Derailment of passenger train ST23, Wallan, Victoria, on 20 February 2020

Final report

Report release date: 09/08/2023

Executive summary

What happened

On 3 February 2020, a fire in a signalling equipment hut at Wallan in Victoria resulted in damage to the signalling system on the standard gauge rail network operated by the Australian Rail Track Corporation (ARTC). Repair of the signalling system would take several weeks and ARTC commenced managing rail traffic over a 24 km section between Kilmore East and Donnybrook using administrative systems. The section was predominantly a single bi-directional track which included a crossing loop at Wallan.

Trains were initially being managed through this 24 km section under the existing train working protocols that limited train speeds to no more than 25 km/h. This speed limit led to significant delays and ARTC developed train working arrangements that would permit trains to operate at normal track speeds. For passenger trains, this was up to 130 km/h. The arrangements that were established used (paper-based) train authorities to give drivers permission to travel through the section without signals operational, and also required an accompanying qualified worker (AQW) to ride in the cab with the driver. The first train authority under these new arrangements was issued on the evening of 6 February.

After the initial loss of signalling, the crossing loop at Wallan was not used and the points at either end of the loop were then locked in their normal (straight) position. Then, on 20 February, trains were to be routed through the loop to clean contamination from the rail head in preparation for signalling system testing. Around mid-afternoon, the points at each end of Wallan Loop were changed to their reverse position to route trains through the turnout to the loop track.

That evening, NSW Trains (TrainLink) was operating XPT train ST23 from Sydney to Melbourne. Train ST23 entered the affected section at Kilmore East and after travelling about 15 km derailed in the turnout at the northern end of Wallan Loop. The derailment occurred at about 1943. As a result of the derailment, the leading power car of train ST23 overturned and slid on its side for some distance. The driver and the AQW in the driver’s cab of the power car did not survive the accident. Eight passengers were seriously injured,[1] and a reported 53 passengers and the 5 passenger services crew members sustained minor injuries.

What the ATSB found

The investigation found that train ST23 derailed due to its speed exceeding the infrastructure design speed by a significant margin. The train entered the turnout to Wallan Loop travelling at a speed of between 114 and 127 km/h following an emergency brake application a short distance before the turnout. The maximum permitted operational speed for the turnout was 15 km/h and the train could not negotiate the turnout at its higher speed.

There was no evidence identified to suggest that the driver was incapacitated leading up to the derailment, and no evidence to suggest a rolling stock or a track defect had contributed to the derailment.

Several scenarios that may have led to ST23 not slowing for the loop turnout were considered. The leading power car was not fitted with in-cab voice or video recording devices and the absence of information on the interactions within the driver’s cab reduced the certainty of this finding. On the balance of evidence, it was concluded that the driver of ST23 probably expected to remain on the straight track through Wallan and was operating the train with that expectation.

The driver had likely developed a strong expectation that ST23 would be travelling on the straight track through Wallan. The driver of ST23 had operated the XPT service through the location 8 times in the 12 days prior, and on all occasions the loop track at Wallan was locked out of service consistent with the arrangements not to use the crossing loop at Wallan while signalling was non-operational.

Information on the routing of ST23 through Wallan Loop on the evening of 20 February was provided to the driver in a modified train authority document given to them at Kilmore East. However, the train working arrangements that were established by ARTC on 6 February did not include protocols that would confirm the driver’s understanding of the authority and excluded the requirement for the driver to read back the train authority to the network control officer. Expectations based on past experience influence the perception of information and it is probable that the driver did not recognise the text changes made to the train authority from those issued to them on their 8 previous trips.

The train working arrangements that were established to manage traffic while the signalling system was not functioning deviated from ARTC network rules and there was ineffective management of the risks introduced by this deviation. There were several safety factors that increased safety risk including weaknesses in ARTC risk management, the train working arrangements, risk controls (including a reliance on manual processes), and stakeholder engagement. For the routing of trains through Wallan Loop on 20 February, it was concluded that there were several available and practical risk controls that were not used by ARTC.

Weaknesses were also identified in the distribution and collection of safety information. It was found that NSW Trains did not have a functioning process for obtaining safety critical information for its Victorian operations from the ARTC web portal (WebRAMS).

It was also found that the configuration of the driver’s cab contributed to the adverse outcome for the driver and AQW. The side door of the power car detached when the car overturned. This resulted in track ballast and earth entering the cab and trapping the driver and the AQW. Efforts by members of the train crew and emergency services to assist those trapped was thwarted by a lack of ground-level access to the cab. It was found that contemporary industry standards did not address the loading of the side-doors of driver cabs during overturn, and ground-level access to train crew trapped in an overturned vehicle.

Soon after the derailment, some passengers self-evacuated the train. It was found that the methods of providing safety information to passengers through briefings, onboard guides and signage did not provide reasonable opportunity for all passengers to have knowledge of what to do in an emergency. Systemic weaknesses in the training of passenger services crew by NSW Trains was also identified.

Other findings are made with respect to potential barriers to safety improvements on the ARTC rail network. These address shared risks between the rail infrastructure manager (RIM) and rolling stock operators (RSO) and the slow, and uncoordinated, adoption of technologies. There continues to be a high reliance on administrative controls and a slow take up of technological solutions by ARTC to improve safety.

What has been done as a result

ATSB identified 15 safety issues against which organisations were requested to advise on their proactive safety actions. The details of these actions, and ATSB comment on these actions, are described in the Safety issues and actions section of this report.

Six safety issues were allocated to ARTC. ARTC advised that it has introduced an updated management process for deviations from ARTC Network Rules (for planned or unplanned works). ARTC advised that this process required a risk assessment involving stakeholders, the development of appropriate controls for implementation by each stakeholder, and ARTC Executive approval of the risk assessment and plan. Three safety issues pertaining to network user engagement and distribution of safety information remained open, and updates will be provided on the ATSB website.

Six safety issues were allocated to NSW Trains. NSW Trains advised that it has developed new procedures for the daily access of the ARTC WebRAMS system for safety information and has also amended procedures to include confirmation of receipt of safety critical information by train crew prior to them starting their day of operations. NSW Trains also advised of changes to crew emergency response training, although 2 related safety issues remain open. The ATSB has made one recommendation to NSW Trains that it undertake further work to improve the methods used to provide safety information to passengers.

One safety issue was allocated to ActivateRail, a contractor to ARTC. Relevant to this safety issue, ActivateRail advised that it has introduced additional control processes pertaining to its participation in projects. ActivateRail also committed to ongoing and future risk management awareness training of its consulting and professional services staff.

The Rail Industry Safety and Standards Board (RISSB) has committed to consider the outcomes of this investigation in a review of the Australian Standards for body structural requirements (locomotive) and access and egress. The outcomes of the RISSB review of these standards will be reported on the ATSB website.

Safety message

Central to this occurrence was the breakdown of risk management processes following deviation from established network rules. Critical to successful risk management in degraded network conditions is the involvement of network users in the identification and assessment of emergent risks, and user participation in the development of appropriate risk controls.

This occurrence also highlighted an over reliance on administrative controls and the missed opportunities to use existing and emerging technologies to manage risk associated with human error. To improve safety outcomes, the rail sector must move faster and together in embracing technology to improve its management of safety risks.

 

The occurrence

Overview

On 20 February 2020, NSW Trains (TrainLink) was operating the express passenger train (XPT) designated ST23 from Sydney, New South Wales (NSW), to Melbourne, Victoria. Train ST23 was operating on the rail network managed by the Australian Rail Track Corporation (ARTC). For a 24 km section between Kilmore East and Donnybrook in Victoria, ARTC was managing rail traffic using temporary train working arrangements while it undertook repairs to the signalling system that had been damaged in early February.

Train ST23 entered the affected section at Kilmore East at about 1935 local time. At about 1943, and after travelling about 15 km into the affected section, ST23 derailed at the northern end of Wallan Loop. As a result of the derailment, the leading power car of ST23 overturned. The driver and an accompanying rail worker in the driver’s cab of the power car did not survive the accident. Several passengers were seriously injured, and a large number of passengers and the passenger services crew sustained minor injuries.

Prior to the occurrence

At about 2343 on 3 February 2020, ARTC identified that the centralised traffic control (CTC) signalling system had been disrupted around Wallan in Victoria. A subsequent investigation by ARTC determined that a road vehicle had struck overhead electrical wires in Wallan, resulting in a ‘power surge’ to the nearby signalling equipment hut. A subsequent fire in the hut resulted in extensive damage to equipment and cabling.

As a result of the damage to the signalling system at Wallan, ARTC commenced managing rail traffic through the affected section using caution orders and other safeworking rules. Under these arrangements, trains were required to proceed cautiously at a speed not exceeding 25 km/h, and as a result there were significant delays to rail services.

To reduce delays through this affected section, ARTC established train working arrangements that used train authorities[2] and permitted higher train speeds. The new arrangements commenced at 1900 on 6 February and the first train authority issued was at 2042 that day. This arrangement was used for the 24 km section between Donnybrook and Kilmore East (Figure 1).

Figure 1: Location of train working between Donnybrook and Kilmore East

Figure 1: Location of train working between Donnybrook and Kilmore East

The affected section was between signals within the passing lanes at Donnybrook and Kilmore East. Rail-km shown from Melbourne.

Source: Google Maps, annotated by CITS

Notification to network users of the change in train working was by a train notice[3] issued by ARTC. Train notice 266 (TN 266) describing the change was issued on 6 February, updated on 7 February, and further amended on 13 February. In the arrangements established, the turnouts at either end of Wallan Loop were set to their normal position for the No.1 track (the through route) and clipped in that position.[4]

For the train working arrangements established, ARTC did not impose any additional speed restrictions through the section. The maximum permitted speed for passenger trains travelling on the No.1 track through Wallan was 130 km/h.

On 19 February, TN 266 was supplemented with train notice 367 (TN 367) advising of a change at Wallan Loop. Trains were to be diverted through the loop (No.2 track) for a short period on 20 February. The purpose of routing trains through the loop was to remove any contamination that may have developed on the rail head of the No.2 track while it was not being used.[5] This was in preparation for signal system testing and re-establishment of the CTC signalling system.

Between 1453 and 1536 on 20 February, and with track protection in place,[6] the points at either end of Wallan Loop were manually reconfigured from their normal position to their reverse position.[7] This change meant that rail traffic travelling in either direction after this time would be diverted into the crossing loop (No.2 track). TN 367 reflected this change and also specified a speed limit of 15 km/h for entry into the loop, and a limit of 35 km/h when exiting the loop. On that same day between 1600 and 1837, track force protection was utilised about 1 km south (towards Donnybrook) of Wallan Loop for the laying of conduit.[8]

The first train to pass through Wallan Loop in this altered configuration was southbound V/Line train 8620. Immediately prior to 8620 departing Kilmore East, the network control officer (NCO) advised the driver that they were going to be the first train through Wallan Loop in the past 72 hours. This notification by the NCO was consistent with the NSW practice of advising drivers of the potential unreliability of track circuits if trains have not run on a track in the previous 72 hours, although in this instance the signalling system was not operating at Wallan Loop.[9] Train 8620 departed Kilmore East at about 1623 and its train authority was cancelled for its arrival at Donnybrook at 1647.

The second train through the loop was northbound V/Line train 8625. When stopped at Donnybrook, and during exchanges between the driver and the NCO, there was no mention by either party of transiting through Wallan Loop. The train departed Donnybrook at about 1857 and was in the affected section when ST23 arrived at Kilmore East. 

Train ST23 journey from Sydney to Albury

Passenger train ST23, operated by NSW Trains, was to be the third train through Wallan Loop under the modified train working arrangements. The train was comprised of leading power car XP2018, 5 passenger cars of varying configuration, and a trailing power car. It was a single-driver operation.

ST23 departed Central Station in Sydney at 0741 on 20 February 2020, just after the scheduled departure time of 0740. The train service was to travel through NSW, into Victoria, and to arrive at its final destination at Southern Cross Station (Melbourne) at 1830 that evening (Figure 2).

Figure 2: Train route from Sydney to Melbourne

Figure 2: Train route from Sydney to Melbourne

Source: Google Maps, annotated by CITS

The train proceeded south and arrived at Junee in southern NSW at 1452,[10] about 85 minutes behind schedule. There was a change of driver at Junee. The train departed Junee at 1456 and continued south, arriving in Albury on the NSW–Victorian border at 1637. There was a change in passenger services crew at Albury. The new passenger services crew comprised a passenger services supervisor (PSS), a crew member training for the supervisory role, and 3 passenger attendants.

Train ST23 journey from Albury

Train ST23 departed Albury at 1644, about 89 minutes behind schedule, and entered the Victorian section of its journey. After departing Albury, there was an announcement to passengers, tickets were checked, and the passenger services crew walked through the passenger cars checking door locks and equipment. Later, the driver was provided with a snack while the train was stopped at Wangaratta and the train departed that station at 1722, 87 minutes behind schedule.

Beyond Benalla, the focus of several of the passenger services crew was on meal activities in the buffet car. The crew described the journey as normal, although passengers were reported to be frustrated with the delays. ST23’s delay had originated prior to Junee.

At about 1840, the NCO at ARTC Network Control[11] contacted the driver of ST23 regarding a network alarm that had been received.[12] Later in the communication, the NCO advised the driver that ST23 would come into Kilmore East and wait until a V/Line train had passed.[13] As part of this communication, the controller mentioned that ‘you’re going via the loop there at Wallan’. The response from the driver did not reference the train’s route via Wallan Loop.

Train ST23 at Kilmore East

Train ST23 continued south before coming to a stand at about 1856 at intermediate home[14] signal KME28, which was displaying a stop indication. There was a standard-gauge passing lane at Kilmore East, with designated East and West Lines, and ST23 had been routed via the East Line (Figure 3).[15]

Figure 3: Kilmore East standard-gauge passing lane shown in black (not to scale)

Figure 3: Kilmore East standard-gauge passing lane shown in black (not to scale)

The schematic shows the track at Kilmore East including the passing lane. Only the signalling for the standard-gauge track is shown. NSW Trains’ services did not use the broad-gauge track.
Source: ARTC, modified and annotated by CITS

The driver of ST23 contacted the NCO at about 1904 and inquired when they might receive permission to proceed. ST23 was required to wait until the northbound V/Line train 8625 had cleared the single-line section.

At around this time, several rail workers were preparing for the arrival of ST23 at signal KME16 (at Kilmore East). These rail workers were to assist ST23 with the train working arrangements between Kilmore East and Donnybrook. Among these rail workers were an (in-field) signaller (referred to in this report as the signaller) and an accompanying qualified worker (AQW).[16] The AQW would accompany the driver from Kilmore East to Donnybrook and arrange the activation of level crossing protection at Wallan–Whittlesea Road just south of Wallan Loop.

ST23 was the first train that the signaller and AQW were to assist after commencing their shifts. The signaller had first arrived at Donnybrook at about 1830, and then travelled to Kilmore East to start their shift. The AQW had also first attended Donnybrook before travelling to Kilmore East. At the start of their shift, the AQW was provided with a copy of TN 367 and then briefed on the transit through the loop and the requirement to advise the driver.[17]

At about 1915, while ST23 was stopped at signal KME28, the signaller positioned near signal KME16 contacted the NCO to advise that they had come on shift and taken over from the previous signaller. During this call, train authority 17 (TA 17) for ST23 to proceed between Kilmore East and Donnybrook was issued to the signaller by the NCO. The NCO read TA 17 to the signaller, describing that the authority was issued in accordance with train notices 266 and 367, that the points at Wallan Loop were set and secured for No.2 track, and that there was a maximum speed entering the loop of 15 km/h and a maximum speed exiting the loop of 35 km/h. From this NCO dictation, the signaller completed their copy of the train authority form and then read the completed TA 17 back to the NCO. The NCO noted the time of the readback as 1920.

A condition affecting the network (CAN)[18] notice was then completed by the signaller under the instruction of the NCO. This notice was to warn train crew of the condition of the Wallan–‍Whittlesea Road level crossing protection, and that the protection was being manually operated. The CAN was designated number 7, and the readback of CAN 7 to the NCO by the signaller was noted by the NCO as being completed at 1921.

ST23 was held at signal KME28 on the East Line until the northbound V/line passenger train 8625 had transited the Donnybrook to Kilmore East single-line section, passed signal KME2, and was travelling along the West Line through Kilmore East. The V/Line train was clear of the single-line section by about 1925 and, soon after, the driver of ST23 was given permission by the NCO to proceed to home departure signal KME16,[19] still on the East Line within the Kilmore East location.

ST23 arrived at signal KME16 at about 1931. The train was met by several rail workers, including the signaller and the AQW. Shortly prior to the train’s arrival, the signaller gave documents TA 17 and CAN 7 to the AQW and briefed the AQW on their content. The AQW boarded the leading power car and joined the driver at the head of the train, and gave TA 17 and CAN 7 to the driver. It was intended that the AQW would accompany the driver for the 24 km section to Donnybrook. The XPT cab was not fitted with a cab voice recording facility (and was not required to be), and there was no record of the conversation between the AQW and driver.[20]

At about 1932, while the train was stopped at signal KME16, the driver and the on-duty NCO communicated via the train radio. This exchange included the NCO asking whether the driver had received all the paperwork, and the driver responding ‘yeah, authority 17 and CAN number 7 filled out ahh the same way it has been for the … rest of the time’.

During this communication between the NCO and driver, the NCO did not read the content of TA 17 to the driver, and the driver did not read back the content of TA 17 to the NCO.[21] The NCO commented ‘points all set for the loop’. The driver’s response to the controller did not reference transiting via the crossing loop (No.2 track) at Wallan. There was no communication between the controller and driver regarding the maximum speed of 15 km/h for entering Wallan Loop.

Derailment of train ST23

The train departed signal KME16 at about 1934 and entered the single-line section towards Wallan and Donnybrook. The line speed for the XPT between Kilmore East and Donnybrook was 130 km/h.[22] After departing from signal KME16, the speed of the train was increased and initially maintained between 100 km/h and 120 km/h.[23]

The AQW was to ensure that the active level crossing protection at Wallan–Whittlesea Road in Wallan was in place for the passage of the train.[24] A level crossing keeper (LCK)[25] was located at the crossing to activate the crossing protection. The AQW contacted the LCK by phone at approximately 1941, when the train was at about the 52 km mark. The LCK reported activating the crossing protection at Wallan–Whittlesea Road and confirmed its activation to the AQW. This phone call lasted about 53 seconds and the LCK did not recall anything unusual about the communications with the AQW. The call was completed when the train was about 4.5 km from the level crossing and 2.7 km from the entry to Wallan Loop.

The speed of ST23 then increased towards the line speed of 130 km/h as the train approached Wallan. At about 1943, ST23 was approaching the northern end of Wallan Loop when an emergency brake application was made. Brake cylinder pressure was recorded as commencing to rise when ST23 was between 153 and 50 m from the turnout.[26] This slowed the train a small amount before it entered the turnout travelling at a speed estimated to be between 114 and 127 km/h. The train was not able to negotiate the turnout to the No.2 track (loop) at this speed and derailed (Figure 4). The leading power car rolled onto its left side. The trailing 5 passenger cars remained upright although tilted by varying amounts, and the rear power car remained upright on the track.

Figure 4: Aerial photograph of derailment site

Figure 4: Aerial photograph of derailment site

Source: ATSB

Emergency response

At the time of the derailment, there were 155 passengers,[27] the driver, 5 passenger services crew members and the AQW on board the train. The driver and AQW were in the driver’s cab, a passenger services crew member was in the second passenger car and the other 4 passenger services crew members were in the buffet car (the third passenger car).

After the train came to a stop, the passenger services supervisor (PSS) called the train crew on a hand-held radio and received responses from the other members of the passenger services crew. However, the driver did not respond and the AQW was not in possession of a NSW Trains issued radio.

Two members of the passenger services crew then commenced raising the emergency using their hand-held radios.[28] The crew members made several emergency calls seeking assistance, advising that the XPT had derailed and requesting that all trains stop.

A V/Line signaller based at Wallan heard the emergency calls and responded within about 25 seconds of the first recorded ‘emergency emergency emergency’ radio broadcast by the passenger services crew. On confirming the nature of the emergency, the Wallan signaller contacted V/Line network control at Centrol.[29] Centrol then contacted ARTC Network Control at Junee at about 1945, relaying the information that the XPT may have derailed. During this communication, Centrol also advised ARTC Network Control that V/Line would stop trains on the broad-gauge tracks that ran parallel to the standard gauge. In response to the Centrol call, ARTC sought confirmation of what had happened and initiated its response.

Emergency services recorded the first ‘000’ call for assistance from a train passenger, time-stamped 1945:06.[30] This was followed by a series of calls from other passengers, members of the passenger services crew, and members of V/Line and ARTC.

Around this time or soon after, some passengers started to self-evacuate from the train prior to the passenger services crew receiving confirmation that rail traffic in the area had been stopped. Although passengers were told to vacate adjacent tracks and leave their belongings behind, video footage and photographs showed that there were mixed levels of compliance with these instructions.

In response to the emergency, passenger services crew undertook a range of tasks including managing passengers that had evacuated onto the track and attending to passengers on the train. At different times, three passenger services crew members also went to the leading power car to check on the driver and AQW. Two crew members separately entered the power car through its right-side cab door, accessible from the ‘top’ of the car laying on its left side. Finding it difficult from within the cab to assist the driver and AQW, who had both been trapped by track ballast and earth that had entered the cab, the crew attempted to break the cab’s windscreen to gain access from outside.[31] However, attempts by the passenger services crew to gain this ground-level access from outside the cab were unsuccessful.

The first emergency service to arrive on site was Victoria Police at about 2003, followed by further emergency, medical and fire services. However, both the driver and the AQW did not survive.

As a result of the movement of the passenger cars during the derailment sequence, 8 passengers were seriously injured and a reported 53 received minor injuries.[32] The 5 passenger services crew members also received minor injuries.

Context

Train operator

Train ST23 was operated by NSW Trains trading as NSW TrainLink.[33] NSW Trains was established in 2013 as part of a restructure of rail arrangements in New South Wales (NSW). NSW Trains operated regional rail and coach services in NSW and interstate rail passenger services between Sydney (NSW) and the east coast capital cities of Melbourne (Victoria) and Brisbane (Queensland).

In accordance with the Rail Safety National Law (RSNL), NSW Trains was an accredited rolling stock operator (RSO), that was defined (in part) as having ‘… effective control and management of the operation or movement of rolling stock on rail infrastructure for a railway…’.[34] As an RSO, NSW Trains was also defined in the RSNL as a rail transport operator and had defined safety duties.[35]

Train information

The XPT (Express Passenger Train) ST23 operating on 20 February 2020 was comprised of 7 vehicles (Figure 5). The leading 3 vehicles were manufactured by ABB Transportation in Dandenong, Victoria, and were commissioned in 1993. The trailing 4 vehicles were manufactured by Comeng in Granville, NSW, and were commissioned between 1981 and 1984. The fleet of XPT vehicles was maintained by Sydney Trains.[36]

Figure 5: Train configuration

Figure 5: Train configuration

Source: Vehicle images supplied by Sydney Trains, annotated by CITS

The XPT was first introduced into service in 1982 and was based on the InterCity 125/Class 43 design used in the United Kingdom. The power car included a forward driver’s cab that was located ahead of a compartment housing propulsive machinery. Cab features included side doors for primary access (fitted on the left and right sides of the driver’s cab), a rear door to the machinery space, the driver’s seat that was positioned slightly left of the car centreline, and a second seat that was located to its right (Figure 6).

Figure 6: Power car layout and cab seat arrangement

Figure 6: Power car layout and cab seat arrangement

Source: RailCorp (NSW Transport), annotated by CITS

A post-derailment review of the condition of the ST23 rolling stock did not identify any adverse rolling stock condition or defect that was likely to have contributed to the derailment. The review involved inspections, testing and an examination of maintenance records (Appendix A).

