On 3 April 2020, light rail vehicles (LRV) 053/054 were stabled at the light rail depot in Randwick, New South Wales. At approximately 0249, workers heard a loud noise and on investigating found a battery enclosure cover on the ground between two other LRVs. The cover was identified as originating from LRV 053.
Closed-circuit television cameras within the light rail depot captured the ejection of the cover from LRV 053. The cover was ejected with a flash visible followed by a plume of smoke or vapour and the cover landed approximately 6 m away.
There was significant damage to the battery compartment and batteries on LRV 053 and also minor damage to two other vehicles. There were no reported injuries.
What the ATSB found
The software controlling the battery charging likely corrupted during the uploading process which went undetected. The fault with the software resulted in overcharging the batteries on multiple LRVs, including LRV 053. The overcharging of batteries was not detected prior to the occurrence through Alstom’s validation or fault monitoring processes.
The overcharging of LRV 053 batteries generated excessive hydrogen within the batteries. The battery enclosure on LRV 053 ruptured when flammable gases were released into the enclosure in the presence of an ignition source. The risk of explosion had been identified although relied on risk controls that were ineffective at preventing the escalation in this instance.
What has been done as a result
Alstom made changes to the management of train fault data to generate automatic alerts for battery over temperature faults. A new fault code was created within the train control monitoring system to monitor the battery charging temperature and alert the driver if any of the defined thresholds were exceeded.
Additionally, further software validation and testing will be conducted by the battery charger software supplier, as well as during software acceptance testing and following uploading of revised software by the maintainer.
Safety message
The introduction and commissioning of new assets must ensure that design requirements and risk controls are tested and validated as functional. Additionally, fault monitoring and maintenance regimes must monitor asset condition, so as to avoid conditions that might escalate and contribute to accidents.
The occurrence
On the evening of 2 April 2020, light rail vehicles (LRV) 053/054 arrived at the light rail Randwick Depot, New South Wales. The vehicles were stabled towards the back of road 3 along with other vehicles. A worker completed a pre-service inspection of LRV 053/054 around midnight with no abnormalities identified.
On 3 April 2020 at approximately 0249,[1] workers in the stabling yard heard a loud noise. On investigating the source of the noise, they located a roof-mounted battery enclosure cover on the ground between two other vehicles on road 1 and 2. Further investigation identified LRV 053 as missing a battery enclosure cover.
Closed-circuit television (CCTV) cameras in the stabling yard showed a flash coming from the battery enclosure of LRV 053 as the enclosure cover was ejected from the LRV (Figure 1). The cover struck the overhead contact wire, then struck LRV 005 and 058 before falling between the two vehicles (Figure 2). The cover was airborne for approximately 4.12 seconds[2] from being ejected to striking LRV 005. There was substantial damage to the battery enclosure on LRV 053 and minor damage to LRV 005 and 058. There were no reported injuries.
Figure 1: Randwick yard CCTV footage
The figure shows stills taken from the CCTV at 0248:50 with a flash visible and at 0248:57 showing smoke or vapour emanating from the battery enclosure of LRV 053. The ejected panel struck the overhead contact wire and landed to the left of LRV 053 out of view of camera CM03DR.
Source: Transdev, modified and annotated by OTSI
Figure 2: Battery enclosure cover landing and on the ground
The figure shows stills from the external CCTV from LRV 005. The ejected cover from LRV 053 struck LRV 005 and 058 and fell between the two vehicles.
Source: Transdev and OTSI, modified and annotated by OTSI
Post-occurrence events
Immediately following the occurrence, Alstom reviewed the available data and identified numerous battery over temperature faults had been recorded on LRV 053 and 054.
In addition, LRV 023 was identified as recording battery over temperature faults. LRV 023 was in service and was terminated, before returning to Randwick depot for inspection at approximately 0920 on 3 April. An initial visual inspection did not detect any obvious abnormalities with the batteries on LRV 023.
The Bureau of Meteorology (BOM) automatic weather station at Observation Hill,[3] recorded the temperature as 18.7 °C at 0300 on 3 April 2020.
The temperature was recorded between 17.8 °C and 24.8 °C in the days leading up to 3 April. The mean temperature for March 2020 was 25.3 °C with a maximum of 37.6 °C.
Location
The light rail depot was located in Randwick, New South Wales (NSW). The depot was built as part of the Sydney Light Rail project and operates as a light maintenance and stabling yard.
There were a total of 13 stabling roads and the yard had the capacity to store the entire fleet of 60 LRVs. LRV 053/054 were stabled on road 3 at the time with LRV 005 on road 2 and LRV 058 on road 1.
Sydney Light Rail
The Sydney Light Rail (SLR) project was awarded to Altrac Light Rail Partnership as a consortium including Acciona, Alstom and Transdev (Figure 3).
Figure 3: Sydney Light Rail structure
Source: Altrac, modified and annotated OTSI
The SLR project included:
design and construction of the CBD South East Light Rail (CSELR)
design, construction and commissioning of the LRVs for the CSELR
operation and maintenance of the CSELR and operation of the existing Inner West Light Rail (IWLR) Line 1.
The CSELR consists of two new rail lines, with Line 2 running between Circular Quay and Randwick and Line 3 between Circular Quay and Juniors Kingsford.
Testing and commissioning for the Line 2 LRVs commenced in Sydney in late 2018 and continued up until December 2019. Public passenger services commenced on Line 2 on 14 December 2019 and Line 3 on 3 April 2020.
Light rail vehicle information
Vehicle 053
LRV 053 was manufactured in Spain and was delivered to Sydney in October 2019. The LRV underwent final commissioning and entered service in November 2019.
As of 2 April 2020, LRV 053 had travelled 18297 km and there were no known faults with the LRV.
General
The SLR vehicles are variant of Alstom Citadis X05 (305)[4] range designed for city environments. The LRVs operate with either a conventional pantograph or on catenary-free sections utilising the Aesthetic Power Supply (APS) system. Both systems provide 750 V DC for traction power and to the auxiliary converter for auxiliary loads and battery charging. Within the stabling yard, the LRV is powered by the pantograph and overhead contact wire.
Each LRV set consist of five vehicles with drivers cabs at each end (Figure 4). In service the LRVs operate with two sets coupled together, in this case LRV 053 and 054.
Figure 4: Light rail vehicle details
Source: Altrac, annotated by OTSI
Battery system
The LRVs are fitted with batteries to provide power to the LRVs auxiliary equipment. The battery enclosure and batteries were supplied by Hoppecke to meet Alstom’s functional requirements. The battery enclosure was mounted on the roof of the M1 vehicle and the batteries were charged by the auxiliary converter fitted to the M2 vehicle.
Battery cells
The battery cells were vented nickel cadmium (NiCd) designed for rail applications. The battery cell consists of two stacks of positive and negative fibre nickel cadmium (FNC) plates submerged in an electrolyte (Figure 5). The electrolyte used was a mixture potassium hydroxide (KOH) with an addition of lithium hydroxide (LiOH) and distilled water.
The battery model was a Hoppecke FNC 235 R3 (235AH) and the cell casings were manufactured from flame retardant polypropylene (PP-VO).
The nominal cell weight when filled with electrolyte was 11.1 kg + 3% (10.77 to 11.43 kg). The volume of electrolyte between the minimum and maximum level was 810 mL.
Figure 5: Battery cell structure
Source: Hoppecke, 2019. D62109-300-en08_Manual_Alstom_X05_NAT, modified by OTSI
Battery enclosure
The battery enclosure consists of two compartments to house the battery cells and electrical compartment for electrical connections and to facilitate current, voltage and temperature monitoring. The battery enclosure design is a standard product and can house a number of different battery cell configurations. The SLR LRVs used 19 battery cells to form the battery bank.
The battery enclosure was manufactured from stainless steel and the covers for both compartments were secured with four latches each. The battery compartment had two vents positioned on the cover to provide ventilation. The covers for both compartments were also fitted with sun shields to provide some thermal protection.
The battery cells were numbered from 1 to 19, starting with battery 1 at the positive battery terminal. Each cell was connected with a metal cell connector strap and a vent / water filling hose. The battery vent / water filling hose connected to each battery cell and vented to atmosphere through a flame arrestor for backfire protection (Figure 6).
The temperature probe was fitted on top of the battery cells between cells 5, 6, 9 and 10 and reported the temperature to the auxiliary converter.
Figure 6: Battery compartment components
Source: Hoppecke (2019). D62109-300-en08_Manual_Alstom_X05_NAT, modified and annotated by OTSI
Maintenance requirements
The technical maintenance plans (TMP) specified a number of tasks to be completed relating to the batteries when the LRV reached 75,000 km (annual inspection). These tasks required the following:
inspection and cleaning of the battery enclosure
checking electrolyte level and topping-up as required
testing the battery insulation resistance
measuring charging voltage of the battery.
LRV 053 had not travelled 75,000 km, neither had any other LRV and was not due these inspections.
Auxiliary converter
The auxiliary converter which contained the battery charger was supplied by Centum Adetel Transportation Solution (Adetel). Alstom as the design integrator communicated the requirements from Hoppecke and Alstom to Adetel to provide a suitable auxiliary converter.
The auxiliary converter functions to invert the 750 V DC power supplied by the overhead contact wire or APS to lower voltages:
400 V AC heating and ventilation air conditioning (HVAC)
230 V AC general
24 V DC low voltage auxiliary equipment and battery charging.
Battery charging
The battery charger was designed to supply voltage and current to the batteries. Hoppecke specified that the battery charging must supply a float voltage of 27.93 V DC at 20 °C and be temperature compensated by -3 mV/°C per cell.[5] The charging voltage should increase for temperatures below 20 °C and decrease for temperatures above 20 °C (Figure 9). The auxiliary converter software controlled the battery charging voltage and temperature compensation.
Software version
The SLR fleet was supplied with auxiliary converter software version B09. This version of software had been designed and validated as meeting the Hoppecke and Alstom’s requirements. This software version was also supplied to Alstom’s X05 fleet of LRVs in Nice, France.
In November 2019, Adetel released a revised software version B11. The change was deemed minimal and was approved for use by Alstom.
The software update to B11 for the SLR fleet commenced in December 2019. There were six LRVs outstanding as of 3 April 2020, these were LRV 023/024, 045/046 and 053/054.
Fault monitoring and management
When the battery temperature reached ≥ 60 °C for more than five seconds a battery over temperature fault (F_MVS_BatOverTempFail) was recorded within the train control monitoring system (TCMS). The maximum charging voltage was also limited to 24.3 V when the battery temperature reached 60 °C.
This fault was available for review within the maintenance menu on the drivers display unit (DDU), although would not generate an alert to the driver. Remote monitoring of the LRV fault data was also possible through the use of Alstom’s HealthHub.[6]
Battery temperature faults
Review of the battery temperature faults for the 30 days prior to the occurrence showed a number of LRVs had recorded over temperature faults. LRV 053 and 054 accounted for most of the detected faults with 971 and 74 faults respectively, closely followed by LRV 023 with 68 faults (Figure 7).
Figure 7: Battery temperature faults
Source: Alstom, modified by OTSI
Hazards associated with batteries
There are a number of hazards associated with batteries that must be managed to ensure batteries perform their intended function safely.
Flammable gases
These vented battery cells produce hydrogen and oxygen during charging. The production of hydrogen gas mostly occurs once the battery has achieved 95 per cent charge, or during any boost charging or overcharging the battery.[7],[8] The hydrogen and oxygen are the result of the decomposition of water in the electrolyte, with hydrogen forming on the negative plates and oxygen on the positive plates.
Hydrogen forms flammable mixtures in air at concentrations between 4 per cent and 75 per cent. These limits are referred to as the lower flammable limit (LFL) and upper flammable limit (UFL) respectively and represent the concentrations where vapours will ignite when exposed to an ignitions source of sufficient energy.[9]
Hydrogen requires minimal energy for ignition (0.02mJ)[10] and must be kept away from all potential sources of ignition such as:[11]
open flames or fire
sparks, electrical (fuses or switches) or mechanical (sparks from grinding)
hot surfaces were the temperature is above 300 °C
electrostatic discharge.
Combustion of flammable mixtures are defined as either deflagrations or detonations, depending on the velocity of the flame front propagation through the fuel-air mixture.[12]
Combustion of hydrogen and air mixtures will typically result in a deflagration but can transition to a detonation. There are a number of factors that can influence a deflagration or detonations including, hydrogen percentage, enclosure design and strength of ignition source. Detonation of hydrogen and air mixtures is possible at a narrower concentration between approximately 18 per cent and 59 per cent.[13]
Deflagrations usually produce fairly low pressure and generally do not pulverize, but can cause serious structural damage. Detonations are more destructive than deflagrations and produce shock waves and very high pressures.[14]
Chemical
The electrolyte within batteries is caustic and can cause severe burns and eye damage in the event of exposure. The battery cells used on the SLR also contained cadmium which is a toxic substance and a carcinogen.
Vented battery cells are typically safe providing they are handled, stored, maintained and charged in accordance with the manufactures guidelines. In the event of a cell casing failure, mishandling or uncontained battery failure, the battery contents can be released or exposed.
Electrical
Battery cells store energy and terminals are always live. Care must be taken when working on batteries to prevent electrical shocks or short circuits. High currents can be delivered by a single cell or battery bank if there is a short circuit.
The batteries must also be installed with the correct polarity.
Similar occurrences
A review of available records was unable to identify similar occurrences relating to batteries on light rail vehicles, passenger, or freight trains locally or internationally.
There have been two previous incidents investigated where a train component was ejected from a train while in service. Both incidents involved the failure of capacitors associated with traction systems.
The Office of Transport Safety Investigations (OTSI NSW) investigated the partial volume deflagration on Waratah carriage N5508 on 20 March 2017. A number of factors contributed to production of flammable gases within the roof mounted traction inverter module. The force of the deflagration ejected a total of four hatches across platforms 3 and 5 at Burwood. (OTSI Investigation - 04770).
The Rail Accident Investigations Branch (RAIB UK) investigated the explosions inside an underframe equipment case at Guilford on 7 July 2017. It was found that a manufacturing defect resulted in the capacitor producing flammable gases. The gas ignited with the force ejecting debris across the adjacent platform and up to 70 m away. (RAIB Investigation - 052018).
Alstom as the design integrator used DOORS[15] to manage and validate the various engineering requirements for the design and construction of the SLR fleet.
Alstom provided evidence demonstrating that the requirements from Hoppecke and Alstom had been communicated to Adetel during the design phase. Adetel in turn provided validation test results demonstrating that the auxiliary converter and software met the requirements and functioned correctly within the design environment.
Auxiliary converter software
Prior to acceptance of software version B09 for installation across the SLR fleet, high level functional testing was conducted on LRVs 027/028. Given all the parameters of software version B09 had been validated by Adetel (charging management, temperature curve, etc), Alstom’s software change processes did not require full functional testing. This high level functional testing did not detect any faults and was approved for installation across the entire SLR fleet.
Software version B09 consisted of a number of separate files that needed to be uploaded. The parameters for the temperature compensation and charger management were contained within the configuration script file. Post incident analysis detected that the temperature compensation law on some LRV’s with software B09 was incorrect. For reasons that could not be determined, it was believed that the configuration file was likely corrupted during the uploading process on some LRVs. This was not detected at the time of uploading the software, during the validation testing or prior to the occurrence. Later it was found that the software on LRV 027 had corrupted during the uploading prior to the acceptance testing.
Adetel provided a revised auxiliary converter software version B11 in November 2019. The release notes for this version of software did not detail any known issue with the temperature compensation for software B09. It was communicated that the only known changes to software B11, was the removal of files associated with B10[16] and changes to the uploading process.[17] The process for uploading software version B11 was different to B09 and did not require separate files to be uploaded. The parameters for the charging management and temperature compensation were now imbedded within software B11 and appeared to upload correctly.
At the time of the software revision (B11), the project was transitioning from design and construction to operate and maintain. The change was deemed minor and approved for use by Alstom with B11 forming the standard configuration for the SLR fleet. This change occurred after the transition and was not subjected to the full configuration control board (CCB) review as required.
Temperature compensation
Recorded data from LRV 053 showed that the batteries were charging at approximately 28 V for most of 2 April 2020 (Figure 8). During the same period the battery temperature fluctuated between 50 °C and 60 °C and the charging voltage of 28.11 V was higher than the specified temperature compensated value (Figure 9). At these temperatures the charging voltage should have reduced to between 26.22 V and 25.65 V which did not occur. The batteries were also charging at a high current (17 A) which increased from 2100 and was recorded at 33 A at the time of the occurrence.
Data from LRV 054 showed the batteries were charging at around 28 V on 2 April 2020. The charging voltage of 28.43 V at the time of the occurrence was also higher than that specified by the temperature compensation. The charging current (3 A) and battery temperature (39 °C) were however lower than that of LRV 053.
The batteries on both LRV 053/054 were overcharging in the lead up to the occurrence, while in service and within the stabling yard. The overcharging likely increased the production of hydrogen and oxygen within the battery cells and depleted the electrolyte. The high current recorded on LRV 053 was very likely a result of the battery condition and effects of overcharging.
The recorded battery temperature on LRV 053 was more than 40 °C above the ambient temperature, so ambient temperature was not a factor in the elevated battery temperature.
Figure 8: LRV 053/054 battery charging data from 2 and 3 April 2020
Source: Alstom, modified and annotated by OTSI
Figure 9: LRV 053/054 charging voltage vs electrolyte temperature
Source: Hoppecke (2019). D62109-300-en08_Manual_Alstom_X05_NAT and Alstom, modified and annotated by OTSI
Temperature probe
The temperature probe was mounted to a post and positioned above batteries 5, 6, 9 and 10. The probe on LRV 053 was found to be sitting up and was not in contact with the top of the battery cells (Figure 11). This was probably the result of the forces created during the occurrence as the temperature probe post allowed the probe to sit on top of the batteries post incident.
The Hoppecke temperature compensation refers to compensating the charging voltage based on the electrolyte temperature (Figure 9). The location of the probe would not provide a direct temperature of the electrolyte but rather the case temperature at the top of the battery cells. Testing conducted post incident determined that the probe measured within approximately 1 °C of the electrolyte temperature.
The difference between the electrolyte temperature and case temperature under normal circumstances would probably be negligible. However, low electrolyte levels would decrease the effectiveness of the temperature probe as the distance between the electrolyte and probe increases.
Survey of battery electrolyte
Post incident Alstom undertook a survey to inspect the battery compartments on the SLR fleet including checking the battery electrolyte levels.
Low electrolyte levels were identified on a total 28 LRVs, including 023, 041, 046 and 54 which had reported battery over temperature faults. The battery banks on the 28 LRVs required between 0.2 and 26 L of distilled water to restore the electrolyte to the correct level. Refer to Appendix A – Electrolyte survey results.
The low electrolyte had not been detected prior to the fleet survey as the LRVs had not reached the 75,000 km maintenance interval and the over temperature faults had not been monitored.
Alstom also undertook the same survey across the global X05 fleets and advised that low electrolyte levels were also identified in the fleet of LRVs in Nice, France.
Uncontained battery failure
The initial inspection conducted on 3 April 2020 identified the battery compartment had ruptured and there was evidence of heat (browning) between a number of cells. Most the battery filler plugs were lifted and a number of battery cell casing had cracked outwards (Figure 10 and Figure 11). The vents on the ejected cover appeared to be unobstructed.
Figure 10: LRV 053 ruptured battery compartment
Source: OTSI
Figure 11: LRV 053 battery cells and temperature probe
The image shows a close up view of signs of heat between battery cells 9 and 10 and between cells 10, 11, 12 and 13. The temperature probe can also be seen to be sitting up and not in direct contact with the top of the battery cells.
Source: OTSI
Two further inspections of the battery compartment were conducted at the Randwick light rail depot on 15 April and 30 April 2020. These inspections were undertaken with representatives from Alstom, ATSB and representatives on behalf of Hoppecke. Observations from these inspections are recorded in Appendix B – Battery cell assessment.
There was no evidence of high resistance joints within the battery or electrical compartments and all electrical connections were secure with witness markings intact. The temperature probe was tested and functioned as expected.
All cells except cell 15 showed signs of damage or the filler plug was lifted. Battery cells 9, 10, 11, 12 and 13 all showed signs of heat with the cell casings melted (Figure 12). Cell 12 had also short circuited. The damage to the cell casings indicates that the actual temperature far exceeded the recorded temperature of 60 °C as the cell casing begin to melt at 120 °C.
There was no visible electrolyte within the cells when inspected and all battery cells were below the minimum electrolyte level. Cell 19 which was missing a portion of the cell casing appeared to have approximately 20 to 30 mm[18] of electrolyte in the bottom of the cell.
The battery cells weighed between 1.5 and 1.9 kg less than the nominal weight of 11.1 kg. Some cells were missing sections of the cell casing although the low electrolyte would be the greatest contributor to the reduced cell weight.
Figure 12: Battery cells 9 to 13
The image shows the damage to the cell casings for batteries 9 to 13. Cell casings for batteries 11 and 12 were fused and required mechanical separation to remove from the battery compartment.
Source: OTSI
The batteries on LRV 053 recorded frequent over temperature alerts in the 30 days leading up to the occurrence. During this time the batteries were overcharging. Most of the electrolyte probably evolved into hydrogen and oxygen due to overcharging and vented to atmosphere via the filler plugs.
The battery compartment ruptured due to pressure caused by the deflagration of flammable gases containing hydrogen. The flammable gases were probably released into the enclosure by a combination of the melted battery cells and an internal deflagration within the battery cells.
The exact source of ignition was not able to be determined. Hydrogen requires minimal energy for ignition and it is possible that the gases could have been ignited by one of the following:
a short circuit in cell 12
heat produced as a result of increased current and cell degradation.
Management of light rail vehicle faults
The battery temperature fault management characteristic for the X05 fleet were based on the similar logic used for Alstom’s Citadis X02 fleet. The over temperature fault had not been determined to be critical providing the temperature compensation and charging logic functioned as designed.
On each occasion the batteries on LRV 053 reached 60 °C a battery over temperature fault would be recorded. Charging continued in excess of the designed maximum charging voltage of 24.3 V at 60 °C.
The over temperature faults, charging voltage and current were all recorded, however, there were no systems in place to monitor fault conditions and alerts. Consequently, the ability to identify and monitor potential defects that might escalate and contribute to accidents was limited.
Enclosure design
The risk of explosion was known to both Alstom and Hoppecke and had been assessed with the following risk controls and recommendations:[19],[20],[21],[22]
temperature compensated charging
appropriate ventilation
maintenance inspection (including electrolyte level, charging voltage and vents for obstruction).
Projection of materials had also been assessed as a known risk in the event of an explosion.
In order to prevent the build-up of flammable gases the battery enclosure was vented. Ventilation had been calculated in accordance with EN 50272 – 2, Safety requirements for secondary batteries and battery installations. Stationary batteries. This specified that the production of hydrogen within the battery enclosure must not exceed 4% (LFL). The following boundary conditions were used to calculate the required ventilation:[23]
Temperature: 20 °C
Cell type: FNC 235 R3 (235AH)
Batteries are fully charged
Batteries are charged with a constant voltage charger with current limit
Train [LRV] is not moving
The ventilation will be calculated for float charging conditions of the battery
We also assume that electrical precaution against charger malfunction will be provided
Factor of safety of 5, to accommodate faulty cells in a battery string and an aged battery this safety factor also compensates for a temperature increase up to approximately 44 °C.
The calculated minimum ventilation requirement was 43 cm2. The battery enclosure cover for the SLR fleet was supplied with two 75 cm2 mushroom style vents (inlet and outlet). The ventilation exceeded the requirements of EN 50272-2 and permitted the use of a standard cover across the various X05 fleets.
Under normal circumstances hydrogen and oxygen produced during charging would be vented externally to the enclosure through the vent / water filler hose and flame arrestor.
The battery enclosure on LRV 053 ruptured as a result of forces created by internal pressure when a flammable concentration above the LFL was ignited. The cover and debris were ejected from the LRV as there was no means of either venting the forces or containing projectiles. The four latches that secured the cover all failed in a similar manner with the lock pin failing.
The ejected cover weighed 20 kg and was airborne for approximately 4.12 seconds in which time it struck the overhead contact wire likely slowing the ascent. The cover landed approximately 6 m away from LRV 053 and posed a significant risk to any persons in the area. The chemical hazards could also have caused burns or eye damage if released when the enclosure ruptured.
The addition of deflagration venting such as frangible panels and/or secondary restraints to prevent projections from the roof of the LRV, may have reduced the potential consequences. These measures could however introduce new or different risks and would require assessment.
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the uncontained battery failure and ejection of the battery compartment cover on LRV 053 on 3 April 2020.
Contributing factors
Data corruption likely occurred during the uploading of the auxiliary converter software configuration file (version B09) on some light rail vehicles, including for LRV 053. The fault rendered the battery temperature compensation ineffective, resulting in overcharging of the battery system.
Overcharging of the battery system depleted the battery cell electrolyte levels and generated excessive hydrogen within the batteries. Overcharging also generated excessive heat within the cells, resulting in the failure of some cell casing.
Flammable gases consisting of hydrogen, were released into battery enclosure in the presence of an ignition source. The gases ignited with the force of the expanding gases rupturing the battery enclosure and ejecting the cover from the roof of LRV 053.
Neither Alstom’s validation processes nor fault monitoring processes were sufficient to detect the overcharging of batteries prior to the event. [Safety issue]
Other factors that increased risk
The battery enclosure while vented was not designed to vent the forces of a deflagration or contain projectiles, resulting in the ejection of the cover.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Alstom's validation and fault monitoring processes
Safety issue description: Neither Alstom’s validation processes nor fault monitoring processes were sufficient to detect the overcharging of batteries prior to the event.
Train details
Train 1 details
Train operator:
Transdev
Train number:
LRV 053/054
Type of operation:
Light Rail Vehicle
Persons on board:
Crew – 0
Passengers – 0
Injuries:
Crew – 0
Passengers – 0
Damage:
Substantial damage to roof mounted battery enclosure and battery cells
Train 2 details
Train operator:
Transdev
Train number:
LRV 005/006
Type of operation:
Light Rail Vehicle
Persons on board:
Crew – 0
Passengers – 0
Injuries:
Crew – 0
Passengers – 0
Damage:
Minor panel damage to LRV 005
Train 3 details
Train operator:
Transdev
Train number:
LRV 057/058
Type of operation:
Light Rail Vehicle
Persons on board:
Crew – 0
Passengers – 0
Injuries:
Crew – 0
Passengers – 0
Damage:
Minor panel damage to LRV 058
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Alstom Limited Australia
Altrac Light Rail
Centum Adetel Transportation Solution
Euro Power Australia
Hoppecke
Office of the National Rail Safety Regulator
Transdev
Transport for NSW.
References
Alstom (2017). Sydney Light Rail - Preliminary Hazard Analysis, RS-PHA-SLR-ALS-D80-RST-SPE-000020_PHA_E_Ap1.
Alstom (2020). X05-SNY-LRV53-LV BATTERY Static converter SW, 10 June 2020.
Australian Standard (2019). AS 3011.1:2019 Electrical installations - Secondary batteries installed in buildings Vented cells.
Australian Standard (2020). AS 2676.1:2020 Installation, maintenance, testing and replacement of secondary batteries in buildings Vented cells.
Brown, William J., et al., (1997). Safety Standard for Hydrogen and Hydrogen Systems: Guidelines for Hydrogen System Design, Materials Selection, Operations, Storage, and Transportation. Office of Safety and Mission Assurance, National Aeronautics and Space Administration. Accessed at: https://ntrs.nasa.gov/archive/nasa/casi.ntrs.nasa.gov/19970033338.pdf
DeHaan, John D., et al., (2012). Kirk’s fire investigation, 7th ed, p.28, 525 – 529.
European Standards. EN 50272 – 2, Safety requirements for secondary batteries and battery installations. Stationary batteries.
Euro Power Australia (2020). Battery Inspection Report, V1.1.
National Fire Protection Agency (2020). NFPA 921 Guide for Fire and Explosion Investigations 2021, p.247 – 270.
Rail Industry Safety and Standards Board (2020). Glossary of Terms. Accessed at: www.rissb.com.au/glossary/
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Altrac Light Rail
Office of the National Rail Safety Regulator
Transport for NSW.
Submissions were received from:
Altrac Light Rail
Office of the National Rail Safety Regulator.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Glossary of terms
Aesthetic Power Supply (APS) system – The APS system provides power through a ground based system with contact shoes under the intermediate car (IC) that transfers power to the vehicle. The system functions similarly to a third rail, however, the sections imbedded within the ground are only live when the vehicle crosses over that section.
Alternating current (AC) – Electrical current that reverses direction periodically.
Auxiliary converter – A auxiliary converter functions to invert direct current to alternating current. In this case the direct current supply from the overhead contact wire or APS to alternating current for use on the vehicle, as well as a DC output for battery charging.
Battery cell – A functional battery containing an assembly of electrodes, electrolyte, container, terminals and usually separators, that is a source of electric energy obtained by direct conversation of chemical energy.
Battery enclosure – a cabinet or box that provides protection against electrical contact or damage to the battery.
Catenary – In overhead electrification, the uppermost of the two overhead wires mounted above the track and supporting the contact wire.
Contact wire – A bare solid conductor being the lowest of the two overhead wires mounted directly above the track centreline. The pantographs of electric trains press against the underside of this wire and collect the current required by the train.
Combustion – A chemical process of oxidation that occurs at a rate fast enough to produce heat and usually light in the form of either a glow or a flame.
Decomposition – The transformation of a substance into simpler substances or basic elements brought about by exposure to heat, light, or chemical or biological activity.
Deflagration – Propagation of a combustion zone at a velocity that is less than the speed of sound in the unreacted medium.
Detonation - Propagation of a combustion zone at a velocity that is greater than the speed of sound in the unreacted medium.
Direct current (DC) – Electrical current that flows in one direction only.
Drivers display unit (DDU) – The display unit within the drivers compartment to display critical information to the driver.
Explosion – The sudden conversion of potential energy (chemical or mechanical) into kinetic energy with the production and release of gases under pressure, or the release of gas under pressure. These high-pressure gases then do mechanical work such as moving, changing, or shattering nearby materials.
Flammable – A combustible that is capable of easily being ignited and rapidly consumed by fire. Flammables may be solids, liquids, or gases exhibiting these qualities.
Float charging – The period of charging after a battery has fully charged and designed to maintain the battery charge.
Fibre nickel cadmium (FNC) – Hoppecke proprietary technology that refers to the metallised fibre structure within the battery cell electrode.
Frangible panels – A sacrificial panel designed to rupture or open to vent forces created through the combustion process to prevent damage to an enclosure or structure.
Light Rail Vehicle (LRV) – A vehicle used on a light rail system.
Lower flammable limit (LFL) – The lowest concentration of a combustible substance in an oxidizing medium that will propagate a flame.
Joule – The preferred international standard (SI) unit of heat, energy, or work. A joule is the heat produced when one ampere is passed through a resistance of one ohm for one second, or it is the work required to move a distance of one meter against a force of one newton.
Nickel cadmium battery (NiCd) – Storage battery which has an alkaline electrolyte, with nickel oxide as the positive element and cadmium as the negative, this type being used especially as a rechargeable battery.
Pantograph – An apparatus fixed to the roof of electric traction vehicles to draw current from the overhead supply.
Polypropylene (PP-VO) – A plastic polymer of propylene, in this instance with flame retardant characteristics.
Upper flammable limit (UFL) - The highest concentration of a combustible substance in a gaseous oxidizer that will propagate a flame.
Volts (V) – The derived SI unit of electric potential or electromotive force, defined as the difference of electric potential between two points of a conducting wire carrying a constant current of one ampere, when the power dissipated between these points is one watt.
Appendices
Appendix A – Electrolyte survey results
LRV No.
Software
Water added (L)
LRV No.
Software
Water added (L)
001
B11
5
031
B11
0
002
B11
9
032
B11
0
003
B11
0
033
B11
0
004
B11
0
034
B11
0
005
B11
0
035
B11
12
006
B11
0
036
B11
24
007
B11
0
037
B11
24
008
B11
0
038
B11
14
009
B11
0
039
B11
0
010
B11
0
040
B11
17
011
B11
0
041
B11
17
012
B11
0
042
B11
17.5
013
B11
20
043
B11
26
014
B11
0
044
B11
1
015
B11
0
045
B11[1]
0
016
B11
0
046
B11[1]
6
017
B11
25
047
B11
0
018
B11
0
048
B11
0
019
B11
0
049
B11
20
020
B11
0.2
050
B11
0
021
B11
8
051
B11
19
022
B11
0
052
B11
20
023
B09
15
053
B09
Failed
024
B09
15
054
B09
25
025
B11
0
055
B11
20
026
B11
0
056
B11
21
027
B11
8
057
B11
20
028
B11
0
058
B11
3.5
029
B11
5
059
B11
0
030
B11
0
060
B11
0
[1] Auxiliary converter software was updated from B09 to B11 prior the completion of the survey for this vehicle.
Note: The addition of electrolyte greater than 15.4 L indicates that the battery cells on average would have been below the minimum electrolyte level.
Source: Alstom, modified by OTSI
Appendix B – Battery cell assessment
Cell No.
Voltage (V)[1]
Voltage (V)[2]
Weight (kg)[2]
Observation
1
1.230
1.236
9.25
Filler plug lifted and cell casing cracked.
2
1.234
1.228
9.30
Filler plug lifted and cell casing cracked.
3
1.235
1.231
9.20
Filler plug lifted and cell casing cracked.
4
1.244
1.240
9.35
Filler plug lifted.
5
1.250
1.246
9.55
Filler plug lifted and cell casing cracked.
6
1.250
1.246
9.40
Filler plug lifted.
7
1.238
1.236
9.40
Filler plug lifted and cell casing cracked.
8
1.245
1.241
9.45
Filler plug lifted.
9
1.247
1.052
9.20
Filler plug lifted.
Cell casing melted and charred between cell 9 and 10.
10
1.245
1.242
9.55
Filler plug lifted.
Cell casing melted and charred between cell 9 and 10 and at the corner of cells 11, 12 and 13.
11
1.245[3]
1.240
9.40
Filler plug lifted.
Cell casing melted and charred between cells 10, 11, 12 and 13.
Casings for cell 11 and 12 were fused and required mechanical separation for inspection.
12
.036
0
9.40
Battery cell short circuit.
Filler plug lifted and melted internally.
Cell casing melted and charred between cells 10, 11, 12 and 13.
Casings for cell 11 and 12 were fused and required mechanical separation for inspection.
13
1.248
1.242
9.50
Filler plug lifted.
Cell casing melted and charred between cells 10, 11, 12 and 13.
Cell 12 was fused to cell 13 and required mechanical separation for inspection.
14
1.253
1.247
9.45
Filler plug lifted.
15
1.245
1.241
9.45
No visible damage and filler plug in situ.
16
1.234
1.229
9.15
Filler plug lifted and cell casing cracked.
17
1.245
1.241
9.45
Filler plug lifted and cell casing cracked.
18
1.230
1.225
9.25
Filler plug lifted and cell casing cracked.
19
1.253
1.240
9.30
Filler plug lifted and cell casing cracked with battery internals exposed.
[1] Voltage recorded on 15 April 2020.
[2] Voltage and weight recorded on 30 April 2020.
[3] Cell 11 was measured but the value not recorded, voltage estimated.
Source: Euro Power Australia and OTSI
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 22 March 2020, a Cessna 172 aircraft, registered VH-CBB, took off from a private airfield in Canyonleigh, New South Wales, on a local private flight with the pilot and one passenger on board. Shortly after take-off, due to turbulent weather, the pilot decided to terminate the flight and return to land at the airfield. During the approach, while the aircraft was lower than the pilot had intended, it encountered turbulence. This resulted in the aircraft pitching up steeply. After the pilot corrected the aircraft’s pitch attitude, the landing gear contacted the tree canopy of a steep forested escarpment on the approach path and below the level of the runway threshold. Uncertain if the aircraft could climb above the canopy, the pilot elected to reduce power immediately and land in the trees. The pilot and passenger sustained serious injuries as a result, and the aircraft was substantially damaged.
What the ATSB found
The ATSB determined that the aircraft was on a relatively shallow approach and was at a low height above the terrain when it encountered turbulence. After recovering from the turbulence, the pilot assessed that the aircraft could not reach the runway over the steep terrain, and decided to land in trees.
Safety message
This accident highlights the importance of adopting an approach profile that mitigates the effects of gusty/turbulent conditions and being prepared to go around if the approach becomes unstable. The Flight Safety Foundation Approach-and-landing Accident Reduction briefing note 6.1 emphasises the need to be ‘go-around-prepared’ or ‘go‑around-minded’ because it is not a manoeuvre that pilots execute regularly.
The investigation
The occurrence
On the afternoon of 22 March 2020, the pilot of a Cessna 172A aircraft, registered VH-CBB, planned to conduct a local private flight from a private airfield at Canyonleigh, New South Wales, with one passenger on board. The pilot noted that the wind speed and direction were as forecast, which were 20 kt and west‑south‑westerly, and therefore selected runway 27[1] for take-off.
Shortly after take-off, the aircraft experienced some turbulence. The pilot and passenger assessed it was ‘not going to be a relaxing time to go for a fly’, and decided to terminate the flight. The pilot confirmed via the windsock that the wind direction had not changed since take‑off, and elected to continue onto a downwind leg of the circuit for runway 27.
When the aircraft was 1 NM from the threshold, and approximately 400 ft above aerodrome level, the pilot completed the turn onto final approach. The pilot reported having selected one stage of flap for the approach and landing. The aircraft was on approach over steep forested terrain when the pilot noticed that the approach profile was shallower than intended and that the aircraft was ‘a bit low’. In response, the pilot increased the power.
The pilot reported that the turbulence then became ‘very severe’ and the aircraft pitched up steeply. The pilot initially decided to conduct a go-around manoeuvre, but after correcting the pitch attitude, realised that the aircraft was far lower than expected, and no longer aligned with the runway. The aircraft’s wheels reportedly brushed the tree canopy on the escarpment downhill from the runway threshold. Uncertain whether the aircraft would be able to climb over the canopy to the runway, the pilot elected to reduce power and land in the trees. The aircraft came to rest approximately 50 metres short of the threshold and to the left of the runway.
Both the pilot and passenger sustained serious injuries, but they were able to exit the aircraft and contact emergency services. The aircraft was substantially damaged.
Context
Recorded data and airfield geography
OzRunways[2] information for the flight was obtained, with the final approach shown in Figure 1. A review of the flight data identified that during the second half of the approach, the aircraft’s altitude remained relatively level (highlighted segment), but the terrain beneath falls away into a deep gully then climbs towards the airfield.
Figure 1: VH-CBB approach to Canyonleigh airfield, runway 27
The recorded data rounded the aircraft’s altitude down to 100 ft increments, giving a low approximation of VH-CBB’s actual approach. Due to sudden changes in attitude and altitude, the last few data points were considered unreliable and were therefore not included in the image. Source: Google Earth, annotated by the ATSB
Pilot’s experience at Canyonleigh
The pilot had landed at Canyonleigh airfield about 50 times prior to the occurrence, all in VH-CBB. During previous landings on runway 27, the pilot reported sometimes making high/steep approaches and extending full flaps to ‘increase the safety margin’ while flying over the steep, heavily forested terrain. On the day of the occurrence, the pilot believed a high approach would not be necessary.
The pilot assessed that the severe turbulence encountered prior to landing was caused by rotors—a specific type of turbulence produced by mountain waves.[3] This kind of turbulence had reportedly been encountered by both the accident pilot and, to a lesser degree, the airfield owner, during previous landings on runway 27.
Meteorological information
The Bureau of Meteorology provided the following assessment of the likely weather conditions at Canyonleigh on the day of the accident:
While winds gusting to 26 knots were observed at [the nearby weather station], it is possible that the winds higher in the atmosphere were a little stronger, possibly reaching 30 knots at times. With 20 to 30 knots of wind over elevated terrain, light to moderate mechanical turbulence is likely.
With regard to the possible formation of rotors beyond the threshold of runway 27, the Bureau of Meteorology stated:
While the atmospheric conditions did not strongly favour mountain wave and rotor turbulence and no evidence of waves could be seen on satellite imagery, the presence of a temperature inversion above the ridge top with moderate winds blowing perpendicular to the ridge means that small scale waves and rotors cannot be ruled out. The terrain downstream from the threshold, sloping sharply downwards towards the valley, could cause an acceleration of the winds close to the ground, thus increasing the possibility of downward air motion as well as rotor formation. There are, however, no observations to confirm that this occurred.
Safety analysis
While on approach to runway 27, the pilot noticed the glideslope was shallower than intended and that the aircraft was low, so increased power. The aircraft then encountered turbulence, resulting in it pitching upward. The exact nature of the turbulence could not be determined, but rotors or downward air motion over the escarpment may have been present at the time.
Once the aircraft’s attitude was corrected, the pilot assessed that the aircraft was too low and close to the terrain to climb out of the valley to the runway and decided to land immediately in the trees below.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the collision with terrain involving Cessna 172, VH-CBB, on 22 March 2020.
Contributing factors
During a shallow approach, the aircraft encountered significant turbulence that affected the aircraft’s pitch attitude and flight profile. As a result, the pilot assessed the aircraft was too low to reach the runway and elected to land in trees.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
pilot
passenger
airfield owner
New South Wales Police Force
Bureau of Meteorology
OzRunways.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the pilot
the airfield owner
the Bureau of Meteorology.
No submissions were received.
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the morning of 17 March 2020, a QantasLink Bombardier Dash-8-402, registered VH-LQJ (LQJ), was being taxied for a scheduled flight from Gladstone Airport, Queensland to Brisbane Airport, Queensland. There were two flight crew, two cabin crew and 34 passengers on board. At the same time, an ATEC Faeta 321, registered 24-8279 (Faeta 8279), with one instructor and student on board, was conducting circuit training at Gladstone Airport.
At about 0645, as Faeta 8279 was on approach to conduct a touch-and-go on runway 10, LQJ entered and taxied along the runway in front of Faeta 8279. The instructor on board Faeta 8279 conducted a go-around to avoid an incident on the occupied runway.
What the ATSB found
The ATSB found that the flight crew of LQJ set the incorrect common traffic advisory frequency and did not select the appropriate traffic collision avoidance system/transponder mode during the before start checks. These errors were likely influenced by increased workload and time pressures experienced during before start preparations.
The errors went undetected during the taxi phase of flight. As a result, the flight crew’s situational awareness was significantly degraded and caused the captain and first officer to form the shared belief that no other traffic was operating in the vicinity of Gladstone Airport. This shared incorrect mental model likely impacted the efficacy of the visual scan conducted prior to entering the runway, with neither flight crew member sighting the approaching aircraft.
What has been done as a result
Following this incident, QantasLink undertook a review of operating procedures at non-controlled airports. The procedural review included transponder activation and introduced a requirement to contact Air Traffic Control prior to entering the runway. QantasLink also provided internal communications to flight crew detailing the importance of standard operating procedures and threat management when dealing with distractions and workload.
Safety message
This incident illustrates the human factors implications associated with the combination of increased workload and time pressures. Flight crews can guard against similar outcomes by applying effective threat and error management strategies that recognise when such threats may arise and set in place suitable actions that minimise error potential. These actions include strict adherence to standard operating procedures and increased cross-checking of system inputs and mode changes.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
At about 0600 Eastern Standard Time,[1] on 17 March 2020, the crew of a QantasLink Bombardier Dash-8-402 aircraft, registered VH-LQJ (LQJ), commenced pre-flight preparations for a scheduled regular public transport flight from Gladstone Airport, Queensland to Brisbane Airport, Queensland. The crew comprised the captain, first officer (FO) and two cabin crew.
It was the first flight of the day for LQJ and the scheduled departure at 0645 meant that the crew had about 45 minutes to prepare the aircraft. Shortly after arriving at the aircraft, the captain started the auxiliary power unit (APU),[2]while the FO conducted the aircraft walk around. The captain then commenced the ‘originating’ and ‘before start’ checks, which included selecting APU bleed air ‘ON’ to provide air-conditioning to the cabin. At this point the APU failed, so the captain completed the automatic APU shutdown actions.
At about 0610 during the walk around, the FO noticed a small aircraft taxi behind LQJ. This aircraft was an ATEC Faeta 321, registered 24-8279 (Faeta 8279), that was being taxied for circuit training with one instructor and one student on board. The FO made a mental note of the taxiing aircraft, finalised the walk around, and returned to the flight deck to complete the remainder of the pre-flight preparations.
The captain and FO then restarted the APU, but it failed for a second time when APU bleed air was selected ‘ON’. At about the same time, a ground crew member attended the flight deck to inform the captain and FO that a ‘person in custody’[3]and their police escort would be travelling on the flight. The captain left the flight deck to review the person in custody paperwork and brief the cabin crew on the custody arrangements. The person in custody and their escort then boarded the aircraft, with the remainder of the flight’s 34 passengers boarding a short time later.
At about 0622, Faeta 8279 commenced circuit training using runway 28. The occupants of Faeta 8279 made regular positional broadcasts on the Gladstone Airport common traffic advisory frequency (CTAF) [4]throughout the training activity.
Meanwhile, on board LQJ, the captain returned to the flight deck and elected to apply the Minimum Equipment List (MEL)[5] to the APU system. The captain and FO then actioned the procedures required to apply the MEL with remote support provided by QantasLink maintenance engineers. Completing this task took the crew 5-10 minutes.
Once the MEL had been finalised, the captain and FO undertook the remainder of the before start checks, but omitted to set the traffic collision avoidance system (TCAS)[6]/transponder[7] to ‘ON ALT’ and to select the Gladstone CTAF in VHF COM 2.[8]The CTAF omission was identified by the FO during the departure briefing and subsequently addressed. However, the FO entered the incorrect frequency of 126.7 MHz instead of 118.8 MHz, which was the correct frequency for the Gladstone CTAF.
At 0643, a pilot in Faeta 8279 made a CTAF broadcast advising traffic that the aircraft would be changing runway direction for a touch-and-go on runway 10. The captain and FO of LQJ did not receive this broadcast as they were monitoring the incorrect frequency.
The weather at the time was reported as being a wind from 201 degrees magnetic at 6 knots, no cloud, and a visibility of 43 km. As the wind did not favour either runway, the flight crew of LQJ elected to use runway 28 to avoid departing towards the rising sun. This required a short taxi from bay 3 to the A5 intersection, and a right turn to enter and backtrack runway 28 (Figure 1 and Figure 2).
Figure 1: Overview of VH-LQJ taxi routing
Source: Google Earth, annotated by the ATSB
Figure 2: Gladstone aerodrome chart
Source: Airservices Australia, annotated by ATSB
At 0643:38, the FO made a broadcast on the incorrect CTAF using VHF COM 2 and LQJ was taxied from its parked position on bay 3.
At 0644:23, the FO made a second broadcast on the incorrect CTAF as the aircraft taxied towards the A5 intersection.
At 0644:29, a pilot in Faeta 8279 made a broadcast on the Gladstone CTAF advising traffic that the aircraft was on short final for a touch-and-go on runway 10. The flight crew of LQJ did not receive this broadcast either.
The captain and FO conducted a visual scan as LQJ neared the A5 intersection, but neither flight crew sighted Faeta 8279 on approach for runway 10. At about 0645, LQJ was taxied onto the runway in front of the approaching Faeta 8279. In response, the instructor on board Faeta 8279 commenced a go-around and attempted, unsuccessfully, to contact LQJ on the Gladstone CTAF.
At 0645:02, as LQJ backtracked along the runway, the FO made a taxi report to Brisbane Centre[9] using VHF COM 1. A secondary surveillance radar transponder code[10] was provided to LQJ and the captain entered it into the transponder. Shortly afterwards, the captain identified that the TCAS/transponder was not appropriately set and selected it to ‘ON ALT’.
At 0645:42, the TCAS presented the flight crew with a traffic advisory[11] indicating climbing traffic above LQJ. The traffic – Faeta 8279 – was subsequently sighted by the captain and FO climbing in an easterly direction overhead the airport.
The captain and FO checked the frequency set in VHF COM 2 and identified the incorrect frequency selection. The frequency was changed to the correct frequency of 118.8 MHz and the FO made a broadcast at 0646:29 advising that LQJ was ‘entering and backtracking’ runway 28.
At about 0646:36, a pilot in Faeta 8279 replied to LQJs broadcast, but the flight crew of LQJ did not respond to Faeta 8279’s transmission. A short time later, the instructor in Faeta 8279 broadcast the intention to manoeuvre for runway 28 to allow LQJ to depart. At about 0648, LQJ commenced its take-off from runway 28.
Context
Air Traffic Control communications
The captain and FO elected to delay the taxi report to Brisbane Centre until LQJ had entered the runway. This was due to the shared understanding that the Gladstone Airport terminal buildings shield VHF transmissions and prevent contact being made with Brisbane Centre when parked on bay 3. QantasLink procedures permit an aircraft to be moved to an alternate location when communications with air traffic services are not possible on the bay.
Human factors
The same crew had flown LQJ into Gladstone Airport the evening prior, arriving at about 1900 on 16 March 2020. The crew then stayed overnight in local hotel accommodation. Both the captain and FO reported no fatigue issues associated with the overnight stay, and an assessment of the flight crew’s previous 14-day roster did not identify any significant fatigue risk factors.
During pre-flight preparations, the captain and FO encountered a number of unanticipated events and distractions, including two APU failures, boarding of a person in custody, and application of a MEL to the APU system. The additional actions, due to these events, increased their workload.
On the morning of the incident, neither the captain nor the FO recalled listening for an aerodrome frequency response unit (AFRU)[12] reply to the two broadcasts made on the incorrect frequency. The first broadcast took place when both flight crew members recall increased workload associated with the turn off bay 3. The second CTAF broadcast was made mid-way through the short taxi to the runway intersection.
Prior to entering the runway, the captain recalled believing there was no other aircraft in the vicinity of Gladstone Airport as the crew had not heard any broadcasts on VHF COM 2 and there was no traffic indicating on the TCAS display. The FO recalls making reference to the small aircraft that had been sighted during the walk around checks. However, given the elapsed time since the sighting, combined with the lack of transmissions received on VHF COM 2, the FO concluded that the traffic was no longer in the vicinity of the airport.
Safety analysis
This was the first flight of the day for LQJ and the crew had about 45 minutes to complete all pre‑flight preparations prior to the scheduled departure time of 0645. During this period, the captain and FO encountered several unanticipated events and distractions, including the APU failure and person in custody paperwork, that required additional actions to be performed within the allocated timeframe. These interruptions and additional actions within a defined time period added workload and time pressures.
The combination of increased workload and time pressures is known to result in degraded information processing, increased errors, the tunnelling of attention, and an increased reliance on familiar strategies or actions (Staal, 2004). This response to workload and time pressures likely resulted in the flight crew’s omission of the two ‘before start’ checklist items and the selection of the incorrect frequency in VHF COM 2.
The frequency selection error was further compounded by the flight crew not recognising an absence of AFRU reply when making radio calls on the incorrect frequency. As a result, the captain and FO were not aware that they were monitoring and broadcasting on the incorrect CTAF.
The flight crew’s inadvertent omission of the TCAS/transponder selection resulted in the captain and FO incorrectly believing the TCAS would alert them to the presence of any transponder equipped aircraft that were operating in the vicinity of Gladstone Airport.
As a result of the frequency selection and TCAS/transponder errors, the flight crew’s situational awareness was significantly degraded resulting in the captain and FO forming the shared belief that no other traffic was operating in the vicinity of Gladstone Airport. This shared incorrect mental model likely impacted the efficacy of the visual scan conducted by the flight crew as they neared the A5 intersection. Consequently, neither flight crew member identified the approaching aircraft and LQJ was taxied onto the runway in front of Faeta 8279. The instructor on board Faeta 8279 conducted a go-around to avoid an incident on the occupied runway.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the runway incursion involving Bombardier Dash-8-402, registered VH-LQJ, at Gladstone Airport, Queensland, on 17 March 2020.
Contributing factors
The flight crew of VH-LQJ were not aware that light aircraft 24-8279 was on approach and taxied onto the runway in front of it. Consequently, the pilot of 24-8279 had to conduct a go‑around.
The visual scan by the flight crew of VH-LQJ before entering the runway did not identify the approaching 24-8279, probably because of their degraded situational awareness.
Increased workload and distractions while preparing VH-LQJ for departure led to the crew not setting the correct radio frequency and the appropriate mode on the traffic collision avoidance system/transponder. Without these essential aids to situational awareness, neither pilot developed an accurate mental model of the traffic.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by QantasLink
Following this incident, QantasLink undertook a review of operating procedures at non-controlled airports. The procedural review included transponder activation and introduced a requirement to contact Air Traffic Control prior to entering the runway. QantasLink also provided internal communications to flight crew detailing the importance of standard operating procedures and threat management when dealing with distractions and workload.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the flight crew of VH-LQJ
the pilot in command of 24-8279
QantasLink
Avdata
Civil Aviation Safety Authority
Airservices Australia.
References
Staal MA 2004, Stress, cognition, and human performance: A literature review and conceptual framework, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2004-212824.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the crew of VH-LQJ, the pilot in command of 24-8279, QantasLink, and the Civil Aviation Safety Authority.
Submissions were received from QantasLink and the captain of VH-LQJ.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the afternoon of 5 March 2020, an Airbus A320, registered VH-VFL and operated by Jetstar Airways landed at Proserpine, Queensland, on a scheduled passenger service from Sydney, New South Wales. On the walk around after landing, damage was found to the nose gear landing light and the left main landing gear, including a pierced hydraulic brake line.
Fluid was subsequently found in the landing gear wheel well. No evidence of a strike or foreign object debris was found on the runway at Proserpine or Sydney. There was no indication that the aircraft had been struck by ground support equipment prior to departure from Sydney, and no recent maintenance had been performed on the left main landing gear.
What the ATSB found
The ATSB determined that the nose gear landing light was probably struck and damaged during departure from Sydney. However, the source of the damage could not be determined. The glass lens from the nose gear landing light most likely struck the main landing gear, resulting in the pierced hydraulic brake line.
Safety message
Visual inspections play an important role in maintaining the safety of an aircraft. In this case, a vigilant flight crew identified damage that could have otherwise impacted on the safety of future flights. Flight crew are encouraged to be attentive in their post-flight inspections, even when the flight has been completed without incident.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
At 1308 Eastern Standard Time[1]on 5 March 2020, a Jetstar Airways (Jetstar) Airbus A320‑232 registered VH-VFL, completed a scheduled passenger flight from Sydney, New South Wales to Proserpine, Queensland. During the subsequent walk around the flight crew noticed damage to the aircraft’s undercarriage, specifically:
the nose gear landing light was damaged
the left main landing gear (MLG) brake hydraulics were pierced, with fluid visible on the apron, tyres and gear assembly
a metal conduit carrying wiring for the left MLG was deformed.
After the damage was found, a member of the cabin crew recalled hearing a ‘deflation noise’ while on descent into Proserpine. There was no visible biological evidence that might indicate a wildlife strike. Therefore, given the extent and nature of the damage, Jetstar reported that a remotely piloted aircraft (RPA) may have collided with the aircraft.
Runway inspections were subsequently conducted at Sydney and Proserpine, however no debris or any evidence of an impact could be found at either location. Jetstar reviewed the flight data but could not identify anything that might indicate a strike had occurred. The flight data did not record the condition of the landing light or the level of hydraulic fluid in the MLG brake line.
Context
Aircraft damage description
Figure 1 shows the damage to the nose gear landing light at the time of the post‑flight walk around. Most of the lamp was missing, with a small fragment still attached to the socket. In the background of the image, the damaged left MLG can be seen. The broken nose gear landing light was inspected by the manufacturer, but there was no comment made regarding possible reasons for the damage.
Figure 1: Damaged nose gear landing light
Source: Jetstar Airways, annotated by the ATSB
Figure 2 shows the damage found on the left-hand MLG wiring conduit and the adjacent brake hydraulic line. Fluid can be seen on the apron as well as the tyres. A subsequent inspection of the aircraft found more fluid in the wheel well of the left main landing gear.
Figure 2: Main landing gear damage
Source: Jetstar Airways, modified by the ATSB
Ground handling and maintenance
The maintenance history of VH-VFL was reviewed to determine if some or all of the landing gear damage could have been due to some earlier maintenance activity, or if tooling might have been left in the wheel well, resulting in the damage to the MLG observed. However, prior to the occurrence, the aircraft had completed 35 scheduled flights since any maintenance was performed on the landing gear.
There were no reported incidents of damage from ground support equipment prior to departure from Sydney, but there was there was no CCTV footage available to confirm this.
Landing gear design and operation
The nose gear landing light used a halogen lamp. The lens was made of glass, but it included a polycarbonate lens cover described by the manufacturer as very resistant to thermal shocks and mechanical impacts. An undamaged halogen lamp, installed on an A320, is shown in Figure 3.
Figure 3: Undamaged nose gear landing light with polycarbonate cover
Source: Jetstar Airways
The damaged main landing gear hydraulic line was responsible for actuating the wheel brakes. The line would pressurise when the brakes were applied via pilot input or the automatic brake system. One function of the automatic brake system was to apply the brakes during landing gear retraction, to prevent wheel rotation.
Hydraulic line examination
The pierced hydraulic line was sent to the ATSB for examination. The line was confirmed to be a titanium-aluminium alloy, per the manufacturer’s specifications. The damage observed was consistent with a concentrated external force resulting in the puncture.
Scanning electron microscopy, including backscattered electron imagery[2] and energy-dispersive X-ray spectroscopy[3] was conducted on the damaged section of line. Figure 4 shows a foreign material identified around the damaged area.
Figure 4: Backscattered electron image of the hydraulic line damage
The darker regions indicate a foreign material is present, consisting of lighter elements than the titanium-aluminium line.
Source: ATSB
Energy dispersive X-ray spectroscopy identified the foreign material as a combination of silicon and oxygen. At higher magnifications, the foreign material appeared to have a granular, crystalline structure. The structure and composition of the foreign material indicated that it was most likely silica, otherwise known as silicon dioxide. Silica is the primary ingredient in most forms of glass.
Safety analysis
The polycarbonate cover on the nose gear landing light would likely have prevented it from disintegrating due to thermal stress, such as from a blown bulb. Therefore, the damage to the light indicated by the recovered bulb fragments was probably the result of an impact. The bulb fragmented despite the presence of the polycarbonate cover, indicating that the light was struck with considerable force. Given their proximity to each other and the nature of the damage, the punctured hydraulic line and deformed metal wiring conduit were also considered to be the result of an impact.
Examination of the damaged hydraulic line identified traces of what was most likely glass. The most probable source of the damage to the hydraulic line and wiring conduit was the glass lens of the nose gear landing light. Other potential sources of damage, such as ground support equipment or foreign object debris could not be ruled out, however there was no evidence found to support these.
Both impacts most likely occurred during the flight between Sydney and Proserpine, since no damage was reported following the previous flight, or during pre-flight inspections in Sydney. Fluid found in the main landing gear (MLG) wheel well likely came from the punctured hydraulic line. The fluid was probably discharged into the well when the crew raised the landing gear during departure from Sydney, as the line would have been pressurised, and the gear was not retracted.
again prior to the damage being found. It is therefore likely that the MLG damage occurred during departure from Sydney, rather than via a remotely piloted aircraft (RPA) while on descent into Proserpine, since damage on descent would not explain the fluid found in the wheel well. As such, the noise heard by the cabin crew member was probably unrelated to the occurrence.
The source of the impact to the nose gear landing light could not be determined. It is possible the aircraft struck a bird or an RPA during departure from Sydney, or foreign object debris during its take-off roll. It should be noted, however, that no debris was found during runway inspections at Sydney Airport and there was no visible biological evidence of a wildlife strike.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the landing gear damage involving Airbus A320 VH-VHL, on 5 March 2020.
Contributing factors
On departure from Sydney, the nose gear landing light was probably struck and damaged by an unknown object. Consequently, part of the nose gear landing light lens likely impacted and damaged the main landing gear.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Jetstar Airways
the nose gear landing light manufacturer.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Jetstar Airways
Airbus
the nose gear landing light manufacturer
French Bureau of Enquiry and Analysis for Civil Aviation Safety (BEA).
A submission was received from:
Jetstar Airways.
The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
In the early morning of 7 March 2020, a maintenance work group was undertaking work between Thorneside Station and Birkdale Station on the Cleveland rail corridor in Brisbane, Queensland. Queensland Rail (QR) was the rail infrastructure manager of the rail corridor. The work involved replacing a defective section of track.
A planned closure was due to commence at 0218, during which the replacement of the rail track would be done under a track occupancy authority (TOA) with in-field protection. Prior to the planned closure, the work group conducted preparatory work under a TOA which did not require in-field protection.
Soon after 0100, an excavator operator was directed by a member of the work group (the recipient) to access the running tracks. However, at that time the rail corridor was open for normal rail traffic activity.
At about 0108, a suburban passenger train was involved in a near collision with the excavator near Thorneside. With the train speed greater than 90 km/h, the driver of the suburban train noticed the excavator on the running tracks and applied the emergency brake. At about the same time, the excavator operator identified the oncoming train and initiated emergency measures, removing the machine from the running tracks as the train passed at a speed of about 61 km/h.
The train stopped 75 m past the incident site. The network control officer (NCO) subsequently approved the driver to continue after being informed that the excavator was clear of the tracks. However, the excavator was still within the (3 m) danger zone, less than 1 m from the nearest rail.
The excavator operator was directed by the work group supervisor to remove the excavator. As the excavator operator was about to do so, at 0137, there was a second near collision when another suburban passenger train passed through the incident site at 60 km/h (after applying emergency braking). The excavator operator had to jump clear down an embankment to escape danger as the train passed.
What the ATSB found
The network pre-start briefing for the work group was conducted at the Cannon Hill depot before the workers departed for the worksite. However, the ATSB found that the lead protection officer (PO), assistant PO and the excavator operator were not included in the briefing, which denied them and the work group of essential safety information applicable to their roles and responsibilities.
There were also limitations with a number of subsequent communications processes after the work group arrived at the worksite. The lead PO was not informed of or aware that the excavator had arrived at the worksite. Consequently, when the NCO notified the PO of a track fault indication (associated with the on-tracking of the excavator) and asked if there was any equipment on-track, the PO had an incomplete mental model of the work group and advised the NCO that there was no equipment on-track at that time.
In addition, without gaining the necessary permission, the recipient had directed the operator of the excavator to on-track under the incorrect assumption the planned closure had commenced, and the worksite was protected by a TOA with in-field protection and train activity on the rail corridor had ceased. The recipient had misinterpreted the situation due to misinterpreting an instruction from the team leader and a combination of other situational factors.
Following the first near collision, communications between the emergency hotline contact (in the network control centre) and the lead PO, and between the lead PO and the work group supervisor, did not clarify that, although the excavator was off the track, it was still in the danger zone. The supervisor also directed the excavator operator to remove the excavator from the danger zone without gaining the necessary authority from the NCO or confirming that rail traffic had been stopped. This omission contributed to the second near collision.
Some of these communication problems were associated with personnel not using appropriate rail terminology when conducting safety-critical communications. The ATSB found that the Queensland Network Rules and Procedures did not provide sufficient guidance for rail safety workers to ensure they used standardised rail-specific terminology when communicating safety‑critical information.
Network pre-start briefings are a critical control in place to manage the risk of collisions between rail traffic and workers and machinery, and Queensland Rail had undertaken significant work in recent years to improve these processes. However, the ATSB found that the design of the first-line assurance activities and the limited conduct of second-line and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively.
What has been done as a result
Soon after the incident, on 10 March 2020, Queensland Rail (QR) issued a critical safety alert (CSA) directed to protection officers (POs) and their supervisors and managers, and all infrastructure workers and their supervisors and managers. The alert outlined a number of key actions, including that all workers must attend a prestart briefing prior to entering the rail corridor (and the briefing must include the PO giving the rail safety component of the briefing). In addition, all workers could not access the danger zone without being given permission by their supervisor, and the supervisor could not allow workers to enter the danger zone until they had received advice from the PO that required protocols were in place.
As a result of the incident, QR subsequently entered an enforceable voluntary undertaking (EVU) with the Office of the National Rail Safety Regulator (ONRSR). As part of the EVU, QR committed to 13 initiatives to improving planning processes for track access, the safeworking control framework, capability of safety-critical workers and effectiveness of safety assurance and performance. As of 1 November 2023, 12 of the 13 initiatives had been externally verified as closed and QR advised that the final initiative was on track for completion by 31 December 2023.
In addition to the EVU initiatives, QR has proactively introduced safety actions in response to this incident by:
redeveloping the protection officer training package
delivering communication training for all rail corridor workers
implementing a first-line assurance activity focused on the effective use of rail-specific terminology and a range of other technical and non-technical skills when communicating safety-critical information
developing targeted first and second-line assurance activities to measure the effectiveness of the improved pre-start briefing process.
Safety message
Substandard network pre-start briefings and communication irregularities have been identified as contributors to railway accidents in Australia and abroad. However, with this knowledge, rail infrastructure managers and track workers are still experiencing problems with the application of effective safety-critical communication, and assurance that network pre-start briefings are conducted in accordance with procedures designed to manage safety risks. It is essential that all workers attend a network pre-start briefing prior to entering the rail corridor and fully understand the worksite protection that is in place for their activities. It is also vital that workers use standardised railway terminology when conducting safety-critical communications to minimise the potential for misunderstanding.
In a safety-critical work environment that fundamentally relies on procedural controls, it is vital that first-line assurance activities are appropriately designed to provide an accurate account of key work practices being assessed, and that sufficient higher level assurance activities are conducted to provide confidence in the results of the first-line assurance activities. The absence of accurate information limits the ability of an organisation to learn and continuously improve safety.
The occurrence
Overview
In the early morning of 7 March 2020, a maintenance work group was undertaking work between Thorneside Station and Birkdale Station on the Cleveland rail corridor in Brisbane, Queensland. Queensland Rail (QR) was the rail infrastructure manager of the rail corridor.
At about 0108 local time, a QR suburban passenger train, with passengers on board, almost collided with an excavator while it travelled along the rail tracks near Thorneside. While personnel were attempting to remove the excavator from the danger zone[1] of the rail corridor, a second near collision occurred involving another suburban passenger train.
Pre-work arrangements
The maintenance work group was tasked with replacing a defective section of railway track located between Thorneside and Birkdale stations. The following personnel were involved in the maintenance work:
a QR depot supervisor
a QR work group team leader (acting as the supervisor of the maintenance task under the guidance of the depot supervisor)
4 QR maintenance personnel, including the operator of a front-end loader and one worker performing the role of the recipient.[2]
In addition, the following contractors were involved in the track maintenance work:
a welder
a labourer
2 protection officers[3] (POs), (lead PO and an assistant PO)
an excavator operator.
The ‘planned closure’[4] was scheduled to start at 0218 on 7 March and involved the use of a track occupancy authority[5] (TOA) with in-field protection (sometimes known as a ‘protected TOA’).
At 2100 on 6 March 2020, the QR personnel, the labourer and the welder commenced their shift at the Cannon Hill depot in Brisbane. The supervisor and team leader discussed planning for the task and potential contingencies if there were delays. The team leader and members of the work group, who signed on at the depot, then prepared the work truck with the necessary tools for the worksite, while the supervisor planned the work schedule from their office.
At about 2130, the team leader gathered the work group members who were present for a network pre-start briefing[6] at the depot. The brief discussed the nature of the work task as well as the hazards and controls that would be applied. The work group was told that it was likely that preparation work at the worksite would occur prior to the planned closure using a TOA without in‑field protection (sometimes known as an ‘unprotected TOA’). The POs and the excavator operator were not involved in the pre-start briefing at the Cannon Hill depot.
After completing the network pre-start briefing, the team leader and members of the work group signed the relevant section of the Network Pre-Start Briefing form(MD-15-43), verifying they were present and that they understood the requirements of the briefing.
At about 2200, the work group members at the Cannon Hill depot travelled to the worksite at Thorneside, stopping briefly to purchase refreshments. At the same time, the POs arrived at the Cannon Hill depot to meet with the supervisor to discuss work arrangements, in particular the protection at the worksite. The supervisor communicated the potential for performing preparation work prior to the planned closure under the safeguard of a TOA without in-field protection,[7] which would require protection arrangements for the period of the preparation work in addition to those published in the train notice[8] for the planned track closure. Following the discussion between the supervisor and the POs, the team leader was provided with an overview of the proposed arrangements.
The lead PO contacted the network control officer (NCO) to discuss the proposed arrangements. The NCO checked their train diagram[9] and confirmed with the PO that there was availability to instate a TOA without in-field protection for the preparation work that allowed workers access to the track between trains for brief periods. As the NCO was nearing the end of their shift, they stated that they would inform the incoming NCO of the proposed work on track arrangement and the agreed protection for that work.
At about 2215, the team leader departed the Cannon Hill depot and travelled to the worksite at Thorneside. Shortly after, the POs and the supervisor also left the depot and travelled to the worksite in separate vehicles.
Preparation work
At about 2235, the team leader and members of the Cannon Hill work group arrived at the work group entrance gate to the rail corridor at Thorneside (located at the 23.645 km mark),[10] which was about 340 m east of the actual worksite (Figure 1). The team leader directed the recipient and the front-end loader operator to travel to Thorneside Station to collect the front-end loader that was required at the worksite.
At about 2245, the POs arrived at the work group entrance gate. The team leader and lead PO discussed the required protection arrangements for the preparation work, and the PO then briefed the work group members who were present about these arrangements.[11] The supervisor had not arrived at the worksite at this time. The PO explained that work in the danger zone would be for short periods, which would occur between train activity under the safeguard of a TOA without in‑field protection. The PO then contacted the NCO and the paperwork relevant to this TOA was completed. At about that time, the supervisor arrived at the entrance gate.
The TOA without in-field protection was issued to the lead PO at 2252 and it was suspended 10 minutes later at 2302. In that period, the PO, supervisor, and team leader entered the rail corridor through the entrance gate and walked to the worksite to evaluate the track defect and work requirements. While the TOA was suspended, they stood clear of the danger zone and 2 suburban passenger trains passed the site.
The TOA was reinstated at 2322 and suspended at 2333. In that period, at the request of the team leader, 4 members of the work group walked from the entrance gate to the worksite to perform preparation work, while the team leader returned to the entrance gate to measure a length of rail that had been placed in the rail corridor days earlier. The length of rail was to be cut to size in preparation for the replacement of the track defect at the worksite. The lead PO and supervisor remained at the worksite.
At 2325, the excavator operator, who was required for the planned closure (but not the preparation work) contacted the supervisor to obtain information about the location of the worksite. The supervisor directed the excavator operator to travel to the work group entrance gate and wait for instructions.
The excavator operator arrived at the entrance gate at about 2335, where they were met by the team leader and members of the work group. The excavator operator requested a worksite briefing but was told to wait until further notice as the excavator was not required until the planned closure and after the preparation work was finished. After completing several tasks, the team leader discussed the work arrangements with the excavator operator and requested the operator sign the network pre-start briefing form, which was signed. The excavator operator was not provided a formal network pre-start briefing and was not provided with any briefing about worksite protection arrangements by the lead PO. The PO was not informed or aware that an excavator had arrived at the worksite.
The team leader advised the excavator operator not to unload the excavator from the truck as passage through the work group entrance gate was not suitable for the excavator (as cement troughing was blocking its path). Consequently, the team leader directed the excavator operator to travel to another entrance gate further east, located at the 24.117 km mark (Figure 1), and wait for further instructions. In addition, the team leader advised the excavator operator to complete all documentation pertaining to the excavator accessing the rail corridor in readiness for the planned closure. The excavator operator then travelled to the next entrance gate, unloaded the excavator from the truck, and prepared the relevant paperwork.
Figure 1: Places of interest relevant to the worksite and the entrance gates
The image shows Thorneside Station, the worksite, entrance gates for the work group and the excavator and near collision location.
Source: Google earth, annotated by the ATSB
The TOA was reinstated at 0022 (on 7 March) and suspended at 0033. In that period, members of the work group walked from the worksite back to the work group entrance gate as preparation work at the worksite had been completed. The only remaining work activity prior to the planned closure was to load the bucket of the front-end loader with tools and equipment in readiness for transportation from the entrance gate to the worksite. At this time, the front-end loader was in the rail corridor near the entrance gate, but on the opposite side of the rail tracks to that of the entrance gate, work truck and work group.
While the TOA was suspended, the recipient, who had assisted in preparing the worksite, travelled by car to meet with the excavator operator at the other (excavator) entrance gate. The recipient and the excavator operator completed the necessary documentation in relation to the height limiter[12] on the excavator. The recipient advised the excavator operator that they required additional information on the state of the planned closure before they could grant access to the rail corridor. The recipient then travelled back to the work group entrance gate.
At 0051, as the recipient arrived back at the work group entrance gate, the TOA was reinstated. The team leader communicated an instruction to the work group ‘it’s on’, by which they meant the TOA had been reinstated and tools and equipment could be transferred from the work truck into the front-end loader.
On-tracking of the excavator
The recipient heard the team leader’s instruction and witnessed the work group loading the front‑end loader and assisted with the loading. Soon after, the operator of the front-end loader gave the recipient the height limiter key, which was a requirement before machinery could perform work on track under live overhead equipment. In interview, the recipient stated that the combination of these events gave them the impression that the planned closure was now in force.
In the belief that the planned closure was now active, the recipient contacted the electric control officer[13] (ECO), in accordance with procedures, to inform them about the location of the worksite and the number of machines (excavator and front-end loader) at the worksite.
Without seeking or receiving confirmation from the relevant personnel (team leader, supervisor, or PO) on the state of work and protection arrangements, the recipient travelled back to meet with the excavator operator at the (excavator) entrance gate. The recipient informed the excavator operator that the planned closure was active and that they could on-track the excavator, and the recipient unlocked the access gate.
Meanwhile, at the work group entrance gate, the team leader instructed all the workers there to stand down. At 0102, the lead PO, who was unaware that the recipient had directed the excavator operator to on-track the excavator, suspended the TOA and advised the NCO that preparation work was complete and there would be no further work until the planned closure at 0218. On receipt of the suspend code,[14] the NCO suspended the block,[15] and then set the signal path for a suburban passenger train (1898) to travel from Thorneside to Cleveland (eastward).
Shortly after the TOA for the preparation work was suspended, the excavator was driven into the rail corridor and, with the aid of its boom arm and bucket, the operator pulled the upper frame of the excavator onto the track and placed its guide wheels on the running tracks. The recipient advised the excavator operator to proceed towards Thorneside where they would be met. The recipient then returned to the work group entrance gate by car.
Track fault
At 0106:55, while train 1898 was stationary at Thorneside Station, the signalling system detected a track section between Thorneside and Birkdale was occupied. This detection momentarily generated a ‘failed track’ message on the monitor of the NCO’s workstation. At 0107:01 the track recovered, and at 0107:19[16] the passenger train departed the station.
As the indication of the failed track was in the vicinity of the work group, it prompted the NCO to contact the lead PO and question the whereabouts of the work group and machinery in relation to the running line. The NCO asked the PO if anyone in the work group had ‘gone on or near the track’, to which the PO replied ‘no’. The NCO further stated, ‘I’ve had a track fail and recover, which is most unusual, within the extremities of your TOA … which seems a bit odd’.
The lead PO ended the conversation by reassuring the NCO that everyone in the work group was off the track. At this time, the PO was unaware of the excavator’s movements and that it had on‑tracked as directed by the recipient.
First near collision
As train 1898 passed the work group entrance gate, it accelerated to above 90 km/h along the 100 km/h section of track (Figure 2). The recipient, who only minutes earlier directed the excavator operator to on-track the excavator, had just arrived back at the work group entrance gate as the train passed. On seeing the train, the recipient sounded the car horn in an attempt to warn the excavator operator of the approaching train, and they then proceeded in the car back towards the excavator.
Figure 2: View from train 1898 showing the work group, front-end loader, and headlights of the excavator in the distance
The image is from the front-of-train camera in train 1898. The time is 0108:22, about 19 seconds prior to the near collision. In the distance, the headlights of the excavator can be seen as it travelled towards the worksite.
Source: Queensland Rail, annotated by the ATSB
The excavator operator first noticed the train’s headlights in the distance and assumed that they belonged to other machinery at the worksite. They had not heard the car horn.[17] At about the same time, the train driver observed the lights of the excavator, which they thought belonged to a car travelling on the road adjacent to the rail corridor.
As train 1898 traversed the sweeping left curve between the 2 entrance gates (Figure 1), both the train driver and the excavator operator realised that there was an imminent risk of collision. The train driver immediately applied the emergency brake, while the excavator operator swung the boom arm about 90° to the right of the excavator’s direction of travel, gouged the bucket into the ground and dragged the excavator from the rail tracks just prior to the train passing at about 61 km/h (Figure 3).
The excavator came to a stop clear of the running tracks. However, it was still in the (3 m) danger zone, less than 1 m from the nearest rail.
Figure 3: View from train 1898 showing the near collision
The images, from 1898’s front-of-train camera, are in sequential order and show the near collision between 1898 and the excavator. The rear of the excavator moved clear of the running line less than 1 second before the train’s arrival, with the train travelling at about 61 km/h.
Source: Queensland Rail, annotated by the ATSB
After stopping (about 75 m past the excavator), the driver of 1898 contacted the NCO and reported that they had almost collided with a ‘tractor or backhoe’ that was on the track.
The NCO then called the lead PO and described what the train driver had reported and made further inquiries as to whether a backhoe or loader was at the worksite. The PO advised the NCO that there was a front-end loader at the worksite, but it was well clear of the track when the train passed. The NCO then asked the PO if there was any other machinery at the worksite, to which the PO replied, ‘we only have one machine that’s it … and I’m standing right next to it’. Further discussion between the PO and NCO considered the possibility that another machine had on tracked near the worksite.
After finishing the call, the lead PO informed the depot supervisor of the situation. The supervisor stated that they had just received a call from the recipient explaining how they had directed the excavator operator to on-track as they thought that the planned closure was active and train activity had ceased.
At 0116, the lead PO contacted the QR ‘emergency hotline contact’ (located at the network control centre) and reported the near collision. As the PO was not located at the incident site, they provided details to the hotline contact as received from the supervisor, who was in direct communication with the recipient at the incident site.
The emergency hotline contact asked the lead PO ‘… has he moved away from the track’, referring to the excavator. The PO then relayed this question to the supervisor. The supervisor, after consulting with the recipient, confirmed that the excavator was away from the track, and this information was relayed on to the hotline contact. The emergency hotline contact then told the PO to leave the excavator where it was as the incident was going to be investigated. That message was then relayed to the depot supervisor, who passed it on to the recipient. During these communications, it was not made clear to any party that although the excavator was no longer on the track, it was still within the danger zone.
At the network control centre, the NCO was informed (by the emergency hotline contact) that the excavator had been moved away from the running tracks. After checking the welfare of the train driver, the NCO authorised the train’s movement from the incident site.
The depot supervisor, who had been in contact with their off-site manager regarding the incident, advised the lead PO that work was cancelled and that they were required to travel to the Cannon Hill depot for drug and alcohol testing. The depot supervisor then had another conversation with the recipient, who confirmed that the excavator was off track but may still be in the danger zone. The depot supervisor then travelled to the incident site to assess the situation (Figure 1). The PO discussed the supervisor’s directive with another member of the work group and then decided to travel to the incident site rather than returning to the Cannon Hill depot, as it was their role to oversee the protection of workers within the rail corridor.
Second near collision
When the depot supervisor arrived at the incident site, they noticed the excavator was still in the danger zone although they believed it was not within the profile of a train. The supervisor, without gaining the necessary authority from the NCO (via the PO), instructed the excavator operator to move the excavator from the danger zone. The supervisor later reported that they assumed that after a near collision, the NCO would have stopped all trains, but they did not confirm that this had occurred.
At 0136:22, the next suburban passenger train en route to Cleveland (18A0) departed Thorneside Station.
As the excavator operator moved towards the excavator, in accordance with the supervisor’s instruction, they heard a member of the work group call out ‘train on’. The excavator operator stated that, after seeing the train, they jumped down the embankment and clung to the fence as they thought the train may collide with the excavator. The train passed by the incident site at about 60 km/h.
At 0137, the driver of 18A0 contacted the NCO and reported ‘… the excavator was only just clear of the track, I thought I was going to clip it’.
After 18A0 had cleared the area, and without requesting the necessary protection, the excavator operator was again directed to remove the excavator. On this occasion, members of the work group cut a gap in the fence and the excavator was removed from the rail corridor.
After receiving advice of the second near collision, the NCO contacted the lead PO regarding the location of the excavator and its proximity to the running track. The PO advised the NCO that the excavator had been removed from the rail corridor and the work group were returning to the Cannon Hill depot for drug and alcohol testing.[18]
Context
General information of planned closure
Track defect
A track inspection in 2019 identified a track defect just east of Thorneside Station. Work to rectify the defect involved the replacement of a 5 m section of track, which involved cutting and welding. As dry weather restrictions were in place at the time, the work was deferred until the restrictions were lifted.
Train notice
On 28 February 2020, a train notice (TN20-02366) was issued that detailed the planned closure and work required to correct the track defect. The train notice included information such as:
the date of the planned work – 7 March 2020
the depot of the work group performing work – Cannon Hill
the protection for the worksite – track occupancy authority (TOA) with in-field protection
the extent of protection – main Cleveland line between signal L294 and signal TS9 Thorneside and No.2 road from signal TS11 to 656 points Thorneside (in effect from Thorneside Station east towards Birkdale Station)
the name and contact details of the assigned protection officer (PO).
The train notice also specified the type of plant (machinery) that was permitted to work within the TOA, which consisted of a front-end loader and an excavator. In addition, it noted that rail traffic would be suspended on the main line from Birkdale to Thorneside for maintenance work between 0218 to 0440. No trains would normally be running on the line during this period.
The purpose of the train notice was to inform relevant rail personnel of the details associated with the planned work and the impact that it would have on operations and advise those who needed to plan for the proposed closure.
The train notice did not mention that preparation work would be conducted under the protection of a TOA without in-field protection, as this arrangement was initiated after the train notice was published and as a result of some staff reporting sick during the day of 6 March.
Planned closure protection
In the scheduling phase of the planned closure, a TOA with in-field protection[19] was the chosen ‘work on track authority’[20] to protect workers within the worksite. It was selected because repairing the track defect involved breaking and obstructing[21] the track. In addition, machinery and members of the work group were required to work within the danger zone. This option was determined as an efficient and safe means of protecting the work group when performing such work.
To implement the TOA with in-field protection, the PO needed to coordinate with the network control officer (NCO) so that the NCO applied blocking facilities to prevent unauthorised rail traffic entering the portion of track within the TOA limits. Additionally, the PO or their delegate was to organise in-field protection at the limits of the TOA or at a defined distance from the worksite after blocking facilities were in place.
Two POs had been allocated to the planned work, with a QR employee assigned the role of lead PO and a contractor the role of assistant PO (to organise the in-field protection).
The protection arrangements (TOA with in-field protection) for the planned closure on 7 March was appropriate for the type of work involved in removing and replacing the section of track at Thorneside.
Preparation work prior to planned closure
Reason for preparation work
On 6 March, the day prior to the planned closure, the assigned lead PO and one of the 2 assigned welders reported sick. To fill the role of the lead PO, the contractor PO who had already been assigned the role of erecting in-field protection was elevated to the role of lead PO, and another contracted worker was engaged to erect the in-field protection for the planned closure. During the afternoon, both POs were advised to meet the QR depot supervisor at the Cannon Hill depot at 2200 to discuss protection arrangements for the worksite.
A replacement welder, however, could not be found at short notice, which placed pressure on the work group completing the work within the available timeframe. To remedy this problem, there was a proposal to start preparation work earlier than the scheduled start time listed on the train notice. This involved gaining access to the rail corridor, under the safeguard of a TOA without in-field protection, to perform the preparation work prior to the planned closure. The proposal required approval from the NCO overseeing the area where the preparation work was planned.
