened line, heading west, between Mount Rainbow and Dumgree without incident.
At about 1545, empty coal train 9QJ5 passed through Mount Rainbow heading west towards Moura Mine, travelling at about 64 km/h. The train gradually increased speed to a maximum of 77 km/h, before the driver applied dynamic brake to decrease speed for an approaching 60 km/h track speed limit.
When approaching the 99 km, the rail traffic crew noticed a transition in ballast colour from dark to light (Figure 4). A short time later, at 1556:50, the recorded brake pipe pressure began to decrease in the remote distributed power locomotives. At 1556:57, travelling at 54 km/h, the emergency brake was activated (due to a loss of brake pipe air) in the leading locomotive, stopping the train about 160 m later at about 100.220 km. The in-cab telemetry between the leading locomotive and remote locomotives was broken.
After securing the train, one of the drivers walked back, discovered that the wagons had derailed (Figure 2), and reported the derailment to Aurizon network control.
Figure 2: Main wreckage site
Source: Aurizon, modified by the ATSB
Context
Train information
General
Train 9QJ5 consisted of 2 leading diesel electric locomotives, 50 empty coal wagons, 2 distributed power diesel electric locomotives, and another 50 empty coal wagons. The total length of the train was 1,714 m with a gross mass of 2,501 t. The train was operated by 2 appropriately qualified Aurizon drivers. Both drivers recalled during interview that the track was smooth as the leading locomotive passed over the recently ballasted track.
Recorded information
The locomotives were fitted with event data recorders. Data from the leading locomotive (4012) showed the train was operated consistent with the advertised track speeds. In addition, the emergency brake automatically activated as a direct result of the brake pipe loss of air due to the train separation.
At the time of derailment, the leading remote distributed power locomotive (4044) recorded a 4 kN tractive effort. The ATSB considered if this force contributed to the derailment through buff (compressive) forces in the couplings between the wagons. It was determined that the 4 kN was erroneous and did not contribute.
Track infrastructure
The narrow-gauge track[1] between Mount Rainbow and Dumgree consisted of 60 kg/m continuously welded rail fastened with resilient fasteners on concrete sleepers nominally spaced at 667 mm on ballast 250 mm deep. There was no overhead wiring electrical traction system or stanchions installed. The track consisted of undulating terrain with multiple tight radius[2] reverse curves (Figure 3 left). The point of derailment was located between 301 m radius reverse curves on a 1 in 153 downhill grade (Figure 3 right).
Figure 3: Track details at the point of derailment
Source: Aurizon, annotated by the ATSB
Site and wreckage information
Following the derailment, Aurizon inspected the derailment site and commenced an investigation. Based on the site evidence, Aurizon determined that the leading left wheel of the trailing rear axle of the 31st wagon (behind the 2 leading locomotives, VSAS 50930) climbed over the left rail (in the direction of travel) at 99.277 km (Figure 3). The wheel flange ran along the rail head for about 3.6 m then dropped off the field side.[3]
The following 20 wagons derailed (not including the 35th position wagon) and 2 remote distributed power locomotives derailed (located at position 51 and 52 in the consist). The train travelled about 400 m in a derailed condition. Aurizon specialists inspected the rolling stock in-field and found no pre-existing defects.
Aurizon found evidence of a track misalignment commencing at about 99.270 km, just prior to the point of derailment, where the concrete sleepers had begun to move both vertically and laterally (left and right). The track misalignment progressively worsened beyond the point of derailment (Figure 4). The ballast in the work location was also analysed. Although the ballast failed under 53 mm and 37.5 mm sieve tests,[4] Aurizon determined that the specification failure identified was not considered to have been contributory to the accident.[5]
Aurizon concluded that the recent track maintenance activity had a substantial impact on the compressive stress condition of the track leading up to the point of derailment in the heat of the day. This resulted in the track infrastructure becoming unstable and a flange climb derailment due to track misalignment.
Figure 4: Point of derailment and track misalignment
Note: The rear portion of wagons was removed from the site before the above photograph was taken. New ballast is lighter in colour.
Source: Aurizon, annotated by the ATSB
Stress-free temperature
Railway tracks are constructed of steel rails that expand and contract with changes in temperature. When the temperature increases, the rail expands and when the temperature decreases, the rail contracts. These changes in length can cause stresses and strains in the rail, which can lead to breaks, buckling, and other types of lateral instability. To prevent such instability, the rail is designed to have a stress-free temperature.
The design stress-free temperature refers to the temperature at which the rail is neither in compression nor in tension, and is established during track construction. However, this may change due to factors such as rail creep,[6] dynamic train forces (such as train acceleration and braking), and maintenance activities (such as tamping, destressing or ballast cleaning). Therefore, the actual stress-free temperature of the rail may not necessarily be the design temperature. Consequently, the actual temperature should be routinely measured to ensure it remains within the designed tolerances.
Aurizon specified a rail design stress-free temperature of 38°C for the line between Mount Rainbow and Dumgree. Although the line had been regularly inspected and maintained, the actual stress-free temperature of the rail before the track disturbance work commenced was unknown.
Track standards
The track was to be maintained in accordance with Aurizon’s standards including the Civil Engineering Track Standards[7] and Track Stability Manual.[8]
Track consolidation
The Civil Engineering Track Standards stated:
All track that has been recently disturbed must have a speed restriction applied following the work as specified in Table 10.1 Acceptance Criteria for Track Consolidation.
An excerpt of Table 10 is shown in Figure 5 indicating that a temporary speed restriction of 40 km/h or less was required after undercutting works until consolidation of the ballast[9] had occurred through either dynamic stabilisation or having 10 loaded coal trains pass over the track, establishing valid stress-free temperature results and making any rail adjustments.
Figure 5: Excerpt from the Civil Engineering Track Standards detailing the requirements for temporary speed restrictions for track disturbance works
Source: Aurizon, modified by the ATSB
Management of track stability
The Track Stability Manual described approved processes and procedures for the management of track stability on continuously welded rail by correct rail adjustment, and improving the track’s resistance to track buckles (compressive force) and breaks (tensile force). The management of track stability involved 2 separate processes:
control of rail stress to reduce longitudinal forces in the rail that can lead to buckling
maintenance of the ballast profile and condition to improve ability of track to resist these forces.
Figure 6 is an excerpt from the Track Stability Manual showing the track stability requirements for various disturbance works, including ballast undercutting. Ballast control through track consolidation, and rail stress control through stress testing or rail adjustment, were both mandatory requirements. The manual also noted that, as there were different mandatory requirements listed, there may be a situation where 2 or more speed restrictions may apply, and that the more ‘severe restriction’ should always apply. Following ballast undercutting works, in addition to the speed restriction required until ballast consolidation was completed (discussed above), a 40 km/h limit was to be put in place until a stress test with an adequate result or rail adjustment was performed.
Figure 6: Excerpt from the Track Stability Manual detailing the track stability requirements
Source: Aurizon, modified by the ATSB
Figure 7 is an excerpt from the Track Stability Manual and shows the level of applied speed restriction based on the ambient air temperature and unknown status of the rail stress‑free temperature. In this instance, based on the unknown status of the rail stress-free temperature and ambient air temperature, a temporary speed restriction of 40 km/h was required until a rail adjustment was performed within the intervention threshold of 3 days (Figure 8).
Figure 7: Excerpt from the Track Stability Manual detailing speed restrictions based on ambient air temperature
Source: Aurizon, modified by the ATSB
Figure 8: Excerpt from the Track Stability Manual detailing the risk controls for an unknown rail stress-free temperature
Source: Aurizon, modified by the ATSB
Planned trackwork
Without dismantling the track, the ballast cleaning machine undercut the ballast bed with a moving chain beneath the rails and sleepers, removing contaminated and degraded ballast. The ballast was replaced with new ballast under the track, shown as the lighter colour in Figure 4.
Ballast undercutting track work, between Mount Rainbow and Dumgree, disrupted track stability between 99.840 and 99.286 km (554 m). This disruption potentially extended to include an influence zone up to 100 m either side of the work.[10] To mitigate the risks associated with track instability, the following key tasks were usually performed during and following disturbance work to assure track stability. They were, but not limited to:
rail stress testing (if applicable) and subsequent adjustments to the rail
using temporary speed restrictions until track stability was assured.
On 27 October 2021, following an initial delay, work commenced at about 1230 and about 350 m was completed before a shift handover. Following the handover to the afternoon shift, it was noted by the work supervisor that no temporary monuments had been installed. In preparation for continuation of the work, steel star pickets were hammered into the field-side of the track to create a temporary datum or monument points. The pickets were used at intervals of about 50 m to record track offsets, to ensure the track was returned to its original position following undercutting work. The afternoon shift completed about 200 m of undercutting work with monuments installed and track offsets recorded.
Following ballast replacement, the track was realigned using the previously recorded track offsets before design curvature and elevation corrections were made. The track was also dynamically stabilised to consolidate the ballast.
Generally, when ballast undercutting works was conducted, a stress test was completed following that works using a VERSE®[15] stress testing machine. The results of that test determined whether adjustments to the rail were required if found to be outside tolerances. In this case, as the curvature of the track was too tight to use this machine and receive accurate results, a re‑stress was planned to be completed. A re-stress (rail adjustment) involved cutting the rail, measuring the rail gap and temperature, calculating the rail stress-free temperature and required gap, then welding the rail together.
Prior to the work commencing, a rail stress plan was approved to begin following the work on 28 October 2021. Due to staff availability, the planned rail adjustment was not conducted on that date nor was there evidence provided to the ATSB that it had been rescheduled to occur within 72 hours, as specified in the Track Stability Manual (Figure 8). Following the work, a temporary speed restriction (TSR) board was not erected to cover the worksite. The site supervisor believed that other TSRs for the broader work covered that specific worksite.
Environmental information
The closest Bureau of Meteorology weather monitoring station was at Thangool Airport, about 35 km south-south-west from the derailment site. The maximum outside air temperature recorded on 30 October 2021 was 34.2 °C.