Inspections were conducted at several locations and included observations at the derailment site, inspection of vehicles XP2000 and XFH2108 at the Sydenham Maintenance Centre, and inspection of vehicles XP2018, XAM2179, XL2229, XBR2155 and XF2201 at the Auburn UGL facility. Post-occurrence testing conducted by Sydney Trains and witnessed by the Office of Transport Safety Investigations (OTSI) included testing of braking, vigilance and communication systems.

Personnel information

Driver

The driver of train ST23 had been associated with the rail industry for about 40 years, employed in a range of roles including driving, training, and management. They returned to driving in mid-2016 as a regional driver with NSW Trains and were assessed as competent on the route between Junee and Melbourne in July 2019. The driver was qualified to operate the XPT train and had completed continuation training (safeworking).

Typically when driving the XPT services between Junee and Melbourne, they would drive the Junee to Melbourne leg of the Sydney to Melbourne service and, following a period of rest in Melbourne, drive the return journey to Junee. After the commencement of train authority working through Wallan on 6 February 2020, they drove the Junee–Melbourne–Junee round trip (including a rostered rest period in Melbourne) 4 times between 8 and 19 February, including several trips after all signals within the section had been extinguished.

On 20 February, the driver’s shift commenced in Junee at 1315 and their scheduled sign-off in Melbourne was at 1845.[37] As a result of the delayed arrival of ST23 into Junee (85 minutes), the commencement of driving duties were delayed (to 1456) and would have led to a late arrival in Melbourne. A review of the driver’s roster and recent history found there was insufficient evidence to conclude that the driver was experiencing a level of fatigue that would adversely affect their performance (Appendix B).

The driver was medically assessed as fit for duty (unconditional) in accordance with the requirements for a Category 1 Safety Critical Worker[38] and no pre-existing health issues were identified that were likely to have contributed to the occurrence. Further, toxicology results did not identify any substance that may have impaired performance.

There was no evidence of any phone calls to or from the driver or messages sent from the driver’s phone in the period immediately prior to the occurrence.

Passenger services crew

There were 5 passenger services crew members on board ST23, one more than the normal complement. Their years of service ranged between 1 and 13 years. The passenger services crew consisted of:

  • a passenger services supervisor (PSS) responsible for overall supervision of the passenger operations and the management of passengers in an emergency[39] 
  • a senior passenger attendant (SPA) responsible for the buffet operations and ticket sales
  • a passenger attendant 4 (PA4) responsible for assisting the SPA in the buffet, and assisting with general passenger duties along the train
  • a passenger attendant 2 (PA2) responsible for general passenger duties along the train
  • an additional crew member who was shadowing the PSS as part of on-the-job training.
The accompanying qualified worker

The accompanying qualified worker (AQW) on board ST23 was employed by Programmed, a labour-hire organisation that provided skilled workers across a range of industries including transport. Programmed supplied several personnel to ARTC from 4 February 2020 to assist with the management of rail traffic between Donnybrook and Kilmore East.

The AQW was certified to Track Protection Coordination level 3.2, most recently renewed in March 2019. They had completed several safeworking related training modules including (in 2017) the units TLIC2081 (Pilot rail traffic within work on track authority limits)[40] and TLIL3083 (Implement a track work authority and manage rail traffic through worksites).

The AQW had been with Programmed since 2006. Records[41] indicated that the worker had been engaged by several rail operators in Victoria in various roles, and in recent years primarily as a track force protection coordinator or hand signaller. There were no records identified of previous experience in performing the role of an AQW, or in train pilotage.

The AQW had been engaged at Wallan from 4 February, primarily in the role of level crossing keeper (LCK) at the Wallan–Whittlesea Road level crossing. All shifts from February were night shifts that mostly commenced at about 1900. On 20 February, the AQW had just commenced the night shift. A review of the AQW's roster and recent history found there was insufficient evidence to conclude that the AQW was experiencing a level of fatigue that would adversely affect their performance. The AQW was rostered off duty from 16 to 18 February and conducted a night shift commencing 19 February from 1900 to 0500.

The evening of 20 February was the first time this rail worker performed the role of an AQW, and ST23 was to be their first train that evening. Reporting in at Donnybrook for the start of their shift, the AQW received a briefing from a more senior AQW on the tasks to be performed, and the conditions of transiting through the loop described in TN 367. They then travelled to Kilmore East for the start of the shift.

The AQW was medically assessed as fit for duty (unconditional) in accordance with requirements for a Category 1 Safety Critical Worker and no pre-existing health issues were identified that were likely to have contributed to the occurrence. Further, toxicology results did not identify any substance that may have impaired performance.

The network control officer

The network control officer (NCO) on duty at the time of the derailment had worked as a network controller since 2004 and was qualified on all the control boards at ARTC Junee network control. This was the first shift that this NCO had experienced the train authority process being used between Donnybrook and Kilmore East.

The NCO came on shift at about 1445. The NCO advised that they received instruction on how the train authority forms were to be used from the NCO that was previously on shift. A conversation also took place between an ActivateRail representative[42] and the NCO at 1530, during which the NCO was advised of the correct train authority forms that reflected train notice 367 (TN 367). At 1554 a further conversation took place between the NCO and the ActivateRail representative for the issuing of train authority 15 to train 8620, during which the NCO stated that they were ‘still trying to get my head round all of this’.

The NCO had been issued with the new train authority form for use under TN 367 and completed that form with the correct information in train authority 17 (TA 17) for the passage of train ST23. At interview, the NCO referred to the AQW as a ‘pilot’ and advised that they had not spoken to the ‘pilot’ that was issuing TA 17 for service ST23.

The signaller

The (in field) signaller involved in the receipt of TA 17 was employed by labour-hire firm Australian Recruiting Group (ARG Rail) and had been contracted by ActivateRail to perform the duties of a signaller on this project. They were certified to perform signalling duties and were rostered on night shifts from 1900 to 0700. Their first shift on this project was on 16 February and 20 February was their fifth consecutive night shift. At interview, the signaller also referred to the AQW as a pilot.

On the evening of 20 February 2020, the signaller, positioned at Kilmore East, was issued TA 17 and the condition affecting network (CAN) notice 7 from the NCO commencing at 1917. The signaller read back TA 17 to the NCO at 1920, and the train authority and CAN notice were then passed from the signaller to the AQW. The signaller remained at Kilmore East until the AQW had boarded train ST23. The signaller did not board the train or speak to the driver (consistent with the normal process implemented by other signallers involved in the train working arrangements). The signaller then left Kilmore East, by car, for Donnybrook with the intention of receiving the next train authority for a northbound freight train travelling between Donnybrook and Kilmore East.

Infrastructure

Network manager

ST23 was operating on the rail network managed by the Australia Rail Track Corporation (ARTC). This management included track and signalling infrastructure and rail traffic control. ARTC was created following a Commonwealth and mainland State Governments’ Intergovernmental Agreement in 1997 for the establishment of a ‘one-stop shop’ for rail operators seeking access to the standard gauge rail network between Brisbane and Perth.[43] Established in 1998, ARTC was a Government Business Enterprise fully owned by the Commonwealth of Australia.

In Victoria, the standard gauge infrastructure was leased by ARTC from VicTrack.[44] Under the agreement, ARTC was required to maintain, replace and repair the leased infrastructure to a level where its condition was no worse than it was at the commencement of the lease. There was also provision in the lease agreement that, in addition to maintenance, repair and renewal works, ARTC could undertake capital works at its own cost and risk.

In accordance with the RSNL, ARTC was an accredited rail infrastructure manager (RIM), that was defined (in part) as having ‘…effective control and management of the rail infrastructure…’.[45] As a RIM, ARTC was also defined as a rail transport operator in the RSNL and had defined safety duties.[46] ARTC was also accredited as a rolling stock operator.

Track

The XPT service was running on the standard-gauge interstate track that connected Sydney and Melbourne. The standard-gauge track between Donnybrook and Kilmore East was a single, bi‑directional line used by the XPT, V/Line passenger services and rail freight.

On this single-line section, there was a 1,550 m crossing loop located at Wallan (Figure 7). The northern entry to this loop was located about 1.8 km north of Wallan–Whittlesea Road. Towards the southern end of Wallan Loop was Wallan Railway Station, which serviced broad-gauge passenger trains operated by V/Line.[47]

Figure 7: Standard-gauge track and signals at Wallan Loop (not to scale)

Figure 7: Standard-gauge track and signals at Wallan Loop (not to scale)

The schematic shows the standard-gauge track at Wallan including the crossing loop. The standard-gauge tracks are shown in black, and the adjacent broad-gauge tracks in red. Only the signalling for the standard-gauge track is shown in this figure.
Source: ARTC, modified and annotated by CITS

Wallan Loop northern turnout

The turnout at the northern end of the Wallan Loop was located at the 49.058 km mark (Figure 8). The turnout design was reported by ARTC as being rated for a train speed of 25 km/h (for entry into the loop) and the maximum operational speed was 15 km/h in accordance with the ARTC operating code of practice.[48] It consisted of 60 kg/m rail on timber bearers, with a cast V-crossing. Following the left turnout, the right curve (in the direction of travel) along the No.2 track had a radius of about 420 m.

Figure 8: Elevated view of northern turnout to No. 2 track at Wallan Loop

Figure 8: Elevated view of northern turnout to No. 2 track at Wallan Loop

The photograph shows the turnout and signal WLN8 on 21 February 2020 after the passage of train ST23 and its derailment. The points are set for the No.2 track as they were at the time of the derailment.

Source: ATSB

For southbound trains approaching the northern end of Wallan Loop, there was a downhill gradient of approximately 1:150 and the track was tangent (straight) for about the final 800 m of the approach to the turnout with trees lining the rail corridor. The approach track was comprised of 60 kg/m rail, fastened to concrete sleepers.

Wallan–Whittlesea Road level crossing

The Wallan–Whittlesea Road level crossing was located just south of Wallan Loop (Figure 9).

Figure 9: Aerial view of Wallan–Whittlesea Road level crossing and surrounds

Figure 9: Aerial view of Wallan–Whittlesea Road level crossing and surrounds

Source: Pass Assets, annotated by CITS

The Wallan–Whittlesea Road level crossing was fitted with active protection that included boom barriers, flashing lights and bells. While the signalling system at Wallan was being repaired, the crossing protection was manually activated by a level crossing keeper (LCK) located at the crossing. The operation of the crossing protection for each train was initiated by a call from the AQW travelling on the approaching train.

Signalling

Approach from Kilmore East towards Wallan Loop

Approaching from Kilmore East, the first signal to advise of the state of the turnout at Wallan Loop was signal ES1712 located about 2.7 km prior to the northern turnout to Wallan Loop.[49] At the time of the derailment, signal ES1712 was extinguished and was fitted with a black cross near its base to indicate that it was not functioning (Figure 10).

Figure 10: Signal ES1712 following derailment, non-operational and with cross affixed

Figure 10: Signal ES1712 following derailment, non-operational and with cross affixed

Source: CITS

Signal ES1712 was a 3-position automatic signal. When operational, the signal would provide an indication of any speed reduction required approaching the next signal (WLN8) at Wallan Loop. A normal speed warning indication (yellow over red) at ES1712 would require a driver to be prepared to stop at the next fixed signal (WLN8) at the entry to Wallan Loop. If the train was signalled for the straight (No.1 track) at Wallan Loop, ES1712 would show a clear normal speed indication (green over red).

Wallan Loop Up home signal

Entry to the northern end of Wallan Loop was normally controlled by signal WLN8. At the time of the derailment, signal WLN8 was extinguished and was fitted with a black cross near its base to indicate that it was not functioning (Figure 11).

Signal WLN8 authorised train movements in the Up (towards Melbourne) direction. When operational, signal WLN8 could provide several indications (Figure 11). For train movements routed on the straight track at line speed, signal WLN8 would show a clear normal speed indication. For movements into the crossing loop, the low speed caution indication was used, which meant that trains must not exceed 15 km/h. Trains could also be signalled to stop at signal WLN8.

Figure 11: Signal WLN8 possible indications (left) and on day of occurrence (right)

Figure 11: Signal WLN8 possible indications (left) and on day of occurrence (right)

 

The figure shows the possible indication for signal WLN8 (when operational), and a photograph of the signal extinguished. The photograph of signal WLN8 also shows the black cross that was attached to the signal post.
Source: CITS

Broad-gauge signal near Wallan Loop entry

A broad-gauge distant signal was located about 45 m to the north of WLN8 and was probably indicating a proceed (green) aspect at the time ST23 passed (Figure 12).[50] This broad-gauge signal did not apply to the operation of ST23, which was running on the standard-gauge line.

Figure 12: Probable aspect of broad-gauge signal at the northern end of Wallan Loop

Figure 12: Probable aspect of broad-gauge signal at the northern end of Wallan Loop

The figure shows the approach to the Wallan Loop turnout. The image has been modified to show the extinguished state of standard gauge signal WLN8 and the probable proceed (green) indication of broad-gauge distant signal at the time of the derailment. In this image, the points are set for the straight and the black cross is not fitted to the base of signal WLN8 as the image was taken prior to the signalling failure.
Source: V/Line training video, with signal aspects modified and annotated by CITS

Environmental conditions

The conditions at the derailment location were dry. At 1930 at the nearest weather station, located at Kilmore Gap,[51] the temperature was recorded as 13°C, and the wind was from the south at 32 km/h. These weather conditions were unlikely to have been a factor in this occurrence.

The derailment occurred about 30 minutes before sunset. At 1943 at Wallan, the sun was at an azimuth[52] of 259°48'28" and altitude[53] of 5°02'59".[54] The direction of travel was 223° from true north, meaning the sun was about 36° to the right of the driver’s direct view ahead and low in the sky.

Photographs taken soon after the derailment showed a mostly cloud-covered sky with a break in the clouds on the southern horizon towards which ST23 was travelling. The sky near the horizon was therefore probably bright (with possible sun glare) when train ST23 approached Wallan. However, the circumstances of this occurrence do not suggest that visibility approaching Wallan Loop was a factor in the overspeed of ST23.

Management of rail traffic between Donnybrook and Kilmore East

Background

Late on 3 February 2020, ARTC identified that signalling had been disrupted around Wallan due to a fire in the signalling equipment hut. As a result of the damage to the signalling system, ARTC commenced managing rail traffic through the section using caution orders and other safeworking rules, consistent with the ARTC Code of Practice for the Victorian Main Line Operations (TA20). The rules associated with caution orders meant that trains were restricted to speeds not exceeding 25 km/h, which contributed to service delays of probably at least 45 minutes.[55]

To reduce delays, ARTC sought an alternative method of managing trains in the 24 km section between the passing lanes at Donnybrook and Kilmore East. The use of caution orders under the CTC safeworking system was then replaced with a method using train authorities that permitted train speeds up to normal line speed. Train authorities had previously been used by ARTC during infrastructure commissioning activities.

In early February, ActivateRail[56] had been engaged by ARTC to assist with a safeworking solution to improve the passage of rail traffic between Donnybrook and Kilmore East. The scope of its services included the development and management of the safeworking solution and the provision of qualified signalling personnel for its implementation. ActivateRail in turn engaged ARG Rail for the provision of an additional 3 qualified signallers.

ARTC also sourced personnel from labour-hire firm Programmed to assist with the implementation of the train working arrangements. Contracted workers included accompanying qualified workers (AQWs), car drivers (to transport personnel), level crossing keepers (LCKs), and track force protection staff.

Train notice 266 description of train working arrangements

Initial issue of Train Notice 266

The use of train authorities between Donnybrook and Kilmore East in February 2020 was notified by train notice 266 (TN 266), issued on 6 February 2020 and effective from 1900 on that day (Appendix C). The train notice was a typed document of 6 pages and provided the following introduction to the change of conditions:

TRAIN AUTHORITY WORKING DONNYBROOK PASSING LANE TO KILMORE EAST PASSING LANE:
----------------------------------------------------------------------------------
Owing to signalling disarranged at Wallan Loop, commencing 1900hrs on Thursday 06/02/2020, rail traffic will operate by means of Train Authority issued by the ARTC Network Controller between signal DBK6 and DBK18 Donnybrook Passing Lane, and signals KME4 and KME16 at Kilmore East Passing Lane.
All signalling between Donnybrook Passing Lane and Kilmore East Passing Lane will be disarranged and the Train Authority single line section will be Donnybrook Passing Lane to Kilmore East Passing Lane.

TN 266 advised the details of the signals that were disarranged, and that black crosses were affixed to the posts of disarranged signals. TN 266 advised that within the affected section:

It should be noted that the signal may be lit and any aspect displayed may be ignored provided the driver of the rail movement is in possession of a Train Authority as detailed in this Train Notice.[57]

TN 266 also advised that the points at either end of Wallan Loop would be placed in the hand‑operating position and clipped in the normal (straight) position, and that signage would be installed at each end of the section advising of the transition between CTC and train authority working.

TN 266 discussed the roles of the various parties and advised:

ARTC NETWORK CONTROLLER
-----------------------------------------------
The ARTC Network Controller is responsible for ensuring the track is safe for traffic prior to each rail movement and issuing a Train Authority for a rail movement to proceed between Donnybrook Passing Lane to Kilmore East Passing Lane.
SIGNALLER
-----------------
A signaller will attend Donnybrook Passing Lane, or Kilmore East Passing Lane to receive a Train Authority and CAN from the ARTC Network Controller and issue it to the driver of each rail movement.
The signaller will deliver the Train Authority and CAN to the driver of the rail movement as required.
ACCOMPANYING QUALIFIED WORKER
-------------------------------------------------------
All rail movements operating between Donnybrook Passing Lane to Kilmore East Passing Lane during the period of the Train Authority Working will be provided with an Accompanying Qualified Worker who will advise the driver of the rail movement the activities occurring and the affected infrastructure.

TN 266 further specified the processes to be used for the issuing of the train authority to the driver. It described a requirement for the (in-field) signaller to read back the contents of the train authority to the NCO, and for delivery to the driver TN 266 stated:

The signaller may then hand the Train Authority to the driver and the driver must sign for the Train Authority on the butt of the form. The signaller will deliver the Train Authority to the driver of the rail movement as required.

TN 266 also described the processes for the issuing of a condition affecting the network (CAN) notice, which was required because the Wallan–Whittlesea Road level crossing protection was not operating normally.[58] The described process included the signaller delivering the CAN to the driver.

For the passage through the section under the train working arrangements, TN 266 stated:

RAIL MOVEMENT PASSAGE THROUGH SECTION
----------------------------------------------------------------------
Prior to entering the section, the driver must verify the Train Authority with the ARTC Network Controller.
The Accompanying Qualified Worker must also board the locomotive and once the Train Authority has been verified, the Accompanying Qualified Worker must advise the train crew of the work activities and that details of the non-operational level crossings.
The rail movement may proceed through the section in the normal manner.
As the movement approaches the Wallan - Whittlesea Rd level crossing at Wallan Loop. The Accompanying Qualified Worker must contact the level crossing keeper and advise of the rail movements approach, and when advised, the level crossing keeper operate the test switch to activate the level crossing and provide the driver the ‘all clear’ hand signal.
Changes to train notice 266

TN 266 was updated and reissued on 7 February. This amended notice introduced reference to the arrangements being in exception of a rule within TA20 and stated:[59]

SIGNALLING DISARRANGED
--------------------------------------------
Rule 5, clause b Section 5 of TA20 will not apply for the disarranged signals and the signals will have a black cross affixed to the signal post and the signal may be lit.
The following signals are disarranged and have a black cross affixed to the post of the signal…

TN 266 was further amended and re-issued by ARTC on 13 February 2020 (Appendix D). Amendments included:

  • removal of the advice that signals in the section may remain lit[60]
  • addition of text advising that ‘Repeat Back of the Train Authority is not required to be undertaken by the driver of the rail movement’
  • replacement of ‘The rail movement may proceed through the section in the normal manner’ with ‘The rail movement may proceed through the section up to track speed as advised by the Accompanying Qualified Worker’
  • addition of the instruction that ‘The driver must approach the level crossing with caution, prepared to stop short of the crossing unless the ‘all clear’ hand signal has been provided’
  • that Rule 1, Section 3, did not apply during Train Authority Working.[61]
Train authority form

A train authority form was prepared for use as part of the process described in TN 266 (Appendix E). This form was then to be completed by the NCO and the (in-field) signaller.

Application of train notice 266

In-practice application of TN 266

The method applied for issuing a train authority to a driver travelling in the section between Donnybrook and Kilmore East involved the on-duty ARTC NCO at Junee, an in-field signaller (the signaller) and an AQW. Key steps used by these parties in practice were:

  • The NCO and signaller were both provided with train authority forms to be used under TN 266 (Appendix E).
  • The signaller positioned themselves at whichever end of the Donnybrook–Kilmore East section that was to receive the next train.
  • Prior to the arrival of the next train, the signaller contacted the NCO to obtain details specific to the next train movement and was issued with a train authority.[62] The issuing process involved the NCO dictating the details of the train authority to the signaller and the signaller completing the form accordingly.
  • The signaller then read back the completed train authority to the NCO to verify its contents.
  • A CAN notice was also completed by the signaller under the instruction of the NCO.[63]
  • The signaller gave the completed train authority and CAN notice to the AQW and, on the train’s arrival, the AQW boarded the driver’s cab of the train. There was no contact between the signaller and the driver of the train.
  • Once on board, the AQW gave the train authority and CAN notice to the driver. The driver then contacted the NCO to verify the train authority. ARTC network control required the driver to verify the train authority to the NCO by its number only. There was no expectation that the driver would read the content of the train authority to the NCO, and no provision made on the train authority form for the driver to sign the form.
Train authority statistics

Between 6 and 20 February, 255 train authorities were issued for the section between Donnybrook and Kilmore East; 126 were issued at Donnybrook and 129 at Kilmore East.[64] Two of these authorities were cancelled owing to errors, one at each location.

Of the 255 train authorities issued, 55 were issued to XPT drivers, with 8 being issued to the driver of train ST23 prior to the day of the derailment. TA 17 was the ninth train authority that the driver had received. Drivers of other (non-XPT) passenger trains received 59 train authorities.

There were several instances during the two weeks where the signaller was issued a train authority for the single line section between Donnybrook and Kilmore East prior to the previous train authority for the single line section being cancelled. This was contrary to the instructions of TN 266.

Between 6 and 20 February, there were 21 NCOs and 5 signallers involved in the issuing of the authorities.

Driver readback statistics

Even though the train working arrangements did not specify a requirement for drivers to read back the train authority to the NCO, over a quarter of V/Line drivers and some others read the train authority back to the controller. The proportion was about the same before and after the (13 February) amendment of TN 266 that stated explicitly that readback was not required.

The driver of ST23 read back the train authority on their first journey under the altered train working arrangements. On subsequent trips, this driver did not read back the train authority and verified the authority by stating its number.

The reaction of NCOs to driver readback varied; on some occasions they allowed it to continue, and on other occasions they indicated to the driver that the readback was not necessary. At 1322 on 20 February 2020, when a V/Line driver was repeating back the train authority, the NCO on duty on the shift prior to the derailment, advised the driver that they did not need to repeat back. When the driver continued to repeat back the message, the NCO attempted to talk over the driver’s repeat back and instructed the driver to ‘standby’.[65] The driver continued to repeat back and advised the NCO that they were of the understanding that a repeat back to the controller was required.