Preparation work protection
The QR document MD-12-189 (Queensland Network Rules and Procedures or QNRP) stated the safety requirements for all persons required to access and perform activities on QR’s rail corridor.The QNRP allowed for work within the danger zone under the safeguard of a TOA without in-field protection provided there was no requirement to break or obstruct the track. The preparation work prior to the planned closure did not require the track to be broken or obstructed.
At the worksite, and prior to requesting the TOA without in-field protection, the lead PO completed a ‘corridor safety planner and assessment form,’ which determined the protection was adequate for the proposed work arrangements. The PO contacted the NCO, who issued the TOA without in‑field protection to perform the preparation work between train movements prior to the planned closure.
During the preparation work, the lead PO and the NCO were suspending and re-instating the TOA without in-field protection as required between train movements. When the TOA was active:
The NCO was applying blocking facilities to prevent unauthorised rail traffic entry into the portion of track within the limits of the worksite.
The lead PO’s role was to inform the work group that protection was in place and work could be performed within the danger zone. Immediately prior to suspending the TOA, the PO’s role was to ensure workers were clear of the danger zone and in a safe place.
Under the requirements for a TOA without in-field protection, a ‘lookout’[22] was required if the track speed approaching the worksite was 100 km/h and there was less than 560 m minimum sighting distance. The track speed approaching the worksite from the west was 100 km/h and the sighting distance was about 350 m. Therefore, a lookout was required as an additional safety measure at the worksite. The ATSB identified that there was no ‘lookout’ in place at the worksite while the preparation work was conducted. Although this omission did not comply with the procedure, it did not contribute to the first near collision.
Worksite and rail corridor information
The worksite was about 500 m east of Thorneside Station, on the Cleveland rail corridor branch line (Figure 1). The branch line, which commenced at Park Road Station, serviced the south‑eastern suburbs of Brisbane. Between Park Road and Manly stations there were 2 suburban unidirectional running lines with some bi-directional signalling to facilitate the passing of trains. The main line east of Manly (which included Thorneside and Birkdale stations) had a single bi-directional running line that continued through to Cleveland Station.
Steep slopes on either side of the rail corridor prevented direct access to the worksite. To reach the worksite it was necessary for the work group to enter the rail corridor through the entrance gate about 340 m further east.
The excavator could not access the rail corridor through the same entrance gate as the work group, as cement troughing blocked its entry. Therefore, it was necessary to transport the excavator to the entrance gate about 470 m further east of the entrance gate used by the work group (Figure 1).
Rail network safety
Responsibilities of track workers
The QNRP referred to track workers as ‘Competent rail safety workers whose primary duties are associated with work on or around infrastructure in the Rail Corridor.’ It stated:
Track workers’ responsibilities may include:
• performing track maintenance or construction work under supervision
• supervising track maintenance or construction work groups
• coordinating track maintenance or construction work groups and associated rail traffic in liaison with the Network Control Officer
• operating track machinery
• obtaining Authorities
• determining safety measures required for occupation of track
• managing worksite protection.
The QNRP also stated:
Work planned for the Rail Corridor must be assessed for safety and its potential to intrude on the Danger Zone.
No one can enter the rail corridor without:
• being accredited as a Protection Officer or being supervised by a Protection Officer
• contacting the relevant Network Control Officer or their delegate prior to entering the rail corridor and advising of their entry.
The deport supervisor, team leader, and recipient confirmed that prior to accessing the rail corridor under a TOA, the PO would obtain access authority and then inform the work group leader, who would then instruct other workers that they could access the rail corridor.
When dealing with a track vehicle needing to access or travel within a TOA, the QNRP stated:
Track vehicles associated with a… Track Occupancy Authority [TOA], entering or moving within the limits of the… Track Occupancy Authority must:
• be piloted, or
• receive written instructions from the Possession Protection Officer or Protection Officer.
Work group information
The QNRP defined a work group as:
One or more workers who function as a team to undertake a common task, within the Rail Corridor and/or Danger Zone under the authority of a Workgroup Supervisor and have their own prestart briefing.
Track workers must only perform work relevant to their competency qualifications. The work group assigned the task of repairing the track defect at Thorneside were appropriately qualified to perform relevant rail safety work applicable to their area of competence.
Supervisor information
The responsibility of a work group supervisor / team leader was to ensure there were sufficient qualified workers to complete the work within the time available. This included:
ensuring workers were appropriately qualified and competent to perform work
ensuring the necessary tools, equipment and machinery were available for workers to complete work tasks
having contingency plans in place if the work could not be completed in the scheduled time
ensuring that all work group members participated in the network pre-start briefing.
At a worksite, the supervisor / team leader was required to:
actively oversee and communicate with work group members to ensure the work was progressing as planned
communicate with the PO to ensure protection arrangements were adequate for the protection of the work group
assist as required at the worksite and comply with the rules and procedures relevant to QNRP.
The supervisor of the work group involved in the near collision at Thorneside gained employment with QR in July 2012 and held positions in several roles, all within track maintenance operations. At the time of the incident, their role was acting supervisor at the Cannon Hill depot. Their role at the worksite was to oversee the work and supervise the team leader and others as required.
The supervisor attended training courses and successfully gained numerous rail safety qualifications applicable to rail safety work. Training and critical safety alerts relevant to this incident included:
Communication protocols
Communications (QNRP)
Safely access the rail corridor (QNRP)
Protection officer 1 (QNRP)
Protection officer 2 TOA (QNRP)
Critical safety alert: Follow instructions respond to emergency
Critical safety alert: Entering the danger zone
Critical safety alert: Communication safety critical information
Emergency response
Safety critical communications
Delivering a pre-start briefing (network)
Rail safety awareness
Toolbox talk: Safeworking incidents
Plan and organise work
Operate under track protection
Process workplace documentation
Follow work health and safety
Perform lookout duties
Awareness safeworking rules.
Safety comes first always workshop.
On the day of the near collisions, the supervisor was overseeing the team leader, who was acting as the supervisor in charge of the work group.
The supervisor had been working day shifts until 5 March and had over 30 hours free of duty prior to signing on for the overtime shift at 2100 on 6 March. They reported that they had a nap on the afternoon of 6 March before going to work, and they did not feel fatigued at the time of the incident.
Team leader information
The team leader worked as a track maintainer with a rail contract company for about 3 years prior to gaining employment with QR in September 2016. Through internal training, the team leader acquired rail safety qualifications appropriate to their employment in network maintenance operations. They had recently undertaken the role of acting team leader. Training relevant to this incident included:
Safely access the rail corridor (QNRP)
Communications (QNRP)
Protection officer 2 TOA (QNRP)
Protection officer 1 (QNRP)
Network lockout workshop
Toolbox talk: First worker at emergency site
Delivering a pre-start briefing (network)
Toolbox talk: Post incident management guideline
Rail safety awareness
Follow occupational health and safety
Process workplace documentation
Lead a work team or group
Perform lookout duties
Safety comes first always workshop.
On the day of the incident, the team leader was acting as the supervisor under the guidance of the depot supervisor. The team leader delivered the network pre-start briefing at Cannon Hill depot and oversaw the work group and work activities associated with the replacement of the defective section of track.
The team leader had been working day shifts until 5 March and had over 30 hours free of duty prior to signing on for the overtime shift at 2100. They reported that they had a normal sleep on the night of 5 March and a nap on the afternoon of 6 March before going to work, and they did not feel fatigued at the time of the incident.
Protection officer information
The QNRP stated that the primary duty and responsibility of the PO was to manage the rail safety component of a worksite, and that the PO must be satisfied other work will not interfere with their primary duties. A worksite in the danger zone, or a worksite with potential to intrude into the danger zone, was required to have a PO for the duration of the work.
Specific planning duties of a PO included:
investigating the location of the worksite
having a detailed work plan
completing a safety assessment to determine the work on track authority, means of protection[23] or safety measures[24] needed to protect workers
meeting with the supervisor of the work group to discuss safety and protection arrangements
providing worksite protection details for the worksite safety briefing
participating in the network pre-start briefing
contacting the NCO if necessary.
Specific duties at the worksite included:
communicating with the NCO about the work
ensuring the appropriate protection had been selected to protect the work group at the worksite
identifying the safe place (for workers at the worksite)
advising the supervisor / work group when it is safe to enter the rail corridor / danger zone
immediately prior to suspending a TOA ensuring workers cease work and remain clear of the danger zone
keeping records about the work on track method and protection arrangements.
The lead PO involved with the track work near Thorneside held the appropriate competencies to administer TOA protection. The PO had worked for contract providers while performing the role as a PO for more than 3 years. They had worked on the QR network many times but had not previously worked at Thorneside. On the day prior to the planned closure, the PO was advised by a QR representative that they would be the lead PO and to meet the depot supervisor at Cannon Hill depot at 2200 to discuss protection arrangements for the planned work at Thorneside.
The assistant PO was not involved in any work activity related to the preparation work. Their role was to place in-field protection after the preparation work was completed and prior to the commencement of the planned closure.
Excavator operator information
The role of the excavator operator during the planned closure was to move the replacement piece of rail from within the rail corridor to the worksite. At the worksite, they were required to remove the defective rail and fit the replacement rail into place so it could be welded. In addition, they were required to comply with rules and procedures applicable to working safely within the rail corridor.
The excavator operator was employed by an external provider as a sub-contractor providing services to QR as required. They were advised to meet a QR representative at Thorneside Station at 2230 on 6 November, who would direct them to the worksite.
The excavator operator was qualified to operate the excavator and held the relevant competencies to work within the rail corridor and danger zone. They had worked in the earthmoving industry for many years and owned an earthmoving business for 11 years. The excavator operator stated that they had worked excavators at QR worksites on multiple occasions but had not previously worked at Thorneside.
Recipient information
The role of ‘recipient’ was previously known as ‘authorised person’ until a recent name change. Although the title of the role had changed, the responsibilities remained the same.
In accordance with QR’s authorised person [recipient] facilitator guide (FG-STD-141-01), the authorised person [recipient], working in QR’s 25,000 volts electrified area, was a qualified and competent worker who:
• needs to be aware of the inherent hazards (high voltage electric shock) and risks associated with undertaking work activities in and around the three (3) metre Electrical Exclusion Zone within the Electrified area.
• supervises (and may also perform) the electrical safety aspects of the work when the work could come closer than three (3) metres of the Overhead Line Equipment.
• accepts Forms [associated with the isolation of the Overhead Line Equipment].
• stays on site while work is being done.
• is appointed by line management to take charge of a specific worksite in the electrified area.
• holds an ‘Authorised Person’ Card, confirming competency.
On the day of the incident, the recipient’s role was to ensure the excavator and the front-end loader did not encroach into the electrical exclusion zone while working under the overhead line equipment at the worksite. This involved completing the relevant documentation with the machine operators and ensuring the height limiter on each machine was engaged prior to working under the overhead line equipment.
As required, the recipient was to interact with and discuss relevant information with the PO at the network pre-start briefing and at the worksite to ensure safety. The recipient could also perform other work tasks at the worksite, providing they were qualified to do so and that the work did not interfere with their primary duties and responsibilities. During the planned closure on 7 March, the recipient was also required to act as the mobile plant spotter,[25] which involved separating the excavator and front-end loader from workers at the worksite.
According to QR’s safe work method statement (SWMS) work activity MD-13-268 (Operation of height limited plant), the recipient was required to establish communication processes with machine operators and these processes had to be incorporated in the network pre-start briefing. The recipient was to observe and supervise the plant operations with full visibility and communication. To ensure this means of communication was operating as intended, they were required to confirm the radio channel and test the radios with each mobile plant operator.
On the day of the incident, the recipient (acting as the mobile plant spotter) was not in possession of a radio when they directed the excavator operator to on-track the excavator and therefore was not able to contact and alert the excavator operator of the approaching train. Channel 15 was recorded in documentation associated with the network pre-start briefing as the radio channel for machine operators to use. However, the recipient did not advise the excavator operator of which channel to use. The excavator operator had set their radio to channel 15 as this was the preferred channel when working on QR worksites (Excavator information).
The recipient had worked in rail maintenance operations as a QR employee for about 3 years. Prior to working for QR, they were employed by a railway construction contractor performing rail safety work. The recipient had gained numerous rail safety qualifications and attended operational training courses that enabled them to perform rail safety work. Training relevant to this incident included:
Safely access the rail corridor (QNRP)
Communications (QNRP)
Safety comes first always workshop
Delivering a pre-start network briefing
Rail safety awareness
Authorised person
Working in the electrified territory
Process workplace documentation
Operate under track protection
Follow work health and safety
Lead a work team or group
Perform lookout duties
Protection officer 1 (QNRP)
Safety comes first always workshop.
Two days prior to the incident, the recipient attended a training course that provided them with recipient qualifications. The recipient attended the course on 4 and 5 March (0800–1600), before having 31 hours free of duty and signing on for work at 2100 on 6 March. The maintenance work at Thorneside on 6–7 March was the first time they had acted in the role of recipient since gaining the qualification. They had previously performed the role of mobile plant spotter.
The recipient noted that normally they would seek confirmation from the team leader / supervisor before directing a vehicle to on-track but on this occasion, they did not do so because they thought they had understood the situation. The recipient also noted that normally all the workers accessed the rail corridor from the same location, whereas on this occasion the excavator being at a different location added some complexity. The recipient also noted that in their experience it was normal for all the workers (including the POs) to be at the same briefing whereas on this occasion the briefings were distributed.
Network pre-start briefing
The QR procedure Network Pre-Start Briefing (MD-12-87) defined a network pre-start briefing as:
A communication and on-site activity planning session undertaken prior to the commencement of work or an activity.
The Network Pre-Start Briefing should involve all workers, contractors, and / or visitors involved or exposed to, the work to be undertaken.
The purpose of a network pre-work briefing was to provide an opportunity for the work group to gain an understanding of the work, roles, and responsibilities of individuals, and provide an environment where questions relating to the work and worksite protection could be asked and answered. The briefing, and its associated form (MD-15-43), provided the framework to ensure hazards were identified, risks were managed, and relevant personnel at the worksite had the appropriate delegation to authorise safeworking decisions.
The QNRP and QR guidelines required the nominated person[26] (in this case the team leader) to deliver the network pre-start briefing before starting work (with a briefing to be conducted for each work activity). MD-12-87 stated the nominated person was to ‘gather all workers and contractors involved in the work to be undertaken’ and explain the activities that were to be completed and how it would be undertaken. Where safeworking requirements existed (for work in the rail corridor), these were to be discussed by the PO.
The nominated person was also required to compile and complete the appropriate network pre‑start briefing form. In addition, they were required to ensure that all identified workplace health and safety and rail safety hazards associated with the work and equipment had appropriate controls in place to manage and or eliminate risk. Each worker / contractor was to have the opportunity to identify any additional hazards or controls, and each worker and contractor was required to sign the briefing form.
The PO’s role at the network pre-start briefing was to inform all workers about the protection in place at the worksite and the limits of the protection. In addition, they were to answer any questions related to protection and worksite arrangements.
Although a planned network pre-start briefing occurred at the Cannon Hill depot on 6 March 2021, delivered by the team leader, the POs and the excavator operator were not invited to the briefing and therefore did not participate in the briefing.
In interview, the recipient stated that a second network pre-start briefing occurred at the worksite prior to entering the rail corridor at Thorneside. This however was not a network pre-start briefing, but rather a briefing to advise the work group that protection was in place for the preparation work and when they could enter the rail corridor and the danger zone. The team leader confirmed that a network pre-start brief did not take place at the worksite.
To assist the investigation, the ATSB interviewed a QR subject matter expert who designed and delivered training for track workers, including POs. In relation to the planned track maintenance work at Thorneside, it was their view that all members of the work group, including the lead PO, assistant PO, and excavator operator, should have attended the network pre-start briefing at the Cannon Hill depot.
Network pre-start briefing form
After a fatal accident in Brisbane in May 2017 (see Previous network occurrences), QR revised and developed a new network pre-start briefing form (MD-15-43) specifically for staff who delivered and participated in network pre-start briefings. The formcontained 6 sections that had to be completed by the nominated person before work commenced at a worksite.
The purpose of the revised network pre-start briefing form was to establish a consistent process for the delivery of a network pre-start briefing and provide a workplace focus on the identification, treatment and communication of both task and site-specific risks. QR developed a facilitator’s guide for trainers, and specific training was provided to rail safety workers who had a responsibility to deliver network pre-start briefings.
The network pre-start briefing form for the work at Thorneside on 6–7 March 2020 was completed by the team leader. Content in the form relevant to this incident included:
Section 1 – This section briefly required details for the work group, the person in charge (in this case the team leader), and the work task (requiring a clear description, SWMSs and permits used). The completed form listed 3 SMWSs but no description of the work task was provided.
Section 2 – This section listed several specific items and sought brief information regarding the process in place for each item.
In response to the question ‘Is the work occurring within the Rail Corridor?’, a box was ticked for the answer ‘Yes – Protection Officer to provide a brief on the track protection requirements’.
In response to the question ‘Is there potential for mobile plant or equipment (including vehicles) to contact people, infrastructure or other plant?’, a box was ticked for ‘Yes – detail the site plan for the separation of people and plant in your briefing…’.
Section 3 – With regards to a site sketch, a train signal diagram for Thorneside with annotations was appended to the form. The diagram showed (in broad terms) the area of the worksite and the travel path that machinery would be using. The travel path did not explicitly indicate that different machinery would be using different access gates (as that had not been determined prior to or during the briefing). The type of machinery using the travel path was not noted.
Section 4 – The form required a list of site-specific hazards and controls. The completed form included several hazards and controls, including:
With regard to the hazard ‘Trains’, it listed ‘Blocks, Lookout’ as the applicable controls. There was no record in the briefing form that there would be 2 phases of work (preparation work and the planned closure work), each with different protection arrangements.
With regard to the hazard ‘Machinery’, it listed ‘Separation, spotters’ as the applicable controls. There was no indication on the form of the types of machinery that would be used (and no mention that an excavator would be used).
Section 5 – This section contained details of what needed to be done if something changed. It included instructions for a ‘Pause and Re-start’ in the event of workers being unprotected, there was a change to the condition / task or a new hazard / risk was identified. Details of any debrief could be included on the form (and in this case it was blank). The instructions for a pause and re-start included:
Immediately pause the work we are doing;
Move to a safe place, and ensure any plant or equipment is moved clear of the Danger Zone and is protected;
Document the new hazard / risk and list the controls (using Section 4); and
Communicate the controls to everyone onsite by conducting a ‘Restart Briefing’.
Section 6 – This section (titled ‘Commitment to work safely’) asked workers to sign the form as acknowledgement that they had ‘taken the opportunity to ask questions and thoroughly discuss this briefing, so you can implement the controls agreed to protect you and your co-workers’. With regard to the completed form:
The work group members who attended the briefing at the depot signed the form at the depot.
The 2 POs and the excavator operator did not attend the briefing at the depot, however their signatures were recorded on the form. The excavator operator signed the form at the worksite at the request of the team leader. Both POs signed the form after returning to the Cannon Hill depot after work at the worksite had been cancelled as a result of the near collisions.
The supervisor’s signature on the network pre-start briefing form was listed after the excavator operator and the lead PO. The supervisor (and another worker) confirmed they were at the briefing at the depot, but the supervisor did not sign the form at that stage.
Network communication
QNRP rule 2007 (Network communications) and QNRP procedure 2008(Spoken and written communication) provided information for rail safety workers relevant to safeworking communication, general communication protocols and communication equipment.
Rule 2007 referred to effective communication as the ability to successfully send, receive and understand information. It stated that communication in the network must be:
clear, brief and unambiguous, and
relevant to the task at hand, and
agreed as to its meaning before being acted upon.
In general, the rule provided information on the principles, fundamentals, and protocols of network communication. It noted that emergency communications needed to commence with the phrase ‘emergency, emergency, emergency’. It also detailed specifics relevant to spoken and written communication in the context of electronic transmissions. However, it did not specify the requirement to use rail industry specific terminology when communicating safety-critical information, either electronically or face-to-face.
QNRP procedure 2008 provided standard terms to be used in radio communications, including using the term ‘out’ when the transition was complete and the term ‘roger’ meaning the information had been received and understood. Like the rule however, there was no guidance to rail safety workers on the use of rail-specific terminology when communicating safety-critical information, either via electronic devices or face-to-face.
In the context of the work and near collisions at Thorneside, rail-specific terminology used in communication should have included terms such as:
Conversely, the Rail Industry Safety and Standards Board’s (RISSB’s) Safety critical communications guideline (2018) stated in a section on fundamentals of communication:
• Where practicable, avoid the use of acronyms and words with alternate meanings… but do use common technical terms used in the industry…
The guideline noted such principles should be applied to all communications, safety critical or not.
The RISSB guideline also stated:
That communications, or the failure thereof, contribute to incidents is not doubted. The exact extent is not accurately established but studies put the rate at approximately 30% across all incident events, with something in the region of 50% in relation to all track work incidents.
Within Australia, one major rail network carried out their own studies and they found that, in an examination of their incidents, a significant number of all incidents had communication as a root cause.
The main factors contributing to these incidents comprised of:
• Lack of Communication;
• Poor Communication; and
• Incorrect Information being passed on.
Train and excavator information
Trains 1898 and 18A0 information
Both trains (1898 and 18A0) were scheduled suburban passenger services travelling between Shorncliffe and Cleveland via Central Station. Train 1898 consisted of suburban multiple units (SMUs) 227 and 229, and 18A0 consisted of an interurban multiple unit (IMU) 166 and SMU 285. Both trains were crewed by a driver and guard and had passengers on board.
Trains 1898 and 18A0 were fitted with event recorders and front-of-train cameras. Relevant information from these recordings has been included in other sections of this report.
Excavator information
The excavator involved in the near collisions was a Kubota CRV032 (Figure 4). It had an operating weight of 5 t and was fitted with small, retractable rail wheels enabling it to mount and operate on the running tracks.
The maximum speed of the excavator while on track was 4 km/h. It had an R3[32] detection rating, which meant the vehicle did not reliably operate track circuits; as a result, the vehicle was not detected by the signalling system and was not visible on the NCO’s workstation monitor. The boom arm was fitted with a height limiter allowing it to work under live overhead line equipment.
According to QR standard MD-14-575 (Road Rail Vehicles), the excavator was classified as a ‘road rail vehicle’ and was only allowed to operate within track closures. The QNRP categorised a road rail vehicle as a track vehicle. In accordance with the QNRP, permission had to be obtained from the PO before a track vehicle could enter a work on track authority (such as a TOA) or traverse a worksite within a work on track authority. On the day of the incident, the excavator was on-tracked at Thorneside without the permission of the PO.
Australian Standard (AS) 7502:2016 (Road Rail Vehicle) stated that a flashing beacon light shall be mounted on the top of the vehicle, or in a suitable location(s), so that the light is visible to a person standing 4 m in any direction from the vehicle on level ground. In addition, the flashing beacon light was required to be activated while the vehicle was operating on-track in rail mode. Although the excavator involved in the near collisions was fitted with a beacon capable of flashing, video footage showed that it was not active at the time of the near collisions.
In general, where people and mobile plant (machinery) share the same worksite, there should be radio communication between the plant operator and the mobile plant spotter / supervisor. The excavator was fitted with a UHF radio, which was set to channel 15 when it was placed on-track. The excavator operator said that channel 15 was QR’s preferred channel for maintenance work communication and they had been told to use this channel at other QR worksites.
In interview, the excavator operator stated that after the first near collision they transmitted a call over the radio but communication with the work group was unsuccessful. The team leader reported that they heard a radio call on channel 15 including the word ‘train’ but did not know who had made the call and the call did not make sense (as they were not aware that the excavator operator had on-tracked). They asked the person to repeat the message but heard no reply.
Figure 4: Excavator involved in the near collisions
Source: Queensland Rail
Related occurrences
Introduction
This section provides information about a selection of rail occurrences that involve problems with the briefing of rail workers prior to them undertaking work on track. The list is not exhaustive. Each of the occurrences involved a range of different factors, and the descriptions below focus only on aspects that have some relevance to the incident at Thorneside on 7 March 2020.
Mindi, Queensland, 2007
On 7 December 2007, 2 QR workers were fatally injured as a result of being struck by a track machine when carrying out their duties at Mindi, Queensland. The Queensland Transport Rail Safety Investigation (QT2140) stated that worksite safety briefings [network pre-start briefings] were not performed prior to starting work. It also noted that work group members did not challenge the absence of a worksite safety briefing.
One of the recommended safety actions from the investigation noted:
QR take the necessary steps to ensure that Worksite Safety Briefings are conducted in accordance with the Track and Trackside Safety Manual SAF/ STD/0038/SWK [currently MD-12-189, QNRP] and in particular the requirement that:
a. A TPO [PO] is nominated and present before workgroups commence work at a worksite on or near the track; and
b. Worksite protection methods are determined and communicated including when additional workers or workgroups join a worksite.
A coronial inquest into the Mindi accident noted that the absence of a worksite safety brief [network pre-start briefing] was most likely a contributing factor to the death of the 2 workers.
At about 1116 on 5 May 2010 a collision occurred between an XPT passenger train and a track‑mounted excavator near Newbridge, New South Wales. The operator of the track-mounted excavator was fatally injured.
The PO had conducted a pre-work brief involving the excavator operator and a hot-work labourer, during which a TOA was identified as the control in place for rail traffic. After obtaining a TOA from the NCO, the PO then advised the excavator operator and the hot-work labourer that the TOA had been obtained and that they could prepare for work while the PO put the site protection in place. A short time later both the hot-work labourer and excavator operator entered the danger zone before the worksite protection arrangements (detonators and flags) had been put in place.
An examination of the pre-work briefs found that the identified hazards were mostly related to general issues (for example, slips trips and falls and hazards associated with work equipment such as the excavator or oxyacetylene cutting). The only mention regarding the hazard of potential rail traffic identified the TOA as the relevant risk control. There was no mention of unexpected approaches of other rail vehicles and the use of additional site protection.
The excavator operator and hot-work labourer were relatively inexperienced. The ATSB found that, although the PO had told the excavator operator and hot-work labourer that the PO had received the TOA, they did not explicitly communicate to the workers that they should not occupy the danger zone until all site protection measures were put in place.
On 28 March 2011, a freight train 7SP3 collided with a track mounted excavator between Jaurdi and Darrine, Western Australia. The train driver sustained a minor injury. There was significant damage to the lead locomotive and the excavator, and minor damage to the track as a result of the accident.
The ATSB found that 2 track mounted excavators had been placed back on the track without permission of the authorised employee responsible for the coordination of track side safeworking activities between Jaurdi and Darrine. Another finding was that, although separate pre-work briefings were conducted, there was no discussion about train running information and site protection between the supervisor of the excavators and the authorised employee (who was the supervisor of the track machines at another location).
On 2 October 2015, a train departing Laverton Station approached a worksite where a supervisor was marking a track to identify dog spikes to be removed, with a lookout for their protection. The lookout observed the train, warned workers of its approach, and signalled to the driver that the track was clear. However, as the train took the crossover, the supervisor was foul of the track, and was struck by the train that was travelling at about 59 km/h. The supervisor suffered serious injuries.
The ATSB found that the pre-work briefing was not conducted. As a result, the supervisor and lookout (and others in the work group) did not receive the benefits of a safety briefing that would have informed them of the outcomes of the worksite hazard assessment, train running, and the designated position of safety.
On 18 June 2016, a signal maintenance team (SMT) worker was fatally injured by a train at Clyde, New South Wales, while working in the rail corridor. The ATSB investigation (conducted by the NSW Office of Transport Safety Investigations) identified a number of contributing factors and other factors that increased risk. Safety factors related to pre-start briefings included:
The PO had briefed the civil team, however they did not brief the signal team, and the signal team did not seek a pre-work briefing before commencing work on-track.
The signal team assumed their workplace was within the limits of the TOA and did not plan their own worksite protection…
The Sydney Trains worksite briefing process did not compel a new work group to seek a worksite protection pre-work briefing when accessing an existing worksite. The safety message from the ATSB report noted:
This accident highlights the importance of planning and integrating safety across the entire scope of work. It also highlights the importance of briefing all workers and all workers seeking a safety briefing about the worksite protection plans before work commences and when circumstances change.
The investigation report also included a finding relating to network communications between multiple parties not being ‘clear, brief and unambiguous.’
In May 2017, a QR protection officer (PO) was fatally injured after being struck by a suburban passenger train at Petrie, Queensland.
Four POs were assigned to the maintenance task, including 3 POs at Petrie Station. The lead PO participated in the briefing of the maintenance workers, and the 3 POs then undertook a pre-start brief for the implementation of the protection (stop signs and railway track signals), which the other 2 POs then started implementing. It was one of these POs who was fatally injured.
The ATSB found that the POs were not familiar with the new rail infrastructure and uncommon site layout at Petrie Station. The POs were not advised of an early work shift start requirement, which resulted in them having insufficient time to prepare for the task, and they experienced pressure to complete the task within the scheduled time. In addition, QR had no process for ensuring the provision of adequate time for the POs to familiarise themselves with new or changed worksites.
The train notice diagram had been incorrectly marked with the open and closed rail lines by a different PO, and the POs’ pre-start briefing was limited to about 90 seconds. In addition to this, the recorded pre-start briefing forms contained errors and inconsistent sign-off entries; it is possible that the recording of the pre-start brief had been rushed.
Following the accident, QR undertook a number of safety actions. The QR investigation had found that the ‘pre-start briefing process on the night was not effective in ensuring the risks of individual live tracks and site-specific hazards and risks were understood and controlled by the Protection Officers’. A subsequent review of the task distribution for POs noted that the pre-start safety briefings often lacked planning and were delivered spontaneously, and it recommended a review of the effectiveness and improve the delivery of the pre-start safety briefings. The network pre‑start briefing procedure and form were subsequently revised with briefings provided to relevant workers.
Training and qualification records showed that the supervisor, team leader and recipient involved in the occurrence at Thorneside, had attended training in delivering the revised network pre-start briefing procedure and form, and the revised form was used during the pre-start briefing on 6 March 2020. QR also re-enforced the message of ‘the right to stop work and getting safety right before commencing’ as part of its ongoing network pre-start brief project.
In addition, QR organised the development of a consistent process for marking up train notice diagrams.
On 3 July 2019, at Margam East Junction in South Wales, United Kingdom, 2 track workers were struck and fatally injured by a passenger train. A third track worker came close to being struck.
The group of 6 track workers were assigned a safe work pack (SWP) that included 3 tasks to be completed, and another task was added on the morning of the accident that was not included in the SWP. The SWP stated the work would be conducted between 1230 and 1530, with 2 types of protection included for this period (line blockages and lookout warning), although which tasks were to be protected by which method was not clearly articulated.
The workers commenced the tasks soon after 0800 using a lookout, but there were problems with its implementation when the workers spilt into 2 groups doing different tasks with only 1 designated lookout between them. The workers who were struck were performing a noisy task (maintaining a set of points) that should only have been undertaken with the line blocked. The controller of site safety (PO) and the lookout were with the other group when the accident occurred.
Overall, the system of work that was proposed was not adopted, and an alternative arrangement became progressively less safe as the work proceeded, which created conditions that made an accident much more likely. The SWP was developed without the involvement of any of the workers involved, and there was no challenge by the workers to the way the work was being conducted.
The investigation by the UK Rail Accident Investigation Branch (RAIB) found that local management/supervisors were not actively monitoring, and had not identified and managed, non‑compliant safety behaviors at the depot. The investigation also considered why Network Rail (the rail infrastructure manager) had not created the conditions that were needed to achieve a significant and sustained improvement in track worker safety. Relevant underlying factors were identified:
• Over a period of many years, Network Rail had not adequately addressed the protection of track workers from moving trains...
• Network Rail had focused on technological solutions and new planning processes, but had not taken account of the variety of human and organisational factors that can affect working practices on site…
• Network Rail’s safety management assurance system was not effective in identifying the full extent of procedural non-compliance and unsafe working practices, and did not trigger the management actions needed to address them…
• Although Network Rail had identified the need to take further actions to address track worker safety, these had not led to substantive change prior to the accident at Margam.
In terms of safety assurance, frontline management/supervisors were required to undertake planned ‘Level 1’ (first-line) assurance activities, which included worksite inspections to review the effectiveness of the planning process, competence of staff, and unsafe behaviours and activities/ conditions, including corrective actions as required. Regarding worksite inspections, the investigation identified that managers may have been relying on submitted paperwork rather than undertaking observations of work on site. In addition, there was a self-assurance process where front-line management was required to formally check compliance with procedures by responding to a series of subject-related questions. These questions were designed to monitor the managers’ own compliance and that of their staff.
The evidence obtained by RAIB suggested that the underlying weaknesses in the design of the level 1 assurance processes included:
• since managers in Network Rail are often judged on the level of compliance with process, there is an obvious disincentive to assess their part of the organisation as non-compliant
• once a manager has judged their part of the organisation to be non-compliant, there is an implied responsibility to take action; this may mean challenging well established work processes, or risk unwanted confrontation with those in the team
• route level audits tend to be focused on areas considered to be high risk or where self-assurance checks have revealed particular problems. If there are no reports of non-compliances and no significant issues are raised in self- assurance returns, it is easy for particular delivery units or depots to avoid route level audits
The investigation also found multiple problems with the design and execution of this process and noted that it was frequently referred to by managers and staff as a ‘tick box’ exercise. Overall, for a variety of reasons, the audits were not effective in detecting a range of problems with planning paperwork, procedural non-compliance, and unsafe working practices, and did not trigger the higher-level management actions needed to address them.
In contrast, level 2 audits (conducted by persons independent from those with the responsibility to implement the risk controls) detected numerous examples of non-compliance in work practices. Over a 3-year period (June 2016–July 2019), 30 level 2 audits were undertaken. These identified 36 non-compliance reports (NCRs) and 8 repeat NCRs. Most NCRs contained multiple instances of non-compliance of various types and 10 NCRs included non-compliances that were considered by the auditor to be ‘systemic’ in nature. The RAIB noted that the NCRs confirmed evidence that the management self-assurance (level 1) process was an unreliable mechanism. The RAIB also noted these level 2 audits, although reasonably thorough, were heavily based on reviews of paperwork.
Other incidents
Track worker safety has been a significant concern for the rail industry for many years, and at the time of the Thorneside incident track work safeworking was listed by the Office of the National Rail Safety Regulator (ONRSR) as one of its safety priorities. For the calendar year 2020 it reported that there were 458 track work safeworking rule and procedure breaches.
During the investigation, QR was requested to provide records and brief descriptions of notifiable safety incidents relevant to work on track safety breaches between 1 March 2018 and 29 February 2020. QR provided details of 24 incidents that occurred on its south-east Queensland network. Limited details were provided for some incidents. However, the available information indicated at least 3 notifications had some similarities with the incident at Thorneside:
One notification in which a PO advised that an excavator operator had on-tracked an excavator without permission.
One incident in which a welding crew had accessed a rail corridor and commenced work. The welding crew had not contacted the PO to sign on to the multiple workgroup register. A subsequent internal investigation identified a number of ‘absent or failed defences’, including the ineffective use of the pre-start briefing.
One incident involving a near collision between the tilt train[39] and a work group, where the PO suspended the TOA unaware that there was a work group working on-track.
Management oversight of network safety
Overview of risk management and assurance process
QR had documented standards and procedures for risk management and assurance. The standard MD-11-1338 (Risk management) stated:
Risk management embodies an organisational culture of prudent risk-taking within Queensland Rail. It is the process of identifying, assessing and responding to risks, and communicating the outcomes of these processes to the appropriate parties in a timely manner…
Managing risk effectively requires people at all levels in the organisation to have specific accountabilities, authorities, delegations, and appropriate competence to establish, apply and maintain the risk management framework as a basis for good decision making. It is important to have complete and current risk information available as this information assists in ensuring informed decisions around both strategic direction and operational objectives.
Risk management is not a stand-alone discipline and requires integration with existing business processes such as business planning, assurance and Internal Audit, in order to provide the greatest benefits…
In a section titled ‘Monitor and review, the standard stated:
Continuous monitoring and review are vital components of an effective risk management process. They may be undertaken as part of a formal periodic process [planned assurance activities], or performed on an adhoc [ad hoc] basis, (e.g. change in policy or change in requirement).
The primary purpose of monitoring and review is to determine whether risks still exist, whether new risks have arisen, whether the likelihood or impact of risks have changed, and to reassess the risk priorities within Queensland Rail’s internal and external context.
Monitoring and review provide important feedback with regard to assurance over the efficiency and effectiveness of controls implemented to treat risks. It enables QR to analyse and learn lessons from event successes, failures and near-misses.
The standard also stated:
For risk management to be effective, controls must be regularly monitored and reviewed. Controls must be monitored to ensure that they continue to perform as intended and continue to modify the risk in the manner and to the extent assumed in the risk assessment…
QR standard MD-16-24 (Assurance) expanded on the monitor and review concepts. It stated that in order for risk management to be effective, QR should comply with a set of assurance principles, which included:
Assurance is an integral part of all organisational processes. Assurance is not a stand-alone activity that is separate from the main activities and processes of the organisation.
Assurance is risk-based. Assurance should be weighted to risk and control effectiveness. The importance of this is highlighted by following an integrated risk and assurance approach. Ultimately assurance is part of risk management…
Assurance activities are aimed at obtaining reasonable assurance, rather than absolute assurance over Queensland Rail internal performance of controls.
Assurance is systematic, structured and timely. A systematic, timely and structured approach to assurance contributes to efficiency and to consistent, comparable and reliable results…
Assurance is a continuous process that facilitates unceasing improvement. It consists of assurance providers and management incorporating consistent and systematic processes in their day-to-day activities to monitor and assess control effectiveness…
Assurance activities are interdependent and inter-related. All previous and planned assurance activities form an integrated whole and contribute to the application of the Three Lines of Defence Assurance Model.
QR’s 3 lines of defence assurance model was summarised in a diagram, as shown in Figure 5.
Figure 5: QR’s 3 lines of defence assurance model
Source: Queensland Rail
In line with QR’s procedure MD-12-27 (Assurance), QR was to develop an integrated assurance plan (IAP) focussing on second-line and third-line assurance activities through an assurance mapping exercise to provide a holistic view of all assurance activities in relation to the corporate risk hierarchy. The assurance procedure also stated that the planning of second-line and third-line assurance activities would be based on matters such as:
The relevant Key Operating Risks (KOR) and Event Risks (ER) of the Corporate Risk Hierarchy, their linked risks and key controls and the risk tolerance levels.
Findings, conclusions and status of actions from previous management reviews.
Findings, conclusions and status of actions from previous second line and third line assurance activities (including investigations) impacting the risks and controls.
Assurance activities performed by other managers with the Group, Function and other Functions.
QR’s corporate risk register regarded the safeguard of its workforce as one of its major priorities. One of the risks identified was:
The risk of a rail traffic collision with worker whilst in the danger zone, resulting in a serious injury or fatality.
As part of the investigation process, QR was asked to provide its integrated assurance plans[40] for financial years 2017–18, 2018–19, 2019–20 and 2020–21. In addition, the ATSB requested first‑line, second-line and third-line assurance activities over a predetermined period related to network pre-start briefings and related matters.
First-line assurance activities
One type of first-line assurance activity QR used to assess pre-start briefings and protection arrangements and compliance was conducted by use of form MD-17-27 (Worksite protection compliance inspection). The form was focussed on evaluating a specific worker’s compliance relevant to work activities and included 10 items, each with a comments section to record non‑compliances and required actions. One of the items referred specifically to ‘Pre-start safety briefings including additional Site-Specific hazards’. Five of the items referred to different types of safeworking protection. The compliance inspections and the forms were completed by the worker’s supervisor or manager.
There was no explicit guidance associated with the form to explain what aspects of the pre-start briefing were being evaluated (for example, whether it was simply evaluating whether a briefing was conducted, or whether it was also evaluating the content the worker provided during the briefing or whether all members of the work group were at the briefing).[41]
During the 12 months from January to December 2019, south east Queensland (SEQ) network conducted 495 compliance inspections using form MD-17-27. Of these, 9 inspections (about 1.8%) identified non-compliance where action was required with a small number also including reminders or minor issues. The non-compliances included:
incomplete or missing SW01 (corridor safety planner and assessment) form
incomplete or missing safe work method statements
inadequate worksite protection.
No instances of non-compliance in relation to the network pre-start briefing were identified. It was noted that a relatively high proportion of the non-compliance and feedback were identified by a relatively small proportion of those who conducted the inspections.
Another type of first-line assurance activity QR utilised to assess compliance with network pre‑start briefings, worksite protection, and multiple other tasks on the rail corridor was form MD‑12-66 (Construction / Maintenance HSE Inspection Record). The form related to all types of maintenance activities and worksites (not just those on track) and included 199 questions within 24 sections. The form’s instructions stated:
1. Review previous Planned Inspection to ensure all identified issues are addressed.
2. Identify any HSE [health safety and environment] issues that require rectification to ensure compliance…
3. Where a serious issue is identified which presents immediate risk to health, safety or the environment, interrupt the inspection to stop the operation/process and have workers relocated to a safe area (if required).
4. The relevant Manager / Supervisor is responsible for assigning resources to complete required corrective actions within the agreed time frame.
5. HSE issues that are unable to be rectified on the day of the inspection must be risk assessed / prioritised as either: Low, Medium, or High.
6. Ensure all fields are completed and not left blank. If not applicable, add N/A.
7. It is advisable that Supervisors and Managers schedule and attend a Pre-start brief to ensure quality of Safe Work Method Statement (SWMS) delivery.
In a section titled ‘Prestart Safety and Environment Briefing’, one of the questions asked if a ‘pre‑start safety and environment briefing was performed prior to accessing the site’ and another question asked, ‘During the Pre-start brief are the hazards and controls communicated to the workers and captured on the Pre-start brief’. None of the questions specifically asked whether all workers were at the pre-start brief or whether the PO specifically discussed worksite protection at the brief.
Another section was titled ‘Safe Working’ and included 35 items. These items primarily dealt with the technical implementation of different types of protection; none of the items referred to the conduct or content of the pre-start briefing.[42]
One of the questions regarding the pre-start briefing asked if radio channels / other communication was discussed. Another section on mobile plant included questions related to whether amber lights were fitted and operational, and whether the plant had a UHF radio and was it operational.
As part of the ATSB request, QR provided 118 (MD-12-66) forms that were conducted between 2019–2020. The ATSB examined the completed forms in accordance with the form’s instructions. The examination identified noteworthy similarities with each completed form, including:
Of the form’s 199 elements for inspection, they were either marked as compliant (Y) or if the element was not able to be inspected it was marked as not applicable (NA). There were very few cases where non-compliance (N) was recorded on an inspection form.
None of the forms recorded outstanding issues from previous inspections.
There were no recorded non-compliance issues noted with the network pre-start safety briefing component of the form.
There were no recorded issues relating to the separation of people and plant.
There were no recorded issues related to safeworking or worksite protection.
None of the inspections recorded any outstanding issues at the completion of the inspection.
All the inspection forms examined included minimal (if any) commentary or contextual evidence to support the results/findings of the inspections.
There were many cases of forms being completed by the same person with similar entries or phrasing in comments.
Second and third lines of assurance
During the financial years 2017–18, 2018–19 and 2019–20, QR’s integrated assurance plans recorded 3 scheduled second-line assurance activities that related to network pre-start briefings. One scheduled in Q3 of financial year 2017–18, another in Q4 of 2018–19 financial year and the other which took place in Q2 of the 2019–20 financial year.
On request, QR was able to provide a report for one of these 3 scheduled second-line assurance activities – a second-line assurance activity titled ‘Pre-Start Briefing Improvements Review’, which was conducted in September 2019. Its purpose was to determine whether changes made to the network pre-start briefing process (following the May 2017 Petrie accident (see Petrie, Queensland, 2017) had been effectively implemented across the network function and whether the changes met the intent of recommendations arising from QR’s investigation.
The assurance activity involved reviewing worksite activities at 21 locations throughout Queensland. Where the pre-start briefing had already been conducted and work had started, the auditor reviewed the completed briefing form and discussed with workers whether they were aware of the listed hazards and controls. For those worksites where the briefing had not commenced, the auditor discussed with the workers how the briefings were completed using the current version of the form. The audit report did not specifically note that any observations were conducted of briefings, and it also did not note whether all relevant workers (particularly POs) were present at the briefings.
The assurance activity noted that all work groups were using the required form, workers were aware of the risks and controls, and most work groups shared the task of conducting the briefings. Overall, the results of the second-line assurance activity recorded that the control effectiveness score was substantially effective. Some minor areas for improvement were noted. The auditor identified irregularities with documentation in relation to where the network pre-start briefing should be delivered (at the worksite or away from the worksite, such as at a depot) and recorded work groups receiving slightly different information in relation to completing the network pre-start briefing form.
Although not directly related to network pre-start briefings, another second-line assurance activity was undertaken in the second half of 2018 titled ‘Protection Officers’. The objective of the activity was to determine how QR (POs) interpreted safeworking rules in the field, how effective safeworking changes were communicated, and the effectiveness of first-line assurance activities.
According to the auditor, the risk control effectiveness of the assurance activity was rated at substantially effective. The auditor noted that none of the 42 POs interviewed were aware of the requirement to assure the worksite location on the detailed work plan (worksite diagram) matched the actual work location by comparing the plan to a labelled permanent structure and to have this validated by a member of the work group. The ATSB notes that, given this was a common understanding, it appeared to be related to the dissemination of information to POs rather than a compliance problem. The audit report did not provide any information regarding the network pre‑start briefing process.
Evidence provided by QR indicated there were no internal recorded third-line assurance activities directly relevant to changes made to the network pre-start briefing process following the May 2017 Petrie accident.
However, there were a number of compliance inspections undertaken by ONRSR in relation to track worker safety during 2019–20. Although the inspections did not identify any non‑conformance requiring action by QR, there were observations during the inspections that required consideration by the rail operator. Examples of those observations included:
• Queensland Rail staff undertaking the walking patrol were not in possession of a Pre-Start Brief form for the planned work, having left it at the depot at Sunshine. Changes to safety requirements for trackworkers were not able to be re-assessed as a result of changes to track conditions.
• The worksite protection plan completed by the Queensland Rail staff did not indicate safe places for the trackworkers to move to when required to clear the danger zone for rail traffic as required by the Queensland rail network Rules.
Safety analysis
Introduction
At about 0108 on 7 March 2020, a Queensland Rail (QR) suburban passenger train (1898) with passengers on board almost collided with an excavator while it travelled between Thorneside and Birkdale stations. The excavator operator was directed to on-track the excavator on the understanding that the section of track was closed and protected from rail traffic.
The near collision had the potential for serious consequences. In this case, it was very likely that the emergency actions of the train driver and the excavator operator prevented an imminent collision. Had this scenario resulted in a collision, it most certainly would have led to significant adverse consequences for the excavator operator and potentially the derailment of the train.
After the initial near collision, and while attempting to remove the excavator from the danger zone of the rail corridor, a second near collision occurred with another suburban passenger train. Although this occurrence was not as serious, it still had the potential for adverse consequences.
The safety analysis will consider the events and conditions which influenced the near collisions, particularly:
limitations associated with the network pre-start briefing
other limitations with communications at the worksite
the effectiveness of assurance activities related to these matters.
Pre-start briefing processes
All documentation associated with QR network pre-start briefings gained during the investigation stated that all work group members, including protection officers (POs), contractors and others associated with work within the rail corridor, were required to attend a network pre-start briefing. This understanding of the requirements was supported by a subject matter expert who developed and delivered training for QR’s POs and track workers.
In most cases, and as described by QR’s guidelines, a nominated person will deliver the network pre-start briefing with assistance from the PO and others as required. For example, the recipient or the mobile plant spotter should also provide information when required. The pre-start briefing should provide an environment where all work group members can participate and ask questions relevant to the work, including protection arrangements and the roles and responsibilities of individuals. One key aim of the briefing was to ensure everyone working on the site had a correct, shared understanding of the worksite protection arrangements that would be used and the limits of that protection.
On 6 March, the lead PO was advised to meet the depot supervisor at the Cannon Hill depot at 2200 to discuss protection arrangements for the planned work at Thorneside. By the time the PO arrived at the depot, the team leader had completed the network pre-start briefing, and shortly after the work group departed the depot for the worksite. Neither the lead PO or the assistant PO attended the briefing or provided any input to the briefing regarding worksite protection arrangements for the planned closure or the preparation work (for which the protection arrangements had not yet been assessed, planned, and confirmed). Most of the workers present at the briefing signed the network pre-start briefing form, even though they had not received a briefing from the PO. The supervisor did not sign the briefing form until after the near collisions.
The excavator operator was also not invited to the network pre-start briefing at the Cannon Hill depot. Instead, the arrangement was for a QR representative to meet the excavator operator at Thorneside Station at 2230, prior to the commencement of work. On arrival at the worksite, the excavator operator correctly requested a worksite briefing. The team leader explained the work requirements pertaining to the excavator. However, they were not provided with a network pre‑start briefing or any briefing from the PO explaining the protection arrangements relevant to the worksite, even though they were requested to sign the network pre-start briefing form.
Other than the network pre-start briefing delivered at the Cannon Hill depot, neither the supervisor nor the team leader, who was working under the guidance of the supervisor, provided an opportunity for the PO to deliver information about the worksite protection requirements to the work group for the planned work activities.
It was suggested by the recipient at interview that the PO delivered their component of a network pre-start briefing immediately prior to the work group entering the rail corridor at Thorneside. This however was not a formal network pre-start briefing, but a mandatory requirement of the Queensland Network Rules and Procedures (QNRP) before work could commence in the rail corridor. At the time the PO delivered the brief to access the rail corridor, the excavator operator and the supervisor of the work group were not present as they had not yet arrived at the worksite. There was no discussion of the work activities and protection arrangements for the planned closure.
It is understandable that in some situations, where maintenance work extends over several days, not all workers will be able to attend the same network pre-start briefing. Under those conditions multiple network pre-start briefings should be delivered to ensure that all workers are provided with safety information relevant to their working environment. However, the maintenance work at Thorneside was scheduled over one shift. Therefore, all members of the work group, including the POs and the excavator operator, should have attended the same pre-start briefing to enable them to develop a shared understanding of the worksite protection arrangements that would be in place for both the preparation work and the planned closure.
In this case, given the excavator operator was not present at the network pre-start briefing, the team leader (and supervisor) needed to ensure that the operator was provided with a full network pre-start briefing when they arrived at the worksite (or at least prior to the team leader directing them to an alternate entrance gate away from the worksite). This should have included briefings and involvement from relevant personnel such as the PO and the recipient / mobile plant spotter.
As well as the actual briefing, there were limitations with the level of detail included in the network pre-start briefing form about the type of machinery that would be used. The protection arrangements listed were also general in nature, and not clearly specified for both the preparation work and the planned closure. Given that the POs did not see the form prior to the near collisions, and the excavator operator was not involved in the preparation work, limitations within the form did not contribute to the near collisions.
In summary, there were a significant number of problems associated with the application of the network pre-start briefing process prior to work commencing at the Thorneside worksite. Of most importance, the POs and the excavator operator were not included in a network pre-start briefing, which denied them and the work group of essential safety information applicable to their roles and responsibilities. This limitation significantly increased risk and contributed to the initial near collision.
Other communication processes
Introduction
When working in a rail environment such as a worksite, communication for the purpose of developing a shared understanding is vitally important. The network pre-start briefing is an essential part of ensuring subsequent communications are based on a shared understanding and are effective.
In this case, there were a number of communication problems that occurred following the network pre-start briefing, many of which can be attributed in part to the absence of a thorough network pre-start briefing involving all of the personnel working at the site.
Protection officer awareness of the excavator
While at the worksite, the supervisor received a call from the excavator operator regarding the location of the worksite. The supervisor directed the operator to travel to the worksite and meet workers at the work group entrance gate. This information was passed on to others in the work group, including the recipient and the team leader, for future planning consideration. However, it was not communicated to the lead PO. The PO was not cognisant of the working arrangements involving the excavator and they were unaware an excavator had arrived at the site.
The need for that information became safety critical when the network control officer (NCO) contacted the PO regarding a track fault, which was very likely caused by the excavator when it was being on-tracked. When the NCO asked the PO if there was any equipment on-track, the PO had an incomplete mental model of the work group and advised the NCO that there was no equipment on-track.
Had the PO known that the excavator had arrived on site, it is likely they would have associated the track fault with the on-tracking of the excavator and communicated this information to the NCO. Given that the track fault occurred about 105 seconds prior to the first near collision, it is likely that such communications would have prevented the first near collision (or at least significantly reduced the risk associated with any such near collision).
Direction to on-track the excavator
The recipient directed the excavator operator to on-track the excavator before the planned track closure. This action appeared to result from a combination of situational factors. Firstly, the recipient misinterpreted the team leader’s instruction of ‘it’s on’ as meaning the planned closure was active, whereas the team leader was referring to the reinstatement of the protection for the preparation work, and that the work tools could be loaded into the bucket of the front-end loader. The recipient’s misinterpretation was reinforced by the work group loading the front-end loader with tools for the planned closure and then receiving the height limiter key from the operator of the front-end loader.
Although the chain of events had the potential to be misinterpreted by the recipient, there should have still been some level of doubt that the planned closure was in force. The time of the team leader’s instruction (0051) was well prior to the scheduled start time of the planned closure (at 0218), and there had been no discussion of changing the start time of the planned closure (and scheduled trains were still operating). In addition, the PO had not authorised the on-tracking of the excavator and the team leader (or supervisor) had not explicitly informed the recipient to direct the excavator operator to on-track at that time.
For any questions relevant to protection arrangements, the communication pathway should be through the PO. If a member of the work group required clarification on information or instructions, then they should gain this clarification from the person in charge at the worksite. In a work group there should be clearly defined communication protocols, and these protocols should be highlighted at every network pre-start briefing.
The recipient had been formally trained in network communication and should have been aware that, before acting upon a communication regarding access to the rail corridor and danger zone that is not explicit, further clarification is necessary. However, in this case the recipient acted on an assumption rather than clarifying the instruction and gaining the necessary authority from the PO and the person responsible at the worksite before they directed the operator to on-track the excavator.
It is conceivable that the recipient undertook the action with the view that it would help facilitate the work and provide more confidence that subsequent tasks would be completed within the planned closure period. However, there was no indication that the recipient was intentionally deviating from procedures when they directed the excavator operator to on-track. Rather they appeared to simply misunderstand the situation.
The work group member acting as the recipient was new to the role, having only received their qualification 2 days before. Therefore, consideration to provide supervision over the actions and performance of the recipient (also acting as the mobile plant spotter) should have been a priority for the supervisor and the team leader. However, there appeared to be limited supervision or support provided.
In summary, without gaining the necessary authority, the recipient directed the operator of the excavator to on-track under the incorrect assumption the planned closure was active, and the worksite was protected by a TOA with in-field protection and train activity on the rail corridor had ceased. However, there was no protection in place and the rail corridor was open for normal train traffic.
Use of standardised railway terminology
It is important that standardised industry-specific terminology is used when communicating safety‑critical information. When using general terms, it is possible for individuals to misinterpret the intent of a communication. In a work environment such terms can lead to a situation where something important can be taken out of context, which may lead to serious consequences. In the case of this investigation, there were 2 instances where workers used generic language to communicate safety-critical information that was misinterpreted and lead to serious consequences.
Firstly, the team leader communicated the generic term ‘it’s on’ to the work group to signify the TOA without in-field protection (or an ‘unprotected TOA’) had been reinstated and tools and equipment could be transferred from the work truck into the front-end loader. This term was misunderstood by the recipient and interpreted as the planned closure was now in force, prompting the recipient to direct the excavator operator to on-track the excavator.
A contributor to the second near collision was the conversation between the lead PO and the emergency hotline contact (located at the network control centre) by not incorporating standardised industry-specific terminology during their conversation. While gaining information relevant to the first near collision, the emergency hotline contact asked the PO had the excavator been moved away from ‘the track’, rather than using the rail-specific term ‘danger zone’.
The lead PO then gained confirmation from the supervisor (and indirectly from the recipient at the incident site) who verified the excavator was away from the track. On gaining this information, the emergency hotline contact advised the PO to leave the excavator where it was for investigation purposes. The emergency hotline contact then informed the NCO that the excavator was away from the track. Based on this information, the NCO believed that the excavator was clear of the danger zone and therefore allowed rail traffic to proceed past the incident site without imposing restrictions. However, the excavator was still in the danger zone and close to the running line, which meant it was a risk to operations. Had the conversations between the PO, emergency hotline contact and other parties identified the excavator was in the danger zone, it is highly likely that this information would have been forwarded to the NCO and the second near collision would have been avoided.
Guidelines for the use of standardised railway terminology
The Rail Industry Safety and Standards Board’s (RISSB’s) Safety critical communications guideline (2018) stated that one way to mitigate the risk of misunderstanding in communication was to avoid the use of acronyms and words with alternative meanings. Instead, the guideline advised the use of industry-specific terminology that cannot be misinterpreted. Although QR’s QNRP provided relevant information on spoken communication and the use of standard terms, such as the phonetic alphabet, when communicating information, there was no formal guidance for rail safety workers to incorporate standardised rail-specific terminology when communicating safety-critical information. Including this guidance, and reinforcing its use during safety-critical communications, would reduce the risk of these types of miscommunications, particularly during an emergency response.
Direction to remove the excavator from the danger zone
Following the first near collision, the supervisor travelled to the incident site to assess the situation, after being advised that the excavator was off the track but may still be in the danger zone. After arriving at the site, they confirmed that it was still in the danger zone, and they instructed the excavator operator to move the excavator further away from the tracks.
In interview the supervisor advised that they had assumed that rail traffic would have been suspended following the first near collision, but they had not confirmed that this was the case with the NCO. It is understandable that a natural reaction to such a situation would be to immediately remove a potential collision hazard. However, by instructing the excavator operator to enter the danger zone and move the excavator without first gaining permission from the NCO and confirming that rail traffic had been suspended, the supervisor was placing the excavator operator and others nearby (and potentially those on the train) at unnecessary risk.
After the second near collision, again the supervisor exposed the excavator operator to danger by directing them to remove the excavator from the danger zone without gaining the necessary protection from the NCO.
Assurance activities
Additional task performance aspects
At present in most rail networks in Australia, work on track fundamentally relies on administrative controls (rules and procedures), with there being limited use of technology to reduce the risk of workers being struck by rail traffic. However, human performance is inherently fallible. Accordingly, working within the rail corridor requires significant planning, communication and worker adherence to rules and procedures in order to provide a safe work environment.
As already outlined in previous sections of this analysis, there were limitations associated with the network pre-start brief that increased safety risk. There were also limitations with a number of subsequent communications that increased risk, as discussed in the previous section. In addition, the investigation identified a number of other actions at the worksite that increased risk, many of which were explicitly or implicitly inconsistent with the rail operator’s rules and procedures. These actions included:
The supervisor did not attend the briefing delivered by the lead PO at the worksite regarding the TOA without in-field protection prior to the preparation work and they then commenced work tasks in the rail corridor.
The supervisor provided limited supervision of the team leader and the recipient at the worksite, who were both new to their roles.
There was no designated ‘lookout’ in place for the preparation work, which was conducted with a TOA without in-field protection with less than the required sighting distance.
The recipient did not gain permission from the PO before directing the excavator to on-track the excavator.
The recipient did not advise the excavator operator of the radio channel to use at the worksite (although this was listed on the network pre-start briefing form).
The recipient did not have a radio and did not maintain full visibility and communication (radio contact) with the excavator operator.
After the first near collision there was no ‘pause and re-start’ in accordance with the network pre-start briefing form.
The supervisor directed the PO, who oversaw protection within the rail corridor, to return to the Cannon Hill depot while machinery and workers were still in the rail corridor without the required protection.
Although the team leader (acting as the person in charge of work) and the recipient were acting in roles for which they were inexperienced, they and the supervisor of the work group were experienced in track work safety. All 3 rail safety workers had been formally trained to act as a PO, deliver a network pre-start briefing, conduct communications (as per the QNRP), conduct lookout duties and rail safety awareness. Their training and experience should have provided them with the necessary competence and skills to work safely in the environment of the rail corridor.
The investigation did not identify any environmental conditions that necessitated the undertaking of deviations from procedures. The absence of one worker due to sickness resulted in the work group undertaking preparatory work prior to the planned closure to manage this contingency. However, there appeared to be no indication that there would be insufficient time to undertake the preparatory work and the preparatory work was completed well before the planned closure period.
The arrival of workers at different times and the need to use multiple access gates for different machinery complicated the situation for the work group. However, this situation should have indicated a need for more thorough briefings and communications as these problems developed. Although the activities were occurring overnight, the available evidence did not indicate that any of the involved work group was experiencing adverse levels of fatigue.
Given the number and variety of individual actions that increased risk associated with the near collisions, and no obvious explanation for this overall pattern of actions, the investigation considered the assurance processes the operator had in place to detect work practices being inconsistent with rules and procedures.
Assurance activities related to network pre-start safety briefings
It is essential that information gained from first-line assurance activities genuinely reflects what is actually happening when frontline workers are performing tasks in the rail corridor. Accurate data capture is critical in first-line assurance, as second and third-line assurance are linked and leverage off the results. If the information is not accurate, then the integrity of the 3 lines of defence assurance model will be flawed, which will likely have a significant impact on future safety.
As already outlined, the network pre-start safety briefing is an essential and safety-critical component of minimising safety risk while conducting work on track. Findings from investigations have shown that ineffective network pre-start briefings have either directly or indirectly contributed to the death of workers as a consequence of being struck by rail traffic, and this was also a key problem in the near collisions at Thorneside. Accordingly, the ATSB focussed its assessment on the application and results gained from assurance activities, relevant to pre-start briefings, to determine the effectiveness of the 3 lines of defence assurance model in identifying and managing risk.
The ATSB reviewed first-line assurance inspection forms that were completed between 2019–2020, which included (among other things) the inspection of compliance with network pre‑start briefings, worksite protection and safe work activities. These consisted of 495 worksite protection compliance assessment forms and 118 maintenance inspection records. Almost every form examined by the ATSB identified near full compliance with all aspects of the required processes with very few safety-related matters identified. This data could be interpreted as providing assurance to the organisation that workplace activities were routinely being conducted effectively. However, the results of this investigation and at least some other incidents indicate that workplace activities were not always effective.
The extent to which the first-line assurance activities provided a reliable assessment of the network pre-start briefings appeared to be limited due to multiple factors:
There was no explicit guidance associated with the worksite protection compliance assessment form that explained what aspects of the briefing were to be evaluated. More specifically, the extent which all relevant workers (including POs) were at the briefing and participated in the briefing was not explicitly requested or recorded.
The maintenance inspection form covered a wide range of topics and was detailed, consisting of 199 items. However, although some of these items referred to the network pre-start briefing, none of the questions asked if all relevant workers (including the PO) were at the briefing and participated in the briefing. It is acknowledged that not every specific aspect can be covered in such assessments, and increasing the length of such assessments will not always lead to more useful, accurate data.
The maintenance inspection forms were completed by a supervisor or team leader on their own work section (which is an inherent part of many first-line assurance activities). However, as noted in the UK Rail Accident Investigation Branch report into the Margam accident, such a process can be associated with a range of factors that may limit the objectivity, completeness, or accuracy of such assessments.
Accordingly, appropriate use of independent (or second-line / third-line) assessments is needed to provide confidence in the validity and reliability of first-line assessments. Evidence provided by QR showed that there had been limited second-line and no third-line assurance activities directed at network pre-start briefings, possibly due to the near faultless results of first-line assurance activities. One second-line assurance activity conducted after the May 2017 fatal accident at Petrie focussed on network pre-start briefings and involved interviewing workers associated with 21 tasks about a briefing or the briefing process. Given the identified criticality of effective pre-start briefings following the Petrie accident, this was a relatively small sample. The assessments also appeared to focus on the extent to which workers advised whether the briefings provided information about hazards and controls, which is obviously important. However, the extent to which all relevant personnel (including POs) attended briefings and actively participated in briefings was not documented.
The available evidence does not indicate that there was widespread non-compliance with network pre-start briefing procedures or related communication processes, and the ATSB has not concluded that widespread non-compliance was occurring. However, the assurance activities that were conducted did not provide sufficient assurance regarding the extent to which network pre‑start briefings were being conducted effectively. In other words, based on the nature of the assessments conducted, the extent to which the problems that occurred at Thorneside on 6–7 March 2020 had occurred at other locations or at other times could not be reliably evaluated.
In summary, QR’s 3 lines of defence assurance model is well equipped to manage safety. Nevertheless, if the process is not administered as intended and in line with risk management principles then track worker safety may be at risk. Network pre-start briefings are a critical control to manage the risk of collisions between rail traffic and workers. However, the design of the first‑line assurance activities and the limited conduct of second and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively.
It is understood that assurance processes, regardless of how well or how often they are conducted, will not prevent all instances of procedures not being conducted as expected. In this case, given some of the situational factors involved, the extent to which improvements in the assurance processes would have prevented the near collisions at Thorneside was difficult to evaluate.
The ATSB notes that, following the Thorneside incident, QR has undertaken a significant program of work to improve track worker safety. Further details are provided in the Safety issues and actions section of the report.
Accident prevented
On recognising the imminent risk of collision, both the train driver and the excavator operator took immediate action which prevented the serious incident becoming an accident. The train driver applied the emergency brake on the train while the excavator operator used the excavator’s boom arm and bucket to drag it from the rail tracks as the train passed at about 61 km/h.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the near collision incidents involving an excavator and passenger trains 1898 and 18A0 near Thorneside, Queensland, on 7 March 2020.
Contributing factors
The lead protection officer (PO), assistant PO and the excavator operator were not included in a network pre-start briefing, which denied them and the work group of essential safety information applicable to their roles and responsibilities.
The lead protection officer (PO) was not informed of or aware that an excavator had arrived at the worksite. Consequently, when the network control officer (NCO) notified the PO of a track fault indication (associated with the on-tracking of the excavator) and asked if there was any equipment on-track, the PO had an incomplete mental model of the work group and advised the NCO that there was no equipment on-track.
Without gaining the necessary authority, the recipient directed the operator of the excavator to on-track under the incorrect assumption the worksite was protected by a track occupancy authority (TOA) with in-field protection and train activity on the rail corridor had ceased. However, there was no protection in place and the rail corridor was open for normal train traffic.
Following the first near collision, communications between the protection officer (PO), the emergency hotline contact and other parties about the location of the excavator did not clarify that, although the excavator was off the track, it was still in the danger zone.
The Queensland Network Rules and Procedures did not provide sufficient guidance for rail safety workers to ensure they used standardised rail-specific terminology when communicating safety-critical information. [Safety issue]
After the first near collision, the supervisor directed the excavator operator to remove the excavator from the danger zone without gaining the necessary authority from the network control officer or confirming that rail traffic had been stopped. This omission contributed to the second near collision between another suburban train and the excavator.
Other factors that increased risk
Network pre-start briefings are a critical control in place to manage the risk of collisions between rail traffic and workers and machinery, and Queensland Rail had undertaken significant work to improve these processes. However, the design of the first-line assurance activities and the limited conduct of second-line and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively. [Safety issue]
Other findings
After detecting that the train and the excavator were on a collision course, the driver of train 1898 and the operator of the excavator both promptly undertook all available actions to reduce the collision risk.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The Queensland Network Rules and Procedures did not provide sufficient guidance for rail safety workers to ensure they used standardised rail-specific terminology when communicating safety-critical information.
Assurance activities related to network pre-start safety briefings
Safety issue description: Network pre-start briefings are a critical control in place to manage the risk of collisions between rail traffic and workers and machinery, and Queensland Rail had undertaken significant work to improve these processes. However, the design of the first-line assurance activities and the limited conduct of second-line and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Queensland Rail
Critical safety alert
Soon after the incident, on 10 March 2020, Queensland Rail issued a critical safety alert (CSA) directed to protection officers (POs) and their supervisors and managers, and all infrastructure workers and their supervisors and managers. The alert provided a brief overview of the incident and stated the following actions to be taken:
All workers must receive a prestart briefing prior to entering the Rail Corridor. The prestart briefing must include:
• the workgroup supervisor giving a briefing on the type of works that will take place and the risks and hazards associated with the worksite; and
• the Protection Officer giving the rail safety component of the briefing e.g. limits and types of track protection that will be used.
Workers may only enter the Danger Zone once they have been given permission from their workgroup supervisor.
Workgroup supervisors may only allow workers to enter the Danger Zone once they have confirmation from the Protection Officer that the required protection is in place.
If an incident occurs in the Danger Zone, workers must immediately notify their supervisor who must notify the Protection Officer. Where workers cannot contact their supervisor, they are to ensure the Protection Officer is advised. The Network Control Officer must also be notified.
Where necessary, the Protection Officer must arrange to have all rail traffic stopped.
Following an incident, the workgroup supervisors must confirm with the Protection Officer that adequate protection is in place prior to any workers re-entering the Danger Zone.
Subsequent improvement activities
Following the incident, Queensland Rail (QR) offered an enforceable voluntary undertaking (EVU) to the Office of the National Rail Safety Regulator in September 2021, with clarifications made in October 2021. This EVU summarised the following additional actions undertaken by QR:
• On 10 March 2020, the Executive General Manager SEQ Assets held a Safety Pause for applicable SEQ Assets employees to raise awareness of the incident and help focus employee mindsets on safe behaviours.
• On 12 March 2020, the Head of SEQ facilitated a Management Safety Workshop with key managers and supervisors to review details of several recent incidents (including reviewing interim findings of this Incident) to determine actions to help prevent future recurrence of similar incidents.
• On 30 April 2020, Queensland Rail commenced reporting on implemented lead indicators for key controls regarding trackside safety to the Executive Safety Committee on a monthly basis.
• On 18 May 2020, the Senior Manager SEQ Signalling & Telecommunications issued a CSA mandating that planned work in the Danger Zone must be advertised on Train Notice within SEQ Network Assets.
• On 18 May 2020, the Senior Manager Rail Safety and Accreditation clarified terminology to be used when communicating safety critical information when working in the Network within all Protection Officer training and the revised pre-start briefing training.
• On 1 June 2020, the Senior Manager SEQ Signalling & Telecommunications implemented a process for ensuring plans for work in the Danger Zone within SEQ are endorsed and approved including an escalation process for approving a change to an approved plan.
• On 14 July 2020 Queensland Rail updated its safety management system, including its pre-start briefing training to better outline the role of employees prior to entering the Rail Corridor. Part of these updates included further explaining the purpose of pre-start briefings, what makes a good pre-start and the importance of asking questions and developing good site sketches.
• On 29 July 2020, the Senior Manager Assurance & Capability implemented first-line and second-line assurance regimes for compliance with safety procedures and processes for working in the corridor throughout the SEQ network.
Subsequent proposed initiatives
Under the EVU, QR outlined 13 initiatives to improving planning processes for track access, the safeworking control framework, capability of safety-critical workers and effectiveness of safety assurance and performance. The EVU outlined safety initiative leads and accountabilities and a proposed schedule for implementation. The initiatives included the following:
improve planning and communication between track workers and network control officers (NCOs) in south-east Queensland
implement a track access system (a common interface between NCOs and POs)
conduct further work to review the Queensland Network Rules and Procedures (QNRP) and deliver refresher workshops
enhance network lookout processes (to reduce the likelihood of unintentional release of track protection while workers are still in the danger zone)
cease using lookout working[43] within south-east Queensland
review lookout working in regional areas
improve trackside pre-start briefings
introduce a non-technical skills program for POs
introduce a non-technical skills program for trackside worker supervisors
use external and internal incidents to review QR processes for any deficiencies
develop an approved tool for conducting first-line assurance of POs (and compliance with procedures for working in the rail corridor) and an associated assurance plan
develop an assurance tool for assessing communications between NCOs and POs and implement the assurance process.
QR advised the ATSB that, as of 1 November 2023, 12 of the 13 initiatives had been externally verified as closed and the final initiative was on track for completion by 31 December 2023.
Additional safety action by other parties
In January 2023, the Office of the National Rail Safety Regulator (ONRSR) and the Rail Industry Safety and Standards Board (RISSB) released the results of a global investigation into how world standard technology can protect track workers in the Australian rail industry. The introduction section of the Track Worker Safety Options Report stated:
This research project has been undertaken to establish a shared understanding of TWS [track worker safety] options and their use in the rail sector. The purpose of the project is to identify primarily current, and some emerging, TWS options for improving the safety of workers on Australian rail networks. It is anticipated that understanding the options available as well as their context for use in providing TWS will enable the rail sector to invest in these solutions and implement them successfully.
This report captures many aspects of this project, including a summary of the literature review, highlights from the survey findings, a snapshot of the stakeholder engagement workshop and an options table….
The options in the table were grouped in the following types:
vehicle installed devices that give warnings to train crew
worksite installed devices the give warnings to track workers
sensors and devices that give targeted alerts to both vehicle crew and track workers
infrastructure systems, methods and devices that remove the need for workers on tracks to undertake work
infrastructure systems and devices that automatically prevent vehicles from entering a worksite.
The sources of information during the investigation included:
relevant staff from Queensland Rail
the lead protection officer
the excavator operator
event recorder evidence from trains 1898 and 18A0
CCTV footage from the front-of-train camera of train 1898
universal traffic control replay system
Queensland Rail.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Queensland Rail
the depot supervisor
the work group team leader
the recipient
excavator operator
the Officer of the National Rail Safety Regulator (ONRSR).
Submissions were received from Queensland Rail and ONRSR. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Danger zone: all space within 3 m horizontally from the nearest rail and any distance above or below this 3 m, unless a safe place exists or can be created.
[2] Recipient: an authorised person who has the competence and responsibility to supervise the electrical safety aspects of the work and has been appointed in that function for a specific worksite in electrified areas.
[3] Protection officer: the competent worker responsible for managing the rail safety component of worksite protection.
[4] Planned closure: a pre-planned work arrangement on a railway which may exclude rail traffic from the rail corridor.
[5] Track occupancy authority (TOA): an authority for competent workers and their equipment to occupy a defined portion of track for a specified period.
[6] Network pre-start briefing: a communication and on-site activity planning session undertaken prior to the commencement of work or an activity. It should involve all workers, contractors and / or visitors involved, or exposed to, the work to be undertaken.
[7] Under this arrangement, signals are restored to STOP in the field by the NCO, restricting trains from entering the signalled section where work is being performed, and a lookout [competent person] positioned near the workers is used as a secondary safety measure. Work being performed cannot break or obstruct the track.
[8] Train notice: a notice issued by a rail infrastructure manager that contains safeworking and other relevant information for workers.
[9] Train diagram: a diagram that tracks the scheduled movement of trains, which is used by NCOs.
[11] The assistant PO was not required for the preparation work.
[12] A height limiter allows an operator to define the pre-set limit of machinery boom height.
[13] Electrical control officer: the worker who controls the power supply to the overhead line equipment and is responsible for all switching operations and isolations of electrical equipment.
[14] Suspend code: a code number communicated by the PO to the NCO.
[15] The NCO enters the suspend code into the system to enable the NCO to route train movements through the previous closed section.
[16] The failed track indication was most likely caused by the excavator’s bucket or boom arm contacting the rail(s) and short circuiting the track section as it on-tracked.
[17] Given the distance from the work group entrance gate and the noise of the excavator, it is extremely unlikely that the excavator operator could have heard the car horn at that time.
[18] The drug and alcohol tests of the involved workers produced a negative result (that is, no drugs or alcohol detected).
[19] In-field protection: 1 or more devices approved by access providers that provide warning to protect rail traffic crew and workers. Such devices include stop signs and railway track signals (that is, detonators placed on the track that explode on impact to attract the attention of rail safety workers). These devices may be used in conjunction with signalling or blocking facilities.
[20] Work on track authority: an authority to perform work on track (either a local possession authority, track occupancy authority or track work authority.
[21] Obstructing: any defect in the track or track formation or obstacle on or adjacent to the permanent way which will prevent the safe passage of trains.
[22] Lookout: a competent worker responsible for keeping watch for approaching rail traffic and for warning other workers to stand clear of the line before the rail traffic arrived.
[23] Means of protection: a method used to exclude rail traffic from a portion of track.
[24] Safety measure: a measure used to provide protection for workers when working or walking in the danger zone.
[25] Mobile plant spotter: a person responsible for the separation of plant and people at a worksite.
[26] Nominated person: a competent person trained and qualified to deliver a network pre-start briefing.
[27] Foul: in a position to obstruct rail traffic.
[28] Obstruction: any defect in the track or track formation or obstacle on or adjacent to the permanent way which will prevent the safe passage of trains.
[29] Safe place: a place where workers and equipment cannot be struck by rail traffic.
[30] Access: a designated safe way into, along, across or out of a rail corridor.
[31] Any defect in the track or track formation, or obstacle on, above or adjacent to the track which will prevent the safe passage of trains.
[32] R3: track/road vehicles that do not reliably operate track circuits and axle counters.
[33] ATSB rail occurrence investigation RO-2010-004, Collision between an XPT passenger train and a track-mounted excavator, near Maitland NSW, 5 May 2010
[34] ATSB rail occurrence investigation RO-2011-016, Collision between freight train 7SP3 and a track mounted excavator near Jaurdi, Western Australia, 28 March 2011
[35] ATSB rail occurrence investigation RO-2015-009, Track worker struck by train near Laverton station, Victoria on 2 October 2015
[36] ATSB rail occurrence investigation RO-2016-008, Track worker fatally injured when struck by train W510, Clyde, New South Wales, on 18 June 2016
[37] ATSB rail occurrence investigation RO-2017-003, Running line collision with worker involving passenger train T570, Petrie, Queensland on 29 May 2017
[38] RAIB Rail accident report 11/2020, Track workers struck by a train at Margam, Neath Port Talbot, 3 July 2019
[40] Integrated assurance plan: an assurance plan that puts together into an integrated whole all assurance activities of second and third-line assurance providers for a financial year.
[41] Sections: 2, 3 and 8 of the network pre-start briefing procedure referred to the delivery of the briefing, participation in the briefing and the debrief (following work).
[42] One item asked whether a specific type of qualified driver had been nominated in the briefing for an on-track vehicle authority.
[43] Lookout working: a safety measure used by competent workers to carry out work on track without a formally issued work on track authority. It involves positioning workers as lookouts to warn other workers of approaching rail vehicles.
On 11 March 2020, a Cessna 404 aircraft, registered VH-OZO, was being operated by Air Connect Australia to conduct a passenger charter flight from Cairns to Lockhart River, Queensland. On board were the pilot and 4 passengers, and the flight was being conducted under the instrument flight rules (IFR).
Consistent with the forecast, there were areas of cloud and rain that significantly reduced visibility at Lockhart River Airport. On descent, the pilot obtained the latest weather information from the airport’s automated weather information system (AWIS) and soon after commenced an area navigation (RNAV) global satellite system (GNSS) instrument approach to runway 30.
The pilot conducted the first approach consistent with the recommended (3°) constant descent profile, and the aircraft kept descending through the minimum descent altitude (MDA) of 730 ft and passed the missed approach point (MAPt). At about 400 ft, the pilot commenced a missed approach.
After conducting the missed approach, the pilot immediately commenced a second RNAV GNSS approach to runway 30.
During this approach, the pilot commenced descent from 3,500 ft about 2.7 NM prior to the intermediate fix (or 12.7 NM prior to the MAPt). The descent was flown at about a normal 3° flight path, although about 1,000 ft below the recommended descent profile. While continuing on this descent profile, the aircraft descended below the MDA. It then kept descending until it collided with terrain 6.4 km (3.5 NM) short of the runway. The pilot and 4 passengers were fatally injured, and the aircraft was destroyed.
What the ATSB found
The weather conditions when the aircraft reached the MAPt for the first approach could not be determined. It is possible that the conditions were better than the landing minima at that point but then deteriorated as the approach continued and when the aircraft was at a lower altitude.
The indicated airspeed during the latter part of the first approach was about 140 kt, which significantly exceeded the operator’s preferred speed after the final approach fix (FAF) (about 110 kt) and the operator’s stabilised approach criteria speed (about 110 kt at 300 ft above aerodrome elevation). Whether the pilot made the decision to conduct the missed approach based on the weather conditions, airspeed, descent rate or some combination of those factors could not be determined.
The aircraft probably entered areas of significantly reduced visibility during the second approach. In particular, there was a period of heavy rainfall at the airport after the first approach, and it is likely the aircraft entered the rain during the second approach.
There was no evidence of any conditions or circumstances likely to induce a medical problem or incapacitation for the pilot and the aircraft appeared to be in controlled flight up until the time of the impact. There was also no evidence of any aircraft system or mechanical anomalies that would have influenced the accident. Therefore, based on the available evidence, the accident was very likely the result of controlled flight into terrain (CFIT).
The most likely scenario to explain the descent 1,000 ft below the recommended descent profile on the second approach could not be determined. Regardless of the exact scenario, it is evident from the continued descent that the pilot did not effectively monitor the aircraft’s altitude and descent rate for an extended period.
In addition, when passing the FAF (5 NM prior to the MAPt), the aircraft significantly exceeded the operator’s required (lateral) navigational tolerance for the instrument approach for an extended period. This should have resulted in a second missed approach but, although the pilot was correcting the lateral deviation, a missed approach was not conducted. The aircraft’s speed after the FAF also increased to 140 kt, before increasing to 150 kt towards the end of the flight.
The ATSB found that the pilot was probably experiencing a very high workload during periods of the second approach. In addition to the normal high workload associated with a single pilot hand flying an approach in instrument meteorological conditions (IMC), the pilot’s workload was elevated due to conducting an immediate entry into the second approach, conducting the approach in a different manner to their normal method, the need to correct lateral tracking deviations throughout the approach, and higher than appropriate speeds in the final approach segment.
The pilot had the required qualifications and had been regularly logging RNAV GNSS approaches, although these approaches were almost all conducted in visual meteorological conditions. However, their workload was potentially further exacerbated by having limited recent experience in conducting RNAV GNSS approaches in IMC.
The aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required. In addition, there was no evidence to indicate any organisational or commercial pressures on the pilot to complete the flight, but the extent to which self-imposed pressures or incomplete knowledge of procedural requirements influenced the pilot’s performance could not be reliably determined.
The aircraft was not fitted with a terrain avoidance and warning system (TAWS). Given the aircraft’s descent profile on the second approach, if a TAWS had been fitted and been operational, it would have provided the pilot with both visual and aural alerts of the approaching terrain for an extended period.
There was no requirement in Australia for piston-engine aeroplanes (such as VH-OZO) to be fitted with a TAWS. Although the Civil Aviation Safety Authority (CASA) had been considering changes to TAWS requirements since 2008, the Australian requirements at the time of the accident for some types of small aeroplanes being used for air transport operations were less than those of comparable countries and they were not consistent with International Civil Aviation Organization (ICAO) standards or recommended practices.
More specifically, although there was a TAWS requirement in Australia for turbine-engine aeroplanes carrying 10 or more passengers under the IFR, there was no requirement for piston-engine aeroplanes authorised to carry 10 or more passengers (an ICAO standard adopted as a requirement by many comparable countries) and no requirement for turbine-engine aeroplanes authorised to carry 6 to 9 passengers (an ICAO recommended practice adopted as a requirement by many comparable countries). However, even if these changes had been introduced in Australia prior to the accident, it is unlikely they would have resulted in an aeroplane such as VH-OZO being fitted with a TAWS.
The aircraft was fitted with 2 Garmin GNS 430W GPS units that provided navigation and radio communication capability. As part of the unit’s navigation capability, there was also a terrain awareness function capable of providing visual pop-up terrain alerts. However, that functionality was not to the same standard required for a TAWS installation. It could not be determined whether this function was selected on by the pilot during the accident flight.
Although the GNS 430W unit was suitable for an RNAV GNSS approach and other non-precision instrument approaches, it did not provide vertical guidance information, which would have explicitly indicated that the aircraft was well below the recommended descent profile.