Aurizon monitors air and rail temperatures at numerous locations on their network, including Mount Rainbow (7.7 km east) and Dumgree (10.4 km west). Table 1 shows the maximum air and rail temperatures, including near the time of derailment (at 1600).
Table 1: Aurizon recorded temperatures
Location
Maximum temperature °C
Time of derailment temperature °C
Train at 1130 (°C)
Train at 1215 (°C)
Mount Rainbow
Air
Rail
33.1 at 1330 hrs
48.1 at 1400 hrs
31.1
40.1
30.9
47.6
32
48
Dumgree
Air
Rail
35.7 at 1445 hrs
51.6 at 1315 hrs
35.3
49
32.3
48.1
33.8
50.8
Figure 9 and Figure 10 show Aurizon recorded air and rail temperatures at Mount Rainbow and Dumgree between 28 October 2021 and 30 October 2021. The maximum air temperatures on each day were below the design stress-free temperature of 38°Cfor the rails. However, at the time of the derailment, the rail temperature was decreasing and was about 40.1 °C at Mount Rainbow and 49 °C at Dumgree.
On 24 January 2018, at about 1347 local time, loaded Aurizon coal train EF01 encountered a track buckle at Duaringa, on Aurizon Network’s Blackwater System between Emerald and Rockhampton, Queensland. The buckle resulted in 17 wagons in the train consist derailing (Figure 11), damaging 502 m of track on the down line and 54 m of track on the adjacent up line, with rails, sleepers and overhead line equipment requiring replacement.
Figure 11: Duaringa derailment site
Source: ATSB
The ATSB found that the track buckle had formed on a falling 1 in 50 grade at the point of the track where ballast cleaning and track stabilisation work had been completed less than 12 hours earlier. The ballast cleaning operational plan did not consider compressive stress in the continuous welded rail as a risk at this location.
The compressive stress, steep grade, proximity to a turnout and high ambient temperature meant the track structure had a limited capacity to constrain lateral forces. While the ballast cleaning, track resurfacing and dynamic track stabilisation work met Aurizon Network’s civil engineering track standards, negative operational outcomes were not anticipated when a risk assessment was done for the site.
Following this occurrence, Aurizon changed its procedures to ensure a temporary speed restriction was applied to all work sites on which ballast undercutting had been performed. The restriction was to remain in place until rail adjustment or stress testing had been completed and it had been determined that the rail stresses were within accepted limits. In addition, sites with a high risk of compressive rail stress would be identified and added to the site hazard map before conducting ballast cleaning.
Safety actions implemented by Aurizon following the Duaringa derailment had not been applied as part of the planned track work between Mount Rainbow and Dungree and are discussed in the Safety analysis below.
Safety analysis
On 30 October 2021, Aurizon empty coal train 9QJ5, derailed while traversing a section of track following disturbance work 7.7 km west of Mount Rainbow, Queensland. This analysis will discuss the track disturbance work and associated requirements following that work.
Track irregularity and derailment
The on-site examination identified wheel flange climb on the outside of the curved section of track between Mount Rainbow and Dumgree, indicating the point of derailment. Once the wheel climbed and dropped off the rail head, it created further damage, which led to further following wagons derailing. At the time, the train was travelling at 56 km/h.
The track in the vicinity of the derailment had been disturbed during ballast undercutting work, which was completed 2 days prior to the accident. This work destabilised the track until such time that it was realigned/tamped, stabilised, and the rail adjusted.
Further, it was established that the track immediately prior to the point of derailment near where the ballast undercutting transitioned to the original track (within the influence zone) was misaligned. Therefore, as there was no evidence to indicate that any issues with the rollingstock or train handling contributed, it was likely that the derailment occurred as a result of a track irregularity following the recent works.
Rail adjustment
To reduce the risk of lateral instability due to rail stress-free temperature being outside design tolerances, the Aurizon Track Stability Manual relied on the track being placed back into the same position following disturbance work. The stability manual also relied on a rail adjustment or stress test to confirm the rail stress-free temperature before a temporary speed restriction, protecting the area, was removed.
In this instance, a rail adjustment was planned (due to track curvature) as part of the work. However, due to resourcing issues, this was not performed before the track was returned to service as planned. In addition, there was no evidence provided to the ATSB indicating that the rail adjustment was rescheduled to be completed within the 72-hour requirement specified in the manual.
Consequently, the actual stress condition of the track was unknown when the track was returned to service. However, while the 2 other trains had passed over the disturbed track earlier in the day at normal speed without issue, the operator concluded that the track would have been in a compressive state following the works. Therefore, it was likely that the track was likely left in a stressed condition following the disturbance works and the track irregularity developed under train 9QJ5.
Temporary track monuments
Track monuments are used as datum points for the positioning of track within the rail corridor. Based on the records provided, the initial 350 m of work had not been monumented and the offsets not recorded. However, temporary monuments were regularly installed and used for about the final 200 m of the ballast undercutting, near the point of derailment. This meant that the final section of work had likely been realigned/tamped and stabilised in, or very near the original position. Therefore, the lack of track monuments for the earlier works was not considered to be a contributing factor in the derailment.
Irrespective, where permanent track monuments are not installed, the regular installation and use of temporary monuments ensures accurate track offsets are taken and the track is restored to the original position following any track disturbance works. This reduces the risk of affecting the rail stress-free temperature due to incorrect track alignment.
Temporary speed restriction
Following track disturbance work, Aurizon specified the requirements for temporary speed restrictions. In this instance, the track disturbance works required a 40 km/h temporary speed restriction to be applied, covering the works area and influence zones either side. Based on Aurizon requirements, the restriction was required pending the rail adjustment. Although it was not required for ballast consolidation as it had been dynamically stabilised during the restoration process.
However, following the work, a temporary speed restriction was not implemented. Potentially, a broader temporary speed restriction related to other work may have been mistaken as applying to the ballast undercutting area. Furthermore, the missing temporary speed restriction was not detected during the track hand back process to the integrated possession protection officer.
Considering 2 previous trains had passed over the site, in the heat of the day, and at normal track speed (up to 60 km/h) without incident, the contribution of the missing temporary speed restriction was unable to be established. Despite this, Aurizon mandated the implementation of temporary speed restrictions following track disturbance work. This is important to manage the risk of lateral track instability due to unconsolidated ballast and/or incorrect or unknown rail stress-free temperature.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the derailment of coal train 9QJ5 near Mount Rainbow, Queensland, 30 October 2021.
Contributing factors
As 9QJ5 travelled between Mount Rainbow and Dumgree at 56 km/h on a curved section of track, the train derailed likely due to a track irregularity following track disturbance works.
The track near the point of derailment was not re-stressed (adjusted) following the track work, as planned. Consequently, the track was likely left in a stressed condition when the track was handed back fit for service.
Other factors that increased risk
Temporary track monuments had not been regularly placed throughout the worksite, increasing the risk of the track not being returned to the correct position following track disturbance work.
After the track disturbance works had been completed, a temporary speed restriction of 40 km/h was not applied to assure safe passage over that section of track, which had not yet been cleared for operating at the normal speed of 60 km/h.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by Aurizon
Aurizon advised the ATSB of the following safety actions:
A rail stress worker course was developed and rolled out to relevant roles.
Roadshows were conducted in all districts, where network asset leaders discussed the intent and application of the Track Stability Manual.
The Track Stability Manual was reviewed and updated.
A rail stress appreciation course was created and attended by civil supervisors and civil superintendents across the Aurizon network.
Site assessment walkout templates were updated to include relevant rail stress related information.
A toolbox talk was created and issued to all infrastructure workers, reinforcing procedural requirements when performing track disturbing work to maintain track stability.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the train crew
Aurizon
References
Office of the National Rail Safety Regulator. (2019). Guideline -Road Rail Vehicle Management and Operations, Version 1.0. Adelaide, SA: Office of the National Rail Safety Regulator.
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
train crew
Aurizon
Office of the National Rail Safety Regulator.
Submissions were received from:
Aurizon
Office of the National Rail Safety Regulator.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[2] Aurizon defined a tight radius curve as a 300 m radius.
[3] The side of the rail opposite the gauge face (the inner side of the running rail head).
[4] New ballast contains approximately 40-45% voids and has the size, shape, density, and grading requirements specified to suit the operational requirements and environment. However, although all Australian railway systems have differing grading requirements, all have a maximum size of 53 or 63 mm and are limited to approximately 0.7% of dust passing a 75 μm sieve.
[5] Aurizon Category A investigation report of derailment of 9QJ5.
[6] The permanent or progressive longitudinal movement of rails in track caused by expansion or contraction of the rail or the action of rail traffic.
[7] SAF-STD-0077-CIV-NET Module 10 Civil Engineering Track Standards – Track Stability and Hot Weather Precautions, Ver 1.0, 11/01/2021.
[8] AZN.NA.MAN.12.6170.005 HWD Track Stability Manual – Network, Ver 2.0, 04/01/2021.
[9] The process of recompacting the ballast after track disturbance works, achieved through either the action of loaded trains or mechanical means.
[10] Any rail adjustment or speed restriction resulting from track disturbance works must cover the extent of the site, and an additional length of track beyond the immediately affected area. This is known as the influence zone as defined by Aurizon (Track Stability Manual). For rail adjustments, the influence zone extended 100 m at each end of the affected work area.
[11] A permanent monument located at the side of the track to facilitate the accurate measurement of rail creep. Measurements were taken between a marker on the monument and punch marks made on the side of the rail head. Where no permanent monuments were installed, it was best practice to install and use temporary monuments, such as steel star pickets.
[12] The process by which ballast is packed around the sleepers of a track to ensure the correct alignment for the location, speed and curvature of the line.
[13] Generally, the term superelevation (or cant) is used for intended height difference in the rails (that is, where the track is inclined in a curve), and the term 'cross-level' is used for unintended height difference (that is, due to track irregularity).
[14] Dynamic track stabilisation is a track maintenance technique that uses controlled vibrations to improve the stability of the ballast bed. This is done by applying horizontal vibrations to the track while simultaneously applying a vertical load. The vibrations cause the ballast stones to re-arrange themselves in a denser and more homogeneous structure, which improves the track's resistance to lateral displacement and settlement.