Other operator queries and feedback

On establishment and the subsequent use of the alternative train working arrangements, there was disquiet within some sectors, and concern that the arrangements introduced were outside the established operating rules of TA20. The expressed concerns were mostly amongst V/Line drivers. The following is a selection of relevant actions and concerns on the train working arrangements in place:

  • On 7 February, a northbound NSW Trains driver queried the wording in TN 266 that indicated that drivers should disregard signals between signals DBK8 and KME2. The driver advised the on-duty NCO that DBK8 would be facing trains travelling in the other direction.[66] The NCO advised they would raise the matter, although there was no subsequent change to this part of TN 266.
  • On 10 February, a V/Line driver advised ARTC train control that that they would not pass signal WLN8 at stop (that was still lit), as they believed they could not treat it as a signal that could be disregarded. The driver requested separate authority to proceed, or for the lights in the signal to be extinguished, leading to a long delay in train operations through the section. The NCO advised that the instructions in the train notice covered the workings and they would not issue an additional authority as they believed this would be a second authority for the same section. All signals within the section were subsequently extinguished, and TN 266 was revised on 13 February with the text ‘the signal may be lit’ removed.
  • On 11 February, a V/Line driver made an inquiry to their management as to why ARTC had implemented train authority working when TA20 section 25.1d did not allow for such use of train authorities.
  • On 12 February, a V/Line driver advised the on-duty NCO that they had been instructed by their superiors to travel through the section at 25 km/h ‘due to the rule book’. TN 266 was reissued on 13 February with the text ‘Rule 1, Section 3, did not apply during Train Authority Working’ added and the text ‘The rail movement may proceed through the section in the normal manner’ in the original notice replaced with ‘The rail movement may proceed through the section up to track speed as advised by the Accompanying Qualified Worker.’
  • On 14 February, a V/Line driver requested that the signaller give them the train authority directly (as stated in TN 266) rather than via the AQW. This required the signaller (who had by that time departed the handover position) to return to Kilmore East to hand the train authority directly to the driver.

Train notice 367 description of changed conditions

Details of notice

Train Notice 367 (TN 367) (Appendix F) was issued on the evening of 19 February 2020 and contained additional instruction to TN 266. In relation to the changed conditions at Wallan Loop, the notice advised:

Trains Operating Via No. 2 Track Wallan Loop
----------------------------------------------------------------------------------
In addition to instructions contained in Train Notice 266 / 2020 issued on 13/02/2020 the following temporary alteration to working will apply.
On Thursday 20 February 2020 between 1430 hrs and 2130 hours, all trains will operate via No. 2 track at Wallan Loop, in the Donnybrook to Kilmore East, Train Authority Single Line Section.
At approx. 1400hrs the TFPC[67] will obtain a Track Warrant between Signal DBK8 at Donnybrook and KME4 at Kilmore East and upon Stop Boards being erected at Wallan Loop, the Safeworking Manager will set points 3 at the Melbourne end of Wallan Loop, and Points 7 at the Kilmore East end of Wallan Loop to the reverse position and then reapply the point clips and secure the point clips with special padlocks.

TN 367 also provided information on what would be in the train authority with the note:

NOTE: POINTS AT WALLAN LOOP SET AND SECURED FOR NO. 2 TRACK
MAXIMUM SPEED ENTERING WALLAN LOOP 15KPH
MAXIMUM SPEED EXITING WALLAN LOOP 35KPH UNTIL TRAIN HAS CLEARED POINTS

At the conclusion of TN 367 was the following special note:

SPECIAL NOTE:
# The maximum speed for trains entering Wallan No. 2 track and is 15Kph until the whole of the train has cleared the points, and
# The maximum speed for trains exiting Wallan No. 2 track is 35Kph until the whole of the train has cleared the points.
The Accompanying Qualified Worker must remind train crews of trains that the train will operate via No. 2 track at Wallan Loop and the speed limits required.[68]
A separate train notice details testing of signalling at Wallan after which normal main line running will resume.

The instruction in TN 367 on the maximum speed for entering Wallan Loop was not documented as a temporary speed restriction.[69] Therefore, a CAN warning for the 15 km/h speed limit at entry to Wallan Loop was not issued.

Train authority form for transit through Wallan Loop

A new train authority form was prepared for use by NCOs and (in-field) signallers during train transit through the loop (Appendix G). The form included the additional note that:

NOTE: POINTS AT WALLAN LOOP SET AND SECURED FOR NO. 2 TRACK
MAXIMUM SPEED ENTERING WALLAN LOOP 15KPH
MAXIMUM SPEED EXITING WALLAN LOOP 35KPH UNTIL TRAIN HAS CLEARED POINTS

Distribution and receipt of TN 367

ARTC distribution

ARTC procedures defined the processes to be followed for preparing, reviewing, approving and issuing operational notices (including train notices) on the ARTC network.[70] Different processes applied to different parts of the ARTC rail network. For its NSW and Queensland network, the ARTC procedures for distribution of operational notices specified direct transmission to selected internal and external stakeholders.

For Victoria, South Australia and Western Australia, approved operational notices were published on the ARTC WebRAMS (Rail Access Management System) portal.[71] Standing train notices were specified as being uploaded to this portal at approximately 1800[72] each evening. There was no specified timeframe in which a notice was to be issued prior to it coming into effect.[73] Access to WebRAMS was available to ARTC customers and stakeholders via an allocated User ID system. For rail operators operating in Victoria, the onus was therefore on them to access ARTC safety notices through this portal.

Formal distribution of TN 367 by ARTC to rail operators was via the WebRAMS portal. ARTC reported that TN 367 was uploaded to WebRAMS as part of an automated system update at 1845[74] on 19 February 2020.

In addition to the formal release (on WebRAMS), a draft of TN 367 was forwarded to V/line for comment at about 1330 on 19 February. There was no reported similar active engagement by ARTC with, or direct release of TN 367 to, NSW Trains or freight operators.

NSW Trains receipt

NSW Trains did not have an active process in place to interrogate the ARTC WebRAMS portal for network operational information related to its Victorian operations. The activity of searching the ARTC portal was inadvertently discontinued around 2017 following a restructure within NSW Trains. For its operations within Victoria, NSW Trains drew on weekly operational notices (WONs) prepared by Metro Trains Melbourne (MTM) that were issued each Tuesday for the week commencing the Wednesday.[75] The WONs included safety information for metropolitan and regional services. The WONs did not, however, typically include ARTC train notices, and reference was instead made within the WON to the ARTC WebRAMS portal.

Each week, NSW Trains extracted information from the WON that was considered relevant to its Victorian operations. This process was used to produce an information pack for NSW Trains regional drivers that would operate in Victorian territory. This information pack was then placed in the pigeonhole of each driver at their Junee base. It was a driver’s responsibility to collect the information from their pigeonhole and assimilate that information.

No evidence was identified to indicate that NSW Trains was aware of TN 367 prior to the occurrence. WON Issue No.07, which was published on 18 February 2020, did not include information from TN 367. This WON did contain TN 266 (as amended on 13 February), which was the ongoing train notice for the Kilmore East to Donnybrook section at the time of the release of WON 07. Its direct inclusion in the WON was not standard practice and was instead the result of V/Line re-issuing ARTC TN 266 (as amended on 13 February) within its own safety information distribution system.

Extracts from WON 07 were prepared for distribution to NSW Trains drivers by 1139 on the morning of 20 February. The information pack (that did not include information on TN 367) was reported as being placed in the pigeonholes of regional drivers (at Junee) by 1247 the same day. It could not be confirmed whether the driver of ST23 had read the information pack issued on that day. There was no functioning system to assure that drivers read and understood the distributed safety information.

For its operations on the NSW portion of the ARTC network, NSW Trains received SAFE notices directly from ARTC.[76]

V/Line receipt and distribution

Normal V/Line process entailed driver supervisors checking the WebRAMS portal after the evening publishing of ARTC notices on that portal and distributing train notices to affected drivers.

In the case of TN 367, V/Line also received pre-information by email at 1333 on 19 February. ARTC provided V/Line with a draft of TN 367, although the distribution was not accompanied by an assessment of risk and risk controls. The notice was then circulated to various staff within V/Line with safety responsibilities. At 1434, a V/Line member of staff responded that:

there should be track force protection mainly, due to the fact that for the past week we have been running at line speed, thru No.1 road, now we have a change to No.2 road with the necessary speed reductions.

In response to receiving TN 367, V/Line published a V/Line safe working circular (SW.0024.2020), incorporating TN 367, for distribution to all drivers. The V/Line drivers that were to run through Wallan Loop on 20 February were also contacted by their driver supervisor prior to their shift and advised of the change in operating conditions at Wallan Loop.

The issuing of TA 17 to ST23 under TN 266 and TN 367

On 20 February, the issuing of the train authority (TA 17) for the passage of train ST23 followed the same processes as had been used during the previous 2 weeks. The NCO issued TA 17 to the signaller, and that process included a signaller readback. The copy of TA 17 completed by the signaller was consistent with the TA 17 that was completed by the NCO. The signaller’s copy of TA 17 was then transferred via the AQW to the driver of ST23, again consistent with the processes used in the previous weeks.[77]

Operating rules

Safeworking rules and use of train authorities

ARTC operating rules for Victoria were defined in the ARTC Code of Practice for the Victorian Main Line Operations (TA20).[78] This code described the following safeworking systems for those parts of the ARTC network covered by the code:[79]

  • centralised traffic control (CTC)
  • the train order system.

Prior to the signalling hut fire at Wallan in early February 2020, rail traffic through this section was managed using the CTC system described in section 17 of TA20. In the case of signal failure, this section provided for the use of caution orders and CTC arrival messages. The caution order form used in conjunction with a CTC system required that traffic ‘proceed cautiously’ …. ‘in accordance with Rule 1, Section 3’.[80]

The use of train authorities in the circumstances that were present between Donnybrook and Kilmore East in February 2020 was not provided for in TA20. The procedures associated with train authorities were specified in section 25 of TA20. This section stated that ‘Train Authority Working[81] must be used as specified by the individual operation of the safeworking system’. For sections with Centralised Traffic Control, the scope of train authority use was specified in TA20 as:[82]

  • to assist a disabled train
  • train to return to the crossing loop in the rear
  • working a train to the point of an obstruction on one or both sides.

For those circumstances where the use of a train authority was permitted, section 25 of TA20 described the methods of delivery, books of train authority forms, and verification protocols. The processes subsequently used in the train working between Donnybrook and Kilmore East were not consistent with those described in section 25 of TA20.

Communication requirements in TA20

Section 25 described that a driver must not proceed into the section unless the train authority was fully understood.[83] Verbal communication requirements were also specified in section 1 of TA20, although the direct applicability of this section to the train working arrangements in use at the time of the derailment is unclear. Section 1 stated that ‘the receiver must confirm the content of a message by repeating the message back exactly as it was received to the sender, if the communication is about: …… special working.[84]

The same clause of TA20 section 1 also addressed the relaying of communications and stated that ‘if it is not possible for a sender to communicate directly with an intended receiver, Competent Workers may relay the content’. In this case, direct communication between drivers (the intended receiver) and the NCO was possible via radio.

Condition affecting the network (CAN)

Within the ARTC operating rules for Victoria (TA20), Section 1, rule 7.a. provided information on the issuing of CAN warnings and stated that the ‘Condition Affecting the Network (CAN) form is used by Network Controllers when giving written warning to rail traffic crews if … faulty or potentially faulty level crossings have been reported’.[85] The use of a CAN to notify drivers of the manual operation of the level crossing protection at Wallan–Whittlesea Road was consistent with this description.[86]

Other rules

Other codes and rules that described potentially relevant safeworking systems and procedures were also reviewed (Appendix H). None were considered directly relevant to this occurrence.

Risk management

ARTC risk management system

ARTC captured operational risks on the ARTC network in its enterprise risk management system (ERMS). The ERMS was a repository of identified risks, risk controls and risk owners.

For the top event of derailment, 44 potential causes were recorded. The top event of derailment was for any train type, and risks associated with passenger operations were not separately considered.

Of the 44 identified causes of derailment, the cause ‘Train driver error (eg. overspeed)’ was listed and was linked to 15 risk controls. ‘Other rail operator’ was identified as the responsible party for 6 of these controls that pertained to the rolling stock operator, and included controls such as driver competency, route knowledge and fatigue management. ARTC was identified as the responsible party for the remaining 9 risk controls. Of these ARTC controls, the first 2 listed were ‘ATMS (where in place)’[87] and ‘Two person train operation (where in place)’. Neither of these controls was applicable to passenger train operations in Victoria. Of the remaining 7 controls allocated to ARTC responsibility, the most significant were ‘Network rules and procedures’, ‘Track signage’ and ‘Train graphs’ that were each rated as ‘partially effective’.

Within other causes for derailment, the risk control of ‘ARTC Safety Management System (SMS)’ was a common risk control and rated as ‘substantially effective’. For the derailment cause of ‘Human Factors’, train notices were listed as an administrative control and rated as ‘minimally effective’.

For operations of the XPT on the ARTC network, the risk management interface between ARTC and NSW Trains was described in a 2011 interface agreement that was agreed between ARTC and RailCorp.[88] The document included a risk review table describing the risk of derailment due to train overspeed, although this document had not been updated since the agreement in 2011.

ARTC risk management procedure

ARTC’s safety management system (SMS) included a risk management procedure that advised that the identification and management of risk occurs at all levels of ARTC.[89] This procedure was described as being consistent with ISO 31000:2018 Risk Management – Guidelines[90] (Standards Australia 2018) and included different types of risk assessment and approaches (Appendix I).

This risk management procedure included requirements for a risk study or assessment for a range of activities and system changes. It specified that formal risk studies were usually undertaken for complex activities where potential impact was likely to be significant. The listed types of activities where the procedure suggested a formal risk study may be considered appropriate included:

  • significant civil works, such as tunnel construction, bridge construction
  • technical operational changes, such as introduction of new signal/track infrastructure
  • safety-critical system changes, such as network control system changes.

Consistent with the overarching procedure, the relevant ARTC work instruction[91] for the application of risk management referenced alignment with ISO 31000. The work instruction specified establishing the objectives, context and scope to be carried out by the workshop convenor prior to a risk workshop taking place.

Application of risk management for train working arrangements

Risk workshop and development of risk management plan

For the train working arrangements between Donnybrook and Kilmore East from 6 February, a risk management plan was prepared. A limited risk workshop was conducted at about 1600[92] on 6 February and involved representatives from ARTC and its contractor, ActivateRail. There was no evidence of involvement of a risk specialist or risk manager in the process. The associated risk management plan was then finalised on 7 February.

This documented risk management plan was not updated for the duration of the temporary train working arrangements. ARTC advised that risks relating to the train working continued to be informally assessed as feedback was received and that changes were reflected in the amendments made to TN 266.

Context described in risk management plan

Within the ‘context setting’ section of the risk management plan, the background of the risk assessment was documented as being the re-signalling of Ararat Junction and referenced documents included the ‘Operations and Safety Commissioning plan for the commissioning of signalling at North Geelong C’. It is probable that previous plans were used as the basis for risk assessment, but not all sections of the risk management plan had been updated for the signalling disruption between Donnybrook and Kilmore East and the planned train operations.

Scope described in risk management plan

The scope documented in the risk management plan stated ‘the scope is specific to the rail operations and safeworking activities for the commissioning’. It is probable that the scope referred to a previous commissioning activity and was not updated for the extended period of train operations between Donnybrook and Kilmore East.

Consultation in risk assessment process

The ARTC risk management procedure stated that ‘a consultative approach with stakeholders must be used to determine the context, risk criteria and structure for the remainder of the process.’ The risk management plan for the train working between Donnybrook and Kilmore East identified rail operators as stakeholders. The risk worksheet associated with the plan was released to V/Line and labour-hire firm Programmed at about 1700 on 7 February, the day after TN 266 and the train working arrangements came into effect. NSW Trains and freight operators were not included in this distribution.

Outcomes of risk assessment described in risk management plan

The risk management plan for the ‘Operation of Train Auth Working between Donnybrook and Kilmore East’ identified 10 risks and associated control measures. The plan documented the treatment for each risk and ARTC was identified as the ‘responsible party’ for each risk and associated control.[93] The plan provided no evidence of treatments that had been considered but rejected.

Several described hazards were associated with works and commissioning of signals. There were no identified hazards or scenarios (and associated risks) specific to passenger train operations.

Risks associated with routing trains through Wallan Loop or derailment due to overspeed were not directly identified in the risk worksheet. There were also no subsequent changes to the risk management plan specific to the routing of trains through Wallan Loop on 20 February.

Of the 10 risk items that were identified in the plan, the risks most relevant to this investigation were:

  • rail operator not aware of the altered train working (risk item 2)
  • deactivated level crossing protection (risk item 6).

The identified risks and risk controls associated with risk item 6 and the level crossing protection at Wallan–Whittlesea Road are described at Appendix J.

Rail operator not aware of the altered train working (risk item 2)

The risk management plan described the hazard, cause and outcome associated with the operator (driver) not being aware of the altered train working (Table 1).

Table 1: Risk management plan description of risk item 2

HazardRail Operators not aware of the altered working
Caused byTrain notices not received by train crews detailing the processes in place
Worst outcomeTrain driver accepts the train authority and proceeds into the section not conversant with the altered working

For this risk, the plan identified 4 controls that were to be implemented, of which 2 controls, the timely issue of train notices and the ‘piloting’ of the train, were also relevant to the management of risks associated with the subsequent routing of trains through Wallan Loop (Table 2).

Table 2: Specified risk controls for risk item 2 and ATSB comment on implementation

Specified risk controlATSB comment on the implementation of the control
Train notices will be issued in a timely fashion

All train notices were issued a short time prior to them taking effect.

  • The initial release of TN 266 was on 6 February and came into effect at 1900 the same day.
  • The 2 subsequent updates to TN 266 came into effect on the same day as their issue.
  • For the changed conditions at Wallan Loop, TN 367 was released on the ARTC portal at about 1845 local time (1815 in Adelaide) on the evening of 19 February, and the changed conditions (points set for the loop) existed by 1536 the following day (20 February).
Signals at the interface of the commissioning will have change of safeworking signage to indicate the interface between CTC and train authority working

Signage at Donnybrook and Kilmore East provided a visual cue to drivers at the extremities of the affected section of the transition between CTC and the altered train working.

This control was not relevant to the change to route trains through Wallan Loop.

Disarranged signals will have black crosses affixed to them

Black crosses were affixed near the base of disarranged signals rather than at the signal head and were reported as difficult to observe. In addition, the deviation from the practice of extinguishing affected signals resulted in confusion until signals were extinguished and the update reflected in the amended TN 266 issued on 13 February.

This control was not relevant to the change to route trains through Wallan Loop.

Trains are piloted through the section[94]

Although the risk management plan specified that trains would be piloted, a pilot was not made available for the trains operating during the altered working. Instead, an AQW was made available. Differences between the roles of pilot and AQW are discussed below.

For the changed conditions and routing of trains through Wallan Loop, this control was augmented by the issue of TN 367, which specified that the AQW was to advise the driver that the train would operate via No.2 track and of the speed limits required.

A pilot as a risk control

Although the definition of a ‘pilot’ varied across a number of references, descriptions were of a directive role (compared to that of the AQW described in TN 266). Consistent themes were that the role of a pilot involved directing the movement of the train, and that to perform their role the pilot required a full understanding of the route, the infrastructure and operational constraints.

Within the ARTC code of practice for operations in Victoria (TA20), the role of a pilot was mentioned within section 14 (Single Line Working) and section 15 (Infrastructure Works). These sections included detailed requirements for a pilot ranging from identification badges to tasks specific to the safeworking activity. Neither of sections 14 or 15 were applicable to the train operations in place at the time of the derailment of train ST23 and the described process for the AQW did not follow the requirements in these sections. There was no mention of the use of a pilot in section 25 of TA20 (Issue of Train Authorities).

The Rail Industry Safety and Standards Board (RISSB) Glossary defined the title of ‘Pilot’ as:

A Competent Worker, who accompanies, directs and advises rail traffic crews.

The ARTC Glossary[95] (applicable to NSW) included the following definitions pertaining to pilotage:

Pilot: a Competent Worker who accompanies, directs and advises Rail Traffic Crews
pilot: to direct or guide Rail Traffic Crews and advise them about local conditions and operating restrictions on running lines and at worksites.

Also applicable to NSW, the ARTC document ANRP 710: Piloting trains and track vehicles[96] contained specific requirements on what a pilot should do. Of note, the procedure advised that:

  • The driver was responsible for the safe operation of piloted trains and track vehicles.
  • The pilot needed to confirm their knowledge of the route.
  • The pilot needed to establish and maintain effective communication with the NCO.
  • The pilot needed to give clear directions (to the driver).

Comparing these requirements with the role of an AQW under TN 266 and TN 367:

  • The driver was similarly responsible for the safe operation of the train.
  • There was no clear requirement for the AQW to confirm their knowledge of the route.
  • The AQW was not required to, and did not, communicate with the NCO.
  • The AQW was not required to, and did not, direct drivers.
The role of an AQW for the train working arrangements

The role of an AQW was not defined nor referenced in either TA20 or the Code of Practice for the Defined Interstate Rail Network. The role of an AQW (or qualified worker) was also not defined by the industry body, RISSB.[97] The qualifications, knowledge and experience required of an AQW were also not described within the documentation for the train working arrangements between Donnybrook and Kilmore East in February 2020 (TN 266).

A primary task allocated to an AQW was to call (by mobile phone) the level crossing keeper (LCK) to ensure activation of the level crossing protection at the Wallan–Whittlesea Road prior to train arrival. TN 266 also described that the AQW was to advise the driver of the ‘work activities’ and affected infrastructure, and a later amendment to the notice added that ‘the rail movement may proceed through the section up to track speed as advised by the AQW’. Although not documented in TN 266, the AQW also performed the task of delivering the train authority and CAN notice to the driver of the train. There were no defined qualifications or experience requirements to perform the role of an AQW.

The role of an AQW was to provide information rather than be directive and there was no responsibility on the part of the AQW to ensure the driver understood the content of the train authority. Under TN 367, there was an additional requirement for the AQW to remind the driver that the train was to operate via No.2 track at Wallan Loop. However, there was no associated protocol for assuring driver understanding of the train authority, and no readback requirement between a driver and the AQW.

AQW experiences during the train working between Kilmore East and Donnybrook, including interactions with drivers, were explored in interviews. Described experiences included:

  • On the shifts prior to the change at Wallan Loop on 20 February, the AQWs told drivers that they could travel at line speed (at the driver’s discretion), that the crossing at Wallan–‍Whittlesea Road had been disabled, and that the LCK would be contacted to activate the crossing.
  • In the period that the disarranged signals were still lit (prior to the 13 February amendment to TN 266), the AQWs would generally inform drivers that they could pass any lit signals at normal speed.
  • Experiences and recall of train operating speeds varied across the AQW group. There was reasonable consensus that the XPT would generally operate at speeds around the line speed of 130 km/h, whereas V/Line trains would mostly travel at a lower speed, with one AQW suggesting typically around 75 km/h. The speed of freight operators varied.
  • AQWs varied in their recall of the speed of trains approaching the Wallan–Whittlesea Road level crossing. One AQW stated that they would advise the drivers to use caution going through this level crossing.
  • Interaction between the AQWs and train crew would vary. Although there were sometimes conversations with the drivers, one AQW described this as ‘cab-chat’.
Application of the role of AQW for train ST23

This shift was the first time the rail worker was performing the role of AQW. At the start of their shift, the AQW allocated to ST23 was briefed by a more senior AQW on the role of the AQW. The briefing included instruction on calling the LCK to facilitate and confirm level crossing protection at Wallan–Whittlesea, and the landmarks for making that call.

The briefing also included discussion on TN 367 that specified a requirement for the AQW to advise the driver that the train would operate via No.2 track at Wallan Loop and of the speed limits at entry to and exit from the loop. The AQW on ST23 was also in possession of a copy of TN 367. When at Kilmore East, the AQW was also briefed by the signaller on the particulars of the train authority and the speed restrictions. Based on this evidence, it is very likely that the AQW on train ST23 was aware that ST23 was being routed through Wallan Loop and of the requirement to advise the driver.

As previously noted, the AQW did not have experience as an AQW or as a pilot prior to this shift. The AQW also did not have front-of-train experience or route knowledge[98] for the section between Donnybrook and Kilmore East.

Also as previously noted, due to the absence of in-cab recordings the nature and content of the conversations that took place between the AQW and driver on ST23 are unknown.

Train recorded information

The Hasler RT recorder

Power cars XP2018 and XP2000 were each fitted with a Hasler RT data recorder. The Hasler RT is an electro-mechanical device that records data onto a waxed paper tape (roll). Data recorded included speed, distance, time, a combined power-vigilance parameter, and brake cylinder pressure. The Hasler equipment included an analogue speedometer located on the driver’s console.