CFIT accidents have been a significant problem over many years, although the rate of such accidents has been decreasing. However, risk factors still remain, particularly for smaller operators. Ideally, in order to minimise the risk of CFIT, operators conducting passenger transport operations under the IFR would use aircraft fitted with a TAWS and/or have a GPS/navigational system that provides vertical guidance during non-precision instrument approaches.
Nevertheless, even without these systems, there are other means available for such operators to minimise CFIT risk. In this case, the operator had specified a flight profile for straight-in instrument approaches and stabilised approach criteria in its operations manual, and encouraged the use of stabilised approaches, but there were limitations with the design of these procedures.
In particular, the operator’s stabilised approach criteria specified an applicable height of 300 ft above aerodrome elevation for operations in IMC. A similar problem has also been identified in multiple other operators conducting passenger transport operations under the IFR. Although an applicable height of 1,000 ft in IMC has been widely recommended by ICAO and many other organisations for over 20 years, CASA had not provided formal guidance information to operators in Australia regarding the content of stabilised approach criteria.
There were also limitations with the operator’s other risk controls for minimising the risk of CFIT, including no procedures or guidance for the use of the terrain awareness function on the aircraft’s GNS 430W units, and limited monitoring of the conduct of line operations.
What has been done as a result
On 2 December 2021, Civil Aviation Safety Regulation (CASR) Part 121 (Australian air transport operations – larger aeroplanes) and CASR Part 135 (Australian air transport operations – smaller aeroplanes) commenced. Associated with these regulations, piston-engine aircraft being used for air transport with a maximum operational passenger seat configuration (MOPSC) of 10 or more were required to have a TAWS and operate under Part 121, with the applicable dates dependent on the MOPSC and other factors.
In December 2021, CASA also published guidance material for CASR Part 121 and Part 135. This included guidance information about stabilised approach criteria, including advice regarding applicable heights for stabilised approach criteria in IMC, including an example height of 1,000 ft above aerodrome elevation in IMC.
Associated with the introduction of CASR Part 135 in December 2021, air transport operators of smaller aeroplanes were required to conduct a flight crew member proficiency check at intervals of 6 months (for IFR or night VFR operations) or 12 months (for day VFR operations).
Safety message
All operators conducting air transport operations under the IFR should evaluate the risk of CFIT in their operations. In addition, any such operators that do not currently have a TAWS fitted to their aircraft should recognise the substantial benefits of a TAWS, and be actively seeking to install a TAWS to maximise the safety of their operations.
In addition, there are many other lessons for operators of small aircraft to reduce their CFIT risk. These include:
If a TAWS is not currently viable but they have aircraft with a GNS 430 or similar system that provides a terrain awareness function, fully understand the nature and limitations of this function and develop procedures and guidance for pilots about its operation (particularly for instrument approaches or operations in IMC).
If not already fitted, actively seek to upgrade their GPS/navigational system to one that provides vertical guidance information on non-precision instrument approaches.
Develop (or review) flight profiles for instrument approaches that provide clear guidance regarding the expected configuration, speed and other requirements at key stages of the approach.
Develop (or review) stabilised approach criteria in line with best-practice industry guidance and ensure that the applicable heights or reference points are suitable for straight-in approaches and operations in IMC.
Review the frequency and content of flight crew member proficiency checks to ensure they provide sufficient opportunities to monitor the way instrument approaches are being conducted during line operations (noting that such checks for IFR operations conducted under CASR Part 135 are now required every 6 months). In addition, such operators should consider options for obtaining and reviewing recorded flight data of normal line operations for continuous learning purposes.
The occurrence
Overview
On 11 March 2020, a Cessna 404 aircraft, registered VH-OZO, was being operated by Air Connect Australia to conduct a passenger charter flight from Cairns to Lockhart River, Queensland. On board were the pilot and 4 passengers. The flight was being conducted under the instrument flight rules (IFR).[1]
Consistent with the forecast, there were areas of cloud and rain that significantly reduced visibility at Lockhart River Airport. After arriving at Lockhart River, the pilot commenced an area navigation (RNAV) global satellite system (GNSS) instrument approach to runway 30. The aircraft descended to an altitude of about 400 ft before the pilot conducted a missed approach. The pilot immediately commenced a second RNAV GNSS approach to runway 30, and during the descent the aircraft collided with terrain.
Planned flight
The passengers were contracted to carry out work at the local school at Lockhart River. The client arranged with the operator for the aircraft to depart Cairns at 0730 Eastern Standard Time[2] on 11 March 2020, wait on the ground at Lockhart River for about 5 hours, then depart at 1430 with the same passengers for the return flight. The operator assigned the pilot who regularly conducted the operator’s charter flights.
For the arrival at Lockhart River, the forecast weather was for light winds and rain and low cloud with periods of visibility reducing to 3 km in rain. There was also a 30% probability of thunderstorms. The pilot had submitted a flight notification, which specified IFR and capability for an RNAV instrument approach. The aircraft had sufficient fuel to conduct an approach at Lockhart River and return to Cairns and hold at Cairns for 1 hour if required.
Flight to Lockhart River
The aircraft departed Cairns at 0719 and tracked for the first planned waypoint on climb to its cruise level of 10,000 ft above mean sea level. Based on the forecast winds, the estimated time of arrival at Lockhart River was 0852. As the flight progressed, the pilot amended the estimated time of arrival to 0904. The aircraft’s track during the flight is shown in Figure 1.
Figure 1: VH-OZO recorded flight path from Cairns to Lockhart River, Queensland
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
At 0836, the pilot advised air traffic control that the aircraft was approaching top of descent, then tracking direct for the runway 30 RNAV GNSS instrument approach at Lockhart River, and the pilot requested traffic information. The controller responded there was no reported IFR traffic. At 0840, the pilot reported leaving 10,000 ft on descent and, at 0842, the controller advised the pilot of the very high frequency (VHF) and high frequency (HF) radio frequencies applicable to the rest of the flight. That was the controller’s last contact with the pilot and no further routine interactions with the controller were expected.[3]
During descent, the pilot transmitted on the common traffic advisory frequency (CTAF) for Lockhart River to activate the runway lighting for a period of 30 minutes. At 0852, the aerodrome frequency response unit (AFRU) broadcast ‘Lockhart River CTAF, runway lights are on’.
At about this time, the pilot very likely obtained weather information from the automated weather information service (AWIS) via VHF radio. Notes taken by the pilot indicated the wind was calm, visibility was at least 10 km, there was broken cloud[4] at 1,800 ft, broken cloud at 3,500 ft and overcast cloud at 5,300 ft, and the QNH was 1,008 hPa (see Automated weather information service).
At about 0857, the aircraft levelled off at 5,500 ft. At this time the aircraft was heading to waypoint LHREB, one of 3 initial approach fixes (IAFs) for the RNAV GNSS instrument approach to runway 30 (Figure 2). The weather information indicated that the conditions were better than the landing minima (which were a cloud ceiling of 730 ft and visibility 4,200 m).[5]
Figure 2: Lockhart River RNAV GNSS runway 30 approach chart
Source: Airservices Australia, annotated by the ATSB
First approach at Lockhart River
Figure 3 depicts the aircraft’s recorded flight track for the first approach and missed approach at Lockhart River. The altitudes described throughout the report are truncated to the nearest 100 ft.[6]
At 0859:38, the aircraft passed abeam LHREB, commenced descent from 5,400 ft and turned left to track to the runway in accordance with the RNAV GNSS procedure. At 0901:25, the pilot made a radio broadcast on the CTAF, advising the aircraft was 10 NM[7] to the south-east of the aerodrome, inbound to runway 30 and on descent passing 4,000 ft. Shortly afterwards, the aircraft passed the intermediate fix (IF) LHREI at 4,000 ft.
Figure 3: Flight track of VH-OZO during first RNAV GNSS approach at Lockhart River Airport with times, feature labels, and approach parameters superimposed
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
At about 0903, one of the passengers sent a text message that contained an image of conditions outside the aircraft (Figure 4). At that time, the aircraft was over halfway between LHREI and the final approach fix (FAF) LHREF, at an altitude between 3,100 and 2,500 ft. The photograph had been taken through a passenger window on the right side of the aircraft cabin and, although there was significant cloud in the vicinity, some terrain/coastline was visible near the intersection of the wing’s leading edge and the engine cowl.
Figure 4: Image recorded by a passenger looking forward over the right engine and sent via text message at 0903
Source: Supplied, lower section of image cropped by the ATSB
The aircraft continued the descent on the approach track and passed LHREF on descent through 2,300 ft. At 0904:27, the pilot broadcast on the CTAF that the aircraft was at 5 NM and on final (approach) to runway 30.
The minimum descent altitude (MDA) was 730 ft.[8] The aircraft arrived at the missed approach point (MAPt) LHREM at 0906:17 on descent through about 600 ft. The descent continued to about 400 ft then, about 1,000 m from the runway, the aircraft started to climb. The aircraft was passing 600 ft as it crossed the runway threshold in the early stages of a missed approach. In accordance with the missed approach procedure, the aircraft was turned slightly right to track towards the turning fly-over waypoint LHREH.
At 0907:22, the pilot broadcast on the CTAF that they were conducting a missed approach for runway 30, tracking to the west then turning back to the east and climbing towards 3,500 ft (as specified for the missed approach procedure). After passing LHREH at 0907:43 on climb through 1,200 ft, the aircraft turned right to track east as prescribed by the approach chart.
At 0909, the pilot contacted Flightwatch[9] on HF and advised:
[VH-OZO] conducting a missed approach runway three zero [30] at Lockhart River, and we’ll be joining the approach on runway three zero [30], ops normal time two three three zero [2330]
The middle part of this radio transmission, as recorded by Airservices Australia, was unclear, which is not uncommon for HF radio communication.
Second approach at Lockhart River
The aircraft continued the climb to 3,800 ft before descending to level out at 3,500 ft, heading towards the closest IAF, LHREA. At 0912:51, the AFRU recorded runway lights on, consistent with the pilot reactivating the runway lights for another 30-minute period. About 2.0 NM prior to reaching LHREA, at 0913:53, the aircraft commenced a right turn towards the IF, and initially was right of the inbound track to LHREI (Figure 5).
Figure 5: Flight track of VH-OZO during second RNAV GNSS approach at Lockhart River Airport with times, feature labels, and approach parameters superimposed
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
At about 0914, while the aircraft was tracking towards LHREI on a south-westerly heading at 3,500 ft, an image was uploaded to social media by one of the passengers (Figure 6). The camera was oriented to the west, which was in the general direction of Lockhart River. An associated message indicated very low visibility and that the pilot was circling while waiting for a break in the weather. Another passenger sent a text message at 0914 stating that the first attempt at landing was unsuccessful, the runway was not visible and there was heavy rain.
Figure 6: Image recorded by a passenger looking over the right wing and uploaded to social media at 0914
Source: Supplied
At about 0914:43, when about 2.7 NM from LHREI, the aircraft started descending from 3,500 ft. At this time, the aircraft was tracking towards the initial approach track between LHREA and LHREI (Figure 5).
At 0915:50, the pilot made another inbound broadcast on the CTAF advising:
ten miles [10 NM] to the south-east on descent passing three thousand eight hundred [3,800 ft] correction two thousand eight hundred [2,800 ft], straight-in approach runway three zero [30], circuit area two one [time 0921].
The recorded height was about 2,800 ft at this time.
The aircraft continued descending and passed over LHREI and turned right to fly parallel to the intermediate approach track at about 2,800 ft. According to the recommended flight profile for a 3° approach (Figure 2), the aircraft should have descended from 3,500 ft at about 4.2 NM from the FAF (9.2 NM from the MAPt). At this point, the aircraft was at about 2,500 ft.
The descent continued at a similar gradient to the first approach although at about 1,000 ft lower than that approach. About halfway between LHREI and LHREF, the aircraft descended below the intermediate segment minimum safe altitude of 1,800 ft and continued to descend on the same descent profile.
When the aircraft passed LHREF at 0918:23, it was on descent through about 1,100 ft (below the 3° approach profile height of 2,160 ft). The aircraft was right of the final approach track and, shortly after passing LHREF, the aircraft started turning back towards the final approach track.
From LHREF to LHREM, the altitude limitation was the MDA of 730 ft and, at 09:18:55, the aircraft was approaching 700 ft. The aircraft then descended below the MDA and, soon after, the aircraft’s flight path crossed the final approach track (on a ground track about 20° left of the final approach track).
Collision with terrain
The aircraft’s track and descent continued until it impacted a sand dune on the coastline at about 0919:41. The pilot and 4 passengers were fatally injured, and the aircraft was destroyed. Due to the impact forces, the accident was not survivable.
Context
Pilot information
Qualifications and experience
The pilot held a commercial pilot licence (aeroplane) with an instrument rating and multi-engine aeroplane endorsement. They had recorded a total of 3,220 hours before the accident flight.
The pilot obtained the multi-engine endorsement in June 2014 (on a Cessna 310 aircraft), and had accrued 1,177 hours on multi-engine aircraft, including 399 hours on the Cessna 404 aircraft type. In June 2014, the pilot also obtained their initial (multi-engine) instrument rating, and their total instrument time was recorded as 148 hours.
The pilot operated as a commercial pilot in remote locations for about 5 years. Up until March 2016, they operated single-engine aircraft. In March 2016 they received training and were found competent on the Piper PA31 aeroplane type. Between March 2016 and February 2018, the pilot conducted flights for a charter company that operated Cessna 310 and Piper PA-31 aircraft, usually under visual flight rules (VFR[10]) with occasional instrument flights. They were approved by the Civil Aviation Safety Authority (CASA) as chief pilot of this operator in December 2016.
From October 2018, the pilot was employed by Air Connect Australia on a casual basis. Prior to joining the operator, the pilot’s recorded total flying time was 2,800 hours. The pilot completed induction then conducted a flight for type-specific training in a Cessna 421 from an independent CASA-approved flight examiner that the operator frequently used for proficiency checks. This flight was about 1.6 hours and the examiner recalled that the pilot managed the transition to the 400-series Cessna without any problems. Other than the pressurisation system in the Cessna 421, the examiner considered it was operationally equivalent to the unpressurised Cessna 404.[11]
Following this type-specific training, the chief pilot of Air Connect Australia supervised the pilot on 4 flight sectors in VH-OZO and conducted an operator proficiency check (OPC) over 2 further sectors on 29 October 2018. The chief pilot noted that the pilot’s planning was satisfactory, and operation of the aircraft was above standard.
From November 2018 to the accident flight, the pilot was based in Cairns and conducted most of the operator’s charter flights, normally in VH-OZO. In December 2019, the chief pilot organised for the pilot to undertake some supervised flying at night with an instructor in a Piper PA-44 Seminole in order for the pilot to maintain night recency. The operator rarely conducted night flights.
In the 90 days prior to the accident (11 March 2020), the pilot had conducted 59 flights (60 flight hours), all in VH-OZO. This included 4.5 hours recorded instrument flying time. In the last 30 days, the pilot had conducted 12 flights (13.5 flight hours), including 1.0 hour recorded instrument flying time. The most recent flights were on 18 February 2020.
Since joining the operator in late 2018, the pilot had logged 69 RNAV GNSS approaches to various aerodromes. These included 21 RNAV GNSS approaches in the previous 6 months, 12 in the previous 90 days, and 2 in the previous 30 days (with the last on 18 February 2020). Only one of the approaches in the previous 6 months was conducted to some extent in instrument meteorological conditions (IMC),[12] and this approach resulted in a missed approach (see Prior missed approach during an RNAV GNSS approach (22 January 2020).
Lockhart River experience
Since the start of 2019, the pilot had flown into Lockhart River 8 times, 6 of which were logged as RNAV GNSS approaches, with the most recent being on 14 October 2019.
The recorded data for previous RNAV GNSS approaches into Lockhart River were reviewed by the ATSB, with the details provided in Table 1. A review of recorded weather information indicated that none of these previous approaches at Lockhart River were conducted in IMC. For the 17 January 2019 approach, there may have been reduced visibility in the early part of the approach.[13]
Table 1: Pilot’s prior flights to Lockhart River 2019–2020
Date
Departure location
Approach type recorded
ATSB comments
17 January 2019
Cairns
RNAV GNSS
Aircraft passed over MAPt for runway 30 at 1,500 ft and then conducted a circling approach to land on runway 12
21 March 2019
Cairns
RNAV GNSS
Missing flight data for the approach and landing though appeared to be heading for runway 30 IAF
23 March 2019
Cairns
RNAV GNSS
Flight data shows an RNAV approach to runway 30 from the FAF but missing flight data before that point
24 March 2019
Coen
RNAV GNSS
Flight data shows an RNAV approach to runway 30 from the FAF but missing flight data before that point
24 March 2019
Coen
VFR
Logged as VFR flight, so data was not reviewed
18 April 2019
Cairns
VFR
Logged as VFR flight, so data was not reviewed
9 October 2019
Cairns
RNAV GNSS
No flight data available
14 October 2019
Cairns
RNAV GNSS
No flight data available
Proficiency checks and flight reviews
The pilot conducted initial instrument flight training in 2014. During training it was noted that the pilot needed to scan faster, improve situation awareness and improve radio phraseology. On one simulator training exercise it was noted the pilot was too high on the RNAV GNSS MDA and minimum altitudes.
The pilot did not pass their first attempt at attaining an instrument flight rating (in a Cessna 310) on 2 June 2014 for not maintaining altitude within +100 ft and -0 ft at the MDA, not using accepted navigation procedures, not being within half-scale deflection of glideslope, and not demonstrating sound command judgement. On the next day, 3 June 2014, the pilot passed on their second attempt.
Under Civil Aviation Safety Regulation (CASR) 61.650, pilots need to have completed an instrument proficiency check (IPC) in the previous 12 months to fly a multi-engine aircraft under the instrument flight rules (IFR). The IPC must also be done in a multi-engine aircraft of the same category.
The pilot undertook 6 IPCs with 3 different independent CASA-approved flight examiners between 2016 and 2019. These are detailed in Table 2.
Table 2: Pilot instrument proficiency checks 2016–2019
Date
Outcome
17 March 2016
Competent
14 May 2017
Not competent on a ground component (underpinning knowledge) with no assessment of flying capability
27 July 2017
Competent
4 August 2018
Not competent due to misread of altimeter by 1,000 ft (under-read)
5 August 2018
Competent
7 August 2019
Competent
The pilot’s last 3 IPCs were conducted on 4 August 2018, 5 August 2018 and 7 August 2019, all with the same CASA-approved flight examiner (who also conducted the IPC in March 2016).
On 4 August 2018, the pilot did not pass the IPC due to misreading the altimeter. The flight examiner recalled that they were on descent to the minima on a circling approach and, when the aircraft was at 1,000 ft above the MDA, the pilot asked whether they were visual. It then became apparent that the pilot had misread the altimeter by 1,000 ft (that is, they thought the aircraft was 1,000 ft lower than it was). The pilot successfully passed the check the following day.
The pilot’s most recent IPC was conducted on 7 August 2019 and was valid until 7 August 2020. The flight examiner who conducted this check was selected by the pilot; it was not the flight examiner regularly used by the operator (and who was familiar with the Air Connect Australia operations manual and could also conduct OPCs).
For each of the IPCs in 2018 and 2019, the pilot conducted a training flight with an instructor prior to the test flight, using the same Cessna 310 aircraft as in the test flights. The instructor commented that the pilot flew significantly better in 2019. Between the 2 checks in 2018 and 2019, the Cessna 310 aircraft was fitted with a GPS/navigational system and electronic flight instruments comprising an attitude display indicator (ADI) and a horizontal situation indicator (HSI). The ADI displayed aircraft attitude information, together with a secondary display of air data information (airspeed, altitude and vertical speed). The ADI and HSI each provided course and advisory vertical guidance during RNAV GNSS approaches.[14]
As already noted, the pilot undertook an operator proficiency check (OPC) on 29 October 2018 before commencing line operations with Air Connect Australia. This was the last OPC carried out on the pilot (see also Operator proficiency checks).
Between February and June 2018, prior to joining the operator, the pilot undertook training with an airline in a multi-crew environment and high-performing (turboprop) aircraft. Although the pilot obtained high marks in theory and written tests, they did not obtain satisfactory ratings during 3 proficiency assessments in a simulator (with remedial training given after each of the first 2 assessments). A common identified problem was instrument approaches, with issues identified including inefficient instrument scan, fixation (on some parameters), speed control, workload management, insufficient situational awareness and ineffective profile management. The ATSB notes that the training and checking environment at the airline was different to the pilot’s previous experience and the operational environment at Air Connect Australia.
Observations of the pilot’s approach to safety
The chief pilot (and managing director) of Air Connect Australia described the pilot as being a good pilot who would not have gone into an approach if they thought the weather was going to be poor, and that there was never any pressure to fly in poor weather. The pilot was trusted to make safety decisions, which would be supported by the chief pilot. This was consistent with the recollection of a previous pilot who flew with the operator, who reported that there was never any operational pressure (from the operator’s key personnel).
Another pilot stated that the pilot of the accident flight had ‘good stick and rudder skills’ and that everything was done ‘by the book’. It was also reported that the pilot had not expressed any concerns about the operator, including its approach to safety.
Former colleagues from when the pilot was chief pilot at a previous operator described the pilot as smart, diligent, and methodical with good knowledge of the rules and regulations. They reported that the pilot did not take shortcuts or unnecessary risks and had good hand-flying skills.
With reference to instrument approaches, one pilot advised that they had many conversations with the pilot of the accident flight regarding aircraft accident reports and safety, and the pilot of the accident flight had stated that they would conduct instrument approaches using the published constant-descent profile and would not intentionally deviate below published segment minimum safe altitudes in order to get visual early in an approach.
During January 2020, the pilot spent a week conducting a series of charter flights between Aurukun and Weipa, Queensland, in VH-OZO with the same group of passengers (see also Prior missed approach during an RNAV GNSS approach (22 January 2020)). Their perception was that the pilot was a good, competent pilot who was diligent, professional, and responsible and that they never felt unsafe. They also advised that they observed the pilot reviewing forecast and actual weather conditions regularly and that the pilot would delay flights due to weather conditions if necessary. Some of the passengers reported observing the pilot make weather-based decisions and did not display any indications of external pressure to fly in poor weather. One of the passengers reported that the pilot had said they would only ever make 2 attempts at landing and, after that, would return to the departure aerodrome or divert to an alternate.
Recent history
The pilot had recently returned from annual leave, with their last flights before leave conducted on 18 February 2020. The 3 days prior to the accident flight were reported to be uneventful. It was described that the pilot ate and exercised regularly and had been sleeping well with a standard time to sleep about 2230 and wake time about 0700–0730. The night before the accident flight, the pilot went to bed at about 2230 and woke at about 0530. There was nothing of note from the pilot’s recent history to suggest they were experiencing a level of fatigue known to affect performance.
The pilot was notified about the 11 March 2020 flight a few days in advance. It was reported that the pilot had been in a good mood in the days prior to the flight and was looking forward to flying again. On the day before the flight, the pilot went to Cairns Airport and started the aircraft’s engines to re-familiarise themselves and ensure everything was ready for the next day’s flight.
Medical information
The pilot’s Class 1 Aviation Medical Certificate was renewed on 14 February 2020 and was valid until 14 February 2021. There were no indications of any significant medical problems in the pilot’s aviation medical records. There was no evidence to suggest the pilot had any current or ongoing medical issues at the time of the accident.
A post-mortem examination was conducted by a forensic pathologist on behalf of the Queensland Coroner. The pathologist found that there was ‘No obvious natural disease to contribute to the cause of death within limits of examination …’. Forensic toxicology screening returned negative results (that is, no alcohol or substances were detected). The sample was unsuitable for analysis for carbon monoxide.
Aircraft information
General information
The Cessna 404 Titan is an unpressurised, low-wing, twin piston-engine aircraft with retractable landing gear. The maximum take-off weight (MTOW) is 3,810 kg, and the aircraft was certified to be flown by a single pilot.
VH-OZO was manufactured by the Cessna Aircraft Company in 1980. It was reported that the aircraft was first operated in Australia before being transferred to Papua New Guinea and registered as P2-ALG. In December 2009, a CASA Certificate of Airworthiness was issued, and the aircraft was registered as VH-OZO. At that time, the aircraft’s total time in service was 28,193 hours.
Seating
The type certificate data sheet for the Cessna 404 stated the aircraft type had 11 total seats (2 pilot seats and 9 passenger seats). In 1980, VH-OZO was configured with a modified seating configuration with 13 seats (2 pilot seats and 11 passenger seats).[15]
During an audit of Air Connect Australia in June 2017, CASA identified that the Airplane Flight Manual stated a maximum of 9 passenger seats aft of the pilot seats but there was 11 on the aircraft. In its initial audit response, the operator stated that the seating change was approved many years ago and it was attempting to find supporting documentation. In a subsequent response, the operator stated that it had previously operated and would continue to operate with a maximum of 9 passengers. It noted that the extra seating would remain in the aircraft as it formed part of the aircraft’s current weight and balance data.
During the investigation, the chief pilot confirmed that the operator never operated the aircraft with more than 9 passengers and normally operated with significantly less than 9 passengers.
Photos taken during the accident flight indicated that no passengers were seated in the front right seat next to the pilot.
Aircraft instruments and systems
On arrival into Australia, the aircraft was fitted with aerial geophysical survey equipment and was operated in that configuration until the equipment was removed in March 2012. Concurrently, the aircraft were modified in accordance with an engineering order to install new types of avionics and integrate those with existing units. The post-modification avionics, including existing equipment, consisted of:
Bendix/King KR87 automatic direction finder (ADF) and Bendix/King KI-227 ADF indicator
Collins HF radio
Cessna 400B Navomatic autopilot
Bendix weather radar (monochrome display).
These units were still installed at the time of the accident except for the transponder, which had been replaced by an automatic dependent surveillance-broadcast (ADS-B) compliant unit in April 2017.
VH-OZO was not fitted with a terrain avoidance and warning system (TAWS), nor was it required to be under legislation in place in Australia at the time of the accident. Further information is provided in Terrain avoidance and warning systems.
An assigned altitude indicator was fitted to the aircraft, which was designed to be used as a reminder of the designated altitude. Altitudes could be manually set by means of individual thumb wheels and no aural or visual alerts were provided when reaching or leaving the set altitude. The aircraft did not have an altitude alerting system, nor was it required for the type of aircraft and operation.[16]
The 400B autopilot was one of the standard equipment options for the Cessna 404 type. It could provide pitch and roll control with heading and altitude hold (on command). A navigation function provided the autopilot with inputs from an associated CDI (the GI-106A), which in this case received data from the number‑1 GNS 430W.
For an RNAV GNSS approach, a pilot could ‘couple’ the autopilot for lateral navigation and manage vertical navigation by adjusting the autopilot pitch wheel to achieve the intended rate of descent. For a level segment, the pilot could select altitude hold on reaching the intended altitude. Several pilots who had flown VH-OZO advised that they routinely hand flew instrument approaches due to autopilot constraints.
The aircraft was fitted with the instrumentation required for operations under the IFR. These flight instruments were conventional analogue indicators and reflected the original specifications for the aircraft. The second artificial horizon/attitude indicator and altimeter were located on the right side of the co-pilot panel (far side of the instrument panel relative to the pilot) (Figure 7).
Figure 7: VH-OZO instrument panel
Source: Supplied, annotated by the ATSB
A closer view of the instrument panel is depicted in Figure 8. It had the standard 6 flight instruments directly in front of the pilot’s seat on the left. These include the attitude indicator, which depicts the aircraft’s basic roll and pitch attitude, and the primary performance instruments – altimeter, airspeed indicator and vertical speed indicator (VSI). Below those were 2 (GI-106A CDI) instruments[17] that provided course deviation indication provided either by the GNS 430’s digitally-tuned VOR/localiser and glideslope receiver or GPS input to conduct an RNAV GNSS approach. One CDI instrument was coupled to the aircraft’s number-1 GNS 430W GPS unit and the other to the number-2 GPS unit.
The basis of cockpit design is to have the primary instruments within a small arc of the pilot’s forward line of sight. Navigation systems such as the GPS units may be located next to the primary instruments, as was the case in VH-OZO. While conducting an RNAV GNSS approach, it is imperative that the pilot includes the GPS units in the scan.
Figure 8: Instrument panel of VH-OZO
Source: Supplied, annotated by the ATSB
Altimeters
VH-OZO was equipped with two 3-pointer altimeters (Figure 9), including one directly in front of the pilot. They had a 100-ft pointer (long and narrow), 1,000-ft pointer (short and wide) and 10,000-ft pointer (long and thin with a triangle at the end). The diagonal hashing indicated when below 10,000 ft and was gradually covered above that height.
These types of 3-pointer altimeters are very common in general aviation aircraft, including small aeroplanes used for passenger transport activities. Research has shown that such altimeters can be associated with misreading errors, including misreading the altitude by 1,000 ft, although accidents known to be associated with such errors seem relatively rare. Accordingly, such altimeters (and some other altimeter designs) are no longer allowed to be used on air transport certificated aircraft. Further information about requirements and guidance regarding altimeters is provided in Appendix A – Research and guidance regarding design of altimeters.
The aircraft was not fitted with a radio altimeter, nor was it required for the type of aircraft and operation.
Figure 9: Example of the 3-pointer type of altimeter fitted in VH-OZO
This altimeter shows an altitude of 1,210 ft (10,000 ft pointer indicating 0, 1,000 ft pointer indication 1,000 ft and 100 ft pointer indicating 210 ft.
Source: avioelectronica.com
GNS 430W overview
The Garmin GNS 430W is a panel-mounted unit that provides GPS navigation, instrument landing system or VHF omnidirectional radio range navigation, and VHF radio communication. It was approved for IFR operations, including RNAV GNSS approaches, and was used in conjunction with a CDI.
Although the ‘W’ designated wide area augmentation system capabilities[18] that facilitated GPS approaches with vertical guidance, Australia did not have the associated satellite-based augmentation system to enable this functionality at the time of the accident. As such, the GNS 430W was approved to provide distance and track information only for RNAV GNSS non-precision approaches.
Information was displayed to the pilot on an 8.4 cm by 4.6 cm (240 by 128 pixel) high-contrast colour LCD. A pilot could select the pages and menus to display relevant information during various flight stages. Those included the default navigation page and additional pages including:
a 2-dimensional representation of terrain relative to the aircraft position
information for vertical navigation of the aircraft
a moving map display
information about the status of the GPS satellite constellation
information relevant for the navigation and communication functions of the unit.
When used for an RNAV GNSS approach, the navigation page would display a graphic CDI together with the active leg of the approach and 6 user-selectable data fields.[19] After passing the waypoint it was tracking to, the unit would automatically sequence to the next waypoint.
When approaching a waypoint such as an initial approach fix (IAF), if a turn was required, the unit would display the recommended flight path (turn) to intercept the next track segment. The unit would also display a flashing message about 10 seconds prior to the start of the recommended turn, alerting the pilot that a turn was required and the track to intercept.
To use the unit for RNAV GNSS approaches, it was a requirement that the NavData card[20] was valid and the approach procedure was loaded from the database. The operator subscribed to the Jeppesen NavData service that provided monthly updates. It was reported that the pilot updated the NavData card using a laptop computer in the 24 hours prior to the flight. There were no changes in the update that would have been relevant to the accident flight.
The terrain, obstacle and airport terrain database was loaded on a terrain data card. The operator did not subscribe to an update service for terrain/obstacle data. Obstacle data was updated on a 56-day cycle and updates to the terrain database were released on an ‘as-needed’ basis. There was no requirement to have current obstacle or terrain databases to use the GNS 430W for flight under the IFR and/or during an RNAV GNSS approach. A June 2018 photograph of VH‑OZO’s GNS 430W receivers indicated the obstacle database installed at that time was dated October 2011.[21]
Fault detection and exclusion was incorporated into the GNS 430W software to detect satellite failure and exclude failed satellites from usage.
In addition to their experience with VH-OZO, the pilot of the accident flight had experience using GNS 430 units during their time flying Cessna 310 and PA-31 aircraft with a previous operator, which included units with a terrain awareness function.
Garmin TERRAIN function
Garmin TERRAIN was a non-certified[22] terrain awareness system, provided as a standard feature of 400W-series units, to increase pilot situation awareness and help reduce the risk of controlled flight into terrain (CFIT). The functions required a valid 3D GPS position and a valid terrain and obstacle database. Terrain and obstacle information was advisory only and was not equivalent to warnings provided by TAWS. The Garmin 400W SeriesPilot’s Guide & Reference manual stated:
CAUTION: The Terrain feature is for supplemental awareness only. The pilot/crew is responsible for all terrain and obstacle avoidance using information not provided by the 400W-series Terrain feature.
When the GNS 430’s terrain page was selected, it presented a 2-dimensional colour-coded display of terrain tiles and obstacles from its database, relative to the aircraft’s current position/altitude. Red (warning) indicated terrain/obstacles above and up to 100 ft below the aircraft’s current altitude, yellow (caution) between 100 ft and 1,000 ft below the current altitude, and black more than 1,000 ft below the current altitude. The terrain page would not normally be selected when conducting an RNAV GNSS approach.
Terrain advisory and alert messages were provided when flight conditions met specific parameters. The advisories/alerts comprised a visual annunciation in the lower left corner of the unit’s LCD display, accompanied by a larger pop-up advisory/alert on the current display page (except the page displaying terrain). To clear the pop-up advisory/alert, the pilot would either acknowledge the message to return to the selected page or acknowledge the advisory/alert and display the terrain page. The system did not provide auditory alerts.
A pilot could use an ’inhibit mode’ to deactivate the terrain advisory/alert message system and pop-up messages would not be generated. The terrain page was still selectable and would display colour-coded terrain and obstacle information relative to the aircraft’s position. Once inhibited, the terrain annunciator field displayed a ‘TER INHIB’ annunciation and the terrain alert system remained deactivated until reselected. The GNS 400W-Series manual stated that the terrain inhibit mode could be used when the advisories/alerts were deemed unnecessary by the pilot. The manual also stated:
Flying VFR into an area where unique terrain exists could cause the system to annunciate a nuisance alert. Pilots should use discretion when inhibiting the TERRAIN system and always remember to enable the system when appropriate.
According to the GNS 400W-Series manual, the terrain system issued a premature descent alert (PDA) when the aircraft was significantly below the normal approach path to a runway. The manual indicated that this alert would activate depending on the aircraft’s height above terrain and distance from the runway threshold (for example, it would be triggered if the aircraft was about 400 ft above terrain when 10 NM from the runway threshold, 350 ft at 5 NM, 320 ft at 4 NM, and 280 ft at 3 NM). PDA alerts were not provided when the aircraft was within 0.5 NM of the runway or less than 125 ft above terrain within 1.0 NM of the runway.
Based on this information and the recorded data for the accident flight (Recorded flight data), provided that the terrain advisory/alert function was enabled, a yellow and black ‘TERRAIN’ annunciation would be generated in the lower left corner of the LCD display, accompanied by a yellow and black ‘TOO LOW – TERRAIN’ PDA pop-up alert (Figure 10), about 15 seconds prior to the terrain collision.
Figure 10: Premature descent alert on the GNS 430W display
Source: Garmin GNS 400W Series Pilot’s Guide & Reference
The terrain system also provided forward-looking terrain avoidance (FLTA) alerts. Provided the terrain system was enabled, a FLTA terrain alert was generated when the predicted or present aircraft altitude above terrain or obstacles was below the minimum clearance value for that phase of flight. During an approach, the clearance value was 150 ft during level flight and 100 ft when descending.[23] The terrain/obstacle advisory alert comprised a yellow and black ‘TERRAIN’ annunciation in the lower left corner of the LCD display, accompanied by a yellow and black ‘TERRAIN ADVISORY’ or ‘CAUTION OBSTACLE’ pop-up message. The pop-up advisory alert would be displayed on all selectable pages (except the terrain page) and remained visible until the message was cleared/acknowledged by the pilot, or the minimum clearance value was no longer infringed.
If the minimum clearance value for terrain/obstacles remained, a terrain/obstacle ahead alert would be generated. The alert consisted of a flashing yellow and black ‘TERRAIN’ annunciation in the lower left of the LCD panel display and a flashing yellow and black ‘TERRAIN AHEAD’ or ‘OBSTACLE AHEAD’ pop-up alert. The pop-up alert would be displayed on all selectable pages, except the terrain page and remained visible until the message was cleared/acknowledged by the pilot, or the minimum clearance value was no longer infringed.
The GNS 400W-Series manual did not specify the warning period for FLTA alerts. However, an earlier version of the 430/430A-Series manual indicated the ‘TERRAIN ADVISORY’ or ‘OBSTACLE ADVISORY’ pop-up terrain alert would be displayed when approximately 60 seconds from potential impact and the ‘TERRAIN AHEAD’ or ‘OBSTACLE AHEAD’ flashing pop-up terrain alert when 30 seconds from potential impact.
On the accident flight, the descent rate when the aircraft reached 5 NM from the runway threshold (or 3.6 NM from the MAPt) is unclear (see Recorded flight data). However, soon after, the descent rate was about 1,200 ft/min and the predicted flight path would have resulted in an FLTA alert to be generated. Therefore, if the terrain awareness/alert system was enabled, an FLTA alert should have been generated about 30 seconds (or longer) prior to the collision.
Air Connect Australia did not have any operational guidance or procedures regarding the use of the terrain awareness function on the GNS 430W units. The chief pilot reported that, when they were the pilot flying VH-OZO, they would generally leave the function turned on, even though it could be annoying in some locations. However, they did not regularly fly the aircraft and had not conducted the most recent flights in the aircraft.
The ATSB spoke to several pilots who were familiar with GNS 430 units with a terrain awareness function. Some advised that the terrain awareness function would often be inhibited, whereas others would use the function on one 430 unit and inhibit it on the second 430 unit. None of the pilots were aware of operators having specific procedures and guidance for using the terrain function.
Pilots stated that the main reason for the terrain awareness function to be inhibited was the perception that it could issue nuisance alerts, with some of these pilots clarifying that this would only occur (or be a valid concern) when conducting visual approaches at non-licenced aerodromes. One pilot advised that they had heard of some pilots in one operator being concerned about using the terrain function if the terrain/obstacle database was not current. However, 2 experienced flight examiners advised that, in their experience, these databases were commonly not current on aircraft they encountered in their roles and that having a current database was not critical; the advantages of the terrain awareness function were more significant than any potential problem with a terrain/obstacle database not being current.
There was no information available regarding what the pilot of the accident flight normally did with the terrain awareness function when flying VH-OZO. Based on the available information, the ATSB could not establish if the terrain awareness function was enabled or inhibited during the accident sequence, or to what extent the pilot had previously encountered terrain alerts when conducting operations in the aircraft.
Configurations and speeds
The flap settings on the Cessna 404 included ‘UP’, ‘T.O. & APPR’ (take-off/approach) and ‘LAND’ (landing). The take-off/approach setting was often referred to as ‘approach flap’ and sometimes called ‘10° flap’.[24]
According to the Cessna 404 Pilot’s Operating Handbook (POH), which included the Airplane Flight Manual approved by the US Federal Aviation Administration, the maximum landing gear extension speed (and operating speed) was 182 kt, the maximum speed to select approach flap was 182 kt, and the maximum speed to select landing flap was 152 kt.
The POH specified a recommended minimum approach speed (or Vref[25]) at 50 ft of 91 kt (all engines operating, landing flaps, weight 8,100 lb or 3,6764 kg). For all aircraft weights of 7,500 lb (3,402 kg) and lower, the POH stated approach airspeeds (at 50 ft) of 88 kt. Consistent with the POH, the operator’s operations manual provided values for VAPP[26](approach speed) of 91 kt at 8,100 lb and 88 kt at 7,500 lb and lower weights.
The POH stated the minimum control speed (VMCA) with approach flap selected was 78 kt. In addition, the one-engine inoperative best rate-of-climb speed for the aircraft type was 102 kt (flap in the take-off/approach position and gear up) and 109 kt (flap and gear up).
Aircraft maintenance
The aircraft logbook statement specified that VH-OZO was to be maintained in accordance with the system of maintenance developed by the aircraft owner and approved by CASA. The key elements of the system were:
daily inspection in accordance with the Cessna 404 POH
engine and airframe inspections every 100 +/- 10 hours in accordance with the Cessna 404 progressive care program (Operations 1 and 2 plus 3 and 4 completed within 12-month period)
electrical and instrument inspections every 220 hours or 12 months in accordance with system of maintenance schedules
IFR avionics inspections every 220 hours or 12 months in accordance with system of maintenance schedules
special inspections, supplemental inspection documents, and corrosion prevention control program as required
altimeter and pitot-static system inspection and test every 24 months
maintenance release issue for a period of up to 220 hours or 12 months, whichever occurred first.
Scheduled engine and airframe maintenance was carried out by the CASA-approved maintenance organisation associated with the aircraft owner. While the aircraft was based in Cairns, electrical, instrument, and radio maintenance as well as unscheduled maintenance was contracted to licensed aircraft maintenance engineers.
The most recent maintenance was the scheduled 100-hour inspection based on Operations 3 and 4 of the Cessna 404 progressive care program. That was completed on 16 February 2020 at 31,066 hours total time. A maintenance release was issued with the next scheduled maintenance being the oil/filter change after 50 hours operation and compass swing in July 2020.
Other key maintenance was:
19 January 2020 at 31,050 hours: inspection of the electrical, instrument and IFR avionic systems certified as satisfactory
29 January 2019 at 30,750 hours: inspection and test of the pitot-static system and check of altimeters certified as satisfactory.
The current maintenance release was not found at the accident site. Operator records showed that the aircraft had been operated for 3.8 hours between maintenance release issue and the accident flight. The operator and aircraft owner both advised that no aircraft defects had been reported.
The ATSB identified that the vacuum pumps had been in service for a relatively long period and internal wear had not been inspected at the recent 100-hour inspection. Also, there was no record of testing or replacement of the vacuum manifold in the previous 10 years. Although these aspects increased the likelihood of a vacuum system failure, there was no evidence that the vacuum-powered instruments were adversely affected. Further information regarding the maintenance and serviceability of the vacuum system (associated with the attitude indicators and directional gyro) is provided in Appendix B – Vacuum system analysis.
Terrain avoidance and warning systems
General description
A terrain avoidance and warning system (TAWS) provides visual and aural alerting including a look-ahead terrain function. The aircraft’s height above terrain can be based on GPS or radio altitude information. TAWS is a generic term that also includes a ground proximity warning system (GPWS) with a forward-looking terrain avoidance function.
A TAWS is an important tool to help minimise the risk of controlled flight into terrain (CFIT). It provides an independent and unambiguous warning of proximity to the ground or obstacles, regardless of any navigational uncertainty or error such as mis-setting or misreading the altimeter.
Multiple levels or classes of TAWS are defined and internationally recognised. Class B TAWS (TAWS B) includes a minimum of the following alerts:
reduced required terrain clearance
imminent terrain impact
premature descent
excessive rates of descent
negative climb rate or altitude loss after take-off
descent of the aeroplane to 500 ft above the terrain or nearest runway elevation (voice callout ‘Five hundred’) during a non-precision approach.
Class B+ TAWS also has a terrain awareness display that shows surrounding terrain/obstacles relative to the aircraft. Class A TAWS (TAWS A) has all the requirements of Class B+ TAWS, plus 3 additional alerts. Both Class A and class B TAWS have a forward-looking terrain avoidance function.
To maximise its effectiveness, an aircraft operator should have standard operating procedures for the use of a TAWS and for actions to take in response to TAWS alerts.
Australian requirements
Civil Aviation Order (CAO) 20.18 (Aircraft equipment — basic operational requirements), which was in force at the time of the accident, stated that for Australian aircraft:
9.1C A turbine-engined aeroplane that:
(a) has a maximum take-off weight [MTOW] of more than 15 000 kg or is carrying 10 or more passengers; and
(b) is engaged in RPT [regular passenger transport], or charter, operations;
must not be operated under the I.F.R. unless it is fitted with
(c) an approved ground proximity warning system that has a predictive terrain hazard warning function…
(e) if the aeroplane has a maximum take-off weight of 5 700 kg or less, but is carrying 10 or more passengers – a TAWS-B+ system.
In effect, this meant that turbine-engine aeroplanes being used to conduct passenger transport operations under the IFR were required to have a TAWS if the aeroplane was carrying 10 or more passengers or it was a larger air transport aeroplane.[27] There was no requirement for a piston-engine aeroplane (such as VH-OZO) to be fitted with a TAWS.
International requirements for turbine-engine aeroplanes
The Australian TAWS requirements for turbine-engine aeroplanes were consistent with the standards included in International Civil Aviation Organization (ICAO) Annex 6 (Operation of Aircraft) Part I (International Commercial Air Transport – Aeroplanes), which included a standard[28] for all turbine-engine aeroplanes with a MTOW of more than 5,700 kg or authorised to carry 10 or more passengers to have a TAWS. In addition to Australia, this standard had been adopted by comparable countries, including the United States, Canada, New Zealand and Europe.
In 1996, the US National Transport Safety Board (NTSB) issued a recommendation to the US Federal Aviation Administration (FAA) to require that all turbojet-powered airplanes equipped with 6 or more passenger seats have an operating GPWS installed. In 1999 it also recommended that all turbine-powered aeroplanes of the same size be fitted with a TAWS.
In response, the FAA commissioned a report that examined 44 CFIT accidents that occurred between 1985 and 1994 in the US involving turbine-powered aeroplanes with 6 to 10 passenger seats. Of the 44 aeroplanes, 11 were powered by turbojets and 33 were powered by turboprops. None were fitted with a GPWS system. Computer modelling techniques used to analyse the data showed that, had GPWS been fitted, 33 accidents could have been prevented; had enhanced GPWS been fitted, 42 accidents could have been prevented.
Accordingly, the FAA introduced a requirement for all turbine-powered aeroplanes with 6 or more passenger seats to be fitted with a TAWS B (in Federal Aviation Regulations 91.223 and 135.154). The requirement commenced in March 2002 for new aircraft and March 2005 for older aircraft.
The FAA did not propose to introduce the same requirement for piston-engine (or reciprocating-engine) aeroplanes. In its final rule summary in 2000, the FAA stated:
The General Aviation Manufacturers Association (GAMA) is against requiring TAWS on reciprocating-powered [piston-engine] airplanes because the costs would be high (e.g., “TAWS equipment would cost more than the hull value of the aircraft”), and the panel space for installing TAWS with a situational display is not available in these airplanes.
The FAA did not receive any comments that would justify undertaking a new rulemaking project to mandate TAWS for reciprocating-powered airplanes.
However, regarding the issue of panel space, the FAA knows of at least one manufacturer who has developed a complete TAWS unit that was designed to replace an existing panel instrument.
Following the US introduction, from November 2006, ICAO Annex 6 Part I included a recommendation that turbine-engine aeroplanes with an MTOW of 5,700 kg or less and authorised to carry 6–9 passengers should be equipped with a TAWS. This recommended practice was introduced as a regulatory requirement in other countries, including New Zealand (from 2007 for air transport operations under the IFR), Canada (from 2014 for operations other than day VFR flights), and in Europe (for such aeroplanes with an individual certificate of airworthiness issued after 1 January 2019).[29]
International requirements for piston-engine aeroplanes
Applicable from January 2007, ICAO Annex 6 Part I included a standard for TAWS B to be fitted to piston-engine aeroplanes with a MTOW greater than 5,700 kg or authorised to carry 10 or more passengers.
Subsequently, TAWS requirements were introduced in Canada (from 2014 for air transport operations other than day VFR flights), New Zealand (from 2007 for air transport operations under the IFR) and Europe (from 2012 for air transport operations) for piston-engine aeroplanes. No such requirements for piston-engine aeroplanes were introduced in the United States.
Canada also introduced the same requirement for piston-engine aeroplanes with a passenger seating capacity of 6–9 conducting air transport operations other than day VFR flights from 2014. As far as could be determined, no other countries had introduced a TAWS requirement for piston-engine aeroplanes with a passenger seating capacity less than 10.
In its notice of amendments about TAWS requirements in 2012, Transport Canada indicated that the cost for installing a TAWS B on small aeroplanes conducting air taxi (charter) operations in aircraft with a passenger seating capacity of less than 10 was about Can$23,000. It also noted that the expected benefits of TAWS (in terms of reduced fatalities, serious injuries and accidents due to CFITs) were significantly higher than the costs.[30]
Considerations of changes in Australia
In March 2006, the ATSB issued safety recommendation R20060008:
The Australian Transport Safety Bureau recommends that the Civil Aviation Safety Authority review the requirements for Terrain Awareness Warning Systems for Australian registered turbine-powered aircraft below 5,700 kgs, against international standards such as ICAO Annex 6 and regulations such as FAR 91.223, with the aim of reducing the potential for CFIT accidents.
CASA accepted the recommendation and stated that it would examine the capital/installation costs and benefits. This work was initiated as part of CASA’s notice of proposed rule making (NPRM) 0808OS (Passenger transport services and international cargo operations – Small aeroplanes) published in February 2009. The proposed requirements included that small aeroplanes (regardless of engine type) conducting passenger transport operations carrying 6 or more passengers under the IFR to be fitted with a TAWS B. In terms of benefits and costs, the NPRM stated:
The costs and benefits of mandating TAWS B equipment for IFR aeroplanes carrying 6 to 9 passengers has been assessed by CASA. Equipment and fitment costs are forecast to be approximately $23,000 per aeroplane. Options to offset these additional costs are under consideration by the Government. Benefits are expected to flow to the industry from increased public confidence with this equipment fit to small aeroplanes in which passenger operations are conducted, as the overall accident rate is expected to reduce.
Accordingly, the ATSB recommendation was closed.
Subsequently, CASA released a consultation draft of Civil Aviation Safety Regulation (CASR) Part 135 (Australian air transport operations—smaller aeroplanes) in 2012. This contained a requirement for a TAWS for aeroplanes conducting passenger transport operations with a maximum operational passenger seat configuration (MOPSC)[31] of 6 or more. The proposed requirement’s applicability had expanded to include all flights (not just IFR flights) and was based on the passenger seat capacity rather the actual number of passengers carried on a flight.
Following further consultation, the 2012 proposal was amended to a MOPSC of 10 or more. In the summary of proposed change for CASR Part 135 (published in August 2018), CASA stated:
CASA had originally proposed the fitment of a minimum of TAWS-Class B for aeroplanes with a MOPSC greater than 5 which aligned with the Federal Aviation Administration of the USA (FAA) and Transport Canada rules however this was changed after discussion with the Aviation Safety Advisory Panel Technical Working Group.
In the 2018 explanatory statement in for the introduction of CASR Part 135, CASA outlined the options it considered (in its regulatory impact statement) regarding the implementation of TAWS. It noted that the estimated cost of installing a TAWS was about $21,000 (including about $12,000 for the system and additional costs for installation and training). One option (named option 2) was to only require a TAWS for all aeroplanes with a MOPSC of 10 or more or a MTOW greater than 5,700 kg. It was determined that this would affect 18 aeroplanes (in addition to those that already had or required a TAWS). Another option (option 3) was to require a TAWS for all aeroplanes with a MOPSC of 6–9 as well. In terms of option 3, the statement noted:
The types of aircraft that are within this category include, the piston powered AeroCommander 680, Beech 95 and Cessna 421 and the turbine powered aeroplanes that include the Cessna 208, Fairchild SA 226 and Pilatus PC 12. CASA estimates that there are approximately 323 of these types of aircraft. Based on 323 aircraft within the six to nine seat range and the 18 aircraft with MTOW>5700kg of option 2 this would result in an estimated cost impact of $7.2m for 341 aircraft... [as well as $0.72m annually]
The statement noted that initially CASA had proposed option 3 to industry but, following initial consultation, it did not pursue this option. Feedback associated with the initial consultation on TAWS (and other proposed regulatory changes) included that charter businesses were operating in a difficult marketplace with many not being profitable.
As a result of this regulatory reform process, the Australian requirements for TAWS changed from December 2021, such that piston-engine aeroplanes with a MOPSC of 10 or more conducting air transport operations were required to have a TAWS, with the applicable date being December 2021 or December 2022 dependent on various factors (see Safety issues and actions).
For VH-OZO and its seating configuration at the time of the accident, CASA advised the MOPSC was 12.[32]As such, if the operator had continued operating the aircraft for passenger transport flights with that seating configuration, the aeroplane would have been required to have a TAWS by December 2022 and, from December 2024, the operator would have had to operate the aeroplane under CASR Part 121 (and conduct all flights with 2 pilots under the IFR, as well as meet additional requirements compared to Part 135). Alternatively, the aeroplane would not have been required to have a TAWS or be operated under Part 121 if some seats were removed such that the MOPSC was 9 or less.[33]
Aerodrome information
Lockhart River Airport had one sealed runway (12/30), which was 1,500 m long and 30 m wide. It was not serviced by an air traffic control (ATC) tower and it was outside of ATC radar coverage. The airport had a common traffic advisory frequency (CTAF), which was used by pilots to advise intentions and arrange separation with other traffic.
The elevation of the runway was 76 ft at the threshold for runway 30 and 48 ft at the threshold for runway 12. The runway was equipped with low-intensity runway lights, and there was no visual approach slope guidance.
At the time of the accident there were 3 instrument approaches available at the airport:
NDB approach to runway 30
RNAV GNSS approach to runway 12
RNAV GNSS instrument approach to runway 30 (Figure 2).
The airport was located on a coastal plain 4.5 km west of the Lockhart River township. The Great Dividing Range was nearby with the terrain rising to over 800 ft to the south-west and west within about 8 km of the airport.
Lockhart River was known to experience low cloud and poor visibility conditions. The average (mean) rainfall at Lockhart River is 2,058 mm. In the month of March, the average rainfall is 446 mm and 19.5 days have rainfall of more than 1 mm.
The ATSB interviewed several pilots with experience conducting RNAV GNSS approaches, including some who had conducted multiple approaches at Lockhart River due to poor visibility conditions. The pilots had several suggestions for reducing workload for a second approach, including holding or diverting to Coen or Weipa to wait for weather to pass.
Meteorological information
Weather forecasts - overview
The Bureau of Meteorology produced aviation forecasts, observations, warnings and advisories. As the official provider of the Aeronautical Information Service, Airservices Australia delivered the bureau’s aviation meteorological products to pilots through National Aeronautical Information Processing System (NAIPS).
For the flight from Cairns to Lockhart River, the meteorological forecast information consisted of aerodrome forecasts (TAFs), graphical area forecasts (GAFs), grid point wind and temperature charts (GPWTs) and any warnings (such as SIGMETs[34]). These could be supplemented by aerodrome weather reports (METARs), ground-based weather radar imagery, and satellite imagery.
According to the weather forecasts, the pilot would have expected mostly visual meteorological conditions (VMC)[35] during the day at Cairns with some periods of rain showers and low cloud. For the arrival at Lockhart River, the forecast weather was predominantly VMC but there were overlapping periods of rain and low cloud with 30% probability of thunderstorms.
Aerodrome forecasts
A TAF for Lockhart River was issued at 0449 EST[36] and was valid from 0600 to 1800. The expected weather conditions were:
From 0600 to 1000: wind variable at 3 kt with visibility 10 km or greater. Light rain showers and cloud scattered at 1,000 ft.[37]
Between 0600 and 1000: TEMPO[38] - visibility reduced to 3,000 m with rain and broken cloud at 500 ft.
From 0600 to 0800: 30% probability of fog with visibility reduced to 500 ft and broken cloud at 100 ft.
From 1000 to 1800: wind from the north-east at 5 kt with visibility 10 km or greater. Light rain showers with scattered cloud at 1,000 ft.
Between 1000 and 1800: TEMPO - visibility reduced to 3,000 m with rain showers and broken cloud at 800 ft.
For the whole forecast period, 0600 to 1800: 30% probability TEMPO - winds gusting 25 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,000 ft.
Based on this forecast a pilot arriving at Lockhart River was required to plan for 60 minutes holding or diversion to an alternate aerodrome. The aircraft had more than sufficient fuel for that purpose (see Fuel calculations).
An amended TAF for Lockhart River was issued at 0925 (5 minutes after the accident) and was valid from 0900 to 1800. The expected weather conditions were:
From 0900 to 1300: wind variable at 3 kt with visibility 10 km or greater. Light rain showers with cloud scattered at 1,000 ft and broken at 2,000 ft.
For whole forecast period, 0900 to 1800: TEMPO – winds gusting from 20 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,500 ft.
Graphical area forecasts
A GAF was issued at 0835 and was valid from 0900 to 1500 and applicable from surface to 10,000 ft. This covered the Queensland-North region, which was divided into 6 areas for this forecast. Most of the flight including the arrival at Lockhart River was within one area that was forecast to have the following conditions:
Broken stratus 1,000 ft to 2,000 ft with broken cumulus/stratocumulus above that. Visibility reduced to 6,000 m in widespread rain.
Isolated towering cumulus from 2,000 ft, broken stratus from 800 to 2,000 ft, and broken cumulus/stratocumulus from 2,000 ft. Visibility reduced to 2,000 m in scattered rain showers.
Isolated cumulonimbus from 2,000 ft and broken status between 500 ft and 1,000 ft. Visibility reduced to 500 m in isolated thunderstorm rain showers.
A GPWT forecast was issued at 0538 and was valid to 1000. Lockhart River was located near the intersection of 4 data boxes and therefore roughly equidistant from 4 forecast locations. Taking 2,000 ft as a reference height for the approaches and coastal data as more relevant, the wind was forecast to be from the north-west at 9 kt increasing to 21 kt north of Lockhart River.
There were no significant weather warnings applicable to the flight.
Weather conditions - overview
The Bureau of Meteorology provided an overview to the ATSB of the actual weather conditions at Lockhart River on the day of the accident. It stated that a developing monsoon trough extended across Cape York Peninsula crossing the coast near Weipa and Lockhart River. A tropical low was embedded in the trough and was near Weipa at 1000, moving slowly eastward. The monsoon trough and low were causing scattered to widespread rain and isolated thunderstorms over much of Cape York Peninsula.
The surface winds at Lockhart River Airport were generally light and variable. Automatic weather sensors detected rain and heavy rain reducing visibility to 800 m and scattered to broken layers of cloud as low as 1,100 ft above ground level.
Aerodrome weather reports for Lockhart River
The METARs for Lockhart River were automatically generated every 30 minutes for routine reports and were issued as a special report (SPECI) at other times when one or more elements met specified criteria for degradation and improvement. For the period from 0830 to 0929 on 11 March 2020, the reports included:
0830: nil wind, visibility[39] 10 km or greater with rain and scattered cloud from 3,000 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
0900: nil wind, visibility 10 km or greater with rain and broken cloud at 2,000 ft, 3,500 ft, and 4,100 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0910: nil wind, visibility 10 km or greater with rain and broken cloud at 1,800 ft and 3,400 ft then overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0913: nil wind, visibility 3,800 m with rain and broken cloud at 1,800 ft and 3,400 ft, overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 2.2 mm.
SPECI 0929: wind westerly at 5 kt, visibility 8,000 m with heavy rain and scattered cloud at 1,200 ft, broken cloud at 1,900 ft, and broken cloud at 3,600 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm and rainfall since 0900 was 3.8 mm.
The QNH remained at 1,008 hPa during this period.
Automatic weather station
The Bureau of Meteorology (BoM) provided data from the Lockhart River Airport automatic weather station (AWS) recorded at 1-minute intervals. Table 3 details 1-minute rainfall, 30-minute cloud and 10-minute visibility data for the period encompassing the aircraft’s first approach prior to the final approach fix (FAF) at 0904 to the accident at 0920. The last column in the table indicates the 1-minute visibility associated with the telephone message for the aerodrome’s automated weather information service (see following section section). More detailed information from the Lockhart River AWS for the period 0850 to 0930 is provided in Appendix C – Detailed 1-minute weather data Lockhart River 0850–0930.
Table 3: Extract of 1-minute weather data from Lockhart River Airport AWS
The first shaded area indicates when the aircraft was at the MAPt on the first approach and the second shaded area indicates the time of the accident on the second approach. The 1-minute visibility data was that recorded to be broadcast by the AWIS by telephone. The times have been displaced by 1 minute (back) to align with the 1-minute rainfall data provided by BoM. The cloud data was averaged over the previous 30 minutes (see description in report text).
Source: Bureau of Meteorology
The cloud information was derived using a sky condition algorithm. This involved taking a sample (using a ceilometer at the aerodrome) at least every 30 seconds and averaging the data over a 30-minute period, with samples taken in the last 10 minutes provided double weighting.[40] Although this algorithm provided more stable estimates of cloud than each sample, the reported cloud for any given minute did not necessarily reflect the cloud level at that specific point in time.[41]
The visibility meter estimated atmospheric visibility based on the continuous sampling of a single point, providing a measurement of the prevailing visibility at the sensor. However, it sampled a relatively small volume of air in the immediate vicinity of the instrument and, unlike a human observer, was not capable of estimating visibility in different directions or over longer distances. One-minute data was based on the last 60 seconds of sensor output, as an average based on a processing algorithm. The 10-minute data recorded each minute was the average value over the previous 10 minutes.
A number of factors can affect the accuracy of the reported visibility, including:
discrete air masses, such as a shower of rain or a bank of fog, will not be identified unless the sensor is engulfed, and if the phenomenon is not of uniform density the visibility will be misreported
stationary localised patches of fog will remain undetected if the sensor is clear of fog, or if the sensor is within the patch of fog the reported visibility may be less than actual.
The temperature and dewpoint were about 25 °C for the duration with the relative humidity at 99% (increasing to 100% from 0917).
The reported wind speeds and directions were the mean values at 10 m above ground level, averaged over the last 1-minute period. The recorded wind was 0 kt until 0914, with speeds of 3–4 kt from the west, between 0916 and 0921.
Automated weather information service
Lockhart River was equipped with an automated weather information service (AWIS) that transmitted AWS data in text-to-speech format on a discrete VHF frequency. A new AWIS message was generated every minute in a similar format to the METAR reports. To produce the reports from the AWS 1-minute data, some averaging and rounding of the information occurred. The broadcasts were not recorded.
In addition, AWIS data at Lockhart River could also be accessed by telephone. A different phone message based on the AWS data was produced every minute and this was recorded. However, the AWIS information available by telephone was processed differently to the AWIS information available by VHF, and therefore there could be slight differences in the information produced at the same time.
During the flight, the pilot recorded the following data in the space allocated for arrival weather information in the flight plan/log:
calm (nil wind)
10 km (visibility)
B1800 (broken cloud at 1,800 ft)
B3500 (broken cloud at 3,500 ft)
OV 5300 (overcast cloud at 5,300 ft)
1008 (QNH 1,008 hPa)
25 (temperature 25 °C).
This information closely matched the recorded AWS 1-minute data at 0854, which stated (with expected transmitted message in brackets):
wind 0 kt at 023° (wind calm)
visibility 10 km (visibility one zero)
(present weather – rain)
cloud 4 oktas[42] at 1,800 ft (cloud broken one thousand eight hundred)
cloud 5 oktas at 3,500 ft (broken three thousand five hundred)
cloud 7 oktas at 5,300 ft (broken five thousand three hundred)
temperature 25.4 °C (temperature two five)
dewpoint 25.2 °C (dewpoint two five)
QNH 1,008.5 hPa (QNH one zero zero eight hectopascals)
rainfall last 10 minutes 0.4 mm (rainfall last ten minutes zero decimal four millimetres).
The pilot’s recorded weather information was also broadly consistent with the recorded AWIS messages available by phone for the period 0853–0855. It did not closely match any of the other recorded AWS 1-minute data or the recorded AWIS messages available by phone during 0840–0920. Accordingly, it is very likely that the pilot wrote down the AWIS data accessed by VHF radio at about 0854. It could not be determined whether the pilot additionally accessed the AWIS data prior to this time and/or after this time.
The AWIS broadcasted the most recent 1-minute visibility data measured by the AWS (see Table 3, last column). This data indicated visibility below the landing minima (4,200 m) at the AWS site between 0911 and 0915, and at 0917.
BoM operated a network of weather watch radars around Australia that detected water droplets in the atmosphere. Information from the weather radar was displayed on a map, with different colours depicting the approximate rainfall/precipitation intensity.
The nearest weather radar was at Weipa, approximately 150 km west of Lockhart River. Coverage in the vicinity of Lockhart River was affected by the distance from the radar and terrain, reducing the radar’s ability to detect low-level showers. However, precipitation at higher altitudes would still produce radar echoes.
Figure 11 provides an indication of the weather around Lockhart River at 0918 on the morning of the accident (during the second approach), with Figure 12 displaying an extract of radar images from the time of the first approach and the time of the accident. The weather radar depicted areas of moderate precipitation in the vicinity of Lockhart River. In addition, an analysis of a sequential series of images showed precipitation moving through the area at a speed of about 30 kt (55 km/h) from the north-west.
The minute-by-minute data from the AWS around the time of the accident (see Automatic weather station and Table 3) recorded no significant surface wind. However, there was a short period of rainfall between 0910 and 0916, including moderate to heavy rainfall between 0912 and 0914. If this rainfall persisted and continued moving in a direction/speed consistent with the observed radar returns, it would have been in the vicinity of the accident site about the time of the accident.
Figure 11: Weipa radar image at 0918 EST (about 2 minutes prior to the accident) showing weather in Lockhart River area (circled, approximate radius 25 NM/46 km)
Source: Bureau of Meteorology, annotated by the ATSB
Figure 12: Extract of Weipa radar images at 0906 (time of the first approach) and 0918 EST showing rain rate on the approach path to runway 30 at Lockhart River Airport
Source: Bureau of Meteorology, annotated by the ATSB
Local weather observations
Two pilots were operating aircraft in the Lockhart River area before and after the accident. The first pilot, operating before the accident, tracked to Lockhart River from the south and conducted the RNAV GNSS runway 30 approach, landing at 0810. There were intermittent rain showers in the area and the pilot advised that the end of the runway was visible while descending through 1,000 ft. The pilot remained on the ground at Lockhart River until later in the day and heard an aircraft (VH-OZO) fly over at high engine power. They recalled that, at that time, there was scattered low cloud at 500–1,000 ft with reduced visibility in rain showers.
The following pilot, operating after the accident, tracked to Lockhart River from the south-west and diverted 15 NM to the right of track due to weather. On arrival, the pilot conducted the Lockhart River RNAV GNSS runway 30 approach and landed at 0953. The pilot reported that there was rain in the area and, although the conditions allowed visual navigation after the final approach fix (FAF) while descending through 1,500 ft, the runway was not visible until later in the approach.
A person who was near the airport at the time of the accident described the conditions as an unusual morning with mist coming from the rainforest, and that there was about 5 to 10 minutes of heavy rain at about the time the aircraft would have been in the area. At that time, there was low-lying cloud (north-west of the airport) and no wind.
Fishermen who were in the area at the time reported that, at about the time of the second approach, there was a ‘wall’ of heavy rain that came across from the north-west.
Instrument approach
Overview
An instrument approach is a published procedure that allows for safe navigation of an aircraft operating in instrument meteorological conditions (IMC) to descend from the lowest safe altitude to a specified position (missed approach point - MAPt) near the aerodrome. If the conditions are suitable, the approach can be continued to land. If the conditions are not suitable, the pilot must conduct a missed approach in accordance with the procedure.
There are 2 general categories of instrument approach:
2-dimensional (2D) – lateral/tracking guidance only, also known as non-precision approaches or LNAV (lateral navigation)
3-dimensional (3D) – lateral/tracking and vertical guidance, including precision approaches such as an instrument landing system (ILS) approach and a (non-precision) approach with vertical guidance (APV).
Both categories of instrument approaches were only conducted utilising ground-based navigation aids until RNAV GNSS[43] approaches were available in Australia from 1998.
An RNAV GNSS approach is a 2D instrument approach that utilises an on-board GPS receiver (or flight management system - FMS) to generate lateral/tracking guidance and distance information. These approaches are pre-programmed in a GPS/navigation system’s database. Other types of non-precision approaches use ground-based aids such as a non-directional beacon (NDB) or a VHF omni directional radio range (VOR).
The transition in Australia from navigation reliant on ground-based navaids to performance-based navigation is continuing. As part of that process, Airservices Australia has been implementing barometric vertical navigation (Baro-VNAV) APV approaches since 2016. These 3D approaches are restricted to runways with a validated (LNAV/VNAV RNP APCH) procedure and aircraft with the applicable avionics, typically an FMS. Although these approaches were available at Lockhart River from 3 December 2020, VH-OZO was not Baro-VNAV capable.[44]
RNAV GNSS approach design
RNAV GNSS approaches in Australia have a Y-pattern, runway-aligned design. The Lockhart River runway 30 RNAV GNSS approach uses this typical layout, as shown in Figure 13.
Figure 13: Extract from Lockhart River RNAV GNSS runway 30 approach chart showing layout of waypoints
Source: Airservices Australia, annotated by the ATSB
The approaches have 3 initial approach fixes (IAFs, in this case, LHREA, LHREB and LHREC), followed by an intermediate fix (IF, LHREI), final approach fix (FAF, LHREF) and missed approach point (MAPt, LHREM).
The segment between an IAF and the IF is the initial approach segment, the segment between the IF and the FAF is the intermediate approach segment, and the segment between the FAF and the MAPt is the final approach segment. Each segment is typically 5 NM.
The intermediate approach track is normally aligned with the final approach track. One of the IAF waypoints is also aligned with the intermediate/final approach track (in this case, LHREB) and the other IAFs are located 70° off the intermediate/final approach track (LHREAS and LHREC). A pilot can commence an approach by flying to one of the 3 IAFs within the capture region for that waypoint. The capture region is a 140° arc for the IAF on the intermediate/final approach track and a 180° arc for the IAFs not on the intermediate/final approach track (with the extreme points parallel to the intermediate/final approach track).
Instrument approach waypoints can either be fly-by waypoints (which require turn anticipation to allow tangential interception of the next segment) or flyover waypoints (at which the turn is initiated). For RNAV GNSS approaches, the IAFs, IF and FAF are fly-by waypoints and the MAPt is a flyover waypoint.
The approaches are recommended to be flown using a continuous descent angle.
The recommended profile published on approach charts consists of an initial approach altitude which then joins a constant descent to 50 ft above the runway threshold. The approach path angle of the descent is normally (and ideally) 3°. Depending on the approach, the initial approach altitude joins the constant descent profile at about the FAF or earlier.
For example, the approach chart for the Lockhart River runway 30 approach (Figure 14) had an initial approach altitude of 3,500 ft leading to an approach path angle of 3°, which commenced 0.8 NM after the IF (4.2 NM prior to the FAF and 9.2 NM prior to the MAPt).
Figure 14: Excerpt from Lockhart River RNAV (GNSS) runway 30 approach chart showing recommended vertical profile and segment minima safe altitudes
The full approach chart is provided in Figure 2.
Source: Airservices Australia, annotated by the ATSB
Each segment of an RNAV GNSS approach has one or more specified segment minimum safe altitudes, depicted by shading on the chart’s profile diagram and the relevant altitude with a solid line underneath. For example, between the IF and the FAF on the runway 30 approach, the segment minimum safe altitude was 1,800 ft. The last segment minimum safe altitude, in the final approach segment, is the minimum descent altitude (MDA).
During an instrument approach, a pilot is able to descend below the recommended descent profile, but they are not allowed to descend below a segment minimum safe altitude, except for the MDA if certain conditions are met (as discussed below).[45] However, as stated in the Civil Aviation Advisory Publication (CAAP) 178-1(2) (Non-precision approaches (NPA) & approaches with vertical guidance (APV)):
While some pilots in the past have flown NPAs as a series of descending steps conforming to the minimum published altitudes, (a technique colloquially referred to as the ‘dive and drive’), CASA recommends a constant angle descent in a stabilised configuration. Many Controlled Flight into Terrain (CFIT) accidents have been attributed to the ‘dive and drive’ technique, due to human errors such as early descent before a step or failing to arrest descent. In addition, the aircraft’s descent is more difficult to manage due to changes in airspeed, rate of descent and configuration.
If the recommended descent profile starts prior to the FAF, the RNAV GNSS approach chart includes an advisory crossing altitude (or procedure height) at the FAF (and if required the IF) to assist pilots with maintaining the recommended descent profile (for example, 2,160 ft at the FAF in Figure 14). In addition, a pilot is provided with a distance/altitude scale on the approach chart that provides guidance for the recommended descent profile (see top of Figure 14). The distance specified is the distance to the next waypoint.
Approach waypoint naming convention
The waypoints documented on an RNAV GNSS approach chart are identified by a unique identifier comprising the airport identifier (in this case LHR), compass quadrant from which the approach is flown (E - east), and position on the approach (A, B, C, I, F, M or H).
During the investigation, some flight examiners stated that pilots occasionally misidentified waypoints (due to their similar names) and believed that they were on a different segment of the approach than they actually were. One flight examiner noted that this was more likely to occur when coming straight in via the IAF ‘B’ rather than when coming via one of the other 2 IAFs. This flight examiner also noted that one operator they worked with had introduced call-out requirement for pilots to annunciate that they were tracking from one waypoint to another in order to minimise this risk.
Conducting an approach
Before conducting the approach, the pilot must ensure they are qualified for RNAV GNSS approaches and satisfy the recent experience requirements. The aircraft must be equipped with an approved GPS receiver with a valid aeronautical database. It is also essential that the availability of receiver autonomous integrity monitoring (RAIM) is checked pre-flight and before entering the approach.[46]
To conduct the approach, the pilot selects the specific approach and IAF in the GPS unit (or FMS) and tracks towards the applicable IAF within the capture region. Prior to passing the IAF, a pilot must set the QNH to either the actual aerodrome QNH (from an approved source such as AWIS) or the aerodrome/area forecast QNH.
As the approach proceeds, the GPS (or FMS) will automatically sequence through the waypoints, displaying the next waypoint and distance to that waypoint. The pilot maintains the track with reference to the associated course deviation indicator (CDI).
To maintain the recommended descent profile (without electronic vertical guidance), pilots are required to:
establish a 3° descent by managing the descent rate proportional to the groundspeed (through engine power and pitch angle)
with reference to the altimeter, monitor the aircraft’s altitude - relative to the distance from the next waypoint with reference to the table on the approach chart and/or when passing waypoints with advisory altitudes
adjust the descent rate and/or groundspeed as required to correct the profile
level at the MDA and continue tracking to the MAPt unless the conditions are suitable for continuation of the approach.
The height of the MDA above the aerodrome elevation and the required visibility (in km) to complete the approach were included as bracketed figures after the MDA. If the minima label boxes on the approach chart were shaded, the MDA could be reduced by 100 ft when the actual aerodrome QNH was set. For example, for the accident flight, the pilot had noted the actual QNH so the 830 ft MDA could be reduced to 730 ft (Figure 15). At the lower MDA, the aircraft would be 653 ft above the aerodrome elevation and the minimum required visibility was 4.2 km. Practically, if the visibility was at the minima value, the pilot would see the runway threshold before the MAPt and, if the aircraft was on the recommended profile, by the MDA.
Figure 15: Excerpt from Lockhart River RNAV GNSS runway 30 approach chart showing minima table
The full approach chart is provided in Figure 2.
Source: Airservices Australia
The Aeronautical Information Publication (AIP) outlined several instructions or methods for pilots regarding the conduct of instrument approaches, in addition to those specified by an operator’s operations manual. CAO 20.91 (Instructions and directions for performance-based navigation, Instrument 2014) also applied to the operation of Australian aircraft using performance-based navigation (which included RNAV approaches during IFR flight), providing instructions/directions to operators and pilots conducting those operations. Relevant CAO and AIP requirements, instructions and methods are outlined in subsequent sections below.
Descent below the minimum descent altitude
After passing the FAF, a pilot is permitted to descend to the MDA (provided the aircraft is within navigational tolerances). Further descent below the MDA must not be made without the required visual reference. There may be different MDAs specified for a straight-in or circling approach. Descent below the straight-in approach MDA could only be conducted (AIP ENR 1.5, 1.8.2)[47] when:
visual reference can be maintained;
all elements of the meteorological minima are equal to or greater than those published for the aircraft performance category…; and
the aircraft is continuously in a position from which a descent to a landing on the intended runway can be made at a normal rate of descent using normal flight manoeuvres that will allow touchdown to occur within the touchdown zone of the runway of intended landing.
The AIP also stated that, if visual reference is not established at or before reaching the MAPt, a missed approach must be executed (ENR 1.5, 1.10.1).
The competencies and standards required for an initial instrument rating and IPCs were specified in the CASR Part 61 Manual of Standards (MOS). For a 2D approach, the required tolerance was within +100 ft at the MDA but not below it.
Lateral tolerances
The AIP stated that instrument approach procedures were based on specific navigation aids, ‘with the applicable navigation tolerances associated with the aids being used in the development of the procedure’s obstacle protection surfaces.’ For an RNAV GNSS approach, CAO 20.91 stated that the lateral tracking tolerances were 1.0 NM (1,852 m) for the initial, intermediate and missed approach segments (terminal area operations) and 0.3 NM (556 m) for the final approach segment.
Navigational equipment could be designed so that full-scale deflection on the CDI represented the required navigation performance (RNP) lateral tracking tolerance during that phase of flight. For an RNAV GNSS approach, this would typically be represented as a lateral 1 NM displacement being represented as a full-scale CDI deflection during the initial segment and most of the intermediate segment, then transitioning from about 2 NM (3,704 m) prior to the FAF to a 0.3 NM displacement being full-scale deflection about 1 NM after reaching the FAF (Figure 16).
The GNS 400W-series manual indicated that the CDI full-scale deflection varied during the final approach segment.[48] When conducting an RNAV GNSS approach using a GNS 400W-series unit, the full-scale deflection was 350 ft (0.06 NM or 107 m) at the MAPt, diverging back to the FAF at an angle of either 2° to the final approach track, or an angle such to achieve 0.3 NM full-scale deflection at the FAF, whichever was less (Figure 16).[49] For 5 NM final approach segments, the angular 2° would always be less than the lateral 0.3 NM CDI full-scale deflection at the FAF.
Figure 16: Conventional transition from RNP 1.0 to RNP 0.3 NM during final approach segment (represented by full-scale CDI deflection) compared to the full-scale CDI deflection provided by the GNS 400W-series GPS
Source: ATSB, derived from information contained in ICAO Doc 8168 Procedures for Air Navigation Services-Aircraft Operations, Vol II − Construction of Visual and Instrument Flight Procedures and the Garmin GNS 400W-Series Pilot’s Guide & Reference manual.
For the 5 NM final approach segment for the runway 30 approach at Lockhart River, an angular 2° to the final approach track displaced 350 ft (107 m) at the MAPt equated to 0.23 NM (430 m) at the FAF. The transition from 1.0 NM full-scale deflection during the intermediate segment to the 2° automatic rescaling full-scale deflection for the final approach segment commenced 2 NM prior to reaching the FAF and was completed by the FAF. In other words, during the final approach segment, GNS 400W series units presented CDI full-scale defection that was less than the lateral tracking limit specified in CAO 20.91 for the final approach segment. This difference was relatively minor at the FAF (0.3 NM versus 0.23 NM) but increased significantly as the aircraft got closer to the MAPt.
When using the GNS 400-series units, if the CDI exceeded a full-scale deflection, a green arrow and distance was displayed on the default navigation page’s CDI, indicating the direction (left or right) and distance the aircraft was displaced (in NM) from the required track.
For a straight-in, area navigation-based approach (such as the RNAV GNSS approach to runway 30 at Lockhart River), the AIP (ENR 1.5, 1.21) stated that an aircraft was required to:
…pass the waypoint, and when established on the specified track, descend to not below the specified altitude….
Note: “Established” means being within half full scale deflection for the ILS, VOR and GNSS... [50]
The AIP (ENR 1.5, 1.10.1) also stated that a missed approach had to be conducted if:
…during the final segment of an instrument approach, the aircraft is not maintained within the applicable navigation tolerance for the aid in use…
CAO 20.91, Appendix 6, contained operating standards for conducting an RNAV GNSS approach, which included the requirement to commence a missed approach if the cross-track error/deviation equalled or was reasonably likely to equal the RNP for that segment of the approach (that is, 1.0 NM for the initial and intermediate segments and 0.3 NM during the final approach segment).
In other words, to comply with the AIP, after passing the FAF, the aircraft needed to be established within half full-scale deflection before descending below the previous segment’s MSA. If the aircraft was established within half full-scale deflection, the descent could continue to an altitude not below the segment minimum safe altitude, which in this case was the MDA.[51] In addition, to comply with CAO 20.91, a pilot was required to conduct a missed approach if the aircraft was laterally displaced 0.3 NM or more from the final approach track.
CASA advised the ATSB that there was, in the aviation community, a commonly held misconception that half full-scale deflection was the required tracking tolerance limit. This was potentially related to a number of factors, such as:
CAO 20.91 included a note that stated ‘So far as practicable, the cross-track error/deviation for normal operations should be limited to 0.5 NM (½ x RNP) for the initial segment, the intermediate segment and a missed approach, and to 0.15 NM (½ x RNP) for the final approach segment. Brief deviations are acceptable during and immediately after turns where accurate cross-track information is not provided during the turn.’ This reference to half the RNP was providing a target level of safety rather than a minimum acceptable level of safety.
The CASR Part 61 MOS required tolerance when assessing a pilot’s competency for a 2D approach was within half full-scale deflection.
CAAP 179A-1(1) (Navigation using the Global Navigation Satellite Systems (GNSS)), issued in 2006, stated (erroneously) that for an RNAV GNSS approach that ‘The tracking tolerance is half of full-scale deflection regardless of the CDI scale’.[52]
CASA advised that operators could choose to specify a more restrictive lateral tracking requirement than that stated in CAO 20.91. If an operator specified a more restrictive limit (such as half RNP or half full-scale deflection), and included that in its operations manual, then that limit would be the applicable limit for that operator.
As discussed in Operator’s stabilised approach criteria, the operator of VH-OZO specified in its operations manual that a missed approach was required if an aircraft on an RNAV approach was not within ‘half scale deflection’ at the FAF. The ATSB is aware through its investigations that a number of other operators also specified a similar requirement for initiation of a missed approach.
Handling speeds
The AIP (ENR 1.5, 1.16) stipulated handling airspeeds for aircraft during instrument approaches based on the aircraft’s performance category. Aircraft performance categories were based on an indicated airspeed at the runway threshold (VAT).[53]
The Cessna 404 VAT was 91 kt. Therefore, the performance category for the Cessna 404 was category B, which applied to aircraft with a VAT of 91–120 kt.
The relevant handling speeds for instrument approaches for category B aircraft were:
120 to 180 kt for the initial and intermediate approach segments
85 to 130 kt for the final approach segments
maximum 150 kt for the missed approach.
A note in the AIP stated that a pilot was permitted to reduce the speed below the minimum in the initial/intermediate segments ‘to enable the final approach speed to be achieved prior to the commencement of the final segment’. In other words, for a category B aircraft, a pilot could operate below 120 kt prior to reaching the FAF but they could not operate above 180 kt.
The AIP handling speeds are broad speed bands used for purposes such as ensuring aircraft remain within the design tolerances for instrument approach procedures. Operators should provide more specific guidance regarding the appropriate speeds to use during instrument approaches for their aircraft types (see Flight profiles).
The AIP also stated that the descent rate after the FAF ‘should not normally exceed’ 1,000 ft/min.
Instrument flying and workload
Single pilot IFR operations are widely regarded to be among the most difficult and/or involve the highest workload. As stated by the US Aircraft Owners and Pilots Association (AOPA) in 2006:
No type of flying requires greater skill or longer periods of concentration than [single-pilot IFR] SPIFR…
Very simply, the problem is pilot workload, aggravated by the need for multi-tasking. A single IFR pilot also serves as navigator, radio operator, systems manager, onboard meteorologist, record keeper, and sometimes, flight attendant. En route flight in benign weather is usually not too stressful, but add high-density traffic in poor weather conditions or a significant equipment malfunction, and overload may not be far away.
In instrument flight, the pilot maintains an awareness of the aircraft’s spatial position by reference to instruments rather than outside visual references. The fundamental skills of instrument flight are instrument scanning and instrument interpretation. Instrument scanning is ‘the continuous and logical observation of instruments for attitude and performance information’ (FAA 2012).