[15] The vertical rail stress equipment (VERSE®) machine is a scientific instrument used to non-destructively measure the stress-free temperature of continuously welded rail.
A privately operated Cessna 510 Citation Mustang aircraft, registered VH-MSU, was flying from Sunshine Coast airport, Queensland to Essendon Airport, Victoria with a planned stop at Temora Aerodrome to refuel. At about 1857 Eastern Daylight Time, the pilot landed on runway 18 at Temora Aerodrome. On touchdown, the pilot noticed unserviceability markers further along the runway and elected to continue the landing. The pilot slowed to taxi speed and left the runway to refuel prior to reaching the markers. While refuelling, the pilot checked the NOTAMs for Temora Aerodrome and found that runway 18/36 was closed due to runway works.
What the ATSB found
The ATSB found that during pre-flight planning, the pilot dismissed NOTAMs that were deemed irrelevant to the planned operation. This included one stating that runway 18 was closed due to works in progress, which was deemed irrelevant due to the planned landing on runway 05. The pilot did not review NOTAMs when considering changes to the plan during flight. During approach and landing, the pilot did not see evidence of runway works or closure until touchdown and judged that they would be able to stop before the cones.
White crosses had been placed on the runway, but not in locations visible to aircraft conducting a straight-in approach on runway 18. The size and number of unserviceability markings along the runway were insufficient to fulfil the requirements of the Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) for closed runways.
What has been done as a result
Temora Aerodrome now has obtained larger unserviceability markings. The pilot has adjusted their in-flight decision-making process to check all NOTAMs for an aviation facility when plans change.
Safety message
An essential component of pre-flight planning is to check all NOTAMs relevant to the planned flight, and potential changes to the plan. This includes all NOTAMs regarding all aviation facilities that a pilot plans to use.
To ensure clear communication of changes that may affect the safety of aircraft operations, aerodrome operators must ensure that all works are conducted, and markings displayed, in accordance with the current Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) for aerodromes.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
On 21 October 2021, the pilot of a Cessna 510 Citation Mustang aircraft was conducting a private flight from Sunshine Coast Airport, Queensland to Essendon Airport, Victoria with 4 passengers on board. During pre-flight planning, the pilot checked the weather and NOTAMs,[1] and decided to make a refuelling stop due to diversions around a thunderstorm system in south-east Queensland. The pilot identified Temora Aerodrome, New South Wales (NSW), as an appropriate stop and after calling the fuel provider and checking NOTAMs, planned to land on runway 05 due to weather conditions at the aerodrome.
During cruise, the pilot tuned into the Aerodrome weather information service (AWIS)[2] at Temora Aerodrome and made the decision to land on runway 18 instead of runway 05 due to changes in wind direction and apron accessibility. The pilot did not hear any broadcasts on the Common Traffic Advisory Frequency (CTAF)[3] and elected to land straight-in with a 5-mile final approach to save on time and fuel.
On touchdown, at about 1857 local time, the pilot noticed cones (unserviceability markers) across the runway a long distance ahead of the threshold. They elected to continue the landing after judging that there was sufficient runway to stop safely. The unserviceability markers were located 700 metres from the threshold, just south of intersection D on runway 18/36 (see ‘Locations of unserviceability markers’ in Figure 1). The pilot did not see any other visible markings or obstructions on the runway to indicate that it was closed.
Figure 1: Temora Aerodrome chart (closed pavement in red)
Source: Airservices Australia, annotations by the ATSB
After landing, the pilot re-checked the NOTAMs and found that runway 18/36 was closed but available for use as a taxiway. The pilot re-fuelled the aircraft and, while taxing for departure on runway 23, looked for any unserviceability markings near intersection A but did not see any. The pilot departed at about 1920 local time.
Context
Temora Aerodrome
Temora Aerodrome was a certified and non-controlled aerodrome located in southern NSW. It had two asphalt runways, one dirt runway and two grass runways for glider operations. It was primarily used by the Temora Aviation Museum and Temora Aero Club.
Runway 05/23 was 2,040m long and runway 18/36 was 1,469m long. Both runways were 30m wide.
Runway works
Works began on 5 October 2021 to construct a link taxiway to the threshold of runway 23 and complete drainage works at the southern end of runway 18/36. Works were planned to be completed by 30 November 2021. During this time, runway 18/36 was closed. About 640 metres of this runway, between taxiways A and D, continued to be available as the sole taxiway for runways 05/23 and 09/27. At the time of the incident, works markings and a NOTAM outlining these changes to the operation of the airport were active.
Aerodrome markings
A combination of unserviceability markers (cones) and markings (crosses) had been placed on the aerodrome as annotated in Figure 1.
Unserviceability markers, consisting of 50cm high white cones with a red band, were placed at the end of taxiways E and F entering runway 18/36, and across runway 18/36 south of taxiway ‘D’, to prevent aircraft taxiing into the works area.
Three unserviceability markings, constructed with 6-metre-long white lines laid as a cross, were placed on the runway:
116 metres north of the threshold of runway 36
halfway between taxiways D and E, and
42 metres south of the runway 18 threshold, between the numbers and ‘piano-keys’.
The distances between these markings were 431 and 750 metres.
Unserviceability markings
As defined by the Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) for Aerodromes, unserviceability markings are used for temporary and permanent closures of aerodrome surfaces. They consist of white or yellow crosses of various sizes. When used to mark a runway as temporarily unserviceable, the MOS requires:
markings to be white
markings to be placed at each end of the runway, or portion of a runway, that is declared unserviceable
additional markings to be placed so that the maximum interval between markings does not exceed 300 metres.
The size of the markings for unserviceable runways was determined by the width of the runway (Figure 2):
for runway widths greater than 30 m – a 36-metre-long by 14.5-metre-wide cross
for runway widths from 18 m up to 30 m – a cross with 9-metre-long lines
for runway widths less than or equal to 18 m – a cross with 6-metre-long lines.
Figure 2: Unserviceability markings and unserviceability marker specifications
Source: Civil Aviation Safety Regulations Part 139 (Aerodromes) Manual of Standards
To allow aircraft to taxi along a runway that has been closed with unserviceability markings, unserviceability markers are required to delineate the serviceable portion of the runway to be used as a taxiway. Additional temporary lighting is required for any night operations.
Unserviceability markers
As defined by the MOS, unserviceability markers were to be a 50 cm tall white cone with a 25 cm wide horizontal red stripe (Figure 2). These markers had to be placed at the entrance to, and across, any part of the movement area of an aerodrome (including runways) that are not to be used by aircraft. Additionally, at least three had to be displayed across the centreline of any portion of a taxiway, apron or holding bay that is unserviceable.
Pre-flight planning
The pilot used the AvPlan electronic flight bag (EFB) application on a tablet for pre-flight planning, including accessing weather information and NOTAMs. Weather information for the flight had been reviewed the previous day and multiple times on the day of the incident. Due to the expectation that diversions around weather would be necessary, Temora Aerodrome was identified as an appropriate additional stop for refuelling. When planning to stop in Temora, the pilot reported calling the fuel provider to confirm availability of Jet-A1 fuel in addition to checking weather and NOTAMs using AvPlan.
The pilot’s NOTAM checking procedure involved using AvPlan to mark NOTAMs as ‘read’ when the pilot determined they were not relevant to their operations. They did this to reduce the cognitive load when referring to relevant NOTAMs, which were left ‘unread’, during further planning and flight. In this case, the pilot planned to land on runway 05 due to a light headwind. The NOTAM regarding closure of runway 18/36, and availability as a taxiway, was marked as read as it had no effect on their planned operation.
In-flight decision making
When in flight, the pilot listened to the AWIS system to retrieve the current weather conditions at Temora Aerodrome. The pilot reported that both the Temora AWIS and Williamtown ATIS[4] broadcast on the same frequency (134.45), which resulted in difficulties hearing the broadcast at cruise altitude. The pilot reported that the AWIS was broadcasting the wind as 090 at 5 knots.
Due to the drop in wind and lack of traffic on the Temora CTAF, the pilot decided to change plans and land on runway 18 to minimise taxiing after landing. At this time, the pilot did not review the NOTAMs issued for Temora Aerodrome.
Safety analysis
NOTAM information
The NOTAM closing 18/36 was dismissed as part of the pilot’s practice of marking irrelevant notices as ‘read’ in AvPlan during pre-flight planning. While this process enabled notices deemed relevant to be referenced more easily during flight, in the event of an emergency, change of plans, or misunderstanding of relevancy, this may result in critical information not being recalled or reviewed.
Had the pilot reviewed all NOTAMs for Temora Aerodrome when considering landing on runway 18 during flight, they would have been alerted to its closure. In this case, the pilot would have continued to land on runway 05 as planned.
Evidence of closure
As well as the active NOTAM at the time of the incident, Temora Aerodrome had a total of three unserviceability markings, crosses with 6-metre-long lines, along runway 18/36. The Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) required these markings to be 9 metre markings for a 30 m wide runway and be placed no more than 300 m apart. This would mean that at least 5 markings were required for the 1,469-metre runway. As the length of runway being used as a taxiway exceeded 300 metres, temporary taxiway markings would also be required to separate unserviceability markings from the taxi route.
At the time of the incident, the unserviceability markings, were not located in positions that were clearly visible when landing or taxiing on runway 18 and were not of the required size. These factors likely contributed to the pilot not seeing the unserviceability markers during landing or taxi.
Unserviceability markers (cones) located at the entrances to the works area, both on taxiways and on the runway, were placed in accordance with the requirements of the MOS. These markers are primarily designed to be visible from the ground and were identified upon touchdown.
Although the pilot predicted that the aircraft would be able to stop before reaching the cones, they were not aware why the cones were present or consider the possibility of other runway issues (such as holes) being present before the cones. Had the pilot conducted a go-around when encountering unexpected markings, they would have had the opportunity to re-check NOTAMs and identify the closure of the runway.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the landing on closed runway involving a Cessna 510 Citation Mustang at Temora Aerodrome on 21 October 2021.