Unlike modern data logger systems that provide digital information for a wide range of operating parameters, the Hasler tapes provide their limited information in graphical format. As a result, there is less precision in the data. GPS data from the train’s installed radio system was used to verify time, speed and position information.

Estimated train speed, throttle and braking

The Hasler and GPS data was analysed to assess recorded driver activities and train speed, including on the approach and into Wallan Loop (Appendix K). It was found that an emergency brake application was made when the train was travelling at about 129 km/h.[99] Brake cylinder pressure began to rise when the train was between 153 and 50 m from the turnout to Wallan Loop. The speed at entry to Wallan Loop was estimated to be between 114 and 127 km/h.

On the approach to Wallan, there was braking and throttle activity consistent with expected driver activity. A power application was made, and speed increased to about line speed after the confirmation was obtained from the LCK that the crossing protection at Wallan–Whittlesea Road was activated. There were no warnings provided by the vigilance system (therefore indicating there was driver activity) after the train departed Kilmore East.

Cab video and voice recording devices

The leading power car (XP2018) was not fitted with in-cab voice or video recording devices, nor was it required. As a result, there was no available evidence with respect to communications or interactions between the driver and AQW prior to the occurrence. Voice recording within the driver’s cab would have assisted the investigation in ascertaining the interactions within the cab, and the potential identification and analysis of any associated safety factors.

Derailment site

Site overview

The derailed train came to rest in a concertinaed arrangement and the leading power car had overturned onto its left side (Figure 13). The 5 passenger cars had derailed and were at various angles of incline. The rear power car was upright and still on track.

Figure 13: Train ST23

Figure 13: Train ST23

Source: ATSB

Turnout and track

At the time of the derailment, the points at the northern end of Wallan Loop were in their reverse position to provide entry to the loop (Figure 14). The points mechanism had been placed into the hand-operating mode[100] and the points were locked in position. The mechanism was also padlocked. These settings were consistent with the arrangements specified in TN 367 and TA 17.

Figure 14: No. 7 points at the northern entrance to Wallan Loop set to reverse

Figure 14: No. 7 points at the northern entrance to Wallan Loop set to reverse

Source: CITS

There was no evidence of derailment prior to the turnout. Inspection identified evidence of derailment within and beyond the turnout. Track damage, including to rail and track formation, was extensive within No.2 track.

There was no evidence identified to indicate that the condition of the track at the northern entry to Wallan Loop was a factor in the derailment, noting also that the speed of the train exceeded the design rating of the turnout by a significant margin. The left rail of the turnout had been lifted a small amount at the commencement of the reverse route, possibly as a result of loading of the right side of the track in the vicinity of the crossing block[101] during the passage of ST23.

Power car XP2018

The leading power car (XP2018) had rolled onto its left side and come to a stop to the left of No.2 track and against a row of pine trees (Figure 15). With the power car on its side, the only reasonable access to the cab was through the right-side driver’s cab door.

At the time the site observations were made, the brake controller in the driver’s cab of power car XP2018 was in the emergency brake position with the power (throttle) controller in OFF and the reverser direction in forward. Both diesel fuel tanks of power car XP2018 had been torn open along their bottom left edge during the derailment and overturn.

Figure 15: Power car XP2018 overturned and access route via right door

Figure 15: Power car XP2018 overturned and access route via right door

Source: ATSB

Leading passenger car

Of the passenger cars, the first (car A) had the greatest tilt (about 30° from the vertical) and the most extensive exterior damage. It had come to rest on a row of pine trees (Figure 16).

Figure 16: The derailed position of car A (photograph taken after cutting of trees)

Figure 16: The derailed position of car A (photograph taken after cutting of trees)

Source: CITS

Power car XP2018 crashworthiness and survivability

General inspection findings

Inspections of power car XP2018 were conducted to examine its crashworthiness performance and crew survivability features. The car was initially inspected at the derailment site, and further examined at the Auburn UGL facility (Figure 17).

Figure 17: Power car XP2018 at Auburn workshops on 10 March 2020

Figure 17: Power car XP2018 at Auburn workshops on 10 March 2020

Source: ATSB

Scouring damage was present along the full left side of the power car that suggested the car had slid on its side for a significant distance. The car had retained its whole-body structural integrity, however both doors on the left side had been dislodged. There was evidence of a significant amount of ballast and earth having entered the driver’s cabin through the left-side driver’s cab door opening. Instruments, control panels and interior fittings were mostly intact.

The car’s forward windscreen had remained in place during the derailment.[102] The lower rear corner of the left-side quarter window had detached from the frame, although it was assessed that only a limited amount of ground material had entered the cab through that opening.

Inspection of left-side cab door

The left-side driver’s cab door was made from fibre-reinforced polymer and contained a glass window panel (that remained intact). The door was inward opening, hung with 2 hinges on its rear edge and closed by a single door latch on its forward edge. After the power car overturned onto its left side, the door separated from the door frame and was loose within the cabin.

Inspection identified that the 2 hinges had failed. The upper hinge knuckles had peeled open (Figure 18) and the fastening of the lower hinge to the door frame had failed (Figure 19).

Figure 18: Upper internal hinge of left cab door of XP2018

Figure 18: Upper internal hinge of left cab door of XP2018

Source: ATSB

Figure 19: Lower internal hinge of left cab door of XP2018

Figure 19: Lower internal hinge of left cab door of XP2018

Source: ATSB

Assessment of left-side driver’s cab door separation

Design standards for pressure loading

The configuration of the driver’s cab door and the potential scenarios leading to its separation from the door frame were considered. It was concluded through inspection of the components, and the probable comparative loading on the upper and lower hinges, that the most likely initial failure was of the upper door hinge.

A simplified assessment of the hinge was conducted using design loads from contemporary Australian and overseas industry standards.[103] Australian standard AS 7521:2018 (Standards Australia 2018a) specified that external vehicle doors were required to meet the United Kingdom’s Rail Safety and Standards Board (RSSB) standard GMRT2100. Issue 6 (2020) of that standard specified external static and aerodynamic loads that were both defined as 2.5 kPa for trains travelling up to 200 km/h. Analysis indicated that the upper hinge on the XPT would not be expected to fail with a 2.5 kPa external pressure, applied quasi-statically (Appendix L).

Design standards for loading when overturned

GMRT2100 did not specify loading associated with external impact during rollover but did note that ‘where hinged external doors are used, typically for cabs, it is good practice to pay particular attention to the design of the door frame and locks’. It further noted that ‘there is a risk that, in the event of a derailment resulting in a roll-over, the structure can flex sufficiently to spring the door open, with the subsequent risk of the ingress of ballast and debris’. Assessment of the door and door frame of ST23 concluded that, in this instance, the door probably failed at its hinges rather than opening. Regardless, the result was the same with the entry of debris.

Australian industry standard AS 7520.1-2022 (Standards Australia 2022) specified that:

The cab roof structure, cab mounting systems, and adjacent structures should be capable of supporting the weight of the locomotive (including the bogies) in the situation when the locomotive is resting on its side without exceeding the critical design stress in the main supporting members …..

There were no specific requirements in the standard that related directly to the external loading of doors when the vehicle was on its side, nor dynamic loadings associated with a vehicle impacting the ground.

Although these loading scenarios were not specified for doors, an assessment was made of the upper hinge considering the pressure applied to the cab door if the power car was resting on its side with its own weight evenly reacted across the side profile of the car. This scenario equated to an applied pressure of about 11 kPa. It was found that the upper hinge knuckles would probably unfurl under this applied external pressure or at least commence to plastically deform (Appendix L).

Loading on door of ST23

In the process of overturning and sliding on its side over uneven ground, the dynamic loading of the left-side driver’s cab door would be expected to be significantly higher than the static load case of the car resting on its side (11 kPa). Given the probable commencement of unfurling of the upper hinge knuckles in the static-load case, complete unfurling of the upper hinge knuckles in the higher dynamic-load scenario was considered very likely. Consistent with this finding, it was also concluded that the cab side-door attachments were probably not designed to withstand the power car overturning and sliding on its side.

Survivability assessment of access to/egress from driver’s cab

Access to the driver’s cab on overturned power car

The normal access to and from the XPT driver’s cab was through its side doors. With the power car on its left side, the right-side driver’s cab door, which was now at the top of the overturned power car, was the most accessible access route to the cabin and the train crew inside.

The right-side driver’s cab door of ST23 remained operable and was used by members of the passenger services crew to gain access to the cab. However, this access route was only accessible by able-bodied people climbing on top of the power car and there was no reasonably practical way to extricate any non-ambulatory people from the driver’s cab.

At the rear of the driver’s cab there was an internal door to access the machinery space, and at the rear of that space there were 2 rear door side exits and a rear central door. However, access to the driver’s cab via the machinery and equipment compartments with the power car overturned would be hazardous and probably unrealistic.

Contemporary Australian egress requirements

Australian industry standard AS 7522:2021 (Standards Australia 2021)[104] specified that enclosed cabs of rolling stock shall be fitted with sufficient emergency exits to provide escape paths to the vehicle exterior when the vehicle was upright and when overturned on its side. There was no requirement specified for how a person might move to such exits if the vehicle was overturned. In the case of the overturned ST23, the right-side door at the top of the overturned vehicle was available to able-bodied people.

AS 7522:2021 and a NSW standard (Transport for NSW 2017) contained a number of other egress requirements for passenger train rolling stock. However, requirements generally applied to new passenger cars, or following a major modification, and none were identified as directly applicable to the configuration of the XPT power car.

There were no Australian Standards identified that specifically referred to requirements for ground-level access to overturned locomotives or power cars.

Similar occurrence related to crew survivability in a power car

On 6 November 2004, a 10-vehicle high speed train (HST) was derailed when it struck a motor vehicle at a level crossing at Ufton Nervet, United Kingdom. The accident was investigated by the RSSB (2005).

The HST was travelling at about 160 km/h at the time of the collision. The leading power car and all trailing vehicles derailed. The leading power car overturned and slid on its left side for some distance. Five passengers, the train driver and the motor vehicle occupant were fatally injured.

The XPT was based on the HST design and had similar form and structural configuration (Figure 20). There were differences in the cab internal layout, window arrangement and driver’s cab side door detail.

Figure 20: HST (left) and XPT (right)

Figure 20: HST (left) and XPT (right)

Source: Redditch Railway Interest Group and Government News

In the Ufton Nervet derailment, the leading power car came to rest on its left side with severe abrasions down the side of the car but with the whole-body structure substantially intact. There was structural failure at the top of a left leading pillar, this being the frame to which the left-side driver’s cab door was latched (Figure 21). The cab door had separated from the door frame and earth and ballast had entered the cab through the door aperture. In both the Ufton Nervet and Wallan derailments, the loss of the side cab door (when the power car overturned) resulted in material entering the cabin and impacting the occupants.

Figure 21: Ufton Nevert cab side damage (left) and Wallan cab side damage (right)

Figure 21: Ufton Nevert cab side damage (left) and Wallan cab side damage (right)

Skin penetrations are circled on the HST damaged at Ufton Nevert. The windscreens and windows have been removed on both trains.

Source: RSSB and ATSB.

The RSSB final investigation report into the Ufton Nevert derailment did not make a direct recommendation on the ingress of materials into the driver’s cab and referred the matter to the RSSB (2007) research project into cabin design and driver protection. The scope of this research project, which had already commenced at the time of the Ufton Nevert accident, was amended to include aspects of that accident; specifically, protecting the driver’s cab occupants from ingress of debris. The released report from this research project acknowledged that the door would open in such an accident and suggested the installation of partitions or reorientation of the door opening to screen the driver from the incoming debris.

Passenger car crashworthiness and survivability

Passenger injuries

There were 155 passengers and 5 crew members in the 5 passenger cars of train ST23. Available data from NSW Trains and Victoria Police was combined with passenger survey response data to estimate a total number of 61 passenger physical injuries.[105] This was comprised of 8 serious injuries and a reported 53 minor injuries.[106]

The estimated number of passengers in each car, the known injuries to passengers in each car, and the associated injury rate are shown in Table 3. The injury status for some passengers could not be determined, and it is possible there were more minor injuries. In addition to passenger injuries, the 5 members of the passenger services crew (1 in Car B and 4 in Car C) all received minor injuries.

Table 3: Estimated number of passengers in each car, known injuries and injury rate

Passenger carSerious injuriesMinor injuriesPassengersInjury rate
Car A (cabin / sleeper)21560%
Car B (first class)3285260%
Car C (first class / buffet)131233%
Car D (economy class)2165732%
Car G (economy class / baggage)052619%
Total85315539%

Most injuries to passengers were a result of people being unprepared for the sudden deceleration or movement during and following the derailment. Passenger injuries were more prevalent and more severe in the forward passenger cars (as shown in the table above). Loose luggage also became projectile hazards during the derailment. Some luggage fell from overhead racks and there were instances of loose luggage causing injury to passengers and service crew.

Inspections

The 5 passenger cars were inspected to examine crashworthiness performance (Appendix M). Inspection of all passenger cars was conducted at the derailment site, and the leading passenger (sleeper) car (Car A) was further examined at the Auburn UGL facility. Inspections did not identify any passenger car structures that generated injuries by their design.

Evacuation routes from passenger cars

The majority (14) of the 18 exits in the passenger cars were available for use. Four exits were deemed unavailable, either due to obstruction, jamming or excessive height off the ground.[107] Of the 14 usable exits, 6 exits were considered freely available and 8 were operable but with some hindrance to their free use due to the distance from the ground, the angle of the access ladder, or some other hazard.

Most people were able to evacuate with limited assistance although sometimes with difficulty due to the distance to the ground or the angle of the car. Some passengers with special needs were assisted out of the carriages.

Passenger information

Passenger survey
Overview

The ATSB conducted a survey of passengers who were on board train ST23 at the time of the derailment. From 155 passengers reported to be on board, 83 responses to the survey were received: a response rate of 54%. The survey included questions on:

  • passenger demographics
  • passenger seating location
  • safety information and briefings
  • experiences during and after the event
  • the nature of injuries.
Safety information

On questions pertaining to safety information:

  • Most (70%) of the passengers who responded to the question about the provision of safety information reported that they either did not receive any safety information or could not recall receiving any.
  • Of the 63 responses about the format of the safety information provided, 8 passengers (13%) reported that they received the information from a briefing card.
  • Of the 74 responses to a question related to paying attention to the safety information provided, 57% reported that they did not pay attention.
  • Most (70%) of the survey respondents reported that, prior to the derailment, they did not know how to get out of the train in an emergency.

In response to questions on suggestions for improvement in safety information:

  • Ten passengers referred to the way in which safety information is provided by airlines.
  • Some passengers mentioned that better signage on the seat in front of them or at the end of carriages may have been helpful.
  • Other comments included increasing the number of announcements.
The evacuation

There were varied responses from passengers about the communication received from crew members following the derailment. This was at least in part due to the distribution of the crew, with 4 of the 5 crew members being in the buffet car at the time of the derailment and no crew members present in Car A, Car D or Car G. Most of the passengers who responded advised that initial crew instructions were to remain on board the train. Others reported being unsure about what to do. There was no report of any announcements being made via the public address system or the use of megaphones.

Passengers were asked to estimate how long it took to exit the train. The responses ranged from a ‘few minutes’ to up to 30 minutes, supporting other evidence that some passengers self‑evacuated prior to being instructed to do so by the passenger services crew. About half of the respondents indicated having difficulty exiting the train due to carriage orientation and/or difficulty with getting down to the ground. Once passengers were out of the train, crew members were observed instructing passengers to move off the adjacent tracks (due to concern of possible rail traffic).

Sixteen respondents utilised the free text question to provide praise for the handling of the emergency event by members of the train crew and first responders.

Emergency preparedness

Passenger safety information
Verbal safety briefing

The train operator’s procedures provided details of the verbal safety briefing to be conducted by the passenger services crew (Appendix N). Key messages included, but were not limited to:

  • to remain seated and wait for instruction from the crew
  • to leave luggage if instructed to evacuate
  • to refer to the safety card for further information.

Evidence suggested that it was probably the normal practice for crew supervisors to develop their own announcement script rather than using a pre-prepared script developed by NSW Trains.

Operator procedures specified the conduct of announcements at the departure point in Sydney and at selected stations en route to Melbourne, including at Albury. The replacement passenger services crew boarded at Albury and an announcement was made to passengers using the public address system. However, the announcement did not include the full safety briefing. Evidence suggests that some crew members were not familiar with the requirement to provide a safety briefing at Albury.

Written briefing information

Written information about what passengers should do in an emergency was contained in an ‘on‑board guide’ located in the back pocket of passenger seats. This guide was a 10-page booklet that contained general information about the train service and destinations, food and beverage menu items, and emergency procedures.

The messaging on emergency procedures contained in this guide (Appendix N) was consistent with the operator’s procedures for verbal briefings. The instructions on what to do in an emergency included guidance to:

  • remain seated until instructed by the crew or emergency services
  • leave luggage behind
  • be aware of hazards outside the train.

The instructions were in written form only and did not include diagrams or pictorials to supplement the text.

It was reported by passenger services crew members that on some trips there would be a large proportion of onboard guides missing from the back of passenger seats. Although there were a significant number of onboard guides present on ST23 on the day of the derailment, not all seats were provided with a copy. The passenger survey indicated that only a small number of passengers obtained safety information from this guide.

On-board safety signage

There was no onboard safety signage identified on ST23 that provided guidance to passengers on actions for them to take in the case of emergency.

Emergency response procedures

Emergency response plan

The train operator had an emergency response plan that was supported by operational procedures. The emergency response plan was summarised in the Countrylink Incident Response Summary (Appendix O). This summary was contained in onboard logbooks, and displayed on the bulkhead at crew stations (Figure 22).

Figure 22: Onboard incident response summary at a crew station

Figure 22: Onboard incident response summary at a crew station

Source: NSW Trains, annotated by the ATSB

The response summary contained a 9-step action plan to be followed by the train crew in the case of a major incident or emergency. This action plan was supplemented by specified additional actions for 15 types of incidents, including derailment. The incident response summary also included guidance on communication protocol, deciding to evacuate, and evacuation procedures. A range of warnings were described, including to ‘evacuate to tracks only after receiving positive confirmation from Network Control Officer that train movements have been stopped …’.

Crew members were also provided with an ‘emergency pocket guide’ that included shortened advice on quickly assessing risk, and communicating with emergency services, the NCO and management.

There was no ready-use guidance available to crew members about what or how they should communicate with passengers in the period prior to the decision being made to evacuate. There were no documented standard phrases or positive commands to instruct passengers to remain seated or on board the train.

Procedures for an evacuation when not at a station

In circumstances where the train was not at a station and the crew had determined the situation to be life-threatening, they were required to conduct a risk assessment to determine the safest course of action. If an evacuation was required, the driver was responsible for securing the train, notifying the NCO and ensuring that all adjacent traffic had been stopped. The driver or PSS was then required to protect the train, determine an evacuation plan (including which doors to use), inform passengers and manage the evacuation.  

Use of the public address system

The public address (PA) system was serviceable throughout the train journey prior to the derailment. Following the derailment, it was not utilised by the passenger services crew to communicate to passengers. It was not determined if its serviceability was affected by the derailment. There was also no specific procedure that advised the crew what to do if the PA system was unsuitable for use in an emergency.

Megaphones were available for use on board the train. There was no specific procedure describing when they should be used, and they were not used in this instance.

Passenger services crew training

ST23 crew training and assessment records

NSW Trains provided details of crew training courses that included content related to emergency evacuation (Table 4).

Table 4: Training courses covering derailment and evacuation

Course nameFrequency
Safeworking (PSS only)Annually
CPRAnnually
Competency assurance check rideAnnually
WF25 Emergency ladder and evacuationEvery 2 years
IC01 Emergency and evacuationEvery 2 years
NCA01 NSW Operational staff competence assurance: Emergency and evacuationEvery 2 years
WX63R0109 Incident response planEvery 2 years
First AidEvery 3 years

The individual learning profiles of the passenger services crew on ST23 were compared with the courses required for passenger services crew. The review identified that not all the crew members had completed the required courses, several courses had not been completed at the frequency specified, and none of the passenger services crew members were recorded as having completed the listed course WX63R0109 (Incident response plan).

The facilitator guide for the incident response plan course was reviewed. Except for a specified instruction to use when initiating a passenger evacuation, the course material did not include other standard phrases or commands that the passenger services crew should use in an emergency, such as an instruction to remain on the train following a derailment. In addition, the training courses reviewed did not provide passenger services crew with the opportunity to practice using the PA or megaphone to make announcements, or use standard phrases or commands in an emergency context.

Assessment records were obtained for the passenger services crew members on ST23 and these included the written assessments for their most recent ‘NCA01 NSW Trainlink Operational Staff Competence Assurance: Emergency and Evacuation’ course. Review of these records found inconsistencies and, in some cases, an absence of the use of the marking scale. In several cases there was also an absence of assessor sign-off.

Training needs analysis

NSW Trains provided a report of a training needs analysis completed in April 2019.[108] This review included a detailed task analysis of passenger services crew roles, and the approach to training and assessment of required competencies. It identified that evacuation-related competencies should be trained and assessed practically, with a frequency of every 6–12 months. The report also included driver incapacitation scenarios and the use of high-fidelity mock-ups. The outcomes of this project had not been implemented at the time of the Wallan derailment.

Other information related to training and competency management

Research conducted by the NSW Independent Transport Safety and Reliability Regulator (ITSRR)[109] highlighted, among other things, that accident reports had a reoccurring theme in the deficiency of emergency procedures training provided to train crew (ITSRR 2004).

Published in July 2021 (post the Wallan derailment), the Office of the National Rail Safety Regulator (ONRSR) provided guidance about the management of rail safety worker competencies, which included a rail safety worker competency assessment fact sheet (ONRSR 2021) and various examples (including a competency register) of how organisations could record the competency requirements and expiries of train crew.

Review of regulator activities

Scope

ONRSR was the national rail regulator. A review was undertaken of potentially relevant regulatory activities in the 5 years preceding the Wallan occurrence.[110] Activities examined included reported overspeed occurrences, notified changes to safeworking arrangements, and relevant audit and inspection activity.

Notified occurrences associated with train overspeed from 2015

ONRSR was requested to provide notified overspeed occurrences on the ARTC network in Victoria in the 5 years prior to the Wallan occurrence.[111] Eleven overspeed occurrences were identified in the supplied data, including the following 5 that involved passenger trains:

  • 6/1/2015 – an XPT passenger train went through a 40 km/h temporary speed restriction between Somerton and Donnybrook at 130 km/h.
  • 11/7/2015 – a V/Line passenger train transited the turnout into Wallan Loop at over 90 km/h compared to the required 15 km/h. This overspeed occurrence was investigated by the ATSB.
  • 29/12/2015 – a V/Line passenger train went through a 40 km/h temporary speed restriction at Euroa at 72 km/h.
  • 13/3/2018 – an XPT reported travelling through a 40 km/h temporary speed restriction at Violet Town at excessive speed.
  • 6/8/2018 – a V/Line passenger train went through a 40 km/h temporary speed restriction between Seymour and Benalla at the line speed of 130 km/h.
Notifications of change to network rules from 2015

ONRSR advised that 5 notifications of change to the Code of Practice for the Victorian Main Line Operations (TA20) were submitted by ARTC in the 5 years preceding the Wallan occurrence. None of these notifications of change related to the processes used at Wallan on 20 February 2020.

Audits and inspections from 2015

Topics not audited

ONRSR used a risk-based approach in its decisions and plans for regulatory activity. As a result, regulatory activity was targeted and operators and topics received different priority. For the ARTC network in Victoria in the 5 years before the Wallan occurrence, ONRSR advised that it did not conduct audits or inspections of ARTC on the following topics:

  • caution orders or train authorities
  • the use of AQWs or safeworking pilots
  • the risk of train derailment due to overspeed[112]
  • the overspeed of a V/Line passenger train at Wallan Loop (Victoria) on 11 July 2015.
ARTC risk management

ONRSR was requested to provide audit and inspection reports that included the topics of ARTC risk management systems and/or risk assessment processes associated with safeworking. ONRSR identified 4 audits and 6 compliance inspections conducted across 2017 and 2018 that included either or both of the requested risk topics.