In any phase of flight or manoeuvre, there are primary instruments that give the most pertinent information and supporting instruments that assist in their continued correct interpretation. For example, even when the aircraft is established in a constant-rate descent, and trimmed to remove control pressure on the yoke, it is necessary for the pilot to continuously check relevant instruments and make appropriate control adjustments to maintain aircraft performance and control.
With proficiency, a pilot scans at an appropriate rate and is able to interpret the instruments to maintain an accurate mental picture of what is happening. An ineffective scan, such as fixation on one instrument or the omission of another, or misinterpretation of the displayed information, can result in a pilot having an incorrect mental model of the aircraft’s position or flight path.
More generally, workload is described by Wickens and others (2013) as follows:
Mental workload characterizes the demands of tasks imposed on the limited information processing capacity of the brain in much the same way that physical workload characterises the energy demands upon the muscles. In any resource-limited system, the most relevant measure of demand is specified relative to the supply of available resources...
People experience workload differently, based on their individual capabilities and the local conditions at the time such as training and experience in the situation at hand and the operational demands during that phase of flight (Orlady and Orlady 1999). When workload gets too high for the available resources task shedding occurs (Wickens and others 2013).
Dismukes and others (2007) discussed task shedding in this context, explaining that a pilot may move from a proactive assessment of the situation, commonly referred to in aviation as ‘being ahead of the aircraft’, to a reactive situation, where the pilot is responding to events as they occur without an overall strategy to manage the situation (that is, being behind the aircraft). Wickens and others (2013) further explained that task shedding can result in some tasks being shed altogether, and others being shed in a non-optimal manner. In addition, tasks such as internal and external communication are often shed during periods of high workload.
Holmes and others (2003) stated that distractions and high workload can result in a pilot scanning fewer instruments and checking them less frequently. High workload can also lead to a reduction in the number of information sources that an individual will search, as well as the frequency or amount of time these sources are checked (Staal 2004). Additionally, vigilance tasks, such as monitoring flight instruments, require sustained attention with the associated eye movements being fatiguing (Wickens and others 2013).
The United Kingdom Civil Aviation publication, Monitoring Matters, provided information regarding monitoring and stated:
… whilst you are ahead of the game, concentrating on the next event, keeping an eye on all the flight parameters, system modes etc, everything runs fairly smoothly. But as soon as something draws your attention away and you become out of the loop it becomes difficult to play catch up.
Although it is possible to attend to more than one task using selective attention techniques, there is a limit to cognitive capacity. If tasks consume this capacity, that is when task shedding will occur. This publication further advised that under high workload, especially during approach and descent, attention capacity diminishes. This includes the ability to detect when the configuration of the aircraft is not correct, even when there is an aural or visual alert, particularly in the case of single-pilot operations as:
…the processes and procedures will be equivalent to multi crew operation except there will only be one person in the cockpit and the systems may be less automated. Hence the need to monitor the flight profile, flight instruments, fuel state, engines, radios, etc. diligently. The instrument scan must be carried out very frequently, especially during departure and approach in order to monitor the aircraft state and planned profile.
In addition to being a complex skill to acquire, instrument flying skills needs to be maintained by frequent practice (Newman 2007). As stated by CASA in 2016 (Changes to instrument proficiency checks):
Conducting IFR operations is a relatively high risk activity and so requires dedicated knowledge and practical flight training… Skill-based qualifications, like the instrument rating, require the qualification holder to maintain their skills and operational knowledge. Skills and knowledge degrade over time. In the interests of safety, rules are put in place to ensure pilots are sufficiently competent conducting IFR operations.
Accordingly, there are requirements in place for pilots conducting IFR operations to regularly undertake proficiency checks (Proficiency checks and flight reviews) and have recent experience (Monitoring of pilot recency). In general, skill decay or skill degradation increases as the retention interval (or time since learning) increases, and it also increases depending on the quantity and quality of the initial and recurrent training and the amount of task exposure (Arthur and others 1998, Sanli and others 2018, Vlasblom and others 2020). Skill decay has various effects, such as preventing the development of further expertise and decreasing spare mental capacity. As noted by the European Aviation Safety Agency (2021):
Proficiency decay in only a few skills may lead to time management issues, reduced situation awareness, and the ability to keep ahead of the situation. In non-normal situations or emergencies, appropriate actions may not be taken due to one’s inability to analyse the situation as a result of the cognitive overload.
RNAV GNSS approach workload
There has been limited research that has compared different types of instrument approaches, and specifically looked at RNAV GNSS approaches. Research was conducted by the ATSB following a CFIT accident on an RNAV GNSS approach at Lockhart River in 2005 (Godley, 2006). The study found that, for pilots of smaller single-engine and twin-engine aircraft, pilot workload was perceived as being higher, and reported losses of situational awareness were more common, for RNAV GNSS approaches compared to other approach types except for NDB non-precision approaches.
In contrast, pilots of larger aircraft found that RNAV GNSS approaches were not as problematic, with the workload only being higher than ILS (precision) approaches. The different aircraft category responses were likely to have been due to high capacity aircraft having advanced automation capabilities and operating mostly in controlled airspace. Such aircraft were also more likely to have an FMS rather than a GPS unit.
The concern most respondents had regarding the design of RNAV GNSS approaches was that they did not use references for distance to the missed approach point on the approach chart and cockpit displays (in contrast to previous types of approaches). Other problems raised were short and irregular segment distances and multiple minimum segment altitude steps, that the RNAV GNSS approach chart was the most difficult chart to interpret, and that five letter long waypoint names differing only by the last letter can easily be misread. The most common incident reported with RNAV GNSS approaches was commencing the descent too early due to a misinterpretation of position.
It should be noted that at the time of this research, many GPS units displays only provided numerical data rather than a map view of the aircraft’s lateral position (such as with the GNS 430W). In addition, RNAV GNSS approaches have become more common and pilots have become more familiar with them, and the design of RNAV GNSS approach charts has improved.
Recorded flight data
General information
The aircraft was not fitted with a flight data recorder or cockpit voice recorder, nor was it required for the type of aircraft and operation.
The ATSB obtained data broadcast by the automatic dependent surveillance broadcast (ADS-B)[54] equipment fitted to the aircraft and GPS data from the pilot’s iPad with the OzRunways[55] application installed. The data included:
timestamp
latitude and longitude
pressure altitude (from the ADS-B data) – rounded to the nearest 100 ft (for example, 498 ft would be rounded to 500 ft)
GPS altitude (from OzRunways) – truncated to 100 ft (for example, 498 ft would be presented as 400 ft)
groundspeed.
The lateral location (latitude and longitude) from OzRunways and ADS-B-based data were in close agreement. This indicated that the data from OzRunways was sufficiently reliable to show the aircraft’s lateral flight path.
The pressure altitude data from the ADS-B data was fairly consistently 100 ft higher than the OzRunways GPS height, which was partially due to the ADS-B data being rounded to the nearest 100 ft and the OzRunways data being truncated to the nearest 100 ft. In addition, the local QNH was 1,008.5 to 1,008.9 hPa during the period from 0900 to 0921, lower than the standard 1,013.25 hPa datum for pressure altitude. This would result in an altimeter set to the local QNH reading about 130–140 ft lower than the pressure altitude.[56] Thus, within the applicable errors, the altitudes from the 2 sources were consistent.
The OzRunways data points were provided at 5-second intervals, with some data points missing, and they covered the whole flight (including all of the 2 approaches), whereas the ADS-B data points were only available for parts of the approaches and/or were provided at less frequent intervals. As such, the OzRunways data is used in this report.
Figure 17 depicts the recorded data for the first and second approaches from the initial approach fix (IAF), through the intermediate fix (IF) and final approach fix (FAF) and to the missed approach point (MAPt). The top panel displays the aircraft’s altitude, the middle panel displays the lateral position, and the bottom panel displays the groundspeed. All distances on the horizontal axes are relative to the next waypoint, as would be displayed to the pilot on the GPS unit during the approach.
Figure 17: Recorded data for first and second approaches to Lockhart River
The upper panel shows altitude, the middle panel shows lateral deviation from the instrument approach path and the lower panel shows groundspeed. The purple bands on the groundspeed panel refer to the handling speeds (for indicated airspeed) specified in the Aeronautical Information Publication for a category B aircraft, such as the Cessna 404 (see Handling speeds).
Source: OzRunways data overlaid with Airservices approach information, annotated by the ATSB
Altitude during approaches
The top panel of Figure 17 shows the 3° approach path guidance (recommended descent profile) to the MAPt, which commenced from the initial approach altitude of 3,500 ft about 9.2 NM from the MAPt. As previously noted, the minimum descent altitude (MDA) was 730 ft unless the pilot had the required visibility. Key aspects regarding the recorded altitude data included:
The first approach (in blue) was flown at or slightly above a 3° approach to the MAPt from significantly prior to the IAF until reaching 700 ft just prior to the MAPt. The average descent rate during the first approach from the IAF to the MAPt was about 720 ft/min.
Although not indicated on the figure, the aircraft kept descending and reached a recorded altitude of 400 ft[57] at about 0.5 NM past the MAPt or 0.9 NM (1,700 m) before the runway threshold. It remained at that recorded altitude over 3 data points, or until it was 0.5 NM (900 m) from the runway threshold. The next 2 data points were not recorded, with the subsequent recorded data point indicating an altitude of 600 ft as the aircraft passed the runway threshold.
ADS-B data was available for the latter part of the first approach, and this data indicated that the aircraft had still been descending when it reached the second of the 400-ft data points (0.7 NM or 1,300 m from the runway threshold), and had started climbing just before the third of the 400-ft data points (1,000 m from the threshold). The ADS-B data also provided recorded values of geometric altitude rate of change. This data indicated that just before and just after the MAPt the descent rate was about 900 ft/min, and at about the second 400-ft data point the descent rate was about 960 ft/min.
The second approach (in red) was flown at about 3,500 ft prior to and after passing the IAF, with the aircraft starting to descend at about 0914:48 when about 2.7 NM from the IF. From about 1.6 NM prior the IF (at 0915:18 and an altitude of 3,300 ft), this descent was flown at about a 3° flight path, although about 1,000 ft below the recommended descent profile.
The radio call commencing at 0915:50, when the pilot stated the position (10 NM) and altitude of the aircraft (3,800 ft then corrected to 2,800 ft), started about 0.4 NM prior to the IF. At 0915:58, about 0.2 NM prior to the IF, the aircraft was at a recorded height of 2,800 ft.
For the second approach, the descent rate was about 700 ft/min during the descent from 3,300 ft to about 700 ft (at 0919:08 and 3.3 NM before the MAPt). From 700 ft until 100 ft, the descent rate was about 1,200 ft/min. Given this last part of the descent was over a 30-second period, it probably indicates an actual change rather than the effect of truncated data.
During both approaches, there were several instances during descent where 2 data points in succession were at the same recorded altitude. There were also 2 occasions during the second approach where 3 data points in succession were at the same recorded altitude (at 700 ft and at 2,200 ft). Although this could indicate that the descent rate decreased to some extent at those altitudes, such patterns could also occur (at least in part) due to the data being truncated to the nearest 100 ft and the small amount of error associated with each GPS data point. A descent rate of about 700 ft/min would equate to about 60-ft difference every 5 seconds, whereas a descent rate of 600 ft/min would equate to about a 50-ft difference every 5 seconds.
Lateral position during approaches
Figure 17 depicts the lateral paths flown on the 2 approaches relative to the lateral track prescribed for the approach (shown as a dash-dot line). Dotted lines depict the full-scale CDI deflection on the Garmin GNS 430W and show the scale transitioning from 1 NM full-scale deflection during the intermediate approach segment to 0.23 NM full-scale deflection at the FAF, narrowing to 0.06 NM full-scale deflection at the MAPt. The aircraft’s position is based on GPS data; the actual CDI values displayed to the pilot were not recorded.
Key aspects regarding the lateral position data include:
The flight paths for both approaches were consistent with the pilot hand-flying the aircraft, rather than the autopilot maintaining a programmed track.
The first approach passed the IAF LHREB in the middle of the capture region for that waypoint. The whole approach was contained within half full-scale deflection of the CDI.
For the second approach, the aircraft was just within the 180° capture region for the IAF LHREB when the pilot commenced the turn towards the IF LHREI (Figure 5). Prior to turning towards the initial approach track, the aircraft was on a track that was about 100° to the initial approach track.
On the second approach, the turn onto the track between the IAF and the IF resulted in the aircraft initially being displaced full-scale CDI deflection to the right, which was corrected soon after. The aircraft was also turned slightly late at the IF and overshot the waypoint, before being corrected back to the intermediate approach track.
About 3 NM before the FAF, the aircraft started deviating right of the intermediate approach track. About 2 NM before the FAF, the sensitivity of the CDI began increasing (as indicated by the dotted lines, see also Figure 17).
When passing the FAF on the second approach, the aircraft was at about full-scale CDI deflection (0.23 NM to the right), and it continued deviating further right of the final approach track for 25 seconds before starting to return closer to the final approach track. The aircraft remained outside full-scale deflection in the final approach segment for about 55 seconds and outside half-full scale deflection for an additional 5 seconds. From about 17 to 32 seconds after passing the FAF, the aircraft’s deviation equalled or slightly exceeded 0.3 NM to the right of the final approach track (the lateral tracking tolerance specified in CAO 20.91 for the final approach track).
The aircraft started to deviate left of the final approach track at about 2.5 NM prior to the MAPt and it continued left until the end of the recorded data.
Groundspeed during approaches
Deriving an estimate of indicated airspeed from groundspeed involves considering several factors. In this case:
The recorded wind at ground level indicated nil wind during the first approach and 3–4 kt from about 280° during the second approach. However, a review of wind and temperature forecast and analysis charts from multiple sources indicated that there would have been more wind at higher altitudes. Acknowledging that this was forecast and analysis data rather than recorded data, the ATSB estimated that there would have probably been about 10 kt headwind on the intermediate/final approach track at 2,300 ft and 5 kt at 1,000 ft. In addition, when the aircraft was heading towards the IAF on the second approach at 3,500 ft, and when the aircraft was heading from the IAF to the IF, there would have been a tailwind.
Air pressure and temperature differences from a standard atmosphere meant that calibrated airspeed would have been lower than the true airspeed, with this difference increasing as the altitude increased. The difference was about 10 kt at 3,500 ft and 5 kt at 1,100 ft.
The Cessna 404 Pilot’s Operating Handbook (POH) stated that the indicated airspeed at 140 kt was 1 kt higher than the calibrated airspeed with gear and flap up, 3 kt higher with gear down and flap selected to the take-off/approach position, and 5 kt higher with gear down and flap selected to the landing position. During the descent part of an approach, the operator’s flight profile stated the landing gear should be down and the flaps in the approach position (Flight profiles).[58]
Overall, the ATSB estimated that the indicated airspeed would have probably been close to (within 0 to +5 kt) of the recorded groundspeed during the 2 approaches while the aircraft was on or close to the intermediate/final approach track. For simplicity in this report, the groundspeed was considered to be equivalent to the indicated airspeed during these periods.
Key aspects of the recorded groundspeed (and estimated indicated airspeed) data for the 2 approaches include:
The groundspeed (and estimated indicated airspeed) for the first approach was about 130–140 kt for the whole approach between the IAF and the IF, and 130 kt at the FAF. It then increased to 140 kt before the aircraft reached 1,000 ft and then remained at about that speed as the aircraft passed through the MDA, passed the MAPt and passed the runway threshold.
For the second approach, the groundspeed when the aircraft was heading toward the IAF was about 185 kt, but the indicated airspeed was about 160 kt. After making the turn towards the IF, the groundspeed was about 160 kt and the indicated airspeed was about 145 kt.
Before commencing descent from 3,500 ft, at 0914:43, the groundspeed was about 150 kt and the indicated airspeed was about 135 kt. Soon after, there was a decrease in speed, which was probably associated with the pilot selecting approach flap and lowering the landing gear. The subsequent increase was probably associated with the aircraft’s descent.
Between the IF and the FAF, the groundspeed (and estimated indicated airspeed) was about 135 kt. It increased to 140 kt soon after passing the FAF and, when the aircraft was 3 NM from the MAPt, the groundspeed increased to about 150 kt (associated with the aircraft’s increased descent rate).
Wreckage and impact information
The accident site was located on a sand bank adjacent to the beach, about 6.4 km (3.5 NM) south-east of the runway 30 threshold at Lockhart River Airport and 500 m to the south-west of the specified final approach track. This location was about 2.1 NM (3.9 km) from the missed approach point (MAPt).
The accident site was in line with the aircraft’s recorded track over the previous 3 data points. It was about 200 m beyond the last recorded data point (which had a recorded height of 100 ft), and its location indicated that the impact occurred less than 3 seconds after the last recorded data point.
The wreckage trail was spread over a distance of about 20 m from the initial impact point and the trail indicated that the aircraft was on a heading of about 280° (magnetic), with the impact point about 30 ft above mean sea level (Figure 18).
Figure 18: Overview of accident site
Source: ATSB
The ATSB’s on-site examination of the wreckage, damage to surrounding vegetation and ground markings indicated that at initial impact the aircraft was:
upright and close to wings level
at a flight path angle of about 5° nose down
at relatively high speed.
An area of foliage around the aircraft displayed signs of chemical burn from avgas, indicating that the aircraft had a significant amount of fuel on board. There was no evidence of any structural or mechanical defects, but the examination was limited by the extensive damage.
The damage to the recovered propellor blades indicated significant rotational energy at impact consistent with both engines operating normally with substantial power.
The landing gear was extended at the time of impact. Other aircraft configuration information such as flap position, trim settings and switch selections could not be validated due to the impact damage.
The only components on the aircraft that may have recorded data were a digital fuel flow indicator/totaliser and a transponder, and the ATSB recovered these components. After consideration of the damage to these components and the potential value of any data, no further examination was undertaken.
Survivability aspects
Given the aircraft’s speed at impact (about 150 kt or 278 km/h) and the resultant impact forces (as evidenced by the nature of the wreckage), the accident was not considered survivable.
The aircraft was not fitted with a fixed emergency locator transmitter (ELT), nor was it required to be under the current regulations. A personal locator beacon (PLB) was in the pilot’s flight bag. Post-accident onsite examination noted it was within its expiry date and it passed a function test. PLBs do not have an inertial g-switch to automatically switch them on when an accident occurs, so the PLB did not activate during the accident sequence.
At 0934 and 0938, air traffic control (ATC) attempted to contact the pilot of VH-OZO after they had not cancelled or amended the SARTIME[59] of 0930. ATC also requested that the pilot of an inbound aircraft attempt to contact VH-OZO on the CTAF.
At 0939, an INCERFA was declared (which is a situation where uncertainty exists regarding the safety of an aircraft and its occupants) and soon after ATC transferred management of the situation to the Joint Rescue Coordination Centre (JRCC). At 1020, the JRCC advised ATC that it had declared a DETRESFA or distress phase (which is a situation where there is reasonable certainty that an aircraft and its occupants require immediate assistance). At 1251, the JRCC advised the ATSB that the wreckage at been located.
Organisational information
Air Connect Australia
Air Connect Australia was issued with an Air Operator’s Certificate (AOC) by the Civil Aviation Safety Authority (CASA) in March 2017 with an expiry date of 31 March 2020. It authorised the certificate holder to operate Cessna C310/340, C404, C402/421 and Raytheon Baron/Travelair twin piston-engine aeroplane types as well as single piston-engine aeroplane types with a MTOW not exceeding 5,700 kg on charter and aerial work operations.
At the time of the accident, CASA was assessing the operator’s application to renew the AOC, which was subsequently issued on 1 May 2020 with an expiry date of 30 September 2023.
From April 2017, the operator dry-leased VH-OZO from the aircraft owner, who was based in Western Australia. In this arrangement, the aircraft owner was responsible for the continuing airworthiness of the aircraft and the operator managed the operational aspects, such as fuel and flight crew.
Initially the operator’s personnel consisted of a chief pilot and the managing director, who was also the head of aircraft airworthiness and maintenance control. The chief pilot and managing director were the operator’s only line pilots. The chief pilot left in 2018, and the manager director became the chief pilot following an assessment by CASA.
In the 18 months prior to the accident, VH-OZO was the only aircraft operated and the operator employed one pilot (the pilot of the accident flight) additional to the chief pilot. As previously stated, the pilot of the accident flight conducted most of the operator’s flights.
Operator proficiency checks
To conduct IFR flights in a multi-engine aircraft, a pilot was required to complete an instrument proficiency check (IPC) every 12 months. The checks had to be conducted by a CASA-approved flight examiner. There were no additional requirements for proficiency checks for pilots conducting passenger charter operations under the IFR unless the operator had a check and training organisation as specified in Civil Aviation Regulation 217 (Training and checking organisation), which did not apply to operators such as Air Connect Australia.
CASR Part 135 (Australian air transport operations—smaller aeroplanes) was registered in December 2018 and commenced on 2 December 2021. It included a requirement for operators to conduct proficiency checks on pilots, with the requirements for such checks to be specified in the Manual of Standards (MOS). The draft Manual of Standards (MOS) for Part 135, publicly consulted in September 2018, included specific requirements for recurrent proficiency checks. For operators conducting IFR flights or flights at night, an operator proficiency check (OPCs) was required about 6 months after commencing unsupervised line operations for the operator and subsequently at intervals of 6 months. The MOS for Part 135 that came into effect in December 2021 had effectively the same requirements (with an OPC now called a ‘flight crew member proficiency check’).
Version 2 of the operator’s operations manual (February 2018) required an OPC to be conducted ‘every year’, with another section stating these needed to be completed ‘within the previous 12 months’. Version 3 of the manual (February 2020) required an OPC be conducted at the chief pilot’s discretion at periods not exceeding 24 months.[60] The manual stated that the OPC could be conducted by the chief pilot or a designated flight examiner.
The chief pilot noted that the flight examiner who regularly conducted IPCs for the operator (and was designated to conduct OPCs) would effectively conduct an OPC when they did an IPC. The change to every 24 months was done to provide more flexibility for scheduling checks.
In terms of the nature or content of the OPC, the operations manual stated that an OPC was required to be conducted
…on a flight encompassing all operations in which the pilot would normally be engaged. These flights will cover flight planning, refuelling, aircraft weight and balance, passenger briefing, forced landings and all emergency operations.
The manual also included an OPC form, which listed 23 items to be evaluated.
As previously discussed (Qualifications and experience), after the pilot of VH-OZO was cleared for line operations on 29 October 2018 (which included an OPC), the operator did not conduct any OPCs on the pilot. In addition, the chief pilot did not conduct any flights with the pilot after October 2018.
The pilot’s IPC in August 2019 was conducted with a flight examiner who was not familiar with the operator’s operations manual and therefore did not cover all aspects of an OPC, and the additional supervised training in December 2019 for night recency was done by an external provider and did not evaluate line operations.
Monitoring of pilot recency
CASR Part 61 outlined several different recency requirements. With relevance to the accident flight, these included a pilot not being able to:
conduct a flight with passengers by day in a particular category of aircraft unless had conducted 3 take-offs and landings within the previous 90 days in that category of aircraft (CASR 61.395 (1))
conduct a flight under the IFR unless had conducted at least 3 instrument approaches within the previous 90 days (CASR 61.870 (2))
conduct a flight under the IFR in a particular category of aircraft unless had conducted at least 1 instrument approach in the previous 90 days in that category of aircraft (CASR 61.870 (3))
conduct a 2D instrument approach unless had conducted at least one such approach in the previous 90 days (CASR 61.870 (4))
conduct a flight under the IFR in a single-pilot operation unless had conducted at least one single-pilot flight under the IFR in the previous 6 months that had a duration of at least 1 hour and involved one instrument approach (CASR 61.875).
The CASA website stated:
We use recent experience requirements to maintain a pilots knowledge and skills when conducting instrument approach operations.
When conducting an approach to satisfy a recent experience, pilots should recognise the purpose of the approach is to maintain their competency to conduct such operations.
Simulating IMC, when safe to do so, will enhance the purpose of the approach. Conducting the approach provides some effective practice…
As previously noted, the pilot had been regularly logging the conduct of RNAV GNSS approaches (Qualifications and experience) as well as other types of instrument approaches. The pilot met all required recency requirements listed above.
The operator used the Aerotrack aviation management tool. The tool could be used to manage flight scheduling, fleet operations, and crew recency and rostering to meet regulatory requirements. It also created an online pilot logbook, as it tracked all flights conducted for the operator, and totalled recency requirements such as IFR flight time and instrument approaches.
The Aerotrack system correctly tracked all of the recency requirements except for CASR 61.875. The system tracked the total number of single-pilot IFR flight hours over a rolling 6-month period, calculated as a sum of all hours logged including partial hours (such as 0.5 hours).[61] However, it was not programmed to track if a single-pilot flight under the IFR (of at least 1 hour duration) was conducted.
Regulatory oversight
In June 2017, CASA conducted a level-1 surveillance event on Air Connect Australia. CASA concluded that the operator was:
an overall compliant organisation with sufficiently equipped facilities and suitable qualified personnel conducting operations in accordance with its legislative authorisations and responsibilities.
The audit identified 5 non-compliance notices, including 3 relating to operations manual content regarding transponders, daily inspections and oil consumption records, and 2 relating to incomplete staff induction records for one pilot and the emergency proficiency checks for one pilot carried out by a person who was not the chief pilot. Other findings included 2 observations relating to job descriptions and one aircraft survey report finding. These findings were addressed by the operator.
In June 2018, CASA conducted a level-2 airworthiness and maintenance system surveillance activity relating to VH-OZO, prior to a flying operations inspector flying on the aircraft for the purpose of a chief pilot assessment. The surveillance report found there were no anomalies identified in either the technical documentation assessment or the physical inspection of the aircraft and the chief pilot assessment was then conducted.
In February 2020, CASA conducted a desk-top surveillance activity to determine if the AOC could be subsequently re-issued. The surveillance considered the organisation’s surveillance and compliance history, the management structure and operational oversight effectiveness. The review did not indicate any matter that would preclude a subsequent issue of the organisation’s AOC.
In May 2020, CASA conducted a post-accident regulatory and safety review. This review concluded that VH-OZO was correctly registered, certified for flight, maintained by qualified people, flown by a qualified person to a qualified aerodrome using a correctly validated approach. The review stated that past and current surveillance events had not detailed safety concerns with the operation of VH-OZO.
Operational information
Pre-flight planning and in-flight monitoring
Civil Aviation Regulation 239 (Planning of flight by pilot in command) stated:
Before beginning a flight, the pilot in command shall study all available information appropriate to the intended operation, and, in the cases of flights away from the vicinity of an aerodrome and all I.F.R. flights, shall make a careful study of:
a. current weather reports and forecasts for the route to be followed and at aerodromes to be used;
b. the airways facilities available on the route to be followed and the condition of those facilities;
c. the condition of aerodromes to be used and their suitability for the aircraft to be used; and
d. the air traffic control rules and procedure appertaining to the particular flight;
and the pilot shall plan the flight in relation to the information obtained.
AIP ENR 1.10 (Flight Planning) also stated these requirements. In addition, it stated a pilot was required to review NOTAMs[62] applicable to the flight.
At 1326 on the day before the accident flight, the pilot accessed a location briefing for Lockhart River from the National Aeronautical Information Processing System (NAIPS) via an electronic flight bag (EFB) application. This type of briefing typically displayed current forecasts, reports, and ‘notice to airmen’ (NOTAM) applicable to the nominated location.
Later that day, at 1830, the pilot requested grid point wind and temperature charts (GPWT) and a specific pre-flight information bulletin (SPFIB) from NAIPS via flight planning software. The SPFIB request was for Cairns to Lockhart River and return with the estimated time of departure nominated as 1930 the same day. This bulletin was valid until 1830 on the day of the accident.
A printout of the SPFIB found at the accident site showed aerodrome forecast (TAF) and weather reports (METAR) for Cairns. The weather for the next day (day of accident flight) at Cairns Airport was expected to be a visibility of 10 km or greater and showers of light rain with scattered cloud at 1,800 ft in the morning lifting to 2,500 ft. In addition, the forecast imposed a TEMPO for the next day to specify periods of visibility reduced to 2,000 m with showers of moderate rain and broken cloud at 1,000 ft.
On the printout of the SPFIB, a METAR for Lockhart River for 1800 (10 March 2020) showed light winds, visibility 10 km or greater and nil cloud detected. Since 0900 that morning, recorded rainfall was 1.8 mm.
No TAF was provided on the SPFIB for Lockhart River as the time of the request was outside the issue and validity period. There were no predicted outages of global positioning system/global navigation satellite system (GPS/GNSS) capability for Cairns or Lockhart River. NOTAM information included a change to Lockhart River runway distance and gradient data and no other notices with significance for the planned flight.
After the SPFIB was received, at 1942, the pilot submitted a flight notification for the planned departure from Cairns at 0730 the next morning to Lockhart River followed by a departure at 1430 for the return sector. Both sectors were planned under IFR with nominated capability for instrument approaches using GPS/GNSS equipment.
After the pilot requested the SPFIB and submitted the flight notification on the evening before the accident flight, there was no record of further requests for meteorological information from NAIPS. Such information was also available from the Bureau of Meteorology website and other sources without any user registration requirements. The ATSB was advised that the pilot was aware of the current weather forecasts for Lockhart River and Cairns on the morning before the flight.
A damaged and partly illegible copy of the pilot’s flight plan/log was found at the accident site. This was a printout from flight planning software showing key navigational data and pilot notes on progress of the flight. There was no indication of any operational abnormalities.
Fuel calculations
On the morning of the flight, the pilot refuelled the aircraft with 650 L of avgas. A tabulated fuel plan showed 1,040 L on board at engine start at Cairns and expected fuel consumption of 285 L for the planned 94-minute flight to Lockhart River. The pilot had included provision for 45 minutes fixed reserve (124 L), 40 L variable reserve and 60 minutes holding (110 L) if required (consistent with the forecast TEMPO conditions in the TAF, see Aerodrome forecasts). If the variable reserve and holding allowance was consumed on the outbound sector (in addition to the calculated flight fuel), the remaining 605 L was sufficient to return to Cairns with allowance for 60-minutes holding on arrival.
In summary, the aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required. The pilot was probably not intending to refuel at Lockhart River, although avgas was available if required.
Weight and balance
The pilot completed the operator’s passenger/cargo manifest form and calculated the aircraft’s weight and balance with reference to individual passenger weights and baggage. The take-off weight was recorded as 3,678 kg and nominal landing weight as 3,366 kg (7,421 lb). The aircraft’s maximum take-off weight was 3,810 kg and maximum landing weight was 3,674 kg. The graphical trimsheet showed the centre of gravity was within limits throughout the flight.
A copy of the operator’s in-flight monitoring form was found at the accident site. When the pilot completed the form in cruise at 10,000 ft, all of the recorded engine parameters for each engine were comparatively similar with no indication of any aircraft-related problems.
Communications during approaches
The AIP (ENR 1.1, 10.1) recommended radio calls at an uncontrolled aerodrome. These included:
the pilot being inbound to an aerodrome (10 NM or earlier, commensurate with aeroplane performance and pilot workload, with an estimated time of arrival)
during an instrument approach:
departing the FAF or established on the final approach segment (including details of position and intentions)
terminating the approach or commencing the missed approach (including details of position and intentions).
The Air Connect Australia operations manual stated the following for communications at non-towered aerodromes:
When operating within the vicinity of a non-controlled aerodrome, a known training area or authorised low flying area, Company pilots are to broadcast their intentions, listening out and communicate with any possible conflicting aircraft in accordance with the requirements of the AIP.
Additionally, for straight-in approaches at non-towered aerodromes, the manual stated:
Monitor / broadcast on CTAF shall be made by 10 NM and include aircraft type, position, callsign and include the intention to make a straight-in approach.
Monitor / broadcast at 3 NM that the aircraft is established on the final approach.
During both of the approaches at Lockhart River, the pilot of VH-OZO made broadcasts when at 10 NM (that is, at about the IF). During the first approach, the pilot also made a broadcast at 5 NM (at the FAF) and during the missed approach. There was no call recorded when the aircraft was at 5 NM on the second approach.
Electronic flight bag and approach charts
During the flight, the pilot was using an iPad with an electronic flight bag (EFB) application (OzRunways) and was carrying a second iPad as a backup. The operator’s operations manual (section 2A1.3.2.2) stipulated that all EFB devices permitted for use were class 1 (portable electronic device) and functionality level 1, which meant that it could be one or more of the following:
held in the hand
mounted on an approved mount
attached to a stand-alone kneeboard secured to a flight crew member
connected to the aircraft power for battery re-charging
connected to an installed antenna intended for use with the EFB for situational awareness but not navigation.
Furthermore, unless secured in accordance with b or c above, the EFB was required to be stowed during take-off, landing, instrument approach and when flying less than 1,000 ft above terrain. It was also only to be used:
…as a source of navigational data e.g. Departure and Approach plates and airport information.
The operator did not have an approved mount for the iPad. Accordingly, the operator required paper approach charts to be used when conducting an instrument approach. The chief pilot stated that the pilot subscribed to the departure and arrival procedure charts published by Airservices Australia. There was a clamp on the control column where a paper approach chart could be placed (Figure 8). There were no paper approach charts identified at the accident site, although the flight plan/log was found. Due to the disruption of the wreckage, it could not be determined whether the pilot carried the paper charts on board.
A friend of the pilot stated that they had provided the pilot with a mounting device that could be used to mount an iPad on a control column. The pilot’s iPad EFB was on[63] during the approach, however there were differing reports about how the pilot used the iPad during previous flights and whether it was mounted on the control column, placed on their knee or placed on the vacant seat next to the pilot. Due to disruption of the aircraft in the accident, only the second (backup) iPad was found at the accident site.
Flight profiles
The operator’s operations manual included flight profiles to be used for various situations for the Cessna 404, and stated that the profiles were required to be used for all operations. The prescribed flight profile for an RNAV GNSS approach (and other straight-in instrument approaches) is shown in Figure 19.
The indicated airspeed was required to be below 180 kt at the IAF and at 130 kt (+ or - 5 kt) at the start of the descent after passing the IAF (with the landing gear down and approach flap selected). The airspeed was also required to be Vref to Vref +10 kt at the FAF. As noted in Configurations and speeds, the Vref at maximum landing weight (8,100 lb) for the Cessna 404 was 91 kt and at weights 7,500 lb and below was 88 kt. In effect, the operator’s flight profile requirement to be at Vref to Vref + 10 kt at the FAF equated to an indicated airspeed of about 90–100 kt.
Figure 19: Flight profile for Cessna 404 RNAV GNSS approach
In another section titled ‘Final approach & threshold speeds’, the operations manual stated:
The [pilot] shall conduct the final approach in accordance with the stabilised approach criteria… [see next section]
These were the ‘handling speeds’ referred to the AIP for instrument approaches for a category B aircraft, such as the Cessna 404 (see Handling speeds). In effect, these speeds meant that the maximum allowed indicated airspeed after passing the IAF for the Cessna 404 was 180 kt and the maximum airspeed after passing the FAF was 130 kt.
The chief pilot recalled that the flight profiles were included in the operations manual by the previous chief pilot, who had based them on profiles used by another operator. The chief pilot stated that they advised the pilot of the accident flight to be at about 5,000 ft at the start of an approach (at the IAF) and then use a continuous descent to the runway from the IAF, and they demonstrated this to the pilot during their supervised flying in October 2018.
The chief pilot recalled that, when they flew the aircraft, they would select approach flap and landing gear early in the descent and be stabilised at a speed of 120 kt and a descent rate of 600 ft/min[64] well before the FAF. The chief pilot stated that the speed at the FAF should be about Vref + 20 kt (which equates to about 110 kt) but that the 100 kt specified in the flight profile would be acceptable. They stated that 130 kt at the FAF was too fast.
The previous chief pilot also recalled that the operator’s flight profile was most likely obtained from another operator. They noted their recollection of speeds was limited given the time since they flew the aircraft, but they recalled that they would be at least at Vref + 10 kt (that is, 100 kt) but not faster than 120 kt at the FAF, then slowing the aircraft down by 1,000 ft.
The flight examiner regularly used by the operator also worked with another operator of Cessna 404 aircraft (which was a different operator to that referred to by the previous chief pilot). The examiner stated that at the IF they would normally be at 130 kt with gear down and approach flap selected. The normal speed they used at the FAF was 110 kt (Vref + 20 kt), and 100 kt would be a little slow at that point on the approach. The examiner advised that these speeds were also used by the other Cessna 404 operator.
In summary, the ATSB concluded that the operator’s published flight profile speed of 90–100 kt at the FAF was probably not the operator’s preferred speed during flight operations. Rather, it appeared that the preferred speed at the FAF was probably about 110 kt. However, the extent to which this was clearly communicated to the pilot of the accident flight could not be determined.
Stabilised approach criteria
Guidance regarding stabilised approach criteria
A stabilised approach is one in which all criteria specified in the operations manual are met, at or before the applicable height or reference point. The Flight Safety Foundation (FSF) has for many years recommended that operators have stabilised approach criteria. Detailed guidance was provided by the FSF in its approach and landing accident reduction (ALAR) briefing note 7.1 (Stabilized approach, 2000a). The recommended criteria were summarised in a list, as reproduced in Figure 20.
Figure 20: FSF recommended elements of a stabilised approach
Source: ALAR briefing note 7.1 (Flight Safety Foundation 2000a)
The FSF briefing note also stated:
The flight crew must “stay ahead of the aircraft” throughout the flight. This includes achieving desired flight parameters … during the descent, approach and landing. Any indication that a desired flight parameter will not be achieved should prompt immediate corrective action or the decision to go around.
The minimum stabilization height constitutes an approach gate on the final approach; a go-around must be initiated if:
The required configuration and airspeed are not established, or the flight path is not stabilized when reaching the minimum stabilization height;
The aircraft becomes unstabilized below the minimum stabilization height.
ICAO Annex 6 Part I applied to international commercial air transport operations in aeroplanes. Since 1998, it included a standard stating an operator’s operations manual had to include stabilised approach procedures.
ICAO document 8168 (Procedures for Air Navigation Services, Aircraft Operations, known as PANS-OPS) provided recommendations on procedures for flight crew. Since 2001, PANS-OPS included content on stabilised approaches and stabilised approach criteria. It stated:
Studies have shown that the risk of controlled flight into terrain (CFIT) is high on non-precision approaches. While the procedures themselves are not inherently unsafe, the use of the traditional step down descent technique for flying non-precision approaches is prone to error, and is therefore discouraged. Operators should reduce this risk by emphasizing training and standardization in vertical path control on non-precision approach procedures…
Operators should use the CDFA (continuous descent final approach) technique whenever possible as it adds to the safety of the approach operation by reducing pilot workload and by lessening the possibility of error in flying the approach…
This technique requires a continuous descent, flown either with vertical navigation (VNAV) guidance calculated by on-board equipment or based on manual calculation of the required rate of descent, without level-offs. The rate of descent is selected and adjusted to achieve a continuous descent to a point approximately 15 m (50 ft) above the landing runway threshold or the point where the flare manoeuvre should begin for the type of aircraft flown...
The guidance document also stated:
The primary safety consideration in the development of the stabilized approach procedure shall be maintenance of the intended flight path as depicted in the published approach procedure, without excessive manoeuvring.
PANS-OPS stated the types of information that should be included in stabilised approach criteria (such as speeds, minimum power settings, attitudes, crossing altitude deviation tolerances, aircraft configuration, maximum sink rate and competition of checklists and briefings). In addition, the document stated that an operator’s procedures should include, as a minimum:
a) that in instrument meteorological conditions (IMC), all flights shall be stabilized by no lower than 300 m (1 000 ft) height above threshold; and
b) that all flights of any nature shall be stabilized by no lower than 150 m (500 ft) height above threshold.
Although the FSF and ICAO guidance may be considered most applicable to larger air transport aircraft with multi-crew operations and turbine engines, similar guidance (with the same applicable heights of 1,000 ft for operations in IMC and 500 ft for operations in VMC) has also been widely recommended for operations in smaller aircraft (Appendix D – Guidance to industry regarding stabilised approaches). This guidance has emphasised the benefits of using a CDFA technique with stabilised approach criteria in terms of reducing workload and increasing the time to monitor, detect and react to problems.
In Australia, since 2014, the Civil Aviation Advisory Publication (CAAP) 215-1 (Guide to the preparation of operations manuals) stated that an operator’s manual should include stabilised approach criteria in its section on approach and landing procedures. Guidance regarding applicable heights or reference points for such criteria were not specified in the CAAP or other CASA guidance documents.[65]
CASA advised the ATSB that specific Australian guidance was not provided prior to 2021 since there was no direct legislative requirement for operators to use such criteria, and it was considered that there was readily available and significant global guidance on this topic available from a wide range of authoritative sources.
Operator’s stabilised approach criteria
The Air Connect Australia operations manual stated:
Stabilised Approach Criteria are as follows:
(a) All flights, other than training flights, must be stabilised by 300 feet above aerodrome elevation in both IMC and VMC.
(b) An approach is stabilised when the following criteria are met:
The aircraft is on the correct flight path;
Only small changes in heading and pitch are required to maintain the correct flight path;
The aircraft is not more than Vref + 20 kts and not less than Vref indicated airspeed
The aircraft is in the correct landing configuration;
Sink rate is no greater than 1000 fpm [ft/min];[66] if an approach requires a sink rate greater than 1000 fpm, a special briefing should be conducted;
Power setting is appropriate for the aircraft configuration and is not below the minimum power for approach as defined by the aircraft operating manual;
All briefings and checklists have been conducted;
Instrument approaches are stabilised by the final approach fix, if they also fulfil the tracking requirements – established within ‘half scale deflection’ for the ILS, VOR and GNSS, within + or – 5 degrees for the NBD; during a circling approach, wings should be level on final by 300 feet above aerodrome elevation;
Unique approach procedures or abnormal conditions requiring a deviation from the above elements of a stabilized approach require a special briefing.
Missed Approach Procedure is as follows:
(a) Other than on training flights, an approach that is not stable below 300 feet aerodrome elevation in both IMC and VMC requires an immediate GO-AROUND. The procedure for a go around / missed approach is as follows:
Should be flown as per the approach chart missed approach procedure, or as advised by ATC;
The aircraft handling technique will be as per the relevant AFM for the appropriate aircraft…
The manual further stated:
If an approach does not meet the criteria for a stabilised approach…, the Pilot-in-Command shall conduct a missed approach.
To meet these stabilised approach criteria, the maximum indicated airspeed in a Cessna 404 needed to be Vref + 20 kt or about 110 kt at 300 ft above aerodrome elevation.
The chief pilot advised the ATSB that the published applicable height of 300 ft was too low to be effective, as it was normally below the MDA. They believed approaches should be stabilised much earlier, ideally at height of about 1,000 ft or even earlier. The chief pilot also stated that all configuration changes should be done early in the approach, with only the selection of landing flap to be completed late in the approach at the pilot’s discretion. The flight examiner used by the operator noted that stabilised approach criteria for most piston twin-engine and single-engine aeroplanes needed to acknowledge that the last stage of flap (or landing flap) should generally not be selected until about 300 ft due to aircraft performance considerations.
The chief pilot also recalled that they had discussed the importance of being stabilised early in the approach to the pilot of the accident flight on multiple occasions, and they had stated the importance of conducting constant angle descents down to the MDA at 600 ft/min. The chief pilot also noted that they had emphasised to the pilot the importance of gradual reductions in power and therefore speed during approaches in order to minimise undesirable cylinder head temperatures, and use slow descent rates for passenger comfort.
Additional information
During its investigation into the 2005 CFIT accident of a Metro aircraft at Lockhart River involving an operator that conducted passenger transport operations in Metro turboprop aircraft, the ATSB identified that that operator did not have stabilised approach criteria.[67] Of 5 other operators conducting operations in Metro aircraft, all had stabilised approach criteria, with 1 having an applicable height of 200 ft, 2 having an applicable height of 300 ft and 2 having an applicable height of 1,000 ft.
The ATSB also identified that an operator conducting passenger transport operations in a DHC-8 aircraft in 2012 had stabilised approach criteria based on an applicable height of 300 ft.[68] In addition, during another investigation commenced in 2021, the ATSB recently identified another operator of turboprop aircraft conducting passenger transport operations (charter) that had stabilised approach criteria with an applicable height of 300 ft. The ATSB has also identified that major airlines and some operators of single-pilot IFR operations in Australia have criteria based on 1,000 ft above ground level in IMC.
Prior missed approach during an RNAV GNSS approach (22 January 2020)
A review of the pilot’s logbook identified one other flight since the pilot joined the operator that involved 2 instrument approaches (and therefore a missed approach following an instrument approach). This occurred on a flight from Weipa to Aurukun, Queensland, on 22 January 2020, after which the pilot logged 2 RNAV GNSS approaches. Recorded data confirmed that the pilot conducted 2 approaches to runway 34 at Aurukun.
Analysis of the weather conditions and interviews with the passengers identified that there was a storm in the vicinity at the time, and interviews and recorded flight data indicated that the pilot was trying to avoid the weather. The passengers recalled observing the pilot using the onboard weather radar as well as an iPad with the weather on it to track the movement of the storm.
Passenger recollections regarding the weather during the first approach were varied; some recalled that they could not see the runway at times whereas others recalled the runway was still visible though restricted. The ground appeared to be visible most of the time. Images taken by a passenger during the first approach confirmed that there was significant cloud in the area though the ground could be seen to the left of the aircraft.
Review of the recorded flight data indicated that, on the first approach, the aircraft commenced descent on the recommended descent profile from about 1,600 ft, slightly below the initial approach altitude of 1,800 ft. The aircraft passed the FAF at an indicated airspeed of about 140 kt, and it was about 200–300 ft below the recommended descent profile when it passed the MDA at an indicated airspeed of about 145 kt. The aircraft descended to a recorded altitude of about 200–300 ft (at about 140 kt) before starting to climb.
The missed approach did not conform to the published missed approach procedure, with the aircraft flying to the right of the MAPt rather than maintaining the runway heading. However, the conditions may have been visual at this time. After the missed approach, the pilot circled for some time, remaining in VMC and waiting for the storm to pass, before conducting a second approach (about 31 minutes after the first approach). Images taken by a passenger during the second approach confirmed that the weather conditions were significantly better than on the first approach.
The exact reasons for the missed approach could not be determined (that is, whether it was due to reduced visibility of the runway or also due to the aircraft’s speed not meeting the operator’s stabilised approach criteria at 300 ft above aerodrome elevation).
Further details of these 2 approaches are provided in Appendix E – Aurukun incident flight – 22 January 2020.
Review of the pilot’s recent RNAV GNSS approaches
General aspects
The ATSB reviewed the available recorded data for the pilot’s flights in the previous 6 months for which the pilot had logged an RNAV GNSS approach (that is, 21 approaches). Recorded data was available for 16 of these approaches. Of these 16 approaches:
10 involved straight-in approaches to the runway
5 were flown to past the FAF and then a circling approach was flown from above the specified circling minima to the opposite (reciprocal) runway
1 was not an RNAV GNSS approach as it did not fly near the designated waypoints (and it was therefore not considered for further analysis).
Based on a review of available weather information, all 21 approaches were very likely conducted in VMC except for the first approach conducted at Aurukun on 22 January 2020 (which was potentially in IMC for a brief period). For those approaches conducted in VMC, the pilot was not specifically required to conduct an RNAV GNSS approach, except for the purpose of meeting recency requirements.
The published approach charts for all the approaches had 5 NM segments between the IAF and IF, IF and FAF, and FAF and MAPt. Most of the approaches were conducted at locations where the recommended descent profile commenced at about the FAF, except for one approach to runway 11 at Cooktown (where the recommended descent profile commenced at the IAF).
Vertical profiles
For most of the 15 RNAV GNSS approaches with recorded data available, the data showed the pilot typically descended to about 5,000–5,300 ft and then levelled out for a short period prior to the IAF. When passing the IAF, the pilot commenced a continuous descent to join the approach’s recommended descent profile on about a 3° approach.
The only exceptions to this method were the 2 approaches conducted at Aurukun on 22 January 2020 (when the pilot commenced descent on the approaches from close to the published initial approach altitude of 1,800 ft). As noted in Recorded flight data, the second approach at Lockhart River during the accident flight was also commenced at a lower altitude (that is, the published initial approach altitude of 3,500 ft) when the aircraft was between the IAF and the IF).
In general, the approaches were conducted close to the recommended descent profile. The only exception was the first approach at Aurukun on 22 January 2020, which reached the MDA about 200–300 ft below the recommended profile.
Lateral positions
The pilot generally entered each approach via the nearest of the 3 IAFs. In most cases, the aircraft passed the IAF from close to the middle of the capture region for that waypoint, or at least on a track that was less than 45° difference to the initial approach track. On one approach (at Cooktown), they entered from a similar position as the second approach at Lockhart River, although from about 65° right of the extended initial approach track to the IAF labelled ‘A’ (as opposed to about 100° at Lockhart River).
For all the straight-in runway approaches (except the second approach at Lockhart River), the aircraft remained close to the intermediate approach track and final approach track. In most cases, the aircraft also remained close to the initial approach track. The only exceptions were:
the Cooktown approach (when the aircraft flew over the IAF then, while descending, deviated left of the initial approach track by 0.9 NM and remained left until close to the IF)
the first approach at Aurukun on 22 January 2020 (when the pilot commenced the approach from slightly more than 1 NM west of the IAF and flew direct to the IF from that position, while remaining close to the initial approach altitude).
Indicated airspeeds
The ATSB reviewed the indicated airspeeds during the pilot’s 8 previous straight-in RNAV GNSS approaches to evaluate their consistency with the operator’s speed requirements and preferences, and these were compared with the 2 approaches at Lockhart River on the day of the accident (Figure 17). The 8 other approaches included the 2 approaches conducted at Aurukun on 22 January 2020 (Figure 25), and 6 other approaches that the pilot conducted from December 2019 to February 2020 and logged as RNAV GNSS approaches.
For the 10 approaches, the ATSB estimated the indicated airspeeds based on the recorded groundspeed, forecast and analysis wind charts and other relevant information. The actual wind speeds above the aerodrome on each occasion were not known, and as a result there could have been some differences between the estimated indicated speeds and the actual indicated airspeeds.
The results for key points on the approaches are shown in Table 4. In general terms:
In all 10 cases, the approaches did not exceed (and were well below) the maximum AIP handling speed of 180 kt in the initial and intermediate approach segments.
In all 10 cases, the approaches exceeded the operator’s preferred speed of 110 kt at the FAF. Most of the approaches were about 130–140 kt at the FAF, and 7 of the approaches appeared to exceed the maximum AIP handling speed of 130 kt at or after passing the FAF by 10 kt or more.
In most cases, the approaches appeared to be close to the operator’s maximum stabilised approach speed of 110 kt at or approaching 300 ft. However, in 3 cases there was a significant exceedance. These included the first approach at Aurukun on 22 January 2020 (which was followed by a missed approach), and the 2 approaches at Lockhart River (with the first followed by a missed approach).
Table 4: Summary of estimated indicated airspeeds during the pilot’s recent RNAV GNSS approaches (in kt)[69]
IF
FAF
FAF
1,000 ft
300 ft
Operator requirement or preference
(180 max)
110 preferred
(130 max)
(130 max)
110 max
Mornington Island, 2 Dec 2020 (VMC)
145
140
140
140
120
Normanton, 9 Dec 2020 (VMC)
145
145
145
145
125
Cooktown, 4 Jan 2020 (VMC)
140
140
140
140
115
Aurukun, 22 Jan 2020 (potential IMC, missed approach)
140
140
140
140
140
Aurukun, 22 Jan 2020 (VMC, second approach)
135
135
135
125
105
Aurukun, 3 Feb 2020 (VMC)
150
145
145
145
115
Kowanyama, 13 Feb 2020 (VMC)
140
120
120
120
115
Pormpuraaw, 18 Feb 2020 (VMC)
150
130
130
120
115
Lockhart River, 11 Mar 2020 (IMC, missed approach)
135
130
130
140
1401
Lockhart River, 11Mar 2020 (IMC, second approach, accident)
135
135
135
140
150
The requirement at 300 ft above aerodrome elevation is from the operator’s stabilised approach criteria. The maximum requirements for the IF, FAF and 1,000 ft above aerodrome elevation are from the AIP handling speeds for a category B aircraft (also referred to in the operations manual). The operator preferred speed at the FAF is based on interviews. All speeds rounded to nearest 5 kt. Green shading indicates the speed was consistent with the requirement or preference (within 5 kt), orange shading indicates a small exceedance (within 10 kt), and red shading indicates a significant exceedance (15 kt or more).
1Descent to just above 300 ft above aerodrome elevation (or just below that height) on this approach occurred after passing the MAPt.
In summary, the pilot was not conducting RNAV instrument approaches in the Cessna 404 in accordance with the operator’s preferred speed of 110 kt at the FAF. In some cases, the pilot appeared to be complying or was close to the AIP handling speed requirement to be at a maximum speed of 130 kt in the final approach segment, but in some cases they exceeded this requirement. The chief pilot advised that they were unaware that the pilot was conducting RNAV approaches with a speed that was significantly above 110 kt at the FAF.
Controlled flight into terrain
CFIT accident data
The ATSB research report CFIT: Australia in context 1996 to 2005 (ATSB, 2007), defined a controlled flight into terrain (CFIT) as an in-flight collision with terrain, water, or obstacles, in which:
the aircraft is under the control of the pilot(s)
there is no defect or unserviceability that would prevent normal operation of the aircraft
the pilot(s) had little or no awareness of the impending collision.
In the 10-year reporting period for that research (1996–2005), there were 27 CFIT occurrences in Australia. Of these 27 occurrences:
25 were accidents, including 15 fatal accidents, resulting in a total of 47 fatalities.
19 involved aeroplanes (including 18 accidents and 12 fatal accidents) and 8 involved helicopters (including 7 accidents and 3 fatal accidents)
17 (63%) occurred during the approach phase, with 8 during a visual approach and 9 during an instrument approach
1 occurred during a low-capacity regular public transport flight (RPT), 8 during charter flights, 4 during aerial work flights and 14 during private/business flights.
only one aircraft of the 27 occurrences was fitted with a TAWS – the Fairchild SA227-DC (Metro) aircraft involved in the low-capacity RPT CFIT accident at Lockhart River in May 2005.[70] This GPWS was not a predictive or enhanced TAWS, which became required for turbine aircraft like the Metro by the end of June 2005.
Of the 9 CFIT occurrences that occurred during an instrument approach:[71]
all 9 were accidents, including 7 fatal accidents, resulting in a total of 31 fatalities
all 9 involved aeroplanes
4 occurred during an RNAV GNSS approach, 2 during a GPS arrival and 3 during an NDB approach.
1 occurred during a low-capacity RPT flight, 3 during charter flights, 2 during aerial work flights and 3 during private/business flights.
Further details of some of these accidents are provided in Appendix F – Related occurrences.
A review of the ATSB database for the 15-year period 2006–2020 identified only 1 CFIT involving an aeroplane on an instrument approach (that is, VH-OZO at Lockhart River, resulting in 5 fatalities). There were also 5 other CFITs involving aeroplanes on visual approaches, which resulted in 2 accidents, including 1 fatal accident with 4 fatalities.
The International Air Transport Association (IATA) (2018) published a report on worldwide CFIT accidents from 2008 to 2017 involving aircraft with a MTOW of at least 5,700 kg (12,540 lb). During that period, there were 47 CFIT accidents, which accounted for 6% of total accidents. Most (42 or 89%) of the CFIT accidents involved fatalities, and CFIT was the second highest fatal accident category (after loss of control in-flight), accounting for 28% of all fatal accidents.
Of the 47 CFIT accidents, 24 (51%) occurred during the approach phase of flight, 7 (15%) during landing, and 4 (9%) during a go-around. Turbo-prop aircraft had a much higher CFIT rate (per million flights) than jet aircraft. Older generation aircraft were also involved in more CFIT accidents.
The IATA report found that the rate of CFIT accidents was significantly lower in the last 5 years (2013–17) compared to the first 5 years (2008–12). The report stated:
It is generally accepted that the reduction in CFIT accidents can be traced back to the introduction of Ground Proximity Warning System (GPWS), and Terrain Awareness Warning System (TAWS). Other improvements, may have also contributed directly or indirectly to the reduction of the likelihood of CFIT accidents, including aircraft design, replacing non-precision with precision approach procedures, pilot training, improved flight standards, Continuous Descent Final Approach (CDFA) technique, approach lightning, visual approach guidance and procedures, ground-based Minimum Safe Altitude Warning (MSAW) system, visual and instrument approach guidance and procedures.
In addition, the IATA report noted common contributing factors to CFIT accidents, including poor visibility or IMC (49%) and lack of visual reference (33%). Unstable approaches were cited in 10% of accidents. The report stated:
Unstable approaches increase the possibility of diverting a flight crew’s attention away from the approach procedure to regain better control of the airplane. Stabilized approach policies broadly concur in stating that a safe approach requires the flight path angle, configuration, and airspeed to be stabilized. Once one or more of these parameters are violated, the approach becomes unstable and the margin for a safe landing is decreased to a level requiring flight crew action; a go-around should be initiated.
Since the CDFA techniques contribute to a stabilized approach, the industry should also as soon as, and wherever, possible to develop procedures and train pilots to fly a stabilized CDFA…
The report also stated:
It is evident that most of the CFIT accidents result from a pilot’s breakdown in situational awareness (SA) instead of aircraft malfunction or a fire. In other words, these accidents are, for the most part, entirely preventable by the pilot. SA refers to the accurate perception by flight crew of the factors and conditions currently affecting the safe operation of the aircraft, and their vertical and/or horizontal position awareness in relation to the ground, water, or obstacles. The data shows that 49 percent of CFIT accidents had vertical, lateral or speed deviations as a contributing factor to CFIT accidents. One method to provide pilots with a greater level of safety through enhanced situational awareness and, more reliable warnings of possible terrain conflicts such as EGPWS that is equipped with accurate navigation systems like global positioning system (GPS) for both navigation and terrain surveillance.
Research conducted for the Netherlands Directorate-General of Civil Aviation, under the auspices of the Flight Safety Foundation, identified a fivefold increase in accident risk in commercial aircraft flying a non-precision approach compared with a precision approach (Enders and others, 1996).
Other research conducted into the human factors associated with CFIT accidents between 2007 and 2017 found that 24 out of 50 accidents reviewed (48%) occurred during the approach phase of flight (Kelly and Efthymiou, 2019). This research also found that ‘Breakdown of the Visual Scan’ occurred in 84% of accidents and that, in 42 of the analysed accident reports, a critical parameter such as altitude was ignored, and an unsafe situation occurred through ‘distraction’, ‘complacency’ or ‘lack of skill’.
Efforts to reduce CFIT accidents
In 1995 an international CFIT task force, whose major goal was to prevent CFIT accidents, completed its work after creating several unique products for the Flight Safety Foundation (FSF) including a CFIT Education and Training Aid. The training aid described GPWS (now known as TAWS) as ‘one of the major weapons in the growing arsenal of CFIT prevention methods.’ It further recommended every aircraft be fitted with such a system, as a GPWS warning ‘is normally the flight crew’s last opportunity to avoid CFIT’.
The training aid recommended standard operating procedures and/or guidance from the aircraft manufacturer that specified flight crew actions in the event of a terrain warning. In the absence of these, the aid provided a standard escape manoeuvre for flight crew to follow in the event of a terrain warning.
The CFIT task force identified 2 ‘basic causes’ of CFIT accidents – a lack of flight crew’s vertical position awareness and their lack of horizontal position awareness in relation to the ground, water, or obstacles. More than two-thirds of all CFIT accidents were the result of altitude error or lack of vertical situational awareness. To mitigate against this, the training aid emphasised the importance of flight crew training and discipline.
CFIT mitigation strategies
In 1994, the international CFIT task force also designed a CFIT checklist for the FSF, aimed at reducing CFIT accidents (Appendix G – Flight Safety Foundation CFIT Checklist). The checklist had 3 parts:
Part I enabled a calculation of the CFIT risk factors for the planned destinations (including air traffic control capabilities and the types of approaches available) and risk multipliers (such as the type of operation and weather conditions). Some of the risk factors relevant to this accident included no ATC at the airport and a non-precision approach type. Risk multipliers included passenger-carrying charter operation, IMC, and a single-pilot flight crew.
Part II of the checklist listed CFIT risk-reduction factors in 4 areas: company culture, flight standards, hazard awareness and training, and aircraft equipment.
Part III calculated the CFIT risk score by adding the destination CFIT risk factors (which are negative values) multiplied by the calculated risk multiplier to the risk-reduction factors.
The ATSB included copies of the FSF checklist in several of its accident reports, and also referred to the checklist in the research report CFIT: Australia in context 1996 to 2005 (ATSB, 2007).
In addition to the checklist, the FSF developed a CFIT Education and Training Aid in the 1990s, which included an example CFIT training program (albeit focussed on larger aircraft operations). It also developed a video training aid (for regional and business aircraft operators) and the ALAR Tool Kit, which included a number of briefing notes, such as the briefing note on stabilised approaches (see Guidance regarding stabilised approach criteria).
More recently, the FSF also developed a basic aviation risk standard (BARS) program that was designed to provide organisations that engaged contracted aircraft operators with a standard to assist in the risk-based management of aviation activities. It advised that the standard was suited to any organisation that used aircraft operators to provide contracted aviation support for its operations, particularly within remote and challenging environments. The program was used by several large mining/resource companies and other organisations. Participating aircraft operators could be audited against the standard.
The standard document stated:
All national and international regulations pertaining to aviation operations must be followed. This Standard is designed to supplement those requirements.
With regards to CFIT, the following risk controls were specified:
2 pilots for flights to be flown at night or ‘in IFR’
multi-engine aircraft to be used for flights flown at night or ‘in IFR’
aircraft operators to include type-specific stabilised approach requirements in their operations manual
aircraft that fly under IFR or at night and on long-term contract to be fitted with an approved and serviceable Class A TAWS when an approved modification exists for the aircraft type (and the operator must have related procedures to be followed by the flight crew in the event of an alert).
The BARS implementation guide outlined guidance for stabilised approach criteria, based on the ALAR briefing note 7.1.
Operator’s CFIT risk mitigation
General aspects
At the time of the accident, Air Connect Australia was not required to have a safety management system (SMS). At the core of an SMS is a formal risk safety management process, which is used specifically to:
identify hazards associated with an organisation’s operations
analyse and assess the risks associated with those hazards
implement control, to prevent future accidents, incidents or occurrences (CASA, 2018).
The operator advised it had an SMS incorporated into its operations manual, which included a requirement for 6-monthly safety meetings as well as a hazard, incident and accident report form. However, this did not include a detailed hazard identification and mitigation process. Without a documented hazard identification process, Air Connect Australia had not explicitly identified CFIT as a hazard nor detailed how it would mitigate the risk.
Based on the FSF CFIT checklist, the ATSB assessed that a single-pilot passenger transport operation involving non-precision approaches to airports without ATC and radar coverage (such as Lockhart River) in IMC carried a significant CFIT risk. Many of the risk-reduction factors listed in the checklist were specific to multi-crew operations and would not be appropriate or viable for a small operator conducting single-pilot operations such as Air Connect Australia. However, the checklist highlighted the CFIT risk for such an operation and provided some ways to mitigate the risk.
The ATSB further assessed Air Connect Australia and the aircraft (VH-OZO) against the suggested risk-reduction factors, as outlined in the following sections.
Section 1 – Company culture
The checklist items included aspects such as the operator placing safety before schedule and placing no negative conations on diversions or missed approaches. The chief pilot advised the ATSB that they often cancelled or postponed flights due to adverse weather. They also stated that they had frequent discussions with the pilot, and they were approachable and open to discussions with the pilot about any safety issues or concerns. Friends of the pilot were not aware of the pilot having any concerns about the chief pilot or the operator and confirmed that the pilot and chief pilot had frequent discussions about operational matters before flights.
Section 2 – Flight standards
The CFIT checklist did not specifically refer to stabilised approach criteria (which were introduced in later FSF guidance material). However, it listed a number of other items. Those potentially applicable to single-pilot operations included:
Reviewing approach or departure plates
Reviewing significant terrain along intended approach or departure course…
Briefing and observing MSA circles on approach charts as part of plate review
Checking crossing altitudes at IAF positions
Checking crossing altitudes at FAF and glideslope centering…
Use of 500-foot altitude call and other enhanced procedures for NPAs…
The operator’s operations manual stated, for all arrivals:
Before descending to an ALA [aircraft landing area], the Pilot-in-Command shall study available charts of the proposed ALA and surrounding area and make a note of hazards indicated on the charts.
The manual also required pilots to check the existing conditions in flight to determine their suitability for the approach and landing (including in terms of the MDA and required visibility on the approach charts). In addition, the manual included a requirement for crew to self-brief prior to the approach and also before landing:
Instrument Approaches – A self-briefing is to be carried out before every landing regarding the intentions of the Pilot-in-Command before / after the commitment point.
…
An emergency self-briefing is to be carried out before the landing regarding:
(a) the intentions of the Pilot-in-Command before / after the commitment point; and
(b) identifying missed approach track or heading.
As previously noted, the flight profile for a straight-in instrument approach also required a pilot to check the altimeter at the FAF. No other checks or altitude calls were explicitly stated.
Section 3 – Hazard awareness and training
The FSF checklist outlined various requirements for CFIT hazard awareness, including:
Your company’s pilots are reviewed annually about the following:
Flight standards operating procedures
Reasons for and examples of how the procedures can detect a CFIT “trap”
Recent and past CFIT incidents/accidents
Audiovisual aids to illustrate CFIT traps
Minimum altitude definitions…
The operator did not conduct formal hazard awareness training and there were no records of any training relating specifically to CFIT. There was no specific regulatory requirement for the operator to conduct such training.[72]
The checklist also included items regarding incident reporting and investigation:
You have an incident/exceedance review and reporting program
Your organization investigates every instance in which minimum terrain clearance has been compromised
The company culture items also referred to fostering a culture where CFIT incidents could be reported. The chief pilot advised they had frequent discussions with the pilot and believed there was a high level of mutual trust, such that that if the pilot had a concern they would feel comfortable coming to talk to the chief pilot about it. However, the chief pilot was not aware of the circumstances associated with the missed approach at Aurukun in January 2020.
The chief pilot advised that the pilot used their own tablet device (iPad) and OzRunways subscription. As a result, the chief pilot did not have access to the recorded data.
Section 4 – Aircraft equipment
The CFIT checklist referred to GPWS, radio altimeter, various types of displays and autopilot functions. The checklist was not up-to-date and not targeted to the needs and potential current opportunities for small aircraft.
As previously noted, VH-OZO was not fitted with a TAWS or radio altimeter, nor were these mandated by the regulatory requirements at the time. The aircraft’s GPS units did not provide vertical guidance for RNAV GNSS approaches and the autopilot was not capable of maintaining a vertical profile without pilot input.
CFIT risk score
Based on the total CFIT risk factors for the destination and risk multipliers, then consideration of the available risk-reduction factors, the total CFIT risk score calculated for the operator was less than zero and indicated a significant CFIT risk. However, as already noted, other operators conducting single-pilot charter flights involving non-precision approaches in IMC to airports without ATC and radar coverage (such as Lockhart River) would also be exposed to a significant CFIT risk as assessed by this checklist.
Safety analysis
Introduction
After conducting an area navigation (RNAV) global navigation satellite system (GNSS) approach to runway 30 at Lockhart River and then a missed approach, the pilot of the Cessna 404 aircraft (VH-OZO) immediately commenced a second RNAV GNSS approach to runway 30. The aircraft’s descent gradient was similar to the first approach but significantly lower than the recommended profile in the approach chart. This descent continued until the aircraft collided with terrain 6.4 km short of the runway.
There was no evidence of any conditions or circumstances likely to induce a medical problem or incapacitation for the pilot, who had been in good health and was well rested. Also, based on the recorded flight data and impact information, the aircraft appeared to be in controlled flight up until the time of the impact. Accordingly, it is very unlikely that the pilot was incapacitated or impaired during the flight.
There was no evidence of any aircraft system or mechanical anomalies that would have influenced the accident. However, as a consequence of extensive aircraft damage, it was not possible to be conclusive about the aircraft’s serviceability.
Therefore, based on the available evidence, the accident was very likely the result of controlled flight into terrain (CFIT). That is, an airworthy aircraft under the control of the pilot was flown unintentionally into terrain, probably with no (or very limited) prior awareness by the pilot of the aircraft’s proximity to terrain.
As evidenced in this case, a CFIT accident generally results in significantly adverse consequences for the occupants of an aircraft, and thus operators conducting operations in instrument meteorological conditions (IMC) or degraded visual conditions need to have robust risk controls to minimise the risk of such accidents.
This analysis considers the weather and sequence of events, followed by the factors that likely influenced the pilot’s performance. It also discusses risk controls for CFIT relevant to this accident.
Weather conditions
The weather conditions at Lockhart River at the time of the 2 approaches were consistent with the forecast, with periods of reduced visibility due to rain and cloud. The conditions had been suitable for the pilot of one aircraft to land about 1 hour prior to the accident and allowed another to land about 30 minutes afterwards.
Although the pilot of VH-OZO had not obtained the latest weather forecast for Lockhart River on the morning prior to the flight using their National Aeronautical Information Processing System (NAIPS) account, they could have obtained the forecast from other sources and they were reportedly aware of the current weather information. In any case, the pilot had ensured the aircraft had sufficient fuel to hold, divert or return to Cairns if necessary.
The landing minima for the runway 30 approach at Lockhart River included a cloud ceiling (for broken cloud or worse) of 730 ft and a visibility of 4,200 m. On arrival at Lockhart River, the pilot listened to the automated weather information service (AWIS) via VHF radio, and received information that the reported conditions were above the landing minima (with 10 km visibility and broken cloud at 1,800 ft).
The conditions recorded by the airport’s automatic weather station (AWS) at the time of the first approach’s final segment (0904–0907) included a visibility of 10 km, some rainfall (0.2 mm at 0904) and nil wind. The visibility was measured in the immediate vicinity of the sensor and may not have reflected the conditions experienced by the pilot during the approach. The recorded cloud base was 1,800 ft, however the recorded values for cloud were averaged over the preceding 30-minute period, and the cloud conditions at any specific time may have been worse than recorded.
Based on a witness report, it appeared as though the conditions at times were probably worse than recorded, with periods of reduced visibility due to cloud and rain. Messages sent by 2 of the passengers at 0914 indicated there was low visibility and one stated there was heavy rain, however it was not clear whether these comments were related to the conditions during the first approach or were observations of the conditions closer to 0914, which was about 7 minutes after the aircraft passed the missed approach point (MAPt).
Therefore, although the AWS observations indicated the weather was above the landing minima, there were areas of reduced visibility in the vicinity of the airport and it was not possible to conclusively determine the actual conditions experienced by the pilot when they reached the MAPt during the first approach.
The recorded visibility deteriorated to 800 m at 0912 and was below the landing minima for most of the period 0911–0917. This aligned with recorded rainfall between 0910–0916, including moderate to heavy rain during 0912–0914. Weather radar images from the Bureau of Meteorology (BoM) also showed rain passing through the Lockhart River area during both approaches, with heavier rain during the second approach. The radar images were consistent with the weather observations by people in the area, including that a ‘wall’ of heavy rain passed through at about the time of the accident. Given the direction the radar returns were moving, it is likely the aircraft entered the rain during the second approach.
In summary, while the pilot was operating in the vicinity of Lockhart River Airport, there were areas of cloud and rain that significantly reduced visibility and increased the risk of CFIT. In particular, the aircraft probably entered areas of significantly reduced visibility during the second approach. As a result of the reduced visibility, the pilot would have been reliant on the aircraft’s flight instruments and GPS units during both approaches.
Conduct of the approaches
First approach and missed approach
On the first approach, the pilot levelled at about 5,000 ft prior to the initial approach fix (IAF), which in this case was LHREB, then established the aircraft on a 3° descent from the IAF. This was consistent with the pilot’s normal method and conformed to the operator’s recommendations and the guidance shown on the approach chart. The pilot conducted the approach consistent with the recommended (3°) constant descent profile, and the aircraft kept descending through the minimum descent altitude (MDA) of 730 ft and passed the missed approach point (MAPt).
There were no significant lateral deviations from the published track, and the indicated airspeed when passing the final approach fix (FAF) was about 130 kt. However, after the FAF, the airspeed increased to about 140 kt, which was sustained throughout the remaining descent. This was significantly in excess of the operator’s preferred airspeed for such approaches (about 110 kt at the FAF), and it also exceeded the applicable handling speed limit specified in the Aeronautical Information Publication (AIP) of 130 kt in the final approach segment.
After passing the MAPt, the aircraft’s recorded descent rate was 900 to 960 ft/min. When the aircraft reached about 400 ft, the pilot initiated a missed approach. The airspeed at that time significantly exceeded the operator’s stabilised approach criteria speed (that is, about 110 kt at 300 ft above aerodrome elevation).
The reason for the non-conforming airspeed on this approach could not be determined. It is possible that this was intentional, and the pilot was expediting the arrival in response to the visible weather. Alternatively, it could have been inadvertent and associated with a focus on other flying tasks in this phase, such as maintaining track (with reduced tolerances) and/or searching for visual cues such as the runway threshold in reduced visibility (see also Awareness of procedural requirements). Whatever the reason, the high airspeed would have made it difficult to configure the aircraft for a stabilised final approach and landing.
Although the descent rate was just within the operator’s limit for a stabilised approach (that is, 1,000 ft/min), it was higher than the 600 ft/min that would be typical for this stage of a final approach. It was also higher than the 750 ft/min that would be commensurate with a 3° profile at 140 kt. Similar to the high airspeed, the reason for the relatively high descent rate could not be determined. It is possible that the pilot was attempting to maintain visual reference.
As previously noted, the weather conditions when the aircraft reached the MAPt could not be determined. It is possible that the conditions were better than the landing minima at that point but then deteriorated as the approach continued and when the aircraft was at a lower altitude.
Irrespective of the conditions, this was not a stable approach due to the relatively high airspeed and a missed approach was necessary. Ultimately, the pilot commenced the missed approach when the aircraft reached about 400 ft. Whether the decision to conduct the missed approach at that time was based on the weather conditions, airspeed, descent rate or some combination of those factors could not be determined.
After initiating the missed approach, the pilot was required to select one of 4 options:
immediately conduct another instrument approach
hold in the area, monitor the weather at Lockhart River and, if suitable, conduct another instrument approach
divert to a nearby airport, monitor the weather at Lockhart River and, if suitable, return for another approach
return to Cairns.
Having descended to 400 ft then overflown the airport during the missed approach, it is expected that the pilot had an appreciation of the low-level weather conditions. Then, during the missed approach, the aircraft tracked initially to the north-west, which was in the direction of weather that was moving towards Lockhart River. Given heavy rain was recorded at the airport about 5–7 minutes after the aircraft had been overhead, the boundary of this rain area may have been visible to the pilot. The rain should also have been displayed on the aircraft’s weather radar display and potentially also the iPad the pilot was using during the flight, although exactly what information was displayed to (or observed by) the pilot could not be determined.
As reported by a passenger in a text message at 0914, at some point during the missed approach or transition to the second approach, the aircraft was in or near heavy rain. Although the AWS between 0911 and 0917 was indicating below-minima weather at the airport, it is unlikely that the pilot had spare capacity to access the AWIS in that period.
Given this context, the pilot may have considered there was a window of opportunity to conduct a second approach before there was heavy rain at the airport and, accordingly, they expedited the second approach.
Second approach – vertical profile
The pilot tracked directly towards the IAF LHREA at 3,500 ft to commence the second approach. After passing the IAF, the aircraft remained at that altitude while heading to the IF. The pilot then commenced descent from 3,500 ft about 2.7 NM prior to the IF. From about 1.6 NM before the IF, the descent was flown at about a normal 3° flight path, although about 1,000 ft below the recommended descent profile. The aircraft descended through the intermediate segment minimum safe altitude of 1,800 ft and passed the FAF at about 1,100 ft. When the aircraft reached a recorded altitude of 700 ft, the descent rate increased from about 700 ft/min to about 1,200 ft/min until the collision with terrain.
The investigation considered 3 main scenarios to explain the vertical profile of the second approach. The first scenario is the pilot misunderstood their position along the approach (or misidentified the waypoints) and believed they were one segment (5 NM) further along the approach than they actually were. Figure 21 shows the vertical profile of the second approach (in red) and it also shows the vertical profile moved 5 NM to the left (in green), as if the pilot thought they were one segment further along the approach. With regard to this scenario:
The scenario does not provide a good explanation of the recorded data as the aircraft remained about 600 ft above the recommended profile for an extended period and there was no indication of any attempt to correct such a perceived problem prior to reaching the perceived MAPt.
The waypoint names on RNAV approaches are similar and there is some potential for confusion. However, in this case the pilot had significant cues to indicate their position along the approach, given they were turning at the IF (10 NM from the MAPt), and they had broadcasted they were at this position just prior to the turn. Although the absence of a subsequent broadcast by the pilot at the FAF (5 NM) could indicate a loss of awareness of the aircraft’s position at that time, it could also have been omitted because the pilot assessed it was unnecessary due to the lack of other aircraft in the vicinity, and/or the pilot was experiencing high workload.
Figure 21: Second approach to runway 30 (red), second approach displaced 5 NM (green) and second approached raised 1,000 ft (yellow)
The second scenario is the pilot believed they were 1,000 ft higher than they actually were during most of the descent. This scenario is shown on Figure 21 (in yellow). With regard to this scenario:
The scenario closely matches the recommended descent profile in terms of commencing the 3° descent at about the right point for a constant descent and then continuing the descent past the IF and FAF.
When the pilot commenced the descent from 3,500 ft, they were correcting the aircraft’s lateral position (right of the initial approach track) and would therefore have been experiencing a high workload. The potential to mis-read instruments (such as an altimeter) is significantly increased under high workload, and the ability to subsequently detect and correct such an error would also be reduced, given that high workload can lead to scanning information sources less frequently and also scanning them for shorter durations.
Just prior to passing the IF, the pilot broadcasted that they were at ‘3,800 correction 2,800 ft’, and this correction was an accurate broadcast of the aircraft’s altitude at the time. This indicated an initial mis-reading of the altimeter, but it also indicated that the pilot had correctly read the altimeter at that time. However, this correction occurred at one point in time for the purpose of making the radio broadcast, and the pilot may not have fully assimilated the information for the purpose of monitoring their descent profile.
The pilot should have been regularly checking the altimeter during the descent as part of their instrument scan, so for this scenario to be viable the pilot would need to mis-read the altimeter multiple times, or at least not detect a problem when scanning the altimeter after an initial error. This would seem unlikely over an extended period. However, as noted before, the pilot may have been scanning instruments less frequently and for shorter durations due to workload. They may also have been focussing more on the vertical speed indicator than the altimeter after commencing the descent.
The aircraft was fitted with a 3-pointer altimeter, which are widely used in small aircraft. Research has shown that pilots can mis-read this type of altimeter, including mis-reading by 1,000 ft, although accidents known to be associated with such errors seem relatively rare.
The scenario does not specifically explain why the descent rate increased in the last 30 seconds of the approach. However, the pilot was probably experiencing a very high workload at that time associated with correcting the aircraft’s lateral position (see Second approach - lateral position). The pilot may also have started increasing the amount of time they were looking outside the aircraft for visual cues, and/or their attention was diverted when entering heavy rain. In addition, heavy rain on a windshield is known to create refraction effects that can lead a pilot to perceive that the aircraft is too high, which can result in an unwarranted nose-down correction and flight below the desired flight path (Flight Safety Foundation 2000).[73]
The third scenario is the pilot intentionally descended below the recommended descent profile and segment minimum safe altitude in order to maximise the chances of becoming visual before reaching the MAPt. For this type of scenario, it is unlikely a pilot would intentionally descend below the MDA before the MAPt unless there were some visual references. With regard to this scenario:
There were no indications in the pilot’s recent RNAV GNSS approaches of descending this early on an approach or descending below segment minimum safe altitudes, although it is acknowledged that the pilot had limited experience with having to conduct a second approach in IMC. There was also no indication that the pilot took unnecessary risks in interviews with other pilots who had flown with the pilot.
Lockhart River is a location widely known to be problematic in terms of the weather conditions and terrain. Although the pilot had flown to Lockhart River on several occasions, as far as could be determined they had not previously encountered IMC at this location before. Nevertheless, given the location’s reputation, it would be reasonable to expect that the pilot would be conducting approaches cautiously and therefore less likely to descend below altitude limits.
If the pilot was intentionally descending early, it is not exactly clear why they would choose to conduct a 3° descent that was about 1,000 ft below the recommended descent profile. However, it is possible the pilot wanted to reach the MDA over water (to ensure more clearance from terrain) and had calculated that such a profile would enable the aircraft to be over water just after reaching the FAF.
There was some indication in the recorded data that the aircraft’s descent rate may have briefly reduced near the MDA, with 3 successive data points recorded at 700 ft. This might be associated with an attempt to level out at about the MDA. Alternatively, the descent rate may have only briefly reduced from 700 ft/min to 500–600 ft/min due to the pilot’s workload and attention been focussed on the aircraft’s lateral position at that time, or due to the pilot’s attention being diverted when they entered heavy rain. It is also possible that the 3 data points at the same level were an artefact of the recorded data and there was no significant change in descent rate.
If the pilot was attempting to level out at about 700 ft, it is unclear why the aircraft kept descending for over 30 seconds after reaching this altitude at a descent rate of 1,200 ft/min. It is possible the pilot did not retrim the aircraft after levelling out and then did not effectively monitor the altimeter due to other tasks, including looking outside to gain visual references.
In summary, following the missed approach, the pilot immediately conducted another approach to the same runway that was on a similar gradient to the recommended descent profile but displaced about 1,000 ft below that profile. While continuing on this descent profile, the aircraft descended below a segment minimum safe altitude and the minimum descent altitude, then kept descending until the collision with terrain about 6 km before the runway threshold.
Based on the available evidence, it is unlikely that the pilot thought they were one segment out on the approach and there was no specific evidence to indicate that the pilot had or would intentionally descend below the recommended descent profile and below a segment minimum safe altitude. Overall, mis-reading the altimeter by 1,000 ft appears to be the most likely scenario, although there was insufficient evidence to provide a definitive conclusion. Regardless of the exact scenario, it is evident from the continued descent that the pilot did not effectively monitor the aircraft’s altitude and descent rate for an extended period.
Second approach - lateral position
The aircraft was just within the capture region for the IAF LHREA when the pilot commenced the turn towards the IF, and it was then initially significantly to the right of the initial approach track. The pilot corrected the aircraft’s heading, but the aircraft was still more than half full-scale deflection on the course deviation indicator (CDI) at the time it started descending from 3,500 ft. The descent was paused soon after and then recommenced, before the IF, with the aircraft within the required half full-scale deflection in order to descend.
Before reaching the IF, the aircraft was close to the initial approach track. The pilot then turned slightly late at the IF and the aircraft was left of the intermediate approach track, reaching about half full-scale deflection on the CDI. The pilot promptly took corrective action, though the aircraft then started deviating to the right of the approach track about 3 NM prior to the FAF. However, the lateral deviation at that stage was less than half full-scale deflection.
Nearing the FAF, the sensitivity of the CDI increased, and when the aircraft passed the FAF it was at about full-scale deflection on the CDI (as presented by the Garmin GNS 430W), and then it exceeded full-scale deflection for about 55 seconds (and was outside half-scale deflection for about 60 seconds). The aircraft’s change of track to the left during the final 30 seconds of the approach suggests the pilot had observed the CDI and attempted to correct the situation, but had then flown through the final approach track and, before a further correction back to the right could be conducted, the aircraft impacted terrain.