Contributing factors
During pre-flight planning, the pilot regarded information about a closed runway to be irrelevant and did not review the available information when the plan was changed during flight.
The pilot did not see the unserviceability markings or markers that were on the runway prior to touchdown, leading to a landing on a closed runway.
The pilot elected to continue the landing after seeing unserviceability markers on the closed runway.
The runway was not marked in accordance with the Part 139 Manual of Standards to communicate that the runway was closed for take-off and landing.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Safety action addressing in-flight decision making
The pilot has advised that they will now review all NOTAMs for an aviation facility when changing plans during flight.
Safety action by Temora Aerodrome operator
Additional 9 metre markings have been purchased for use on both runways.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Civil Aviation Safety Regulations Part 139 (Aerodromes) Manual of Standards 2019 (as amended 13 August 2020)
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Temora Aerodrome operator
the Civil Aviation Safety Authority
the pilot
A submission was received from the pilot.
The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 21 October 2021, at 0743 local time, a Beech Aircraft B200 aircraft, registered VH-WXB, departed Roma Airport on a passenger charter flight to Brisbane West Wellcamp Airport (Wellcamp), Queensland. At 0806, a Saab 340B aircraft, registered VH-ZLV, departed Brisbane Airport on a scheduled passenger service flight to Wellcamp. Both aircraft were operating under instrument flight rules, and both estimated their time of arrival at the airport to be at 0827.
Prior to each aircraft leaving controlled airspace, the Brisbane Centre air traffic controller passed traffic information to VH-WXB and VH-ZLV in 2 separate broadcasts with an updated arrival time for each aircraft. The pilots of both aircraft made a number of calls on the common traffic advisory frequency to organise separation at the non-controlled aerodrome, however, at about 0828, VH‑WXB conducted a 180° left turn on the active side of the circuit, crossing in front of VH-ZLV. This resulted in the separation between the aircraft reducing to 300 ft vertically and 1,000 m horizontally. As VH-WXB commenced the left turn, VH-ZLV’s traffic alert and collision avoidance system (TCAS) announced a traffic advisory (TA), shortly followed by a resolution advisory (RA). The pilot flying immediately disconnected the autopilot and followed the RA instructions and climbed the aircraft until they were clear of conflict. At about the same time, the pilot of VH-WXB received a TCAS TA and commenced a visual lookout.
The flight crew of VH-ZLV advised VH-WXB they had received a TCAS RA. Further communication occurred between the pilots of the 2 aircraft to confirm and visually identify each other’s position in the circuit and ensure separation. Both aircraft landed safely at Wellcamp Airport.
What the ATSB found
The ATSB found that the pilots of both aircraft had an incorrect mental model of the positions of the other aircraft and neither had positively sighted the other aircraft before the conflict. The flight crew of VH-ZLV broadcast an incorrect position of their aircraft when approaching the circuit, which probably resulted in the pilot of VH-WXB misidentifying VH-ZLV for another aircraft on their TCAS.
This misunderstanding affected the pilot of VH-WXB’s decision to fly opposite the downwind circuit direction while in a descent. The pilot then conducted a 180° left turn in front of VH‑ZLV, as they thought that aircraft was further ahead on the downwind leg. Further, the flight crew of VH-ZLV also did not effectively monitor the radio, resulting in them having an incorrect mental model of VH-WXB’s position, and not identifying it as a threat. As neither the crew in VH‑ZLV and the pilot in VH-WXB had positively sighted the other aircraft, alerted see-and-avoid was limited and the last line of defence was the TCAS, which prevented a potential collision.
What has been done as a result
As a result of this occurrence the operators advised the ATSB of the following actions:
The operator of VH-WXB:
will ensure there is an increased buffer between a regular public transport (RPT) flight and their aircraft by orbiting at a waypoint further out, to ensure that the RPT flight is on final approach when they join the circuit
have briefed their pilots of the event and communicated the need to adhere to the procedures written in CAAP 166 - Operations at Non-Towered Aerodromes. Further, they advised their pilots that when traffic congestion is anticipated, actions such as conducting orbits to allow greater spacing in traffic sequencing should be considered
have discussed the traffic congestion issue with the flight training school based at Wellcamp and have agreed that during the scheduled arrival times of RPT aircraft, the training school will limit the number of their aircraft flying within the area.
The operator of VH-ZLV:
has included operations at, and in the vicinity of, non-towered aerodromes as a focus item in the periodic aircrew check cycle
will use this occurrence internally as a human factors case study for operations around common traffic advisory frequency airports.
Safety message
The ATSB’s SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported by industry. One of the priorities is safety around non-controlled aerodromes. Insufficient communication between pilots is the most common cause of safety incidents near non-controlled aerodromes. Pilots should ensure that the location and intention of surrounding traffic is well understood, and their intentions are clearly communicated while maintaining a visual lookout.
Safe operation at any aerodrome requires pilots to use sound judgement and to follow standard procedures and CASA guidance. Using standard procedures at non-towered aerodromes, unless otherwise stated in the En Route Supplement Australia (ERSA), assists pilots in maintaining situational awareness and separation from other aircraft.
Developing and maintaining situational awareness is essential for the conduct of safe flight, particularly at non-towered aerodromes. In addition to radio communication, systems such as ADS-B and TCAS are valuable sources of information to assist pilot’s situation awareness and decision making.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
On 21 October 2021, at 0743 local time, a Beech Aircraft B200 aircraft, registered VH-WXB (WXB) and operated by Air Charter Coordinators, departed Roma Airport, Queensland on a passenger transport flight to Brisbane West Wellcamp Airport (Wellcamp), Queensland. On board were the pilot and 8 passengers.
At 0806, a Regional Express Saab 340B aircraft, registered VH-ZLV (ZLV), departed Brisbane Airport, Queensland on scheduled passenger service flight ZL5662 to Wellcamp (Figure 1). On board were 2 flight crew, one cabin crew and 9 passengers. The captain was the pilot monitoring (PM), and the first officer was the pilot flying (PF).[1] Both aircraft were operating under the instrument flight rules.[2]
Figure 1: Locations of Brisbane and Roma Airports in reference to Brisbane West Wellcamp Airport
Source: Google Earth, annotated by ATSB.
Prior to each aircraft leaving controlled airspace, the Brisbane Centre[3] air traffic controller passed traffic information to the pilot of WXB and the flight crew of ZLV on 2 separate broadcasts at 0811 and 0820, respectively. The controller advised the pilot of WXB that ZLV was inbound to Wellcamp from Brisbane with an estimated time of arrival of 0829, and advised the flight crew of ZLV that WXB was inbound for Wellcamp with an estimated time of arrival of 0830.
At 0821 the pilot of WXB made a broadcast on the Wellcamp common traffic advisory frequency (CTAF)[4] advising that they were 30 NM west of the airport, on descent, inbound for Wellcamp via waypoint LUKEY.[5] The stated intention was to make a left turn and to join right base for runway 12 (Figure 2), with an estimated time of arrival of 0827. About 1 minute later, the PM of ZLV made a radio call advising traffic they were 20 NM east of Wellcamp, at 8,000 ft, descending shortly to join crosswind for runway 12, with an estimated arrival time of 0827.
As WXB and ZLV approached the airport there were 5 other aircraft operating in the CTAF area. There were 2 Diamond DA 40’s associated with a flight training school operating in the circuit for runway 12, VH‑YNH and VH‑EQV and another DA 40, VH-YTK, which was outbound from Wellcamp via Toowoomba to the north-east operating at 4,600 ft. In addition, a Beech Aircraft 58, VH‑CLE, that was inbound for Toowoomba from the west and another Beech Aircraft B200, VH‑WXN, that was inbound to Wellcamp, 3 minutes behind WXB.
At 0823:56, the pilot of VH-YNH broadcast on the CTAF they were entering and rolling for take-off on runway 12 to conduct circuit training. At 0824:26, the flight crew of ZLV responded to this call, advising they were 11 NM to the east leaving 8,000 ft with the intention to join downwind behind VH-YNH. About 30 seconds later, the pilot of the second DA 40 VH-EQV, which was in the circuit ahead of VH-YNH, advised the pilots of both ZLV and WXB that they were downwind in the circuit for runway 12 for a touch-and-go.[6]
At 0825:07, the pilot of WXB advised the pilots of both ZLV and the DA 40s, that they were 6 NM west of LUKEY, with the intention to soon make a left turn to join a wide right base circuit leg and again advised their estimated arrival time was 0827.
The pilot of VH-EQV responded and advised the pilot of WXB they would be on final when WXB and ZLV joined the circuit and would stay out of their way.
The pilot of WXB then contacted the crew of ZLV at 0825:43 (Figure 2 - positions 1) and advised them they were about to make a left turn at LUKEY and then join the circuit on the base leg for runway 12 at time 0827 and asked if ZLV would be happy if WXB went number 1[7] to them.
Figure 2: Aircraft flight paths and positions during different CTAF broadcasts – WXB in yellow, ZLV in blue, EQV in green and YNH in pink, with numbering showing where each aircraft was at the time of the broadcasts
Source: Google Earth, annotated by ATSB based on FlightRadar24 data.
The crew of ZLV acknowledged the request and incorrectly advised that they were positioned on a very early downwind (rather than their actual crosswind position) and would reduce their airspeed and track second to WXB.
The pilot of WXB, thinking that ZLV was already established in the circuit on downwind rather than on an early crosswind, responded and advised they would track as number 2 to ZLV and join the circuit behind them on downwind. The PM of ZLV acknowledged the broadcast.
At 0826:40, the pilot of VH-YNH made a downwind broadcast on the CTAF and advised they would be making a full stop landing.
At 0827:37 (Figure 2 - positions 2), the pilot of WXB broadcast on the CTAF that they were continuing on an easterly heading, passing 3,500 ft on descent to 3,000 ft (circuit altitude), and would be shortly making a left turn to join downwind behind ZLV. The pilot then continued their descent through 3,500 ft, opposite to the circuit direction on the downwind leg.