Reports from these regulatory activities referenced concerns with the currency of the centralised risk register and ARTC’s introduction of a new Enterprise Risk Management System (ERMS). Of note, an audit in November 2018 made several observations, including that ARTC should consider the risk of passenger and freight train derailment separately in view of the different potential consequences and required controls.

NSW Trains systems for accessing and distributing safety critical information

ONRSR was requested to provide audit and inspection reports that included the topics of NSW Trains’ systems for accessing safety-critical information (such as train notices) from ARTC for operations on the Victorian network, and NSW Trains’ systems for disseminating such information. In response, ONRSR identified a total of 5 audit and 5 inspection activities between 2015 and 2018 that referred to either or both of these topics.

Consistent through these activity reports was reference to the issue of a Train Crew Weekly Information Pack (WIP) as the primary vehicle for distributing safety-critical information including train notices. There was no commentary or findings identified in the review that discussed the collection and immediate distribution of notices accessed from the ARTC WebRAMS portal.

Other occurrences at Wallan Loop investigated by the ATSB

V/Line high speed entry into Wallan Loop in 2015

In July 2015, a Melbourne to Albury V/Line service entered the southern turnout to Wallan Loop travelling at more than 90 km/h (compared to the required 15 km/h). The train remained on track, however some passengers required medical attention from the onboard service crew due to the rough ride as the train transited the turnout.

This occurrence was investigated by the ATSB (2017). It was found that signalling at the location was operating as designed and there were no signal sighting issues, but that the driver did not demonstrate effective awareness and train handling techniques. The report also made findings related to post-occurrence processes and actions.

As part of the investigation into the derailment of train ST23, further enquires were made into safety actions taken by ARTC and V/Line following the 2015 occurrence, and specifically consideration of train enforcement solutions at Wallan Loop (to automatically enforce train braking if a train was detected as being overspeed).

ARTC advised that consideration of train enforcement solutions at Wallan Loop was a matter for V/Line. Also, ARTC did not introduce any additional risk controls at Wallan Loop in response to the V/Line train overspeed occurrence.

V/Line advised that, following the 2015 occurrence, the potential application of the train protection and warning system (TPWS) on the ARTC Northeast standard gauge line was evaluated.[113] It was concluded by V/Line that (based on safety risk to its operations) there was a case to install TPWS at several locations on the ARTC North-east standard-gauge line (including at Wallan Loop) to protect against a V/Line passenger train overspeed or the passing of a signal at danger. TPWS was used for V/Line trains on the Victorian broad gauge networks and V/Line passenger rolling stock was fitted with compatible equipment.

The project to integrate TPWS (for V/Line trains) on the ARTC network was being funded by the Victorian Government and ARTC confirmed in its response to ATSB that it had been involved in discussions with V/Line and was committed to supporting the implementation of TPWS. TPWS was scheduled to be fitted at Wallan Loop in 2024.

TPWS would not be compatible with the XPT (and its NSW Trains replacement) or freight traffic.

Derailment of freight train at Wallan Loop November 2017

On 4 November 2017, freight train 7MC1 was signalled into the southern entry to the crossing loop at Wallan. Entering the loop, the leading bogie on the 37th wagon derailed.

The occurrence was investigated (ATSB 2019). It was found that the derailment occurred within a rapid transition of track superelevation from the main line to the loop track, resulting in wheel unloading. Following the derailment, ARTC completed rectification works and enhanced its work management processes for the response to geometry conditions. There was no aspect of this occurrence found to be relevant to the derailment of train ST23.

Safety analysis

Introduction

The derailment of the interstate passenger rail service (train ST23) between Sydney and Melbourne resulted in the death of the train’s driver and the accompanying rail worker, and serious injuries to 8 passengers. There was potential for further passenger injury that was probably mitigated by a row of trees limiting the rollover of the leading passenger car.

The report analysis first considers the physical scenario that resulted in the derailment of train ST23 and describes those factors unlikely to have influenced the occurrence.

Potential scenarios that may have led to the train travelling at near the track speed of 130 km/h as it approached the turnout to Wallan Loop are then considered. Evidence supporting the most likely scenario, that the driver of train ST23 was probably unaware of the routing of ST23 through Wallan Loop, is discussed. Other scenarios considered less likely are also presented. The mechanisms for informing the driver of the changed conditions at Wallan Loop and missed opportunities are then introduced.

The analysis further examines the underlying factors that either directly influenced this occurrence or increased the safety risk associated with train operations. The analysis discusses the train working system, risk assessment processes, risk controls, and the distribution of safety critical information. Comment is also made on the risk management of passenger trains on the ARTC rail network.

The remainder of the analysis considers factors associated with events following the derailment, including power car survivability following overturn and the preparedness of passengers and passenger services crew for a major emergency occurrence such as train derailment.

The derailment

At Wallan Loop, the track was configured with low speed turnouts to No.2 track from No.1 track that had a permitted speed of 130 km/h for passenger trains. The significant speed differential at this location created the risk of derailment due to overspeed that was controlled through driver compliance with the signalling system. When the signalling system became non-operational in February 2020, the risk of derailment at the turnouts due to train overspeed was (initially) effectively eliminated by locking the points to their normal position and removing the option to transit through No.2 track. The hazard at the turnouts and the risk of derailment were then re‑established on 20 February when the points were locked in their reverse position to route trains via No.2 track with (only) the implementation of administrative control that relied on ‘paper-based’ information exchange.

The investigation found that train ST23 entered the turnout to Wallan Loop travelling at between 114 and 127 km/h. The turnout was rated by ARTC for a train entry speed of 25 km/h and the maximum permitted operational speed was 15 km/h. In the absence of indications of infrastructure or rolling stock defects, it was concluded that ST23 derailed as a result of its speed significantly exceeding the speed rating of the infrastructure.

Recorded data indicated that ST23 was approaching Wallan Loop at 129 km/h[114] when there was a rise in brake cylinder pressure as a result of an emergency brake application. Assuming a nominal 2 seconds between the cues of the unexpected situation and braking system response,[115] the cues(s) that resulted in the brake application may have arisen when ST23 was between 120 and 220 m from the turnout (Appendix K).[116] Possible reasons for the driver realising the need to brake included recall of the points setting by the accompanying qualified worker (AQW) or the driver, or direct observation of the setting of the points at the turnout to the loop.[117] Given the AQW had no driving experience, the emergency brake application was almost certainly the action of the driver.

Site inspection indicated that the vehicles of the train derailed within the Wallan Loop turnout and No.2 track, and there was no indication of derailment prior to the turnout. Given the leading power car overturned onto its left side, the rolling over of the power car was more likely to have occurred (or commenced) within the right curve transitioning onto the tangent (straight) section of No.2 track. Damage to the exterior of the power car also suggested it had slid on its left side for a significant distance.

Factors unlikely to have influenced the occurrence

Driver incapacitation

There was no evidence identified to suggest that the driver was incapacitated leading up to the derailment, and there was evidence to support the proposition that the driver and AQW were functioning normally. The AQW was in contact with the level crossing keeper (LCK) less than 2 minutes prior to the derailment, had sounded normal in that conversation and did not raise any concerns regarding the condition of the driver. An earlier brake application for a 115 km/h track section, and a power application made shortly after the conversation between the AQW and LCK, also support the proposition that the driver was actively in control of the train.

The derailment occurred about 6.5 hours after the driver started their shift, a little under 5 hours after they commenced driving ST23, and about an hour after the driver’s scheduled end-of-shift. Although the driver may have been tiring towards the end of the train journey, there was no evidence, including in radio communications, that suggested that driver fatigue was a factor. A review of the driver’s roster and recent history found that there was insufficient evidence to conclude that the driver was experiencing a level of fatigue that would significantly affect performance.  

There was no pre-existing health condition of the driver that was likely to have contributed to the accident and toxicology results did not identify any substance that may have impaired their performance.

Rolling stock condition

Inspections, testing and a review of maintenance records did not identify any adverse rolling stock condition or defect that was likely to have contributed to the derailment.

Track condition

There was no evidence identified to suggest that the condition of the track or turnout at the northern entry to Wallan Loop was a factor in the derailment, noting also that the speed of ST23 significantly exceeded the ARTC speed rating for the turnout. The facing points were found to be locked and in position for the train movement into No.2 track.

Factors leading to train overspeed

Discussion on potential scenarios
Scope

Having excluded the likelihood of driver incapacitation or defective train braking, this section discusses the evidence for, and likelihood of, the following scenarios that could have led to the overspeed of ST23 at the Wallan Loop turnout:

  • The driver of ST23 was not aware of the routing of ST23 via Wallan Loop and expected to travel on the straight track through Wallan.
  • The driver was aware of the routing of ST23 via Wallan Loop and forgot this information during the journey between Kilmore East and Wallan.
  • The driver lost awareness of their location in the section between Kilmore East and Wallan.
  • Approaching Wallan Loop, the driver misinterpreted an adjacent broad gauge signal (that was probably at proceed) as applying to the standard gauge track.
Driver awareness of changed conditions and expectancy

Prior to the derailment, there were a number of radio conversations between the NCO and the driver and there was no instance where the driver of ST23 expressed an understanding that conditions at Wallan Loop were different to what they had been during the previous 12 days, and that ST23 was being routed onto No.2 track on that day. In a radio conversation between the driver and the NCO about an hour before the derailment, the NCO mentioned that ‘you’re going via the loop there at Wallan’. There was no acknowledgement of the routing via the loop by the driver.

In another interaction with the NCO about 11 minutes before the derailment, when at Kilmore East receiving the train authority, the driver commented that they were in possession of the train authority and CAN and stated that they were ‘filled out ahh the same way it has been for the … rest of the time’. This latter interaction suggests that the driver may have believed that the track conditions were the same as they had been and that ST23 would proceed through Wallan in the same way as the driver had experienced in the preceding trips through the location, including on the day before.

Also while ST23 was stopped at Kilmore East for the driver to receive the train authority, the NCO mentioned ‘points all set for the loop’. The driver did not respond directly to this comment and there are a number of ways it could have been interpreted.

Expectations based on past experience strongly influence where a person will search for information and what they will search for (Wickens et al. 2023), and they also influence the perception of information (Wickens et al. 2022). In simple terms, people are more likely to see and hear what they expect to see and hear, and less likely to see and hear what they do not expect to see and hear. After the commencement of the alternative method of train working, the driver of ST23 ran the Junee–Melbourne–Junee round trip 4 times (8 times through the location) between 8 and 19 February. For all previous trips, the points at each end of Wallan Loop had been locked in the straight position, and trains could proceed through this location at normal track speed (130 km/h for the XPT). This experience likely developed an expectancy in the driver that strongly influenced their mental model on the day of the derailment.

Limitations of prospective memory

Another scenario is that the driver correctly assimilated the information from the train authority, the NCO’s mention of the transit through the loop and/or verbal information potentially provided by the AQW, but forgot about the changed conditions at the loop during the short journey between Kilmore East and Wallan Loop.

Remembering information about the use of the loop and associated speed restriction and applying it later would require prospective memory (Loukopoulos et al. 2009). Prospective memory refers to an intention to perform an action at a later time, and a delay between forming the intention and acting on it. It is known to be vulnerable to failure and has been associated with many incidents in aviation and other work domains (Dismukes 2012). Prospective memory errors have also been associated with previous incidents of overspeeding trains due to drivers forgetting a temporary speed restriction (Sato et al. 2020).[118]

Conditions that increase this vulnerability include the delay between the intention to do a task and the execution of the task being filled with other activities, an interruption to a task sequence, and the cues or prompts to retrieve the intention from memory not being explicit (Dismukes 2012). In the case of train ST23, the driver did not have any strong cues or prompts (such as signage or in‑cab alarms) for recalling the speed requirement. Conversely, there would probably not have been excessive task demands on the driver and, as far as is known, there were no distractions or interruptions to their normal driving activities. The interactions between the driver and the AQW during this period and any possible distractions could not be determined.

It is feasible that when ST23 approached the turnout loop, the driver recognised they were now approaching Wallan and remembered that they were being routed through Wallan Loop and made the emergency brake application. However, there was no evidence available to determine whether that scenario may have occurred or instead the driver reacted to being prompted by the AQW or observing the position of the points at the turnout.

Other possible scenarios

It is also possible that after departing Kilmore East, the driver lost awareness of their location within the 15 km section to Wallan, and only made a brake application after realising their proximity to Wallan Loop. Given the driver was familiar with the route and had travelled on this track several times in the preceding 12 days,[119] there was no compelling case to suggest a loss of positional awareness.

It was also considered whether the driver may have been confused by the broad gauge signal, which was probably at proceed. Given the experience of the driver, their familiarity with the route and their recent and repeated transits through the location with the standard-gauge signalling system not operating, there was also no compelling case to suggest that the driver had misread the broad-gauge signal as applying to the standard gauge track.

Summary

Having discounted several other possibilities, the remaining most likely scenarios were that the driver was either unaware of the routing through the No.2 track at Wallan, or the driver was aware of the routing but forgot (prospective memory failure). The recorded driving actions of applying power after receiving confirmation that the level crossing protection at Wallan had been activated and then making a late emergency brake application approaching the loop turnout were both consistent with, and plausible driver actions in the case of, either scenario.

There was, however, no direct evidence to support the proposition that a failure of prospective memory was a factor in this instance. No radio interactions between the driver and NCO suggested recognition by the driver of the routing through the loop, or the differences (compared to previous days) in the train authority that had been issued on that day. It was therefore concluded that there was insufficient evidence of a failure in the driver’s prospective memory.

Considering the radio communications between the driver and the NCO, and in the context of an expectation developed by this driver during 8 trips through the location in the 12 days after the signalling system was disrupted, it was concluded that it was more likely that the driver of ST23 was not aware that ST23 was being routed through Wallan Loop on that evening. Supporting the potential for such a scenario, there were several weaknesses in the delivery of information to the driver to overcome their expectancy, and several missed opportunities to confirm the driver’s understanding of the changed conditions.

Information available to driver and missed opportunities

Scope

This section discusses the information that was available (and not available) to the driver and introduces the missed opportunities for confirming driver awareness. These themes are developed further when discussing risk management and risk controls later in the analysis.

The information that is discussed and the implications for the driver include:

  • train notice 266 and its reinforcement of the expectation that the loop was not being used
  • train notice 367 and its absence as pre-information for the driver
  • train authority 17 and weaknesses in the delivery processes for assuring driver understanding
  • communications between the NCO and driver as a missed opportunity
  • communications between the AQW and driver as a missed opportunity
  • rail resource management as a missed opportunity
  • cues in the real-world environment as a missed opportunity.
Train notice 266

Prior to the day of the derailment, the driver of train ST23 had driven through the location several times operating under the altered train working arrangements and the instructions of train notice 266 (TN 266). On 8 February, the driver had also repeated back the associated train authority for this method of working prior to their first transit under these conditions. The driver was therefore very likely familiar with the conditions specified in TN 266, and specifically the condition that the points at either end of Wallan Loop were locked in their normal position for transit on No.1 track. TN 266 did not contain any information suggesting the possible operation of trains through Wallan Loop (No.2 track). This meant that TN 266 had worked to establish a strong expectation (in the driver) that the points would be set to their normal position (for the straight).

Train notice 367

TN 367 was a potential source of pre-information about the change in conditions at Wallan Loop, however, the driver did not have a copy of TN 367 with them on ST23 and was probably unaware of this notice. This removed the opportunity for the driver to familiarise themselves with the changed conditions.

Train authority 17

The driver of ST23 received a copy of train authority 17 (TA 17) while stopped at signal KME16, about 12 minutes before the derailment. TA 17 detailed the changed conditions at Wallan Loop, including the requirement to slow to 15 km/h. However, this added text was towards the end of TA 17 and was not marked or highlighted in any way to indicate it was different to the previous train authorities that had been issued for the same section of track in recent weeks. In addition, the body text of the train authority was in upper case, which can be more difficult to read or scan than lowercase text (Wickens et al. 2022). It is therefore very plausible that the driver did not pick up the change from previous train authorities. The radio communication by the driver that the documentation was ‘…filled out … the same way it has been...’ suggests this was probably the case.

Consistent with the practice that was used during the 2 weeks of the altered train working arrangements, TA 17 was given to the driver by the AQW. It was the practice for signallers to deliver the train authority to the driver via an AQW, although this was inconsistent with the description in TN 266 that specified that the signaller was to deliver the train authority to the driver. Delivery of TA 17 directly to the driver of ST23 would have provided an opportunity for the driver to receive direct verbal advice of the changed conditions from the signaller during the transfer of the authority document.

The driver was also not required to (and did not) read back the contents of TA 17 to the NCO or the signaller, and almost certainly did not read back TA 17 to the AQW. Readback/hearback refers to the process of issuing and confirming track authorisation (Gertner and Acton 2003). Verbal rehearsal can result in the encoding of information in short-term memory (Greene 1987). Readback of safety-critical information is adopted by industries to ensure information is correctly understood by the sender and the (actioning) receiver, in this case the NCO and the driver of ST23 respectively. An industry guideline on safety critical communications (RISSB 2018) stated that to ‘ensure the message has been understood, require the recipient to repeat back the message if not already done by them’. In their similar manual, the Rail Safety Standards Board (RSSB 2017) in the United Kingdom outlined that:

To confirm that all parties have the same understanding of the communication, the person with lead responsibility must ask for a ‘repeat back’. This is a crucial step in making sure the arrangements have been fully understood by both parties. It provides the opportunity to identify any misinformation, misunderstandings, or omissions.
The person with lead responsibility should use the phrase ‘repeat back’ to confirm the understanding of both parties. It can also be used by others who don’t have the lead responsibility to confirm their understanding. It can be used to confirm details relating to who we’re talking to, what the situation is, or what actions are being given.

Had the driver of ST23 read back the full content of TA 17 to the NCO, it is probable that they would have realised the changed conditions at Wallan Loop, complied with the speed instruction and this occurrence would probably not have occurred.

NCO – driver communications

In addition to the driver’s acknowledgement of the receipt of train authority 17, there were other conversations between the NCO and driver that were missed opportunities for the NCO to confirm the driver’s understanding of the change in conditions at Wallan Loop. The NCO and driver had conversations that skirted the topic of the routing of ST23 through Wallan Loop, without achieving confirmation of driver understanding. Although these opportunities existed, there was no procedural requirement for the NCO to seek confirmation of the driver’s understanding. In addition, the NCO’s belief that there was a pilot on board probably provided some reassurance with the arrangements.

AQW – driver communications

Tasks of the AQW included delivering the train authority and CAN notice to the driver and organising the activation of level crossing protection at Wallan–Whittlesea Road. These tasks were completed by the AQW on train ST23.

For this day, TN 367 added the instruction for the AQW to remind the driver that the train would operate via No.2 track at Wallan Loop, although the notice did not include any procedural requirement on how this activity was to be conducted by the AQW or how driver understanding was to be ensured (such as by readback). The AQW was briefed on this requirement and would also have expected that the driver was likewise aware of TN 367. There was probably sufficient time from when the AQW boarded ST23 to its departure from KME16 for this exchange of information to occur.

In the absence of voice recordings from the driver’s cab, the details of conversations between the driver and the AQW are unknown. There are many plausible scenarios in which conversations may have occurred but may have been misinterpreted by either party.

The presence of an authority gradient can influence the effectiveness of personal interactions. An authority gradient refers to the perceived difference in status between different members of an organisation (RISSB 2018). Its presence can influence the effectiveness of the delivery and receipt of information between safety-critical personnel. There was insufficient evidence available to examine whether this may or may not have been a factor in this instance.

Rail resource management

Rail resource management (RRM) is the application of non-technical skills of rail safety workers, which includes team communication and co-ordination, planning and contingency management, critical decision-making, situational awareness, and workload management (Klampfer and others 2012). These skills enable operational staff such as drivers, guards, NCOs, signallers and rail workers to effectively manage hazards and errors in the workplace. In this instance, there were missed opportunities for application of RRM principles between the NCO and the driver to assure driver awareness of transit through Wallan Loop. There was insufficient evidence to conclude the nature of the probably missed opportunities to apply RRM principles between the AQW and driver.

Visual and audible cues for the driver

The driver was not provided with visual cues (such as signage or conspicuous warning devices)[120] or audible cues (such as in-cab alarms) to warn of the need to slow to 15 km/h when approaching Wallan Loop. These were significant absent risk mitigants and missed opportunities for cues in the real-world environment to address limitations in transmitting information by administrative systems and mitigate against a failure of prospective memory and expectation bias.

Deviation from established network rules

A safety management system (SMS) is a ‘formalised framework for integrating safety into the daily operations of an organisation and includes the necessary organisational structures, accountabilities, policies and procedures’ (Fox 2009). The Rail Safety National Law described an SMS as providing a ‘comprehensive and systematic assessment of any identified risks’.[121]

The ARTC SMS was listed several times as a risk control for derailment within the ARTC enterprise risk management system (ERMS). The Code of Practice for the Victorian Main Line Operations (TA20) formed part of the ARTC SMS and described the operating rules for the Victorian section of the North-east standard gauge rail corridor.

The use of train authorities in the circumstances that were present through Wallan in February 2020 was not provided for in TA20, and uncoupling from the established procedure and rules was observed. The use of train authorities became sanctioned through train notices and further ‘gained legitimacy through unremarkable repetition’ (Snook 1996). The final ‘drift into danger’ (Rasmussen 1997) was the application of the administrative arrangements to transit through a section that included a low-speed turnout. The effectiveness of the paper-based train authority as a risk control then relied on non-formalised person-to-person interactions.

The effective management of safety during unpredicted situations requires risk management processes that can comprehensively identify and assess risks, effective implementation of those processes, and organisational systems that ensure safety is not compromised at the expense of operations.

Weaknesses in risk management and stakeholder engagement were evident in both the initial establishment of the train working arrangements on 6 February, and then to operate trains through Wallan Loop on 20 February. Each of these phases, including the implemented risk controls is discussed separately in the following 2 sections of the analysis.

Train authority working arrangements established on 6 February

Risk workshop and risk management plan

For the proposed implementation of ‘train authority working’ between Donnybrook and Kilmore East, there was a brief risk assessment workshop involving ARTC and ActivateRail on the afternoon of 6 February, shortly before implementation of the train working solution. The timing of the workshop, the absence of key stakeholders (rail operators) from the process and the preconceived suitability of a previously used arrangement reduced the likelihood of the workshop identifying all risks associated with the proposed rail operations and the controls to appropriately manage those risks.

The risk management plan was finalised on 7 February, the day after release of TN 266 and the commencement of the train working arrangements. The plan had significant weaknesses, including:

  • The context setting described in the risk management plan was from a previous assessment that had limited relevance to the risk profile associated with the train operations between Donnybrook and Kilmore East. The context should have reflected the specific environment of the activity to which the risk management process was to be applied (Standards Australia 2018). In addition, ARTC’s risk management procedure specified that ‘Establishment of operational context is a requirement of the risk assessment process. A consultative approach with stakeholders must be used to determine the context’. Deficiencies in stakeholder consultation diminished the likelihood of the context being correctly defined.
  • The scope documented in the risk management plan was specific to the rail operations and safeworking activities for (signal) commissioning, referring to previous commissioning activity. This scope was not fully reflective of the extended period of passenger and freight operations between Donnybrook and Kilmore East. This scope definition limited the scope of hazard scenarios and risks being considered.
  • The effectiveness of controls at addressing identified risks was not recorded in the risk management plan. The ARTC work instruction for the application of risk management stated that it was essential to ‘determine whether the control (or combination of controls) adequately reduces the risk level’ and ‘identify whether additional control(s) are required’.
  • Individual risk control owners were not identified in the risk management plan, either by name or position. ARTC’s work instruction for the application of risk management stated that control owners were responsible for taking remedial action to address identified deficiencies of controls.
  • Controls were identified within the risk management plan but not implemented. Specifically, pilotage was identified as a control but was replaced by an AQW in practice.
  • Treatments considered but rejected were not documented. ARTC’s procedures stated that ‘It is essential that rejected proposed treatments and information regarding the decision to reject the proposed treatment is recorded against the risk…’.