Given the aircraft was more than half full-scale deflection on the CDI when it reached the FAF, the pilot was required to conduct a missed approach in accordance with the operator’s stabilised approach procedures. It is acknowledged that the GNS 430W presented full-scale CDI deflection more restrictively than the required navigation performance (RNP) requirements specified in Civil Aviation Order (CAO) 20.91 (that is, 0.23 NM compared to the RNP of 0.3 NM at the FAF). Nevertheless, given that the aircraft’s position was at full-scale deflection (rather than half-scale deflection), this difference should not have affected the pilot’s decision.
In addition, the aircraft was at 0.3 NM lateral displacement shortly after passing the FAF (for about 10 seconds). This would have been displayed to the pilot as more than full-scale CDI deflection, and the lateral displacement distance would also have been displayed on the graphical CDI on the default NAV page of the GNS 430W. Accordingly, the pilot was also required to conduct a missed approach in accordance with the CAO 20.91 requirements at that time.
Finally, with reference to the AIP, the pilot was also required to be within half full-scale deflection on the CDI after passing the FAF before continuing the descent below the previous segment minimum safe altitude (1,800 ft). This should have precluded further descent when passing the FAF (actual altitude 1,100 ft) or soon after (when the actual height was 800 ft and the perceived height may have been 1,800 ft).
It is possible the pilot may not have promptly detected the lateral deviation due to other workload, or they may not have fully realised the extent of the change in the sensitivity of the CDI near the FAF. Alternatively, it is possible that the lateral deviation was due, in part, to the pilot attempting to avoid the most adverse weather.
In summary, the pilot experienced some difficulty controlling the aircraft’s lateral position throughout the second approach. In particular, when passing the FAF and after passing the FAF, the aircraft reached or exceeded the required limits to conduct a missed approach, and a missed approach was not conducted. Regardless of the reason for the lateral deviations, by continuing the approach the pilot significantly increased their workload and the risk of collision with terrain/obstacles.
Second approach - indicated airspeed
The aircraft was at about 135 kt when it passed the FAF, before increasing to 140 kt soon after the FAF. It then increased to 150 kt towards the end of the flight, which was associated with the increased descent rate.
By exceeding the operator’s preferred speed of 110 kt at the FAF, the pilot significantly increased their workload and reduced the time available in the final approach segment to detect and identify other problems with the conduct of the approach (in terms of altitude, descent rate or lateral deviation). More specifically, if the airspeed had been about 110 kt at the FAF, and remained at or below that speed, the pilot would have had over 20 seconds more time prior to the collision to identify problems with the aircraft’s flight path (as well as additional time prior to reaching the FAF). A lower speed would also have made it easier to effectively correct the aircraft’s lateral position.
Unstable approach
Overall, at times during the conduct of the second approach, the pilot appeared to experience difficulty controlling the aircraft’s lateral position, and after passing the FAF they did not effectively control the aircraft’s altitude, descent rate, lateral position and airspeed. As already noted, the approach did not meet the operator’s stabilised approach criteria for lateral deviation at the FAF, and the pilot was required to conduct a missed approach at that point.
In addition, the second approach did not meet the stabilised approach criteria for airspeed (110 kt maximum) or descent rate (1,000 ft/min) at the operator’s applicable height of 300 ft above aerodrome elevation. At this point, the aircraft was travelling at about 150 kt and descending at 1,200 ft/min. However, given that the pilot may have believed the aircraft was 1,000 ft higher than it actually was during the approach, or may have thought they were in level flight near the MDA, they may have not yet considered these stabilised approach criteria.
Factors influencing pilot performance
Introduction
As previously noted, there was no evidence to indicate that the pilot was incapacitated during the accident flight. There was also no evidence to indicate the pilot was experiencing fatigue. The investigation considered a range of other factors that could have influenced the pilot’s performance, including workload, instrument flying proficiency, awareness of procedural requirements, and operational, social or organisational pressures.
Workload and monitoring
Single-pilot operations under the instrument flight rules (IFR), conducting instrument approaches in poor visibility and hand flying an aircraft are all demanding tasks. A pilot needs to be regularly scanning and interpreting the flight instruments, GPS unit (or navigational display) and approach chart, and assimilating the information from multiple sources. As they near the MAPt, they also need to be looking outside to evaluate the visual conditions.
It could not be determined with certainty whether the pilot was using a paper approach chart clamped to the control column and/or was referring to an iPad with the approach chart displayed. Based on the evidence available, it was more likely the pilot was using an iPad, but it was not clear whether it was secured to the control column or if it was on the pilot’s knee. If they were routinely scanning an iPad that was not fixed to the control column, this would have increased the difficulty of the pilot’s scanning and exacerbated the inherent workload associated with the tasks.
Overall, the pilot’s workload on the second approach was elevated throughout the approach compared to the first approach (and other recent instrument approaches conducted by the pilot). Initially the workload was elevated because they joined the approach directly after conducting the missed approach and from just within the capture region of the IAF LHREA. This limited their time to prepare for the approach, and also required more manoeuvring than normal at the IAF.
After turning at the IAF, the pilot’s workload was further elevated by the need to correct the aircraft’s track while also reducing airspeed. As previously noted, it was during this period that the pilot decided to commence the descent from 3,500 ft, which also involved selecting the approach flap and lowering the landing gear soon after.
The pilot’s workload after turning at the IF was also elevated due to the turn being slightly late and then needing to correct the aircraft’s track. This workload would have been significantly elevated after passing the FAF, with the deviation from the final approach track needing more significant correction, as well as due to potentially starting to look more outside the aircraft to assess the visual conditions.
At some point the aircraft probably entered rain, and this would also have increased the pilot’s workload and the difficulty of their task. The presence of rain decreases contrast in the visual environment, making it more difficult to detect terrain features. This effect is exacerbated when approaching or flying over water. In addition, as already discussed, heavy rain on a windshield can lead to a perception of being too high. Light rain can also result in a pilot misperceiving their aircraft to be higher than it is, resulting in a tendency to pitch down (Gibb and others 2010, Flight Safety Foundation 2000b, Previc 2004).
A further factor potentially increasing the difficulty of the pilot’s task after passing the FAF was the increasing sensitivity of the Garmin GNS 430W’s CDI. At and just past the FAF, where a decision to conduct a missed approach should have been made, full-scale deflection on the 430W was not significantly different to the RNP. Towards the MAPt, the 430W was significantly more restrictive than the RNP. The pilot should have been familiar with the system, although the extent to which they fully appreciated the effect of the increasing sensitivity could not be determined.
As previously noted, the omission of the broadcast at 5 NM could be an indication of the pilot’s high workload at that time. In addition, the aircraft’s increased descent rate and speed in the final 30 seconds as the pilot was correcting the lateral deviation is also consistent with the effects of high workload, reducing the ability to monitor and effectively control multiple flight parameters at the same time.
As previously discussed, the pilot’s workload could have been reduced by conducting the approach at a lower airspeed prior to and after the FAF. In addition, there were other available options after conducting the missed approach, including taking more time prior to conducting the second approach and commencing it from another position (for example, tracking further away from the IAF and then approaching it from closer to the centre of its capture region). Alternatively, the pilot could have conducted a holding pattern and waited for the weather to pass before attempting the second approach.
Such options would have provided more time to prepare for the approach and minimise the potential for altitude, descent rate or lateral deviations or other workload problems. These options may also have provided the pilot more opportunity to use the autopilot to reduce their sustained workload prior to initiating the second approach.
Instrument flying proficiency
Many pilots experience some difficulty with developing instrument flying skills and then consistently maintaining those skills. The pilot of the accident flight experienced some difficulties obtaining their initial instrument rating in 2014, and also experienced some difficulties in subsequent instrument proficiency checks (IPCs) in 2016 (underpinning knowledge) and 2017 (mis-reading the altimeter), before passing subsequent assessments. The pilot also experienced significant difficulties in conducting instrument approaches, including the management of multiple flight parameters at the same time, when being assessed in an airline simulator in early 2018, albeit in a much different environment to their previous operations.
The pilot’s last IPC was conducted in August 2019, 7 months prior to the accident, and no problems were noted. However, on that occasion, the Cessna 310 aircraft used for the check was fitted with a navigational system capable of providing vertical guidance for an RNAV GNSS approach. As far as could be determined, the pilot’s instrument flying skills using VH-OZO (a Cessna 404 with GNS 430 GPS units) or similar aircraft had not been observed by the chief pilot or a flight examiner pilot since they were cleared for line operations in October 2018.
Since their last IPC, the pilot had regularly logged RNAV GNSS approaches in VH-OZO and these approaches were generally flown accurately. However, these approaches were almost all conducted in VMC, which would have provided the pilot with cues to identify and correct problems with the aircraft’s position.
The pilot had only conducted one previous approach since the last IPC that potentially encountered IMC for a brief period, at Aurukun on 22 January 2020. This approach was not initiated in the pilot’s normal manner (with a descent from about 5,000 ft at the IAF). In addition, the aircraft reached the MDA 200–300 ft below the recommended descent profile and there were problems with speed control, with the speed after the FAF reaching 145 kt.
Overall, it was difficult to assess the pilot’s instrument flying skills at the time of the accident. Given the limited number of recent RNAV GNSS approaches in IMC or simulated IMC, it is conceivable that the pilot would have experienced significant workload in conducting an approach in IMC, particularly in circumstances where the approach required them to use a different method to normal. They would probably also have had limited ability to manage any additional problems or tasks that occurred during the conduct of an approach in IMC.
Awareness of procedural requirements
The operator’s published flight profile for an RNAV GNSS approach required a Cessna 404 to be at an indicated airspeed of about 90–100 kt at the FAF. However, interviews with the operator’s relevant personnel suggested that the operator’s preferred speed was probably about 110 kt. Given that the one-engine inoperative best rate of climb speed for the aircraft type was 102 kt (flap in the take-off/approach position and gear up), 110 kt was a more appropriate speed at the FAF. The pilot’s approaches routinely exceeded the operator’s preferred speed by a significant margin, with speeds of 130–140 kt being common.
Although the pilot should have been familiar with the contents of the operations manual, it is unclear to what extent they were aware of the flight profile speed or the operator’s preferred speed, and, if they were aware, the extent to which they thought these were reasonable expectations. In other regards, the pilot appeared to be conducting RNAV GNSS approaches in a manner consistent with the chief pilot’s expectations, using a constant descent from about 5,000 ft at the IAF in order to maximise the potential for a stabilised approach.
Having held an instrument rating since 2014, and been subject to many IPCs since then, the pilot should have been aware of the requirement to be to be no faster than 130 kt after the FAF while conducting an RNAV GNSS approach. They should also have been aware of the operator’s requirement to be within half-scale deflection of CDI in the final approach segment.
There were no indications from interviews with various people who flew with the pilot to suggest that the pilot routinely or intentionally deviated from procedural requirements. Given many of the pilot’s previous instrument approaches were conducted in VMC, it is possible the pilot did not consider that some procedural requirements, such as keeping the speed below 130 kt, were essential during such approaches. The pilot may have then become familiar with using such speeds and, when actually conducting approaches in IMC, did not fully recognise the problem. Alternatively, as already discussed, these speed deviations on the approaches in IMC may have been unintentional and were symptoms of high workload and/or limited proficiency.
Operational, social and organisational pressures
Pilots conducting passenger charter flights can experience or perceive a range of social and organisational pressures that can influence the potential to conduct or continue flights in unsuitable conditions (Paletz and others 2009, Michalski and Bearman 2014). These can include not wanting to disappoint customers, reluctance to admit defeat or time-related pressures.
Although such pressures can exist in operational environments, the ATSB identified no evidence to indicate the pilot was subject to any pressure to conduct this flight, complete the flight as quickly as possible, or to deviate from procedural requirements. The chief pilot had previously cancelled flights due to poor weather, but the forecast conditions in this case did not necessitate that the flight be cancelled.
As previously noted, the pilot had ensured the aircraft had sufficient fuel to conduct holding after arrival at Lockhart River, and divert or return to Cairns. They had also conducted holding for an extended period after a missed approach on a previous flight to Aurukun while waiting for a storm to pass, without any apparent negative social or organisational consequences.
As noted above, it is possible that, following the missed approach during the accident flight, the pilot assessed that the weather conditions were worsening and they had limited time to conduct a second approach before a more extensive delay. It is also possible that the pilot was worried about some aspect of the aircraft’s serviceability and did not want to delay the flight further. However, as previously noted, there was no evidence available to indicate a problem with the aircraft’s serviceability.
The pilot had previously commented to a passenger that they would only ever attempt 2 approaches prior to diverting. To what extent this may have placed self-imposed pressure on the pilot on this occasion to continue the approach could not to be determined.
Summary
In summary, the pilot was probably experiencing a very high workload during periods of the second approach. In addition to the normal high workload associated with a single pilot hand flying an approach in IMC, the pilot’s workload was elevated due to conducting an immediate entry into the second approach, conducting the approach in a different manner to their normal method, the need to correct lateral tracking deviations throughout the approach, and higher than appropriate speeds in the final approach segment. The workload was potentially further exacerbated by the pilot having limited recent experience in conducting RNAV GNSS approaches in IMC.
There was no evidence to indicate any organisational or commercial pressures on the pilot to complete the flight, but the extent to which self-imposed pressures or incomplete knowledge of procedural requirements influenced the pilot’s performance could not be reliably determined.
Risk controls for minimising the likelihood of controlled flight into terrain
Introduction
CFIT accidents have been a significant problem over the years, although the rate of such accidents has been decreasing. In Australia, the number of CFIT accidents during instrument approaches decreased from 9 in the 10-year period 1996–2005 and only 1 in the subsequent 15 years (that is, the accident involving VH-OZO at Lockhart River).
This decrease can be attributed, at least in part, to improved instrument approach designs, the increased use of better equipment to display relevant lateral and vertical navigational information, the increased fitment of a terrain warning system (TAWS), and greater use of constant descent angle approaches. However, risk factors still remain, particularly for smaller operators.
Air Connect Australia was a very small operator, with effectively only 2 pilots and one conducting almost all of the operator’s flights. Nevertheless, it conducted passenger transport operations in an aircraft with up to 9 passengers, and multiple factors existed that indicated a significant CFIT risk. These factors included:
single-pilot operations under the IFR
many of the operator’s destination aerodromes were in uncontrolled airspace and outside radar coverage
most of the destination aerodromes offered only non-precision approaches with limited runway lighting systems and without visual approach slope indicating systems
some of the destination aerodromes (such as Lockhart River) were associated with frequent rainfall or adverse weather conditions.
Although the operator had started introducing a safety management system (SMS), it had not developed a formal hazard register and a formalised approach to addressing the risk of hazards such as CFIT. The operator had introduced various measures to manage CFIT risk, such as a flight profile and stabilised approach criteria. However, there were limitations with these and some of the operator’s other risk controls.
Design of the flight profile
The operator’s operations manual included a flight profile for RNAV GNSS and other straight-in runway approaches. Such a flight profile can be an effective way of summarising an operator’s requirements and expectations for pilots regarding how an approach should be conducted.
However, as previously noted, the stated speed on the profile at the FAF (Vref to Vref + 10 kt) was very conservative and unrealistic in most situations. In addition, it did not appear to reflect the expectations of the operator’s key personnel (which equated to Vref + 20 kt or about 110 kt). The flight profile also did not include any requirements or expectations at the IF, which increased the potential for ambiguity.
Design of stabilised approach criteria
An essential and effective means of minimising the risk of CFIT accidents is for an operator to publish clear and relevant stabilised approach criteria, and then ensure that flight crew are aware of and comply with these criteria. Air Connect Australia’s stabilised approach criteria covered relevant parameters and factors, such as airspeed, configuration, descent rate, lateral tracking and briefings/checklists. The chief pilot also reportedly promoted the use of stabilised approaches to the pilot.
However, other than for lateral flight path deviations, the operator’s published criteria had an applicable height of 300 ft above aerodrome elevation for operations in both IMC and VMC. Such a height will have limited effectiveness for non-precision (or 2D) instrument approaches conducted in IMC, particularly given that the MDA for such approaches will often be above 300 ft. An applicable height of 1,000 ft above aerodrome elevation in IMC is widely recommended, including for operations in small aeroplanes. This will enable pilots to ensure that an approach is stable well before reaching the MAPt, reducing workload and maximising the time available to monitor the approach and identify and correct any problems.
The pilot of the accident flight generally appeared to be close to the stabilised approach speed of 110 kt at 300 ft in most of the instrument approaches examined by the ATSB, with 2 main exceptions being the first approach at Aurukun on 22 January and the first approach at Lockhart River, both of which resulted in missed approaches. Based on this information, the pilot appeared to be generally complying with the stabilised approach criteria. Therefore, had the operator specified an applicable height of 1,000 ft in IMC, it seems likely that the pilot would generally have been conducting approaches with a lower speed at this height.
However, it is not clear whether an applicable height of 1,000 ft would have influenced the pilot’s performance and changed the outcome of the second approach on the accident flight. As previously discussed, the exact reasons why the aircraft was descending below the recommended descent profile could not be determined. The pilot may have believed the aircraft was 1,000 ft higher than it was, and therefore thought the aircraft was still above 1,000 ft in the period immediately prior to the collision. Nevertheless, if they were effectively monitoring the flight instruments and complying with the criteria, they should have been slowing down well before reaching an altitude of 1,100 ft (the applicable height at Lockhart River given the aerodrome elevation).
An applicable stabilised approach height of 1,000 ft has been widely recommended by organisations such as the International Civil Aviation Organization (ICAO), the Flight Safety Foundation (FSF) and overseas regulators. However, as of the time of the accident, no formal guidance regarding the content of stabilised approach criteria had been published for Australian operators by the Civil Aviation Safety Authority (CASA). The ATSB has identified a number of Australian operators over the years conducting passenger transport operations under the IFR with applicable heights for all approaches of 300 ft. Accordingly, providing more specific formal guidance in Australia should reduce the likelihood that other operators will use such heights as the reference point for their criteria for all approaches.
It is acknowledged that operators need to tailor stabilised approach criteria to their specific aircraft and operations, and the use of 300 ft may be appropriate for some criteria on some types of approaches. In particular, circling approaches could involve a turn onto final approach at about 500 ft, and therefore cannot meet all stabilised approach criteria until about 300 ft (which is acknowledged in the FSF’s recommended criteria). In addition, it may not be appropriate to select full flap on many smaller aeroplanes until much lower than 1,000 ft on an approach (although other criteria could be met at a different height).
Nevertheless, with greater use of straight-in approaches, all operators should ensure the applicable heights for their stabilised approach criteria are consistent with contemporary guidance where possible for such approaches, particularly for operations in IMC.
Fitment of a terrain avoidance and warning systems
The use of a terrain avoidance and warning system (TAWS) has been shown to significantly reduce the risk of a CFIT. However, VH-OZO was not fitted with a TAWS, nor was one required to be fitted.
Given the aircraft’s descent profile on the second approach, if a TAWS had been fitted and been operational, it would have provided the pilot with both visual and aural alerts of the approaching terrain for an extended period. Accordingly, it is very likely that the accident would not have occurred.
The requirements for a TAWS have been increasing over time. However, the requirements in Australian have lagged behind those in comparable countries, and they were also not consistent with ICAO standards and recommended practices. In Australia there was a requirement for turbine-engine aeroplanes carrying 10 or more passengers on air transport flights under the IFR to be fitted with a TAWS, whereas the ICAO standard required aeroplanes authorised to carry 10 or more passengers to be fitted with a TAWS, regardless of the number of passengers carried on a flight. More importantly:
There was no requirement for piston-engine aeroplanes conducting air transport operations to be fitted with a TAWS, even though this had been an ICAO standard since 2007 for such aeroplanes authorised to carry 10 or more passengers, and this standard had been adopted as a requirement in many comparable countries.
There was no requirement for turbine-engine aeroplanes conducting air transport operations that were authorised to carry 6–9 passengers to be fitted with a TAWS, even though this had been an ICAO recommended practice since 2007, and this recommended practice had been adopted as a requirement in many comparable countries.
CASA had been consulting on applying TAWS requirements to more aircraft since 2008, and had proposed introducing a TAWS requirement for aeroplanes conducting air transport operations (turbine- and piston-engine) with a maximum operational passenger seat configuration (MOPSC) of 6 or more in 2012. However, following consultation with industry, this proposal was amended in 2018 to only require aeroplanes with a MOPSC of 10 or more to be fitted with a TAWS, with the application date being December 2021 or December 2022 depending on various factors.
VH-OZO had 12 seats that could be used by passengers and therefore it had a MOPSC of 12 when used for single-pilot operations. If it remained in that configuration, the operator would have had to have fitted a TAWS to the aircraft by December 2022 and, by December 2024, operated the aircraft under CASR Part 121 (which imposed additional requirements, including 2 pilots for all flights). Given that context, it is likely that an operator in this situation would have chosen to modify such an aircraft so that its MOPSC was 9 or less. Consequently, even if the changes to the TAWS requirements had been introduced in Australia earlier, they probably would not have resulted in an aircraft such as VH-OZO being fitted with a TAWS.
In terms of other comparable countries, only Canada has introduced a requirement for piston-engine aeroplanes with a passenger seating capacity of 6–9 seats to be fitted with a TAWS. However, it is noted that Canada generally experiences more adverse weather conditions than most areas of Australia.
In summary, there was no requirement for VH-OZO to be fitted with a TAWS, and piston-engine aeroplanes with a passenger seating capacity of 6–9 seats were not required to have a TAWS in most comparable countries. Accordingly, it would probably have been difficult to justify mandating that such aeroplanes be fitted with a TAWS in Australia.
Nevertheless, the lessons from the VH-OZO accident (and many previous accidents) are clear: all operators conducting passenger transport operations under the IFR in aircraft that do not currently have a TAWS should recognise the substantial benefits of a TAWS, and be actively seeking to install a TAWS in their aircraft to maximise the safety of their operations.
Use of the GNS 430W terrain awareness function
Although not developed to the same standard and with the same functionality as a TAWS, the Garmin GNS 430W units fitted to VH-OZO had a terrain awareness function that was capable of providing visual pop-up terrain alerts. If the function was selected on, then the system should have displayed a terrain alert to the pilot within the last 30 seconds of the flight (and potentially longer).
However, the terrain awareness function could be inhibited by a pilot, in which case no terrain alerts would be displayed. It could not be determined whether the function was selected or inhibited during the approaches at Lockhart River.
Given the pilot had significant experience using GPS units with a terrain awareness function, it would be expected that they were aware of the function and had seen terrain alerts in the past. However, the investigation could not determine how the pilot normally used the function (that is, whether they normally had it selected on or inhibited).
The Garmin 400W SeriesPilot’s Guide & Reference manual explicitly stated that the system’s terrain awareness function was to be used for supplemental awareness only and was not to be relied upon for terrain avoidance. Nevertheless, although not as effective as a TAWS, the terrain awareness function could still be a valuable tool during instrument approaches in IMC if an operator (and its pilots) had clearly-defined procedures, training and guidance on how to effectively and safely use the function.
For example, an operator could require its pilots to confirm that the function was selected on as part of the descent checklist (particularly when conducting an instrument approach). However, the operator of VH-OZO did not have any explicit procedures or guidance, and this was similar to other operators who used the same type of equipment.
Vertical guidance information
At the time of the accident, the approaches available to the pilot at Lockhart River were RNAV GNSS approaches available for runways 12 and 30, and an NDB approach for runway 30. These were non-precision approaches that did not provide vertical guidance to pilots.
More advanced GPS/navigational systems than the GNS 430W, such as that fitted to the aircraft in which the pilot conducted their most recent IPC, can provide vertical guidance to aid in maintaining the correct vertical profile for a non-precision RNAV GNSS approach.
Vertical guidance information (showing the aircraft’s vertical position during the approach) would have significantly assisted the pilot in maintaining awareness of the aircraft’s vertical position and would have provided a salient indication that the aircraft was dangerously low for an extended period. Having vertical guidance available would also have reduced the pilot’s workload, such as reducing the extent of the mental calculations required to ascertain the aircraft’s position versus altitude and any necessary corrections to the descent rate.
There was no requirement for VH-OZO to be fitted a GPS/navigational system that provided vertical guidance information. However, in the absence of a TAWS, such a system could have significantly reduced the risk of CFIT during instrument approaches.
Monitoring of line operations
The pilot generally conducted instrument approaches in a manner that was consistent with the chief pilot’s preferred method. However, the approaches were also conducted at speeds significantly higher than the operator’s preferred speed. Although they were having regular discussions with the pilot about their flights, the chief pilot had no awareness that this was occurring.
One means of identifying potential problems with the conduct of line operations is through regular proficiency checks. The pilot had not received an operator proficiency check (OPC) since being checked to line in October 2018, and the chief pilot (or the designated flight examiner who could conduct OPCs) had also not flown with the pilot since that time. The pilot had completed an IPC in August 2019, although with a flight examiner who was not familiar with the operator’s procedures and in a different aircraft, with different navigational equipment, than the operator used.
At the time of the accident, there was no specific regulatory requirement for most charter operators to conduct OPCs on their pilots (though pilots conducting IFR operations still needed to undertake an IPC every 12 months). However, as of December 2021, such operators needed to conduct OPCs (or flight crew member proficiency checks) every 6 months.
It is acknowledged that OPCs will not necessarily identify all problems, and pilots may sometimes perform differently when being observed compared to when they are not being observed. However, such checks provide a valuable opportunity for identifying potential misunderstandings regarding the operator’s expectations about how key aspects of flight operations should be conducted.
Another option now readily available to small operators is the use of GPS-based flight data, either through an electronic flight bag application (EFB) or via other sources. Such data may only include some basic flight parameters, which is not as useful as a flight data recorder or other device specifically designed for monitoring flight operations. However, it could still assist with evaluating some aspects of flight operations, including the way instrument approaches are conducted.
Reviewing recorded GPS-based flight data would require a chief pilot or other designated person to be aware of the limitations of the data, and the process would be best done cooperatively with pilots. Nevertheless, the process would not require significant resources and, if done on a regular basis, could help identify potential misunderstandings regarding the operator’s expectations and also provide useful feedback and learning opportunities for pilots.
Hazard awareness training
As stated by the FSF, another useful mitigator for reducing the risk of CFITs is hazard awareness training. The operator had not developed any hazard awareness training material relating to CFIT, and it would be difficult for a small operator to develop a detailed and tailored training program. Nevertheless, various resources from the FSF could be selected and used to provide some guidance information to pilots, together with focussed discussions regarding flight profiles and stabilised approach criteria.
Summary
Ideally, in order to minimise the risk of CFIT, operators conducting passenger transport operations under the IFR would use aircraft fitted with a TAWS and/or have a GPS/navigational system that provides vertical guidance during a non-precision instrument approach. However, without such equipment being a regulatory requirement, it would be difficult for some operators to justify the cost, including in cases where they are leasing the aircraft from another organisation (as was the case with Air Connect Australia).
Nevertheless, there are other means available for such operators to minimise CFIT risk. In this case, the operator had included stabilised approach criteria and flight profiles in its operations manual, and it encouraged the use of stabilised approaches. However, there were problems with the applicable height for the criteria (that is, not 1,000 in IMC) and the flight profile for straight-in approaches did not fully reflect the operator’s requirements or preferences. The operator had also not developed clear procedures and guidance for the use of the terrain awareness function in the aircraft’s 430W GPS/navigational units, and had not conducted regular OPCs or other checks of line operations. Overall, improving these procedural controls would have reduced the operator’s CFIT risk and probably reduced the likelihood of this particular accident.
It is likely that many of these limitations will also exist in other small operators conducting passenger transport operations in small aircraft. Accordingly, this accident has provided many important lessons to such operators regarding ways they can minimise their CFIT risk during IFR operations. These are summarised in the Executive summary.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the controlled flight into terrain involving a Cessna 404 aircraft, registered VH-OZO, which occurred near Lockhart River Airport, Queensland, on 11 March 2020.
Contributing factors
While the pilot was operating in the vicinity of Lockhart River Airport, there were areas of cloud and rain that significantly reduced visibility and increased the risk of controlled flight into terrain. In particular, the aircraft probably entered areas of significantly reduced visibility during the second approach.
After an area navigation (RNAV) global satellite system (GNSS) approach to runway 30 and missed approach, the pilot immediately conducted another approach to the same runway that was on a similar gradient to the recommended descent profile but displaced about 1,000 ft below that profile. While continuing on this descent profile, the aircraft descended below a segment minimum safe altitude and the minimum descent altitude, then kept descending until the collision with terrain about 6 km before the runway threshold.
Although the exact reasons for the aircraft being significantly below the recommended descent profile and the continued descent below the minimum descent altitude could not be determined, it was evident that the pilot did not effectively monitor the aircraft’s altitude and descent rate for an extended period.
When passing the final approach fix (FAF), the aircraft’s lateral position was at about full-scale deflection on the course deviation indicator (CDI), and it then exceeded full-scale deflection for an extended period. In accordance with the operator’s stabilised approach procedures, a missed approach should have been conducted if the aircraft exceeded half full-scale deflection at the FAF, however a missed approach was not conducted.
The pilot was probably experiencing a very high workload during periods of the second approach. In addition to the normal high workload associated with a single pilot hand flying an approach in instrument meteorological conditions, the pilot’s workload was elevated due to conducting an immediate entry into the second approach, conducting the approach in a different manner to their normal method, the need to correct lateral tracking deviations throughout the approach, and higher than appropriate speeds in the final approach segment.
The aircraft was not fitted with a terrain avoidance and warning system (TAWS). Such a system would have provided visual and aural alerts to the pilot of the approaching terrain for an extended period, reducing the risk of controlled flight into terrain.
Although the aircraft was fitted with a GPS/navigational system suitable for an area navigation (RNAV) global satellite system (GNSS) approach and other non-precision approaches, it was not fitted with a system that provided vertical guidance information, which would have explicitly indicated that the aircraft was well below the recommended descent profile.
Although the operator had specified a flight profile for a straight-in approaches and stabilised approach criteria in its operations manual, and encouraged the use of stabilised approaches, there were limitations with the design of these procedures. In addition, there were limitations with other risk controls for minimising the risk of controlled flight into terrain (CFIT), including no procedures or guidance for the use of the terrain awareness function on the aircraft’s GNS 430W GPS/navigational units and limited monitoring of the conduct of line operations. (Safety Issue)
Other factors that increased risk
Although an applicable height of 1,000 ft for stabilised approach criteria in instrument meteorological conditions has been widely recommended by organisations such as the International Civil Aviation Organization for over 20 years, the Civil Aviation Safety Authority had not provided formal guidance information to Australian operators regarding the content of stabilised approach criteria. (Safety issue)
The Australian requirements for installing a terrain avoidance and warning system (TAWS) were less than those of other comparable countries for some types of small aeroplanes conducting air transport operations, and the requirements were not consistent with International Civil Aviation Organization (ICAO) standards and recommended practices. More specifically, although there was a TAWS requirement in Australia for turbine-engine aeroplanes carrying 10 or more passengers under the instrument flight rules:
There was no requirement for piston-engine aeroplanes to be fitted with a TAWS, even though this was an ICAO standard for such aeroplanes authorised to carry 10 or more passengers, and this standard had been adopted as a requirement in many comparable countries.
There was no requirement for turbine-engine aeroplanes authorised to carry 6–9 passengers to be fitted with a TAWS, even though this had been an ICAO recommended practice since 2007, and this recommended practice had been adopted as a requirement in many comparable countries. (Safety Issue)
Other findings
The forecast weather at Lockhart River for the time of the aircraft’s arrival required the pilot to plan for 60 minutes holding or diversion to an alternate aerodrome. The aircraft had sufficient fuel for that purpose; and the aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required.
There was no evidence of any organisational or commercial pressure to conduct the flight to Lockhart River or to complete the flight once to commenced.
Based on the available evidence, it is very unlikely that the pilot was incapacitated or impaired during the flight.
There was no evidence of any aircraft system or mechanical anomalies that would have directly influenced the accident. However, as a consequence of extensive aircraft damage, it was not possible to be conclusive about the aircraft’s serviceability.
The aircraft was fitted with Garmin GNS 430W GPS/navigational units that could be configured to provide visual (but not aural) terrain alerts. However, it could not be determined whether the terrain awareness function was selected on during the accident flight.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: Although the operator had specified a flight profile for a straight-in approaches and stabilised approach criteria in its operations manual, and encouraged the use of stabilised approaches, there were limitations with the design of these procedures. In addition, there were limitations with other risk controls for minimising the risk of controlled flight into terrain (CFIT), including no procedures or guidance for the use of the terrain awareness function on the aircraft’s GNS 430W GPS/navigational units, and limited monitoring of the conduct of line operations.
Safety issue description: The Australian requirements for installing a terrain avoidance and warning system (TAWS) were less than those of other comparable countries for some types of small aeroplanes conducting air transport operations, and the requirements were not consistent with International Civil Aviation Organization (ICAO) standards and recommended practices. More specifically, although there was a TAWS requirement in Australia for turbine-engine aeroplanes carrying 10 or more passengers under the instrument flight rules:
There was no requirement for piston-engine aeroplanes to be fitted with a TAWS, even though this was an ICAO standard for such aeroplanes authorised to carry 10 or more passengers, and this standard had been adopted as a requirement in many comparable countries.
There was no requirement for turbine-engine aeroplanes authorised to carry 6–9 passengers to be fitted with a TAWS, even though this had been an ICAO recommended practice since 2007, and this recommended practice had been adopted as a requirement in many comparable countries.
Regulatory guidance for stabilised approach criteria
Safety issue description: Although an applicable height of 1,000 ft for stabilised approach criteria in instrument meteorological conditions has been widely recommended by organisations such as the International Civil Aviation Organization for over 20 years, the Civil Aviation Safety Authority had not provided formal guidance information to Australian operators regarding the content of stabilised approach criteria.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Aerotrack
The owner of Aerotrack has made a change to the tool to ensure compliance with Civil Aviation Safety Regulation 61.875. As a result, only instrument flight rules (IFR) flights with over 1 hour IFR flight time were included in the calculation of recency, and decimals were not included in the calculation.
A barometric vertical navigation (Baro-VNAV) approach with vertical guidance (APVs) enables a suitably-equipped aircraft’s systems to compute and display a vertical guidance path. Accordingly, they are a 3D instrument approach. Airservices Australia has been implementing Baro-VNAV APV approaches since 2016. After the accident (in December 2020), a Baro-VNAV approach was implemented at Lockhart River (and several other airports in Australia). However, this type of approach requires the aircraft to have a flight management system and VH-OZO was not equipped to conduct a Baro-VNAV approach.
On 2 December 2021, CASR Part 135 (Australian air transport operations – smaller aeroplanes) commenced. Air transport operations included passenger transport operations, regardless of whether they were scheduled or charter operations.
It included a requirement for operators to conduct proficiency checks on pilots, with the requirements for such checks to be specified in the Manual of Standards (MOS). The MOS for Part 135 defined a flight crew member proficiency check as:
… an assessment, conducted by an aeroplane’s operator in accordance with the operator’s exposition, of whether a person is competent to safely carry out the person’s duties as a flight crew member in the aeroplane, which relates to the matters mentioned in subsection 12.05(2).
Standard 12.08 stated:
(3) The flight crew member must successfully undertake the operator’s flight crew member proficiency check, for the relevant type or class of aeroplane, as follows:
(a) for a flight crew member only conducting a flight under the VFR by day — subject to subsections (4) and (5), initially 6 months after first commencing unsupervised line operations for the operator, and then at intervals of 1 year after the previous proficiency check;
(b) otherwise — subject to subsections (4) and (5), initially 6 months after first commencing unsupervised line operations for the operator, and then at intervals of 6 months after the previous proficiency check.
For the 1-year requirement, the check could be done within 90 days of the required date and for the 6-months requirement the check could be done within 30 days of the required date.
The matters specified in 12.05(2) were:
(a) training in the duties and responsibilities for the flight crew member’s position;
(b) training in the standard operating procedures for the type or class of aeroplane used for the flight;
(c) training in the normal, non-normal and emergency procedures for an aeroplane of that type or class;
(d) training in any flight procedures or manoeuvres, conducted in an aeroplane of that type or class, for which the operator holds an approval under regulation 91.045, or 135.020, of CASR;
Note: Examples of approvals issued under regulation 91.045, or 135.020, of CASR include approvals to conduct low visibility operations and flights using certain PBN navigation specifications.
(e) training in the procedures for any other operations conducted by the operator in an aeroplane of that type or class that the flight crew member has not previously experienced, for example, precision runway monitor operations or land and hold short operations.
Glossary
ADS-B Automatic dependent surveillance-broadcast
AFRU Aerodrome frequency response unit
AGL Above ground level
AIP Aviation information publication
AOC Air operator’s certificate
APV Approach with vertical guidance
ATC Air traffic control
AWIS Automated weather information service
AWS Automatic weather station
BARS Basic aviation risk standard (a Flight Safety Foundation program)
BoM Bureau of Meteorology
CASA Civil Aviation Safety Authority
CASR Civil Aviation Safety Regulations
CDI Course deviation indicator
CFIT Controlled flight into terrain
CTAF Common traffic advisory frequency
DETRESFA Distress phase
EFB Electronic flight bag
EST Eastern Standard Time
ETA Estimated time of arrival
FAF Final approach fix
FLTA Forward looking terrain avoidance (a function of the Garmin GNS 430W unit)
FMS Flight management system
FSF Flight Safety Foundation
GAF Graphical area forecast
GNSS Global navigation satellite system
GPS Global positioning system
GPWS Ground proximity warning system
GPWT Grid point wind and temperature chart
HF High frequency
IAF Initial approach fix
ICAO International Civil Aviation Organization
IF Intermediate fix
IFR Instrument flight rules
ILS Instrument landing system
IMC Instrument meteorological conditions
INCERFA Uncertainty phase
IPC Instrument proficiency check
JRCC Joint Rescue Coordination Centre
LCD Liquid crystal display
LNAV Lateral navigation
MAPt Missed approach point
MDA Minimum descent altitude
METAR Meteorological aerodrome report
MOPSC Maximum operational passenger seat configuration
NAIPS National Aeronautical information Processing System
NM Nautical miles
NOTAM Notice to airmen
NPRM Notice of proposed rule making
OPC Operator proficiency check
PDA Premature descent alert (a function of the Garmin GNS 430W unit)
PLB Personal locator beacon
POH Pilot’s operating handbook
QNH That pressure setting which, when placed on the pressure setting sub‑scale of a sensitive altimeter of an aircraft located at the reference point of an aerodrome, will cause the altimeter to indicate the vertical displacement of the reference point above mean sea level.
RAIM Receiver autonomous integrity monitoring
RNAV Area navigation
RNP Required navigation performance
SIGMET Significant meteorological information
SMS Safety management system
SPFIB Specific pre-flight information bulletin
TAF Aerodrome forecast
TAWS Terrain avoidance and warning system
VFR Visual flight rules
VHF Very high frequency
VMC Visual meteorological conditions
VNAV Vertical navigation
Vref Reference landing speed
VSI Vertical speed indicator
Sources and submissions
Sources of information
The sources of information during the investigation included the:
operator/chief pilot of Air Connect Australia
aircraft owner and maintainer for VH-OZO
GPS unit manufacturer (Garmin)
Civil Aviation Safety Authority
Queensland Police Service
Airservices Australia
Bureau of Meteorology
OzRunways flight data.
References
Arthur W, Bennett W, Stanush PL and McNelly TL (1998) ‘Factors that influence skill decay and retention: A quantitative review and analysis’, Human Performance, 11:57-101.
Civil Aviation Authority (2013) Monitoring matters: guidance on the development of pilot monitoring skills, CAA Paper 2013/02.
Dismukes RK, Berman BA & Loukopoulos LD (2007) The limits of expertise: Rethinking pilot error and the causes of airline accidents, Ashgate, Aldershot UK.
Enders JH, Dodd R, Tarrel R, Khatwa R, Roelen ALC & Karwal AK (1996) Airport safety: a study of accident and available approach-and-landing aids, Flight Safety Foundation, Flight Safety Digest, 15(3).
European Union Agency Safety Agency (2021), Safety issue report – Skills and knowledge degradation due to lack of recent practice, downloaded from www.easa.europa.eu.
Federal Aviation Administration (2012) Instrument flying handbook, FAA-H-8083-15B
Gibbs R, Gray R & Scharff L (2010) Aviation visual perception: Research, misperception and mishaps, Ashgate, Aldershot UK.
Godley ST (2006) Perceived pilot workload and perceived safety of RNAV (GNSS) approaches, Australian Transport Safety Bureau.
Hoekstra HD, Perry EB & Huang S (1972) Altimetry display study Part 2 – Analysis of altitude accidents, Report No. FAA-RD-72-46 II, prepared by the Flight Safety Foundation for the US Department of Transportation, Federal Aviation Administration.
Holmes S, Bunting A, Brown D, Hiatt K, Braithwaite M & Harrigan M (2003) ‘Survey of spatial disorientation in military pilots and navigators’, Aviation, Space, and Environmental Medicine, 74:957-965.
International Air Transport Association (IATA) (2018) Controlled flight into terrain accident analysis report 2008–2017 data, Montreal, Canada
Kelly D & Efthymiou M (2019) ‘An analysis of human factors in fifty controlled flight into terrain aviation accidents from 2007 to 2017’, Journal of Safety Research, 69:155-165.
Michalski DJ & Bearman C (2014) ‘Factors affecting the decision making of pilots who fly in Outback Australia’, Safety Science, 68:288-293.
Mitchell TR (1972) Altimetry display study Part 1 – Summary report, Report No. FAA-RD-72-46 I, prepared by The Mitre Corporation for the US Department of Transportation, Federal Aviation Administration.
Orlady HW & Orlady LM (1999) Human factors in multi crew operations, Ashgate, Aldershot, UK.
Paletz SBF, Bearman C, Orasanau J & Holbrook J (2009) ‘Socializing the human factors analysis and classification system: Incorporating social psychological phenomena into a human factors error classification system’, Human Factors, 51:435-445.
Previc FH (2004) ‘Visual illusions in flight’, in FH Previc & R Ercoline (Eds) Spatial disorientation in aviation, American Institute of Aeronautics and Astronautics, Reston VA.
Sanli EA and Carnahan H (2018) ‘Long-term retention of skills in multi-day training contexts: A review of the literature’, Industrial Journal of Ergonomics, 66:10–17.
Shrager JJ (1972) Altimetry display study Part 3 – Review of R&D on display readability, Report No. FAA-RD-72-46 III, prepared by the Navigational Aviation Facilities Experimental Center for the US Department of Transportation, Federal Aviation Administration.
Staal MA (2004) Stress, cognition, and human performance: A literature review and conceptual framework, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2004-212824.
Vlasblom JID, Pennings HJM, Van der Pal J and Oprins EAPB (2020) ‘Competence retention in safety-critical professions: A systematic literature review’, Educational Research Review, 30:10.1016.
Wickens CD, Hollands JG, Banbury S & Parasuraman R (2013) Engineering psychology and human performance, 4th edition, Pearson Boston, MA.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the aircraft operator
the aircraft owner/maintainer
the Civil Aviation Safety Authority
Airservices Australia
Bureau of Meteorology
Aerotrack
United States National Transportation Safety Board
the aircraft manufacturer
Garmin.
Submissions were received from:
the aircraft operator
the Civil Aviation Safety Authority
Bureau of Meteorology
Garmin.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Appendices
Appendix A – Research and guidance regarding design of altimeters
Civil Aviation Order (CAO) 20.18 (Aircraft equipment — basic operational requirements) required that aeroplanes engaged in passenger charter operations under the instrument flight rules (IFR) be equipped with 2 sensitive pressure altimeters. As already noted in Aircraft instruments, VH‑OZO was fitted with two 3-pointer altimeters that met this requirement.
A series of research studies have compared the effectiveness different types of altimeter display. In summarising the research from 1960 to 1972 for the United States Federal Aviation Administration (FAA), Shrager (1972) concluded:
3. Comparative laboratory, simulator, and flight tests of 3P [3-pointer], DP [drum-pointer], CP counter-pointer], and CDP [counter drum pointer] altimeter displays[76] indicate that the least preferred was the 3P and the most desirable was the CDP by subject opinion. This order of ranking is most pronounced when the subjects used were pilots as opposed to nonpilots. The subjective display preference was further accentuated when random dynamic changes in altitude and secondary tasks were introduced into the experiment.
4. The 3P display required the longest time to interpret and produced the largest number of errors among all the production-type displays evaluated. The misreading errors included both those of l,000- and 10,000-foot altitudes. The experimental test results have been supported by significant actual flight experiences on the part of both the military and commercial aviation.[77]
5. A majority of the air carriers and the military have or are converting to displays other than the 3P. The principal display selected has been the CDP.
6. The most prevalent type of altimeter display in general aviation is the 3P. The 10,000-foot error of the 3P display has not been supported by significant actual flight experience by general aviation. However, the 1,000-foot error is a problem in the 3P display.
As part of a related research program, Hoekstra and others (1972) reviewed civil and military accidents during 1964–1970. They noted that problems with misreading an altimeter were cited in a small number of accident investigation reports. For the examples provided, where the type of altimeter was stated or otherwise known, the majority involved 3-pointer altimeters. This study also conducted a survey of various organisations. Its conclusions included:
1. Official investigations have cited altimetry as a causal factor in approximately 1% of all accidents; considering accidents of unknown causes and those where altimetry could possibly have been a factor, it is estimated that altimetry contributes to a maximum of 3% of all accidents. This estimate includes mechanical malfunctions and human errors.
2. Ten to twenty percent of all accidents are "altitude-related" as they involve altitude displacement for some reason.
3. "Altitude-related" accidents occur more frequently in conditions where it is difficult to see the terrain, i.e., at night and in restricted visibility.
4. The majority of "altitude-related" accidents occur during the landing approach. Most are without benefit of vertical guidance from any source other than the altimeter and pilot visual contact with the terrain.
5. Although a few accidents occurred in landing approaches where precision aids were used, they were characterized by a deviation from the glide path after the pilot gained visual contact.
6. Survey comments indicated that the three-pointer altimeter is susceptible to frequent misreading by 1,000 or 10,000 feet, but the number of accidents known to have been caused or possibly could have been caused, by this type of misreading was small. However, several incidents of misreading were reported.
7. Small improvements in the accident rate could be achieved by improving altimetry display, static/pitot systems and setting procedures, but greater improvement would result from the provision of more precision aids and visual warning systems in the ground environment.
A report summarising the FAA research program (Mitchell 1972) concluded that retrofitting of aircraft was not justified. However, it recommended that an advisory circular should be distributed, suggesting that all 3-pointer and drum-pointer altimeters be replaced with counter-drum pointer altimeters where feasible, and that counter-drum pointer altimeters should be required for all yet-to-be-constructed transport category aircraft and more expensive general aviation aircraft.
In 1991, the Flight Safety Foundation launched a campaign to reduce the number of controlled flight into terrain (CFIT) accidents and, together with other organisations, it formed a task force. As part of its work, the FSF CFIT task force made 8 recommendations to the International Civil Aviation Organization (ICAO), including a warning against the use of 3-pointer and drum-pointer altimeters.
ICAO Annex 6 (Operation of Aircraft) Part I (International Commercial Air Transport – Aeroplanes) paragraph 6.9.1 required that aeroplanes operated in accordance with IFR (for commercial air transport) be equipped with 2 sensitive pressure altimeters. Since 1998, it also required that these altimeters have ‘counter drum-pointer or equivalent presentation’. A note under this requirement stated that 3-pointer or drum-pointer altimeters did not satisfy this requirement.[78]
All modern transport aircraft are equipped with vertical altimeter displays or, for some older transport aircraft, counter-drum pointer altimeters. However, 3-pointer altimeters are still very common in general aviation aircraft, including small aeroplanes used for passenger transport activities.
Several experienced pilots interviewed by the ATSB during the investigation reported that misreading a 3-pointer altimeter is more commonly seen in pilots undergoing initial instrument training.
Appendix B – Vacuum system analysis
System overview
VH-OZO had 2 artificial horizon (attitude indicator) instruments and one directional gyro instrument that were powered through hoses connected to a common manifold with 2 sources of power from a vacuum pump on each engine, controlled by in-line regulators. An analogue suction indicator (vacuum gauge) located on the lower left pilot-side instrument panel showed the pilot the net amount of suction at the manifold and ‘dolls eye’ indicators showed if each vacuum pump was operating or not.
Maintenance history
Both artificial horizon instruments and directional gyro instrument as well as vacuum regulators were not subject to service life or maintenance requirements, other than regulator garter filter changes that were being carried out. According to a service bulletin issued by the manufacturer of the vacuum pumps, the vanes could be inspected through a wear indicator port and it recommended the pump be replaced at the wear limit.
The left vacuum pump had been in service for about 1,076 hours and the right for about 911 hours, which exceeded the life of the previous pumps (711 hours and 880 hours respectively). The previous pumps were replaced due to failing in service rather than due to wear. Inspection of pump wear through a port was not carried out consistently by the aircraft maintainer and it is unlikely it was conducted at the previous periodic inspection.
The ATSB identified that the vacuum system manifold had not been tested in the previous 5 years or replaced in the previous 10 years, as specified by the component manufacturer. This was due to an oversight in the maintenance tracking system that was subsequently rectified. A search of the aircraft logbooks did not identify any recorded replacement of the manifold and markings that might indicate component life were indistinct.
Pilots and engineers can carry out an informal test of the manifold by alternating the engine that is started (and/or shut down) first and verifying that either vacuum pump by itself can maintain adequate supply. This was not noted at the recent 100-hour inspection and it is not known if the pilot routinely monitored the operation of each vacuum pump at engine start or shutdown. Damage sustained in the accident prevented functional testing and examination of the internal condition of the manifold.
Although the vacuum manifold was outside its specified service life and its condition could not be verified, if there was an age-related defect there was no effect on aircraft operation unless one of the vacuum pumps failed.
Post-accident inspection
Both vacuum pumps were recovered from the aircraft after the accident and examined.
The right vacuum pump showed evidence of casing deformation and damage consistent with a heavy impact sustained during the accident sequence. When the right vacuum pump was removed from the engine the drive shaft was observed to have sheared. An accurate wear measurement could not be ascertained due to internal damage within the unit. Inspection of the internal components indicated that the pump vanes were intact, and the carbon block had fractured. The support pin had also failed in overload. Inspection of the frangible drive shaft showed damage indicative of overload. Further examination of the frangible shaft fracture surface under a microscope did not identify any features indicative of surface-to-surface rotation contact that may be possible when the engine is running and the pump is seized. Post-accident examination concluded that it was highly likely the pump failed due to the impact with terrain.
The left vacuum pump showed no sign of external damage and the drive shaft was intact. The pump did not show any signs of accident damage. An accurate wear measurement could not be conducted because the pump did not have an inspection port. Inspection of the internal components indicated that the pump vanes and carbon block were intact. The pump internal components were rotated and observed to work as designed. There were no pre- or post-impact defects identified within the left vacuum pump that would make it incapable of supplying pressure as required.
The left artificial horizon instrument and directional guidance instrument were recovered from the aircraft after the accident, disassembled and examined. The left artificial horizon instrument was significantly damaged, however detailed examination of the components did not identify any pre-impact defects. Rotational scoring was noted between the rotor, the casing and the end cap with metal transfer evident (Figure 22). This indicates that the rotor was rotating with significant speed, highly likely produced by suction from the vacuum pump(s), when the aircraft impacted with terrain.
The directional gyro instrument was significantly damaged, with detailed examination producing no identified pre-impact defects with the components that were available for inspection. There was evidence of rotational scoring on the rotor case end and the rotor end. There was no scoring evidence in the rotor case. The rotational scoring indicates that the directional gyro was rotating at significant speed, highly likely produced by suction from the vacuum pump(s), when the aircraft impacted with terrain.
Appendix C – Detailed 1-minute weather data Lockhart River 0850–0930
Appendix D – Guidance to industry regarding stabilised approaches
Overview
This appendix provides examples of guidance provided regarding stabilised approach criteria for flight operations in addition to that provided by the Flight Safety Foundation.
Transport Canada guidance
Transport Canada’s Advisory Circular AC700-028 (Vertical path control on non-precision approaches, issued 2013) was applicable to all flight crew and types of operations. It was issued in 2013, at the same time that NAV CANADA introduced non-precision approach (NPA) charts with constant descent angles. In terms of stabilised approaches, the AC stated:
Many air operators require their crews to use a stabilized approach technique which is entirely different from that envisaged in the original NPA procedure design. A stabilized approach is calculated to achieve a constant rate of descent at an approximate 3° flight path angle; with stable airspeed, power setting, and attitude; and with the aircraft configured for landing. The safety benefits derived from a stabilized final approach have been recognized by many organizations including ICAO, the Federal Aviation Administration, and Transport Canada Civil Aviation (TCCA). Those air operators not already doing so are encouraged to incorporate stabilized approach criteria into their Standard Operating Procedures (SOPs) and training syllabi.
With regard to reference points for stabilised approach criteria, the AC stated:
Stabilized approach criteria should be defined for all approaches and may include:
that flights shall be stabilized by no lower than 1,000 feet (ft.) above the threshold when in instrument meteorological conditions (IMC);
that all flights shall be stabilized by no lower than 500 ft. above the threshold;
that the flight remain stabilized until landing
that if an approach is not stabilized in accordance with these requirements, or has become destabilized afterwards, a go-around is required.[79]
The AC also provided detailed comments regarding step-down versus constant descent angle approach techniques. It noted that step-down techniques were inherently unstable and resulted in higher workload. They also resulted in inconsistent rates of descent and at times high rates of descent, and also extended periods with the aircraft flown at minimum safe altitudes. In contrast, constant descent angle approaches were inherently stable and associated with lighter workload.
In 2015, Transport Canada also issued a Civil Aviation Safety Alert 2015-04 (Stabilized approach) for all commercial air operators (including airline, commuter, air taxi and aerial work). It reiterated the key points of the AC, and noted that:
Rushed and unstabilized approaches remain a significant factor in Controlled Flight Into Terrain (CFIT) and other Approach-and-Landing Accidents (ALA). The safety benefits derived from a stabilized final approach have been recognized by many organizations including ICAO, the FAA, EASA and TCCA. These benefits include:
Increased flight crew situational awareness;
More time and attention for monitoring ATC communications, weather conditions and systems operation;
More time and attention for flight path and energy monitoring;
Defined flight parameter deviation limits and minimum stabilization heights to support the decision to land or to go-around; and,
Landing performance consistent with expected performance values.
It also stated:
Stabilized approach criteria should be defined for all approaches and should include that:
Approaches be stabilized by no lower than 1,000 feet (ft) above aerodrome elevation (AAE) when in instrument meteorological conditions (IMC);
All approaches be stabilized by no lower than 500 ft AAE in visual meteorological conditions (VMC);
A call be made upon reaching 1000 ft AAE in IMC or 500 ft AAE in VMC as to whether the approach is stabilized or not;
The approach remain stabilized until landing;
If an approach is not stabilized in accordance with these requirements, or has become destabilized afterwards, a go-around is required.
Federal Aviation Administration guidance
The United States Federal Aviation Administration issued guidance for general aviation pilots regarding CFIT in Advisory Circular AC 61-134 (General aviation controlled flight into terrain awareness), issued in 2003. The background section stated:
According to FAA information, general aviation CFIT accidents account for 17 percent of all general aviation fatalities. More than half of these CFIT accidents occurred during IMC…
Because a single-piloted, small GA aircraft is vulnerable to the same CFIT risks as a crewed aircraft but with only one pilot to perform all of the flight and decision-making duties, that pilot must be better prepared to avoid a CFIT type accident…
Under a section regarding GA operations in IMC on an IFR flight, the AC stated:
These operations also pose special risks. Whether it is failure to follow safe takeoff and departure techniques, recommended en route procedures ― which includes loss of situational awareness ― or failure to maneuver safely to a landing, IFR operations can be dangerous for those not prepared to operate or not current and proficient in the IMC and IFR environments. Many of these accidents result in fatalities. Techniques or suggestions for avoiding some of these IFR risk factors include…
s. The importance of flying a stabilized approach. A common definition of a stabilized approach is maintaining a stable speed, descent rate, vertical flightpath, and configuration throughout the final segment of the approach. Although originally designed for turbojet aircraft, a stabilized approach is also recommended for propeller-driven aircraft. The idea is to reduce pilot workload and aircraft configuration changes during the critical final approach segment of an approach. The goal is to have the aircraft in the proper landing configuration, at the proper approach speed, and on the proper flightpath before descending below the minimum stabilized approach height. The following are recommended minimum stabilized approach heights.
(1) 500 feet above the airport elevation during VFR weather conditions.
(2) MDA or 500 feet above airport elevation, whichever is lower, for a circling approach.
(3) 1,000 feet above the airport or touch down zone elevation during IMC.
In 2011, the United States Federal Aviation Administration (FAA) issued AC 120-108 (Continuous descent final approach), providing guidance for operators on the continuous descent final approach technique for NPAs. The AC was intended for airline and air taxi operators, though it noted the guidance was beneficial to all operators. The background section stated:
Controlled flight into terrain (CFIT) is a primary cause of worldwide commercial aviation fatal accidents. Unstabilized approaches are a key contributor to CFIT events. Present NPAs are designed with and without stepdown fixes in the final approach segment. Stepdowns flown without a constant descent will require multiple thrust, pitch, and altitude adjustments inside the final approach fix (FAF). These adjustments increase pilot workload and potential errors during a critical phase of flight. NPAs designed without stepdown fixes in the final segment allow pilots to immediately descend to the MDA after crossing the FAF. In both cases, the aircraft remains at the MDA until descending for the runway or reaching the missed approach point (MAP). This practice, commonly referred to as “dive and drive,” can result in extended level flight as low as 250 feet above the ground in instrument meteorological conditions (IMC) and shallow or steep final approaches.
In terms of stabilised approaches, the AC 120-08 stated:
A stabilized approach is a key feature to a safe approach and landing. Operators are encouraged by the FAA and the International Civil Aviation Organization (ICAO) to use the stabilized approach concept to help eliminate CFIT. The stabilized approach concept is characterized by maintaining a stable approach speed, descent rate, vertical flightpath, and configuration to the landing touchdown point. Depart the FAF configured for landing and on the proper approach speed, power setting, and flightpath before descending below the minimum stabilized approach height; e.g., 1,000 feet above the airport elevation and at a rate of descent no greater than 1,000 feet per minute (fpm), unless specifically briefed. (Refer to AC120-71.)
The FAA also issued guidance regarding stabilised approaches in AC 91-79A (Mitigating the risks of a runway overrun upon landing), issued in 2014 and last updated in 2018. The intended audience was all pilots, flight crew and operators. The AC stated in part:
Stabilized on Profile. The airplane should be stabilized on profile before descending through the 1,000-ft window or through the 500 ft above touchdown zone elevation (TDZE) window in visual meteorological conditions (VMC). Configuration, trim, speed, and glidepath should be at or near the optimum parameters early in the approach to avoid distractions and conflicts as the airplane nears the threshold window. The electronic or visual glidepath or an optimum glidepath angle of 3 degrees should be established and maintained…
Indicated Airspeed. Indicated airspeed should be not more than VREF + 5 or the POH published approach airspeed, with appropriate adjustments for wind or other factors, and never less than VREF or the appropriate airspeed in order to avoid the loss of aircraft control.
United States Aircraft Owners and Pilots Association
The United States Aircraft Owners and Pilots Association (AOPA) stated in a 2000 article (The stabilized approach):
Most of us don’t have to worry about the vagaries of turbine aircraft and their response to power and speed changes on approach. But there are plenty of good reasons to fly stabilized approaches regardless of whether you fly a Cessna Skyhawk or Golden Eagle, Beech King Air or Piper Super Cub. Here are a few:
It reduces workload…
It gives us more opportunity to see the big picture…
It slows the aircraft down earlier, allowing more time to think…
It allows more time to react...
It makes it easier to fly the VOR, ILS, or ADF needles...
It allows the pilot more opportunity to detect changes in the wind on approach…
It reduces the variables and thus reduces our required reactions to these changes. When you have the airspeed nailed early, you have one less variable to worry about, freeing you to focus on other things. If we can set the power and mostly forget it, we don't have to constantly change power in response to our configuration and speed changes.
It creates the time to finish your before-landing checklist and to really look around the airplane for other things you might have missed or neglected when rushed...
It makes the approach—and thus the landing spot—predictable because you do it the same every time.
Notice that time is the major benefit when we fly a stabilized approach. Time allows us to more easily perceive changes and then make corrections to course, altitude, or airplane management.
Most airlines set the stabilized approach point at 500 feet in visual conditions and 1,000 feet when the weather is IMC. These 500- and 1,000-foot target points might be a good starting place when establishing your own stabilized approach minimums. You might also want to use 1,000 feet for night approaches and landings because the fewer visual cues at night reduce your ability to perceive differences and changes.
Appendix E – Aurukun incident flight – 22 January 2020
Introduction
On 22 January 2020, on a flight from Weipa to Aurukun, the pilot conducted 2 RNAV (GNSS) approaches to runway 34 at Aurukun in VH-OZO, with the first approach followed by a missed approach.
An extract of the relevant Airservices Australia approach chart is depicted in Figure 23. As indicated in the chart, the recommended initial approach altitude was 1,800 ft, with the recommended 3° approach profile to the runway threshold commencing just prior to the final approach fix (FAF). The minimum descent altitude (MDA) for a pilot with an actual QNH was 450 ft.
The ATSB analysed OzRunways GPS data from the 2 approaches and the missed approach (Figure 24). The data was recorded at 5-second intervals. Recorded altitude, lateral position and groundspeed data for the 2 approaches from the initial approach fix (IAF) to the missed approach point (MAPt) is shown in Figure 25.
The recorded altitudes were slightly below the recommended approach profile during the 2 approaches. Aurukun Airport has an elevation of about 30 ft above sea level, and one of the passengers recalled observing the altimeter reading 50–100 ft when the aircraft was on the ground after landing. This indicated the QNH set on the altimeter may not have accurately reflected the actual QNH when the aircraft landed,[80] and the altimeter may have been slightly overreading during the approaches. In addition, the recorded altitude data was truncated to the nearest 100 ft.
Figure 23: Extract of the Aurukun RNAV (GNSS) RWY 34 approach
Source: Airservices Australia, annotated by the ATSB
Figure 24: VH-OZO recorded data 22 January 2020 at Aurukun, Queensland
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
First approach
The data showed that the aircraft approached from the north and about 1,100 ft and overflew the runway 34 threshold before continuing to track south. After passing about 3 NM west of the initial approach fix (IAF) AURSB at 1,500 ft, the aircraft turned 180° then passed 1 NM to the west of the IAF and then tracked direct towards the intermediate fix (IF) AURSI at 1,500 ft. About 1 NM prior to AURSI, the aircraft climbed to 1,700 ft and passed over the IF.
The aircraft was at 1,600 ft when it reached the FAF AURSF, and it then commenced the descent on about a 3° profile (Figure 25). The aircraft was about 200–300 ft below the recommended 3° descent profile when it reached the MDA, about 1.8 NM prior to the MAPt AURSM. The minimum recorded altitude the aircraft descended to (1 data point) was 200 ft when 1.2 NM prior to the MAPt, and it was at a recorded altitude of 200–300 ft over 4 data points (15–20 seconds) prior to reaching the MAPt.
Figure 25: Recorded data for 2 RNAV approaches to Aurukun 22 January 2020
Source: ATSB
The descent rate from the FAF (recorded height 1,600 ft) until the aircraft reached 900 ft was about 650 ft/min, and the descent rate for the remainder of the descent was about 1,050 ft/min.
A review of wind and temperature forecast and analysis charts from multiple sources and other information indicated that the indicated airspeeds would have been about 5 kt higher than the recorded groundspeeds during the 2 approaches while the aircraft was on or near the intermediate/final approach track. Therefore, on the first approach the indicated airspeed was about 140 kt when the aircraft passed the FAF, about 145 kt when the aircraft passed through the MDA and about 140 kt when the aircraft reached a height of 300 ft above aerodrome elevation.
Missed approach
A missed approach was commenced prior to the MAPt, with the aircraft climbing and passing 0.2 NM to the right of the MAPt. The aircraft passed over the Aurukun township at an altitude of about 800 ft, then turned left and heading south, climbing to 1,900 ft.
The published missed approach commenced at AURSM and required the aircraft to maintain runway direction for 3 NM before turning left to heading 170° and climbing to 1,700 ft. Based on witness reports, it is possible that the pilot was avoiding a nearby thunderstorm during the missed approach and/or was in visual conditions at the time.
The exact reasons for the missed approach could not be determined (that is, whether it was due only to reduced visibility of the runway at the time or also due to the aircraft’s speed not meeting the operator’s stabilised approach criteria at 300 ft above aerodrome elevation).
Second approach
The aircraft then headed south to about 8 NM south-south west of AURSB, before turning back to the IAF and then doing a holding pattern before again approaching the IAF. The pilot then commenced a second RNAV approach about 31 minutes after the first approach from an altitude of about 1,900 ft. The aircraft was close to the published descent profile throughout the approach and also within the required lateral tolerances.
Given the indicated airspeeds were about 5 kt higher than the recorded groundspeeds, the indicated airspeeds were 135 kt at the FAF and 105 kt at 300 ft above aerodrome elevation. Overall, the approach appeared to comply with the operator’s stabilised approach criteria.
Appendix F – Related occurrences
Collision with Terrain involving Fairchild Metro 23 aircraft, VH-TFU, 11 km north-west of Lockhart River Airport, Queensland, on 7 May 2005
On 7 May 2005, a Fairchild Aircraft Inc. SA227-DC Metro 23 turbo-prop aircraft, registered VH-TFU, with 2 pilots and 13 passengers, was being operated on an instrument flight rules (IFR) regular public transport service from Bamaga to Cairns, with an intermediate stop at Lockhart River, Queensland. At 1143:39 local time, the aircraft impacted terrain 11 km north-west of the Lockhart River Airport. At the time of the accident, the crew was conducting an area navigation global navigation satellite system (RNAV GNSS) non-precision approach to runway 12. The occupants were fatally injured and the aircraft was destroyed.
The accident was almost certainly the result of a controlled flight into terrain. Weather conditions in the Lockhart River area were poor and necessitated the conduct of an instrument approach procedure for an intended landing at the aerodrome. The cloud base was probably between 500 ft and 1,000 ft above mean sea level and the terrain to the west of the aerodrome, beneath the runway 12 RNAV GNSS approach, was probably obscured by cloud.
The investigated identified a significant number of contributing factors and other safety factors associated with the crew’s performance, local conditions, the operator’s procedures and regulatory oversight. With relevance to the findings of the 2020 accident involving VH-OZO, these included the aircraft descending below the segment minimum safe altitude for the aircraft’s position on the approach (after passing the final approach fix) and the speeds and descent rate exceeding those appropriate for a stabilised approach. The operator’s procedures did not provide clear guidance on approach speeds, when to select aircraft configuration changes during an approach and clear criteria for a stabilised approach. There were also problems with the operator’s processes for supervising the standard of flight operations, and the operator did not have a structured process for managing safety-related risks.
The aircraft was fitted with a ground proximity warning system (GPWS), but there would have been insufficient time for the crew to effectively respond to the GPWS alert and warnings that were probably annunciated during the final 5 seconds prior to impact with terrain. The aircraft was not fitted with a terrain avoidance and warning system (TAWS).
The GPS unit fitted to the aircraft (Garmin GPS 155XL) also had several limitations compared with more recent models available at the time. These included the limited usefulness of the moving map display because of the vertical size of the screen size, the lack of an option to display a distance to the missed approach point (MAPt) throughout the approach, and the lack of any form of vertical advisory guidance.
Additional CFIT investigations in Australia
The ATSB has investigated a number of other CFIT accidents in Australia, all involving aircraft that were not fitted with a TAWS. These included the following occurrences.
On 10 December 2001, a Raytheon Beech 200C Super King Air was being operated under the IFR to Mt Gambier, South Australia, on an aeromedical flight with the pilot and a medical crew member on board. At approximately 2333 local time, the pilot reported to air traffic control that they were in the circuit at Mt Gambier and would report after landing. At approximately 2336, the aircraft impacted the ground at a position 3.1 NM from the threshold of the runway. The pilot was fatally injured and the medical crew member sustained serious injuries.
Dark night conditions existed in the area. The available evidence indicated that the pilot was conducting a GPS arrival procedure.
On 15 May 2003, a Raytheon Beech 200C Super King Air was being operated under the IFR to Coffs Harbour, New South Wales, on an aeromedical flight with a pilot, 2 medical crew and a patient on board. The pilot conducted a missed approach from a low height and the aircraft impacted the sea, or a reef, approximately 3.2 NM north of the airport at about 0833 local time. During the missed approach, the aircraft narrowly avoided a breakwater and an adjacent restaurant. During the subsequent landing the aircraft was substantially damaged.
The pilot was conducting a GPS non-precision approach. Instrument meteorological conditions (IMC) existed at the time, including heavy rain and restricted visibility.
On 28 July 2004, a Piper PA-31T Cheyenne, with one pilot and 5 passengers, was being operated on a private IFR flight from Bankstown, New South Wales, to Benalla, Victoria. The aircraft collided with terrain 18 NM south-east of Benalla. All occupants were fatally injured and the aircraft was destroyed.
IMC existed at the time and the pilot had reported commencing a GPS non-precision approach to Benalla.
On 28 July 2004, a Piper PA31-350 Navajo Chieftain was being operated under the IFR to Mount Hotham, Victoria on a passenger charter flight with the pilot and 2 passengers on board. The aircraft collided with terrain 5 km south-east of the aerodrome and to the left of the extended centreline of runway. All occupants were fatally injured and the aircraft was destroyed.
IMC existed at the time and the pilot had reported commencing an RNAV GNSS approach.
Appendix G – Flight Safety Foundation CFIT Checklist
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR). Procedures and training are significantly more complex as a pilot must demonstrate competency in IMC conditions while controlling the aircraft solely by reference to instruments. IFR-capable aircraft have greater equipment and maintenance requirements.
[2] Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10.0 hours.
[3] In the Lockhart River area, VHF contact with air traffic services was not generally available below 4,500 ft. Outside of VHF coverage, pilots communicated with Flightwatch using HF radio.
[4] Cloud cover: in aviation, cloud cover of the sky is reported using words/abbreviations that denote the extent of the cover. ‘Sky clear’ (SKC) indicates no cloud, ‘few’ (FEW) indicates 1–2 oktas (or eighths) is covered, ‘scattered’ (SCT) indicates 3–4 oktas is covered, ‘broken’ (BKN) indicates 5–7 oktas is covered, and ‘overcast’ (OVC) indicates that 8 oktas is covered.
[5] Landing minima: specified meteorological conditions of cloud ceiling and visibility. In order for an aircraft to land at an aerodrome, the actual weather conditions need to be at or above the landing minima.
[6] The ATSB obtained data broadcast by the automatic dependent surveillance broadcast (ADS-B) equipment fitted to the aircraft and GPS data transmitted from the pilot’s iPad with the OzRunways application installed. Further information on the aircraft’s recorded flight path during the 2 approaches is provided in Recorded flight data.
[8] The MDA published on the instrument approach chart was 830 ft and was based on the aerodrome forecast (TAF) QNH being set on the subscale of the aircraft’s pressure-sensitive altimeter. For this chart, the MDA could be reduced by 100 ft (to 730 ft) when using the actual QNH from an approved source. With the aircraft above the aerodrome and the actual QNH set, the altimeter indicates the approximate height above mean sea level. The aerodrome’s AWIS was an approved source for actual QNH and valid for a 15-minute period from the time of receipt.
[9] Flightwatch: on-request flight information service used to provide operational information including weather, aerodromes and navigational aids.
[10] VFR: a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
[11] The operator’s operations manual stated: ‘Due to the possibility of engine damage, asymmetric training in Company Cessna 404 aircraft is to be undertaken only where strictly necessary. Abrupt or large power changes are to be avoided where possible.’
[12] Instrument meteorological conditions (IMC): weather conditions that require pilots to fly primarily by reference to instruments, and therefore under instrument flight rules (IFR), rather than by outside visual reference. Typically, this means flying in cloud or limited visibility.
[13] The aerodrome forecast for that flight included periods of reduced visibility (3,000 m) in rain showers and cloud at 1,200 ft. Data from the aerodrome’s automatic weather station indicated the 1-minute visibility was 2,500 m at the airport when the aircraft passed the initial approach fix (IAF). However, the visibility had improved to 4,200 m by the time the aircraft reached the final approach fix (FAF) and continued to improve, to more than 10 km by the missed approach point (MAPt). There was no recorded rainfall during this period. The forecast and observed wind favoured a landing on runway 12.
[14] This aircraft retained the conventional airspeed indicator, altimeter and vertical speed indicator flight instruments, which were mounted in their usual positions relative to the ADI display. Those instruments were similar to the instruments fitted to VH-OZO.
[15] A number of other Cessna 404 aircraft introduced to Australia at about the same time also had modified seating arrangements with 11 passenger seats.
[16] An altitude alerting system provides an aural alert (tone) and/or a visual alert when an aircraft on climb/descent approaches the designated altitude and when deviating from that altitude during cruise. They are generally used to assist pilots monitor adherence to the ATC assigned level in controlled airspace, rather than mitigate the risk of controlled flight into terrain. Civil Aviation Order (CAO) 20.18 required aircraft conducting IFR operations in controlled airspace to have either an assigned altitude indicator or an altitude alerting system. For piston-engine aircraft, an altitude alerting system was only required for IFR operations above flight level 150 (which is 15,000 ft measured according to a standard atmosphere).
[17] Second CDI is partially hidden behind control column and clamp in Figure 8.
[18] The wide area augmentation system (WAAS) was developed by the US Federal Aviation Administration. The system provided augmentation information to GPS receivers, which improved the position accuracy and enabled localiser performance with vertical guidance (LPV) approaches to the runway. Those approaches took advantage of the increased position accuracy and were flown to a decision altitude, similar to a Category I instrument landing system procedure. The WAAS system covered most of the US, parts of Canada and Mexico.
[19] The default settings for the user-selectable fields were distance to the next waypoint, desired track, bearing to waypoint, groundspeed, ground track and estimated time en route.
[20] The navigation and terrain data were contained on 2 removable data cards, which slotted into the front face of each unit.
[21] One of the GNS 430W units was swapped with that from another aircraft in July 2018. The last terrain/obstacle database update of that unit was not determined.
[22] The series of Technical Standard Orders (TSO) C151 stipulated the minimum operational performance standards that a terrain awareness and warning system (TAWS) must meet to comply with regulatory requirements for the fitment and use of those systems.
[23] FLTA alerts were automatically inhibited when the aircraft was less than 200 ft above terrain while within 0.5 NM of the runway, or less than 125 ft above terrain within 1.0 NM of the runway.
[24] With approach flap selected, the inboard flap surface extended 10° and the outboard flap surface extended 8°.
[25] Vref: reference landing speed. It is normally defined as the speed required when crossing the runway threshold at 50 ft given the landing weight and configuration of the aircraft. It is usually calculated as 1.3 times the stalling speed in the landing configuration and at the prevailing aircraft weight.
[26] The operations manual used the term VAPP and Vref interchangeably. Often VAPP is used to refer to Vref plus additions for wind and other factors.
[27] Turbo-prop aeroplanes such as the SAAB 340 (maximum 37 passengers) and the Embraer EMB 120 (maximum 30 passengers) had a MTOW less than 15,000 kg.
[28] ICAO annexes specified standards and recommended practices (SARPS).
[29] In its notice of proposed amendment, the European Aviation Safety Agency (EASA) noted that the absence of a TAWS had been noted as a factor in 2 accidents in Europe for these types of aircraft in the previous 10 years. It also noted that new aeroplanes were already fitted with a TAWS and that a significant number of older aeroplanes had already been retrofitted with a TAWS or equivalent system. EASA also noted that the cost of fitting a TAWS in Europe was between €20,000 to €50,000.
[30] Transport Canada also noted that it had considered only introducing this requirement for turbine-engine aeroplanes (as per the US FAA) but that some stakeholders noted that some operators may discontinue using turbine-engine aeroplanes in favour of (less reliable) piston-engine aeroplanes to eliminate the cost of installing TAWS.
[31] MOPSC was defined at that time as the maximum passenger seat capacity of the aircraft, excluding pilot seats, flight deck seats and cabin crew seats.
[32] When the aeroplane was operated by a single pilot, this included the 11 passenger seats in the cabin and the front right seat, as that could also be used by a passenger. CASA further advised that an aeroplane with 2 seats at the front and 9 seats in the cabin (such as a Cessna 404 with the seating configuration specified in its type certificate data sheet) would be considered to have a MOPSC of 9 and the front right seat would not have to be removed.
[33] CASA advised that the definition of MOPSC referred to the number of passenger seats fitted to an aircraft available to be used by a passenger. An operator could not elect to limit the number of seats of an aircraft with a MOPSC of 10 or more through administrative or operational controls in order to have a MOPSC of 9 or less. Rather, seats would have to be physically removed from the aircraft.
[34] A SIGMET provides a concise description concerning the occurrence or expected occurrence, in areas over which meteorological watch is being maintained, of en-route weather phenomena that are potentially hazardous to aircraft.
[35] Visual meteorological conditions (VMC): an aviation flight category in which visual flight rules (VFR) flight is permitted – that is, conditions in which pilots have sufficient visibility to fly the aircraft while maintaining visual separation from terrain and other aircraft.
[36] In aviation meteorological products, time is expressed as coordinated universal time (UTC) and the data is generally expressed in coded terms. For ease of reference, the time has been converted to EST and the data has been decoded.
[37] In aerodrome forecasts and reports, the height datum for cloud is aerodrome elevation.
[38] TEMPO: a significant temporary variation from the prevailing conditions previously given in the TAF, expected to last for periods of between 30 and 60 minutes.
[39] Visibility reported in METARs/SPECIs was a 10-minute average.
[40] This improved the ceilometer’s response time to report changing conditions.
[41] In May 2012, BoM published a pamphlet Ceilometers and Visibility Meters as part of their aviation reference material series (available from www.bom.gov.au). The pamphlet provided information about the measurements made by these instruments and the associated advantages and limitations of the equipment.
[42] The term okta is used to refer to one eighth of cloud cover.
[43] From 9 September 2021, the naming of RNAV (GNSS) charts in Australia was progressively changed to RNP (required navigation performance) in alignment with an international convention.
[44] APV Baro-VNAV procedures required a navigation system capable of continuously computing a barometric VNAV path and displaying the relevant information on the instrument display.
[45] Civil Aviation Regulation 178 (Minimum height for flight under I.F.R.) stated that a pilot could not fly below a published lowest safe altitude except under certain conditions, such as during arrival if the aircraft was being flown in accordance with any instructions in the AIP, during an authorised instrument approach procedure, or if the aircraft was being flown by day in VMC.
[46] Availability of RAIM during the conduct of an RNAV GNSS approach provides an assurance of the integrity of the navigation system and that the calculated position is within the required tolerance for the procedure being flown.
[47] This paragraph and other AIP references were correct for the edition current at the time of the accident. That paragraph numbering may have changed during subsequent revisions of the publication.
[48] As discussed in the section GNS 430W overview, these receivers used satellite or ground-based augmentation (in regions where augmentation was available) to improve the position accuracy, enabling approaches providing localiser performance with vertical guidance (LPV) that could be flown to a decision altitude, similar to a Category I instrument landing system procedure.
[49] GPS units in the manufacturer’s 400 series without the ‘W’ designation (for example GPS 400, GNS 430/430A) used 0.3 NM CDI full-scale during the final approach segment. Those units could not be used to conduct LPV procedures.
[50] The approach procedure instructions published in the AIP to be established on the specified track before commencing descent were different to the navigation tolerances specified for the approach.
[51] For an aircraft conducting the Lockhart River RNAV (GNSS) runway 30 approach, descending on the recommended constant angle 3° profile, the aircraft crosses the FAF about 360 ft above the intermediate segment MSA.
[52] The CASA CNS/ATM resource kit (Chapter 9: Instrument flight rules operations, Flying the approaches), on the CASA website, also stated that ‘The tracking tolerance is half of full-scale deflection regardless of the CDI scale’. This resource kit content was based on the pre-December 2021 legislation but remained on the CASA website after December 2021.
[53] VAT is the indicated airspeed at the runway threshold (50 ft), which is equal to the stalling speed with landing gear extended and flaps in the landing position multiplied by 1.3. It is calculated at the aircraft’s maximum landing weight. At the maximum landing weight, VAT and Vref are the same.
[54] The aircraft was fitted with on-board Automatic Dependent Surveillance Broadcast (ADS-B) equipment, transmitting real-time operational data that enabled air traffic service providers to track aircraft. Airservices Australia recorded the transmissions received by its network of ADS-B receivers. That data could also be received by privately-operated equipment used to feed information to flight tracking websites.
[55] OzRunways is an electronic flight bag application that helps flight crew perform flight management tasks without the need for paper-based information. The OzRunways application also recorded flight data via a built-in GPS receiver. The data used in this investigation was transmitted from an iPad during the flight.
[56] 1 hPa difference equates to an altitude difference of about 30 ft.
[57] As previously noted, due to recorded altitude being truncated, this data have meant an altitude of 400–499 ft. The elevation of the terrain in the area was about 100 ft.
[58] According to the POH, the maximum gear extension speed was 182 kt, the maximum speed to select take-off and approach flap was 182 kt, and the maximum speed to select landing flap was 152 kt.
[59] Search and rescue time (SARTIME): the time nominated by a pilot for the initiation of search and rescue (SAR) action. If the pilot does not contact the SARTIME holder by the allotted time the search and rescue response will begin.
[60] The chief pilot advised the ATSB that, at some point prior to 29 October 2019, a Notice to Aircrew (number 13) was issued which outlined the operator’s change of requirements for OPCs to a period not exceeding 24 months.
[61] In this case, the pilot had conducted multiple flights under the IFR of over 1-hour duration in the last 6 months. On such flights, they had recorded a maximum of 30 minutes IFR flight time on these flights in their logbook.
[62] NOTAM: a notice distributed by means of telecommunication containing information concerning the establishment, condition or change in any aeronautical facility, service procedure or hazard, the timely knowledge of which is essential to personnel concerned with flight operations.
[63] The flight data used in this investigation was transmitted from the iPad during the approach.
[64] A descent rate of 600 ft/min requires a groundspeed of 113 kt to achieve a 3° approach path angle.
[65] CASA’s Air Operator’s Certificate Handbook: Volume 2 – Flying Operations stated in version 3.0 (November 2018) that ‘The use of the stabilised approach concept is mandatory for all approach operations.’ No further guidance regarding the contents of this guidance was included.
[66] The AIP also stated that, after passing the FAF, the descent rate ‘should not normally’ exceed 1,000 ft/min.
[67] ATSB Aviation Occurrence Report 200501977, Collision with Terrain, 11 km NW Lockhart River Aerodrome, 7 May 2005, VH-TFU, SA227-DC.
[69] The ATSB also reviewed the recorded data for 2 other straight-in approaches that the pilot logged as RNAV GNSS approaches in September to October 2019. The recorded groundspeeds were 145–150 kt at the FAF, 140–155 kt at 1,000 ft and 115–135 kt at 300 ft. A full review of winds and indicated airspeeds was not conducted.
[70] ATSB Occurrence Report 200501977, Collision with Terrain, 11 km NW Lockhart River Aerodrome, 7 May 2005, VH-TFU, SA227-DC (Metro 23).
[71] In addition to these accidents, notable CFIT accidents during non-precision instrument approaches resulting in multiple fatalities also occurred on 11 June 1993 (Piper PA-31 piston-engine aircraft on scheduled passenger transport flight to Young, New South Wales, on an NDB/circling approach, 7 fatalities) and 27 April 1995 (Israel Aircraft Industries Westwind 1124 turbojet aircraft on scheduled freight flight to Alice Springs, Northern Territory, on a twin locator NDB approach, 3 fatalities).
[72] Between October 1999 and December 2000, there was a requirement for passenger transport operators under the IFR in turbine-engine aeroplanes with a MTOW more than 15,000 kg or carrying more than 9 passengers to conduct CFIT hazard awareness if the aircraft was not fitted with a GPWS or TAWS. After that time, all such aircraft were required to have a GPWS or TAWS. Some operators continued to include CFIT hazard awareness training as a requirement in their operations manual. Further details are provided in ATSB Occurrence Report 200501977.