At about 0828 (Figure 2 – TCAS RA/TA) WXB made a left turn and crossed ZLV’s path from left to right, resulting in a separation of 300 ft vertically (WXB at 3,000 ft and ZLV at 3,300 ft) and 1,000 m horizontally between the 2 aircraft. As this occurred, the crew of ZLV heard their traffic alert and collision avoidance system (TCAS)[8] announce a traffic advisory (TA)[9], shortly followed by a resolution advisory (RA).[10] In response, the PF immediately disconnected the autopilot and following the RA instructions, climbed the aircraft until they were clear of conflict. Around the same time as ZLV’s TCAS alert, the pilot of WXB received a TCAS TA while they were conducting the 180° turn onto downwind.
At 0828:49 (Figure 2 - position 4), the PM of ZLV made a broadcast on the CTAF to ask the aircraft to the south of the field (WXB) to identify themselves. The pilot of WXB responded and advised they were now mid-downwind and asked the pilot of ZLV to confirm their aircraft was positioned on the base leg (Figure 2 - positions 4 and 5).
At the time of this broadcast, VH-YNH was on the base leg and VH-EQV was on the final leg of the circuit. The PM of ZLV advised they were on the downwind leg of the circuit, and had received a TCAS RA. The pilot of WXB then asked the PM of ZLV to confirm their aircraft’s altitude and the PM advised they were abeam (to the left) WXB. The pilot of WXB, who had not visually sighted ZLV at that stage, then advised they would widen out their circuit and come in behind ZLV. The PM again advised WXB they were to the left of them on downwind and were about to commence their descent back to circuit height.
The pilot of WXB again requested ZLV’s level, to which the PM responded 3,100 ft and the pilot of WXB suggested they would track as number 1. After assessing the risk of another potential conflict between the 2 aircraft on base, the PM of ZLV requested WXB climb clear of the circuit. WXB responded and advised they now had ZLV visual and would track as number 2 to them. The pilot of WXB then made a left turn to reposition behind ZLV.
Both aircraft landed safely at 0833 and 0835 respectively.
Animation 1: Aircraft flight paths and positions during different CTAF broadcasts - WXB in orange, ZLV in blue, and YNH in red.
Source: ATSB based on FlightRadar 24 data
Context
Pilot information
VH-WXB
The pilot held a commercial pilot licence (aeroplane) (CPL(A)) and had a total flying time of 5,556 hours, having flown 88.6 hours in the previous 90 days. The pilot was familiar with Wellcamp and had been operating out of the airport since it opened in 2014.
VH-ZLV
The captain held an air transport pilot licence (aeroplane) and had a total flying time of 4,703 hours, and had flown 148 hours in the previous 90 days. The captain was familiar with Wellcamp and had operated there often in the previous 3 years.
The first officer held a CPL(A) and had a total flying time of 3,361 hours, with 154 hours accrued in the previous 90 days. The first officer was also familiar with Wellcamp and had operated there regularly for the previous 2 years.
Pilot reports
VH-WXB
The pilot of WXB reported that they were aware that ZLV would be joining the circuit at the same time. The pilot also stated that they had ZLV visual most of the time and the only time ZLV was not visual to the pilot of WXB was when the left turn was conducted with the intention of positioning behind ZLV on downwind. However, they also advised that, because of the traffic congestion, they were entirely reliant on their TCAS screen to determine the location of ZLV.
The pilot of WXB reported seeing ZLV to the left of WXB’s position on the TCAS screen, just before they turned to join downwind. They reported that they intended to make 2 more broadcasts to ZLV to verify their position and any other information they could collate, but they were unable to do so because the CTAF was too congested.
Once the pilot thought it was safe to do so, they turned left to join the downwind leg.
The pilot’s TCAS screen was congested with numerous aircraft. For the pilot to identify the aircraft they were required to touch the aircraft symbol on the screen to obtain the callsign, level, and closing speed. It was unknown if the pilot did this.
VH-ZLV
The flight crew both recalled the traffic information providing an estimated arrival time for WXB of 0830, prior to switching over to the CTAF.
The crew reported overflying Toowoomba at 5,600 ft to maintain 1,000 ft separation with outbound traffic, VH-YTK. As a result, the crew reported they were 600 ft higher on their normal descent profile into Wellcamp. Once they were clear of VH-YTK, about halfway between Toowoomba and Wellcamp, they commenced their descent.
They determined that the safest course of action, which was not standard procedure, was to descend while on the early crosswind and downwind legs, as they were limited on where they could conduct a descending orbit without interfering with the Toowoomba circuit traffic, or encroaching Oakey airspace to the north or the training area to the south of the field (Figure 3). They also reported that the dead side/non-active side[1] of the circuit was also an area they could not orbit in due to training aircraft frequently operating in there to avoid interfering with incoming and outgoing high-performance aircraft.
After organising separation with WXB and making circuit position broadcasts on the early crosswind and downwind legs, the flight crew thought separation with WXB had been effectively organised and focused their attention on circuit spacing with VH-YNH and configuring the aircraft for landing.
The flight crew did not recall hearing any broadcasts from WXB about joining downwind, and neither pilot saw WXB visually or on the TCAS until it crossed their flightpath ahead from left to right.
Airspace
The airspace surrounding Wellcamp is non-controlled Class G airspace up to 8,500 ft. About 6 NM to the east of Wellcamp is Toowoomba Airport and about 9 NM to the north-north-west is Oakey Army Aviation Centre (Oakey). There are also other aircraft landing areas (ALAs) within a 10 NM radius of Wellcamp, including Wyreema, Colanya, Argyle and Southbrook (Figure 3).
All the above-mentioned airfields and ALAs, including Oakey, operate on the same CTAF when the Oakey airspace is inactive.
Within the airspace surrounding Wellcamp there are identified Danger Areas[2] to the south and west, including a flight training area up to 6,000 ft.
Figure 3: Brisbane Visual Navigation Chart depicting the airport locations and surrounding airspace
Source: Airservices, annotated by ATSB.
In 2019, the Office of Airspace Regulation (OAR) within the Civil Aviation Safety Authority (CASA), completed a review of the airspace within 10 NM of Wellcamp. At the time of the review, the flight training school had not established operations at Wellcamp.
The 2019 airspace review found that the airspace surrounding Wellcamp was fit for purpose, however the following recommendations were made:
Recommendation 1: The OAR should monitor the traffic growth at Wellcamp over the next two years, including the integration of flight training operations based at Wellcamp. If appropriate, another review should be conducted post-implementation of flight training at Wellcamp.
Recommendation 2: The OAR should continue to liaise with other business areas of CASA regarding the commencement of flight training at Wellcamp to ensure that the airspace remains fit for purpose.
A further review of Wellcamp was scheduled to commence in February 2023. However, this review was delayed due to unscheduled changes to priorities. The OAR expects that a review of Wellcamp will be included in a Brisbane basin aeronautical study and is scheduled to commence late 2023.
Brisbane West Wellcamp Airport
Brisbane West Wellcamp Airport is a certified aerodrome located 8 NM west of Toowoomba CBD. It was opened in 2014 and consists of one runway orientated 12/30. The airport services a variety of operations including regular public transport, charter, freight, flight training and aero‑medical aviation services.
The En Route Supplement Australia (ERSA)[3] details local traffic regulations and procedures for the airport. These included stipulating the use of published departure procedures whenever practicable to avoid Oakey military Restricted Airspace. Additionally, due to high terrain to the north‑east of the airport, left circuits are to be flown to runway 30 and right circuits to runway 12.
Operations at non-controlled aerodromes
Guidance provided by CASA[4] (2019) defined that an aircraft was in the vicinity of a non‑controlled aerodrome if it was:
within airspace other than controlled airspace
within a horizontal distance of 10 NM from the aerodrome (reference point), and
at a height above the aerodrome (reference point) that could result in conflict with operations at the aerodrome.
Radio Broadcasts
When operating in the vicinity of non-controlled aerodromes on the shared CTAF, as per Regulation 166C of Civil Aviation Regulations (1988), pilots were required to make a broadcast whenever it was reasonably necessary to do so to avoid a collision, or the risk of collision, with another aircraft.
Further guidance from CASA Advisory Circular 91-10 V1.1 to pilots on the recommended positional broadcasts in the vicinity of non-controlled aerodrome for inbound aircraft is provided at Table 1. It does advise pilots may use their discretion in the number and type of broadcasts they make.
Table 1: Recommended positional broadcasts in the vicinity of a non-controlled aerodrome
Source: CASA 91-10 (2021)
[1] NOTE: Some distances above refer to the runway threshold and others refer to the aerodrome reference point. Pilots should be aware that a global positioning system (GPS) indication of 3 NM from and aerodrome may not be 3 NM from the runway threshold.
Circuit and arrival procedures
A circuit pattern is a conventional standard path for coordinating air traffic that are taking off or landing on a runway. A circuit pattern consists of 5 legs – upwind, crosswind, downwind, base and final (Figure 4).
The Civil Aviation Safety Authority (CASA) Visual Flight Rules Guide states the following regarding standard circuit procedures at non-controlled airports, such as Wellcamp:
The standard aerodrome traffic circuit pattern facilitates an orderly flow of traffic and is normally a circuit pattern made with all turns to the left. When arriving at an aerodrome to land, a pilot will normally join the circuit upwind, crosswind (mid-field), or downwind (before mid-downwind). Landings and take-offs should be made on the active runway or the runway most closely aligned into wind. Aerodromes that have right-hand circuits are listed in ERSA. Circuit information may also be published or provided by aerodrome operators in other sources of aeronautical information.
The CASA (2019) guidance provided the following caution on arrival into non-controlled aerodromes:
Pilots should not descend into the active side of the traffic circuit from above because of the difficulty of seeing – and being seen by – aircraft directly below the aircraft’s flight path.
The guidance noted that pilots joining the circuit on the downwind leg at a midfield position should enter the circuit at approximately 45° to the downwind leg and give way to aircraft already established in the circuit.
The guidance further noted that joining the circuit on base is not a standard procedure and increases the risk of traffic conflict and/or landing on a closed runway. It is recommended that pilots join the circuit on either crosswind or downwind.