It was concluded that ARTC risk management and oversight processes resulted in a risk management plan that was limited in context, scope and risk identification and, as a consequence, risk controls had significant weaknesses. The non-integrated and manual aspects of the process design introduced potential points of failure.

Risk controls for train working arrangements

Scope

The risk management plan set out a range of risk controls for 10 risk items that had been identified. The following risk controls used in train working arrangements from 6 February and that were most relevant to this occurrence are discussed in this section:

  • the issuing of train notices
  • the issuing of a train authority for each train movement
  • a rail worker to accompany each train movement.
Train notices

The risk management plan listed ‘train notices detail the commissioning activities’ as an administrative control for network controller officers (NCOs) not being aware of the proposed changes. The train notice being issued in a timely fashion was also listed as an administrative control for rail operators not being aware of the train working arrangements.

A train notice can provide early advice on changed network conditions although notices were acknowledged by ARTC as a ‘minimally effective’ risk control.[122] Weaknesses included potential points of failure in document distribution and receipt (that are discussed later in the analysis).

In addition, the effectiveness of train notices can be influenced by their form, content and complexity. TN 266 was a detailed 6-page document describing processes that deviated from established and accepted practices and was amended and reissued twice. As a result, interpretation of this detail and commitment to memory was likely varied across the driver community.

The risk management plan specified issuing train notices in a ‘timely fashion’. Although TN 266 and its revisions were issued prior to their application, there was limited time made available for operators to distribute the notice to key personnel, including safety and risk management staff and drivers. This in turn limited the opportunity for full consideration of the notice detail, internal consultation, driver briefing and implementation of additional risk controls by rail operators.

The veracity of TN 266 was also undermined by its inconsistency with the in-field processes that were implemented by ARTC and ActivateRail, and a lack of clarity in some areas. Examples included:

  • TN 266 specified that the signaller was to deliver the train authority to the driver whereas the practice was to deliver the train authority to the driver via the AQW.
  • TN 266 described that the driver must sign for the train authority on the butt of the form. However, there was no provision on the train authority for the driver to sign off.
  • TN 266 (original issue) specified that the driver must verify the train authority with the NCO. This requirement was not clear and could reasonably be interpreted as verification of the content of the authority by readback, as was undertaken by a number of drivers. The revised TN 266 (amended 13 February) specified that readback was not required.
  • TN 266 (amended 13 February) added the explicit requirement that the driver must approach the level crossing with caution, and be prepared to stop short of the crossing unless the ‘all clear’ hand signal has been provided. The application of the ‘prepared to stop’ clause (in practice) probably varied among drivers, and would have required a significant slowing of trains ahead of the crossing. Verbal (mobile phone) confirmation by the LCK (to the AQW) was probably often used to confirm that the crossing protection was activated and the train was clear to pass.
  • Review of train authority records also identified that on several occasions a train authority for the single line section between Donnybrook and Kilmore East NCO was issued prior to the previous train authority being cancelled, and so contrary to the requirements of TN 266.

It was concluded that the effectiveness of the issued train notice TN 266 and its amendments was undermined by their form, their inexactness, the limited consultation with stakeholders, the method of distribution and their release only a short time before coming into effect.

The issuing of a train authority

The processes established under TN 266 was for the train authority to be issued to the signaller rather than to the driver and there was no protocol to confirm that the driver, the actioning ‘receiver’ of the train authority information, understood the contents of that authority. Network rules (TA20) described that the receiver must confirm the content of a message by repeating the message back exactly as it was received, and that the receiver must not act on the communication until the sender confirms that the message has been repeated correctly.[123] However, driver readback of the train authority was actively discouraged, both in the amended TN 266 (13 February) and by ARTC network control.

Readback of safety-critical information is adopted by industries to ensure information is correctly understood by the sender and the (actioning) receiver, in this case the NCO and the driver. The absence of a protocol that would confirm driver understanding of the train authority was inconsistent with industry practice, and a significant weakness in this risk control. This weakness was exposed following the change to the train authority for routing of trains through Wallan Loop on 20 February and the absence of driver readback of the train authority process established on 6 February was probably a contributing factor to this occurrence.

A significantly more reliable method of issuing a train authority was directly from the NCO to the driver. This process would have involved the driver completing their copy of the train authority from the narration of its content by the NCO, and then repeating back its contents to the NCO to confirm its accuracy. Both the completion of the train authority form by the driver and the repeat back process would increase the likelihood of driver understanding. This process would probably have taken 2–3 minutes in this instance.[124]

Although less reliable than the NCO directly issuing the train authority to the driver, there were other enhancements to the process used that would have improved its effectiveness, including a mandated readback of the authority by the driver to the NCO. The repeating back of the information from the driver to the NCO was a practicable control, evidenced by some drivers repeating back the train authority even though this was not a requirement of TN 266.

A second weakness in the train authority process was its indirect delivery to the driver. Even though TN 266 described the signaller issuing the train authority to the driver, the accepted practice was for the train authority to be passed from the signaller to the AQW, and then from the AQW to the driver after boarding the train. This was contrary to the principles of TA20 that described relaying of communications by a competent worker (only) if it was not possible for a sender to communicate directly with an intended receiver.[125] This indirect delivery removed the opportunity for direct dialogue and information exchange between the signaller and the driver.

Although a risk management plan was produced by ARTC for the application of train authorities, there was no human factors assessment that may have identified weaknesses in the control as it was being implemented. In particular, the potential for human error inherent in the indirect method of issuing the train authority to the driver and the absence of readback by the driver to confirm their understanding was not considered by ARTC.

Rail worker to accompany the driver

Two controls in the risk management plan advised of the intended presence of a pilot. The first was that ‘Trains are piloted through the section’, and the second was ‘Level crossing in place to operate test switch, pilot on train announces approach’. However, the risk control of a pilot was not implemented and instead an AQW was provided as the control.

Industry references, including ARTC procedures, described a pilot as having a role that included providing direction to train crews and having interactions with the NCO. The Australian industry standard for the competency of piloting rail traffic (released after this occurrence) required a pilot to have demonstrated detailed knowledge of the route and the operating conditions.[126] Pilotage would therefore be expected to be a broader risk control than an AQW, and there would be less potential for an authority gradient with the driver.

In contrast, AQWs had limited tasks and were not required to have knowledge in train operations, nor be assessed as having route knowledge and front-of-train experience on the section of track between Kilmore East and Donnybrook. The absence of clearly defined qualification, capability and knowledge requirements weakened this control.

Tasks of the AQW included delivery of the train authority and CAN notice to the driver and to call the LCK to activate the level crossing protection at Wallan–Whittlesea Road. Evidence suggests that all AQWs involved in these processes successfully performed these tasks.

Potential risk controls that were not used

For signalling failure within a centralised traffic control (CTC) section, TA20 included train working processes using caution orders and other safeworking processes.[127] These processes were used up to 6 February and could have been continued for the full period of repairs. However, the impact on the service schedule was substantial due to the 25 km/h speed limit, increasing transit times to an hour or more (Table 5).

Table 5: Transit times for different average speeds through the affected 24 km section

Average train speed18 km/h24 km/h72 km/h96 km/h120 km/h
Transit time (min)8060201512

From 6 February, a potential additional risk control was to apply a temporary speed restriction (TSR) to the Kilmore East to Donnybrook section while rail traffic was operating under administrative controls and without signals. Although not formalised as an instruction, several V/Line drivers chose to run at a slower speed through the affected section. Limiting train speed was not a control in the risk management plan nor was the control referenced as being considered and rejected.

Stakeholder engagement for train working arrangements

Consultation with stakeholders was a key component of the Australian and international standard for risk management (Standards Australia 2018). However, there was limited engagement and consultation with rail operators for the establishment of the train working arrangements that deviated from the standing network rules. Risk worksheets were only released to V/Line and labour hire firm Programmed (the day after implementation) and were not distributed to NSW Trains and freight operators.

The timeframe for V/Line to respond to the arrangements and the exclusion of several rail operators from the process, including the XPT operator, was a significant weakness in engagement strategy and risk management. These factors limited the opportunity for network users to influence risk identification and controls to manage those risks, and the opportunity to consider additional (direct) risk controls that operators might implement for their operations.

ARTC engagement with rolling stock operators continued to be limited after commencement of the train working arrangements even though there was disquiet amongst some drivers. Operator queries and feedback on the train working arrangements, while resulting in some amendments to TN 266, did not trigger a deeper review by ARTC of the risks to train operations and the adequacy of the risk controls that were being implemented.

It was concluded that ARTC risk management and oversight processes did not result in effective stakeholder engagement to support risk management and the development of risk controls for train working arrangements that deviated from ARTC network rules (TA20). This increased the safety risk associated with the rail operations.

Contractor involvement in the establishment of the arrangements

ActivateRail was engaged by ARTC to develop and manage a safeworking solution for train working between and Donnybrook and Kilmore East. Industry contracting guidelines (RISSB 2017) discussed the primary safety duty as being with the accredited operator (ARTC in this case), while also acknowledging the shared responsibilities of contractors to achieve safety outcomes.

ActivateRail contributed to the development of train working arrangements that were inadequately supported by risk management processes. ActivateRail did not have systems that ensured that its contributions were consistent with the risk management procedures of the accredited rail infrastructure manager (ARTC) and Australian risk management standards.

Example of increased risk during temporary signal suspension

A 2018 collision in the USA provides an example of increased risk associated with rail operations during signal suspension and highlights the importance of stakeholder engagement and risk assessment to manage these risks.

In February 2018 in Cayce, South Carolina, a train collided head-on with another, resulting in the death of the driver and conductor of an Amtrak Train, and injury to 115 passengers. The accident was investigated by the National Transportation Safety Board (NTSB 2019), and the identified probable cause of this collision was the failure to assess and mitigate the risk associated with operating through a signal suspension. The management of risk during signal outages was a matter considered further by the Federal Railroad Administration (FRA) and a review of FRA incident data showed that operations during suspended signal system presented increased safety risks (DOT 2018).

Arrangements for transit through Wallan Loop on 20 February

Risk management and stakeholder engagement

For the routing of trains through No.2 track at Wallan Loop on 20 February, there was no documented risk assessment or review of risk controls, and there was no review or update of the risk management plan. ARTC risk management and oversight processes did not result in a risk assessment of the (new) introduced risk of derailment at the low-speed turnouts, and implementation of available and practical risk controls that would manage that risk.

There was also limited engagement with rail operators and limited opportunity for operators to contribute to a review of risk controls. During the afternoon of 19 February 2020, ARTC provided V/Line with a draft of the train notice for the changed condition at Wallan Loop, although no assessment of risks or listing of controls accompanied the notice. The draft was circulated within V/Line and an opinion expressed within V/Line that ‘at the very least, there should be track force protection’ due to the changed running from No.1 track to No.2 track. V/Line was subsequently proactive in issuing its own safety circulars on the change and directly advising affected drivers of this changed condition at Wallan Loop.

There was no similar direct issue of pre-information on the changed condition at Wallan Loop provided to NSW Trains or freight operators. NSW Trains was therefore not provided with the opportunity (as had been given to V/Line) to consider the implications of the change during the afternoon of 19 February and consider pre-emptive actions. Their only potential pre-information for the organisation was via the issue of TN 367 on the evening of 19 February, and this notice was not collected by NSW Trains.

It was concluded that for the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in effective engagement with all rail operators impacted by this change. There was no engagement strategy and passenger train operator NSW Trains was not directly advised of the change.

Risk controls used

Existing controls were utilised for the routing of trains through Wallan Loop, with some expansion as described below:

  • the issue of train notices (train notice 367 was issued)
  • the issuing of a train authority for each train movement (no change to process, text of train authority updated)
  • a rail worker to accompany each train movement (additional tasks allocated to AQW).
TN 367

Issuing train notices was an existing control, and for the change at Wallan Loop TN 367 was issued. TN 367 described the change to operations via No.2 track and was distributed as an additional instruction to TN 266. It was issued on 19 February 2020 on the ARTC web portal, reportedly at about 1815 Adelaide time (1845 in Victoria and NSW). This was 15 minutes later than the listed time of daily publishing of notices on this portal. The issue of this notice on the evening prior to implementation was not consistent with the risk control of train notices in a ‘timely manner’, particularly in the context of the significance of the changed conditions.

This risk control relied on operators accessing the portal after it being published, processing that information internally, distributing the notice to those affected within their organisation, and potentially considering taking additional precautioning action. In the case of V/Line, the earlier awareness of the notice provided greater opportunity for this activity. In the case of NSW Trains, TN 367 was not obtained from the ARTC portal and TN 367 was not known to NSW Trains.

TN 367 was known to the NCO, signaller and AQW who were on duty on the evening of 20 February. They had all received direct copies of the notice, were familiar with its contents and were all aware of the routing of trains through No.2 track at Wallan Loop.

Issuing the train authority

For the changed conditions at Wallan Loop, there were changes to the content of the train authority but no change to the process of issuing the train authority under TN 367. The train authority was accurately updated to include specific detail on the routing of trains through No.2 track and the speed requirements at the entry to, and exit from, the loop. However as noted earlier in the analysis, the changes to the train authority text were not highlighted and the changes were probably missed by the driver of ST23.

The effectiveness of this risk control was already compromised by the existing process weaknesses, including the indirect issuing of the train authority and the absence of a full readback of the content of the train authority by the driver. The gap in confirming driver understanding became a critical weakness when the conditions at Wallan Loop changed. The driver of ST23 did not (and TN 266 instructed that they should not) read back the content of TA 17 prior to entering the affected section. It is very likely that readback would have resulted in the driver becoming aware of the routing of ST23 through Wallan Loop.

Rail worker to accompany the driver

This risk control was already compromised by the use of an AQW rather than pilot, and the absence of clearly defined qualification, capability and knowledge requirements for an AQW. These weaknesses were exposed when additional obligations were placed on the AQW in TN 367, and (for train ST23) the AQW risk control became the final opportunity to ensure the driver understood the changed conditions at Wallan Loop.

It has been concluded that the driver probably never became aware of the changed conditions at Wallan Loop. For such a scenario, the AQW risk control did not ensure that the driver of ST23 understood the changed conditions at Wallan Loop. There was insufficient evidence to conclude the reason for the probable breakdown of this process. A weakness in this control was the absence of any protocol for how driver understanding of the information on Wallan Loop might be confirmed (by the AQW), including no requirement for the driver to read back the train authority to the AQW. The effectiveness of this control was also probably not assessed for potential susceptibility to human error.[128]

In the case of train ST23, the susceptibility to human fallibility was probably augmented by the AQW on duty at the time of the derailment not being familiar with the corridor from the front of the train and this being their first time in the role. Had the AQW been familiar with the rail corridor and key landmarks, they would have been better placed to warn the driver of the overspeed of ST23 as it approached Wallan Loop.

Potential risk controls that were not used
Context

The decision to use Wallan Loop for rail operations on 20 February, and the introduction of low‑speed turnouts into the section, substantially increased the risk of derailment due to overspeed. The risk to passenger trains was heightened due to their line speed of 130 km/h and the potential for serious injury and fatality. The following are examples of additional risk controls that could have been considered to assist with the management of this risk.

Elimination of risk by not running passenger trains through No.2 track

The ARTC SMS identified that in situations where track was not used for some time, such as occurred with No.2 track at Wallan that February, track circuits could be at risk of unreliable detection due to rail head contamination. Trains were routed to run along No.2 track on 20 February to clean the rail head in preparation for testing and recommissioning of the signalling system at Wallan.

Instead of running passenger trains through Wallan Loop for the purposes of cleaning the rails, there were other options available that may have been considered, including a rail vehicle solely for that purpose or another cleaning process. In the absence of any risk assessment where options may have been raised and documented, there was no evidence identified that options other than running passenger trains through the loop were considered.

Temporary speed restriction for section

A potential risk control while routing through the loop was to apply a temporary speed restriction (TSR) to the Kilmore East to Donnybrook section operating under administrative controls. A suitable speed restriction for the full section, or part of the section that included Wallan Loop, would probably have reduced the risk of derailment due to overspeed at the Wallan Loop turnout.

Signage or conspicuous devices ahead of loop as visual cues

Potential (but not used) sources of information to alert the driver were speed signs and/or other conspicuous devices to advise of the reduced speed required to enter Wallan Loop. Without visual cues in the real-world environment, the driver was reliant on obtaining information solely from the administrative controls and remembering to later apply that information. Signage had the benefit of providing in-field cues to mitigate against the scenarios of failed administrative controls (to alert the driver of the changed conditions) and a failure of driver prospective memory. The use of signage was listed as a control for derailment in ARTC’s risk library.[129]

In-cab warnings as visual and audible cues

The XPT train was fitted with an in-cab equipment (ICE) digital train radio system as part of the National Train Communication System (NTCS). This system was used by some other networks for electronic authorities and proximity reminders for speed reduction.[130] ARTC had not implemented such systems on their network.

Track force protection

‘Track Force Protection in place as last form of defence’ was listed as a control in the risk management plan for the altered train working arrangements, although there was no context in the plan as to when, or when not, track force protection was to be applied.[131] TA 20 section 15, rule 3 described several circumstances where track force protection should be applied. These generally related to situations where equipment may be on track and not to the situation that existed at Wallan. Nonetheless, a form of protection through the section was practical and available and had been used for trackside works on the same day, and only a short distance from the loop.

Summary

For the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in the implementation of available and practical risk controls to manage the risk of derailment at the low-speed turnouts at Wallan Loop. Options included not running passenger trains through Wallan Loop, signage or other visual cues in the real-world environment, track force protection for the Wallan Loop section and a temporary speed restriction for part or all of the section.

Distribution of safety-critical information

Distribution by ARTC

For its Victorian network, each evening ARTC issued train notices (to rail operators) on its web portal.[132] This was a pull communication strategy that required rail operators to check the portal each evening. ARTC had a different method of issuing train notices applicable to its NSW network. In NSW, ARTC used a push communication strategy and SAFE notices were emailed to key contacts within rail operators, including NSW Trains. As a result, rail operators with operations in NSW and Victoria would receive ARTC safety notices in different ways, depending on the location.

Safety notices were a common mechanism for distributing safety information in many modes of transport and there were a range of strategies used to maximise the reach and reliability of information distribution. The methods used by ARTC to distribute safety information were sub‑optimal and there was scope to improve the effectiveness of this risk control and support the safety needs of rail operators.

NSW Trains
Accessing ARTC web portal

NSW Trains did not have a functioning process for accessing the ARTC portal for train notices applicable to its Victorian operations and instead relied on Victorian weekly notices which did not normally include the ARTC train notices. The discontinuation of routine checking of the ARTC portal for Victorian network safety notices followed changes to the NSW Trains internal structures in 2017. The loss of these processes reflects a failure of change management within NSW Trains at the time of restructure.

From 2017, there were very likely gaps in NSW Trains’ awareness of operational information for the ARTC network in Victoria, and gaps in weekly information packs provided to XPT drivers operating on that network. The repercussions were a diminished opportunity for NSW Trains to consider any new operational risks and possible controls, and the absence of pre-information to drivers on changes to network conditions.

Distribution to drivers

For drivers commencing their shift at Junee, NSW Trains prepared weekly information packs that were distributed via pigeonhole. NSW Trains did not have a functioning system to monitor that drivers starting their shift at Junee received and had understood distributed safety information. This potentially weakened the reliability of train notices as a risk control.

V/Line receipt and distribution of safety information

Aided by receiving advance information on the proposed train working arrangements directly from ARTC, V/Line distributed this information within its organisation. Then, following receipt of advance information on the changed conditions at Wallan Loop (in TN 367), V/Line was proactive in distributing TN 367 within its safety information system, and driver supervisors briefed affected drivers of the changed conditions at Wallan Loop.

Risk management on the ARTC rail network

Context

The risks and risk controls associated with overspeed derailment at low-speed turnouts on the ARTC network were considered more broadly in the context of the following occurrences in Victoria:

  • the derailment of a freight train at Benalla in June 2006 (ATSB 2007)
  • the overspeed of a V/Line passenger service at Wallan in July 2015 (ATSB 2017)
  • this most recent occurrence of ST23 derailment at Wallan in February 2020.

During normal operations, the primary risk control at the Benalla and Wallan turnout locations was driver compliance with signalling.[133] In the Benalla (2006) and Wallan (2015) occurrences, driver unawareness was a factor in the overspeed. In all three cases, the common factor was the residual risk of a low-speed turnout within the track section, and a failure of risk controls to manage that infrastructure risk.

As part of this (2020) investigation, the ATSB sought information from ARTC and V/Line on their consideration (following the 2015 occurrence) of train enforcement solutions at Wallan Loop to protect against train overspeed.[134] In response:

  • ARTC provided the advice that consideration of train enforcement solutions at Wallan Loop was a matter for V/Line. Following the 2015 overspeed event, there were also no other new risk controls implemented by ARTC at this location. The Office of the National Rail Safety Regulator also provided advice that it did not conduct audits or inspections of ARTC on the topic of the overspeed occurrence at Wallan Loop in 2015.
  • V/Line advised that an internal assessment following the 2015 occurrence had identified that there was a case for additional protection at Wallan and several other locations on the ARTC North-east line (in Victoria) to manage the risk of passenger train derailment due to overspeed. The train protection and warning system (TPWS)[135] was subsequently scheduled to be installed at Wallan and several other locations on the ARTC standard gauge corridor between Melbourne and Albury.[136] The installation was to be funded by the Victorian government.

The installation of TPWS on the standard gauge corridor would facilitate enforced braking of V/Line passenger trains at installed locations but would not provide overspeed protection for incompatible rolling stock operated by NSW Trains (for example, the XPT and its replacement) and freight operators.[137]

Potential barriers to improvements in rail safety
Scope

This section of the analysis discusses identified potential barriers to safety improvements on the national rail network. It is beyond the scope of this investigation to quantify the influence of these factors on safety risk and the conclusions are listed as general findings to this report.

The following are discussed:

  • ARTC risk management for passenger train safety
  • the overlapping safety responsibilities of ARTC and rolling stock operators
  • slow adoption of available technologies
  • diversity of train protection systems in Australian rail networks.
ARTC risk management for passenger train safety

An operator on the ARTC network (V/Line) found that the residual risk of derailment (due to overspeed) for its passenger services should be reduced at higher risk locations on that network. This raises questions as to the role of the RIM in assessing and managing residual risk to passenger train safety that is primarily a result of hazards associated with infrastructure layout. Review of ARTC risk materials found that the ARTC enterprise risk management system (ERMS) was opaque on the assessment and treatment of the risk of passenger train derailment due to overspeed. This opacity had the potential to result in missed opportunities for ARTC to identify and implement additional risk controls to advance safety for passenger train operations on the ARTC network.

Considering the overspeed occurrences at Benalla and Wallan specifically, it was concluded that there were opportunities for improved safety management at higher risk locations that included low-speed turnouts. Examples of risk controls available to ARTC as the rail infrastructure manager at these higher risk locations included speed limits, changes to track and/or signalling infrastructure, and a variety of technological solutions to reduce the likelihood, or manage the outcome, of human error. In the absence of action by ARTC at these higher risk locations, unilateral action has been taken by one passenger train operator (V/Line) to address the potential for train overspeed at such locations. Other above rail operators will not benefit from these risk controls.

Safety responsibilities of infrastructure managers and rolling stock operators

Rail safety regulation in Australia described safety responsibilities (individually) applicable to the rail infrastructure manager (RIM) and the rolling stock operator (RSO). The mechanism for the management of overlapping regulatory obligations to reduce risk so far as is reasonably practical (SFAIRP) was less clear. The safety interface agreement was one available vehicle to facilitate engagement and potentially achieve joint safety outcomes. In the instance of ARTC and NSW Trains, the (safety) interface agreement had not been updated since 2011 and did not provide evidence of a proactive consultative regime that contributed to improved safety.