[73] The operator’s operations manual also stated: ‘Extreme caution should be exercised in low visibility operations. Note that when encountering low visibility conditions due to rain, it is important to be aware that an illusion of being too high can occur, with a resulting undershoot being a possibility.’
[74] The MOPSC for an Australian operator was defined as the maximum passenger seat capacity of the aircraft approved by CASA as part of the approval of the operator’s exposition under CASR Part 119 and specified in the operator’s operations manual.
[75] That is, aeroplanes certified to be operated by a single pilot in accordance with the type certificate data sheet and whose flight manual provided that the flight crew could consist of a single pilot.
[76] A drum pointer altimeter has a single pointer that indicates tens and hundreds of feet, while a single drum indicates thousands and tens-of-thousands of feet (and fractions thereof) in numerals. A counter-drum pointer altimeter includes a single pointer that indicates tends and hundreds of feet while one or more coupled drums (or counters) indicated hundreds, thousands and tens-of-thousands of feet.
[77] Previous research conducted by Fitts and Jones (1947) also identified similar problems with misreading of 3-pointer altimeters, particularly in terms of misreading by 1,000 ft and misreading by 10,000 ft. They found that misreading of altimeters was the most common error in interpreting aircraft instruments at that time.
[78] The same exclusion for 3-pointer and drum-pointer altimeters was not stated in ICAO Annex 6 Part II International General Aviation – Aeroplanes.
[80] 1 hPa difference equates to an altitude difference of about 30 ft.
Preliminary report
Report release date: 11/06/2020
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
First phase of the flight
On 11 March 2020, Air Connect Australia was operating a Cessna 404, registered VH-OZO, on a passenger charter flight from Cairns to Lockhart River and return (Figure 1). The client arranged for the aircraft to depart Cairns at 0730 Eastern Standard Time[1] with four passengers, wait on the ground at Lockhart River for about 5 hours, then depart at 1430 with the same passengers for the return flight. The operator assigned the pilot who regularly conducted the client’s charter flights.
Figure 1: Location of Cairns and Lockhart River in north Queensland, Australia
Source: Google Earth, annotated by the ATSB
According to the weather forecasts, the pilot could expect mostly visual meteorological conditions (VMC)[2] during the day at Cairns with some periods of rain showers and low cloud. For the arrival at Lockhart River, the forecast weather was predominately VMC but there were overlapping periods of rain and low cloud with 30 per cent probability of thunderstorms.
The pilot had submitted a flight notification, which specified instrument flight rules (IFR)[3] and capability for an area navigation (RNAV) instrument approach. On the morning of the flight, the pilot refuelled the aircraft with 650 L of avgas.
The aircraft departed Cairns at 0719 and the pilot tracked for the first planned waypoint on climb to 10,000 ft above mean sea level. Based on the forecast winds, the estimated time of arrival (ETA) at Lockhart River was 0852. As the flight progressed, the pilot amended the ETA to 0904.
At 0840, the pilot advised air traffic control that he was leaving 10,000 ft on descent to Lockhart River. A couple of minutes later, the controller advised the pilot of the very high frequency (VHF) and high frequency (HF) radio frequencies applicable to the rest of the flight. That was the controller’s last contact with the pilot and no further routine interactions with the controller were expected.[4]
During descent, the pilot transmitted on the common traffic advisory frequency (CTAF) for Lockhart River to enable the pilot activated lighting (PAL) for a period of 30 minutes. At 0852, the aerodrome frequency response unit (AFRU) broadcast ‘Lockhart River CTAF, runway lights are on.’
As the aircraft was descending, the pilot tracked to waypoint LHREB, one of three initial approach fixes for the RNAV (GNSS) runway 30 instrument approach at Lockhart River.
First approach at Lockhart River
Note: Figure 2 and Figure 4 provide information on the pilot’s first approach and Figure 3 and Figure 4 provide information on the second approach. Figure 11shows the applicable approach chart, and key parameters for the approachesare incorporated into Figures 2, 3 and 4.
The aircraft flightpath parameters referenced in the following text and shown in Figures 2, 3, and 4 are taken from transmitted GPS data recorded at 5-second intervals by an electronic flight bag application. The quoted heights are geometric altitudes rather than barometric altitudes indicated by an altimeter, which is the primary altitude reference for this approach. The ATSB notes that GPS altitude was transmitted as a rounded value so the recorded altitude could vary up to 100 ft from the actual GPS-computed geometric altitude. Preliminary validation of the flight data indicates that the recorded geometric altitudes correlate with barometric altitude data that is available for part of the flight.
The pilot passed abeam LHREB at 0859:38 on descent through 5,400 ft and turned left to track to the runway in accordance with the RNAV procedure.
At 0901:25, the pilot made a radio broadcast on the CTAF, advising the aircraft was 10 NM to the south-east of the aerodrome, inbound to runway 30 and on descent passing 4,000 ft. Shortly afterwards, the aircraft passed intermediate approach fix LHREI at 4,000 ft.
The pilot continued the descent and inbound track to pass the final approach fix LHREF on descent through 2,300 ft. At 0904:27, the pilot broadcast on the CTAF that he was 5 NM out and on final (approach) to runway 30.
The aircraft arrived at the missed approach point LHREM at 0906:17 and 570 ft. The specified minimum descent altitude (MDA) was 830 ft, which could be lowered by 100 ft if the pilot set the current aerodrome QNH[5] from the automated weather information service (AWIS). The pilot continued the descent to 500 ft then climbed to 600 ft and maintained the approach track for a further 2 NM. Coincident with passing over the aerodrome facilities, the pilot initiated a missed approach and, while climbing, turned slightly right to track to the missed approach turning fix LHREH.
At 0907:22, the pilot broadcast on the CTAF that he was conducting a missed approach for runway 30, tracking to the west then turning back to the east and climbing to 3,500 ft.
After passing LHREH at 0907:43 on climb through 1,200 ft, the pilot made a right turn to track to the east as prescribed by the approach chart. At 0908, the pilot contacted Flightwatch on HF to advise of the missed approach and his intention to provide an update of ‘operations normal’ by 0930. The middle part of this radio transmission, as recorded by Airservices Australia, was unclear, which is not uncommon for HF radio communication. Based on the fragments and context, the pilot was probably advising his intention to conduct another approach.
The pilot continued the climb to 3,500 ft as specified for the missed approach procedure.
Figure 2: Flight track of VH-OZO during first RNAV (GNSS) approach at Lockhart River Aerodrome with time stamps, feature labels, and approach parameters superimposed
Source: Google Earth, annotated by the ATSB
Second approach at Lockhart River
Following the missed approach, the pilot levelled the aircraft at 3,500 ft and turned from the easterly heading towards the closest initial approach fix LHREA. At 0912:51, the AFRU recorded runway lights on, consistent with the pilot reactivating the runway lights for another 30-minute period.
About 2 NM from LHREA, the pilot turned right toward the general direction of intermediate approach fix LHREI and tracked to the south-west for about 2 NM then turned left to intercept the defined inbound track to LHREI. The pilot started descent from 3,300 ft at 0915:18.
At 0915:50, the pilot made another inbound broadcast on the CTAF advising:
10 miles [NM] to the south-east on descent passing three thousand eight hundred [3,800 ft] [unclear phrase, possibly ‘correction’] two thousand eight hundred [2,800 ft], straight-in approach runway three zero [30], circuit area two one [time 0921].
At the start of the transmission, the aircraft was on descent through 2,900 ft. The ATSB notes that the recorded transmission sounded routine; no further transmissions from VH-OZO were recorded.
After passing over LHREI, the pilot flew parallel to the defined RNAV approach track and continued the descent at a similar gradient to the first approach. About halfway between LHREI and final approach fix LHREF, the aircraft descended through the segment minimum safe altitude of 1,800 ft.
When the aircraft passed LHREF at 0918:23, the aircraft was on descent through 1,100 ft. From LHREF to LHREM, the altitude limitation was the MDA of 730 ft (assuming the pilot had set the current QNH). About 30 seconds later, the aircraft was approaching 700 ft with an apparent decrease in the descent rate for a short period. The aircraft then descended below the MDA and the aircraft track diverged to the left, crossing the inbound track at an angle of about 20°.
The divergent aircraft track and descent continued until the aircraft impacted a sand dune on the coastline at 0919:40. The pilot and four passengers were fatally injured and the aircraft was destroyed.
Figure 3: Flight track of VH-OZO during second RNAV (GNSS) approach at Lockhart River Aerodrome with time stamps, feature labels, and approach parameters superimposed
Source: Google Earth, annotated by the ATSB
Profile and speed information
The descent profile of the aircraft on the first approach was slightly higher than the nominal 3° approach gradient specified on the approach chart. The descent profile of the aircraft on the second approach had a similar gradient but was generally displaced 1,200 ft lower.
The ATSB calculated the average groundspeed of the aircraft from the distance travelled between data points in the specified time. This is provisional data that requires further adjustment for the effects of wind, altitude, and temperature to derive estimates of aircraft airspeed.
On the first approach, the groundspeed was between 130 and 140 kt until the missed approach was initiated. On the second approach, the groundspeed was also between 130 and 140 kt until it increased to 150 kt as the aircraft descended below the MDA up to the collision with terrain.
Figure 4: Profile of VH-OZO during the two RNAV (GNSS) approaches to Lockhart River Aerodrome with approach parameters and features incorporated.
Note: Short periods of constant altitude represented in the diagram do not necessarily indicate a constant altitude because the transmitted/recorded data is rounded.
Source: ATSB
Site and wreckage
The accident site was located on a sand bank adjacent to the beach, about 6 km south-east of Lockhart River Aerodrome and 300 m to the south-west of the specified RNAV track. The wreckage trail was about 20 m from the initial impact point (Figure 5), and indicated that the aircraft was on a heading of about 280° (magnetic), with the impact point about 30 ft above mean sea level.
Figure 5: Overview of accident site
Source: ATSB
The ATSB’s on-site examination of the wreckage, damage to surrounding vegetation and ground markings indicated that at initial impact the aircraft was:
upright and close to wings level
about 5° nose down
at relatively high speed.
An area of foliage around the aircraft displayed signs of chemical burn from avgas, indicating that the aircraft had a significant amount of fuel on board.
There was no evidence of any structural or mechanical defects, but the examination was limited by the extensive damage (Figure 6). All but one of the propeller blades were located at the site; damage to the recovered blades indicated significant rotational energy at impact consistent with both engines operating normally with substantial power.
The landing gear was extended at the time of impact. Other aircraft configuration information such as flap position, trim settings and switch selections could not be validated due to the impact damage. The serviceability of the flight instruments and associated systems could also not be verified.
Figure 6: Impact points of VH-OZO and main wreckage
Source: ATSB
The only components on the aircraft that may have recorded data were a digital fuel flow indicator/totaliser and a transponder, and the ATSB recovered these components. After consideration of the damage to these components and the potential value of any data, no further examination was undertaken.
Context
Pre-flight planning and in-flight monitoring
At 1326 on the day before the accident flight, the pilot accessed a location briefing for Lockhart River from the National Aeronautical Information Processing System (NAIPS) via an electronic flight bag (EFB) application. This type of briefing typically displayed current forecasts, reports, and ‘notice to airmen’ (NOTAM) applicable to the nominated location.
Later that day, at 1830, the pilot requested grid point wind and temperature charts (GPWT) and a specific pre-flight information bulletin (SPFIB) from NAIPS via flight planning software. The SPFIB request was for Cairns to Lockhart River and return with the estimated time of departure nominated as 1930 the same day. This bulletin was valid until 1830 on the day of the accident.
A printout of the SPFIB found at the accident site showed aerodrome forecast (TAF) and weather reports (METAR) for Cairns. The weather for the next day (day of accident flight) at Cairns Airport was expected to be visibility of 10 km or greater and showers of light rain with scattered[6] cloud at 1,800 ft[7] in the morning lifting to 2,500 ft. In addition, the forecast imposed a TEMPO[8] for the next day to specify periods of visibility reduced to 2,000 m with showers of moderate rain and broken[9] cloud at 1,000 ft.
On the printout of the SPFIB, a METAR for Lockhart River for 1800 (10 March) showed light winds, visibility 10 km or greater and nil cloud detected. Since 0900 that morning, recorded rainfall was 1.8 mm.
No TAF was provided on the SPFIB for Lockhart River as the time of the request was outside the issue and validity period. There were no predicted outages of global positioning system/global navigation satellite system (GPS/GNSS) capability for Cairns or Lockhart River. ‘Notice to airmen’ (NOTAM) information included a change to Lockhart River runway distance and gradient data and no other notices with significance for the planned flight.
After the SPFIB was received, at 1942, the pilot submitted a flight notification for the planned departure from Cairns at 0730 the next morning to Lockhart River followed by a departure at 1430 for the return sector. Both sectors were planned under instrument flight rules (IFR) with nominated capability for instrument approaches using GPS/GNSS equipment.
A damaged and partly illegible copy of the pilot’s flight plan/log was found at the accident site. This was a printout from flight planning software showing key navigational data and pilot notes on progress of the flight. There was no indication of any operational abnormalities.
A tabulated fuel plan showed 1,040 L on board at engine start at Cairns and expected fuel consumption of 285 L for the planned 94-minute flight to Lockhart River. The pilot had included provision for 45 minutes fixed reserve (124 L), 40 L variable reserve and 60 minutes holding (110 L) if required (consistent with TEMPO conditions). If the variable reserve and holding allowance was consumed on the outbound sector (in addition to the calculated flight fuel), the remaining 605 L was sufficient to return to Cairns with allowance for 60-minutes holding on arrival.
In summary, the pilot was not intending to refuel at Lockhart River, and the aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required. Avgas was available at Lockhart River.
The pilot completed the operator’s passenger/cargo manifest form and calculated the aircraft’s weight and balance with reference to individual passenger weights and baggage. The take-off weight was recorded as 3,678 kg and nominal landing weight as 3,366 kg. The aircraft’s maximum take-off weight was 3,810 kg and maximum landing weight was 3,674 kg. The graphical trimsheet showed the centre of gravity was within limits throughout the flight.
A copy of the operator’s in-flight monitoring form was found at the accident site. When the pilot completed the form in cruise at 10,000 ft, all of the recorded engine parameters for each engine were comparatively similar with no indication of any aircraft-related problems.
After the pilot requested the SPFIB and submitted the flight notification on the evening before the accident flight, there was no record of further requests for meteorological information from NAIPS. Such information is also available from the Bureau of Meteorology website and other sources without any user registration requirements. It was reported that the pilot was aware of the current weather forecasts on the morning before the flight.
During the flight, the pilot was using an iPad with an electronic flight bag (EFB) application and was carrying a second iPad as a backup.
Meteorological information
Introduction
The Bureau of Meteorology produced aviation forecasts, observations, warnings and advisories. As the official provider of the Aeronautical Information Service, Airservices Australia delivered the bureau’s aviation meteorological products to pilots through NAIPS.
For the flight from Cairns to Lockhart River, the essential meteorological data was aerodrome forecast (TAF), graphical area forecast (GAF), grid point wind and temperature chart (GPWT) and any warnings (such as SIGMET). This could be supplemented by aerodrome weather reports (METAR), ground-based weather radar imagery, and satellite imagery.
Forecasts for Lockhart River
On 11 March 2020 (day of accident), the initial TAF for Lockhart River was issued at 0449 EST[10] and was valid from 0600 to 1800. The expected weather conditions were:
From 0600 to 1000: wind variable at 3 kt with visibility 10 km or greater. Light rain showers and cloud scattered at 1,000 ft (all heights are above the aerodrome elevation).
Between 0600 and 1000: TEMPO - visibility reduced to 3,000 m with rain and broken cloud at 500 ft.
From 0600 to 0800: 30 per cent probability of fog with visibility reduced to 500 ft and broken cloud at 100 ft.
From 1000 to 1800: wind from the north-east at 5 kt with visibility 10 km or greater. Light rain showers with scattered cloud at 1,000 ft.
Between 1000 and 1800: TEMPO - visibility reduced to 3,000 m with rain showers and broken cloud at 800 ft.
For the whole forecast period, 0600 to 1800: 30 per cent probability TEMPO - winds gusting 25 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,000 ft.
Based on this forecast, for a flight expected to arrive at between 0900–1000, the pilot was required to plan for 60 minutes or diversion to an alternate. The aircraft had more than sufficient fuel for that purpose.
An amended TAF for Lockhart River was issued at 0925 and was valid from 0900 to 1800. The expected weather conditions were:
From 0900 to 1300: wind variable at 3 kt with visibility 10 km or greater. Light rain showers with cloud scattered at 1,000 ft and broken at 2,000 ft
For whole forecast period, 0900 to 1800: TEMPO – winds gusting from 20 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,500 ft.
Other forecasts
A GAF was issued at 0853 and was valid from 0900 to 1500 and applicable from surface to 10,000 ft. This covered the Queensland-North region, which was divided into six areas for this forecast. Most of the flight including the arrival at Lockhart River was within one area that was forecast to have the following conditions:
Broken stratus 1,000 ft to 2,000 ft with broken cumulus/stratocumulus above that. Visibility reduced to 6,000 m in widespread rain.
Isolated towering cumulus from 2,000 ft, broken stratus from 800 to 2,000 ft, and broken cumulus/stratocumulus from 2,000 ft. Visibility reduced to 2,000 ft in scattered rain showers.
Isolated cumulonimbus from 2,000 ft and broken status between 500 ft and 1,000 ft. Visibility reduced to 500 m in isolated thunderstorm rain showers.
A GPWT forecast was issued at 0538 and was valid to 1000. Lockhart River was located near the intersection of four data boxes and therefore roughly equidistant from four forecast locations. Taking 2,000 ft as a reference height for the approaches and coastal data as more relevant, the wind was forecast to be from the north-west at 9 kt increasing to 21 kt north of Lockhart River.
There were no significant weather warnings applicable to the flight.
Aerodrome weather reports for Lockhart River
The METARs for Lockhart River were automatically generated every 30 minutes for routine reports and were issued as a special report (SPECI) at other times when one or more elements met specified criteria for degradation and improvement. For the period from 0830 to 0930 on 11 March 2020:
0830: nil wind, visibility 10 km or greater with rain and scattered cloud from 3,000 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
0900: nil wind, visibility 10 km or greater with rain and broken cloud at 2,000 ft, 3,500 ft, and 4,100 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0910: nil wind, visibility 10 km or greater with rain and broken cloud at 1,800 ft and 3,400 ft then overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0913: nil wind, visibility 3,800 m with rain and broken cloud at 1,800 ft and 3,400 ft, overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 0.2 mm.
SPECI 0929: westerly at 5 kt, visibility 8,000 m with heavy rain and scattered cloud at 1,200 ft, broken cloud at 1,900 ft, and broken cloud at 3,600 ft. Temperature and dewpoint were both 25 °C . Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0930: westerly at 5 kt, visibility 9,000 m with heavy rain and scattered cloud at 1,200 ft, broken cloud at 1,900 ft and broken cloud at 3,600 ft. Temperature and dewpoint were both 25 °C . Rainfall in the previous 10 minutes was 0.4 mm.
The QNH remained at 1,008 hPa during this period, except at 0929 when it was reported as 1,009.
During the next 30 minutes, there were four SPECI issued with variations to visibility between 5,000 m and 10 km or greater. The wind varied in direction and strength no greater than 7 kt. The temperature and dewpoint both remained at 25°. There was persistent rain, and scattered to broken low cloud.
Automated weather information service
Lockhart River was equipped with an automated weather information service (AWIS) that transmitted text-to-speech on a discrete VHF frequency. A new AWIS message was generated every minute in a similar format to the METAR reports. This data was also available from a telephone service.
The pilot recorded the following data in the space allocated for arrival weather information in the flight plan/log:
calm (nil wind)
10 km (visibility)
B1800 (broken cloud at 1,800 ft)
B3500 (broken cloud at 3,500 ft)
OV 5300 (overcast cloud at 5,300 ft)
1008 (QNH)
25 (temperature 25 °C).
Radar information
Figure 7 provides an indication of the weather around Lockhart River at 0930 on the morning of the accident.
Figure 7: Weipa radar image at 0930 WST (shortly after the accident) showing weather in Lockhart River area (circled, approximate radius 25 NM/46 km)
Source: Bureau of Meteorology, annotated by the ATSB
Local weather observations
Two pilots were operating aircraft in the Lockhart River area before and after the accident. The first pilot, operating before the accident, tracked to Lockhart River from the south and conducted the RNAV (GNSS) RWY 30 approach, landing at 0810. There were intermittent rain showers in the area and the pilot advised that the end of the runway was visible while descending through 1,000 ft. The pilot remained on the ground at Lockhart River until later in the day and heard an aircraft (VH-OZO) fly over at high engine power. At that time, there was scattered low cloud at 500–1,000 ft with reduced visibility in rain showers.
The following pilot, operating after the accident, tracked to Lockhart River from the south-west and diverted 15 NM to the right of track due to weather. On arrival the pilot conducted the Lockhart River RNAV (GNSS) RWY 30 approach and landed at 0953. There was rain in the area and, although the conditions allowed visual navigation after the final approach fix while descending through 1,500 ft, the runway was not visible until later in the approach.
A person who was near the aerodrome at the time of the accident described the conditions as an unusual morning with a bit of mist coming from the rainforest, and that there was about 5 to 10 minutes of heavy rain around the time the aircraft would have been in the area. At that time, there was low-lying cloud and no wind.
Two of the passengers recorded and shared images during the flight, including one image from each passenger while the aircraft was in the Lockhart River area. The first image (Figure 8) was sent by text messaging at 0903, which was during the first approach while the aircraft was over halfway between intermediate approach fix LHREI and final approach fix LHREF at an altitude between 3,100 and 2,500 ft. The camera is orientated to the north so the foreground, if visible, would be the ocean to the east of Lockhart River.
In a subsequent text message sent at 0914, the passenger advised that the first attempt at landing was unsuccessful and the runway was not visible due to heavy rain. This was followed a couple of minutes later by a text to advise of another attempt. No further communication was received.
Figure 8: Image recorded by a passenger looking forward over the right engine and sent via text message at 0903
Source: Provided to the ATSB, lower section of image cropped by the ATSB
The second image (Figure 9) was uploaded at 0914 during the early stages of the second approach, while the pilot was tracking towards LHREI on a south-westerly heading at 3,500 ft. The camera is oriented to the west, which is in the general direction of Lockhart River. An associated message indicated very low visibility and the pilot was circling while waiting for a break in the weather. No further communication was recorded.
Figure 9: Image recorded by a passenger looking over the right wing and uploaded to social media at 0914
Source: Provided to the ATSB
Operator information
The Civil Aviation Safety Authority (CASA) issued Air Connect Australia with an Air Operator’s Certificate (AOC) in March 2017 with an expiry date of 31 March 2020. It authorised the certificate holder to operate Cessna C310/340, C404, C402/421 and Raytheon Baron/Travelair aircraft types on charter and aerial work operations. At the time of the accident, CASA was assessing the operator’s application to renew the AOC.
From April 2017, the operator dry-leased VH-OZO from the aircraft owner based at Jandakot Airport, Western Australia. In this arrangement, the aircraft owner was responsible for the continuing airworthiness of the aircraft and the operator managed the operational aspects, such as fuel and flight crew.
The managing director carried out the key roles in the operator’s organisational structure, such as chief pilot and head of aircraft airworthiness and maintenance control. In the 18 months prior to the accident, Air Connect Australia operated one aircraft (VH-OZO) with one pilot additional to the chief pilot (that is, the pilot of the accident flight).
Pilot information
The pilot held a Commercial Pilot Licence (Aeroplane) with an instrument rating and multi-engine aeroplane endorsement. On 7 August 2019, the pilot completed an instrument proficiency check for multi-engine aeroplanes conducted by an independent CASA-approved flight examiner. This was valid until 7 August 2020 and deferred the requirement for a flight review up to August 2021.
Prior to joining the operator in October 2018, the pilot’s recorded total flying time was 2,800 hours. He had been operating as a commercial pilot in remote locations for 5 years, including a total of 3 years based in Arnhem Land, Northern Territory. Between March 2016 and February 2018, he was chief pilot for a charter company that operated Cessna 310 and Piper PA-31 aircraft.
The pilot completed operator induction in October 2018 and received type-specific training in a Cessna 421 from an independent CASA-approved flight examiner. The examiner recalled that the pilot managed the transition to the 400-series Cessna without any problems. Other than the pressurisation system in the C421, the examiner considered it was operationally equivalent to the unpressurised Cessna 404.
Following this, the chief pilot supervised the pilot in command on four flight sectors in VH-OZO and conducted an operator proficiency check (OPC) over two further sectors. The chief pilot noted that the pilot’s planning was satisfactory and operation of the aircraft was above standard. No further OPC was recorded, which was consistent with the operator requirement for an OPC within a 2-year period.
From November 2018 to the accident flight, the pilot was based in Cairns and conducted most of the operator’s charter flights in VH-OZO. During this period, the pilot recorded 70 RNAV (GNSS) approaches to various aerodromes including six at Lockhart River, most recently in October 2019. On one flight, the pilot recorded two RNAV (GNSS) approaches (to Aurukun), which indicates that the pilot conducted a missed approach after the first attempt and landed after a second approach.
In the 2 months prior to the accident flight, the pilot conducted a number of flights (56 sectors). Prior to the day of the accident, his most recent flights were on 18 February 2020. These flights included a RNAV (GNSS) approach and an instrument landing system (ILS) approach.
The pilot had recorded a total of 3,220 hours before the accident flight, including a total of 1,177 hours on multi-engine aircraft with 399 hours on the Cessna 404 aircraft type. Total instrument time was recorded as 148 hours, including 4.5 hours in the 90 days prior to the accident flight.
The pilot’s Class 1 (Commercial Pilot) Medical Certificate was renewed on 14 February 2020 and was valid until 14 February 2021. There were no indications of any significant medical problems in the pilot’s aviation medical records. It was reported that the pilot had been sleeping well in the nights preceding the accident and exercising regularly. He had been on a holiday in the weeks before the accident and was described to be in good health and looking forward to flying again.
Aircraft history and avionics
The aircraft was manufactured by the Cessna Aircraft Company in 1980. It was reported that the aircraft was first operated in Australia before being transferred to Papua New Guinea and registered as P2-ALG. In December 2009, after the aircraft was flown to Australia, a CASA certificate of airworthiness was issued and the aircraft was registered VH-OZO. At that time, the aircraft total time was 28,193 hours.
On arrival into Australia, the aircraft was fitted with aerial geophysical survey equipment and was operated in that configuration until that equipment was removed in March 2012. Concurrently, the avionics were modified in accordance with an engineering order to install new types of avionics and integrate those with existing units. The post-modification avionics, including existing equipment, consisted of:
Garmin GMA340 audio panel
Dual Garmin GNS430W GPS/Nav/Com
Dual Garmin GI-106A CDI Indicator
Garmin GTX327 Transponder
Bendix/King KR87 ADF and
Bendix/King KI-227 Indicator
Collins HF
Cessna 400B Navomatic Autopilot
Bendix non-colour weather radar.
These units were installed at the time of the occurrence except for the transponder, which was replaced by an automatic dependent surveillance-broadcast (ADS-B) compliant unit in April 2017.
The 400B autopilot was one of the standard equipment options for the C404 type. It can provide pitch and roll control with heading and altitude hold (on command). A navigation function provided the autopilot with inputs from an associated CDI instrument, which in this case received data from the number‑1 GNS430W. For a RNAV (GNSS) approach, the pilot could ‘couple’ the autopilot for lateral navigation and manage vertical navigation by adjusting the pitch control or selecting altitude hold.
The aircraft was fitted with the instrumentation required for operations under IFR. These instruments were conventional analogue indicators and reflected the original specifications for the aircraft. It was noted that the second artificial horizon/attitude indicator and altimeter were located on the right side of the co-pilot panel (far side of the instrument panel relative to the pilot).
Figure 10: VH-OZO instrument panel
Source: Provided to the ATSB
Aircraft maintenance
The aircraft logbook statement specified that VH-OZO was to be maintained in accordance with the system of maintenance (SOM) developed by the aircraft owner and approved by CASA. The key elements of the SOM were:
daily inspection in accordance with the Cessna 404 Pilot’s Operating Handbook
engine and airframe inspections every 100 +/- 10 hours in accordance with the Cessna 404 Progressive Care Program (Operations 1 and 2 plus 3 and 4 completed within 12-month period)
electrical and instrument inspections every 220 hours or 12 months in accordance with SOM schedules
IFR avionics inspections every 220 hours or 12 months in accordance with SOM schedules
Special inspections, Supplemental Inspection Documents, and Corrosion Prevention Control Program as required
altimeter and pitot-static system inspection and test every 24 months
maintenance release issue for a period of up to 220 hours or 12 months, whichever occurred first.
Scheduled engine and airframe maintenance was carried out by the CASA-approved maintenance organisation associated with the aircraft owner. While the aircraft was based in Cairns, electrical, instrument, and radio maintenance as well as unscheduled maintenance was contracted to licensed aircraft maintenance engineers.
The most recent maintenance was the scheduled 100-hour inspection based on Operations 3 and 4 of the Cessna 404 Progressive Care Program. This was completed on 16 February 2020 at 31,066 hours total time. A maintenance release was issued with the next scheduled maintenance being the oil/filter change after 50 hours operation and compass swing in July 2020.
Other key maintenance was:
19 January 2020 at 31,050 hours: inspection of the electrical, instrument and IFR avionic systems certified as satisfactory
29 January 2019 at 30,750 hours: inspection and test of the pitot-static system and check of altimeters certified as satisfactory.
The current maintenance release was not found at the accident site. Operator records showed that the aircraft had been operated for 3.8 hours between maintenance release issue and the accident flight. The operator and aircraft owner both advised that no aircraft defects had been reported.
Garmin GNS 430W
The Garmin GNS 430W is a panel-mounted unit that provided for GPS navigation, instrument landing system (ILS) or VHF omnidirectional radio range (VOR) navigation, and VHF radio communication. It was approved for IFR operations including RNAV (GNSS) approaches and was used in conjunction with a course deviation indicator (CDI) instrument.
Although the ‘W’ designates wide area augmentation system (WAAS) capabilities that allow for GPS approaches with vertical guidance, Australia does not have the associated infrastructure. As such, the GNS 430W was approved to provide distance and track information only for RNAV (GNSS) non-precision approaches.
To use the unit for RNAV (GNSS) approaches, it was a requirement that the NavData card was valid and the approach was loaded from the database. The operator subscribed to the Jeppesen NavData service that provided updates on a monthly basis. It was reported that the pilot updated the NavData card using a laptop computer in the 24 hours prior to the flight, although this is yet to be confirmed by the ATSB.
The GNS 430W has a terrain function that requires a valid 3D GPS position solution and a valid terrain and obstacle database to operate properly. Terrain information is advisory only and can include:
display of altitudes of terrain and obstructions relative to the aircraft’s altitude
pop-up terrain alert messages issued when flight conditions meet parameters set within the terrain system software algorithms
forward looking terrain avoidance alerts in all phases of flight
premature descent alerting on approach to land (including RNAV approaches).
The ATSB has not yet established if the terrain function was operable and the status of any user and system inhibitions.
Fault detection and exclusion was incorporated into the GNS 430W software to detect satellite failure and exclude failed satellites from usage.
Lockhart River RNAV (GNSS) RWY 30 approach
It was reported that the pilot subscribed to the departure and arrival procedures published by Airservices Australia. A copy of the Lockhart River RNAV (GNSS) RWY 30 approach chart as published by Airservices Australia is shown in Figure 10.
To enable the approach, the pilot loads the approach waypoints and approach tracks from the GPS database. All altitudes specified for the Lockhart River RNAV (GNSS) RWY 30 approach are barometric and are managed by the pilot with reference to the altimeter. In addition to the various minimum safe altitudes for different segments of the approach, the pilot is provided with a distance/altitude scale that provides guidance for the optimum descent angle of 3°.
After the final approach fix LHREF, the pilot is permitted to descend to the MDA provided the aircraft is within tracking tolerances. Further descent is only allowed if the pilot has at least 4,200 m visibility and is able to continue the approach and land on the runway. If the pilot arrives at the missed approach point and is unable to continue the approach to land by visual reference, the pilot is required to conduct a missed approach by initiating a climb to the specified altitude and tracking in accordance with the procedure.
Figure 11: Lockhart River RNAV (GNSS) Runway 30 approach chart
Source: Airservices Australia
Further investigation
The investigation is continuing and will include further review and examination of:
recorded flight data for the accident flight
meteorological data at the time of the accident
recorded flight data as available for selected RNAV (GNSS) approaches conducted by the pilot at Lockhart River and other aerodromes
regulatory oversight processes for Air Connect Australia
software version and operation of Garmin GNS 430W units fitted to VH-OZO
training and checking practices related to RNAV (GNSS) approaches, including missed approaches and subsequent approaches
occurrences involving RNAV (GNSS) approaches, including at Lockhart River
existing and potential risk controls for controlled flight into terrain
human factors considerations
potential pilot incapacitation risk factors.
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Acknowledgements
The ATSB acknowledges the significant assistance provided by the Queensland Police Service during the on-site phase of this investigation.
The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this preliminary report. As such, no analysis or findings are included in this report.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 9 February 2020, a Qantas Boeing 787-9 was conducting a flight from London Heathrow Airport, Greater London, United Kingdom to Perth Airport, Australia. During rotation, the pilots received a tail strike caution message and returned for landing at London Heathrow Airport.
The United Kingdom Air Accident Investigation Branch (AAIB) is conducting an investigation into this occurrence. As Australia is the State of Registration of the aircraft, the AAIB has requested an Accredited Representative from the Australian Transport Safety Bureau (ATSB) be appointed.
To facilitate this request, the ATSB initiated an external investigation under the provisions of the Transport Safety Investigation Act 2003.
The UK AAIB is responsible for and will administer the release of the final investigation report into this incident.
Any enquiries relating to the investigation should be directed to the AAIB at: www.aaib.gov.uk
Final report
The occurrence
On 9 February 2020, a Qantas Airways Boeing 787-900, registered VH-ZND, departed on a flight from London Heathrow Airport, United Kingdom to Perth Airport, Australia. Shortly after initiation of aircraft rotation,[1] the flight crew received a caution message indicating that the tail strike prevention system had been triggered. After performing the relevant checks the flight crew returned the aircraft for an overweight landing at Heathrow Airport.
Investigation
The United Kingdom Air Accident Investigation Branch (AAIB) was responsible for the investigation into this occurrence. As Australia is the State of Registration of the aircraft, the AAIB requested appointment of an Accredited Representative from the ATSB.
To facilitate this request, the ATSB initiated an external investigation under the provisions of the Transport Safety Investigation Act2003.
Conclusion
The AAIB investigation concluded that, during conditions of strong and gusty winds, a high pitch rate near lift-off caused the trail strike sensor to contact the runway surface. This resulted in activation of the aircraft’s tail strike prevention system and generation of an Engine Indication and Crew Alerting System TAIL STRIKE message. While the tip of the sensor was abraded due to contact with the runway, no further damage was found.
Any further information regarding this investigation should be directed to the AAIB via: enquiries@aaib.gov.uk
_____________
The information contained in this update is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the AAIB investigation of the occurrence.
At about 0438 local time on 29 February 2020, in darkness and clear visibility, the inbound fishing vessel Sandgroper collided with the outbound self-discharging bulk carrier Accolade II, off the entrance to Port Adelaide, South Australia. The collision occurred within port limits shortly after Accolade II had exited the Port Adelaide channel and resulted in significant structural damage to Sandgroper and minor damage to Accolade II. There were no injuries reported on either vessel.
What the ATSB found
The ATSB found that a proper lookout using all available means was not being maintained on board either vessel in the time leading up to the collision. Consequently, neither vessel was aware of the risk of the collision posed by the other until shortly before the collision when it was too late to take effective avoiding action.
Accolade II’s bridge team did not have a complete appreciation of the traffic situation and of the risk of collision outside the port channel before the ship exited the channel. In particular, effective use was not made of radar and a dedicated look-out was not posted in darkness.
Sandgroper’s skipper initially sighted Accolade II while the ship was still in the channel. However, a proper look-out was not subsequently maintained using all available means, including radar and radio. As a result, Sandgroper's skipper was not aware that Accolade II had exited the port channel and a close quarters situation with the ship was developing. While Sandgroper was not equipped with, nor required to be equipped with, an automatic identification system (AIS) transceiver, had one been fitted, it would have improved the vessel's detectability. That in turn would have increased the chances that the vessel was detected by Accolade II’s bridge team in sufficient time to avoid collision.
What has been done as a result
Following this incident Sandgroper was fitted with an AIS transceiver.
Accolade II’s managers (Inco Ships) advised that a navigational audit of the ship’s operations was conducted, which resulted in several recommendations to improve the ship’s bridge resource management practices.
Safety message
The safety of fishers and people in small boats continues to be of concern to the ATSB as collisions between trading ships and small vessels on the Australian coast continue to occur. Safety investigations into such collisions have consistently shown that the keeping of a proper lookout by all available means, including radar, radio and AIS, in accordance with the collision regulations could have prevented most of these collisions.
The occurrence
At about 1100 Central Daylight-saving Time[1] on 28 February, Sandgroper (Figure 1) departed its fishing grounds off Kangaroo Island, South Australia and began making its way back to North Arm Marina in Port Adelaide. The vessel was crewed by a skipper and two uncertificated crew (deckhands). The crew had been fishing at sea for the previous week when a hydraulic equipment malfunction resulted in the decision to return to port.
Figure 1: Sandgroper
Source: Ashworth Maritime Services
At 0226 on the morning of 29 February, Sandgroper was about 13 nautical miles (miles)[2] south‑west of Port Adelaide’s southern breakwater (Figure 2), on a heading[3] of about 020°, with steering in autopilot mode and a speed of about 5-6 knots. The skipper was on watch in the wheelhouse with the deckhands resting. At about 0300, the skipper handed over the watch to one of the deckhands in order to get some rest. The skipper instructed the deckhand to follow the course plotted on the chart plotter and to wake them if there were any concerns or when arriving at a nominated point marked on the chart plotter near Port Adelaide’s port limits. The skipper then lay down to rest on the wheelhouse bunk, aft of the conning position. Both the vessel’s very high frequency (VHF) radio units were set to maintain a listening watch on VHF channel 16.[4]
Meanwhile, Accolade II was alongside at Adelaide Brighton Cement’s K-Berth in Port Adelaide Inner Harbour. The ship was engaged in discharging a cargo of limestone loaded earlier that day at Klein Point, South Australia.
Figure 2: Section of chart Aus 781 showing key locations and vessel tracks
Source: Australian Hydrographic Office, annotated by the ATSB using electronically recorded data
At about 0230, Accolade II’s first engineer woke the chief mate and provided 1-hours’ notice for the ship’s planned departure at 0330 for Klein Point. The chief mate went up to the ship’s navigation bridge (bridge) to complete the bridge pre-departure checklist. The checklist included checking that the ship’s radar[5] was on, testing that the ship’s whistle was operational and testing engine and steering gear controls. The checks also included confirming that one VHF radio was set to the port’s working channel (VHF channel 12), and that the ship’s planned departure time of 0330 was reported to the Flinders Ports Communications Tower (communications tower).[6]
At 0255, the chief mate woke the chief integrated rating (IR)[7] and shortly after, the master. By about 0310, the master had made his way to the bridge where he met the chief mate who was on his way down to deal with cargo paperwork and read the ship’s draughts. At 0320, cargo discharge was completed, and the ship’s departure draught recorded as 3.77 m forward and 4.97 m aft.
At 0327, the master contacted the communications tower on VHF radio and reported that the ship was departing its berth. The ship’s forward mooring station were manned by the chief mate and an IR while the aft mooring station was manned by the chief IR and another IR. By 0329, all mooring lines were cast off and, by 0339, the ship had completed its swing to the north and commenced its outbound passage to Klein Point through the Port Adelaide Inner and Outer Harbours. The crew at the mooring stations were stood down and the chief IR went up to the bridge to assume helmsman duties. The chief mate went back to the accommodation to finalise cargo-related paperwork while the other IRs attended to routine post-departure tasks on deck.
At about the time Accolade II was casting off, Sandgroper was about 6.8 miles south-west of Port Adelaide’s southern breakwater. The fishing vessel was on autopilot, still on a heading of about 020° and a speed of about 5-6 knots, with a deckhand on watch and the skipper resting.
By 0356, Accolade II was passing the reporting point at beacon number 39 in the Port Adelaide River at a speed of about 8.9 knots. The master reported passing beacon number 39 to the communications tower on VHF channel 12 and continued the ship’s passage with the helmsman steering.
At about 0415, Sandgroper’s deckhand sighted a red light off the port bow and, shortly after, woke the skipper. The deckhand handed over the watch including reporting the sighting of the red light on the vessel’s port bow. The deckhand then left the wheelhouse to rest while the skipper made a coffee.
At about 0420, Sandgroper entered Port Adelaide’s port limits. The weather at the time was fine, with light winds, calm seas, good visibility and no moon. The skipper checked the reported red light and assessed it to be the port sidelight of an outbound ship in the channel. He then identified the ship on the radar display, which was set on a range scale of 3 miles. The skipper assumed the ship would stay in the channel, and at about 0426 or very shortly after, altered Sandgroper’s course to starboard to stay out of the channel and avoid giving the impression of heading for the channel and thereby impeding the ship’s progress. The skipper then reduced the radar display range scale from 3 miles to 0.125 miles as the vessel progressed towards the port’s breakwater.
At about 0428, as Accolade II was approaching Port Adelaide’s southern breakwater, the chief mate arrived on the ship’s bridge. At about 0433, the ship’s course was altered to port and it exited the channel between beacons number 13 and 15 at a speed of about 9.1 knots. The master contacted the communications tower and reported that the ship was ‘…departing at beacon 13.’ The master then instructed the helmsman to change the ship’s steering from manual to autopilot. The helmsman changed the steering to autopilot and turned off two of the ship’s four steering motors, which was the usual practice for the sea passage.
Meanwhile, the chief mate increased the range scale of Accolade II’s radar display from 0.75 miles to 3 miles and selected the ‘Off Center’ function to provide for the maximum view on the display ahead of the ship. Accolade II’s radar immediately detected Sandgroper. The fishing vessel’s radar echo immediately began to paint on the ship’s radar display about 1.2 miles off Accolade II’s starboard bow, but the chief mate did not notice it.
At about 0434, the chief mate used the radar to select and display the automatic identification system (AIS)[8] target data of two vessels off the ship’s port bow. At about the same time, the master dismissed the helmsman who then left the bridge with a radio. At about 0435, the chief mate answered a call on the bridge telephone. The call lasted about a minute before the chief mate went back to familiarising himself with the navigational situation and adjusting bridge equipment, such as dimming lights, in preparation for taking over the watch from the master.
The collision
Just after 0436, the chief mate, who was standing by the steering console on the ship’s centreline, sighted a red light fine off the ship’s starboard bow. The chief mate crossed to the starboard side of the bridge, got a pair of binoculars to better observe the sighted light and moved to the port side of the bridge to avoid a visual blind sector created by the ship’s bucket elevator on deck. Meanwhile, the master, who was also alerted to the red light, crossed to the port side of the bridge to get another pair of binoculars and returned to the centreline. Both officers then recalled seeing both red and green sidelights of the vessel. By this time, Sandgroper was about 0.5 miles from the ship.
Just over a minute later, at 0437, Accolade II’s radar range scale was reduced from 3 to 1.5 miles. By this time, Sandgroper had closed to about 0.25 miles and the master instructed the chief mate to ‘…go more south…’. The chief mate switched over to manual steering and applied 15° of port rudder helm as the master repeated his instructions to go further south. The master went out on to the starboard bridge wing and their instructions to ‘...go more south…’ became increasingly urgent. The chief mate then applied full port rudder as the ship slowly began turning to port at a speed of about 9.4 knots. The chief mate also attempted to sound the ship’s whistle without success.
Meanwhile, on board Sandgroper, the skipper unexpectedly saw Accolade II’s green sidelight at very close range. The skipper quickly put the vessel’s propulsion full astern, but this had little effect. Shortly after 0438, Sandgroper collided with Accolade II’s starboard side, just forward of midships (Figure 3).
Figure 3: Sections of charts Aus 130 and Aus 138 showing sequence of the collision
Source: Australian Hydrographic Office, annotated by the ATSB using electronically recorded data
At about 0439, the master tried unsuccessfully to call Sandgroper on VHF channel 12. Meanwhile, the chief mate recalled the IR to the ship’s bridge and handed over the helm. The chief mate then issued helm orders to steady the ship’s heading to avoid close quarters situations with the two vessels on the ship’s port side. At about 0440, the master reported the collision to the port’s communications tower.
Shortly after, Sandgroper’s skipper called Accolade II on VHF channel 16. The masters of the two vessels then switched over to VHF channel 13 and exchanged details, confirmed that there were no injuries to anyone on either vessel and that neither vessel required assistance. Accolade II’s master then reported the collision to the ship manager by phone and, having assessed there was no significant damage, resumed the ship’s passage to Klein Point.
Sandgroper’s skipper telephoned the vessel’s manager to report the collision and was advised to resume its passage. By about 0830 that morning, Sandgroper was safely alongside at North Arm Marina.
Sandgroper sustained significant structural damage to the starboard bow (Figure 4) with some minor damage to the vessel’s port side as well. Additionally, Sandgroper’s anchor was lost from the vessel’s bow and was found lodged in Accolade II’s deck railings.
Figure 4: Damage to Sandgroper
Source: Australian Maritime Safety Authority and Inco Ships
Accolade II sustained relatively minor damage to deck structures and railings on the ship’s starboard side as a result of the collision (Figure 5).
Accolade II is a 108 m, self-unloading bulk carrier of 6,310 gross tonnage, built in 1982 by Carrington Slipways, Newcastle, New South Wales. The ship was owned by Adelaide Brighton Cement and, at the time of the collision, was managed and operated by Inco Ships. Accolade II was designed and built for the carriage of limestone from quarries at Klein Point, South Australia, across the Gulf St. Vincent, to Adelaide Brighton Cement’s facilities at Birkenhead, situated within Port Adelaide’s inner harbour.
Equipment and machinery
Accolade II was a Regulated Australian Vessel (RAV). RAVs are commercial vessels which operate (or can be operated) outside the Australian exclusive economic zone. RAVs are subject to the Navigation Act 2012 and are generally required to comply with the requirements of international conventions as given effect by the Australian Maritime Safety Authority’s (AMSA) marine orders.[9]Accolade II was equipped with the navigational and safety equipment required by the International Convention for the Safety of Life at Sea (SOLAS)[10] for a ship of its size and age.
The ship’s navigation equipment included a single radar, automatic identification system (AIS), gyrocompass, differential GPS and a bridge navigational watch alarm system.[11]Accolade II was also fitted with a Japan Radio Company (JRC) JCY 1850 simplified voyage data recorder (VDR).[12] The ship’s primary means of navigation was paper charts although it was also fitted with a chart plotter.[13]
The ship’s propulsion was provided by twin Fuji Diesel 6LG32X dual-fuel propulsion engines that used compressed natural gas as their main fuel, although they could also be operated with marine gas oil.
Radar
Accolade II was equipped with a single JRC JMA-5312-6 X‑Band[14] radar with automatic radar plotting aid (ARPA) and automatic target acquisition capability as well as data input from the AIS and GPS units.
SOLAS regulations prescribed radar carriage requirements for ships based on their gross tonnage. Most modern merchant ships of Accolade II’s size were required to be equipped with two radars. However, Accolade II was subject to the provisions of SOLAS regulations that were in force at that time of its construction, which only required that ships of 1,600 gross tonnage and upwards be fitted with a single, type-approved radar. The regulations allowed for ships constructed before 1 July 2002 to be fitted with equipment which fulfilled the requirements prescribed in the relevant regulations in force prior to 2002.
Crew
Accolade II was manned and operated by a crew of nine in compliance with the ship’s AMSA‑issued minimum safe manning document. The ship’s complement included two deck watchkeeping officers—a master and a chief mate—as well as three integrated ratings, a chief engineer, two first engineers and a cook. The ship’s crews operated on a 3-week roster and most personnel had been assigned to the ship for several years. Crew changes were staggered so that different crew began their 3-week duty periods at different stages of the 3-week roster period.
The master had about 32 years of seagoing experience and held an Australian master’s (unlimited) certificate of competency. The master had worked exclusively on Accolade II for the previous 6.5 years and had joined the ship 16 days before the collision. The master’s usual rank on board was as chief mate (with over 10 years’ experience in the rank) but he had acted in the role of master several times in the past, usually for about a week at a time. In this instance, he was acting in the role of master for the last week of his 3-week roster period. The master also held a marine pilotage exemption certificate (PEC) for Port Adelaide. The PEC was endorsed for night navigation and allowed the master to navigate Accolade II in the waters of Port Adelaide’s Inner and Outer harbours at any time without the need to take on a pilot.
The chief mate had about 15 years of seagoing experience, held a Philippines master’s (unlimited) certificate of competency and the equivalent Australian certificate of recognition. The chief mate had about 8 years’ experience in the rank, had worked exclusively on Accolade II for the previous 5 years and had joined the ship 2 days before the collision. The chief mate did not hold a PEC for Port Adelaide.
Operations
Accolade II generally conducted a daily return voyage between Port Adelaide and Klein Point.
The ship’s operations routinely involved a departure from Port Adelaide in the early hours of the morning with the exact time of departure varying depending on when cargo discharge was completed. The chief mate was usually woken about an hour before completion of cargo discharge/departure with the master usually woken about half-an-hour before departure. The chief mate assisted with unmooring operations, following which the master piloted the ship out of the harbour.
On exiting the channel, the chief mate usually took over the watch for the 4-hour sea voyage to Klein Point. The master returned to the bridge when the ship was approaching Klein Point and berthed the ship with the chief mate’s assistance. Once alongside, the chief mate was stood down while the master managed cargo loading operations, which usually took about 4 hours.
The chief mate was recalled for departure and then kept the sea watch for the passage back to Port Adelaide. The master returned to the bridge and took over the watch just before the ship entered the Port Adelaide channel (near beacon number 13). The chief mate then assisted with bringing the ship alongside and with mooring operations. Once alongside, both the master and chief mate stood down while the ship’s cargo was discharged, which usually took about 8 hours.
Sandgroper
Sandgroper is a steel-hulled trawler built in 1978 in Johnsonville, Victoria. The vessel was owned by Pescatore Di Mare and, at the time of the collision, managed and operated by Southern Fisheries Group. The vessel operated out of the Government-owned North Arm Marina, a commercial fishing harbour located in a narrow channel off the Port Adelaide river, south of Torrens Island.
At the time of the collision, Sandgroper was a class 3B domestic commercial vessel (DCV) and was equipped with navigational and safety equipment required for an ‘existing’ class 3B DCV.[15]
The trawler’s wheelhouse was equipped with a Furuno 1942 Mark-2 radar, GPS, echo sounder and two VHF radios, both with dual watch capability. Sandgroper was not equipped with AIS or VDR, nor was it required to be (see the section titled Automatic identification system). Additionally, the trawler was equipped with a vessel monitoring system (VMS)[16] required by the Australian Fisheries Management Authority (AFMA).
Sandgroper was crewed and operated by a crew of three – a skipper and two uncertificated crew – in compliance with the applicable conditions in the vessel’s AMSA-issued Certificate of Operation. The skipper had over 28 years’ seagoing experience and held an Australian master’s (<24 m, near coastal) certificate of competency as well as a marine engine driver’s (Grade 3, near coastal) certificate of competency. The skipper had operated out of Port Adelaide for more than 20 years.
International regulations for preventing collisions at sea
The look-out
The International Regulations for Preventing Collisions at Sea, 1972, as amended (COLREGs) provide internationally‑agreed rules and measures to prevent collisions. The COLREGs generally apply to all vessels at sea, including fishing vessels. The COLREGs include requirements for keeping a look-out, assessing risk of collision with other vessels as well as the conduct and responsibilities of vessels in preventing collisions.
With respect to keeping a lookout, Rule 5 of the COLREGs (Look-out), states:
Every vessel shall at all times maintain a proper look-out by sight and hearing as well as by all available means appropriate in the prevailing circumstances and conditions so as to make a full appraisal of the situation and of the risk of collision.
The rules required that a lookout be kept not only by sight and hearing, but by all available means including radar, AIS, and information from other sources such as port radio broadcasts and ship‑to‑ship or ship‑to‑shore calls.
The ‘prevailing circumstances and conditions’ include various factors that should be considered when keeping an effective lookout. While not explicitly identified in the rule on the look-out, many of these factors were identifiable elsewhere within the COLREGS. For example, Rule 6 (Safe speed) listed several factors that were also relevant to the keeping of a lookout. Factors relevant to keeping an effective lookout include the:
state of visibility and time of day (day, night or twilight)
background lights (shore lights or back scatter from own lights)
expected traffic in the area (open sea, coastal passage, port or harbour)
traffic density, including concentrations of fishing and other vessels
characteristics, efficiency and limitations of radar (including its range and any interference)
constraints imposed by the radar range scale in use.
Other relevant factors include the availability, type, capability, and limitations of the AIS units of the vessels involved, available local knowledge and information, and the availability of traffic information via radio (ship‑to‑ship calls, all ship broadcasts and schedules). A number of the factors listed above are interrelated. For example, the use of radar significantly enhances keeping a lookout, particularly during darkness or when visibility is restricted by fog, rain or other conditions.
The COLREGs made specific mention of the proper use of radar equipment to obtain early warning of the risk of collision. The regulations also warned against making assumptions based on scanty information. The keeping of a proper lookout enables the risk of collision to be assessed in sufficient time for early and appropriate action to be taken.
Navigation lights
The COLREGs also described the requirements for vessels to exhibit specific lights (navigation lights) from sunset to sunrise. These lights were generally dependent on vessel length with some additional lights required depending on the type/purpose of the vessel or under certain circumstances and conditions.
Accolade II was required to display a white masthead light forward, a second masthead light abaft of, and higher than the forward one (mandatory for vessels 50 m or more in length), sidelights, and a stern light.
Sandgroper was not engaged in fishing at the time of the collision and therefore was required to display a single masthead light, sidelights and a sternlight.
At the time of the incident, both Accolade II and Sandgroper were probably displaying the required navigation lights for power-driven vessels of their size while underway. Additionally, neither vessel was displaying other lights, such as working lights or deck lights, that could obscure or be mistaken for regulation navigation lights or otherwise be an impediment to sighting and identifying navigation lights.
Signals to attract attention
The COLREGs required that vessels carry equipment to make sound signals for manoeuvring and warning purposes as well as to attract attention. Depending on size, a vessel may be required to carry a whistle, a bell and/or a gong.[17]
Accolade II was equipped with a pneumatic whistle fitted on the main mast. The whistle could be operated from six different locations, including from buttons on the bridge and bridge wings. Accolade II’s chief mate reported that when he attempted to sound the ship’s whistle to attract Sandgroper’s attention before the collision, he probably did not hold the button down long enough for it to sound. Accolade II was also equipped with an Aldis lamp[18] that was not used to attract attention because of the lack of available time.
Sandgroper was equipped with a manually operated horn. However, no attempt was made to use it, probably due to the rapid sequence and unexpected nature of the collision.
Accolade II’s look-out
Accolade II’s safety management system (SMS) included procedures for the navigation and operation of the ship. The procedures stated that the collision regulations as well as other international and local regulations relating to safe navigation were to be strictly complied with. They also noted that the primary reference documents for the operation of the ship at sea included:
the COLREGs
Standards of Training, Certification and Watchkeeping for Seafarers (STCW) Code[19]
AMSA’s Marine Order 28 (Operations standards and procedures)[20]
Together, these documents and publications, referenced in Accolade II’s procedures, comprehensively dealt with the subject of watchkeeping and the look-out.
The STCW Code provided mandatory watchkeeping standards applicable to ‘seagoing ships’ and required that a proper lookout be maintained at all times in compliance with the COLREGs. The Code required that the lookout be able to give full attention to lookout duties and not be assigned or undertake any duties which could interfere with that task. It also clarified that the duties of a lookout and helmsperson on a ship are separate. While the Code permitted the watchkeeping officer to be the sole lookout in daylight (in good conditions), it implied that a separate, dedicated lookout was to be posted in darkness.
Accolade II’s master’s standing orders made it clear that during the hours of darkness, the minimum manning requirement for the bridge was a qualified watchkeeping officer and one integrated rating (IR) as a lookout. The orders also clarified that the lookout should not be assigned any other tasks, although they could be absent from the bridge for brief periods to perform tasks such as a fire and safety round.
The Bridge Procedures Guide is a publication that aims to reflect best practice on subjects such as passage planning and watchkeeping, including on the subject of the look-out, and is widely used internationally to support shipboard safety management systems. The guide and its content are consistent with the requirements of COLREGs and the STCW Code.
On the morning of the collision, when Accolade II departed the berth at about 0339, the ship’s bridge was manned by a watchkeeping officer (the master) and a helmsman (an IR). The pilot‑exempt master (with the helmsman steering) navigated the ship in darkness within the confines of the Port Adelaide River for about 50 minutes before the chief mate joined them on the bridge at about 0428. As such, for the duration of the ship’s passage within the harbour in darkness, there was no separate, dedicated look-out posted as required.
Once on the bridge, the chief mate performed a number of tasks to become familiar with the navigational situation in preparation for taking over the watch. While the chief mate was pre‑occupied with these tasks, the IR (helmsman) was dismissed from the bridge instead of being retained as a dedicated look-out.
Events and conditions on board Accolade II
On departure from the berth, Accolade II’s radar display was centred, north-up and in relative motion mode on a 0.75 nautical mile (mile) range scale. A variable range marker (VRM) was turned on and set to a range of 1.005 miles, but no electronic bearing line (EBL) was turned on. The radar’s heading input was sourced from the gyrocompass while speed input was from the GPS. The radar’s functionality allowed the ship’s passage plan waypoints to be input to display the ship’s planned track, but this was not used. Target vectors were set to ‘True’ for a duration of 3 minutes.[22] The ‘Trails’ function was off. This function displays the recent history (or past track) of a target as an echo trail or afterglow, making it conspicuous while distinguishing it from inconsistent echoes, such as from sea clutter or from stationary targets such as beacons (depending on whether true motion trails or relative motion trails have been selected).[23].
During the bridge pre-departure checks, the cursor was moved to the right of the display, over the AIS information menu item (Figure 6). The cursor’s position and other radar settings remained unchanged for Accolade II’s passage through Port Adelaide River and channel.
Figure 6: Set-up of Accolade II's radar as it exited the channel at 0433
The radar display was centred on a 0.75 mile range scale and that Sandgroper’s radar echo was not visible with these settings.
Source: Accolade II’s VDR, annotated by the ATSB
Table 1 and Figure 7 below provide a brief sequence of the events leading up to the collision referenced against relevant radar and audio data from the ship’s VDR.[24]
Table 1: Sequence of events referenced against Accolade II's VDR radar and audio data
Time
Event/action
0357
· Accolade II’s master reported passing beacon number 39 to tower
0428
· Chief mate arrived on bridge and engaged in general conversation with master and helmsman
0433:42
· Accolade II’s master reported exiting channel between beacons number 13 and 15 (Figure 6)
0433:47
· Radar display range scale increased from 0.75 miles to 3 miles
0434:02
· ‘Off Center’ view selected
· Sandgroper’s radar echo appeared at a range of about 1.2 miles (Figure 8)
· Chief mate selected AIS target data of a vessel on Accolade II’s port side
0434:26
· Helmsman dismissed from bridge
0434:47
· Chief mate selected AIS target data of a second vessel on Accolade II’s port side
· Sandgroper’s radar echo was now at a range of 1 mile from Accolade II
0434:55
· Chief mate answered bridge phone
0435:56
· Chief mate completed phone call
0436:45
· Chief mate reported sighting a ‘small fishing vessel’ to master
· Sandgroper’s radar echo indicated that the vessel was now at a range of 0.5 miles
0437:32
· Radar display range scale decreased to 1.5 miles
· Sandgroper’s radar echo indicated that the vessel was now at a range of 0.25 miles
0437:46
· Master ordered the chief mate to ‘go more south…’
0438:02
· Ship’s heading began to alter to port (Figure 9)
0438:32
· Sandgroper collided with Accolade II.
Figure 7: Section of chart Aus 138 showing events leading up to collision
Note that Sandgroper’s actual track between 0426 and 0434:02 is an approximate track as there was no positional data available for the vessel between these times
Source: Australian Hydrographic Office, annotated by the ATSB using electronically recorded data
Sandgroper first appeared on Accolade II’s radar display at about 0433 (Figure 8). However, no one on the bridge detected the fishing vessel until about 3 minutes later when the chief mate sighted its port sidelight. In those 3 minutes, the chief mate was pre-occupied with tasks such as adjusting radar settings, acquiring AIS icons of vessels on the radar, dimming lights and getting accustomed to the darkness in preparation to take over the watch.
About 1 minute of the chief mate’s time was taken up attending to a phone call. Meanwhile, the master recalled concentrating on navigating the ship clear of the channel and beacons (rather than checking outside the channel for traffic, either visually or using the radar). The master may have been experiencing a degree of cognitive tunnelling, which is an inattentional blindness where one becomes overly focused on some variable other than the present environment (Mack and Rock, 1998; Most, 2010).
Figure 8: Sandgroper's first appearance on Accolade II's radar at 0434:02
The radar image at 0434:02 shows that as soon as the range scale was increased from 0.75 miles to 3 miles and the ‘Off Center’ view was selected, Sandgroper’s radar echo immediately became visible on the radar display.
Source: Accolade II’s VDR, annotated by the ATSB
Additionally, the repetitive nature of the ship’s voyage may have induced a sense of complacency in the ship’s officers. One behavioural definition of complacency is trending behavioural variation that eventually exceeds safety boundaries (Hyten and Ludwig, 2017). This variation can be influenced by habituation. The master and chief officer had both worked on Accolade II for several years, executing the same voyage almost daily, to the point where it became a highly practiced activity.
Highly practised activities become automatic and require less attention than new or slightly practiced activities. Automatic processes occur without intention, taking place without effort. When a person is using automated processing (sometimes referred to as being on autopilot), they are sometimes ‘out of the loop’. It is recognised that to have good situational awareness, a monitoring operator needs to be ‘in the loop’, in order to notice anomalies.
Figure 9: Accolade II's radar display immediately before collision at 0438:02
Source: Accolade II’s VDR, annotated by the ATSB
Bucket elevator
The cargo system on board Accolade II comprised a single hold, two longitudinal scraper conveyors, a transverse scraper conveyor, a shuttle belt conveyor and a bucket elevator. The bucket elevator was located on the starboard side, just forward of midships. The 2 m wide elevator extended about 8.5 m above the ship’s main deck. This created a visual blind sector across the view of the sea surface as seen from the ship’s bridge (Figure 10).
SOLAS regulations required that any blind sector caused by cargo gear outside of the wheelhouse forward of the beam that obstructs the view of the sea surface as seen from the conning position, should not exceed 10°. Additionally, SOLAS stated that each individual blind sector obstructing the view of the sea surface from the conning position, forward of the bow to 10° on either side, should not exceed 5°.
Figure 10: Views from different positions on Accolade II's bridge
Source: Inco Ships, annotated by the ATSB
Figure 11: Bucket elevator visual blind sectors
Source: Inco Ships, annotated by the ATSB
The bucket elevator had been documented in several of the ship’s annual navigational audits as a known visual obstruction. As such, the blind sector created by the elevator was a known factor that the ship’s crew were aware of and one they routinely allowed for.
While Sandgroper might have been temporarily visually obscured by the bucket elevator, it did not pose a significant impediment to detecting the vessel if an effective visual lookout had been kept. The blind sector would only have affected observers near the starboard extremities of the ship’s bridge with visibility for observers elsewhere on the bridge unaffected. In any case, the bucket elevator had no effect on the performance of the ship’s radar.[25]
Sandgroper’s look-out
Sandgroper’s SMS included procedures on passage planning and watchkeeping which stated that the COLREGs were to be complied with at all times.
Sandgroper’s skipper was alerted to the presence of Accolade II by the deckhand’s sighting of the ship’s red sidelight. The skipper assessed that the ship was in, and would remain within, the channel. Due to that expectation, the potential for collision with the ship was probably not anticipated. Sandgroper’s skipper may have been experiencing an expectation bias in expecting Accolade II to continue down the channel. Expectation bias can occur when an individual's expectations about an outcome influence the perception of one's own or others’ behaviour (Williams and others 2012).
The skipper reported that following the course alteration and reduction of the radar range scale (from 3 miles to 0.125 miles), no vessels were sighted either visually or on radar until the collision. At the reduced radar range scale, the skipper would only have been able to see radar echoes within about 230 m around the vessel. The skipper also reported that the presence of lights on the shoreline made it difficult to visually distinguish Accolade II’s navigation lights.
Sandgroper was within port limits when Accolade II’s master broadcast the message to the communications tower that the ship was exiting the channel at beacon number 13. Sandgroper’s skipper did not hear this VHF broadcast as a listening watch on channel 12 was not being maintained. Although the vessel was equipped with two VHF radio units, a listening watch was being maintained only on VHF channel 16 as was the skipper’s usual practice. The port rules did not require fishing vessels to report to the communications tower and the skipper could not recall any past communications or interaction with the tower.
Automatic identification system
The automatic identification system (AIS) is a maritime communications device that uses the VHF radio frequency band to transfer data, including a vessel’s course, speed and other dynamic and static data. The system enables AIS-equipped vessels and shore-based AIS stations to send and/or receive identification information that, in addition to the AIS unit, can be displayed on an electronic chart and compatible radar. The information received can be used to assist the watchkeeper in making a full appraisal of the situation and of the risk of collision.
The Australian Maritime Safety Authority (AMSA) is responsible for the safety of domestic commercial vessels (DCVs). Under the National Law,[26] the National Standard for Commercial Vessels (NSCV) set out the standards for vessel survey, construction, equipment, design, operation, and crew competencies for DCVs.
The NSCV required that class 3B vessels carry an AIS Class B receiver/transmitter unit. However, ‘grandfathering’ arrangements allowed older DCVs (built before July 2013) to continue to operate under the requirements that existed before the introduction of the National Law and NSCV. As an ‘existing vessel’ built in 1978, Sandgroper was not required to have an AIS unit fitted to comply with survey requirements, and an AIS unit was not fitted on the vessel at the time of the collision.
Use of AIS for collision avoidance
The use of AIS can enhance situational awareness and can assist in target tracking. AMSA considers the use of AIS to transmit accurate data and to locate targets as a way to keep a proper lookout. AMSA also encouraged operators to help improve the detectability of their vessels by transmitting AIS data.[27] However, it is also important to note the use of AIS cannot replace the need for a visual lookout. Additionally, AIS target tracking data should be treated with caution for collision avoidance for which radar plotting data and compass bearings of targets remain the primary assessment tools.[28]
Fatigue
Fatigue has been defined as decreased capability to perform mental or physical work, produced as a function of inadequate sleep, circadian disruption, or time on task (Brown, 1994). Factors that contribute to fatigue-impaired work performance include:
the duration of a duty period
inadequate sleep
circadian effects
the type or nature of the task being undertaken (workload)
the work environment.
Fatigue can have a range of effects on human performance, such as decreased short-term memory, slowed reaction time, decreased work efficiency, reduced motivational drive, increased variability in work performance, and increased errors of omission (Battelle Memorial Institute, 1998).
An AMSA safety awareness bulletin[29] summarised fatigue among seafarers as follows:
The nature of vessel operations means seafarers are exposed to conditions which lead to fatigue. Insufficient sleep, night work, irregular and long working hours, monotonous tasks, high work demands are all frequently present in seafaring jobs. These are the primary factors that lead to fatigue. The need to manage the risk of fatigue - both at the individual and management level - is critical.
The ATSB has also highlighted the issue of fatigue through previous investigation findings and specific publications, including for the fishing vessel sector.[30]
Accolade II
The crew on board Accolade II were required to comply with the rest hour requirements of the STCW Code (as given effect by AMSA’s Marine Order 28). The ship’s SMS included a procedure that defined fatigue, provided guidance on recognising the signs of fatigue and reflected the rest hour requirements of the STCW Code.
The SMS also required crew to record their daily hours of work and rest on board. The rest hour records for Accolade II’s master and chief mate showed that their rest hours complied with the minimum rest hour requirements of the STCW Code. While self-assessment of fatigue is not a reliable indicator of alertness, both reported feeling very alert and well rested.
The sleep environment on the ship was reportedly comfortable and hence suitable for achieving restorative rest. A review of the ship’s voyage reports for January and February 2020 showed at least two instances in each month when the ship’s sailing was delayed to ensure compliance with rest hour requirements. The reports also showed no voyage on 27 February 2020 (2 days before the collision), with the day marked as a ‘Reset day’.
FAST analysis
A roster analysis of the master and chief mate’s work and rest times was conducted using the Fatigue Avoidance Scheduling Tool (FAST) bio-mathematical model to assess fatigue/alertness, and the effect on performance.
The FAST analysis showed that while there may have been a slightly higher fatigue risk for the chief mate, overall, the analysis did not appear to show that levels of fatigue likely to influence performance were present for either the chief mate or the master. The accuracy of the analysis was influenced by the nature of the ship’s fatigue management system. The recorded hours of rest indicated rest opportunity and not the exact hours of sleep, which had to be estimated.
Sandgroper
As a DCV, Sandgroper and its crew were not subject to the minimum rest hour requirements of the STCW Code. There were no prescribed minimum hours of rest and no requirement to record hours of rest. However, AMSA’s Marine Order 504[31] required that ‘the risk of fatigue of the master and crew’ be considered, among other factors, when determining the number of crew required to safely carry out a vessel’s operations. The AMSA website also provided guidance on managing crew fatigue on DCVs including practical information on the causes, effects and management of fatigue and its risks. Owners and masters were advised to take all practicable steps to ensure the safety of the vessel and crew, and that the crew were to be involved in the management of fatigue and the risks to safety.
Sandgroper’s SMS included some basic information on managing crew fatigue and required the skipper to manage crew fatigue. Guidance for crew stated they were to try and achieve 7–9 hours of sleep in every 24 hours.
Sandgroper’s AFMA fishing logs showed that the crew usually shot their fishing gear from about 0230-0430 and hauled the gear between 0930-1330 with rest opportunity obtained in between these times. This meant there was a total of about 18 hours of rest opportunity in every 24-hour period.
On the night before the collision, the skipper reported resting from about 1700–2300 followed by taking the watch until about 0300. The skipper then handed the watch to the deckhand and slept for about an hour until woken shortly after 0415.
Sandgroper’s skipper self-reported feeling ‘…well rested as far as a fisherman gets rest’ and alert. The skipper reported consuming at least one cup of coffee after waking that morning.
FAST analysis
The accuracy of the FAST analysis for Sandgroper’s skipper was influenced by the absence of recorded hours of work and rest, and no reliable record of sleep obtained in the days preceding the collision. The analysis was conducted based on estimates of sleep obtained and the AFMA fishing logs. Overall, the analysis did not appear to show that levels of fatigue likely to influence performance were present for the skipper.
Summary
Based on the available evidence, it was considered unlikely that levels of fatigue likely to influence performance were experienced by either vessel’s crew. However, there were several relevant risk factors present that were conducive to an environment in which fatigue could develop or that could have increased the chances of crew being fatigued.
Port Adelaide
Port Adelaide is the main port of South Australia handling a range of cargo including grains and seeds, limestone, containers, dry and wet bulk, vehicles, and general cargo. The port was owned and operated by Flinders Ports which was formed in 2001 when the Flinders Ports consortium successfully acquired seven ports that were privatised by the South Australian Government.
Port Adelaide port rules
Flinders Ports’ published rules for Port Adelaide that were intended to inform commercial users of the port of their responsibilities for the safe navigation of vessels within the port. The rules did not specifically define a ‘commercial user’ but, according to Flinders Ports, it did not include fishing and recreational vessels.
The rules documented three entry and exit points for the channel—at the entrance beacon, beacon number 5 and beacon number 9—depending on the vessel’s draught. Fishing vessels and recreational vessels could enter/exit the channel at any point. While Accolade II’s entry/exit point between beacons 13 and 15 was not among those listed, the ship was allowed the liberty of entering/exiting the channel at this location owing to its long history of operating in the port and its generally shallow draught.
At the time of the collision, Port Adelaide was not authorised as a Vessel Traffic Service (VTS) Authority. A VTS is established to improve the safety and efficiency of vessel traffic and to protect the environment. Ports may apply to establish a VTS when the volume of traffic or degree of risk justifies the service. Port Adelaide operated a communications tower (Flinders Ports Communications Tower) that kept a 24/7 listening watch on VHF channels 16 and 12. Channel 12 was used for ship/shore operations, information, transit advice and ship-to-ship traffic.
Flinders Ports rules required all pilots, masters and exempt masters to communicate with the tower at designated reporting points on channel 12. The rules also stated that vessels should monitor VHF channel 12 at all times in port limits for information.
Flinders Ports clarified to the ATSB that the port’s reporting requirements and the requirement to monitor the port’s working channel (channel 12) within port limits only applied to commercial vessels. As such, fishing vessels and recreational vessels were not required to report nor were the rules regarding a listening watch on channel 12 applicable to them.
Port Adelaide VTS
On 4 December 2020, about 8 months after the collision, Port Adelaide was authorised as a VTS authority with a new call sign of ‘Adelaide VTS’. Adelaide VTS was authorised to provide services, including a traffic organisation service (TOS). The TOS is a service to prevent the development of dangerous marine traffic situations and to provide for the safe and efficient movement of vessel traffic within the declared VTS area.
Adelaide VTS required all vessels over 150 gross tonnage (or where there was no gross tonnage, vessels 35 m or greater in length) to participate in the VTS. The rules required all commercial vessels to comply with VTS reporting requirements and Adelaide VTS can request any other vessel in the coverage area to participate. However, fishing and recreational vessels were generally not required to report.
While VTS rules stated that all vessels were to maintain a listening watch on VHF channels 12 when within or approaching Port Adelaide port limits, Flinders Ports advised that the rule only applies to commercial vessels. However, all vessels, including fishing and recreational vessels were encouraged to monitor the channel through the port’s safety outreach programs to educate and inform the public. The South Australian Department of Planning, Transport and Infrastructure (DPTI) also published a recreational boating safety handbook and boating safety advice, which included material on radio communication and listed channel 12 as among the channels usually used for port communications.
Rules in other ports
Local rules covering operations within port waters vary depending primarily on the port’s specific risk profile and resources. The applicability of the various rules also varies from port to port but are usually applied on the basis of factors such as vessel type, length or tonnage. Consequently, in each port, certain rules apply to vessels meeting certain defined criteria and not to others as the following examples show.
The Port of Fremantle, Western Australia, required all vessels 35 m or greater in length and all commercial vessels, regardless of length, to participate in the VTS when operating in the coverage area. It required all vessels navigating within port limits or at an anchorage within the port to maintain a continuous listening watch on the port’s working channel.
The Port of Melbourne, Victoria, required all vessels 50 m or greater in length to report at designated points/times and maintaining a continuous listening watch on the VTS working frequency. Non-recreational vessels less than 50 m in length (including fishing vessels) were required to watch the VTS working frequency and to report to VTS if 35 m or greater in length. Recreational vessels less than 50 m in length and equipped with VHF radio were required to watch the VTS working frequency when operating in port waters.
The ports of Weipa and Cairns in Queensland required all vessels, whether commercial or recreational, to maintain a listening watch on channel 16 and, if equipped, channel 12 while within the ports’ pilotage areas. Additionally, all ships greater than 24 m in length had to obtain approval from VTS before entering, leaving or manoeuvring within the pilotage area and all ships between 10 and 24 m in length were required to advise VTS before entering, leaving or manoeuvring within the port’s pilotage area.
The Port of Darwin, Northern Territory, although not serviced by a VTS, required all vessels of 20 m or greater in length, vessels carrying more than 12 passengers and certain other vessels to participate in the port’s traffic organisation service. Other vessels were encouraged to participate voluntarily.
As evident from the examples above, port rules and their applicability vary depending on various factors and there was nothing unusual in the content or applicability of Port Adelaide’s rules.
Similar occurrences
Over the last 30 years, at least 68 collisions between trading ships and small vessels have been reported to the ATSB or its predecessor. Of these, at least 40 have been investigated. The failure to keep a proper and effective lookout and/or take early and effective avoiding action in accordance with the COLREGs were recurrent contributing factors that could have prevented most of these collisions.
Collisions between large trading ships and small vessels, particularly fishing vessels, continue to occur off the Australian coast. In these collisions, a fishing vessel, being significantly smaller than a ship, almost always comes off worse and sometimes with severe consequences. For example, the 2000 collision between Star Sea Bridge and the fishing vessel Sue M, off Evans Head, New South Wales, and the 2003 collision between Asian Nova and the fishing vessel Sassenach off Townsville, Queensland, both resulted in the loss of life and of the vessels themselves.
While the measures in place to prevent such collisions might appear straightforward, the recurrence of similar contributing factors indicates that further effort is required from operators and crews to implement these measures. In addition to its safety investigation reports into collisions, the ATSB has published a number of safety bulletins to highlight collision risks and educate all seafarers. These documents and other safety information about marine safety issues are available on the ATSB website.
At about 0438 local time on 29 February 2020, in darkness and clear visibility, the inbound fishing vessel Sandgroper collided with the outbound self-discharging bulk carrier Accolade II, within port limits, about 1.5 NM south-west of the entrance to Port Adelaide, South Australia. The collision resulted in significant structural damage to Sandgroper and minor damage to Accolade II. Neither vessel identified that a risk of collision existed with the other until it was too late for effective avoiding action to be taken.
Look-out
Accolade II
In the time leading up to the collision, both the master and chief mate were occupied with tasks demanding much of their attention. The master was focused on navigating clear of the shipping channel while the chief mate was busy with various activities, including preparation to take over from the master. There was no dedicated look-out who could devote their full attention to sighting and reporting targets, including Sandgroper. As a consequence, the master and chief mate only sighted the fishing vessel moments before the collision.
Accolade II’s radar offered an additional means of detecting Sandgroper at an early stage. However, the radar’s initially small display range scale setting did not allow for an appreciation of the situation outside the channel before the ship exited it. Further, when the scale was eventually adjusted to one more conducive to detecting Sandgroper’s presence, the chief mate focussed on the automatic identification system (AIS) icons of two other vessels displayed on the radar display at the expense of Sandgroper’s radar echo. In addition, useful radar tools such as the trails function, which could have made Sandgroper’s radar echo more conspicuous and increased the chances of the vessel being detected were not used.
In summary, Sandgroper was not detected by anyone on board Accolade II until it was too late for effective avoiding action to be taken. Had better use been made of the radar or a dedicated lookout been posted as required, it would have increased the chances of detecting Sandgroper early and allowed more time to take action to avoid collision.
Sandgroper
Sandgroper’s skipper sighted Accolade II early when it was in the channel and assumed, not unreasonably, that it would remain in the channel. On that basis, the skipper altered Sandgroper’s course to keep clear of the ship. However, the skipper then paid little attention to the ship and its movement probably due to expectation bias that the ship would follow the channel. Further, the radar range scale was reduced to the minimum and an effective visual lookout by sight was also not maintained.
While there was no explicit requirement for fishing vessels to monitor Port Adelaide’s VHF radio working channel, Sandgroper was equipped to do so. Had the skipper monitored the working channel, it might have provided forewarning that Accolade II was exiting the channel at beacon number 13 (contrary to the skipper’s assumption), and to the developing close-quarters situation.
Sandgroper’s radar and VHF radio were both available means that could have enhanced the skipper’s look-out and allowed for an improved appreciation of the situation. However, neither was used effectively to maintain a proper look-out. Consequently, Sandgroper’s skipper was not aware of the risk of collision until collision was imminent and it was too late for effective avoiding action.
Automatic identification system
Sandgroper was not fitted with an automatic identification system (AIS) transceiver unit, nor was it required to be. Had an AIS unit been fitted, it would almost certainly have improved the detectability of the fishing vessel and made it more conspicuous on Accolade II’s radar and chart plotter. The evidence in this case shows that Accolade II’s chief mate readily acquired and monitored the AIS icons of two other vessels on the radar display but not Sandgroper’s radar echo, which should have been of immediate concern.
In addition, the fitting of an AIS unit with a display on board Sandgroper would have given its skipper the means to detect Accolade II’s AIS-transmitted data thereby enhancing situational awareness and augmented the keeping of a proper look-out.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the collision between Accolade II and Sandgroper, off Port Adelaide, South Australia, on 29 February 2020.
Contributing factors
A proper lookout by all available means was not maintained on board Accolade II. In particular, radar was not used effectively, and the dedicated lookout required in darkness was not posted. Consequently, Accolade II's watchkeepers were not aware of Sandgroper's presence or of the risk of collision until shortly before the collision when it was too late to take effective action.
After initially sighting Accolade II, Sandgroper’s skipper did not maintain a proper lookout or assess the risk of collision using all available means, in particular the radar and radio. As a result, the skipper only saw the ship when collision was imminent and unavoidable.
Other factors that increased risk
Sandgroper did not have an automatic identification system (AIS) transceiver fitted, nor was one required to be fitted. An AIS transceiver would have improved the vessel's detectability and enhanced the ability of its crew to keep a proper look-out.
Other findings
Accolade II’s bucket elevator did not pose a significant impediment to the ability of the ship’s watchkeepers to detect Sandgroper.
Safety actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the marine industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.
The initial public version of these safety issues and actions will be provided separately on the ATSB website on release of the final investigation report, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website after the release of the final report as further information about safety action comes to hand.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future.
Additional safety action by Southern Fisheries Group
Southern Fisheries Group advised the ATSB of the following safety action taken in response to the collision:
Sandgroper was fitted with an automatic identification system
Skippers and crews were provided with education on Port Adelaide River traffic
All crew are now required to be on watch when approaching port.
Additional safety action by Inco Ships
Accolade II’s managers (Inco Ships) advised the ATSB that, following the collision, a navigational audit was undertaken to assess the performance and effectiveness of the ship’s bridge team and bridge resource management. Inco Ships advised that the audit resulted in several recommendations to improve Accolade II’s bridge resource management practices.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the master and chief mate of Accolade II
the skipper and deckhand of Sandgroper
Inco Ships
Adelaide Brighton Cement
Southern Fisheries Group
Australian Maritime Safety Authority
Australian Fisheries Management Authority
Flinders Ports
Ashworth Maritime Services
Lloyd’s Register.
References
Australian Maritime Safety Authority, 2017, Maritime Safety Awareness Bulletin, Issue 5, March 2017, Canberra, Australia.
Australian Maritime Safety Authority, 2018, Marine Order 504 (Certificates of operation and operation requirements — national law) 2018, Canberra.
Australian Maritime Safety Authority, 2020, Marine Notice 06/2020 Reducing the risk of collisions at sea, Canberra, Australia.
Australian Transport Safety Bureau, 2004, Safety Bulletin 04 – Fatigue and fishing crews, Canberra, Australia.
Battelle Memorial Institute. An Overview of the Scientific Literature Concerning Fatigue, Sleep, and the Circadian Cycle, 1998. (Report prepared for the Office of the Chief Scientific and Technical Advisor for Human Factors, Federal Aviation Administration, USA.).
Brown, I. D. (1994). Driver fatigue. Human Factors, 36(2), 298-314.
Hyten, C., & Ludwig, T. D. (2017). Complacency in process safety: A behavior analysis toward prevention strategies. Journal of Organizational Behavior Management, 37(3-4), 240–260.
International Maritime Organisation, Standards of Training, Certification and Watchkeeping for Seafarers (STCW) Code, 1995, as amended, IMO, London.
International Maritime Organization, 2020, The International Convention for the Safety of Life at Sea (SOLAS) 1974 as amended, IMO, London.
Mack A & Rock I 1998, Inattentional blindness, MIT Press Cambridge MA.