ZLV joined the circuit on the early crosswind leg and WXB joined the downwind leg after conducting a 180° turn on the active side of the circuit.
Figure 4: Arrival procedure for a non-controlled airport (left direction circuit). The circuit direction was right at Wellcamp
Source: CASA Visual Flight Rules Guide.
CTAF congestion at Wellcamp
All pilots involved in the incident reported the CTAF can often be quite congested with many calls being over‑transmitted. The flight crew of ZLV reported the CTAF congestion on the day of the incident was manageable and was not a factor in the incident. However, the pilot of WXB reported the CTAF was highly congested. At the time of the incident there were 5 aircraft operating on the CTAF.
In the 3 minutes and 6 seconds from when WXB and ZLV started communicating with each other on the CTAF to just after the incident occurred, 16 broadcasts were made on the CTAF. These had an average length of time of 8 seconds and an average gap of 4 seconds between each broadcast.
Traffic alert and collision avoidance system
Both aircraft in this incident were equipped with a TCAS. In addition to traffic alerts, the TCAS also provides pilots with visual traffic information on a screen. The screen displays other aircraft that are operating in their proximity, and as a result, pilots are able to make decisions based on the displayed information, reducing the risk of collision. The TCAS in WXB only issued traffic advisories and not resolution advisories.
See-and-avoid
When operating in non-controlled airspace, there is no separation service provided by ATC and pilots must rely on their own separation through radio communication with see‑and‑avoid as the last defence.
There are 2 characteristics of see-and-avoid, unalerted and alerted. Unalerted see-and-avoid relies entirely on the pilot sighting another aircraft with no other assistance, while alerted see‑and‑avoid exists when a pilot has been alerted to the existence and approximate location of other traffic. The primary tool of alerted see-and-avoid is radio communication between aircraft and traffic information provided by the air traffic controller. Other tools include ADS-B IN and electronic flight bags that receive traffic information through mobile network or ground-based receivers and TCAS, which provides its own traffic surveillance function.
In the absence of a traffic alert, the probability of a pilot sighting a threat aircraft before impact is low, whereas alerted see-and-avoid can be 8 times more effective.
Reported incidents at Brisbane West Wellcamp and Toowoomba Airports
Since 2016, the ATSB has received 17 airspace occurrence reports that occurred within a 30 NM radius of Wellcamp and Toowoomba Airports (Refer to Appendix A – Separation and TCAS events within the circuit area at Wellcamp and Toowoomba for further details).
Fourteen of the occurrences involved separation issues with the involved aircraft either receiving or not receiving a TCAS alert. Eight of these occurrences occurred at or near Wellcamp, including 6 within the circuit area. Only one of these occurrences involved an aircraft turning inside another aircraft already established in the circuit, during circuit operations. The other 6 were at or near Toowoomba, with 3 occurring within the circuit area.
Two of the occurrences were classified as near collisions. In one, the crew of a Beechcraft B300 observed a glider cross their flightpath near Wellcamp. In the other a Bell 412 was on approach for Toowoomba when a Piper PA-38 crossed their track.
A loss of separation was also reported between a Cessna 182 and a de Havilland DHC-8 25 NM (46 km) east of Toowoomba, where the Cessna182 climbed above its assigned altitude.
Safety analysis
Incorrect mental models
Mental models are a form of cognitive structure that enables an individual to effectively interact with their environment by organising knowledge into meaningful patterns (Reynolds & Blickensdefer, 2009). An individual, when performing a task will develop a mental model of what they think will occur during the task being completed. Their mental model is based upon the information available to them at the time.
VH-WXB
The flight crew of ZLV advised the pilot of WXB that they were on early downwind (Figure 2 - position 1), when they were actually on early crosswind for runway 12. At the time of this broadcast, there were 2 other aircraft in the circuit: VH-EQV on mid-downwind and VH-YNH on mid-crosswind.
The pilot of WXB recalled seeing ZLV to the left of their position on their TCAS screen at about the same time as when they broadcast that they were continuing on an easterly heading (Figure 2 - position 2). However, a review of recorded flight data identified that ZLV was not to the left of WXB until after the 2 aircraft had crossed paths and it was VH-YNH to the left of WXB at this time. The pilot of WXB also stated that they had ZLV visual most of the time and the only period that ZLV was not visual to them was when the pilot was conducting the left turn to position behind ZLV on downwind.
After WXB crossed ZLV’s track and was in communication with the flight crew of ZLV, the pilot asked the crew to confirm ZLV was on base. At the time of this broadcast, VH-YNH was on base (Figure 2 - position 5) and ZLV was to the left of WXB on downwind.
The pilot of WXB's description of when they first became aware of ZLV on their TCAS screen and their common traffic advisory frequency (CTAF) broadcasts after crossing ZLVs flight path, suggested the pilot of WXB had sighted VH-YNH and not ZLV visually or on the TCAS screen. The advice from the crew of ZLV that their aircraft was on early downwind when they were on crosswind, would have likely also confirmed the pilot’s assumption that VH-YNH was ZLV and the pilot possibly assumed VH-EQV was VH-YNH.
The decision by the pilot of WXB to fly opposite to the traffic direction on downwind while descending to circuit height, before turning left, across ZLV’s flight path indicates that it is likely that the pilot had not identified ZLV either visually or on the TCAS.
VH-ZLV
Both flight crew members of ZLV recalled WXB’s field estimate was 0830, which was initially given to them by the air traffic controller. However, after they transferred over to the CTAF, the pilot of WXB broadcast their new arrival time of 0827 on 2 separate occasions, including a broadcast directly to ZLV. This was the same estimated arrival time as ZLV. It is evident that the flight crew of ZLV were aware of the potential arrival time conflict as a discussion occurred between the pilot monitoring and the pilot of WXB, for the flight crew to slow down ZLV to go in number 2 to WXB.
Due to the earlier incorrect positioning call from the flight crew of ZLV, leading the pilot of WXB to believe that ZLV was already established in the circuit on downwind, the pilot of WXB advised the flight crew that they would track number 2 to ZLV and join the circuit behind them on downwind. The pilot monitoring of ZLV acknowledged the broadcast.
The pilot monitoring did not recall hearing anymore broadcasts from the pilot of WXB, after they had organised that WXB would track behind them, until after the TCAS resolution advisory was received. The pilot of WXB had made one other broadcast prior to this, just before they conducted the 180° turn onto downwind, that included intentions to descend and to shortly join the circuit via a left turn (Figure 2 - positions 2). If the flight crew of ZLV had of been effectively monitoring the CTAF, this transmission should have been a trigger for them to look for WXB and respond to confirm their mental model. At this time, ZLV was 1,300 ft higher than WXB (4,800 ft vs 3,500 ft) and in the process of conducting a right turn onto early downwind, making sighting of a lower aircraft more difficult.
It is possible that after organising separation with WXB and agreeing that WXB would go number 2 behind them, the crew thought that WXB was aware of their position and therefore discounted WXB as a threat. Believing adequate separation had been organised, focus switched to VH-YNH and configuring the aircraft for landing.
The flight crew’s ineffective monitoring of WXB’s broadcasts and their incorrect mental model meant that they were now dependent on either visually acquiring WXB or the TCAS detecting them.
Neither crew had positively sighted the other aircraft
The pilot of WXB recalled having ZLV in sight both visually and on the TCAS screen prior to the left turn to join the circuit. If the pilot of WXB had accurately identified ZLV’s location, it is very unlikely that they would have assessed that it was safe to turn left in front of ZLV and cross their flight path. Therefore, the pilot of WXB probably did not identify ZLV visually or on the TCAS until the completion of the left turn when both aircraft were on downwind.
The flight crew of ZLV, reported that while they were on early downwind, they did not hear any broadcasts from WXB about joining the circuit. The first indicator they had that WXB was in the vicinity of their aircraft was when they received a TCAS traffic alert followed shortly after by an RA. They recalled, during their initial communications with WXB, being unsure where WXB was planning to join the circuit, which was why they were initially happy for WXB to go first. After organising separation with WXB, they reported being under the impression that WXB would slow down and join the circuit behind them either on downwind or base. They did not recall seeing WXB on the TCAS prior to the RA. The pilot flying recalled seeing WXB visually for the first time when the aircraft crossed their flight track from left to right.
Separation in a CTAF is dependent on pilots organising their own separation through radio communication, as well as conducting standard circuit procedures. Neither crew positively identified the other aircraft’s location while in, and prior to joining, the circuit, so the potential conflict was not recognised.
Conducting standard circuit procedures provides the best opportunity and risk control for aircraft to maintain separation. Finally, if available, it is also important to follow TCAS RA information. In this instance, it prevented a potential collision.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the separation issue involving a Saab 340B, registered VH-ZLV, and a Beech Aircraft B200, registered VH-WXB that occurred at Brisbane West Wellcamp, Queensland on 21 October 2021.
Contributing factors
The flight crew of VH-ZLV broadcast an incorrect position of their aircraft when approaching the circuit. This probably resulted in the pilot of VH-WXB misidentifying it for another aircraft in the circuit and influenced their decision to conduct a non‑standard circuit entry contrary to the traffic flow.
The flight crew of VH-ZLV did not effectively monitor the radio, resulting in them having an incorrect mental model of VH-WXB’s position and thus not perceiving VH-WXB as a threat.
The pilot of VH-WXB manoeuvred their aircraft opposite to circuit traffic direction while descending into the active side of the circuit in the vicinity of the airport resulting in a conflict with VH-ZLV.
Neither flight crew identified the other aircraft visually or on their TCAS, leading to VH-WXB turning in front of VH-ZLV and resulting in the crew of VH-ZLV receiving a TCAS RA.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Safety action by Air Charter Coordinators
As a result of this incident the operator of VH-WXB advised the ATSB that they:
will ensure there is a 4-minute buffer between a regular public transport (RPT) flight’s time in the circuit and theirs by holding[1] at LUKEY, to ensure that the RPT flight is on final approach when they join the circuit
have briefed their pilots of the event and communicated the need to adhere to the procedures written in CAAP 166 - Operations at Non-Towered Aerodromes. This included advice that when traffic congestion is anticipated, actions such as conducting orbits to allow greater spacing in traffic sequencing should be considered
have discussed the traffic congestion issue with the training school based at Wellcamp and have agreed that during the scheduled arrival times of RPT aircraft, the training school will limit the number of their aircraft flying within the area.