Barriers to improved safety on the ARTC rail network include the absence of an effective concept of shared safety responsibility between RIM and RSO, mechanisms that encourage proactive safety improvement where safety responsibilities overlap, and a framework to resolve funding barriers.

Slow adoption of available technologies

Metropolitan and several regional networks in Australia have adopted technological solutions to mitigate the risks associated with human error. Examples of regional applications include train protection and warning systems on the Victorian regional network, and in-cab information and warning systems on the NSW country regional network.

The roll out of available technologies on the ARTC network was slow by comparison. The ARTC advanced train management system (ATMS) was initiated by ARTC in 2005 and was operational on only a small portion of its network, and opportunities to utilise existing train radio systems to enhance in-cab information and warning had not been taken.

Diversity of train management systems in Australian rail networks

Technological advances in train management systems provide opportunities for significant improvements in the safety of rail transport. There are several technical options and rail networks around Australia are adopting an array of solutions to meet their operational needs (RISSB 2021b).[138] Each network solution requires network users (rolling stock) to interface with the management system for that network.

The range of systems being adopted across Australia raises questions around interoperability and the safety implications of an uncoordinated application of train management technologies.[139] An uncoordinated approach may result in lost opportunities for improved safety while also introducing interface risks.

Power car survivability

Detachment of driver’s cab door

When the leading power car overturned and slid on its side, the left-side driver's cab door detached from the door frame. Although the sequence of door component failures could not be ascertained with certainty, analysis confirmed that the knuckles of the upper hinge would probably unfurl during an overturn event, and that the door attachments were probably not designed to withstand such a loading scenario.

The left-side cab door probably detached early in the sequence of the power car overturning and sliding. With the door aperture open, ballast and earth entered the cab, impacting and trapping the driver and the accompanying qualified worker (AQW) who were inside. A similar derailment in Ufton Nevert in the United Kingdom where the train driver died involved the overturn of a power car of similar design (to the XPT) and track material entering the driver’s cabin.

Contemporary Australian industry standards referred to international standards that required cab side doors to meet external pressures that had aerodynamic origins. Neither these standards nor the Australian standard covering structural integrity included requirements for cab doors following overturn. There was no other Australian standard identified that included requirements to prevent or mitigate against the potential ingress of ballast materials into the driver’s cab following overturn.

Access and egress

Access was available to the driver’s cab via the right-side door, however it proved a difficult route to provide assistance to the driver and AQW in the overturned power car. Without ground-level access to the interior of the cab, passenger services crew and emergency first responders were inhibited in their ability to provide effective assistance to the trapped driver and AQW, prolonging the train crew’s exposure to the adverse environment within the cab.

Contemporary Australian rail industry standards did not include requirements for ground-level access to or egress from driver's cabs in the event of a rollover.[140] This can hinder escape by occupants or immediate access to rolling stock interiors by other crew members and first responders.

Fuel tank breach

The lower left-side edge of both fuel tanks on the leading power car were breached, allowing diesel fuel to drain from the tanks. The fuel tanks were single-skinned and exposed to penetrating and abrading materials in the case of derailment.

The derailment and overturn of a CountryLink Xplorer at Baan Baa in May 2004 resulted in the Office of Transport Safety Investigation (OTSI) recommending that the rolling stock owner (Railcorp at that time) review ‘the design, positioning and protection of fuel tanks on its diesel fleet’ (OTSI 2005). A review of records indicated that a response was provided to the rail regulator by Railcorp indicating that its review had found that there was no significant risk reduction to be obtained by changing the design, positioning and protection of fuel tanks on its diesel fleet.

Passenger safety

Scope

Following the derailment, some passengers started to self-evacuate the train onto the adjacent tracks prior to the train crew directing an evacuation, and prior to the crew receiving confirmation that all trains had been stopped.

This section of the analysis considers the factors that may have led to the passengers’ actions, including the safety information provided prior to the derailment, the communication from crew members during the incident and the training received by crew members to be able to manage such incidents.

Passenger safety information
Overview

The post-occurrence passenger survey revealed a low level of assimilation of onboard safety information and it is probable that the majority of passengers on ST23 were not aware of the specified actions for passengers in the case of an emergency event such as derailment. A range of reasons were given by passengers, including not recalling or not paying attention to safety announcements, and not reading the safety information located at the rear of the onboard guide.

Although passenger attention to safety briefings and retention of the information provided is difficult to ensure, it is important that operators provide passengers the best opportunity of receiving and comprehending safety information. NSW Trains provided passenger safety information to passengers in various formats, including verbal and written information. However, the methods used to convey safety information in this case were not effective for probably the majority of passengers. This meant that, following the derailment, there was greater reliance on passenger services crew to provide instructions to passengers on what to do, and specifically the instruction to remain on the train until it was confirmed safe to evacuate.

Verbal briefing

Passenger inability to recall that information had been provided does not mean that they did not receive the information, however it does indicate that the methods used to provide the information had limited effectiveness.

Although there was a standard announcement documented within the operator’s procedures, it was probably not unusual for a passenger services supervisor (PSS) to prepare their own briefing. This meant that it could not be assured that passengers would receive safety information fully consistent with the NSW Trains’ guidelines.

In addition, there were occasions where passengers boarded at intermediate stations where the briefing was not provided, and in the case of ST23 a full safety briefing was not given in Albury. Any gaps in verbal briefing were compounded by ineffective onboard written safety information.

Written information

Printed instructions provide passengers with a greater opportunity to understand emergency information. This is particularly important when not all passengers receive a verbal briefing when they first board a train.

Passengers on the XPT were provided written safety information in an onboard guide that contained other information not relevant to safety. The passenger survey indicated that only a small portion of passengers accessed that information, and some passengers also commented that information presented like that on airlines (as a safety card) may have been helpful.

The safety information in the onboard guide was presented without any pictorials. Research supports the combination of text and pictorials, particularly for information that is not familiar. The use of both text and pictorials can increase a person’s ability to translate meaning (Mandl and Levin, 1989). In addition to the format of the written information, it was reported that the onboard guides were not present in the back of every passenger seat. 

In addition, signage containing simple instructions to guide passengers on what to do in an emergency were not present on ST23. Some of the surveyed passengers mentioned that better signage on the seat in front of them or at the end of carriages may have been helpful.

Communication to passengers in an emergency

Following the derailment, not all passengers received immediate instruction to remain on board the train. This was in part due to the location of the passenger services crew members at the time of the derailment, which limited the opportunity to immediately communicate directly with passengers in remote passenger cars. As a result, some passengers decided to self-evacuate, probably within a few minutes of the derailment and prior to the adjacent tracks being confirmed by the passenger services crew as being safe for the evacuation.

This situation highlights the importance of communicating with all passengers quickly, especially when they are physically dispersed in different passenger cars. Crew members might achieve this via the use of the public address (PA) system or megaphones. Neither the PA system nor megaphones were used in this instance.

NSW Trains’ procedures referred to the use of the PA system in an evacuation to advise passengers to be prepared to evacuate, however there was no procedure that provided train crew with standard phrases or positive commands to inform passengers of the need to remain on board the train.

The incident response summary guidance located at the passenger service crew stations on ST23 were comprehensive, however they could not be considered a quick reference. Additionally, there was no reference to the use of the megaphones in an emergency to assist in maintaining control of passengers on board, or once they had been evacuated.

Passenger services crew training in emergency procedures

All the passenger services crew members except one had completed some form of emergency and evacuation training. The training included material related to a train derailment and an opportunity for participants to talk through scenarios. However, none of the scenarios were hands‑on or practical in nature. Research (Arthur et al. 2013) shows the importance of practice for skill acquisition and retention, particularly for those tasks that may not be performed on a regular basis.

It is acknowledged that a 2019 NSW Trains training needs analysis identified that evacuation‑related competencies for passenger services crew should be trained and assessed practically. However, changes recommended by this review had not yet been implemented at the time of the Wallan derailment.

Training and assessment administration

Administrative processes for the conduct of written assessments (in this case for emergency and evacuation training) of the passenger services crew on ST23, such as signing of examinations, recording of marks, and the use of the documented marking system, were not consistent with the principles of assessment and rules of evidence (ASQA 2015).

Not all passenger services crew members had been recorded as having completed the required emergency procedures training and some were outside the recurrency requirements. There was also no matrix or recording system that identified the required training and frequency for different crew roles. This meant that the management of the train crews’ competency in emergency procedures was inconsistent and it was unclear how the standards were being applied.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the derailment of train ST23 at Wallan on 20 February 2020.

Contributing factors

The derailment
  • Low-speed (15 km/h) turnouts from the 130 km/h through track at Wallan Loop resulted in a risk of derailment due to train overspeed. This risk was re-introduced into the section on 20 February.
  • Train ST23 did not slow sufficiently to negotiate the turnout to Wallan Loop. ST23 was travelling at between 114 and 127 km/h when it entered the turnout compared to the specified operational speed for the turnout of 15 km/h.
  • The driver was probably unaware of the routing of ST23 into Wallan Loop and their understanding of this routing was not confirmed. During the preceding 12 days, the driver had very likely developed a strong expectation that while signals were not operating trains were not being routed via No.2 track at Wallan Loop.
Train working arrangements and risk management
  • The driver of ST23 did not (and was not required to) read back the content of train authority 17 prior to entering the affected section. Readback of the train authority would likely have resulted in the driver becoming aware of the routing of ST23 through Wallan Loop.
  • Train working arrangements established by ARTC on 6 February 2020 excluded communication protocols to confirm driver understanding of the content of the train authority giving them permission to enter that section. This gap in communication protocols became a critical weakness in this risk control when the track configuration was changed to route trains through Wallan Loop on 20 February.
  • For the routing of trains through Wallan Loop on 20 February, ARTC did not implement available and practical risk controls to manage the risk of derailment due to overspeed at a Wallan Loop turnout.
  • For the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in a documented assessment of the introduced risks and the application of controls necessary to manage those risks. (Safety issue)
  • For the routing of trains through Wallan Loop on 20 February, ARTC processes did not result in its effective engagement with network users that would be affected by this change. (Safety issue)
Power car survivability
  • The power car left-side door detached from its frame when the power car overturned and slid on its side. This allowed earth and ballast materials to enter the driver’s cab of train ST23, impacting and trapping the driver and the accompanying qualified worker.
  • Passenger services crew and first responders were unable to render immediate and effective assistance to the trapped driver and accompanying qualified worker due to the lack of ground level access to the driver's cabin.

Other factors that increased risk

Risk management
  • For the establishment of train working arrangements that deviated from ARTC network rules, ARTC risk management and oversight processes resulted in a risk management plan that was limited in context, scope and risk identification and risk controls that had significant weaknesses. (Safety issue)
  • For the establishment of train working arrangements that deviated from ARTC network rules, ARTC stakeholder engagement did not support its management of the safety risks to network users and the development of agreed risk controls.  (Safety issue)
  • For the establishment of train working arrangements that deviated from ARTC network rules, ActivateRail did not implement processes to ensure its contributions were consistent with the risk management procedures of the accredited rail infrastructure manager (ARTC) and Australian risk management standards. (Safety issue)
Train working arrangements
  • ARTC use of train authorities in the circumstances that were present between Donnybrook and Kilmore East in February 2020 was not provided for in the ARTC Code of Practice for the Victorian Main Line Operations (TA20). In the absence of effective risk management and stakeholder engagement, deviation from the established practices introduced the potential for a degraded level of rail safety.
  • The effectiveness of the ARTC train notices as a risk control was undermined by their form, their inexactness, the limited consultation with stakeholders that would be affected, their method of distribution, and their release only a short time prior to each coming into effect.
  • The practice of the train authority being delivered to the driver by the accompanying qualified worker rather than directly from the signaller removed an opportunity for direct contact and an exchange of safety information between the signaller (who had been issued the train authority by the network control officer) and the driver.
  • ARTC did not specify the qualification and knowledge requirements of persons who were to perform the safety critical role of an accompanying qualified worker. (Safety issue)
  • The accompanying qualified worker used by ARTC for train ST23 was not familiar with the rail corridor environment between Kilmore East and Donnybrook from front of train.  
Distribution of safety critical information
  • ARTC distribution of safety information by train notice was sub-optimal. There was scope to improve reliability of safety information distribution and to consider opportunities for operators in Victoria (and SA and WA) to receive direct distribution of train notices for their operations on the ARTC network. (Safety issue)
  • NSW Trains did not have a functioning process for obtaining safety information from the ARTC web portal for its rolling stock operations within Victoria and did not routinely obtain ARTC train notices. (Safety issue)
  • NSW Trains did not have a functioning system to monitor that drivers starting their shift at Junee received and had understood distributed safety information. (Safety issue)
Power car survivability
  • Contemporary Australian industry rail standards did not include structural requirements for cab doors, or other performance-based requirements, that addressed the protection of train crew in the case of vehicle overturn. (Safety issue)
  • Contemporary Australian industry rail standards did not include requirements for ground-level access to or egress from driver's cabs in the event of a rollover. (Safety issue)
Passenger safety
  • A significant number of passengers self-evacuated onto tracks that had not been confirmed safe by the train crew.
  • The majority of passengers on ST23 were probably not aware of the NSW Trains’ specified actions for passengers in the case of an emergency event such as derailment.
  • NSW Trains’ methods of providing safety information to passengers (including verbal safety briefings, onboard guides and signage) did not provide reasonable opportunity for all passengers to have knowledge of what to do in an emergency. (Safety issue)
  • NSW Trains’ procedures did not provide specific instructions to passenger services crew on when, how and what to communicate to passengers in an emergency. (Safety issue)
  • NSW Trains’ training of passenger services crew did not include periodic simulated exercises that would allow crew members to demonstrate and maintain the knowledge and skills required in an emergency. (Safety issue)
  • NSW Trains did not have systems in place to achieve outcomes in emergency response training consistent with its competency framework for passenger services crew. (Safety issue)

Other findings

Factors unlikely to have influenced occurrence
  • Evidence suggests that both the driver of ST23 and the accompanying qualified worker were fit for normal functioning and were not incapacitated at the time of the derailment.
  • Rolling stock testing, inspections, and a review of maintenance records did not identify an adverse condition or defect that was likely to have contributed to the derailment.
  • There was no evidence identified to suggest that the condition of the track at the northern entry to Wallan Loop was a factor in the derailment.
Voice recorders on rolling stock
  • Voice recording within the driver’s cab would have assisted the investigation to examine the interactions within the cab, and to potentially identify additional safety factors.
Potential barriers to safety improvements on the ARTC rail network
  • The ARTC enterprise risk management system was opaque on the assessment and treatment of the risk of passenger train derailment due to overspeed at higher risk locations (such as Wallan Loop). This probably resulted in missed opportunities for ARTC to identify and implement additional risk controls to advance safety for passenger train operations on the ARTC network.
  • Where risks were shared between the rail infrastructure manager (RIM) and rolling stock operators (RSO), there was the potential for lost opportunities for safety improvement. A review of the (safety) interface agreement between ARTC and NSW Trains did not identify an active safety interface mechanism for the promotion of improved safety.
  • The rollout of technological solutions on the ARTC rail network to mitigate risks associated with human error was slow in comparison with several other regional rail networks in Australia.
  • The uncoordinated application of train management technologies on Australian rail networks could result in lost opportunities for improved safety while also potentially introducing interface risks.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Risk management for routing trains through Wallan Loop

Safety issue number: RO-2020-002-SI-01

Safety issue description: For the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in a documented assessment of the introduced risks and the application of controls necessary to manage those risks.

Stakeholder engagement for routing trains through Wallan Loop

Safety issue number: RO-2020-002-SI-02

Safety issue description: For the routing of trains through Wallan Loop on 20 February, ARTC processes did not result in its effective engagement with network users that would be affected by this change.

Risk management to deviate from network rules

Safety issue number: RO-2020-002-SI-03

Safety issue description: For the establishment of train working arrangements that deviated from ARTC network rules, ARTC risk management and oversight processes resulted in a risk management plan that was limited in context, scope and risk identification and risk controls that had significant weaknesses.

Stakeholder engagement to deviate from network rules

Safety issue number: RO-2020-002-SI-04

Safety issue description: For the establishment of train working arrangements that deviated from ARTC network rules, ARTC stakeholder engagement did not support its management of the safety risks to network users and the development of agreed risk controls.

Contractor processes to support deviation from network rules

Safety issue number: RO-2020-002-SI-05

Safety issue description:For the establishment of train working arrangements that deviated from ARTC network rules, ActivateRail did not implement processes to ensure its contributions were consistent with the risk management procedures of the accredited rail infrastructure manager (ARTC) and Australian risk management standards.

Definition of knowledge requirements of safety critical workers

Safety issue number: RO-2020-002-SI-06

Safety issue description: ARTC did not specify the qualification and knowledge requirements of persons who were to perform the safety critical role of an accompanying qualified worker.

ARTC distribution of safety information

Safety issue number: RO-2020-002-SI-07

Safety issue description: ARTC distribution of safety information by train notice was sub-optimal. There was scope to improve reliability of safety information distribution and to consider opportunities for operators in Victoria (and SA and WA) to receive direct distribution of train notices for their operations on the ARTC network.

NSW Trains collection of safety information

Safety issue number: RO-2020-002-SI-08

Safety issue description: NSW Trains did not have a functioning process for obtaining safety information from the ARTC web portal for its rolling stock operations within Victoria and did not routinely obtain ARTC train notices.

NSW Trains distribution of safety information to drivers

Safety issue number: RO-2020-002-SI-09

Safety issue description: NSW Trains did not have a functioning system to monitor that drivers starting their shift at Junee received and had understood distributed safety information.

Standards for protection of train crew from debris

Safety issue number: RO-2020-002-SI-10

Safety issue description: Contemporary Australian industry rail standards did not include structural requirements for cab doors, or other performance-based requirements, that addressed the protection of train crew in the case of vehicle overturn.

Standards for accessing crew in overturned vehicle

Safety issue number: RO-2020-002-SI-11

Safety issue description: Contemporary Australian industry rail standards did not include requirements for ground-level access to or egress from driver's cabs in the event of a rollover.

Safety information for passengers of XPT

Safety issue number: RO-2020-002-SI-12

Safety issue description: NSW Trains’ methods of providing safety information to passengers (including verbal safety briefings, onboard guides and signage) did not provide reasonable opportunity for all passengers to have knowledge of what to do in an emergency.

Safety recommendation description: The Australian Transport Safety Bureau recommends that NSW Trains undertake further work to improve the methods used to provide safety information to ensure that passengers are given a reasonable opportunity to gain knowledge of what they may be required to do in the event of an emergency.

Guidance on passenger communications in an emergency

Safety issue number: RO-2020-002-SI-13

Safety issue description: NSW Trains’ procedures did not provide specific instructions to passenger services crew on when, how and what to communicate to passengers in an emergency.

Simulated exercises in emergency management training

Safety issue number: RO-2020-002-SI-14

Safety issue description: NSW Trains’ training of passenger services crew did not include periodic simulated exercises that would allow crew members to demonstrate and maintain the knowledge and skills required in an emergency.

Competency management of passenger services crew

Safety issue number: RO-2020-002-SI-15

Safety issue description: NSW Trains did not have systems in place to achieve outcomes in emergency response training consistent with its competency framework for passenger services crew.

Safety actions not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future.
ARTC

ARTC advised that a standing Train Notice has been issued requiring the Network Controller, when issuing a Train Authority to the Rail Traffic Crew, to receive a read back of the Train Authority from the Rail Traffic Crew in full. Confirmation of having read and understood the content of Train Authority is provided by the Rail Traffic Crew via signature, with the time of the Train Authority read back also recorded.

NSW Trains

NSW Trains advised that it has taken the following additional steps to reduce the risks associated with this type of occurrence in the future:

  • Introduction of a range of initiatives to enhance safety critical communications including:
    • the development of a new program to strengthen the quality of safety critical communication across all NSW Trains rail safety workers (as well as digitisation)
    • benchmarking of NSW Trains' systems against safety critical communication systems used by other rail operators
    • five risk workshops with key internal and external stakeholders to identify opportunities to strengthen safety critical communications
    • exploration of future digital solutions for safety critical communications.
  • Additional resources to ensure that NSW Trains has 24/7 shift manager coverage to enhance frontline crew ability to liaise directly with a supervisor.
Programmed

Programmed advised that actions undertaken to strengthen existing controls around placement of rail workers included:

  • Receiving job orders from customers and confirming these in writing by the recruitment and placement teams following a verification against recognised competency frameworks and network rules ie RISSB, TA20 etc.
  • Employing a dedicated National Rail Training and Compliance Manager who is responsible for monitoring and verifying RIW competencies of Programmed’s rail safe working crews.  This extends to arranging RIW refresher training.
  • Implementing a new technology platform for undertaking desktop and in field audits that includes a verification of training and qualification to the role types being supplied.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Australian Rail Track Corporation
  • NSW Trains
  • Sydney Trains
  • ActivateRail
  • Programmed
  • ARG Rail
  • V/Line
  • Office of the National Rail Safety Regulator
  • Victoria Police

References

ASQA (Australian Skills Quality Authority) (2015) Standards for Registered Training Organisations (RTOs) Table 1.8-1 Principles of assessment [contained in Users Guide to Standards for VET Accredited Courses, Appendix 6: Principles of Assessment]

ATSB (Australian Transport Safety Bureau) (2007) Rail Occurrence Investigation Report 2006005 Derailment of Train 5MB7 at Benalla, Victoria on 2 June 2006, Australia.

ATSB (Australian Transport Safety Bureau) (2017) Investigation RO-2015-011 Over-speed of V/Line passenger train 8625 over points at Wallan loop Wallan, Victoria on 11 July 2015, Australia.

ATSB (Australian Transport Safety Bureau) (2019) Investigation RO-2017-016 Derailment of freight train 7MC1 at Wallan, Victoria on 4 November 2017, Australia.

Arthur W, Day E, Bennett W and Portrey A (2013) Individual and team skill decay. The science and implications for practice, Routledge New York.

Dismukes, RK (2012) ‘Prospective memory in workplace and everyday situations’, Current Directions in Psychological Science, 21(4):215-220.

DOT (Department of Transportation) (2018) Draft Safety Advisory Related to Temporary Signal Suspensions, Federal Register Vol. 83, No. 78: Page 17701, U.S.A.

DOT (Department of Transportation) (2018a) Safety Advisory Related to Temporary Signal Suspensions, Federal Register Vol. 83, No. 224: Page 58685, U.S.A.

DOTARS (Department of Transport and Regional Services) 2002 Code of practice for the defined interstate rail network, Volume 3 (Operations and safeworking) Part 1 (Rules), Australia.

Eames A (2007) RSSB Research Programme - T190 Optimising Driving Cab Design for Driver Protection in a Collision (Debris Ingress), Issue 4, Rail Safety and Standards Board UK

Fox K (2009) How has the implementation of Safety Management Systems (SMS) in the transportation industry impacted on risk management and decision making? Lund University.

Gertner J and Acton S (2003) Railroad dispatcher communications training materials. Technical Report No. DOT/FRA/ORD-03/12. Washington, DC: Federal Railroad Administration.

Greene RL (1987) ‘Effects of maintenance rehearsal on human memory’, Psychological Bulletin, 102(3): 403–413.

ITSRR (Independent Transport Safety and Reliability Regulator) (2004) Train door emergency egress and access and evacuation procedures, NSW.

Klampfer B, Grey E, Lowe A, Hayward B and Branford K (2012) ‘Reaping the benefits – how railways can build on lessons learned from crew resource management’ in Wilson, JR, Mills A, Clarke T, Rajan, J and Dadashi, N (eds) Rail human factors around the world: impacts on and of people for successful rail operations, CRC Press, Leiden.

Loukopoulos LD, Dismukes RK and Barshi, I (2009) ‘The perils of multitasking’, AeroSafety World, 4(8):18-23.

Mandl H and Levin JR (1989) Knowledge acquisition from text and pictures, Elsevier New York.