Maritime and Coastguard Agency, 2016, Marine Guidance Note (MGN) 324 (M+F), Navigation: Watchkeeping Safety – Use of VHF Radio and AIS, Southampton, United Kingdom.
Most SB 2010, What's "inattentional" about inattentional blindness?, Consciousness and Cognition, vol. 19, pp.1102-1104.
Williams JB, Popp, D, Kobak KA & Detke MJ 2012, The power of expectation bias, European Psychiatry, vol. 27, pp.1
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the master, chief mate, owner and manager of Accolade II
the master, deckhand and manager of Sandgroper
Australian Maritime Safety Authority (AMSA)
Flinders Ports.
Submissions were received from AMSA and Accolade II’s managers (Inco Ships). The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Glossary
JRC
Japan Radio Company
MO
Marine Order
NSCV
National Standard for Commercial Vessels
PEC
Pilotage Exemption Certificate
RAV
Regulated Australian Vessel
SA
South Australia
SMS
Safety Management System
SOLAS
The International Convention for the safety of Life at Sea, 1974, as amended
STCW
Standards of Training, Certification and Watchkeeping for Seafarers
VDR
Voyage Data Recorder
TOS
Traffic Organisation Service
VHF
Very High Frequency
VMS
Vessel Monitoring System
VRM
Variable Range Marker
VTS
Vessel Traffic Service
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 4 February 2020, an Airbus Helicopters AS 350 B3 was being operated in support of New South Wales National Parks and Wildlife Service activities. Winching of personnel and equipment was being conducted when the operating crewman detected a technical issue with the load cable of the hoist system fitted to the helicopter. The outer strands of the cable toward its termination into the hook assembly had loosened in respect of the inner core.
During a subsequent hoist operation to restore the cable integrity, the cable fractured at the hook assembly while under load, releasing the weight bag and hook assembly to the ground. There was no damage to the helicopter or injuries to personnel.
What the ATSB found
The ATSB found that variations in the operator’s stowage practices over an extended period of winching operations led to inadequate compression of the hook assembly and subsequent wear to the load cable. The wear damage was due to vibration and movement of the hook assembly during periods of helicopter operation. This led to a significant reduction in the cross-sectional area of the cable, fatigue and fracture of the strands and an associated reduction in cable strength.
It is likely that specific post-flight inspection requirements for the Breeze Eastern rescue hoist required in the Civil Aviation Safety Authority (CASA) Airworthiness Directive AD/SUPP/10 were not being adequately completed by the operator. The inspections were targeted at minimising wear damage to the load cable by ensuring correct stowage of the hook assembly at the end of each flight.
Finally, the operator’s method of cycle counting during operation of the rescue hoist led to an accumulation of cycles that significantly exceeded the helicopter manufacturer’s recommended life-limit. That exceedance probably compounded the level of wear damage sustained to the load cable.
What has been done as a result
The New South Wales National Parks and Wildlife Service (ParkAir) implemented a range of pro‑active safety actions since the occurrence, including:
In July 2020, ParkAir provided Breeze-Eastern Flight Line maintenance training for all staff including pilots, maintainers and rescue hoist crewman.
A measurement gauge is now used by crewman to determine whether the hoist has adequate compression in accordance with the pre- and post-flight requirements listed within CASA Airworthiness Directive AD/SUPP/10.
In January 2021, a revision of the ParkAir Flight Manual Supplement was accomplished to ensure cable inspection procedures requirements are now completed in accordance with CASA Airworthiness Directive AD/SUPP/10.
ParkAir have adopted the more conservative Airbus Helicopters method for hoist cycle counting and all hoist cables now have a 500 cycle life-limit.
Additionally, as a direct result of this occurrence and the release of ATSB’s Safety Advisory Notice SAN-2020-013-001, the following pro-active safety advice was released by organisations responsible for the design, manufacture, and regulation of helicopter rescue hoist systems:
Breeze-Eastern Service Information Letter (SIL 14 Maintenance) Breeze-Eastern Rescue Hoist Maintenance & Flight Line Inspections for BL-29700 Series, release date 6 April 2020
CASA Airworthiness Bulletin (AWB) 25-034 Helicopter Rescue Hoist Wire Rope – Wear, Fatigue and Failure, release date 22 April 2020
Airbus Helicopters Safety Information Notice (SIN) 3507-S-25 Fatigue failure of a BREEZE 450 Lbs hoist cable, release date 4 June 2020
European Aviation Safety Agency (EASA) Safety Information Bulletin (SIB) 2020-11 Helicopter Rescue Hoist Cable Failure, release date 11 June 2020.
Safety message
The ATSB advises all helicopter operators and flight crew involved in rescue hoist operations to review their current operational practices to ensure hoist operation and hook stowage are in accordance with the manufacturers’ published procedures.
In addition, it is recommended that the pre- and post-flight inspection requirements of the hook and cable assembly, along with any recurring scheduled maintenance of the hoist system are closely reviewed, to ensure that they are completed in accordance with the manufacturers’ instructions. Improper stowage of the hoist hook assembly can lead to excessive movement and accelerated wear of the cable, which if undetected, could have a fatal outcome.
Should any load cable exhibit an increased frequency of outer strand loosening requiring a condition operation, operators should be particularly mindful to check for narrowing or ‘necking’ of the cable at the ball end within the swivel hook assembly. This can signify that the cable has become damaged due to extreme wear and may no longer be safe to use.
Summary video
The occurrence
An Airbus Helicopters AS 350 B3, registered VH-UAH, was being operated by the New South Wales (NSW) National Parks and Wildlife Service (NPWS) Flight Operations Unit (ParkAir) in support of bushfire operations during the 2019/20 summer period. The helicopter had been repositioned from the ParkAir aviation base at Bankstown Airport to a NPWS depot at Bulga, NSW to provide aerial support to fire crews at the Springvalley fire-grounds, within the Blue Mountains National Park. During that period, the helicopter was operated by a single pilot and a crewman operated the rescue hoist.
On 2 February 2020, the crewman assigned to VH-UAH was exchanged with another ParkAir crewman who had mobilised to Bulga. At duty handover, the departing crewman identified that the rescue hoist was operating without issue, however the load cable was starting to exhibit loose wires and would need monitoring. Over the next two days of operation about 30 winches of personnel and equipment was conducted. During that period the replacement crewman identified that the condition of the load cable from the hoist was continuing to deteriorate.
The outer wire strands of the load cable toward its termination into the swivel hook had loosened in relation to the inner core. Such loosening can develop during repeated short-length cable deployment and retrieval cycles. The crewman reported that, in an attempt to rectify the looseness, the outer wires of the cable were massaged and manipulated as it was reeled in and wound onto the hoist drum during operation. Despite that, the looseness was unable to be rectified.
On 4 February 2020, at the conclusion of the daily operations and on return to the Bulga depot, the crewman recommended to the ParkAir senior pilot that a conditioning operation be accomplished. Cable conditioning was a specific procedure intended to tension the cable and realign the wires to restore the cable integrity. It was agreed that it would be completed the following day prior to the conduct of any further winching sorties.
On the morning of 5 February 2020, following a pre-flight inspection of the rescue hoist, the crewman and senior pilot commenced the conditioning operation. A 160 kg weighted bag was attached to the swivel hook and the helicopter was lifted into a low hover and flown to an open field adjacent the NPWS Bulga depot. The bag was suspended about 5 m above the ground and the helicopter lifted into a vertical climb at an equivalent rate as the cable was reeled out from the rescue hoist. This continued until the maximum reel out extension limits of the hoist system were reached, after which the cable was reeled in. At the conclusion of that first conditioning run the crewman identified that the cable had further degraded.
The conduct of an additional conditioning operation was agreed and during that operation while under tension and close to maximum reel out, the cable failed, releasing the weighted bag and swivel hook to the ground.
The crewman advised the pilot that the cable had failed and that the hook and bag had fallen. The pilot’s only reported perception of an anomaly was a slight tilt of the helicopter from the centre‑of‑gravity redistribution when the bag fell. Both crew members returned to the depot and recovered the bag and swivel hook for subsequent examination. There were no injuries to personnel or additional damage to the helicopter. A portion of the fractured cable and the general fitment of the rescue hoist to the AS350 helicopter is shown at Figure 1.
ParkAir immediate actions
Following the cable failure, the Chief Pilot and Senior Pilot distributed an internal notification to ParkAir staff advising of the occurrence. As an immediate measure, ParkAir contacted the hoist manufacturer and arranged for it to be examined. All further ParkAir winching operations were suspended until each system was inspected and had their cables replaced (with the exception of a single hoist that remained in service due to the recent fitment of a new load cable).
Figure 1: A NPWS ParkAir AS350 helicopter (left) displaying general fitment of the rescue hoist, and a close-up of the fractured cable (right)
The fractured cable was found protruding from the swivel hook assembly. Source: National Parks and Wildlife Service
Context
Operational overview
The New South Wales (NSW) National Parks and Wildlife Service (NPWS) Flight Operations Unit (ParkAir) utilised a fleet of four AS350 B3 helicopters to support field operations that included fire management, personnel insertion duties, feral animal and pest species control. Each ParkAir helicopter could be equipped with an electric-powered recue hoist. A fifth hoist, also operated by ParkAir, was used as back-up in case of an unserviceability. The hoists were used for aerial winching of personnel and equipment into confined areas.
Aircraft information
VH-UAH was an Airbus Helicopters AS350-B3 light utility helicopter manufactured in 2014. It was powered by a single turbine engine and depending on its internal cabin configuration, could transport up to six people. The helicopter had been fitted with a hoist that was attached to an externally mounted mechanical arm on the left side of the helicopter, adjacent to the rear cabin (Figure 1). The arm pivoted outward during use and also allowed the hoist to be stowed against the fuselage during forward flight.
Hoist information
Manufactured by Breeze-Eastern, the rescue hoist was a model HS-29700 and provided a means for the lowering and raising of a single person or equipment to and from the helicopter (Figure 2). The hoist was remotely operated by the crewmember using a controller and the pilot was also able to control the system if necessary.
The hoist was an approved modification for the helicopter. The instructions for continued airworthiness for the hoist were contained in the:
Breeze-Eastern Flight Line and Operations Manual[1]
Airbus Helicopters AS350B3 Master Servicing Manual.[2]
The HS-29700 hoist has an allowable lifting limit of 204 kg and contains a rotating drum onto which is spooled 50 m of useable wire cable that terminates with a swivel hook and bumper assembly. The cable speed can be varied[3] during operation and limit switches within the system automatically trigger to slow the hoist speed as the cable approaches the full-out, or full-in position. The bumper assembly near the swivel hook consists of a crushable rubber block and conical spring that is intended to compress as the cable is reeled in and the full-in limit switch is activated, stopping the hoist. Compression of the spring and bumper assembly is a design feature by the hoist manufacturer to ensure that the swivel hook is adequately homed after being reeled in.
The Breeze-Eastern maintenance manual contained the hoist operating instructions and guidance for continued airworthiness. The manual advised that when reeling in, the cable should be guided by hand, at full pendant thumbwheel deflection to the full in position. The manual provided the following cautionary statement:
WARNING: WHEN NOT IN USE, THE HOOK MUST BE HOMED COMPLETELY IN THE FULL IN POSITION TO AVOID FATIGUE OF THE CABLE NEAR THE BALL END DUE TO VIBRATION.
Hoist cable
The load cable was specified to be manufactured from 0.156-inch diameter corrosion‑resistant stainless steel into a 19-strand by 7-wire configured arrangement comprising an inner core and outer layer (Figure 2). To resist rotation during use, the outer strands were woven in the opposite direction to the inner core. A stainless-steel fitting with a spherical ball-end was swaged onto the termination of the cable to enable secure fitment of the swivel hook and bump stop assembly.
Cycle counting
The Breeze-Eastern hoist was designed with a mechanical counter that recorded each revolution of the drum. The number on the counter was required to be recorded in the hoist logbooks and a calculation provided the total number of hoist cycles accrued during each recurring maintenance period.
Breeze-Eastern used a method whereby the difference on the cycle counter between successive maintenance periods was divided by 264. One complete hoist cycle was equivalent to a full reel-out and then a full reel-in of the cable. This was equivalent to 264 revolutions of the drum being logged by the counter. The method was specific to Breeze-Eastern and did not consider the actual number of winch operations that had been completed. Breeze-Eastern recommended a 1,500‑cycle life-limit for their hoist cables. The following cautionary note was contained within the Breeze-Eastern hoist manual:
1500 hoist cycle recommended replacement criteria is under ideal laboratory conditions, and may not be representative of actual operating conditions, or usage.
Figure 2: Breeze-Eastern HS-29700 rescue hoist and cross-section of the load cable showing its 19 strand x 7 wire configuration
Source: Breeze-Eastern, annotated by ATSB
Recent maintenance
All significant inspections, including recurring maintenance, were conducted by ParkAir’s maintenance provider for the hoist. Records showed that the occurrence rescue hoist (serial number 203) was bought and first introduced into service by ParkAir in December 2011. Over the subsequent 9 years of operation, the hoist was installed onto various AS350 helicopters within the ParkAir fleet until being rotated onto VH-UAH in July 2019 where it remained in service. The hoist logbook contained cycle counter entries confirming that ParkAir had been using the Breeze‑Eastern method for recording usage of their rescue hoists.
The last recorded maintenance activity contained in the hoist logbooks was on 3 December 2019 at approximately 600 hoist cycles and indicated the accomplishment of a 3-month and 6-month repetitive inspection in accordance with the Breeze-Eastern HS-29700 maintenance manual. Along with various checks of the system for functionality, an inspection of the swivel hook assembly was indicated as complete with no recorded defects. The load cable had accrued 617 hoist cycles at the time of the cable failure.
Technical examination
Hoist cable from ParkAir AS350 B3 helicopter, VH-UAH
The rescue hoist and the fractured load cable were sent to the ATSB technical facilities in Canberra for further analysis, with senior personnel from ParkAir in attendance during the preliminary examination.
The construction of the cable confirmed it to be of the configuration and type specified by Breeze‑Eastern for the BL-29700 hoist. Measurements confirmed the cable to be of the correct diameter with a 19-strand by 7-wire arrangement. The specifications[4] required the load cable to be manufactured from an austenitic stainless steel with a minimum breaking strength of 980 kg.
The load cable fractured approximately 10 mm from the swaged ball end fitting that terminated into the swivel hook assembly (Figure 3). The diameter of the remnant cable stub had drawn down with ‘necking’ of the cable cross-section evident. Measurements also identified that the inner core had retracted between 50 to 60 mm from the outer layer. Those outer strands had splayed which was typical of an overload cable failure, while the inner core remained tightly gathered. A faint serial number was etched on the shank of the swaged fitting that was confirmed by Breeze-Eastern to match their own records for the hoist and that the cable had been an original fitment from 2011.
Close visual examination of the cable at the point of fracture in the ‘necked’ region identified that many of the wires were grooved and scalloped (Figure 4). There was no evidence of foreign debris, external abrasion, corrosion, kinking or nicks that might otherwise explain the failure. Remnant lubricant was identified between the wires and on the swaged ball end fitting.
A scanning electron microscope (SEM) was utilised to further analyse the failed cable at much higher magnifications. The SEM examination confirmed that the severe scalloping was due to a wear mechanism of the cable near the point of fracture. The wear had progressed to an extreme level with many of the wires having lost almost the entirety of their cross-section.
A mixed fracture mode was also identified with evidence that some wires had sustained fatigue cracking prior to failure (Figure 5). The general shape of the fatigue cracking was indicative that the cable had been exposed to cyclic bending loads. A portion of the wires had also failed in ductile overstress and these were likely what provided the remnant cable strength during the final conditioning operation.
Hoist cable from ParkAir AS350 B3 helicopter, VH-ZHG
An additional hoist cable was also supplied by ParkAir for comparative examination. That cable had been removed from another Breeze-Eastern BL-29700 rescue hoist as an immediate organisational response to the failure. The secondary hoist cable had accrued 535 hoist cycles. External inspection before destructive sectioning of that cable showed local ‘necking’ had also occurred in the same area as the failed cable approximately 10 mm from the swaged ball end fitting.
The ‘necking’ provided an indicator of the onset toward a serious defect, such as worn or broken internal wires and strands. The subtle changes in diameter associated with the ‘necking’ could also be felt when handling the cable during physical inspection. Magnified examination of the ‘necked’ region identified that wear grooves and scallops had occurred to the wires comprising the cable. The damage was similar in appearance to that from the failed cable off VH-UAH, though all strands remained intact. Figures 6 and 7 provide further detail on the severity of wear damage associated with ‘necking’ of the intact hoist cable.
Figure 3: Swivel hook and bumper assembly
The wire strands comprising the inner core of the cable had retracted approximately 50 mm to 60 mm from the outer strands. Source: ATSB
Figure 4: Close-up of the remnant cable portion near the swaged ball end fitting showed narrowing or ‘necking’ and grooves in many of the wires from severe wear damage
Source: ATSB
Figure 5: SEM images of the fractured cable identified severely worn wires (left) and fatigue crack progression bands from bending fatigue (right)
Source: ATSB
Figure 6: Another ParkAir rescue hoist removed from service after the occurrence displayed narrowing of the cable at the ball end fitting.
The narrowing, or ‘necking’, could be detected during physical handling and close visual examination. The cable had accrued 535 hoist cycles throughout its service life.
Source: ATSB
Figure 7: Severe wear to the wires was evident from the intact cable at the point of narrowing near the swaged fitting
The cable strands in the ‘necked’ region were spread apart in order to identify the extent of wear damage.
Australian operators of Breeze-Eastern hoists were required to comply with Civil Aviation Safety Authority (CASA) Airworthiness Directive AD/SUPP/10.[5] The AD noted that damage can occur to a particular area of the load cable that may evade detection during normal inspection, resulting in a serious compromise of cable integrity. The AD referenced Breeze-Eastern document CAB-100-30[6] that introduced inspections intended to significantly improve the operational safety of the rescue hoist system. Specifically, operators of Breeze-Eastern hoists were required to conduct:
1. A one-time and recurring inspection of the of the hoist’s load cable in a specific area.
2. A pre-flight and post-flight inspection of the hook and bumper assembly during stowage.
During the one-time and recurring inspections, CAB-100-30 required maintenance personnel to partially disassemble the hook assembly to allow a close visual inspection of the cable at the ball end for evidence of necking down, loose or broken wires, and other damage. The hoist logbook indicated no defects were identified from that specific cable inspection, which had last been completed in December 2019 (at approximately 600 hoist cycles).
Pre- and post-flight inspections required from CAB-100-30 were intended to ensure proper stowage of the hook assembly ‑ firmly seated against the bump stop at the conclusion of the homing procedure. CAB-100-30 noted that assurance of adequate hook homing could be achieved by grasping it and rocking it fore and aft. Importantly, the advice from Breeze-Eastern within CAB-100-30 also indicated that during the post-flight inspection of the swivel hook, the degree of spring compression was required to be measured to verify proper homing of the hook, as identified in Figure 8.
Figure 8: Extract from Breeze-Eastern CAB 100-30 describing the inspection requirements 1) the load cable and 2) the hook and bumper spring compression measurement
Source: Breeze-Eastern
Organisation
ParkAir rescue hoist operation
While the rescue hoists within their operator’s fleet were primarily used for winching of personnel and equipment in response to operational requirements, another significant aspect of hoist usage involved hoist training/familiarisation exercises. The familiarisation training was mostly conducted at low heights with about 5 m of cable reeled out, leading to the accrual of hundreds of short-haul winches per year.
Hook homing
The Breeze-Eastern procedures for reeling up the load cable and homing of the hook assembly were defined in the hoist operations manual.[7] At the conclusion of a winching operation, and while positioning the hook to the upper limit stop, Breeze-Eastern indicated that it was important to ensure that completion of that action was uninterrupted and provided the following advice:
Always guide the hook by hand as the cable is reeled in, at full pendant thumbwheel deflection, to the full in position. Ensure the spring in the bumper is compressed sufficiently to prevent the hook from moving when the helicopter is in flight.
ParkAir advised the ATSB that minor variations to the prescribed Breeze-Eastern hook homing procedure had probably developed over the years without correction. It was indicated that in certain instances intermittent control of the cable speed and gentle homing had been conducted to avoid damaging the rubber bumper attached to the hook assembly.
The operator advised that it was uncertain how this deviation in practise arose, however it may have been influenced by a lack of recent Breeze-Eastern Flight Line maintenance training on the hoist system. Such training had last been conducted by ParkAir staff approximately 7 years prior. ParkAir had expanded in that time and staff turnover may have led to the factory‑instructed lessons being diluted.
AD/SUPP/10 hoist inspections pre- and post-flight
The ATSB identified that there was no reference within the operator’s supplementary documentation to ensure the pre- and post-flight verification that the hook assembly was correctly homed. The safety concerns and corresponding checks raised by CASA within AD/SUPP/10 regarding adequate compression of the hook assembly were not mentioned within the documentation. The operator indicated that, although homing of the hook assembly was physically checked by the crewman at the end of each winching operation, a verification measurement for hook assembly compression, as per AD/SUPP/10 was not accomplished.
Airbus Helicopters hoist specific maintenance
Airbus Helicopters provided technical guidance in their Master Servicing Manual[8]that specified the maintenance operations to be performed by the helicopter operator. Within section 25-63Equipment and Furnishings of the manual, Airbus Helicopters defined a hard life-limit of 500 hoist cycles on the load cable for the Breeze-Eastern BL-29700 hoist. Airbus Helicopters defined a hoist cycle as:
Hoisting cycles: HC (Hoist Cycle)
1 HC =
- In flight, one downward movement + one upward movement, whatever the length of cable and load involved.
- On the ground, one downward movement of 5 meters or more and one equivalent upward movement, whatever the load involved.
Both the Airbus Helicopters definition of a hoist cycle, and their definition of load cable life-limit were notably different to the definition and limits specified by Breeze-Eastern. Airbus Helicopters indicated that the reason for the discrepancy was to align the hoist cycle definition to other hoists within the Airbus Helicopters fleet. It was also indicated that although the Airbus Helicopters life‑limit is significantly more restrictive than that defined by Breeze-Eastern, their limits were intended to provide a greater safety margin during operation.
Regulatory guidance on maintenance
During the course of the investigation, CASA advised the ATSB that regulatory information was available to operators regarding which publication should be consulted if there are two sources of conflicting information for maintaining continued airworthiness, such as that issued by Breeze‑Eastern and that issued by Airbus Helicopters. Civil Aviation Regulation (CAR) 50E Inconsistent requirements – resolution of inconsistencies, stated the order of priorities under these circumstances:
(4) The order of priority of requirements is as follows (starting with those of highest priority):
(a) requirements in these Regulations (except those requirements mentioned in the remaining provisions of this subregulation);
(b) requirements in instruments made under these Regulations;
(c) requirements in documents (including designs) approved by CASA or authorised persons under these Regulations;
(d) requirements in instructions issued by designers of modifications of aircraft;
(e) requirements in instructions issued by designers of modifications of aircraft components;
(f) requirements in instructions issued by aircraft manufacturers;
(g) requirements in instructions issued by aircraft component manufacturers;
(h) requirements in instructions issued by aircraft material manufacturers;
(j) requirements in documents that are approved maintenance data because of paragraph 2A(2)(e).
Using the above list of priority requirements, the hoist had been fitted to the helicopter under a separate engineering instruction 4(d), however that instruction advised that the Airbus Helicopters 4(f) and Breeze-Eastern 4(g) maintenance instructions should be followed. CASA indicated that in this instance, the life-limits listed in the Airbus Helicopters master servicing manual would take precedence and were therefore to be followed.
Other occurrences
A search of the Australian defect reporting system, managed by CASA, identified no specific examples of cable failure similar to the occurrence involving VH-UAH.
However, a similar report of cable ‘necking’ was identified on a rescue hoist fitted to an Agusta Westland AW139 helicopter. The necking was identified at the swaged terminal within the hook assembly of a Breeze-Eastern hoist by that operator in May 2020. The defect report indicated that the necking had been found after release of CASA AWB 25-034 Helicopter Rescue Hoist Wire Rope – Wear, Fatigue and Failure (released in response to the occurrence involving VH‑UAH). The cable had accrued 114 cycles and after identifying the necking it was replaced. Also mentioned in the defect report was an indication that the ‘necking’ was associated with many short hoist cycles accrued in training.
The following analysis discusses the factors surrounding the cable failure from a Breeze-Eastern rescue hoist fitted to an Airbus Helicopters AS 350 B3 helicopter, registered VH-UAH, which occurred near Bulga, New South Wales. The failure occurred while the helicopter crew were conducting a conditioning maintenance operation of the rescue hoist system to restore the integrity of the cable. Although no personnel were injured in this occurrence, the helicopter had previously been conducting live winching.
Wear damage and cable failure
The ATSB’s technical examination identified that severe wear damage had developed within the wire strands of the load cable. Additionally, the cable internal core had retracted from the externally wound strands indicating that the inner portion had probably fractured prior to the commencement of the conditioning operation. The failure occurred when the cable was loaded with a 160 kg weighted bag which was significantly less than the ultimate tensile load limit of the cable. In normal circumstances the cable should have withstood the imposed load. There was no evidence of corrosion, kinking, shock loading or any other such damage on the cable that might have otherwise contributed to the failure. Remnant lubricant was identified between the wire strands.
The identified wear led to a significant reduction in cross-sectional area and eventual overstress of the load cable. Some of the worn wires also showed indicators of progressive fracture consistent with the development of fatigue cracking, with the remainder displaying ductile overstress fracture.
Stowage practices and Airworthiness Directive AD/SUPP/10
Breeze-Eastern provided clear advice in the operating instructions for the rescue hoist that when homing the hook, it was important to ensure that the homing action was not interrupted, using full deflection of the controller. This ensured adequate compression of the bump spring and prevented the hook from moving during flight.
The operator commented to the ATSB that in certain instances, intermittent control of the cable speed and gentle homing of the hook had been conducted to avoid damaging the rubber bumper attached to the hook assembly. Although that stowage practice was intended to prevent component damage, it probably led to inadequate compression of the hook assembly that resulted in winch cable damage as the hook assembly vibrated and moved during helicopter operation. The observed wear in the failed cable and the cable off another ParkAir rescue hoist, found to be the result of vibratory movement, supported that conclusion.
In addition to variations in the homing practices, it is likely that specific post-flight inspection requirements for the Breeze Eastern rescue hoist listed in Airworthiness Directive AD/SUPP/10 were not being adequately completed by the operator. The inspections were targeted at verifying correct stowage of the hook assembly at the beginning and end of each flight.
Although the hook assemblies were physically checked for security at the end of each winching sortie, a specific instruction contained within AD/SUPP/10 identified the requirement to measure the degree of spring compression that in turn verified proper hook stowage. The operator’s inspection requirements for the rescue hoist did not contain any reference for a compression measurement to be accomplished.
Cycle counting
A significant difference was identified between the method that Breeze-Eastern and Airbus Helicopters used to define hoist cycles and life-limits for load cables. Breeze-Eastern recommended a 1,500-cycle life-limit while Airbus recommended a 500-cycle life-limit. Breeze‑Eastern utilised a mechanical counter within the mechanism of the winch to determine a full winch cycle, while Airbus identified a hoist cycle as a downward and upward movement of the cable in flight.
The winch had been installed onto the helicopter using an engineering instruction that deferred to both the Breeze-Eastern and Airbus Helicopters technical documentation for maintaining continuing airworthiness. In the event of conflicting sources of information, Civil Aviation Regulation (CAR) 50E Inconsistent requirements – resolution of inconsistencies provided the means to prioritise the relevant instruction. Under these circumstances, given the hierarchy of inspection orders contained within the regulations, the Airbus Helicopters maintenance instructions should have been followed. ParkAir’s use of the Breeze-Eastern method for cycle counting during operation led to an accumulation of load cycles that significantly exceeded the 500-cycle life-limit recommended by Airbus Helicopters.
The wear that occurred to the wires probably occurred over an extended period of in-service movement of the hook assembly, further compounded by the overall extended age and accumulated load cycles of the cable. The hoist cable had accrued 617 hoist cycles and was 9 years old. Based on the number of short-haul winches accrued each year, it is very likely the cable had been exposed to thousands of load cycles. Had the Airbus Helicopters cycle life‑limit been followed, the cable would have been removed from service prior to failure.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the rescue hoist cable failure from an AS350 B3 helicopter that occurred on 5 February 2020.
Contributing factors
While the helicopter crew were conducting a conditioning maintenance operation of the hoist system, the hoist cable fractured, which allowed the suspended load to fall to the ground.
Wear damage from in-service movement of the hook assembly led to a significant reduction in cross-sectional area, fatigue and overstress fracture of the strands and an associated reduction in cable strength. The wear was probably compounded by the extended age of the cable and accumulated load cycles.
Variations in hook stowage practices following winching operations led to inadequate compression of the hook assembly. This probably led to the winch cable becoming damaged due to wear as the hook assembly vibrated and moved during helicopter operation.
It is likely that specific post-flight inspection requirements for the Breeze‑Eastern rescue hoist listed in Airworthiness Directive AD/SUPP/10 were not adequately completed by the operator. The inspections were targeted at ensuring correct stowage of the hook assembly at the end of each flight. (Safety issue)
The operator’s method for cycle counting during operation of the rescue hoist led to an accumulation of cable load cycles that exceeded the 500-cycle life-limit recommended by Airbus Helicopters.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation, industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety action not associated with an identified safety issue
Industry awareness of the rescue hoist cable failure
After being notified of the cable failure and on completing the technical examination of the hoist components, the ATSB advised the Civil Aviation Safety (CASA), Breeze-Eastern, the European Aviation Safety Agency (EASA), and Airbus Helicopters. Those organisations, along with the ATSB, released the following advisories to provide an alert to the broader helicopter industry.
Breeze-Eastern released Service Information Letter (SIL 14 Maintenance) Breeze-Eastern Rescue Hoist Maintenance & Flight Line Inspections for BL-29700 Series, on 6 April 2020. The SIL reminded operators, hoist maintainers and personnel of the critical importance of all listed inspections, including pre-and post-flight, contained in the BL-29700 hoist maintenance manual. The SIL reiterated the requirement to ensure proper compression of the spring from the bumper assembly, and the need for careful inspection of the cable in the immediate area of the swaged ball end fitting.
Proper hook homing inspections post flight must be done according to the flight line maintenance manual and other appropriate technical documents. Failure to complete these checks and verify that the hook is homed correctly post flight could cause a loosely stowed hook to vibrate during flight, creating stress on the wire rope cable.
The continual vibration of a helicopter and a loosely “homed” hook can result in a fatigue failure of the cable immediately above the ball end fitting.
CASA released Airworthiness Bulletin (AWB) 25-034 Helicopter Rescue Hoist Wire Rope – Wear, Fatigue and Failure, on 22 April 2020 to emphasise the care, attention and proficiency required to safely operate and maintain winch systems that lifted and lowered personnel and loads. Within the AWB CASA discussed the cable failure and recommended operators to:
Ensure inspections are completed methodically and thoroughly.
Always ensure the hook has been homed securely, as per approved data. This will prevent the hook causing premature cable fatigue.
Hoist system cycle counters cannot be used to replace physical and visual system inspections. These cycles are based on fatigue life determined in laboratories. Many hoist operations consist of much shorter deploy and retrieve cycles, than a counter may show. Additional inspections may be warranted.
ATSB released a Safety Advisory Notice (SAN) AO-2020-013-SAN-001 on 23 April 2020 that provided a preliminary summary of the cable failure. The SAN was distributed to all Australian operators permitted to conduct aerial work and conduct helicopter winching operations. The SAN advised:
For all helicopter operators and flight crew involved in rescue hoist operations to review their current operational practices to ensure hoist operation and hook stowage are in accordance with the hoist manufacturers’ published procedures.
For operators, flight crew and maintainers to closely review the pre- and post-flight inspection requirements of the hook and cable assembly, along with any recurring scheduled maintenance of the hoist system, to ensure that they are completed in accordance with the manufacturers’ instructions.
Airbus Helicopters released a Safety Information Notice (SIN) 3507-S-25 Fatigue failure of a BREEZE 450 Lbs hoist cable, on 4 June 2020 to all operators of AS350 and AS355 civilian helicopters fitted with the Breeze-Eastern BL-29700 winch. The notice provided a reminder that:
… after a hoisting mission, the hoist operator must position the hoist hook to the upper stop, while holding the control handle in the upward direction without interrupting the automatic stop of the hoist so that the compression phase of the hook assembly is not interrupted.
The notice also advised operators that maintenance of the hoist was to be completed using the Airbus Helicopters definition of a hoist cycle, whereby:
1 Hoist cycle (HC) =
In flight, one downward movement + one upward movement, whatever the length of the cable and load involved
On the ground, one downward movement of 5 meters or more and one equivalent upward movement, whatever the load involved.
EASA released Safety Information Bulletin (SIB) 2020-11 Helicopter Rescue Hoist Cable Failure on 11 June 2020 that informed European operators of the Breeze-Eastern 450 lb BL‑29700 series rescue hoist of the Australian occurrence. EASA recommended the following to all AS350 and AS355 helicopter operators:
…maintenance personnel should use the applicable Airbus Helicopters definition of a hoist cycle
…maintenance personnel and pilot(s), as applicable, should perform the pre-flight and post-flight inspection(s) as per applicable B-E CMM instructions
…pilots and on-board hoist operators should ensure a proper hoist stowing at the end of each hoist operation, by fully reeling it in to compress the hook bumper. Failure to follow this procedure could result in damage (due to wear and fatigue through vibration and aerodynamic loading) to the cable.
Safety issue description: It is likely that specific post-flight inspection requirements for the Breeze Eastern rescue hoist listed in Airworthiness Directive AD/SUPP/10 were not adequately completed by the operator. The inspections were targeted at ensuring correct stowage of the hook assembly at the end of each flight.
Glossary
AD Airworthiness Directive
ATSB Australian Transport Safety Bureau
AWB Airworthiness Bulletin
CAR Civil Aviation Regulation
CASA Civil Aviation Safety Authority
CMM Component maintenance manual
EASA European Aviation Safety Agency
HC Hoist cycle
NPWS National Parks and Wildlife Service
NSW New South Wales
SAN Safety Advisory Notice
SEM Scanning electron microscope
SIB Safety Information Bulletin
SIL Service Information Letter
SIN Safety Information Notice
Sources and submissions
Sources of information
The sources of information during the investigation included:
New South Wales National Parks and Wildlife Service Flight Operations Unit (ParkAir)
Civil Aviation Safety Authority
Breeze-Eastern
Airbus Helicopters
Additional references
Breeze-Eastern Customer Advisory Bulletin CAB 100-51, Use and Maintenance of Wire Rope on Airborne Personnel Hoists, October 1994
Helicopter Rescue Techniques, Civilian Public Safety and Military Helicopter Rescue Operations, United States Department of the Interior National Park Service, National SAR Academy (NSARA), First edition October 2013
Information on Helicopter Hoist Wire Rope, Failure Modes, and Rejection Criteria, Zephyr International IIc 2013
James Paul WALLIS, The importance of cable care, AirMed & Rescue Magazine, 4 June 2019
Kasim TURGAT et. al. Falls from height: a retrospective analysis, World Journal of Emergency Medicine, 2018 pp46-50
US Department of Defence, Wire Rope – Steel - Nonrotating for Aircraft Rescue Hoist, Military Specification MIL-W-83140 April 1969. Washington, DC
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
New South Wales National Parks and Wildlife Service Flight Operations Unit (ParkAir)
Civil Aviation Safety Authority
European Aviation Safety Association
United States National Transportation Safety Board
Breeze-Eastern
Airbus Helicopters
Bureau d'Enquêtes et d'Analyses of France
the helicopter owner
the rescue hoist maintainer
Submissions were received from:
Breeze-Eastern
Civil Aviation Safety Authority
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Around midday on 19 February 2020 a Beech D95A Travel Air, registered VH-AEM, and a Piper PA44-180 Seminole, VH-JQF, collided mid-air approximately 8 km south of Mangalore Airport, Victoria. The Travel Air was approaching Mangalore Airport from the south, on descent to conduct a practice instrument approach, while the Seminole was southbound on climb from Mangalore to Essendon Airport.
Both aircraft were operating under the instrument flight rules (IFR) in non-controlled airspace. The pilots of each aircraft had been provided with traffic information about the other aircraft prior to the collision, in accordance with procedures. Both aircraft were fitted with dual radios. Other pilots monitoring the common traffic advisory frequency (CTAF) associated with Mangalore Airport reported hearing pilots from both aircraft broadcast but had no recollection of hearing them speaking directly to each other.
The two aircraft collided with no evasive manoeuvring identified in recorded flight data. All four pilots were fatally injured and both aircraft were destroyed.
What the ATSB found
This was the first mid‑air collision between two civil aircraft operating under the instrument flight rules and procedures that have been in place in Australia for decades.
The ATSB identified that, following receipt of verbal traffic information from the controller, the pilots did not successfully manoeuvre or establish direct communications on the CTAF to maintain separation, probably due to the collision risk not being recognised.
While it is probable that the aircraft were in instrument meteorological conditions at the time of the collision due to the presence of extensive cloud, the known limitations of the ‘see-and-avoid’ principle meant that the pilots were unlikely to have seen each other in sufficient time to prevent the collision even in clear weather conditions.
Additionally, following receipt of an alert indicating the developing proximity of the aircraft, the controller assessed it in accordance with the required procedure. However, after considering that the pilots were aware of each other’s presence and were required to ensure their own separation in non‑controlled airspace, the controller did not intervene further.
While the pilots were responsible for self-separation within the Mangalore CTAF area, they did not have access to radar or automatic dependent surveillance broadcast (ADS-B) information. As a result, the pilots were required to make timely decisions to avoid a collision without the best available information.
Finally, although not contributory to the accident, the ATSB identified that the wording of procedures relating to the conduct of practice instrument approaches at Mangalore Airport resulted in varied application and an increased risk of traffic conflicts.
What has been done as a result
Airservices Australia (Airservices) have proposed a change to the Civil Aviation Safety Authority (CASA) to introduce a surveillance flight information service (SFIS) around Mangalore Airport, designed to provide enhanced traffic information services to all aircraft operating in a 20 NM radius of the airport. The proposed service would require all aircraft to broadcast on the CTAF within the broadcast area, while providing a dedicated air traffic controller operating on the CTAF to provide a flight information service utilising surveillance.
By listening on the CTAF, the controller would be able to determine whether aircraft have arranged their own separation following receipt of traffic information and provide updated traffic information if required. A similar service was introduced around Ballina Airport in August 2021.
In September 2021, the CASA Office of Airspace Regulation (OAR) announced an aeronautical study into the airspace within a 25 NM area of Mangalore Airport, up to an altitude of 8,500 ft. The scope of this study involves:
a review of traffic type and density over the previous 5 years
an evaluation of the suitability and efficiency of the airspace
a review of the equitability of access to the airspace, the appropriateness of the airspace classification and the suitability of the existing services and facilities provided by Airservices Australia.
As of February 2022, this aeronautical study has not been published.
The proposal for the introduction of an SFIS on the Mangalore CTAF is currently on hold pending completion of the OAR review. However, a dedicated controller is providing safety alerting on the Mangalore CTAF in the interim period. Communications on the CTAF are recorded by Airservices when the safety alerting service is operational. A further consultation has been raised by Airservices to lower the base of Class E airspace around Mangalore Airport. As of February 2022, that proposal was in review by Airservices following an industry consultation period.
In December 2021, the Department of Infrastructure announced a $30 million fund to provide rebates to general aviation aircraft operators to fund up to $5,000 or 50% of the cost of installing ADS-B transponder technology into their aircraft.
Safety message
While this accident involved aircraft operating under the IFR, irrespective of whether operating under the instrument or visual flight rules, pilots are responsible for separation from other aircraft in non‑controlled airspace.
As such, if made aware of traffic, either via advice from air traffic control (ATC), a received broadcast or any other means it is vitally important that the traffic is risk assessed and, if necessary, a plan established to assure separation. The following separation methods can be useful in maintaining a safe operating distance between aircraft:
different operating altitudes
ground feature reference (e.g. townships, lakes or linear features – rivers, roads)
navigation or avionics reference (e.g. radial or GPS distance)
‘clock code’ reference – useful to assist aircraft sighting.
The ATSB also strongly encourages the fitment of ADS‑B transmitting, receiving and display devices as they significantly assist the identification and avoidance of conflicting traffic. The continuous positional information that ADS‑B provides can highlight a developing situation many minutes before it becomes hazardous – a significant improvement on both point‑in‑time radio traffic advice and ‘see‑and‑avoid’. The ATSB also notes that ADS‑B receivers, suitable for use on aircraft operating under both the instrument or visual flight rules, are currently available within Australia at low cost and can be used in aircraft without any additional regulatory approval or expense.
It is also important to recognise however that ADS‑B cannot be relied upon to display all nearby traffic so effective use of radio remains a primary defence in avoiding mid‑air collisions. In that context pilots need to make all required broadcasts detailed in the Aeronautical Information Publication, even if there is no known traffic, and respond to broadcasts if a potential traffic conflict is identified.
Finally, in line with the key objective of ATC being the prevention of collisions, controllers should advise pilots if they become aware of a developing traffic conflict rather than assume that the pilots are already aware of it.
The occurrence
On 19 February 2020, at about 1055 Eastern Daylight-saving Time[1], a Beech Travel Air D95A aircraft registered VH-AEM (AEM), departed Tyabb Airport, Victoria for an Instrument Flight Rules (IFR)[2] training flight to Shepparton via Mangalore, and return to Tyabb. A student pilot (the student) and an instructor (the instructor) were on board. The pilots were planning to conduct a practice VOR[3] approach to Mangalore Airport as part of the student’s training towards the issue of an instrument rating. AEM was estimated to arrive overhead Mangalore Airport at 1126.
At around the same time, a pilot (the pilot under examination) and flight examiner (the examiner) were at Mangalore Airport, Victoria, preparing for an instrument rating flight test in a Piper PA44‑180 Seminole, registered VH-JQF (JQF).
At 1111, the pilot under examination, seated in the left seat of JQF, contacted the Melbourne Centre air traffic controller responsible for the surrounding Class G non‑controlled airspace, to advise that the aircraft was taxiing for a departure from Mangalore Airport. The pilot had submitted a flight plan for a round-trip IFR flight via Essendon and Shepparton. At this time, the Mangalore automatic weather station recorded cloud as broken[4], with a base of about 3,200 ft above mean sea level (AMSL).
After departing Tyabb, the crew of AEM climbed the aircraft to 6,000 ft and tracked north through the Melbourne Class C controlled airspace, before being instructed to contact Melbourne Centre. The student pilot first made contact with the Melbourne Centre controller at 1117:42 (Figure 1). They were informed there was no IFR traffic for the descent to Mangalore Airport. At the time the student pilot in AEM acknowledged this information, JQF had not appeared on the controller’s surveillance display. At 1120:07 the controller passed traffic information to the pilots of AEM that JQF was shortly to depart Mangalore airport heading to the south.
Surveillance data for JQF first appeared on the controller’s display at 1120:31, indicating JQF was airborne. At 1122:19, the pilot under examination in JQF made a departure call to the Melbourne Centre controller and provided information that the aircraft was passing 2,700 ft on climb to 7,000 ft and tracking to waypoint LACEY. The controller identified the aircraft on their display and replied with the area QNH[5]. At 1122:44 the controller provided the pilots in JQF with the following traffic information:
6 [nautical] miles in your 12 o’clock is alpha echo mike, a King Air. They are inbound to Mangalore for airwork. Passing 5,000 [ft] on descent to not above 4,000 [ft].
At 1122:49, five seconds after the controller passed this traffic information to the pilots of JQF, an aural and visual short-term conflict alert (STCA)[6] was provided to the controller. The alert indicated that the two aircraft were to come within 4.8 NM lateral and 600 ft vertical proximity in the next 60‑90 seconds. Based on the predicted velocity vectors[7] presented on the radar display for the two aircraft, the controller assessed that the aircraft would pass each other, with JQF passing behind AEM, then acknowledged the STCA. At 1123:00 JQF acknowledged the traffic information. By this time, JQF was climbing through 3,250 ft, had a ground speed of 81 kt and had commenced a turn to intercept their planned outbound track from Mangalore Airport to LACEY (Figure 2). At the same time AEM had a ground speed of 187 kt and was descending through 4,918 ft on a track of 354⁰. At this point, there was 5.4 NM horizontally and about 1,675 ft vertically between the aircraft.
Under IFR operational requirements, the pilots in JQF were required to intercept their outbound track (in this case the direct track between Mangalore Airport and LACEY) within 5 NM of the airfield, and manoeuvre to ensure terrain clearance until above the minimum sector altitude of 3,400 ft within 10 NM of the airfield. Terrain clearance was also assured above 3,900 ft within 25 NM of the airfield.
Figure 1: Flight paths for AEM and JQF, and airspace around Mangalore, including Melbourne Class C airspace and waypoint LACEY
Source: Google Earth and Airservices, annotated by the ATSB
In addition to AEM and JQF, there were six other aircraft either taxiing on the ground at Mangalore Airport, operating in the circuit area, or in the local area monitoring the Mangalore common traffic advisory frequency (CTAF).[8] Multiple pilots recalled each of the aircraft communicating separately on the CTAF, with one of the crew of JQF making a, rolling and circuit departure broadcast and a pilot from AEM making an inbound broadcast. However, none of the pilots in the CTAF area recalled any radio communications to arrange separation between AEM and JQF.
At 1123:51, another STCA appeared on the controller’s screen for the two aircraft. The controller acknowledged the STCA at 1124:09, whilst providing traffic information to another aircraft. At the time of the STCA activation, the velocity vector of JQF crossed the velocity vector of AEM, with JQF predicted to pass closely behind AEM. However, the controller’s display showed there was 500 ft vertical separation between the aircraft.
At 1124:20 the aircraft collided. Following the collision, the ATC radar display reverted from a presentation of the track of each aircraft based on surveillance data to the flight planned tracks. The controller attempted to contact each aircraft numerous times, before declaring a distress phase for both aircraft.
The collision occurred about 4 NM (7.5 km) south of Mangalore Airport[9] at around 4,100 ft. There were no witnesses to the collision. However, the pilot of a helicopter operating to the south of the collision point reported seeing one aircraft (AEM) descending rapidly, with the other aircraft (JQF) descending more slowly while spinning. Two other witnesses, one, a pilot located on the airfield, and a second closer witness, similarly reported seeing JQF spinning toward the ground.
The two aircraft impacted the ground about 1.3 km apart (Figure 2). Some lighter debris from each aircraft was located at a third location downwind from the collision point. All four pilots were fatally injured in the accident, and both aircraft were destroyed.
Figure 2: Flight path of AEM and JQF, and location of the ground impact of both aircraft
Source: Google Earth and Airservices, annotated by the ATSB
All four pilots and the air traffic controller held the required licences and medical approvals. It was considered unlikely that fatigue affected the performance of any of the involved pilots, due to the time of the accident, and their previous work and rest times. Workload and fatigue assessments for the controller are detailed in a separate section below.
VH‑AEM instructor
Qualifications and experience
The instructor onboard VH-AEM (AEM) held an Air Transport Pilot Licence (Aeroplane) (ATPL(A)) issued on 29 January 2004, and a Commercial Pilot Licence (Aeroplane) (CPL(A)) issued on 13 October 1993. The instructor also held a Grade 1 flight instructor rating with endorsements for multi-engine class rating[10] training and instrument rating training. The instructor had an English language proficiency of level 6[11].
The instructor’s instrument rating and multi-engine aircraft rating were valid until 29 February 2020, and their flight instructor rating was valid until 30 June 2020. The instructor had previously held an examiner rating covering private pilot licence and night visual flight rules testing endorsements, and English language proficiency assessments.
The instructor’s logbook showed a total flying experience of 5,907.2 hours to the last recorded flight on 14 February 2020. In the previous 90 days, the instructor had flown 29.3 hours of which 7.6 hours were in the Beech D95A Travel Air (Travel Air) aircraft type. In the previous 30 days the instructor had flown 25.1 hours total, 5.4 of which were on type.
The instructor had been the operator’s Chief Pilot since March 2019, and the Head of Operations since April 2019.
Medical information
The instructor held a class 1 aviation medical certificate valid until May 2020, with a restriction that it could not be used for ATPL operations. The instructor had a mild colour vision deficiency which had been assessed by specialists as ‘extremely mild’ and had been declared to the Civil Aviation Safety Authority (CASA).
There were no restrictions preventing the instructor from undertaking commercial operations including flight instruction. Additionally, the instructor was not required to wear any vision correction in flight.
VH‑AEM student
Qualifications and experience
The instrument rating student in AEM held a CPL(A) issued on 30 April 2013. The student had also previously held a Grade 3 flight instructor rating permitting single engine aircraft, night VFR and design feature training. The student also held activity endorsements for formation flight, aerobatics and spinning. The student held a level 6 English language proficiency assessment.
The student’s logbook showed a total flying experience of 1,103.1 hours to the last recorded flight on 17 February 2020. The student’s total flying experience on the Travel Air was 6.6 hours. In the previous 90 days, the student had flown a total of 60.4 hours, including the 6.6 hours on the Travel Air; and in the last 30 days had flown 30.3 hours with 2.2 of those in the Travel Air.
Medical information
The student held a Class 1 aviation medical certificate valid until 2 September 2020. There were no restrictions on their medical certificate.
Instrument rating training
An instrument rating is an operational rating permitting a pilot to fly under the IFR.
The student passed their instrument rating theory examination on 2 October 2019. Logbook records indicate that the pilot first completed 1.1 hours in the simulator for ’NDB and instrument flying’ in June 2019. This was completed with another instructor.
Records indicate that the Travel Air instructor and the student began flying together in October 2019 for the purposes of completing the instrument rating. Table 1 identifies the flights logged in the student’s logbook, conducted as flight training toward the instrument rating with multi-engine aeroplane instrument endorsement. The first three flights were conducted as day VFR flights in the Travel Air, conducting elements of handling required for the multi-engine endorsement (see the section titled Pilot Licencing).
Table 1: Flights completed in preparation for instrument rating
Date
Aircraft
Duration (Hours)
Details
14 October 2019
VH-AEM
0.9 (VFR)
General handling, stalls and circuits
16 October 2019
VH-AEM
1.1 (VFR)
Circuits, go arounds
21 October 2019
VH-AEM
2.4 (VFR)
Tyabb – LaTrobe Valley – Asymmetric engine operation and engine failure after take-off - Tyabb
28 October 2019
Simulator
1.7 (IFR)
Sector entry and holding / basic instrument flying
28 October 2019
Simulator
1.0 (IFR)
Holding with winds
18 November 2019
Simulator
1.0 (IFR)
ILS at Essendon, RNAV and hold at Moorabbin
20 January 2020
Simulator
2.1 (IFR)
Holding, cross wind, RNAV Mangalore and Yarram, VOR Approach
23 January 2020
Simulator
2.0 (IFR)
Moorabbin, Yarram – Holding and RNAV, Essendon ILS
28 January 2020
VH-AEM
2.2 (IFR)
Tyabb – Yarram – LaTrobe Valley – MOZZA[2] – MONTY – Essendon ILS
1 February 2020
Simulator
1.2 (IFR)
Moorabbin – Mangalore – VOR approach
[1] ILS, RNAV and VOR are types of instrument approaches. [2] MOZZA and MONTY are IFR waypoints. See the section titled Operational information.
VH‑JQF examiner
Qualifications and experience
The examiner on board VH-JQF (JQF) held an ATPL(A) that was issued on 17 July 1978. They held a flight examiner rating permitting examination of a variety of operational ratings, including an instrument rating and multi-engine aeroplane class rating. The examiner had a level 6 English language proficiency.
The operator’s records indicate the examiner received a briefing on relevant operational policies in August 2018. However, as per the regulations, the examination flight was conducted as a private flight rather than a commercial operation.
The examiner successfully completed an instrument rating proficiency check in a Seminole on 17 February 2020, two days before the accident flight. The examiner’s instrument rating and multi‑engine class rating were valid until 28 February 2021. The examiner’s grade 1 flight instructor rating was valid until 31 December 2021.
The examiner’s flight examiner rating had exceeded the renewal date, however, operation as an examiner was still permitted under CASA EX70/18, an exemption issued by CASA to extend the requirement to conduct a proficiency check until March 2020. This exemption was issued to assist with the transition of examiners from the Authorised Testing Officer delegations to the Civil Aviation Safety Regulations Part 61[12] Flight Examiner ratings.
A review of the examiner’s logbook showed a total flying experience of about 21,600 hours. CASA records indicate that the examiner conducted 194 flight tests in the 2 years prior to the accident, of which 34 were for the initial issue of an instrument rating.
Medical information
The examiner held a class 2 aviation medical certificate that was valid until 15 October 2020. There were two restrictions placed on the examiners medical certificate:
Distance correction was to be worn while exercising the privileges of this licence.
Reading correction was to be available while exercising the privileges of this licence.
The available evidence indicates that these restrictions were being complied with at the time of the accident.
VH‑JQF pilot under examination
Qualifications and experience
The pilot under examination had been enrolled in a diploma course with the operator since February 2017, and although having completed most of the flying program from Moorabbin Airport they were also familiar with operating to and from Mangalore Airport. The pilot under examination held a CPL that was issued on 24 June 2019. The final component of their training was the instrument rating and multi-engine class rating, being tested during the accident flight. The pilot had a level 6 English language proficiency.
The pilot’s logbook showed a total flying experience of 244.9 hours to the last recorded flight on 17 February 2020. The pilot’s total flying experience in the Seminole was 22.2 hours. In the previous 90 days, the pilot had completed 20.4 hours total flying (all in the Seminole), and in the last 30 days had completed 4.8 hours flying.
Medical information
The pilot’s Class 1 aviation medical certificate was renewed 3 days prior to the accident and was valid until 12 March 2021. There were no restrictions placed on their medical certificate.
Instrument rating training
The purpose of the accident flight was examination for an instrument rating, a multi-engine aeroplane instrument endorsement and a multi-engine aeroplane class rating. The pilot under examination had passed the theory component for the instrument rating on 11 November 2019.
Records indicate that the pilot began training for the multi-engine class rating and the instrument rating in August 2019. During this training, the pilot logged:
Day multi-engine aircraft flight: 32.0 hours
Night multi-engine aircraft flight: 7.2 hours
In-flight instrument flight time: 17.2 hours (logged during the 39.2 day and night multi-engine aircraft flight hours)
Simulator time: 20.4 hours
All training was completed with one instructor, and all flying was conducted in a Seminole. Documentation recommending the pilot for the flight examination was completed by this instructor after a final practice flight on 17 February 2020, which included flying to Mangalore Airport.
Air traffic controller
Qualifications and experience
The controller had worked for Airservices Australia (Airservices) since 1989. The controller was issued with ratings for area procedural control and area radar control in 1996; and was issued with an endorsement for the sector being controlled on the day (see the section titled Airspace) in January 2012. The controller held a level 6 English language proficiency.
The controller held a Class 3 medical, appropriate for air traffic controllers, which was valid until 6 October 2021, and required the controller to have reading correction available.
The most recent training completed by the controller prior to the accident was compromised separation refresher training on 2 October 2019, and effective scanning training on 26 February 2019.
Roster and workload
The controller reported that they did not feel fatigued prior to, or at the time of the accident. The controller noted that although some of the roster patterns worked could be fatiguing, controllers found ways to manage this. A review completed by Airservices did not identify any fatigue related‑ issues with the controller’s roster.
While the roster had a mix of morning, afternoon and night shifts during February, in the 3 days prior to the accident the controller had completed the following roster:
Sunday 16 February: day off
Monday 17 February: 1400 - 2200
Tuesday 18 February: 1400 - 2200
Wednesday 19 February: 1100 start
The controller recalled being asleep by midnight after the shift on Tuesday 18 February and waking to an alarm at 0800 on Wednesday morning. The controller arrived at work about 15 minutes early, to prepare for the day.
The controller described the workload on the day as having ‘a bit going on’, but not busy. It was further stated that there were no particular pressures on the day of the accident.
Medical and pathological information
Given the nature of the mid‑air and ground collisions, the accident was not survivable for any of the four pilots.
The autopsy of the examiner in JQF identified a level of ischaemic heart disease capable of causing death in isolation from other factors, but there was no evidence of an acute cardiac event having occurred at the time of the incident.
No other significant medical issues were identified in any of the remaining pilots. Further, the toxicology results did not identify any substance that could have impaired the pilots’ performance or that were not noted in their aviation medical records.
Aircraft information
Both aircraft met the equipment requirements for flight under the IFR, detailed in Civil Aviation Order 20.18 including the carriage of Automatic Dependent Surveillance – Broadcast (ADS-B)[13] equipment (see the section titled Automatic dependent surveillance broadcast).
VH‑AEM
The Beech D95A Travel Air is a four to six seat, low‑wing, retractable-tricycle-undercarriage aircraft fitted with two 180 horsepower Textron Lycoming IO-360-B1B reciprocating engines driving constant‑speed, two-bladed propellers.
AEM (Figure 3) was manufactured in the United States in 1966 with serial number TD 682. It was first registered in Australia in 1967, and prior to the departure from Tyabb, the aircraft had accumulated 7,400.3 hours in service.
Figure 3: Beech Travel Air VH-AEM
Source: Aircraft operator, annotated by the ATSB.
AEM had a current Certificate of Registration, Certificate of Airworthiness and maintenance release. The last maintenance conducted on the aircraft was a calibration of the aircraft’s altimeters, air speed indicators, compass, pitot-static system and fuel quantity system, conducted on 17 January 2020.
The aircraft was certified for IFR and charter operations and was equipped with dual controls for the student and instructor. The aircraft was also equipped with a Garmin GNS530 radio communication and GNSS navigation system, together with a second communication radio. The aircraft was also fitted with a Garmin GTX335 ADS-B OUT transponder. AEM did not have any ADS-B receiving equipment.
One notable modification to the aircraft was the replacement of the original two frame windscreen with a single pane ‘speed-slope’ windscreen. The exact date of replacement was unknown, however this was a common modification to Travel Air aircraft. The speed-slope screen is a component of later-model Travel Air aircraft and Beech Baron aircraft.
The modification involved removal of the centre spine of the original screen, with no further modifications to the fuselage roof area or side frames. The lower section of the speed-slope screen protruded approximately 75-100 mm further towards the aircraft nose than the original windscreen. A larger glareshield was also fitted to the aircraft to fill the space between the instrument panel and the new windscreen.
A review of the previous two aircraft maintenance logbooks for AEM showed that the speed‑slope screen was last replaced on 5 August 2011, and that the pilot’s side window had been replaced on 25 December 2014.
VH‑JQF
The Piper PA-44 Seminole is a four-seat, low-wing, twin-engine light aircraft. It is powered by two 180 horsepower Textron Lycoming O-360-E1A6D reciprocating piston engines. JQF was fitted with three-blade, constant‑speed and full-feathering aluminium propellers. The Seminole is equipped with hydraulically‑operated, retractable, tricycle landing gear. JQF (Figure 4) was manufactured in the United States in 1979 with serial number 44-7995291. It was first registered in Australia in 1990. The aircraft was owned by the operator. Prior to the accident flight, the aircraft had accumulated a total flight time of 11,190.6 hours.
Figure 4: Piper Seminole VH-JQF
Source: Aircraft operator, annotated by the ATSB.
JQF had a current Certificate of Registration, Certificate of Airworthiness and maintenance release. The maintenance release was issued on 12 February 2020, and the aircraft had completed 18.0 hours flying since that time.
The aircraft was certified for IFR and private/airwork operations. It was equipped with dual controls for the student and instructor. The aircraft was also equipped with a Garmin GNS430 radio communication and GNSS navigation system and a second communication radio. The aircraft was fitted with an Appaero Stratus Mode-S transponder unit, which had ADS-B OUT transmit capability only.
Operational information
Airspace
Overview
Airspace in Australia is separated into different classes that may be either controlled (Class A, Class C, Class D, Class E) or non-controlled (Class G) (Figure 5). Different services are offered to aircraft that operate in these airspace classes, based on the flight rules the aircraft is operating under (see the section titled Air traffic services).
Figure 5: Australian airspace structure
Source: Airservices
Common traffic advisory frequency
Mangalore Airport is a non-controlled airport that operates on a common traffic advisory frequency (CTAF). This frequency is shared with four other airfields in the local area – Locksley Field, Nagambie-Wirrate, Wahring Field and Puckapunyal (Figure 6).
The precise boundaries of a CTAF are not defined, however, the Aeronautical Information Publication (AIP[14]) stated that:
An aircraft is in the vicinity of a non-controlled aerodrome if it is within a horizontal distance of 10 [nautical] miles; and within a height above the aerodrome reference point that could result in conflict with the operations at the aerodrome.
Mangalore Airport is located 4 NM north of an 8,500 ft Class C control step. The accident took place almost directly underneath the 8,500 ft step boundary (Figure 6). Class G non-controlled airspace surrounds Mangalore Airport up to 8,500 ft; with Class E controlled airspace from 8,500 ft to flight level[15] 125 (FL125) and Class C controlled airspace from FL125 to FL180. Class A controlled airspace was in place above FL180.
Figure 6: Airspace surrounding Mangalore Airport
Source: Airservices, annotated by the ATSB.
Class G airspace
Class G airspace has been operational in Australia since 1995. In Class G airspace, air traffic controllers provide a traffic information service to IFR aircraft about conflicting IFR and observed VFR flights (see the section titled Flight Information Service). Controllers have offered a similar ‘flight service’ to IFR aircraft operating in non-controlled airspace since 1963.
AEM was transferred from one Melbourne Centre controller to another Melbourne Centre controller, just prior to the 30 DME[16] control boundary (Figure 7), where the lower level of Class C airspace increased from 4,500 ft to 8,500 ft.
The pilots of AEM first made contact with the Melbourne Centre controller at 1117:42, and they entered the airspace around 1118:22. They were not on the Melbourne Centre frequency at 1111 when the pilot of JQF made their taxi call to the Melbourne Centre controller.
Figure 7: Airspace around Mangalore Airport and the outbound IFR track to LACEY
Source: Airservices, annotated by the ATSB
Rules of the air
While both aircraft were operating in the same airspace under the IFR and were in contact with the Melbourne Centre controller, due to the airspace being class G non-controlled airspace, the controller was providing a flight information service only to these aircraft, rather than a traffic control service with positive separation (see the section titled Flight information service). This meant that, as with VFR operations in non-controlled airspace, the pilots were responsible for ensuring they maintained sufficient separation.
The Civil Aviation Regulations 1988161 through 166 sets out a number of associated regulations detailing pilot responsibilities in relation to rules for the prevention of a collision, operating near other aircraft, right of way and operating in non-controlled airspace.
With regard to the responsibility of pilots to communicate on VHF radio, Civil Aviation Regulation 166C – Responsibility for broadcasting on VHF radio states
(1) If:
a. An aircraft is operating on the manoeuvring area of, or in the vicinity of, a non-controlled aerodrome; and
b. The aircraft is carrying a serviceable aircraft VHF radio; and
c. The pilot in command of the aircraft holds a radiotelephone qualification;
The pilot is responsible for making a broadcast on the VHF frequency in use for the aerodrome in accordance with subregulation (2)
(2) The pilot must make a broadcast that includes the following information whenever it is reasonably necessary to do so to avoid a collision, or the risk of a collision, with another aircraft:
a. The name of the aerodrome;
b. The aircraft’s type and call sign;
c. The position of the aircraft and the pilot’s intentions.
The AIP defines a broadcast as: A transmission of information relating to air navigation for which an acknowledgement is not expected.
The AIP further clarified statements about broadcasts and collision avoidance in GEN 3.3 paragraph 7.5.1 Acknowledgement of broadcasts:
Broadcasts should not be acknowledged unless a potential collision risk exists
Flight plans
AEM
The student pilot of AEM submitted a flight plan to Airservices at 1041 on the morning of the flight. The flight plan details were to
depart Tyabb Airport at 1055
fly direct to Mangalore Airport and conduct the VOR hold and approach
depart to Shepparton Airport for the Area Navigation (RNAV) Global Navigation Satellite System (GNSS)[17] approach
return via Mangalore and LACEY to Moorabbin for the RNAV GNSS approach before returning to Tyabb.
A witness from Tyabb reported that the instructor and instrument rating student had tried to book slots to conduct instrument approaches at airports in the Melbourne control zone but were unable to secure any on the morning of the flight[18]. They were also unable to operate at East Sale due to military training. Therefore, it was decided to fly to Mangalore and Shepparton.
The aircraft proceeded as per the flight plan. The pilots were transferred to the Melbourne Centre controller just prior to the airspace boundary and entered the Class G airspace while maintaining 6,000 ft about 24 NM south of Mangalore Airport. About 90 seconds later, when the aircraft was about 18 NM from Mangalore Airport, the student pilot contacted Melbourne Centre to report their departure from 6,000 ft for airwork at Mangalore not above 4,000 ft (operations between ground level and 4,000 ft).
The planned instrument approach was the VOR approach to runway 23 (see the section titled Mangalore VOR). The approach required them to pass overhead the VOR not below 3,900 ft before beginning the outbound leg of the approach, and descending to no lower than 1,800 ft. There were no reported issues with the serviceability of the VOR at the time of the occurrence.
JQF
The pilot under examination submitted a flight plan at 0949. The flight plan detailed:
an 1100 departure from Mangalore Airport and climb to 7,000 ft while tracking to LACEY
conduct of an NDB[20] approach at Shepparton Airport before returning to Mangalore for an RNAV approach.
The flight plan submitted to Airservices did not specify the route planned to LACEY, other than Mangalore Airport direct to LACEY. However, a copy of a handwritten flight plan indicated the intention to track from Mangalore to LACEY along the published IFR route W481 (Figure 7).
JQF commenced the take-off roll from runway 23 at Mangalore just prior to 1120. The aircraft initially departed in an extended upwind direction, before commencing a series of left turns that resulted in the aircraft tracking towards the planned route to LACEY (Figure 8).
The pilot under examination made a departure call to the Melbourne Centre controller with the first communication commencing at 1122:19. At the time of this call, during which the pilots were provided traffic information about AEM, the track maintained by JQF was direct to LACEY. This may have been intentional, or co-incidental due to the increased workload of the student during the take-off phase and climb phase and managing the radio during the Melbourne Centre call. It was at this time the controller reviewed the velocity vectors that were based on the track of the aircraft not the flight planned track, and assessed that JQF would pass behind AEM (see the section titled Short term conflict alert). However, at the end of the radio communication, JQF resumed the turn towards the planned route to LACEY via route W481.
Figure 8: Track of JQF after take-off from Mangalore Airport
Source: Google Earth and Airservices, annotated by the ATSB
Mangalore VOR
The Mangalore VOR is one of four such navigation aids in Victoria. As part of the 2016 Navigation Rationalisation project, in a move towards using a Global Navigation Satellite System (GNSS), 179 ground-based navigation aids were decommissioned across Australia. Twenty eight of the decommissioned instrument approaches were in Victoria, including five VORs. The Mangalore VOR was maintained as part of the back-up network, along with VORs at Melbourne, Avalon and Mildura airports. Despite fewer available local VORs since the decommission of navaids, IFR traffic numbers using Mangalore Airport have decreased (see the section titled Aerodrome information).
Figure 9 details the published VOR instrument approach to Mangalore Airport.
Figure 9: Mangalore Runway 23 VOR approach
Source: Airservices, annotated by the ATSB
Pilot Licencing
Licencing of pilots with operational ratings and endorsements, such as the multi-engine aeroplane class rating and the instrument rating, requires the pilot to demonstrate relevant competencies to a flight examiner. These competencies are set by CASA and mandated under Part 61 of the Civil Aviation Safety Regulations (CASR).
The CASR Part 61 Manual of Standards (MOS) details these competencies both for initial testing and recurrent examination. At all stages of pilot licencing, competence in non-technical skills must be demonstrated by pilots under examination, including
- Maintain effective lookout
- Maintain traffic separation using a systemic visual scan technique at a rate determined by traffic density, visibility and terrain;
- Maintain radio listening watch and interpret transmissions to determine traffic location and intentions;
- Recognise and manage threats
Of the Part 61 MOS competencies outlined for the instrument rating, there were two competencies that were relevant to the departure path flown by the pilot of JQF:
- 2.2 (e) conduct instrument departure to comply with obstacle clearance requirements.
- 4 (w) pilot's responsibility in an IFR visual departure.
If either of these competencies were not demonstrated, then it would be marked as a failure item for the test.
In complying with 2.2(e), the AIP ENR 1.5 stated:
4.4 Take-off minima for other IFR aeroplanes
4.4.3 – It is a condition of the use of the minima in Section 4.4 that the pilot in command of the aeroplane must ensure that:
a. terrain clearance is assured until reaching either an en-route LSALT[21] or departure aerodrome MSA[22]
As identified on the VOR chart (Figure 9), the minimum sector altitude within 10 NM of Mangalore Airport was 3,400 ft, and the minimum sector altitude within 25 NM to the south and south‑east of the airport was 3,900 ft. Therefore, the pilot of JQF had to ensure terrain clearance was maintained until the aircraft climbed to 3,400 ft.
In complying with 4(w), AIP ENR 1.1 paragraph 10.6.2 stated:
The pilot of a departing aircraft is required to establish the aircraft on the outbound track as soon as possible after take-off, and in any case, within 5 nm of the departure aerodrome.
JQF departed from runway 23, and was flight planned on a published IFR route southbound via waypoint LACEY. Figure 10 identifies the latest position at which JQF could have intercepted this outbound track and complied with the requirement to be ‘established’.
Figure 10: JQF track flown and planned track to LACEY
Source: Google Earth and Airservices Australia, annotated by the ATSB
Another competency for a multi-engine aircraft class rating is the requirement to demonstrate how to safely manage a simulated engine failure. The ATSB considered the possibility that the examiner of JQF had simulated an engine failure for the pilot under examination take-off from Mangalore. However evidence provided by the operator suggested that this would not have been the standard practice of the examiner and the recorded climb performance was indicative of the aircraft climbing at a normal two‑engine climb rate.
Neither the student in AEM or the pilot under examination in JQF were likely to have been wearing an IFR ‘hood’, used to simulate instrument conditions, at the time of the accident. AEM had been in cloud for most of the descent from 6,000 ft and the hood for JQF was found in a basket behind the pilot seats, having not been used for the flight.
Self-separation by radio
As previously detailed, while operating in non-controlled airspace, even under the IFR, pilots remain responsible for ensuring their own separation from other aircraft. While the occupants of the two aircraft were provided with traffic information, where the possibility for traffic conflict occurs, communication between pilots over the radio remains the primary means for ensuring separation.
Interpreting location information heard over the radio into a useful mental model is a practical skill taught to pilots during initial training, and developed with experience. Once a pilot hears where another aircraft is through a radio call, they must:
process the audio information
identify where that aircraft is in relation to their own aircraft
determine where both aircraft are heading
assess whether there is a potential conflict and, if so, communicate this risk with the other aircraft.
Despite the importance of this skill, there is limited written guidance to pilots on how to communicate and arrange this separation. CASA CAAP 166-2 (2013) is one document that provided the following written guidance to pilots on suggested methods for traffic separation by radio:
Accurate provision and interpretation of traffic information for the purposes of separation to or from another aircraft is an essential pilot skill. Four commonly used ways of providing and interpreting traffic information by radio communication for the purpose of airborne separation are practised at non‑controlled aerodromes. All methods have their advantages depending upon circumstances.
- Separation by ‘clock code’ – Pilots maintain traffic separation by reference to the central axis and numbers of an analogue clock face. Particular care must be given to identifying which aircraft is the central axis of the clock. You are at my 2 o’clock and low has the opposite meaning to I am at your 2 o’clock and low. The weakness of this method of separation is that is requires at least one pilot to have seen, identified and made contact with the other aircraft.
- Separation by ground reference – Pilots maintain separation by radio by either identifying that each is in different places relative to a ground feature(s), or by agreeing to remain on different sides of a readily identifiable ground feature such as a runway extended centreline, road, town or railway line. The advantage of this method of separation is that it does not required either aircraft to have actually seen each other (although this is desirable). The weakness of this method of separation is that ground features could be misidentified. The uncertainty or confusion can distract from the effort of retaining separation through see-and-avoid.
- Separation by altitude reference – Pilots maintain separation by radio by identifying that each is at a different altitude or by one aircraft descending/climbing to another level. Provided that both aircraft altimeters are set to the correct subscale reference (QNH) this method should provide separation for both aircraft regardless of visual contact.
- Separation by navigational or avionic reference – Pilots maintain separation by identifying that each is in a different place relative to a known navigational point or line (radial), or separated by distance from a fixed point (e.g. Global positioning system (GPS) or a radio navigation aid). This method of separation does not require either aircraft to have actually seen each other (although this is desirable). The weakness of this method of separation is that differing avionic equipment or pilot navigational skill can lead to incorrect assumptions being made about the usability of the separation information offered.
Air traffic services
Overview
Airservices is the national air traffic services (ATS) provider for other than military‑related airspace within Australia. A number of different services are provided by Airservices based on the airspace classification (Table 2), broadly described as either an air traffic control service, or a flight information service.
Table 2: Services provided to IFR aircraft in Australian Airspace
Source: CASA
The AIP defines an air traffic control service as:
A service provided for the purpose of:
a. preventing collisions:
(1) between aircraft; and
(2) on the manoeuvring area between aircraft and obstructions; and
b. expediting and maintaining an orderly flow of air traffic.
An air traffic control service is provided in controlled airspace, such as in Class A, C, D and E airspace in Australia. These classes of airspace have a separation standard for aircraft operating in these control areas. In controlled en route[23] airspace with surveillance services, the minimum separation requirements between IFR aircraft are 5 NM lateral separation and 1,000 ft vertical separation.
A flight information service (FIS), such as that provided in Class G airspace, is defined in the AIP as:
A service provided for the purpose of giving advice and information for the safe and efficient conduct of flights.
A flight information service differs from an air traffic control service in that pilots are not provided with positive separation between aircraft, and there are no separation standards for aircraft. Instead, pilots of IFR flights are provided with traffic information, and are required to comply with the rules of the air to maintain their own separation (see the sections titled Rules of the air and Flight information service).
Air traffic control surveillance
Both AEM and JQF were broadcasting ADS-B and SSR and were identified by the controller, therefore the pilots were receiving traffic information through a surveillance service rather than a procedural information service. All aircraft information on the controller’s display is filtered to update once every 5 seconds (see the section titled Recorded data)
The Manual of Standards (MOS) Part 172 (paragraph 10.2.3) required controllers to verify level information being broadcast by aircraft as being within ±200 ft, and that:
ATC must verify displayed pressure altitude-derived level information:
a. On initial contact with the aircraft or, if this is not feasible, as soon as possible after initial contact; and
b. By simultaneous comparison with:
i. Altimeter-derived level information received from the same aircraft by radiotelephony.
On first airborne contact with each aircraft, the controller validated the altitude information provided by the pilots in the radio transmissions against the altitude displayed on the controller’s console. At this check AEM was indicating 100 ft higher than the pilot reported (6,100 ft rather than the reported 6,000 ft), as it was again when the pilot reported the start of descent for airwork at Mangalore. The altitude displayed on the controller display matched the altitude reported by the pilot of JQF. This was within tolerance for both aircraft.
Flight information service
At the time of the accident, AIP GEN 3.3 paragraph 2.16 outlined the traffic information provided in Class G airspace. This information was available to both pilots and controllers. Key information in this section of the AIP included:
2.16.1 In Class G airspace, a traffic information service is provided to IFR flights about other conflicting IFR and observed VFR flights.
2.16.1.1 An IFR flight reporting taxiing or airborne at a non-controlled aerodrome will be advised of conflicting IFR traffic which is not on that CTAF.
2.16.1.2 An IFR flight inbound to a non-controlled aerodrome will be advised of conflicting IFR traffic. The ATS obligation to provide the pilot with traffic information ceases when the pilot reports changing to the CTAF.
2.16.1.3 Traffic information will continue to be provided about an IFR flight following cancellation of its SARWATCH[24], until expiry of the flights ETA. Traffic information may be provided to an IFR pilot who has cancelled SARWATCH where workload and communications permit.
2.16.2 In accordance with the preceding paragraphs, traffic information will be provided to IFR flights when:
a. requested;
b. notifying intention to change level;
c. reporting either taxiing or airborne or departure, whichever is first; or
d. the ATS officer becomes aware of conflicting traffic.
2.16.3 Pilots of IFR aircraft should advise ATS of the callsign(s) of relevant IFR traffic, previously intercepted, to avoid receiving the same traffic information from ATS.
2.16.4 Traffic information will be provided in accordance with the preceding paragraphs whenever there is a possibility of confliction between aircraft in the following situations:
a. aircraft that climb, descent or operate with less than 1,000 ft vertical spacing and less than 15 NM lateral or longitudinal spacing;
b. overtaking or opposite direction aircraft on the same or reciprocal tracks with less than 1,000 ft vertical spacing and less than 10 minutes longitudinal spacing based on pilot estimates;
c. more than one aircraft arriving at, or departing from, the same aerodrome with less than 10 minutes between arrival and/or departure and falling within these guidelines.
2.16.5 When the traffic assessment is based entirely on the use of an ATS surveillance system, traffic information will be provided when, in the opinion of the controller, it is warranted by the proximity of the aircraft to each other.
2.16.7 Traffic information will include relevant factors from the following:
a. the identification of the conflicting aircraft;
b. the aircraft type;
c. the route of the aircraft;
d. the last position report received from the aircraft;
e. intentions of the pilot (if known), and, as required;
f. the aircraft’s initial departure track and intended cruising level;
g. inbound track or direction, level and next estimate; and
h. any other data which may enhance the value of the information.
An ATS surveillance service is defined in the AIP as a:
Term used to indicate an air traffic service provided directly by means of an ATS surveillance system.
An ATS surveillance system is defined in the AIP as:
A generic term meaning variously, ADS-B, primary surveillance radar, secondary surveillance radar or any comparable ground-based system that enables the identification of aircraft.
AEM and JQF were under a surveillance service, once they were identified by the controller following their first airborne radio calls. Therefore, AIP paragraph 2.16.5 was applicable, with the controller providing traffic information when warranted by controller opinion rather than through the requirements of 2.16.4. There was no requirement for the controller to pass updated traffic information to aircraft that had already received traffic information, even when the information passed no longer accurately reflected the current position the aircraft were in.
An air traffic controller overseeing Class G airspace has the responsibility to provide traffic information to IFR aircraft until they report changing to CTAF. This is a historical procedure that was in place when aircraft commonly only had one radio and remains despite many aircraft being fitted with dual radio systems. However, this procedure remains in the latest edition of the AIP, current 2 December 2021 (AIP GEN 3.3, paragraph 3.3.7.2).
Guidance in the Airservices and Department of Defence Manual of Air Traffic Services (MATS) supports the AIP information, and provides controllers with further advice about how to provide traffic position information to pilots:
9.1.6.5 Position information
Provide position information by:
a. Clock reference;
b. Bearing and distance;
c. Related to a geographical point;
d. Reported position and estimate; or
e. Position in the circuit
Airspace
The Melbourne Centre controller was responsible for monitoring a section of airspace known as ‘Alpine’ that spanned an area from the Melbourne control zone to Canberra (Figure 11). This airspace included Class C and E controlled airspace, as well as Class G non-controlled airspace.
Where workload required, the ‘Alpine’ airspace can be sub‑divided into three sectors – Hume (HUM), Ovens (OVN) and Dookie (DOK). At the time of the accident, the controller was operating the three sectors combined.
Figure 11: Alpine airspace, including Dookie, Ovens and Hume sectors and key aerodromes
Source: Airservices, annotated by the ATSB.
Controller display
Air traffic controllers have multiple screens on their console, displaying information such as a map view of the aircraft in their sector; flight plans of active and future aircraft; weather and NOTAM[25] information. Co-ordination of aircraft passing into their sector may occur either through verbal communication with another controller or through data messages sent between controllers.
The position of AEM and JQF as they operated under a surveillance service were identified through a combination of secondary surveillance radar (SSR) and ADS-B. Airservices advised that, when SSR information was available, this was the primary source of traffic information displayed to the controller. Additionally, data presented to the controller was only updated every 5 seconds (see the section titled Recorded data).
The controller had the ability to zoom into sections of the airspace on the display. This gave the controller the ability to further inspect information available about each aircraft, including callsign, altitude and flight plan information. The controller used this function to inspect alerts that were generated (see the section titled Short term conflict alert).
Following the accident, Airservices recreated the controller’s display for the period that AEM and JQF were operating in Class G airspace. While this did not replicate where the controller had the information labels[26] placed for each aircraft, it did display the same information as the controller would have seen.
The controller operated with the default display setting, with 2 minute velocity vectors projected ahead of each aircraft in their sector. The vectors were based on the current track of the aircraft, and not on any information included in the flight plan. Therefore, following the departure call from the pilot under examination in JQF, when traffic information about AEM was passed to the occupants of JQF (see the section titled Communication, Melbourne Centre), the vectors indicated that JQF would pass behind AEM (Figure 13). However, this projected information did not consider the flight planned track and the intent of the pilot in JQF to turn and intercept the Mangalore to LACEY track within 5 NM of Mangalore Airport (see the sections titled Flight plans and Pilot Licencing). Unlike the velocity vectors that projected where in space an aircraft would be if they continued on the same track and with the same groundspeed, there was no numerical predictive information provided to the controller relating to the projected altitude of a climbing or descending aircraft in that 2 minute timeframe. If needed, this information had to be determined by the controller through processing a combination of climb or descent arrows, known aircraft performance, flight plan information or speed information.
Short term conflict alert
A short term conflict alert (STCA) is an aural and visual alert received on a controller’s console when two aircraft come within a defined proximity of each other. In describing the intent of the STCA, the International Civil Aviation Organization (ICAO, 2016) noted:
The objective of the STCA function is to assist the controller in preventing collision between aircraft by generating, in a timely manner, an alert of a potential or actual infringement of separation minima.
In the Australian ATC system STCAs occur in both controlled and non-controlled airspace, with alerts inhibited in some areas. Specifically, Airservices advised that STCAs in Class G airspace are inhibited below 4,500 ft in the Brisbane flight information region[27], but occur to the ground in areas of the Melbourne flight information region.
When two aircraft are assessed by the system as likely to pass within prescribed vertical and lateral parameters in a particular time window, the controller will receive a pop-up window on their display with aircraft details. The parameters for an alert on aircraft in Class G airspace are the same as the parameters for aircraft in an en-route controlled environment. Aircraft operating below FL285, under a surveillance service will generate a STCA if they are projected to pass within 4.8 NM and 600 ft in the next 60-90 seconds.
The STCA only alerts for aircraft operating under a surveillance service. Both AEM and JQF were included in this, as they were both operating under a flight plan, broadcasting ADS-B and SSR data, and had both been positively identified by the controller. Some aircraft, such as 2 VFR aircraft in non‑controlled airspace operating without a submitted flight plan, will not generate a STCA even if a conflict situation develops.
The procedures documented for the response to a STCA did not differentiate between controlled airspace, where a STCA indicates an infringement of separation minima, and non-controlled airspace where there is no published separation minima.
In terms of prioritisation of alerts, the National ATS procedures manual (NAPM) identified the STCA as one of the highest priority alerts, indicating a system detected safety net critical event, requiring immediate attention.
The response procedure for a controller receiving a STCA was:
14.1.3.1 Alert integrity
On receipt of a STCA:
1. Assess its integrity; and
2. Issue a ‘Safety Alert’ or ‘Avoiding Action’ advice when appropriate.
The process for ‘assessing integrity’ of a STCA was undefined. Airservices advised the ATSB that it was an assessment based on controller judgement and experience, and there was no documented checklist or criteria that controllers used to complete this assessment. A STCA may be assessed as not having integrity if the procedure of passing mutual traffic information to two aircraft had been completed, and the aircraft were expected to be self-separating on the CTAF.