Safety action by Regional Express Pty Ltd
The operator of VH-ZLV advised the ATSB of the following actions:
operations at, and in the vicinity of, non-towered aerodromes have been included as a focus item in the periodic aircrew check cycle
this occurrence will be used internally as a human factors case study for operations around common traffic advisory frequency airports.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Reynolds, R., & Blickensderfer, E. (2009). Crew Resource Management and Shared Mental Models: A Proposal. Journal of Aviation/Aerospace Education & Research, 19(1), 15-24. https://doi.org/10.15394/jaaer.2009.1380
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the flight crew of VH-ZLV
the pilot of VH-WXB
the aircraft operators
the Civil Aviation Safety Authority
Submissions were received from:
the pilot in command of VH-ZLV
the Civil Aviation Safety Authority
Regional Express Pty Ltd
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Appendices
Appendix A – Separation and TCAS events within the circuit area at Wellcamp and Toowoomba
Year
Location
Occurrence type
Aircraft 1
Aircraft 2
Overview
2014
Toowoomba
Airborne collision alert system warning | Issues
de Havilland DHC-8
Unknown helicopter
During initial climb, the de Havilland DHC-8 crew received a TCAS RA on a helicopter operating within the vicinity. The helicopter did not track as previously advised by its crew.
2014
Toowoomba
Near collision
Bell 412
Piper PA-38
Passing 400 ft on approach, the pilot of the Bell 412 observed the Piper PA-38 cross in front in close proximity. The pilot of the 412 contacted the crew of the PA-38 which subsequently conducted a missed approach.
2016
Brisbane West Wellcamp
Issues
Cessna 172
Saab 340
Passing 300 ft on climb, the Cessna 172 crew turned to maintain separation with the Saab 340 on final approach to the reciprocal runway.
2016
Brisbane West Wellcamp
Airborne collision alert system warning | Issues
Bombardier DHC-8
Beech B200
The crew of the Bombardier DHC-8 conducted a missed approach into Brisbane West Wellcamp to maintain separation with the Beech B200 on approach into Toowoomba.
2020
Toowoomba
Airborne collision alert system warning | Issues
Beechcraft B200
Diamond DA 40
During initial climb, the pilot of the Beechcraft B200 received a TCAS TA on the Diamond DA 40 and turned to increase separation. It was determined the pilot of the DA 40 was found to be on the incorrect frequency.
2020
Brisbane West Wellcamp
Airborne collision alert system warning
Saab 340
Diamond DA 40
During approach, the crew of the Saab 340 received a TCAS RA on the Diamond DA 40 in the circuit area.
2020
Brisbane West Wellcamp
Airborne collision alert system warning | Issues
Socata TB-10
Beechcraft B300
During circuit operations, a Socata TB-10 turned inside the Beechcraft B300 that was already established on downwind. The crew of the B300 received a TCAS RA and manoeuvred to maintain separation. No radio calls were heard from the TB-10.
2021
Brisbane West Wellcamp
Issues
Airbus A350
Diamond DA 40
During approach to runway 12, the Airbus A350 closed on the slower preceding Diamond DA 40 on approach to the reciprocal runway 30. The crew of the DA 40 were concerned with the horizontal separation and amended their approach to increase separation. The instructor completed a short field landing that damaged the main landing gear tyres and vacated the runway with the A350 on short final.
2021
Brisbane West Wellcamp
Airborne collision alert system warning
Beechcraft B200
Unknown aircraft
As the Beechcraft B200 joined the circuit, the pilot received a TCAS RA on another aircraft operating in the circuit.
Source: ATSB
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Holding procedure: a predetermined manoeuvre which keeps an aircraft within a specified airspace whilst awaiting further clearance.
[1] Dead side/non-active side: the area on the opposite side of the runway to where the circuit is flown.
[2] Danger area: an airspace of defined dimensions within or over which activities of potential danger to aircraft flying over the area may exist.
[3] En Route Supplement Australia (ERSA): a directory for Australian aerodromes that includes details of an aerodrome and details of available air traffic and ground services, navigation aids and public facilities and any special procedures.
[1] Pilot Flying (PF) and Pilot Monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances, such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
[2] Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR).
[3] Brisbane Centre is one of 2 major centres – the other being in Melbourne. From Brisbane Centre, Airservices manages the airspace over the northern half of Australia, representing around 5% of the world’s total airspace. Brisbane Centre’s flight information region (FIR) neighbours include Indonesia, East Timor, Papua New Guinea, Fiji, New Zealand, and the USA.
[4] A common traffic advisory frequency (CTAF): a designated frequency on which pilots make positional broadcasts when operating in the vicinity of a non-controlled airport or within a broadcast area.
[5] A waypoint is a specified geographical location used to define an area navigation route or the flight path of an aircraft employing area navigation.
[6] Touch-and-go landing: a procedure whereby an aircraft lands and takes off without coming to a stop.
[7] Sequence numbers specify the landing sequence position of an aircraft with respect to any preceding traffic.
[8] Traffic alert and collision avoidance system (TCAS): a type of airborne collision avoidance system (ACAS).
[9] Traffic advisory (TA): an alert issued by an airborne collision avoidance system (ACAS) when the detected traffic may result in a conflict. Pilots are expected to initiate a visual search for the traffic causing the TA.
[10] Resolution advisory (RA): a manoeuvre, or a manoeuvre restriction, calculated by an airborne collision avoidance system (ACAS) to avoid a collision. Pilots are expected to respond immediately to an RA unless doing so would jeopardize the safe operation of the flight.
On 7 September 2021, a Cessna 441, registered VH‑JFU, was being operated on a passenger charter flight from Sawfish Camp to Darwin, Northern Territory. During cruise, the pilot observed abnormal indications (torque fluctuations, high oil pressure and high oil temperature) from the right engine and diverted to Tindal. Maintenance checks identified that the air/oil cooler return line and air/oil separator vent line had been (incorrectly) transposed during a recent engine change.
After rectifications and checks were carried out, the aircraft was released to service. During a flight on 28 September 2021, the pilot observed abnormal indications (torque and oil pressure fluctuations) from the right engine. After landing, oil was observed throughout and under the right engine cowling. The reduction gearbox scavenge pump was found to be unserviceable.
What the ATSB found
The oil lines could be easily transposed given that they were flexible and long enough to reach the 2 ports that were adjacent to each other, were the same size, used the same thread and were almost identical in appearance. This presented a risk of the lines being transposed without hindrance.
It was not possible to determine whether there were any individual or environmental factors associated with the error, and the requirements to carry out an independent inspection did not include checking the oil lines.
The incorrect oil flow resulting from the transposed oil lines damaged the air/oil separator, which then increased the reduction gearbox scavenge pump pressure. This compromised the structural integrity of the pump housing and led to its subsequent failure and, ultimately, abnormal engine indications on the later flight.
The engine manufacturer had issued a service information letter (SIL) in 1990 advising that the oil lines had been transposed on several previous occasions. A limited review of previous occurrences involving such transpositions did not identify any that led to in a complete loss of power or an accident.
What has been done as a result
Following the occurrence, the operator, Chartair:
commenced a fleet-wide program to add markings to engine oil tanks
conducted toolbox talks with engineering staff about distractions during maintenance
commenced documenting each stage of engine changes.
In addition, Honeywell (the engine manufacturer) reissued the SIL with additional information and guidance. The manufacturer also indicated that it would revise the inspection/repair manuals with instructions to re-mark the engine oil tanks.
Safety message
The ATSB reminds maintenance engineers that it is important to check relevant documentation rather than relying on experience and memory, and to remain familiar with other data such as manufacturer service information letters.
Furthermore, since maintenance documents do not always provide advice on non-routine technical situations, operators and maintainers should seek technical advice from the manufacturer to ensure that non-routine problems are fully rectified prior to releasing an aircraft to service.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
Previous maintenance
On 30 July 2021, a Cessna 441, registered VH‑JFU and operated by Chartair, commenced scheduled maintenance on the aircraft at Darwin Airport, Northern Territory. The right engine was removed and replaced with an engine removed from one of the operator’s other Cessna 441s. The operator had conducted about 10 such engine changes during the previous 18 months.
Throughout the following week, the engine installation and other maintenance tasks were carried out by several aircraft maintenance engineers. During the installation, the air/oil cooler return vent line and the air/oil separator vent line were inadvertently transposed when fitted to the oil tank. The fluid lines (including the lines that were transposed) were checked for tightness by the engineer certifying for the engine installation.
The engine change was recorded as being carried out in accordance with the airframe and engine maintenance manuals in the aircraft maintenance and certification record. This record was not broken down into specific sub-tasks, such as fitment of the oil lines, so there was no record of which engineer had done the work. In addition, several weeks had passed between when the work was completed and the detection of the maintenance error. As a result, it was not possible to determine the manner and context in which the work was carried out.
On 9 August 2021, engine ground runs and leak checks were carried out. No irregularities were detected. Independent inspections were completed on the engine’s controls after installation. However, the correct fitment of the oil lines was not part of the regulatory or the operator’s independent inspection requirements.[1] The aircraft was released to service on 10 August 2021.
First flight with abnormal engine indications
On 7 September 2021, about 68 flight hours after the right engine was installed, the aircraft was operated on a charter flight from Sawfish Camp to Darwin, with a single pilot and 9 passengers on board.
During cruise, the pilot saw the following indications for the right engine:
torque fluctuations (varying by about 200 ft-lb)
high and fluctuating oil pressure (between about 30 and 75 psi)
high temperature (100 °C).
The pilot diverted the aircraft to Tindal Airport and landed uneventfully.