It was reported by the controller that it was not unusual to receive a STCA in the airspace being controlled after traffic information was passed. This statement was supported by the Airservices accident investigation report, which noted that other controllers operating the same Alpine sector received a high number of nuisance[28] STCAs. These STCAs activated between aircraft in the circuit or between aircraft on diverging tracks or who had already passed each other. It was reported that IFR aircraft in the vicinity of non-controlled aerodromes often pass within the STCA parameters when self‑separating and did not normally need further intervention after traffic information was passed.
After a controller assessed the integrity of a STCA, and determined that escalation was required, the information for controllers in the MATS regarding safety alerts stated:
9.1.4.1 Vigilance
Remain vigilant for the development of safety alert or traffic avoidance advice situations
9.1.4.2 Responsibility
Do not assume that because another controller has responsibility for an aircraft that an unsafe situation has been observed and a safety alert or traffic avoidance advice has been issued.
9.1.4.3 Issuing a safety alert
Unless the pilot has advised that action is being taken to resolve the situation or that the other aircraft is in sight, issue a safety alert prefixed by the phrase ‘SAFETY ALERT’ when you become aware that an aircraft is in a situation that places it in unsafe proximity to:
a. Terrain;
b. Obstruction;
c. Active restricted or prohibited areas; or
d. Other aircraft
9.1.4.3.1 Airspace classes – safety alerts
You may issue safety alerts, including those based on visual observation, in all classes of airspace both within and outside ATS surveillance system coverage.
Advice to pilots in AIP GEN 3.3 current at the time of the accident stated:
5.1 ATC will issue a Safety Alert to aircraft, in all classes of airspace, when they become aware that an aircraft is in a situation that is considered to place it in unsafe proximity to:
a. terrain;
b. obstruction;
c. active restricted or prohibited areas; or
d. other aircraft.
5.1.1 When providing an ATS surveillance service, ATC will issue advice to pilots regarding avoiding action as a priority, when they become aware than an aircraft is in a situation that is considered to place it at risk of collision with another aircraft.
5.1.2 ATC will prefix advice to turn or change level with “suggest” unless the alerts are for controlled flights with reference to other controlled flights.
5.1.3 ATC may discontinue issuing Safety Alerts or advice regarding avoiding action when the pilot has advised action is being taken to resolve the situation or has reported the other aircraft in sight.
The AIP guidance for safety alerts stated that pilots would receive a safety alert whenever two aircraft were deemed by a controller to come within an unsafe proximity of each other, whether in controller or non-controlled airspace. When the combination of the MATS and NAPM guidance was followed after receipt of a STCA, a safety alert may not be issued if the controller deemed other risk controls were in place such that the proximity was safe. However, the guidance did not preclude a safety alert being issued when a controller deemed it necessary after a STCA, or at any other time.
There was no definition for what ‘unsafe proximity’ between aircraft was when operating in non‑controlled airspace under pilot separation as there was no separation standard in non‑controlled airspace. Further, when pilots were in the vicinity of a CTAF and had been provided traffic information, there was an expectation from controllers that the pilots were in radio contact with each other and self-separating.
The information in MATS regarding traffic avoidance advice was:
9.1.4.4 Traffic avoidance advice
Issue traffic avoidance advice, prefixed by the phrase ‘AVOIDING ACTION’, to an aircraft that:
a. Is receiving an ATS surveillance service; and
b. In your judgement, is in a situation that places it at risk of a collision with another aircraft under surveillance.
In the time between JQF taking off and the collision, there were three STCA alerts generated (Figure 12).
Figure 12: STCA activation and vertical profiles of AEM and JQF
Source: Airservices
Notes:
Callsigns of other aircraft redacted. Controller was actively communicating with either pilots or other controllers at these times.
ASD is an abbreviation for ‘Air Situation Display’, meaning the controller display.
Times on the graph are displayed in UTC (local time – 11 hours at the time of the accident).
Data is displayed in graph in 3 second intervals and is not representative of the 5 second intervals that the controller display was updated with.
On the basis of analysis conducted by an ATC subject matter expert and technical detail provided by Airservices, it was assessed that:
The first STCA, at 1122:42, was a nuisance alert generated by JQF conflicting with VFR traffic in the Mangalore circuit area.
A second STCA, at 1122:49, occurred as the controller passed traffic information to JQF (Figure 13). At that stage, indications were that the aircraft would pass abeam each other. The STCA was assessed by the controller but not cleared from the screen at this point.
The controller re-inspected the two aircraft at 1123:30 after JQF had turned towards the planned outbound track. The velocity vectors indicated that lateral displacement would be maintained, with JQF passing behind AEM in about one minute. At that time, the controller’s display showed AEM at 4,800 ft while JQF was at 3,400ft.
A final STCA alert occurred at 1123:51. The controller zoomed in to inspect the aircraft flight paths and altitudes again and acknowledged the STCA at 1124:09. The controller identified that JQF was going to pass across the track of AEM, but at that time, 11 seconds prior to the collision, indications on the controller’s display showed AEM at 4,500 ft and JQF at 4,000 ft, with 0.9 NM lateral separation between the aircraft.
Figure 13: Recreation of STCA display at 1122:49
Source: Airservices data, annotated by the ATSB
Note: Not to scale or necessarily representative of how the controller had the labels configured.
When each of the STCAs displayed, the controller assessed the integrity of the alert in accordance with the NAPM procedure. The controller reported checking the path of each aircraft using the set velocity vectors, the vertical separation of the aircraft, and confirming that traffic information about each aircraft had been passed to the other aircraft. Having assessed that the aircraft would pass each other and:
the STCA was designed as an alert for a breakdown in separation standards
there was no set separation standard in non-controlled airspace
the pilots were responsible for their own separation
they decided that a safety alert or traffic avoidance advice was not required, and cleared the aural alert.
Radio communication
Common traffic advisory frequency
Table 3 shows the guidance provided by CASA (2019) to pilots on the recommended CTAF broadcasts in the vicinity of a non‑controlled aerodrome.
Table 3: Recommended positional broadcasts in the vicinity of a non-controlled aerodrome
In addition to this guidance, the En-Route Supplement Australia (ERSA)[30] identified a local procedure for pilots to make a report about intentions when conducting practice instrument approaches at Mangalore (see the section titled Practice instrument approaches). The ERSA also noted the following minimum number of radio calls for aircraft operating at Mangalore:
Taxiing, entering (a runway), departing: Inbound, Joining, Base and Final with position, altitude and intentions.
Note: Pilots must respond to radio requests from other traffic for their intentions, position or altitude.
Based on evidence provided by other students trained by the instructor, due to the higher performance of the Travel Air, the instructor encouraged students to make their inbound CTAF call around 15 NM from the airport. The operator of JQF advised that they had a similar procedure to make CTAF broadcasts around 15 NM from Mangalore Airport.
Radio transmissions on the Mangalore Airport common traffic advisory frequency (CTAF) were not recorded, nor were they required to be. Several witnesses stated the CTAF was often congested, but due to the weather at the time of the accident, there was limited flight training and so the CTAF was not as busy.
The ATSB interviewed the pilots operating in the Mangalore area at the time of the accident regarding calls made from the pilots of AEM and JQF. None recalled the pilots of AEM and JQF talking to each other to arrange separation. Various pilots recalled a pilot in JQF making a rolling call, and a departure from the circuit call, and one pilot remembered details of an inbound call made by a pilot of AEM, including mention of an altitude of 3,900 ft.
The CTAF frequency at Mangalore was not equipped with an aerodrome frequency response unit (AFRU)[31]. There was no evidence to suggest either aircraft had selected the incorrect radio frequency or that an AFRU would have changed the sequence of events. The radios installed in AEM were too damaged to be analysed, but notes found in the aircraft, and details provided by another pilot about an inbound call from AEM, indicated it was likely that AEM broadcast on the correct CTAF frequency.
The two radios from JQF were recovered and analysed by the ATSB. One was set to the Melbourne Centre frequency and the other to the Mangalore CTAF. The audio panel configuration was found in a position consistent with the pilots of JQF either broadcasting or intending to broadcast on the CTAF.
Melbourne Centre
The required radio reports for IFR pilots operating in Class G airspace are listed in the AIP (Table 4). Transmissions between each aircraft and the controller were made on the ATS Melbourne Centre 122.4 MHz frequency and were recorded.
Table 4: Required reports for IFR pilots operating in Class G airspace
Source: AIP
Table 5 outlines the communications that occurred between each of the aircraft and the controller providing traffic information (see the section titled The occurrence). A review of the radio recordings confirmed that the pilot of JQF made taxi and departure calls to Melbourne Centre. The student in AEM also made the appropriate calls when changing to the Melbourne Centre frequency and before changing level, when they started the descent from 6,000 ft into Mangalore.
Table 5: Key traffic information on Melbourne Centre frequency
Time start
(* indicates approximate time)
Time end
(* indicates approximate time)
Aircraft
Comment
1111:21
1111:32
JQF
Taxi call
1117:42
1117:55
AEM
Initial contact with controller on entry to airspace. Area QNH provided and advice of no reported IFR traffic.
1119:35
1119:54
AEM
Controller contacted with information about commencing descent from 6,000 ft and establishing a SAR time for airwork in the Mangalore area. Advice of no reported IFR traffic provided by the controller.
1120:07
11:20:08
AEM
Controller called the pilots of AEM to pass traffic. No response received.
1120:15
1120:28
AEM
Controller again called the pilots of AEM. Pilot responded and traffic information about JQF shortly to depart Mangalore was passed and acknowledged.
11:22:19
1123:00
JQF
Departure report to controller. Information was provided that the aircraft was passing 2,700 ft on climb to 7,000 ft and tracking to LACEY. Controller advised the pilots that AEM was inbound to Mangalore in JQF’s 12 o’clock position, for airwork, passing 5,000 ft on descent to not above 4,000 ft.
During this conversation a STCA for proximity between AEM and JQF activated and was acknowledged by the controller.
1123:51
1124:09
STCA for AEM and JQF. Controller zoomed in on screen and acknowledged the STCA at 1124:09.
1124:20
Approximate time of collision
Source: Airservices, annotated by the ATSB
A review conducted by Airservices following the accident concluded that both aircraft were provided with, and acknowledged receipt of, mutual traffic that contained all relevant information. They also assessed that pilot communications with the controller were generally consistent with the AIP phraseology and the required content was included in the transmissions. A subject matter expert was independently asked by the ATSB to review the recordings and confirmed that the controller provided traffic in accordance with the procedures in the AIP and MATS.
Figure 14 details analysis conducted by the ATSB of ADS-B data and Melbourne Centre recordings provided by Airservices.
Figure 14: Approximate timeline of transmissions and key actions from 1117 to the collision
Source: ATSB, based on data provided by Airservices
Note: Radio transmissions on the Melbourne Centre frequency were recorded so correspond to exact times (see Table 5). The ATSB calculated data is based on ADS-B data. Due to a lack of available information, the following assumptions were made:
The start of the JQF take off, at 1120:00 corresponds to the first recorded ADS-B point, which occurred when the aircraft was approximately one third down the runway and around 50ft above the runway. It is likely that the pilot’s rolling call, and the start of the take-off roll occurred some seconds before this time. The time from application of power to attaining a height of 50ft has been estimated to be 20-25 seconds.
The pilots of AEM had a number of opportunities to listen to the Automated Weather Information Service (AWIS)[1] – before and after the descent call to the Melbourne Centre controller at 1119:35. As the aircraft was fitted with two radios, the pilots would likely have selected the AWIS frequency instead of the CTAF for the period of time required. This means they were unable to monitor the CTAF for this time period. A previous student of the instructor described setting up the AWIS frequency in the cruise so that it could be listened to as soon as it came into range, and before top of descent.
When the pilot under examination in JQF made a taxi report at 1111, AEM was not yet in the controller’s airspace. Therefore, at that point AEM was not assessed as conflicting traffic and so no information was provided to the pilots of JQF. Additionally, the expected arrival time of AEM at Mangalore was outside the 10-minute window to be considered arriving ‘traffic’ for JQF in accordance with the guidance provided in AIP GEN 3.3 paragraph 2.16.4c for non-surveillance traffic. The controller indicated awareness of this in interview with the ATSB.
AEM was not given traffic information about JQF when they first called the Melbourne Centre controller at 1117, or initially at 1119 when calling to notify their descent. While JQF had made the taxi call to Melbourne Centre by that time, JQF had not appeared on the controller’s screen as a prompt at that point.
However, the controller did identify JQF as potential traffic for AEM by 1120:07 and called the pilot of AEM. The pilot did not initially respond to this call, however, they did respond to a second call from the controller a short time later at 1120:15. It could not be determined why the pilot did not respond to the initial call, but consideration was given to whether the pilots were listening to the automated weather information services (AWIS) (see the section titled Meteorological information) or making an inbound call on the CTAF as at this point they were about 18 NM from Mangalore. The information given to the pilots of AEM was that JQF was shortly to depart Mangalore southbound via LACEY on climb to 7,000 ft.
Analysis of high-resolution ADS-B information identified that JQF’s take‑off coincided with the pilots of AEM’s call to Melbourne Centre to inform of their descent into Mangalore for airwork. This timing suggests that the pilots of JQF were unlikely to have been actively monitoring transmissions on the Melbourne Centre frequency at this time, including advice of AEM’s descent, due to their focus on the take-off.
AEM reached 15 NM from Mangalore at around 1120:30, just as they finished receiving traffic information from the Melbourne Centre controller. This is the position that previous students of the instructor identified that the instructor encouraged students to make their inbound call. The aircraft reached 10 NM around 1122:30 (Figure 14), which is the latest point the student should have made an inbound call-in accordance with expected CTAF procedures. It is therefore likely that an inbound CTAF broadcast was made during this 2-minute time period. Significantly, that time interval coincided with the time that JQF was in the initial climb, and making a departure call to Melbourne Centre. Therefore, it is possible that the pilots of JQF did not hear this inbound call, nor the pilots of AEM hear the CTAF circuit departure call or the Melbourne Centre departure call from JQF.
AIP GEN 3.4 paragraph 6.16.8 contained information about the standard phraseology expected from pilots making reports after take‑off in particular operating environments. The standard phraseology for a departure report made from a non-controlled aerodrome in a non‑surveillance environment was:
DEPARTED (location)(time in minutes) TRACKING [TO INTERCEPT] (track) CLIMBING TO (intended level) ESTIMATING (first reporting point) AT (time)
The standard departure report phraseology from non-controlled aerodromes under surveillance when notifying departure and identification was expected with the departure report was:
(location reference departure aerodrome) PASSING (current level) CLIMBING TO (intended level) ESTIMATING (first reporting point) AT (time)
AIP ENR 1.1 paragraph 10.6.4 also includes the information
If the pilot transmits the departure report before intercepting the departure track the report must include advice that the aircraft is manoeuvring to intercept departure track.
Radio communication between the Melbourne Centre controller and the pilot under examination in JQF after take‑off was as follows:
1122:19
JQF to ML Centre
Melbourne Centre, juliet quebec foxtrot departure
1122:22
ML Centre to JQF
juliet quebec foxtrot’s identified, verify level with departure
1122:27
JQF to ML Centre
juliet quebec foxtrot departure at Mangalore two three passing two thousand seven hundred on climb to seven thousand tracking to LACEY, Mangalore.
1122:37
ML Centre to JQF
juliet quebec foxtrot area QNH one zero one zero
(Note this call was interrupted internally by another Melbourne controller)
1122:41
JQF to ML Centre
One zero one zero, juliet quebec foxtrot
1122:44
ML Centre to JQF
And juliet quebec foxtrot, traffic six [nautical] miles in your 12 o’clock is alpha echo mike a king air, they’re inbound to Mangalore for airwork, passing five thousand on descent to not above four thousand.
While the controller positively identified JQF, the statement made was by the pilots of JQF that they were tracking to LACEY, without the specific information that they were tracking to intercept the IFR airway from Mangalore to LACEY (Figure 10). Additionally, it did not include detail of the position of JQF with reference to Mangalore, which at the time of the departure report was about 2.2 NM south-south‑west of the airport. While it could not be determined whether the pilots of AEM heard this departure report, the information had the potential to provide them with an incorrect mental model of the aircraft’s relative position. The Airservices investigation report identified that at this time the two aircraft had 8.6 NM lateral separation, and 2,600 ft vertical separation.
There was also a discrepancy with the traffic information, in referencing AEM as a King Air rather than a Travel Air. However, that was unlikely to have had a significant impact on the understanding of the presence of traffic, or its performance, as the groundspeed of AEM was similar to the approach speed of the type of King Air that frequented Mangalore Airport.
Based on the information presented by the velocity vectors, when giving this traffic information the controller judged that JQF would pass behind AEM.
While it would not be expected, as traffic self-separation broadcasts would generally be made on the CTAF, a review of the recording confirmed that neither aircraft attempted to contact the other using the Melbourne Centre frequency.
A review of the air traffic control recordings and transcripts indicated that between 1123:12 and 1124:08, the controller was actively engaged with other aircraft, or co-ordinating aircraft with another controller. It was during this time that the final STCA for the two aircraft occurred.
Automatic Dependent Surveillance Broadcast
Overview
ICAO (2018) defined Automatic Dependent Surveillance Broadcast (ADS-B) as:
A means by which aircraft, aerodrome vehicles and other objects can automatically transmit and/or receive data such as identification, position and additional data, as appropriate, in a broadcast mode via a data link.
ADS-B uses the GNSS for positioning. ADS-B data can be both broadcast (ADS-B OUT) and received (ADS-B IN).
Under Civil Aviation Orders 20.18, both AEM and JQF were required to be fitted with ADS-B OUT equipment to operate under the IFR. Both aircraft were fitted with transponders that complied with this requirement.
To provide an ADS-B based surveillance service, Airservices has a range of ground-based ADS-B receivers. The resulting ADS-B coverage at an altitude of 5,000 ft across Australia is shown in Figure 15. Mangalore Airport was within the coverage area at this altitude. ADS-B coverage improves as altitude increases, and at 30,000 ft almost all flights within Australia can be conducted under an ADS-B surveillance service.
Figure 15: ADS-B coverage at 5,000 ft across Australia
Source: Google Earth and Airservices, annotated by the ATSB.
Cockpit traffic display
Neither aircraft was fitted with a system to receive ADS-B information directly from other aircraft, nor were they required to be. As such, all the positional guidance the pilots had about other traffic was received from the controller and via any received radio broadcasts.
It is possible to receive ADS-B information from other aircraft directly into an aircraft. Aircraft that are fitted with such a receiver (ADS-B IN) can be configured with a cockpit display of traffic information (CDTI) to identify where other aircraft are relative to their position.
CDTI may give an image of the traffic over a moving map or directional guidance about the location of other aircraft. Some of these systems are also able to provide audible and visual alerts to pilots about identified traffic risks.
The CASA CNS/ATM guide (2017) identified some limitations with cockpit displays:
CDTIs will help you spot other ADS-B traffic more easily by showing you where to look. However:
- Depending on the unit’s filtering capability, your CDTI might not show all ADS-B traffic
- CDTIs will not display non-ADS-B traffic
- Don’t try to second-guess ATC instructions with CDTI information
- Do not attempt to take evasive action, or to separate your aircraft from other traffic, using a CDTI. It is there to enhance situational awareness, not to replace separation procedures.
Cockpit display of traffic information does not replace see-and-avoid. You still have to look out the window for other traffic.
Electronic flight bag
The student pilot in AEM was using ‘AvPlan’ electronic flight bag (EFB)[33] software installed on an iPad. In addition to the EFB, this pilot was also carrying a paper flight plan and set of relevant approach charts.
AvPlan has an option to display traffic information overlayed on the map display.
Traffic information can be obtained either by:
having an external ADS-B receiver attached
using the ‘AvPlan live’ feature.
Use of the AvPlan live traffic information system required the live tracking feature to be turned on, a data connection and a connection to a GPS position. The iPad in AEM was fitted with a SIM card capable of providing the required data connection to AvPlan live, but was not fitted with an external ADS-B receiver. The AvPlan user manual identified that traffic displayed using the AvPlan live function was from:
…other connected airborne AvPlan EFB users, a network of ADS-B ground receivers, and FLARM[34] ground receivers.
Data displayed using AvPlan live was updated every 5 seconds, rather than every second when an ADS-B receiver was attached. The software had no capability to identify aircraft using other EFB software, or non-ADS-B equipped aircraft. The AvPlan user manual noted:
Note that this traffic is a great start for situational awareness, however it does not include all traffic. Always be on the lookout/maintaining a listening watch for traffic.
Due to the damage to the tablet sustained in the impact, it was not possible to recover data from the iPad to determine whether the traffic information overlay display was selected at the time of the collision.
The ADS-B ground receiver network used by AvPlan for traffic information was not the same as the network used by Airservices for receiving ADS-B data, and there was limited coverage for the AvPlan network in the Mangalore area. Information provided by AvPlan after the accident identified that aircraft in the approximate location of the collision, 5 NM south of Mangalore airport, were not visible as traffic on AvPlan below approximately 4,900 ft. Therefore, as the pilots in JQF were not carrying an AvPlan‑connected iPad and it was unlikely that the AvPlan ADS-B ground network received broadcasts from JQF it is probable that JQF would not have appeared as traffic on the iPad used in AEM, even if the traffic information overlay had been selected.
The use of an external ADS-B receiver significantly increases the frequency of updated traffic information and receives ADS-B broadcasts directly from ADS-B OUT equipped aircraft within range of the receiver. Information from the AvPlan user manual stated:
When AvPlan EFB is connected to an ADS-B receiver, traffic as far as the receiver can observe will be displayed. Traffic sources from the receiver will be coloured green to allow quick identification of a traffic target’s source. No height or distance limitations are placed on traffic delivered by an attached device. Traffic received via this method is updated once every second”.
At the time of the accident, neither AvPlan nor OzRunways, another Australian EFB provider, provided audible alerts about proximal traffic, although at the time of writing AvPlan offered this feature.
Collision avoidance systems
ADS-B also has the ability to feed into an aircraft collision avoidance system (ACAS). Neither aircraft were required to have ACAS fitted.
In describing ACAS, the ICAO (2021) stated:
The objective of airborne collision avoidance systems (ACAS) is to provide advice to pilots for the purpose of avoiding potential collisions….
ACAS has been designed to provide a back-up collision avoidance service for the existing conventional air traffic control (ATC) system while minimizing unwanted alarms in encounters for which the collision risk does not warrant escape manoeuvres. The operation of ACAS is not dependent upon any ground-based system.
By providing pilots with visual information about where other aircraft are operating in their proximity, pilots are able to make more timely decisions based on displayed information and take avoiding action, thereby reducing the risk of collision.
At present in Australia, there are no regulatory requirements for aircraft of the size and operational category involved in this accident to have any form of ACAS fitted to the aircraft.
In 1991 the Bureau of Air Safety Investigation (the predecessor to ATSB) issued the Civil Aviation Authority (the predecessor to CASA) with a recommendation that:
In light of the serious limitations of the see-and-avoid concept, the CAA should closely monitor the implementation of TCAS[35] in the US and should consider the system for Australia.
In 1998, CASA accepted this recommendation and stated the system would be introduced when cost effective.
Under the current regulations in Australia, an approved ACAS must be fitted any turbine-engine aeroplanes operating under Part 121 (Australian Air Transport Operations – Larger Aeroplanes) that:
Paragraph 11.21
a. Either:
i. has a maximum take-off weight of more than 15,000kg; or
ii. has a maximum certificated passenger seating capacity of more than 30; or
b. Is first registered, in Australia or elsewhere, on or after 1 January 2014, and:
i. has a maximum take-off weight of more than 5,700 kg but not more than 15,000kg; or
ii. has a maximum certificated passenger seating capacity of more than 19 but not more than 30.
Aircraft operating under Part 135 (Australian Air Transport Operations – Smaller Aeroplanes) must be fitted with an approved ACAS if they are turbine-engined, have a maximum take-off weight of more than 5,700kg and was first issued with a certificate of airworthiness on, or after, 1 January 2014. There are no regulations requiring fitment of an ACAS to aircraft equivalent to AEM and JQF.
Meteorological information
Forecast weather
The Bureau of Meteorology (BoM) produced a terminal area forecast (TAF)[36] for Mangalore Airport and the surrounding area, and a graphical area forecast (GAF)[37] for Victoria. The forecast conditions at the time of the accident included scattered cloud at 2,500 ft AMSL[38] and between 3,500 ft and 6,000 ft AMSL. Visibility was forecast to be greater than 10 km, and the wind from the south‑west (230°) at 15 knots at ground level, with gusts up to 25 knots. The grid-point wind and temperature forecast listed the wind at 5,000 ft as from 210° at 32 kt.
Actual weather
The Aerodrome weather report (METAR/SPECI) issued at 1130, 6 minutes after the collision, identified the presence of three cloud layers - broken layers at 3,000 ft and 3,700 ft AMSL[38] and an overcast layer at 4,500 ft.
At the time of the accident, the automatic weather service (AWS) at Mangalore Airport recorded two cloud layers: one scattered at about 3,500 ft AMSL[38] and a second broken layer at 4,200 ft (about the collision altitude).
Three photographic sources were also reviewed to assess the likely cloud conditions at the time of the accident. Figure 16 identifies the locations where these images were recorded.
Figure 16: Location of photographic sources used in the cloud assessment
Source: Google Earth, annotated by the ATSB
Figure 17 shows an image recorded by a BoM weather camera at Kilmore Gap (elevation 1,731 ft), looking north towards Mangalore Airport at the time of the collision.
Figure 17: Weather camera image from Kilmore Gap facing towards Mangalore Airport
Source: BoM
A similar image was recorded at Wahring Field (elevation 410 ft) looking in a south-east direction at 1120 (Figure 18)
Figure 18: Weather camera at Wahring Field
Source: BoM
Video imagery recorded by the Victoria Police Air Wing (Figure 19) near the accident site at 1240, 1 hour and 16 minutes after the accident showed a broken layer of cloud at approximately 4,050 ft AMSL with some lower patches of cloud also present. This is just below the approximate height of the collision (4,100 ft)
Figure 19: View of cloud from the Victoria Police Air Wing helicopter
Source: Victoria Police
The observed cloud conditions were marginally poorer than forecast, but still suitable for the flights. The observations show scattered, broken and overcast cloud layers with bases below, at, and above the collision altitude.
Information from the automatic weather service was available to pilots on an aerodrome weather information service (AWIS) radio frequency. It is likely that the pilots of AEM checked this information before making their inbound CTAF call.
Recognising that both the aircraft were operating under the IFR, AIP ENR 1.2 defined the criteria required for pilots to maintain visual meteorological conditions (VMC) (Table 6).
Table 6: Criteria to maintain VMC in Class G airspace
At the time of the collision a scattered cloud layer was observed at Mangalore Airport at 3,500 ft and a broken layer at 4,200 ft, encompassing the collision altitude. However, just 6 minutes after the accident the lower cloud layer was observed to be broken. The later Police video showed that the broken cloud base was about 4,000 ft with some lower patches. The observations recorded over the time between the accident and the Police helicopter arriving indicated the weather remained similar, with only a slight increase in cloud base of about 100 ft.
Therefore, at the time of the collision, the aircraft were probably near a layer of scattered to broken cloud, and just below a further broken to overcast cloud layer. Consequently, as AEM descended it is probable that the aircraft was surrounded by cloud until passing through about 4,500 ft. While the aircraft may not have been in cloud at the time of the collision, the extensive surrounding cloud would have reduced conditions to significantly below VMC, reducing the opportunity for visual acquisition by any of the pilots.
Aerodrome information
Overview
Mangalore Airport has an elevation of 467 ft. The airport has four paved runways – 05/23 and 18/36[39]. At the time of the accident, runway 23 was in use. The airport is used for a variety of general aviation purposes, including a high volume of ab-initio pilot training. There are no scheduled regular public transport operations to the airport.
There was no specific data collected by the airport about the number of aircraft using Mangalore Airport however, the CASA Office of Airspace Regulation (OAR) provided the ATSB with the traffic information used for monitoring risk at Mangalore airport, which was provided to them by Airservices. This traffic information is summarised in Table 7 (see the section titled Airspace oversight).
Table 7: Mangalore Airport movement data
Source: CASA
Local flight procedures
The ERSA current at the time of the accident included a number of notes that identified several local flight procedures for the airport. Three of these were applicable to the operations of AEM and JQF. The procedure requiring additional radio calls above the standard requirements at non-controlled aerodromes has been previously discussed (see the section titled Common traffic advisory frequency)
Practice instrument approaches
Note 2 stated:
Except as required during instrument rating tests, pilots making practice instrument approaches should add 1,000 ft to the altitude prescribed in the approach to reduce interference with Mangalore AD circuit traffic. Such flights must broadcast their intentions, including altitude limits of OPS. Similarly, pilots making instrument approaches in IMC on encountering VMC are required to remain as high as practicable and join the circuit in the standard manner.
Records from CASA indicated that this local procedure first appeared in the Mangalore ERSA in July 1997. The airport manager provided information to the ATSB that this procedure was requested by a flying school to assist with the separation of instrument approach traffic from circuit traffic. Airservices and CASA were unable to provide any further background about this procedure.
This procedure is not unique to Mangalore Airport, the ERSA also described similar local procedures at Ballarat, Busselton, and Latrobe Valley airports. In a review of Ballarat Airspace published in August 2017, OAR received stakeholder feedback that IFR training aircraft were incorrectly approaching Ballarat without the required additional 1,000 ft of height stated in the ERSA. In response, OAR made a recommendation that:
CASA should provide specific information to IFR pilots that frequent Ballarat about the additional 1,000 ft procedure.
Interviews conducted by the ATSB established that the two operators involved in this accident interpreted and applied this ERSA local procedure differently. Specifically:
Previous students of the instructor in AEM applied 1,000 ft to the minimum decision altitude only, flying the approach as published and discontinuing early.
The operator of JQF stated that they required pilots to add 1,000 ft to all heights identified on the chart. However, they stated that while they were aware that the two largest flying schools using Mangalore Airport applied it this way, there were other operators that applied the procedure the same way as the operator of AEM.
When the ATSB requested clarification about the intention of the wording of the procedure, CASA advised that:
This procedure is to be applied by adding the 1,000 ft to all waypoints and the MDA.
Landing lights
Note 3 stated:
It is recommended that all ACFT shall illuminated LDG and taxi lights WI a 10 NM radius of the airport and when established in the circuit.
Due to the extent of damage, investigators were unable to determine whether AEM had landing lights switched on. Examination of JQF identified the landing lights were switched on at the time of impact however, it is also noted that landing lights have a relatively narrow beam and therefore are only visible from the frontal aspect of an aircraft.
Recorded data
Neither aircraft was equipped with a flight data recorder or a cockpit voice recorder, nor were they required to be, due to their size and type of operation. In January 2021, the ATSB issued a safety recommendation to CASA (Safety issue number AO-2017-118-SI-03) recommending the consideration of mandating the fitting of onboard recording devices for passenger-carrying aircraft with a maximum take-off weight less than 5,700 kg. A second recommendation (Safety issue number AO-2017-118-SI-04) was also made to the International Civil Aviation Organization (ICAO):
The Australian Transport Safety Bureau recognises that the International Civil Aviation Organization has developed technical standards for lightweight recorders and airborne image recorders. However, despite the known benefits for the identification of safety issues, the fitment of such devices for passenger-carrying aircraft with a maximum take-off weight less than 5,700 kg is not mandated. The Australian Transport Safety Bureau recommends that the International Civil Aviation Organization takes safety action to consider the safety enhancement of these devices to passenger-carrying operations.
Airservices provided the ATSB with two sources of data relating to the accident flight:
Filtered ADS-B and radar data showing the aircraft as they appeared on the controller’s display. This data was filtered to approximately 5 second intervals.
Raw ADS-B data captured from the ADS-B receivers. This information captured the ADS-B out data from each aircraft at intervals of less than 1 second. This data was not available to the controller at the time, but has been used for the aircraft performance and visibility study (see the section titled Aircraft performance and cockpit visibility study)
Flight data received from the EFB used by the student in AEM was also provided by AvPlan. This ADS-B data matched the data provided by Airservices.
No data was recoverable from any of the instruments on board either aircraft.
Flight path data
The raw ADS-B data was analysed to determine how the two aircraft came together. The data indicated that approximately 0.55 seconds before the collision AEM was on a true heading of 352° and JQF on a true heading of 132°, giving a relative heading angle of 140° (Figure 20). At this time JQF and AEM were estimated to be at the same level, 4,125ft, with JQF maintaining altitude and AEM descending on approach to Mangalore (Figure 21, Figure 22). The groundspeeds of JQF and AEM, considering all available wind information and limitations in the ADS-B data, were around 94 kt and 192 kt respectively with a closing speed just prior to the collision of approximately 245 kt.
The data for AEM showed very little variation in track and the data for JQF showed a slow turn towards the flight planned track to LACEY. Based on the lack of rapid or pronounced change in the aircrafts’ flight paths it is unlikely that an evasive manoeuvre was initiated by the pilots in either aircraft. Figure 22 shows the total separation, including both lateral and vertical components, of AEM and JQF after the time of JQF’s take-off from Mangalore. This illustrates that the two aircraft remained on a collision course for most of the flight.
It should be noted that this data was not available to the controller at the time of collision. However, this information would have been available to the pilots of AEM and JQF had both aircraft been fitted with additional ADS-B IN technology.
Figure 20: Aircraft position for AEM and JQF
Source: ATSB, based on data provided by Airservices.
Note: Due to wind, the angle of approach (track angle) will appear smaller than the angle of collision (heading angle).
Figure 21: Vertical profile and timeline for AEM and JQF
Source: ATSB, based on data provided by Airservices.
Figure 22: Total separation between AEM and JQF in nautical miles
Source: ATSB, based on data provided by Airservices.
Wreckage and impact information
Overview
Following the mid-air collision, JQF continued for about 0.5 km before impacting an open field, while AEM continued in a northerly direction and impacted a lightly wooded area about 1.4 km from the collision point (Figure 23).
Airborne debris liberated in the collision formed a further wreckage field about 1.6 km to the north-north-east of the collision point and about 200 m to the west of the Hume Highway. The debris field contained parts of both aircraft, including the front section of JQF’s right wing, and the instrument panel coaming from AEM.
Inspection of both aircraft identified paint transfer from the other aircraft. A blue paint transfer was noted on the instrument coaming of AEM, indicating that the right wing of JQF had passed through the cabin area of AEM. After contact between the two aircraft, JQF likely lost a section of the right wing outboard of the engine nacelle, which was the piece found separate from the two aircraft.
Figure 23: Locations of collision, AEM, JQF and debris field
Source: Google Earth and Airservices, annotated by the ATSB.
VH-AEM site
The Travel Air was found in a significantly disrupted state, and it was not possible to conduct an extensive examination of the engines and aircraft control systems.
From observations of the wreckage and damage to nearby trees and ground scars, it was established that the aircraft collided with the ground in a wings-level but steep, inverted attitude. The aircraft passed through the tree canopy and collided with flat ground, the right wing impacted the base of a large tree, a post, and a fence. The wreckage trail was on a heading of 355⁰, just right of the aircraft’s track prior to the collision, with the wreckage spread along a 30‑metre path, from the initial impact point to the resting position of the aircraft.
The examination of the airframe and engine systems did not identify any pre-existing defects likely to have contributed to the accident. Flight data showed the aircraft was descending in a stable attitude, until the mid-air collision. Site inspection indicated that the landing gear and flaps were retracted at impact with the ground.
VH-JQF site
Witnesses reported seeing JQF in a spinning descent prior to the collision with terrain, which is supported by the wreckage examination. The aircraft impacted terrain in a relatively flat attitude.
The examination of the airframe and engine systems did not identify any pre-existing defects likely to have contributed to the accident. Flight data showed the aircraft was level immediately prior to the mid-air collision.
All components of JQF were accounted for at the accident site with the exception of some of the right-wing sections, which were located in the debris field to the north of JQF’s location, and the right aileron mass balance weight, which was located inside the wreckage of AEM.
The collision
Analysis of the wreckage from each aircraft indicated that the two aircraft came together at an obtuse relative angle with JQF crossing over the top of the AEM (Figure 24).
Figure 24: Estimated collision aspect based on ADS-B data and wreckage assessment
Source: ATSB.
Airspace oversight
Under the Airspace Act 2007, CASA, through their OAR was responsible for regulation of all Australian airspace. This included the classification of airspace.
Section 13 of the Airspace Act 2007 specified that:
(1) CASA has the function of conducting regular reviews of the existing classifications of volumes of Australian-administered airspace in order to determine whether those classifications are appropriate.
(2) CASA has the function of conducting regular reviews of the existing services and facilities provided by the providers of air navigation services in relation to particular volumes of Australian-administered airspace in order to determine whether those services and facilities are appropriate.
(3) CASA has the function of conducting regular reviews of Australian-administered airspace generally in order to identify risk factors and to determine whether there is safe and efficient use of that airspace and equitable access to that airspace for all users of that airspace.
The Australian Airspace Policy Statement 2018 outlined the process for reviewing the classification of a volume of airspace at an aerodrome. The thresholds set for conducting an airspace review were based on a set number of either total annual:
aircraft movements;
public transport operation movements; or
public transport operation passengers.
If an airport met or exceeded any of the thresholds for a classification (Table 8), in line with the policy CASA should complete an airspace review of the particular volume of airspace. The purpose of a review was to determine whether the airspace classification was appropriate and whether additional air traffic services was required, considering public, industry and agency comments, forecast future traffic levels, and any other significant risk mitigators.
Table 8: Airspace review criteria thresholds
Source: Australian Government (2018)
There were no requirements for the review of airspace where aircraft movements or passenger numbers did not meet the thresholds identified, however there was a provision in the Australian Airspace Policy Statement 2018, which stated that:
These criteria do not preclude CASA examining the requirement for airspace changes at other aerodrome locations should CASA consider such examinations is required, for example, on risk of safety grounds.
The available information on recorded aircraft movements and passenger numbers at Mangalore Airport (see the section titled Aerodrome information) did not reach the thresholds for the conduct of an airspace review.
Outside the formal review system, the OAR conducted risk assessments on numerous aerodromes and their surrounding airspace. Records provided by CASA indicated that, prior to this accident, these assessments for Mangalore were last conducted in May 2018 and July 2019. Comments associated with these reviews indicated an awareness that the data quality about the known movements was poor, and that there were fluctuations associated with a low number of aircraft movements, and that there has been an increase in Seminole and King Air operations which CASA attributed to training flights.
At the time of the accident, the OAR had not conducted a formal review of the airspace around Mangalore. A 2011 study of the Melbourne airspace noted that Mangalore had a high level of aviation activity, but was outside the scope of the study. CASA launched an aeronautical study of the Mangalore airspace in September 2021. The results of this review had not been released at the time of publication of this report.
The Australian Airspace Policy Statement was updated in November 2021. This update removed the prescriptive thresholds for a review, and instead moved towards risk-based assessments.
Mid-air collisions
See and avoid
In non-controlled airspace, pilots rely on the use of the rules of the air and see-and-avoid to maintain separation from other aircraft sharing the airspace. The limitations of see-and-avoid principle are well published.
The 1991 ATSB report ‘Limitations of the See-and-Avoid Principle’ is cited extensively in pilot guidance by CASA and foreign regulators and investigators. The paper identified a number of factors that influence the ability for a pilot to see-and-avoid other aircraft. It includes the statement that:
See-and-avoid can be considered to involve a number of steps. First, and most obviously, the pilot must look outside the aircraft.
Second, the pilot must search the available visual field and detect objects of interest, most likely in peripheral vision.
Next, the object must be looked at directly to be identified as an aircraft. If the aircraft is identified as a collision threat, the pilot must decide what evasive action to take. Finally, the pilot must make the necessary control movements and allow the aircraft to respond.
Not only does the whole process take valuable time, but human factors at various stages in the process can reduce the chance that a threat aircraft will be seen and successfully evaded. These human factors are not ‘errors’ nor are they signs of ‘poor airmanship’. They are limitations of the human visual and information processing system which are present to various degrees in all pilots’.
It is likely that the cloud present on the day affected the ability of the pilots to see the approaching aircraft. However, even without this cloud, the ATSB paper identified additional limitations of see-and-avoid:
Workload – The pilots in JQF were in the climb phase of a test flight and establishing the aircraft on the outbound track. The crew of AEM were conducting the first in-aircraft VOR approach with this student.
Visual search – A human’s field of vision begins to narrow after 35, and significantly after age 55. Additionally, in daylight, a pilot must look almost directly at an object to see it. Therefore it is possible for a pilot to look past an object in their screen if they do not see it directly.
Cockpit visibility – Items such as engines, window pillars, sunshades, and dirt may impact on the pilot’s ability to see an aircraft.
Time to conduct a traffic scan – Pilots require a long time to effectively conduct a traffic scan, during which time the picture out the window changes due to the motion of the aircraft.
Limitations of vision – Factors such as the eye’s physiological blind spot and the threshold of an individual’s vision and the acuity of their vision. Some individuals may perceive another aircraft much further away than others.
Alerted traffic search – It is estimated that pilots who are told where an aircraft is are around eight times more likely to see the aircraft than pilots who are not alerted to the direction of an aircraft.
Characteristics of the aircraft – Aircraft are more easily spotted if they have a high contrast with their background
Relative movement between aircraft – It is difficult to see another aircraft when there is little relative motion between one aircraft and the other, such as when they are moving towards the same location in space. Furthermore, when aircraft have a high closing speed, the small visual angle presented by an aircraft may not grow rapidly until collision is imminent.
In addition to the issues presented with pilots seeing other aircraft, there is evidence that pilots need around 12.5 seconds after they see an aircraft to perceive what it is and respond with an evasive manoeuvre to avoid the collision. The research shows that older or less‑experienced pilots need even longer.
Excluding the likely influence cloud had on the opportunity for the pilots of each aircraft to sight the other aircraft; at 12.5 seconds prior to the collision, the angular size that each aircraft would have appeared was only around 0.4°; increasing to around 1° 5-6 seconds pilot to the collision.
Studies have assessed the size an object needs to be for it to be sighted, with estimations varying from 0.2° degrees (NTSB, 1988) to 0.4-0.6° (Morris, 2005). However, these observations may be made under certain conditions, and not reflective of the particular conditions experienced by these pilots.
Collision prevention
The United Kingdom (UK) Airprox[40] board commissioned a research paper (Helios 2014a, 2014b) to review the risk of mid-air collision in Class G airspace. While the particular operation and regulation of Class G airspace in the UK is slightly different from that in Australia, it remains non‑controlled airspace, with an available traffic information service.
The research identified seven barriers to mitigate the risk of mid-air collisions (Figure 25). Four of these were preventative, to avoid the occurrence of both conflicting traffic and incidents:
- strategic conflict management, - pre-tactical events, - pilot tactical control, and - ATC tactical intervention,
The other three barriers were attempts to stop an incident becoming an accident:
- ATC recovery, - pilot recovery (ACAS) and - pilot recovery (see and avoid).
Analysis of all the received UK airprox reports identified that pilot see-and-avoid was the most effective at preventing mid-air collision, but was also the last available defence. The study also found that an alert provided by ATC following a STCA effectively prevented 1.5 per cent of events escalating to collisions.
Figure 25: Barriers of defence in preventing a mid-air collision
Source: Helios, 2014b
Aircraft performance and cockpit visibility study
As previously discussed, the evidence indicates that the collision occurred either in, or very close to, the bottom of a cloud layer (see the section titled Meteorological information), with minimal opportunity for the occupants of the two aircraft to see-and-avoid each other.
However, in order to more fully understand the situation presented to the pilots, the ATSB conducted an aircraft performance and cockpit visibility study for this investigation, based on similar work carried out by the United States National Transportation Safety Board[41] and refined for a number of investigations over recent years, most recently for the 2019 mid-air collision near Ketchikan, Alaska (NTSB, 2021).
The study estimated the time windows during which the respective aircraft would have been visible to the pilots in the other aircraft if the accident had occurred in visual conditions. It also assesses the value of the installation and availability of traffic display and alerting systems based on the ADS-B data that both aircraft were transmitting.
This study was conducted as ATSB Safety Study report AS-2022-001. Results of this study indicated that the pilots would have faced significant difficulties in using the see‑and‑avoid principle to avoid the collision and that ADS‑B‑based alerting would likely have prevented the accident.
Related occurrences
This is the first recorded mid-air collision between two civil IFR aircraft operating in Australia.
A review of the ATSB’s national aviation occurrence database identified that a total of 29 civil mid‑air collisions (including this occurrence) were reported in the 20 years between 2001 and 2020. Of these 29 collisions, 21 were classified as accidents, with 12 resulting in fatal outcomes. The remaining 8 collisions did not result in a sufficient level of damage or injury to meet the definition of an accident in the Transport Safety Investigation Act, 2003 and were instead categorised as incidents or serious incidents.
Of the 28 mid-air collisions, other than this accident:
One incident was a collision between an aircraft and a parachutist as they exited the aircraft;
Eight collisions occurred between two gliders (6 accidents with 2 being fatal; 2 serious incidents);
One serious incident was a collision between a paraglider and a hang glider;
One fatal accident was a collision between two ultra-light aircraft that reportedly also hit a powerline;
Three collisions involved two aircraft operating together in either aerial mustering or fire control activities (one fatal accident between two helicopters, one serious incident between two helicopters, and one fatal accident involving a helicopter and an aircraft);
Three collisions occurred between aircraft conducting formation flying (1 accident, 1 serious incident, 1 incident);
Four accidents occurred between aircraft on late final approach to land, 2 of which were fatal;
Five collisions occurred between aircraft operating elsewhere in the circuit – 2 of these were fatal accidents, 2 were accidents with no injuries and one was a serious incident;
One fatal accident occurred between an aircraft departing from an airport and one conducting aerial agriculture work in the vicinity of the aerodrome; and
One fatal accident occurred between two aircraft converging at the approach point to an airport.
All of the aircraft involved in these 28 mid-air collisions were operating under visual flight rules. Twenty six of the 28 mid-air collisions occurred in non-controlled airspace. Nineteen of these occurred within 10 NM of an airport, aerodrome or authorised landing area.
Apart from this accident, in the same 20-year period there have been 25 other airspace‑related occurrences reported to the ATSB in the vicinity of Mangalore Airport.
Eleven of the 25 occurrences were categorised as a near collision[42]; four of which involved one aircraft operating under the IFR, and one that involved both aircraft operating under the IFR. All eleven occurrences were categorised as serious incidents.
Two of these serious incidents were investigated by the ATSB and are summarised below:
AO-2011-119: Airprox - VH-CIX/VH-KHG, Piper PA-28-151/PA-44-180, Mangalore Airport, Victoria on 27 September 2011
While conducting circuits, the Piper PA-28 came within close proximity of a Piper PA-44 rejoining the circuit following an instrument approach, resulting in the crew of the PA-28 taking evasive action. Both aircraft were operated by the same company.
As a result of the incident the operator introduced a procedure whereby, when the wind conditions favoured a take-off towards the north or north-east, aircraft joining the circuit from a practice instrument approach were to descend to an overfly height of 2,000 ft AMSL and join the circuit from the non-active side of the circuit.
AO-2014-006: Near collision involving a Cessna 404, VH-VEC and a Piper PA-28, VH‑UNW near Mangalore Airport, Victoria on 10 January 2014
The pilot of a Cessna 404 aircraft registered VH-VEC (VEC) was conducting an aerial survey flight north-east of Mangalore Airport, Victoria. The flight was being conducted under the instrument flight rules (IFR) and flown at about 1,500 ft above ground level. The survey pattern required the aircraft to fly across the extended centreline of runway 36. The pilot made all required CTAF broadcasts while operating in the area.
At the same time as VEC was conducting the survey, several aircraft were departing Mangalore for a series of different navigational exercises. The pilot of VEC continually attempted to call the pilots in the departing aircraft, to establish their position and intentions. However, as per their training, the pilot’s did not respond until their respective aircraft were at least 500 feet above the ground. Also, due to misunderstanding the pilot of VEC’s intentions, they did not respond to his radio calls, unless the request was directed at their particular aircraft. When the solo student pilot of VH-UNW (UNW) departed runway 36, they focussed on flying the aircraft rather than communicating, until reaching 500 feet above ground level. The pilot of UNW then lowered the aircraft nose to check for traffic and saw VEC in close proximity. In response, they turned UNW to the right at the same time that the pilot of VEC initiated a climbing turn to the right.
Both of these near collisions involved a conflict between a VFR and IFR aircraft in the CTAF area. In the near collision in 2014, separation between the two aircraft was reduced to 100 m horizontally and 200 ft vertically. In the earlier occurrence the separation was 30‑45 m horizontally, and at the same level.
One of the other near collisions in the CTAF area at Mangalore involved two aircraft operating under the IFR. One of those aircraft was VH-JQF, the same aircraft involved in this collision. A summary is below:
ATSB Occurrence 201200571: The Piper PA-44 was tracking outbound in the VOR holding pattern when another PA-44 crossed its path in close proximity, tracking inbound to the NDB at the same level.
At the time of writing, the ATSB is investigating another separation occurrence between two aircraft near Mangalore Airport on 6 June 2021 (AO-2021-023). In this incident, an Augusta Westland 139 helicopter was flying southbound toward Mangalore at an altitude of 3,100 ft. At the same time, a PA-44 was conducting an instrument approach to Mangalore.
Due to cloud conditions, the PA-44 commenced a missed approach from below 2,000 ft in a northerly direction toward Mangalore. Shortly after the PA-44 began climbing, and prior to the pilot broadcasting that the missed approach had been commenced, the pilot of the AW139 received a traffic collision and avoidance (TCAS) alert and manoeuvred the aircraft to increase separation. Both flights continued without further incident. A final report for this investigation is due to be published in the second quarter of 2022.
The two aircraft, VH-AEM and VH-JQF, collided in mid-air south of Mangalore Airport. This was the first recorded mid-air collision of two civil, instrument flight rules (IFR) flights in Australia, although not the first event where two IFR aircraft have come into close proximity with each other.
Site and wreckage examination did not identify any aircraft defects or anomalies that might have contributed to the accident. Additionally, no evidence was found to suggest any medical or fatigue‑related issues that would have likely affected pilot performance on the day of the flight.
Both aircraft involved in the accident were fitted with Automatic Dependent Surveillance Broadcast (ADS-B) OUT equipment which broadcast positional information. However, neither aircraft had the capability to directly receive this information. Flight path data did not support an evasive manoeuvre being initiated by either aircraft, suggesting that the pilots of both aircraft did not see each other in sufficient time prior to the collision to initiate avoiding action.
This analysis will examine how the two aircraft flight paths conflicted without the risk of a collision being identified and the accident prevented. Further, it will review the controls that could be used to prevent similar accidents from occurring in the future.
Operational environment
In non-controlled airspace, pilots hold responsibility for maintaining separation from other aircraft. The rules of the air require pilots to maintain a lookout for other aircraft when conditions permit, to not operate in a way that creates a hazard for other aircraft, and to monitor and broadcast on the appropriate frequency whenever it is reasonably necessary, to avoid the risk of collision.
Both aircraft had experienced pilots on board. The examiner in JQF and instructor in AEM were both highly experienced and had conducted similar operations many times before. The student in AEM had a high level of experience as a VFR pilot operating in controlled and non-controlled airspace. The exam candidate in JQF had completed an intense period of training and been assessed as competent to undertake the final assessment for their training course. All the pilots were familiar with the operational environment and how to separate from other traffic.
Both aircraft had operational requirements that needed to be achieved. According to the published approach chart, and the pilots interpretation of the ERSA requirements, AEM had to be at an altitude of not below 3,900 ft passing overhead Mangalore Airport to conduct the planned approach. Vertically, JQF had to avoid terrain until above 3,400 ft within 10 NM of the airport, and laterally, JQF had to be established on the outbound track to waypoint LACEY within 5 NM of the departure airport. If the intercept of the outbound track exceeded this distance, the candidate would not have demonstrated the required competencies for the departure sequence of the flight test. In controlled airspace these flight tracking requirements would be assessed and managed by an air traffic controller. In non-controlled airspace the pilots’ were required to assess and manage the operational requirements and collision risk.
AEM and JQF were both fitted with dual radios. Examination of the radios fitted to JQF identified that the radios were tuned to the expected CTAF and Melbourne Centre frequencies. As the pilots of AEM had not indicated to the controller that they were switching to the CTAF, it can also be reasonably assumed that they also had the radios tuned to the appropriate CTAF and Melbourne Centre frequencies.
Air traffic control recordings confirmed that pilots from both aircraft communicated with Melbourne Centre, and interviews with other pilots in the area identified calls occurring from pilots of both aircraft on the CTAF. Significantly, a review of events leading up to the collision identified that pilots from AEM and JQF may have been communicating on different frequencies at the same time and therefore missed important alerting information from, and about, the other aircraft.
The human ability to monitor two frequencies simultaneously is limited, particularly in periods of high workload or stress, such as during a flight test or early instrument flight, and when there are other non-pertinent broadcasts on the frequencies. While the instructor in AEM and the examiner in JQF had more capacity to monitor both frequencies than the students by virtue of their relative experience, they both had other responsibilities in their training and checking roles that may have affected their ability to identify and assess all broadcasts. The initially missed call made from the Melbourne Centre controller to the pilots of AEM, where the pilots were likely either listening to the AWIS or setting up the aircraft for the descent to the approach is consistent with the known effect of workload on other tasks.
While other pilots flying in the area recalled broadcasts from both aircraft on the CTAF prior to the accident, no‑one recalled coordinating transmissions between the pilots of the two aircraft. While it is possible that this may have occurred and not been recalled by other pilots in the area, this was considered unlikely.
Having both been advised of the presence of the other by the Melbourne Centre controller, it is also highly unlikely that the pilots intentionally continued into a situation where they assessed the other aircraft to be a threat without taking action, including communicating, to protect themselves. As such, the ATSB concluded that the pilots either failed to identify that a collision risk existed or identified the potential risk but incorrectly assessed that the aircraft were sufficiently separated. In either case, the primary defence of established self‑separation required in non‑controlled airspace was absent.
Limitations of see-and-avoid
While it is not certain that the accident took place in cloud, it is clear the accident took place in instrument meteorological conditions due to the presence of extensive cloud. It is likely that AEM was in cloud for most of its descent from 6,000ft. JQF may have manoeuvred around cloud during the climb, explaining the variation in track, or passed through cloud on its climb, and had cloud between it and AEM for most of the time from when traffic information was passed until the collision.
This would have significantly reduced the likelihood that the aircraft were visible to one another prior to the collision. If either aircraft were operating in cloud, see-and-avoid would have been unachievable to both. However, if visual meteorological conditions had existed, under IFR, they would have been expected to use see-and-avoid, along with radio broadcasts, to avoid each other.
The limitations of see-and-avoid have been widely discussed in previous accident investigations, and in CASA guidance to pilots.
After JQF entered a turn towards the outbound track, the two aircraft maintained a reasonably constant relative position. This means that, had they been visible to each other, their position in the windscreen would have had limited movement, making perception difficult. The closure rate between the two aircraft was also very high, meaning that even 20 seconds prior to the collision, the angular size of each aircraft would have made them barely perceivable. Other factors that may have affected the ability of the pilots to see and avoid conflicting traffic included:
The crew of AEM were not directly alerted to the direction and height of JQF once airborne and may have either believed JQF was right of their track from the information in the associated departure call. Equally, they may have not heard JQF’s departure call through making their own report to Melbourne centre or inbound CTAF broadcast at the same time, and therefore not realised JQF was airborne.
The aircraft were both white with a background of textured ground or cloud.
The lack of variation in the flight tracks prior to the mid-air collision strongly suggests that the pilots did not see the other aircraft in time to commence avoiding action.
Local procedures
The evidence supports the pilots in the two aircraft probably having different interpretations of the wording of the local altitude requirements for practice instrument approaches at Mangalore detailed in the En-Route Supplement Australia (ERSA). It is also known that these different interpretations were held and applied by pilots other than those involved in this accident.
The different interpretations affected the altitude that AEM was required to be at when overhead the VOR. According to the reported understanding of the pilots in AEM, the approach would be flown as published, passing overhead the VOR at 3,900 ft and terminating the approach 1,000 ft higher than the minima. However, using the reported understanding of the pilots in JQF, aircraft conducting a practice VOR approach at Mangalore would start the approach at 4,900 ft. While it is not possible to determine why the pilots of JQF levelled off briefly at 4,100 ft prior to the collision, one possible consideration is that they may have believed they were passing a safe distance below AEM on its inbound descent to the VOR.
While the controller provided traffic information to the pilots of JQF that AEM was descending for airwork to ‘not above 4,000 ft’, the information that AEM was at 5,000 ft when the traffic information was passed, combined with possibly not hearing any inbound call from AEM, may have supported the pilots of JQF’s mental model of the higher practice approach height being used.
The safety benefit of clearly worded standard operating procedures, applied in the same way by all, is clearly understood in aviation. The procedure was originally written to separate IFR traffic from circuit traffic, which both interpretations would achieve. The risk of misunderstanding this procedure was identified by the CASA Office of Airspace Regulation at Ballarat in 2017. Despite that, the written procedure remained unchanged at Ballarat, Mangalore and two other airports. Information in the ERSA is published by Airservices, based on information provided by the airport operator. CASA advised that the procedure was intended to be applied by adding 1,000 ft to all heights in the approach.
Traffic information
From the Melbourne Centre records, ADS-B data, and the estimated times of broadcasts on the CTAF, it appears that there was some overlap between the pilots of the two aircraft making key transmissions or actions on different radio frequencies at the same time. In particular, around 1119 – 1121 the crew of AEM were likely checking the AWIS and communicating with the Melbourne Centre controller at the top of their descent and receiving traffic information. During the same time period, the pilot under examination in JQF was probably broadcasting on the CTAF prior to take-off.
This may have affected pilot awareness of the position of the other aircraft, and the associated collision risk.
The controller provided traffic information to each aircraft in accordance with the required procedures. The content of the traffic information gave the pilot of each aircraft the position of the other aircraft at the time, and the intended flight path. However, the timing of the traffic information did not give the pilots in AEM in particular, a clear understanding of where JQF would be as their flight paths neared.
AEM was outside the Melbourne Centre controller’s airspace and on a different frequency when the pilot of JQF made their taxi call. When AEM was given traffic about JQF, it was reported that JQF was still on the ground, shortly to depart. Analysis of ADS-B data available after the accident, which was not available to the controller at the time, indicated it was likely that JQF was somewhere in the take-off sequence at this time, but had not yet appeared on the controller’s display.
It is possible that JQF made a rolling broadcast, reportedly heard by other pilots in the CTAF, at the time that the pilots of AEM were providing information to the Melbourne Centre controller about their descent and airwork, or listening to the AWIS. If this were the case, the pilots of AEM may have been waiting to hear a broadcast from JQF on the CTAF indicating their take-off, and not expecting that they were airborne already. This, combined with the absence of JQF on the electronic flight bag display of the student in AEM, and the higher workload environment that would be expected in training a first VOR approach, made it unlikely that they had updated their mental model that JQF had departed and were a potential threat.
At the time the pilots of JQF were passed traffic about AEM, AEM was 10-11 NM from Mangalore. Previous students of the instructor have advised they were taught to provide traffic information early, at about 15 NM rather than the minimum required 10 NM. This was a recommended procedure due to the high performance of the Travel Air, but also meant that it was likely that AEM made a CTAF broadcast sometime in the window that the pilots of JQF were in the initial climb, changing radio frequencies to Melbourne Centre, or actively making the departure report to the Melbourne Centre controller.
If the pilots of AEM had made their CTAF broadcast later in the window, closer to 10 NM, which is possible considering the workload for the student setting up and conducting their first VOR approach, it is possible that the CTAF broadcast from AEM and the Melbourne Centre report from the crew of JQF were made at the same time, with neither aircraft occupants hearing the other.
Alternatively, the pilots of AEM may have heard the Melbourne Centre departure report made by the pilot of JQF, but, due to the missing ‘tracking to’ information in the call, expected that JQF was to the right of their track and not a threat to their inbound descent.
In summary, while there were a number of factors that may have impeded radio communication between the pilots of the two aircraft, it could not be determined why there was no apparent coordination on the CTAF.
There were opportunities for the traffic information to have been passed by the controller to each aircraft earlier, although the pilots of AEM would still have been told JQF was on the ground and the crew of JQF would have been told that AEM was inbound, but over 15 minutes away at the time of the JQF taxi call. As such, the earlier provision of traffic information would probably not have changed the alerting it provided. There is potential however, that traffic information provided to the pilots of JQF while they were still on the ground after their initial taxi call, but prior to departure, could have led to the aircraft remaining on the ground until AEM was overhead the airport.
Air traffic control procedures have no requirement for a controller responsible for Class G airspace to provide updated traffic information to IFR aircraft. Analysis conducted for the ATSB by an air traffic services subject matter expert identified a number of potential reasons why updated traffic information would not have been provided. Specifically, the controller:
could reasonably expect the occupants of the aircraft were talking to each other and taking action to avoid each other
may over-transmit the pilots while they are trying to talk to each other
not being fully aware of any coordination between the occupants of the two aircraft, could give advice that created a hazardous situation.
Automatic Dependent Surveillance Broadcast
When automatic dependent surveillance broadcast (ADS-B) equipment became mandatory for IFR aircraft, there was no requirement to be fitted with ADS-B receiving equipment. Had each aircraft been fitted with ADS-B IN, and a suitable cockpit display, the occupants would have received the same quality of surveillance information received by the controller.
This technology could have prevented this accident from occurring and, more generally, it provides a valuable enhancement to the long‑established procedures for maintaining separation in non‑controlled airspace.
Instead of receiving one snapshot of traffic information from a controller in non-controlled airspace, an ADS‑B display in the aircraft constantly updates a pilot about the position of other ADS‑B‑equipped aircraft and is capable of providing alerts when the traffic come within an unsafe proximity. If the pilots had more information about their proximity, either through updated traffic information or ADS-B IN display and alerts, they would probably have acted differently to separate, and avoided the collision.
Surveillance service technology has aided the work of air traffic controllers, enabling them to provide a traffic position service with known accuracy of aircraft altitude and position rather than simply applying procedural separation.
This accident occurred in a location where both SSR and ADS-B data was captured and a surveillance service was offered. In areas where an existing SSR service exists, the mandatory fitment of ADS-B broadcasting equipment, without the fitment of ADS-B receiving equipment and an in-cockpit display of traffic information has provided little advantage to operators of IFR aircraft in non-controlled airspace.
Arguably, if these two aircraft were operating outside a surveillance service, the traffic information provided to them based on AIP GEN 3.3 paragraph 2.16.4, in the AIP version dated 7 November 2019, current at the time of the accident standards, would have kept them further apart than when their positions were accurately known. So, while the controller had better traffic information and a more accurate picture of where the two aircraft were coming together, the pilots did not share this information.
The advantage of ADS-B broadcast equipment comes from extending the area in which a surveillance service can be offered to an operating aircraft, as well as providing direct information to aircraft fitted with receiving equipment both within and outside of a surveillance environment.
ADS‑B IN and OUT also provide valuable alerting to VFR aircraft. CASA Advisory Circular 91-23 (2020) stated, in relation to ADS-B options for VFR aircraft, that:
All instrument flight rules aircraft have ADS-B transmitting equipment (ADS-B OUT). Logically, ADS-B OUT is the ideal way for VFR aircraft to signal their presence directly to other aircraft. In effect, ADS-B turns the ‘see and avoid’ concept into ‘see, BE SEEN, and avoid’.
In the lead up to the collision, all four pilots had to make decisions about the location of the other aircraft, based on information supplied to them by the controller. It is difficult for pilots to keep an updated mental model of where other aircraft are, particularly if they are not familiar with the performance capability of that particular aircraft, as they manoeuvre their own aircraft in the airspace.
By contrast, ADS-B IN equipment has the benefit of identifying accurate positions of other aircraft broadcasting ADS-B OUT information, although it still has the limitation that it cannot display other aircraft not broadcasting ADS-B OUT. Consequently, even with ADS-B IN display equipment, pilots need to be aware of positional information about potentially conflicting not broadcasting ADS-B aircraft, and not just rely on alerts generated by the ADS-B IN equipment. The NTSB report into the 2019 Ketchikan, Alaska mid-air collision, in which both aircraft were carrying ADS-B IN display equipment, showed there were limitations in alerting functions due to software differences. As such, even when ADS-B receiving equipment is fitted, radio communications should remain the primary method for pilots operating in non-controlled airspace to arrange separation with other pilots in the vicinity.
The student pilot in AEM made a proactive choice to carry an electronic flight bag (EFB), connected to a mobile network. While this EFB had the ability to display conflicting traffic, there were limitations in the type of traffic that would be displayed, and in this case it was unlikely to have displayed JQF. Tablets can however be fitted with an external ADS-B receiving unit that will provide this additional information, and in some cases aural alerting, from ADS-B broadcasting aircraft.
Short term conflict alert
Once a controller passes traffic information to two IFR aircraft, they do not receive any feedback on whether the two aircraft have established communications or a separation plan. There is no requirement for a pilot to respond that they have traffic sighted or contacted. Once traffic is passed, the controller operates on the expectation that, if required, the pilots will coordinate to ensure separation.
Because aircraft operate in non-controlled airspace, without published separation standards, it is not unusual for controllers to receive a short term conflict alerts (STCAs). Nuisance alerts, or alerts which need to be checked but very rarely responded to are of little benefit. Controllers responsible for the same airspace reported regularly receiving STCAs, with this accident being the first collision involving IFR aircraft.
These were not the only two aircraft the controller was managing at the time. While it was not reported to be a high workload period, the controller was constantly communicating with other aircraft in the time between providing traffic to the pilots of JQF and the accident. There is guidance that a STCA alert should be responded to over all other communications, and records show that the controller did prioritise an assessment of the alert while talking to another aircraft.
In the documented procedures for a STCA, there was no written difference for response to a STCA in controlled airspace and non-controlled airspace. Controllers are taught to use their judgement in assessing the integrity of a STCA and to respond appropriately. Therefore, in non‑controlled airspace, when the controller is displayed a STCA, they assess the risk in the context of whether traffic information has been passed from the controller to each of the pilots of the involved aircraft. Additionally, Airservices do not consider the STCA as a defence in non-controlled airspace.
In the 3 minutes before the collision, the controller received three separate STCAs involving these two aircraft. One was spurious and the velocity vectors at the time of the others projected the aircraft would pass each other, albeit narrowly for the third alert. The recordings indicated that the controller responded to these as per procedures.
With hindsight, the velocity vectors during the third STCA, which occurred less than 30 seconds prior to the collision, accurately indicated the conflict. When the STCA was assessed and acknowledged by the controller about 10 seconds prior to the collision, the display indicated that 500 ft displacement existed between the two aircraft, which the controller considered to be a reasonable pilot‑managed vertical separation. However, taking into account the filtering of data, and the permitted 200 ft tolerances, the risk of collision was higher that indicated on the display.
Additionally, this information was presented in the context that:
alerts regularly occurred as nuisance or no-risk alerts
alerts were based on separation standards not appropriate to the airspace
traffic had been provided to the aircraft in accordance with procedures
the aircraft still appeared vertically separated
self‑separation permitted the two aircraft to pass relatively closely.
It is acknowledged that the final STCA activation provided limited time for the controller to react and broadcast a safety alert or suggested avoiding action.
However, given typical reaction times, the ATSB determined that 30 seconds was sufficient time to assess the final STCA, provide a safety broadcast and probably prevent the collision. Equally, given the same reaction time considerations, it is questionable whether a controller radio broadcast, 10 seconds prior to the collision could have been processed and reacted to by the pilots sufficiently to have manoeuvred the aircraft to prevent the accident.
Airspace
When operating in non-controlled airspace (such as the current Class G airspace around Mangalore), whether under the instrument or visual flight rules, pilots hold responsibility for separation from other aircraft. An ATSB review of historical occurrences identified that this was the first ever collision between aircraft operating under the instrument flight rules in Australia under a procedure that has been in place for some decades.
This record indicates that self-separation using broadcast traffic advice has been a largely reliable procedure.
The ATSB does however note that the effectiveness of the current pilot-separation method relies on individual pilots:
recognising a potentially unsafe situation
formulating an effective separation plan that often requires coordination with the occupants of the other involved aircraft.
This process is almost exclusively reliant on individual human actions without other mechanisms potentially acting as a safeguard and/or safety redundancy, and as such subject to human error, even when it involves experienced pilots. Furthermore, such errors often increase under high workload associated with, for example, instrument flying procedures, low experience or a busy airspace environment. Of note, the airspace surrounding Mangalore Airport is commonly utilised for training and by pilots gaining experience, especially in instrument flying.
In that context, while the available evidence in this investigation does not support a conclusion that the present self‑separation system is unsafe, there is an opportunity to potentially reduce safety risk further.
The ATSB therefore supports systemic enhancements to the overall air traffic system that have been assessed by regulatory and air traffic specialists, in keeping with their obligations as providing a net overall safety increase. Key examples of such enhancements include:
the increased use of controlled airspace and ADS‑B aircraft surveillance data (both by air traffic services and in‑cockpit)
improved monitoring of air traffic movements (both quantity and complexity) to assist the identification of increasing risk areas.
With respect to the accident involving VH‑JQF and VH‑AEM, had the aircraft been operating in controlled airspace (an example being Class E airspace) they would have been positively separated and therefore the collision would have been unlikely to have occurred.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the mid-air collision and subsequent collision with terrain involving Piper PA44-180 Seminole, VH-JQF and Beech D95A Travel Air, VH-AEM, near Mangalore Airport, Victoria, on 19 February 2020.
Contributing factors
Following receipt of verbal traffic information, the pilots did not successfully manoeuvre or establish direct communications on the common traffic advisory frequency to maintain separation, probably due to the collision risk not being recognised.
While it is probable that the aircraft were in instrument meteorological conditions and could not visually separate to avoid the collision; the known limitations of the see-and-avoid principle meant that the pilots were unlikely to have seen each other in sufficient time to prevent the collision even in visual conditions.
Following receipt of a short-term conflict alert, the controller assessed it in accordance with the required procedure. After considering that the pilots had been passed mutual traffic information and were required to ensure their own separation in non‑controlled airspace, the controller did not intervene further.
While the pilots were responsible for self-separation within the Mangalore common traffic advisory frequency area, they did not have access to the same surveillance data, including automatic dependant surveillance broadcast information available to air traffic control. As a result, the pilots were required to make timely decisions to avoid a collision without the best available information.
Other factors that increased risk
The En-Route Supplement Australia included a requirement to add 1,000 ft to the prescribed practice instrument approach ‘altitude’ at Mangalore Airport. The procedure did not detail whether this height was to be applied to the minimum descent altitude or to all approach altitudes, resulting in varied application and an increased risk of traffic conflicts. (Safety issue)
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The En-Route Supplement Australia included a requirement to add 1,000 ft to the prescribed practice instrument approach ‘altitude’ at Mangalore Airport. The procedure did not detail whether this height was to be applied to the minimum descent altitude or to all approach altitudes, resulting in varied application and an increased risk of traffic conflicts. (Safety issue)
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Civil Aviation Safety Authority addresses the ambiguity in the En‑Route Supplement Australia requirement relating to practice instrument approach altitudes at Mangalore Airport to reduce the variation in application and risk of traffic conflicts.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Safety action by the Civil Aviation Safety Authority
The Civil Aviation Safety Authority is conducting a study of the airspace within a 25 NM area of Mangalore Airport from the ground to 8,500 ft AMSL. The study will evaluate the suitability of the airspace, including efficient use, equitable access for all users, appropriateness of the airspace classification and the existing services and facilities provided by the air navigation service provider. At the time of publication this study has not been published.
Safety action by Airservices Australia
Airservices Australia has submitted a proposal to the Civil Aviation Safety Authority for the implementation of a surveillance flight information service (SFIS) at Mangalore Airport, however the review process for the SFIS is pending the completion of the Office of Airspace Regulation study of the airspace surrounding Mangalore Airport. In the interim period a Melbourne Centre controller is monitoring the CTAF frequency during prescribed hours to provide a safety alerting service if required.
Airservices Australia has also raised a consultation to lower the base of Class E airspace around Mangalore Airport. At the time of writing that proposal was in review by Airservices following an industry consultation period.
Glossary
ACAS Airborne collision avoidance system
ADS-B Automatic Dependent Surveillance Broadcast
AIP Aeronautical Information Publication
AMSL Above mean sea level
AFRU Aerodrome frequency response unit
ASD Air Situation Display
ATC Air traffic control
ATS Air traffic services
ATSB Australian Transport Safety Bureau
AWIS Automated weather information system
AWS Automatic weather service
BoM Bureau of Meteorology
CASA Civil Aviation Safety Authority
CASR Civil Aviation Safety Regulations
CDTI Cockpit display of traffic information
CTAF Common traffic advisory frequency
DOK Dookie (sector of airspace)
EFB Electronic flight bag
ERSA En-Route Supplement Australia
FIS Flight information service
GAF Graphical Area Forecast
GNSS Global navigation satellite system
HUM Hume (sector of airspace)
ICAO International Civil Aviation Organization
IFR Instrument flight rules
ILS Instrument landing system
MATS Manual of Air Traffic Services
MOS Manual of Standards
NDB Non-directional beacon
NAPM National ATS procedures manual
NM Nautical mile
OVN Ovens (sector of airspace)
QNH That pressure setting, which, when placed on the pressure setting sub‑scale of a sensitive altimeter of an aircraft located at the reference point of an aerodrome, will cause the altimeter to indicate the vertical displacement of the reference point above mean sea level
SAR Search and rescue
SFIS Surveillance flight information service
SME Subject matter expert
STCA Short term conflict alert
TAF Terminal area forecast
TCAS Traffic collision avoidance system
VOR VHF Omni-directional range
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Helios (2014a) Review of existing Class G airspace risk studies: what do we know? Helios Document reference P1838D002, produced for United Kingdom Civil Aviation Authority.
Helios (2014b) Class G airprox reports analysis: results and conclusions. Helios document reference P1838 D003, produced for United Kingdom Civil Aviation Authority.
International Civil Aviation Organization (2018)) Annex 11: Air Traffic Services. Fifteenth edition. International Civil Aviation Organization, Canada.
Morris, C (2005) Midair collisions: Limitations of the see-and-avoid concept in civil aviation. Aviation, Space, and Environmental Medicine. Vol 76, No. 4 April 2005.
National Transport Safety Board (1988) AIRCRAFT ACCIDENT REPORT - Midair Collision of Skywest airlines Swearingen Metro II, N163SW, and Mooney M20, N6485U, Kearns, Utah, January 15, 1987
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the operators of VH-AEM and VH‑JQF
the owner of VH-AEM
the air traffic controller
Airservices Australia
air traffic control subject matter expert
Bureau of Meteorology
Civil Aviation Safety Authority
AvPlan
United States National Transportation Safety Board
Office of the Aircraft Accident and Incident Investigation Commission, Thailand
Submissions were received from:
the operators of VH-AEM and VH-JQF
the air traffic controller
Airservices Australia
Bureau of Meteorology
Civil Aviation Safety Authority
Office of the Aircraft Accident and Incident Investigation Commission, Thailand
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Appendices
Appendix A - Sequence of events
The sequence of events shows the key events identified in the report, including a transcript of the radio calls recorded between the Melbourne Centre controller and the pilots of AEM and JQF (in italics). The transcript does not include all calls made between the Melbourne Centre controller and other pilots or controllers.
Time start
(* indicates approximate time)
Time end
(* indicates approximate time)
Aircraft
Comment
1055*
Departure of AEM from Tyabb
1111:21
1111:32
JQF
Melbourne Centre, JQF is two POB IFR Mangalore taxying for runway two three for Mangalore
Melbourne Centre
JQF, Melbourne Centre, G’day. Squawk three six two four, there’s no reported IFR traffic.
JQF
Three six two four, JQF
Coordination to Melbourne Centre controller of AEM. Aircraft had previously reported estimating Mangalore at 1126.
1117:42
1117:55
AEM
Melbourne Centre, AEM, maintaining six thousand.
Melbourne Centre
AEM, G’day Melbourne Centre. Area QNH one zero one zero, and there’s no reported IFR traffic for your descent for your airwork at Mangalore.
AEM
One zero one zero, not traffic for airwork at Mangalore, thank you, AEM.
1118:22
AEM entered ML Centre airspace (30 DME boundary)
1119:35
1119:54
AEM
AEM, leaving six thousand for airwork four thousand down to ground, will call again time five zero or on departure.
Melbourne Centre
AEM thanks, I’ll talk to you again by time five zero and no reported IFR traffic for not above four thousand.
AEM
AEM
1120:07
11:20:08
Melbourne Centre
AEM, actually I will pass you some traffic when you’re ready.
1120:15
1120:28
Melbourne Centre
AEM, Centre?
AEM
AEM go ahead
Melbourne Centre
AEM shortly to depart Mangalore southbound, or via LACEY is JQF, a Seminole, they’ll be on climb to seven thousand
AEM
JQF copied, AEM.
1120:31
JQF first appeared on controller’s display
1122:19
1123:00
JQF
Melbourne Centre, JQF departure
Melbourne Centre
JQF’s identified, verify level with departure
JQF
JQF departure at Mangalore two three passing two thousand seven hundred on climb to seven thousand tracking to LACEY, Mangalore
Melbourne Centre
JQF area QNH one zero one zero
JQF
One zero one zero, JQF
Melbourne Centre
And JQF, traffic six miles in your twelve o’clock is AEM, a kingair, they’re inbound to Mangalore for airwork, passing five thousand, on descent to not above four thousand
JQF
Copy traffic JQF
1122:42
First STCA - between JQF and other traffic (during calls listed above)
1122:49
Second STCA – between JQF and AEM. Occurred as Melbourne Centre controller was providing traffic to the pilots of JQF (above)
1123:51
11:24:09
Third STCA appeared on controller display. Was assessed and acknowledged.
1124:16
Last updated data point displayed to controller prior to collision.
1124:20
Approximate time of collision
Preliminary report
Report release date: 23/04/2020
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
On 19 February 2020, at about 1055 Eastern Daylight-saving Time[1], a Beech Travel Air D95A aircraft, registered VH-AEM (AEM), departed Tyabb Airport, Victoria for an Instrument Flight Rules (IFR)[2] training flight to Shepparton via Mangalore, and return to Tyabb. On board were an instructor and student.
At 1111, the pilot of a Piper PA44-180 Seminole, registered VH-JQF (JQF) contacted air traffic control (ATC) to advise that the aircraft was taxiing for departure from Mangalore Airport. The pilot had submitted a flight plan for a round-trip IFR flight for Mangalore via Essendon and Shepparton. Also on board was an authorised testing officer, who was testing the pilot for an instrument flight rating.
AEM tracked as per the flight plan and, at 1117, began a descent from 6,000 ft above mean sea level (AMSL) for airwork at Mangalore. Radio communication with ATC indicated the airwork was to occur between 4,000 ft and ground level.
At 1119, the air traffic controller passed traffic information to AEM about JQF departing from Mangalore. At 1122, JQF made a departure call from Mangalore, advising ATC of a planned climb to 7,000 ft. ATC passed traffic information about AEM to the Seminole crew.
At 1124, Automatic Dependent Surveillance Broadcast (ADS-B)[3] data indicated the two aircraft collided approximately 8 km south of Mangalore Airport at approximately 4,100 ft (Figure 1). There were no witnesses to the collision, however another pilot in the area witnessed both aircraft descending immediately after the collision. All four pilots were fatally injured in the accident, and both aircraft were destroyed.
Figure 1: Flight path of AEM and JQF, and location of ground impact of both aircraft
Source: Google, modified by the ATSB
Context
Pilot information
All four pilots involved in the accident held the licences and medical approvals required to undertake the operations they were conducting.
The instructor on board AEM held an air transport pilot licence (aeroplane) and was a grade 1 flight instructor, with approvals to conduct instrument rating instruction and multi-engine aircraft class rating instruction. The instructor’s logbook indicated he had about 5,800 hours total flying experience. The student on this aircraft held a commercial pilot licence (aeroplane), and had passed the instrument rating theory exam. The student’s logbook indicated he had approximately 1,100 flight hours. This lesson was his second instrument training flight.
The examiner on board JQF held an air transport pilot licence (aeroplane), was a grade 1 flight instructor, and held a flight examiner rating to conduct a range of examinations, including for instrument ratings and multi-engine class ratings. He had about 21,000 hours flying experience. The pilot on this aircraft held a commercial licence (aeroplane), and had passed the instrument rating theory exam. This pilot’s logbook indicated she had approximately 220 hours of total flight experience. The test being conducted was for the purpose of issuing the pilot with both an instrument rating, and a multi-engine class rating.
Aircraft information
VH-AEM (Figure 2) was a Beech D95A Travel Air, twin-engine aircraft. It was manufactured in the United States of America in 1966 with serial number TD-682. It was first registered in Australia in 1967.
Figure 2: Beech Travel Air, registered VH-AEM
Source: Aircraft operator
VH-JQF (Figure 3) was a Piper PA44-180 Seminole, twin-engine aircraft. It was manufactured in the United States of America in 1979 with serial number 44-7995291. It was first registered in Australia in 1990.
Figure 3: Piper Seminole, registered VH-JQF
Source: Aircraft operator
Wreckage and impact information
Following the mid-air collision, JQF travelled for about 0.5 km before impacting an open field, while AEM continued in a northerly direction and impacted a lightly wooded area about 1.4 km from the collision point. Airborne debris liberated in the collision formed a further wreckage field that was located about 1.6 km to the north-north-east of the collision point and about 200m to the west of the Hume Highway.
Meteorological information
The forecast meteorological conditions for the Mangalore area indicated scattered[4] cloud at 2,000 ft above ground level (approximately 2,500 ft above mean sea level), with scattered stratocumulus cloud between 3,000 and 6,000 ft. Visibility was forecast to be greater than 10 km, and the wind from the south‑west at 25 knots.
At the time of the accident, the automatic weather station at Mangalore Airport, 8 km north of the collision location, recorded two cloud layers: one scattered at 3,467 ft AMSL and a second broken layer at 4,174 ft AMSL, (about the collision altitude).
Video taken by the Victoria Police Air wing (Figure 4) near the accident site at 1240, 1 hour and 16 minutes after the accident showed the base of a broken layer of cloud to be at approximately 4,050 ft AMSL with some lower patches of cloud also present.
Figure 4: View of cloud from the Victoria Police Air Wing helicopter
Source: Victoria Police
Aerodrome and airspace information
Mangalore Airport has an elevation of 467 ft. The airport was non‑controlled, and utilised a ‘Common Traffic Advisory Frequency’ (CTAF)[5]. The CTAF frequency was shared with three other aerodromes in the local area.
Surrounding the Mangalore CTAF was class G non‑controlled airspace. In class G airspace, air traffic controllers provide traffic information to IFR aircraft about other conflicting IFR and observed VFR flights.
Recorded data
Neither aircraft was equipped with a flight data recorder or cockpit voice recorder, nor were they required to be. One aircraft was carrying an iPad, which had AvPlan[6] software installed and operating at the time of the accident. This data was provided to the ATSB.
Both aircraft were fitted with transponders that broadcast ADS-B data. This information included the position and altitude of the aircraft and was received by Airservices Australia, as well as other third-party ADS-B receivers (FlightRadar24) and provided to the ATSB.
Radio transmissions on the CTAF were not recorded.
Further investigation
The investigation is continuing and will include further examination and analysis of:
weather conditions at the time of the accident
recovered radios from the aircraft
recorded radar data, as well as recorded area frequency calls and recollections of CTAF radio broadcasts.
pilot qualifications, experience and medical histories
aircraft maintenance and operational records
air traffic services actions, procedures and practices
traffic density in and around Mangalore Airport
classification of the airspace around Mangalore Airport
Class G and CTAF operational and communication processes and procedures around Mangalore Airport
visibility from both aircraft.
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Acknowledgements
The ATSB acknowledges the assistance of Victoria Police, and the Victorian Coronial Support Unit in supporting the ATSB’s on-site investigation team and providing information and support through the evidence collection phase of the investigation.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.