Subsequent rectification actions
At Tindal, it was identified that the air/oil cooler return line and the air/oil separator vent line had been transposed (each incorrectly fitted to the wrong part of the oil tank) when fitted to the oil tank (Figure 1).
Following consultation with an engine overhaul organisation, the air/oil separator was changed, and the engine oil was checked for contamination. After the oil lines were correctly assembled, an engine run was carried out and no further defects were identified. The aircraft was released to service.
Figure 1: Oil tank fittings as found
Source: Chartair, modified by the ATSB
Second flight with abnormal engine indications
During a flight on 28 September 2021, the pilot observed torque and oil pressure fluctuations on the right engine.[2] The flight continued to its destination. After landing, oil was observed throughout and under the right engine cowling. The reduction gearbox scavenge pump was later found to be cracked (see Figure 3). The aircraft had flown about 114 hours since the right engine was installed, and about 46 hours since the transposition of the air/oil cooler return and the air/oil separator vent lines had been rectified.
Context
Aircraft information
The aircraft was a Cessna 441 (Conquest II) 11-seat pressurised aeroplane powered by 2 Honeywell TPE-331-10 engines. It was manufactured in 1980 and first registered in Australia on 2 May 2012.
Engine information
Oil tank and fittings
The externally mounted engine oil tank incorporated 2 adjacent fittings that were almost identical in appearance, were the same size, and used the same thread (Figure 2). These 2 fittings included:
an upper fitting for oil returning to the tank from the air/oil cooler
a lower fitting for an overboard vent line from the air/oil separator.
The fittings were labelled, but the markings were anecdotally reported to wear off in‑service (Figure 2). These markings were not present on VH-JFU’s right engine at the time of the engine change.
The air/oil separator was mounted inside the oil tank and consisted of a tube that contained a screen and several Teflon ribbons. Air/oil vapour returning to the oil tank passed through the air/oil separator (where the oil vapour adhered to the Teflon ribbons) and, after coalescing, re-entered the oil supply. The remaining air was vented overboard.
When installed on a Cessna 441, separate flexible lines were attached to the air/oil cooler return and the air/oil separator. The lines were removed and installed using the same size spanner and the lines were typically long enough to reach both ports.
Figure 2: TPE331 oil tank assembly
Source: Honeywell, modified by the ATSB
Service information letter
In May 1990, the engine manufacturer published service information letter (SIL) P331-115 to advise maintenance and engineering personnel that the air/oil cooler return line and the air/oil separator vent line could be transposed. It stated:
There have been several instances in the field where the lines attached to the oil tank were reversed. Specifically, the oil "scavenge return" line has been reversed with the "overboard vent" line. In this case, some of the teflon ribbons in the air-oil separator at the top interior of the oil tank have been forced into the oil tank by the greater pressure exerted by the scavenge return oil. The teflon ribbons may eventually pass from the oil tank through the pressure oil pump in the gearbox and on to the oil filter.
The SIL included 2 illustrations showing the correct orientation of the lines.
The SIL was revised in August 2022 (after the occurrence involving VH-JFU), adding a template for the reapplication of the oil tank markings. It also noted:
Blockage of the air/oil separator from the collapsing teflon ribbons may result in severe damage to the gearbox scavenge pump, including fracture of the pump housing with a resultant loss of oil supply and pressure.
Operator requirements for engine changes
The operator conducted maintenance in accordance with its system of maintenance and the manufacturer’s technical documentation. Technical documentation was produced by the manufacturers of aircraft, engines, and components. Manufacturer documentation was also available from third-party providers.
Aircraft Technical Publishers (ATP) provided operators with an alternative source for maintenance information and was used by the operator for this purpose. The operator used the airframe and engine maintenance manuals for engine removal and installations. The engine removal and installation sections of these manuals correctly showed the orientation of the air/oil cooler return and the air/oil separator vent lines.
Effects of transposed oil lines
The engine manufacturer advised that flow reversal from the incorrect fitment of the air/oil cooler return line to the air/oil separator would have compacted the Teflon[3] ribbons inside the air/oil separator.
After the 28 September 2021 (second) occurrence involving VH-JFU’s right engine, the operator’s maintenance personnel consulted with an engine overhaul facility regarding the possible nature of the defect. The facility suggested the reduction gearbox scavenge pump may be unserviceable and provided a method to check its output pressure. When tested, the pump pressure was considerably lower than specification.
The engine was removed and sent to an overhaul facility. The engine was disassembled, and the reduction gearbox scavenge pump housing was found to be cracked (Figure 3). The engine manufacturer advised the ATSB that the Teflon ribbons would have been compacted inside the air/oil separator following incorrect fitment of the air/oil cooler return line. This would have increased the reduction gearbox scavenge pump pressure and compromised the structural integrity of the pump housing.
Source: TAE Aerospace and Honeywell, modified by the ATSB
The air/oil cooler return and the air/oil separator vent lines had been incorrectly transposed on other aircraft previously. Although the frequency of this is not known, a limited ATSB search of other occurrences did not identify any that led to a complete loss of power or an accident.
The engine manufacturer advised the ATSB that, as well as being detectable through visual inspection of the engine, an early symptom of this transposition occurring could be excessive engine oil venting out of the vent line. The engine manufacturer advised that, when there was no damage to the engine, this could be resolved by returning the lines to the correct configuration. However, if there was also a loss of reduction gearbox scavenge pump pressure, this might indicate damage to the air-oil separator and gearbox oil scavenge pump.
Safety analysis
Unintentional transposition of oil lines
When the right engine was fitted to VH-JFU, the air/oil cooler return and the air/oil separator vent lines were incorrectly transposed. The airframe and engine maintenance manuals correctly showed the orientation of the air/oil cooler return and the air/oil separator vent lines. Accordingly, there was sufficient accurate information available for engineers to be aware of the possibility of inadvertent oil line transposition.
As there was no record of which engineer had done the work, it was not possible to determine whether there were any individual or environmental factors associated with the error, or the extent to which the available maintenance documentation had been checked.
Memory of how to do specific tasks is not always reliable, especially for tasks that are not performed frequently. Ideally, the potential for this type of foreseeable error needs to be designed out of the task or, if that cannot be practicably achieved, brought to the engineer’s attention (through referral to instructions, diagrams, or other information) as the task is performed.
This type of error was possible because the 2 lines were flexible and could reach (and be fitted to) both ports, which were adjacent to each other. The fittings were the same size, visually similar, and the same spanner would have been used to attach the lines. This presented a risk of the lines being transposed without hindrance. A limited review of occurrences did not identify any previous occurrences that led to in a complete loss of power or an accident.
The manufacturer had implemented controls that would help prevent this error occurring. These included markings showing the correct position of the lines, but they could wear off in service. The markings were not present on VH-JFU’s engine oil tank at the time of the maintenance error and therefore there was no prompt to check the correct fitment. As a result, there would have been no clear indications of which way around the 2 lines should be fitted, and there was a risk of inadvertent transposition.
The engine manufacturer had identified this possibility of these lines being transposed and published a service information letter about it in 1990 and revised in 2022. Although there was no change to the oil tank design, so the possibility of transposition of the oil lines remained, the 2022 service letter included a template for the reapplication of its markings.
The error was not detected by the person carrying out the work or when the certifying engineer checked the engine installation prior to releasing the aircraft. The requirements to carry out an independent inspection did not include checking the oil lines.
Non-detection of engine damage
During the flights totalling 68 hours with the oil lines transposed, the right engine was damaged to an extent that later led to further engine malfunction. This damage was not initially detected during post-occurrence maintenance activities. Since this occurrence, the engine manufacturer added information to the existing service information letter to reduce this risk.
As non-normal configurations such as the oil cooler return line and the air/oil separator outlet line being transposed are generally not included in maintenance documents, operators and maintainers should seek technical advice from the manufacturer to ensure that non-routine problems are fully rectified prior to releasing the aircraft to service.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the engine malfunction involving a Cessna 441, registered VH-JFU, 100 km north-east of Tindal Airport, Northern Territory, on 7 September 2021.
Contributing factors
During the installation of the right engine, the oil cooler return line and the air/oil separator outlet line were transposed when attached to the oil tank.
The oil cooler return and the air/oil separator outlet flexible lines could be easily transposed given that their fittings were adjacent to each other, of the same size, and visually similar. Additionally, as occurred in this case, their markings on the oil tank could wear off in service.
The inspections carried out to check the newly-installed engine did not detect the incorrect transposition of the oil cooler return and the air/oil separator outlet lines.
Other factors that increased risk
When the oil lines were returned to the correct position, the damage to the reduction gearbox scavenge pump housing was not detected and the aircraft was returned to service.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by Chartair
After the occurrence, the operator:
commenced a fleet-wide program to apply markings to the oil tanks on its Cessna 441 fleet
conducted toolbox talks with engineering staff
expanded the maintenance log entry requirements for engine changes.
Safety action by Honeywell
On 18 August 2022, Honeywell (the engine manufacturer) reissued service information letter (SIL) P331-115 about the potential transposition of the oil lines with additional information and guidance. Specifically, the manufacturer provided a template for the reapplication of the oil tank markings. It also noted:
Blockage of the air/oil separator from the collapsing teflon ribbons may result in severe damage to the gearbox scavenge pump, including fracture of the pump housing with a resultant loss of oil supply and pressure.
The manufacturer also advised that it would revise the inspection/repair manuals with instructions to re-mark the engine oil tanks.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
aircraft operator
aircraft manufacturer
engine manufacturer.
References
Cessna Aircraft Company, Model 441 Maintenance Manual, chapter 71-00-03, 3 September 1984.
Garrett Airesearch, Maintenance Manual TPE331-8/-9, chapter 79-10-01, 31 July 1984.
Submissions
Submissions were received from:
the aircraft operator
the engine manufacturer.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] CAR 42G required independent inspections to be carried out on flight control systems when they were disturbed during maintenance. The operator expanded these requirements to include engine controls.
[2] Details of this flight, such as origin and destination, were not provided.
[3] Teflon: a trade mark used for polytetrafluoroethylene (PTFE) and other fluoropolymers.