National Vocational Education and Training Regulator Act 2011 (Cth)

NTSB (National Transportation Safety Board) (2019) Amtrak Passenger Train Head-on Collision With Stationary CSX Freight Train Cayce, South Carolina February 4, 2018. NTSB/RAR-19/02 PB2019-101308, U.S.A.

ONRSR (Office of the National Rail Safety Regulator) (2021) Assessment of rail safety worker competence fact sheet, Australia.

OTSI (Office of Transport Safety Investigation) (2005) Investigation report Road Motor Vehicle Struck by Countrylink Xplorer Service NP23a on Baranbah Street Level Crossing (530.780kms), NSW.

RAIB (Rail Accident Investigation Branch) (2008) Investigation report 22/2008 Train overspeeding through an emergency speed restriction at Ty Mawr Farm Crossing on 29 August 2007, U.K.

RAIB (Rail Accident Investigation Branch) (2016) Investigation Report 14/2016 Overspeed at Fletton Junction, Peterborough 11 September 2015, U.K.M

RISSB (Rail Industry Safety and Standards Board) (2014) ANRP- Centralised traffic control, version 1.2, Australia.

RISSB (Rail Industry Safety and Standards Board) (2014a) ANRP – Network Communication, version 1.3, Australia.

RISSB (Rail Industry Safety and Standards Board) (2017) Contracting in the Rail Industry, Accreditation and Safety Management Systems Guideline, Version 1.0, Australia.

RISSB (Rail Industry Safety and Standards Board) (2018) Guideline - Safety critical communications, Version 1.0, Australia.

RISSB (Rail Industry Safety and Standards Board) (2021) Development and Maintenance of Network Rules, Australia.

RISSB (Rail Industry Safety and Standards Board) (2021a) Interoperability Impact Plan version 1.0, Australia.

RISSB (Rail Industry Safety and Standards Board) (n.d.) Hazard register, RISSB website, accessed 8 March 2022.

RSSB (Rail Safety and Standards Board) (2005) Formal Inquiry: Collision with a Road Vehicle and Subsequent Derailment of Passenger Train 1C92 1735 hrs Paddington to Plymouth at Ufton Automatic Half Barrier Level Crossing on 6 November 2004, UK

RSSB (Rail Safety and Standards Board) (2007) Research Programme T190: Optimising driving cab design for driver protection in a collision (Debris Ingress),U.K.

RSSB (Rail Safety and Standards Board) (2017) Safety critical communications: the manual, U.K.

RSSB (Rail Safety and Standards Board) (2020) Railway Group Standard GMRT2100 Rail Vehicle Structures and Passive Safety, Issue 6, UK

Rasmussen J (1997) ‘Risk management in a dynamic society: a modelling problem’, Saf. Sci. 27 (2–3), 183–213.

Sato A, Onoma N and Masuda T (2020) ‘Prospective calling method to prevent excessive train speed’, Quarterly Report of RTRI, 61(4):290-296.

Snook SA (1996) Practical Drift: The Friendly Fire Shootdown over Northern Iraq, ProQuest Dissertations Publishing.

Standards Australia (2006) Railway Safety Management – Operational systems (AS 4292.5 - 2006),  http://standards.org.au

Standards Australia (2017) Management of Network Route Competence (AS 7454:2017), Rail Industry Safety and Standards Board

Standards Australia (2018) Risk management: Principles and guidelines (AS/NZS ISO 31000:2018), http://standards.org.au

Standards Australia (2018a) Interior Crashworthiness (AS 7521:2018), Rail Industry Safety and Standards Board

Standards Australia (2021) Access and Egress (AS 7522:2021), Rail Industry Safety and Standards Board

Standards Australia (2022) Australian railway rolling stock - Body structural requirements - Part 1 - Locomotive (AS 7520.1:2022), Rail Industry Safety and Standards Board

Transport for NSW (2017) Passenger Rolling Stock Access and Egress, Version 1.0 including TN 041:2017 (T HR RS 04001 ST) State of NSW

Wickens CD, Gutzwiller, RS and McCarley JS (2023) Applied attention theory, 2nd edn, CRC Press, Boca Raton.

Wickens CD, Helton WS, Hollands JG and Banbury, S (2022) Engineering psychology and human performance, 5th edn, Routledge, New York.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to organisations and individuals to confirm factual accuracy and/or where parties were potentially affected by findings within the report. Submissions from those parties were reviewed and, where considered appropriate, the text of the draft report amended accordingly.

Appendices

Appendix A – Rolling stock condition assessment

Derailment site observations

Observations were made at the derailment site prior to the rolling stock being moved. The preliminary observations did not identify evidence of rolling stock defects or equipment failures potentially causal to the derailment. All vehicles remained mechanically coupled, although some couplers had sustained damage in the derailment. All bogies remained attached to their car body.

Testing of braking and vigilance systems

Static brake testing on the leading power car (XP2018) was conducted at the Auburn UGL facility to determine whether the brakes were degraded prior to the derailment.[141] Testing also included assessment of the vigilance control system that initiates a brake application in the case of driver incapacitation. There was no evidence found that the brake system or vigilance control system on XP2018 was defective or may have contributed to the derailment. Also, the driver of ST23 did not report any issues with the braking system prior to the derailment.

Power car XP2018 twist test

A twist test on power car XP2018 was conducted at the Auburn facility to determine the vehicle’s capacity to negotiate track twist.[142] The twist test arrangements were in accordance with the twist (packing) described in RailCorp Standard ESR0001-200 (2013) that represented the standard current at the time of the derailment. The testing found a maximum wheel unloading of 57.3%, compared to the maximum permissible value of 60%. Given this result, it is unlikely that the twist performance of the leading power car contributed to the derailment.

Train radio performance

The radio system was function tested and radio logs reviewed to assess the condition of the radio system shortly prior to the derailment. During testing, the system was operational although with some degraded performance, probably due to derailment damage and removed antennas. Based on results of this function testing and the review of radio log files, the Sydney Trains specialist maintenance group responsible for the train communications concluded that there was no evidence to suggest that the onboard communications systems were non-operational or defective at the time of the occurrence.

A review of maintenance records also found that the train radio system was within the required maintenance inspection timeframes and compliant at the time of the derailment. The most recent inspection of communications equipment on XP2018 was on 6 February 2020, and for power car XP2000 the inspection was on 4 February 2020.

Bogie and wheel inspections

The strip-down inspection of the bogies of power car XP2018 did not identify defects likely to have contributed to the derailment. There was minor distortion of the bogie frames, possibly as a result of the derailment. Non-destructive testing identified cracking of one brake bracket casting in the trailing bogie, probably a result of the derailment. 

There were no pre-existing adverse conditions identified in the bogies of the passenger cars. Review of bogie and wheelset sheets did not identify any areas of concern with the condition of the bogies at the time of overhaul or wheelset change. Bogie weights at time of overhaul were within specification. Braking components including brake levers and cylinders were within specified dimensions and clamping forces at the time of servicing.

Wheel profile measurements taken following the derailment were compared to the WPR2000 profile specified for these vehicles. No sharp flanges were identified, and profiles were within tolerance and generally close to the WPR2000 profile. The most recent routine wheel measurement also indicated flange and rim thickness were within engineering standards.

Maintenance status of ST23 on 20 February 2020

Maintenance of the XPT fleet was managed using the Sydney Trains enterprise asset management (EAM) system. Work orders were generated within the EAM in accordance with the requirements of the technical maintenance plan (TMP). The TMP specified the frequency of tasks required for the power cars and trailer (passenger) cars. Maintenance inspections included major inspections and trip inspections (prior to service). In addition to the maintenance regime, heavy overhauls were conducted at specified frequencies.

Open and closed faults for the 120 days prior to the derailment were reviewed. There were no open faults identified that would suggest the train was operating at increased risk relevant to the derailment sequence. Review of closed faults did not show any recent faults that might have been addressed incorrectly and created increased risk.

At the time of the derailment of ST23, a number of work orders within the TMP were listed as ‘open’ although none of the open orders were found to be relevant to the risk of derailment. It was also found that ST23 entered service with work orders for the Trip Inspection of all cars identified as ‘open’. However, review of records identified that most tasks had been completed prior to the train entering service. Those tasks that were not completed were not considered potential contributors to the derailment.

Appendix B – ST23 driver roster and fatigue assessment

The driver’s actual and scheduled duty hours for the 2 weeks prior to the occurrence are shown in Table 6. The driver commenced a series of duty periods at about 0215 on 19 February, with the second commencing at about 1815 and ending at about 0100 on 20 February. After about 12 hours free of duty, the driver’s third duty period commenced at Junee at 1315 and the scheduled sign-off time in Melbourne was 1845.[143]

Table 6: Scheduled and actual duty times for the driver of ST23

DateWork activityRoster startRoster finishActual finishActual hours
7 FebruaryOff    
8 FebruaryJunee to Melbourne0215074508596:44
8 FebruaryMelbourne to Junee1815010001056:50
9 FebruaryOff    
10 FebruaryJunee to Melbourne0215074508326:17
10 FebruaryMelbourne to Junee1815010001006:45
11 FebruaryOff    
12 FebruaryJunee to Melbourne0215074508325:36
12 FebruaryMelbourne to Junee1815010001277:12
13 FebruaryOff    
14 Feb 2020Off    
15 Feb 2020Junee to Sydney1341211622318:50
16 Feb 2020Melbourne to Junee07251340Note 1Note 1
17 Feb 2020Off    
18 Feb 2020Off    
19 Feb 2020Junee to Melbourne02150745Note 1Note 1
19 Feb 2020Melbourne to Junee18150100Note 1Note 1
20 Feb 2020Junee to Melbourne13151845Note 26:28

Note 1. The driver had not submitted actual worked hours for the period 16 to 20 February as of the day of the occurrence.

Note 2. The derailment occurred at about 1943.

It was reported that the driver normally slept 8 hours a night, though less at times when doing shift work. Information from the driver’s mobile phone included phone calls, messages sent and physical activity (steps taken in each 1-hour period). There was no such phone-related activity for a 5-hour period at night prior to the first shift on 19 February (as well as an earlier period of more than 60 minutes in the afternoon), a 6.5-hour period prior to the second shift on 19 February, and an 8-hour period prior to the shift commencing on 20 February. For the 2 nights prior to these shifts, there were periods of more than 10 hours without such phone activity.

Overall, it was not possible to determine the quantity or quality of sleep obtained by the driver in the days leading up to the occurrence. However, based on the available information (including the length of the duty period and the time of day), there was insufficient evidence to conclude that the driver was experiencing a level of fatigue known to adversely influence performance at the time of the occurrence.

 Appendix C – Train Notice 266 initial issue

Appendix C – Train Notice 266 initial issue
Appendix C – Train Notice 266 initial issue
Appendix C – Train Notice 266 initial issue
Appendix C – Train Notice 266 initial issue
Appendix C – Train Notice 266 initial issue
Appendix C – Train Notice 266 initial issue

Appendix D – Train Notice 266 as amended 13 February

Appendix D – Train Notice 266 as amended 13 February
Appendix D – Train Notice 266 as amended 13 February
Appendix D – Train Notice 266 as amended 13 February
Appendix D – Train Notice 266 as amended 13 February
Appendix D – Train Notice 266 as amended 13 February
Appendix D – Train Notice 266 as amended 13 February

Appendix E – The train authority form used under TN 266

Appendix E – The train authority form used under TN 266

Appendix F – Train Notice 367

Appendix F – Train Notice 367

 

Appendix F – Train Notice 367

Appendix G – The train authority form used after TN 367

Appendix G – The train authority form used after TN 367

Appendix H – Other rules and codes

Scope

The operating rules for Australian Rail Track Cooperation’s (ARTC’s) Victorian network were described in the ARTC Code of Practice for the Victorian Main Line Operations (TA20). This appendix provides a brief summary of other codes and rules that were reviewed for any possible relevance to the protocols that were established between Donnybrook and Kilmore East in February 2020.

Code of Practice for the Defined Interstate Rail Network

Volume 3 of the Code of Practice for the Defined Interstate Rail Network described safeworking rules and route standards for the Defined Interstate Rail Network in Western Australia, South Australia, parts of New South Wales and a small section of the Victorian network west of Dimboola (DOTARS 2002).[144] The document had the intention to ‘provide a more unified, harmonised and efficient operation’ and was aligned with 'occupancy control systems and occupancy authorities' defined in AS 4292.5 (Standards Australia 2006).

This code described the potential use of train authorities to pass fixed signals at stop through a section during Centralised Traffic Control (CTC) system failure, where the cause was not unsafe track. Section 3.9 of the code also specified a range of procedural requirements for preparing and issuing train authorities, including step by step instructions for the processes of communication between the train controller and the ‘recipient’ of the train authority. There were broad similarities between the train authority format requirements of this code and the train authorities used between Donnybrook and Kilmore East in February 2020, but also some variation in detail and the application of narration and readback requirements. The system used in February 2020 could therefore not be described as being consistent with all the detail of this code.

Australian Network Rules and Procedures for CTC

The Australian Network Rules and Procedures, and the subsequent National Rules Framework, (RISSB) described how access providers and access users could operate safely on the Australian network.[145] Rules for the CTC system were described in ANRP5001 (RISSB 2014) and stated that if the function to control points and signals failed, the network control officer (NCO) could institute a method of special working.

Special working was included in the RISSB glossary and defined as ‘working rail traffic using an Alternate Proceed Authority (APA) or manual block working’. The RISSB glossary stated an APA may be used to authorise rail traffic movements when the proceed authority normally provided by the safeworking system was not available. In the instance at Wallan, the issuing of caution orders and other safeworking requirements specified in TA20 for the CTC system was available and had been applied in the initial days of the signalling failure.

Australian Network Rules and Procedures for Network Communication

Industry guidance on communications (RISSB 2014a) allowed for the relaying of communications when it was not possible to communicate directly with the intended receiver. However, direct communication between train control and train drivers was always available between 6 and 20 February 2020, as evidenced by train drivers confirming receipt of train authorities and CAN forms to train control.

Appendix I – ARTC types of risk assessment

Appendix I – ARTC types of risk assessment

Appendix J – Risk management of level crossing protection

The ARTC risk management plan for the train authority working between Donnybrook and Kilmore East in February 2020 described the controls being used to manage the risks associated with the absence of automated activation of the level crossing protection at Wallan–Whittlesea Road. The risk management plan described the hazard, cause and outcome associated with the deactivated level crossing (Table 7).

Table 7: Risk management plan description of risk item 6

HazardTrain operates through non operating level crossing at Wallan
Caused byLevel crossing taken out of service and no protection in place
Worst outcomeCollision with road vehicle or pedestrian leading to injury or fatality.

For the identified risk, the risk management plan identified 2 controls that were to be implemented by the on-duty level crossing keeper (LCK) and the accompanying qualified worker (AQW). Those controls and how they were implemented are described in Table 8.

Table 8: Specified risk controls for risk item 6 and ATSB comment on implementation

Specified risk controlATSB comment on the implementation of the control
Level crossing (keeper) (LCK) in place to operate test switchAn LCK was located at the Wallan–Whittlesea Road level crossing and would communicate with the AQW of the approaching train. When notified, the LCK would activate the crossing protection and confirm its activation with the AQW. There were no instances identified where this process had failed.
Pilot on train announces approachAn AQW (not a ‘pilot’) on board the approaching train would contact the LCK by mobile phone at sufficient distance to warn of the train’s approach, confirm successful activation of the crossing protection by the LCK, and advise the driver of its activation. There were no instances identified where this process had failed.

Appendix K – Train recorder (Hasler) analysis

The Hasler RT recorder

Power cars XP2018 and XP2000 were each fitted with a Hasler RT data recorder and the tapes from the 2 power cars were recovered for analysis (Figure 23). Limited parameters are recorded and included time, speed, throttle and vigilance control (on the same trace), and brake cylinder pressure.

Figure 23: Hasler waxed paper rolls removed from power cars XP2018 and XP2000

Figure 23: Hasler waxed paper rolls removed from power cars XP2018 and XP2000

The photograph shows the recovered waxed tapes. The centre roll is the tape from power car XP2000. The left and right rolls are the tape from power car XP2018 that jammed during its removal and was torn at one location.
Source: CITS

Data processing

To process the data, both tapes were scanned and examined using photographic software. The traces for each recorded parameter were assessed for alignment with key events, such as start/stop points. Some horizontal re-alignment of parameters was required and both the horizontal and vertical scales of the images were calibrated for measurement.

Wheel diameter corrections

The Hasler used a pre-set (average) wheel diameter to calculate both speed and distance from the measured revolutions of the left wheel on the second axle of the power car (wheel 3).[146] Actual speed may deviate from that recorded (and displayed) due to differences between this pre-set diameter and the diameter of the actual wheel providing the feed to the Hasler system. The actual measured wheel diameter for both power cars was larger than the pre-set value.

The recorded values for speed and distance were corrected for the ratio of actual-to-pre-set wheel diameter (Table 9). The larger actual wheel diameter on the XP2018 (compared to the pre-set) meant that the recorded speed was about 2% lower than the actual train speed.

Table 9: Measurements used for speed and distance correction factor

 XP2018 – leadingXP2000 – trailing
Pre-set diameter (mm)1,0001,000
Measured diameter (mm)1,019.21,011
Ratio (correction factor)1.01921.011
Uncertainties in recorded data

An initial review identified a likely recording anomaly in the latter part of the XP2018 data. All channels recorded noise in the latter phase, likely associated with the derailment. An overlay of the data from the 2 power cars showed the discrepancy (visible as diverging speed toward the end of the data) and also confirmed that the speed data prior to this occurring was consistent (Figure 24).

Figure 24: Overlay of data recordings from XP2018 and XP2000

Figure 24: Overlay of data recordings from XP2018 and XP2000

The image shows an overlay of speed records from power cars 2018 and 2000. It indicates consistent speed records after departing Kilmore East, then a consistent initial sharp deceleration of both cars followed by diverging speed records during the derailment.

Source: ST23 Hasler recordings annotated by the ATSB

There were also potential inaccuracies in the XP2000 data in the latter stages due to uncertainty in the measured wheel rotation being an accurate measure of train speed during this phase.

Other sources of train speed

GPS data from the installed ICE radio system[147] was interrogated and used as a comparator for time, speed and position information. Although only coarse GPS data was available due to the system’s polling frequency, it provided a source for comparison with the Hasler data and an enhanced confidence in the assessed train speed. The GPS data was also the primary source for locating the position of ST23 when stopped prior to signal KME16.

Throttle and braking events

One limitation of the fitted Hasler data recorder was that it did not record the positions of the driver’s throttle and brake handles. Instead, it recorded a generic power ON-OFF parameter and brake cylinder pressure.

Between Kilmore East and Wallan, the Hasler recorded that power was applied on departing Kilmore East at approximately 19:34:57. Application of power was maintained until around 19:41:34 and remained off until 19:42:20. During this 46 seconds, 2 periods of brake application were recorded that controlled the speed of the train to between 115 km/h and 120 km/h. The reductions in speed were consistent with permanent speed restrictions of 115 km/h between 55.43 km and 53.52 km at Wondong, and between 52.00 km and 51.21 km at Heathcote Junction. At 19:42:20, application of power was recorded. This was maintained until a power off and brake application was recorded at approximately 19:43:22. No records of vigilance control acknowledgements were recorded for the journey of train ST23 between Kilmore East and Wallan loop as brake and throttle controller movements would have acted as vigilance control system task linked activities.

The data from both power cars indicated that, at a point just prior to the commencement of deceleration, the power moved from ON to OFF and there was a rapid increase in brake cylinder pressure. For each recording, the points at which brake cylinder pressure began to rise and then reached a steady state were determined. The steady state pressures were noted for each record and compared with expected values. For both power cars, the recorded pressure was above that expected for a Notch 7 (full-service) application (345 kPa). The pressure recorded on XP2018, the leading power car, was about 378 kPa, which was in line with the pressure expected for an emergency application (375 kPa). Although the pressure recorded on XP2000 was lower, about 358 kPa, it was still substantially above the full-service value. These results indicated that it was very likely that the brake application was an emergency application. The speed of the train at the commencement of braking was about 129 km/h.[148]

Location of rise in brake cylinder pressure

Due to known limitations and potential anomalies in the Hasler data recording, obtaining position information from the data with respect to fixed points on track was difficult to achieve with high levels of accuracy. Therefore, the position at which brake cylinder pressure began to rise and the speed at which the train entered the turnout could not be directly read from the Hasler data.

Instead, the Hasler speed and distance data was used to calculate estimates of position considering different known stop locations. This was cross-checked using data from other sources to provide greater confidence. The different methods yielded slightly different results, however all indicated that the brake cylinder pressure started to rise before entry to the Wallan Loop (Table 10).

Table 10: Estimated limit points of rise in brake pressure and speed at entry to turnout

ParameterEstimated closest brakingEstimated furthest braking[149]
Distance from brake cylinder pressure rise to No.7 points50 m153 m
Speed at No. 7 points127 km/h114 km/h

The brake cylinder pressure increase was a result of an emergency brake application, presumed to be by the driver in response to a cue or cues. To provide an estimate of when the cue(s) for braking may have presented, a nominal 2 second period from the cue(s) to brake cylinder pressure rise has been used.[150] Based on this figure, the cue(s) may have presented when ST23 was between about 120 and 220 m from the turnout.

Train handling of ST23 during journey

The Hasler recordings and the GPS data were examined to evaluate any potential trend in speed exceedance by ST23 during the Victorian segment of the journey. The ARTC Route Access Standard specified a maximum speed for express passenger trains in Victoria (including the XPT) of 130 km/h in areas where no local speed restrictions applied.[151] The assessment focussed on any identifiable trends and did not include local speed restrictions remote from the event.

Review of the GPS data identified 11 speed peaks of between 133 and 137 km/h in the Victorian section. These exceedances within the GPS data were cross-checked with the Hasler recordings and similar peaks identified, including a maximum actual value of about 139 km/h.[152]

None of the overspeeds identified were for a significant duration. These observations suggest that the driver was targeting line speed and occasionally overshooting. There was no evidence identified to suggest unusual train handling.

Vigilance parameter

The locomotive was fitted with a vigilance system. The installed Hasler data recorder did not record all information on driver activity associated with the vigilance system and its information was therefore of limited value.[153] However, the Hasler did record a vigilance parameter. The last point at which the vigilance parameter was recorded as active was prior to the stop at signal KME28. There were no vigilance parameter events recorded between ST23 departure from signal KME16 and the derailment.

Appendix L - Driver’s cab side door separation

Sequence of door attachment failure

There were 3 potential failure scenarios of the left-side driver’s cab door considered plausible:

  1. External loading on the door led to the knuckles of the upper hinge unfurling. This was then followed by the failure of the lower-hinge fastening and disengagement of the door latch.
  2. External loading on the door led to failure of the lower hinge fastening. This was then followed by failure of the upper hinge and disengagement of the door latch.
  3. External loading on the door and flexing of the car body led to disengagement of the door latch, followed by the failures at both hinges.

Although the sequence of failure cannot be confirmed with certainty, it was concluded through inspection of the components and the comparative loading on the upper and lower hinges that the more likely component to fail first was the upper hinge.

Evaluation of upper hinge

To evaluate the upper-hinge behaviour under defined loads, simplified loading was assumed. The external force was assumed to be an even pressure acting over the entire door, as used in design standards. This was converted to a point load (F) applied at the centroid of the door’s external surface, and resolved into balanced forces acting on the attachments in the frame from the external door surface (Figure 25).

Figure 25: Inside view of cab door opening and fitting locations (dimensions in mm)

Figure 25: Inside view of cab door opening and fitting locations (dimensions in mm)

Source: ATSB

The glass fibre composite cab door was a plug shape that rotated inward on the hinges mounted on the inner rear edge of the door frame. The door hinges were fabricated from 3 mm thick stainless steel, and attached to the door frame by bolts into tapping plates (Figure 26).

Figure 26: Door and doorframe section drawing

Figure 26: Door and doorframe section drawing

Source: Commonwealth Engineering (NSW) Drawing 022010940-1 annotated by CITS.

Unfurling of upper hinge knuckles

The upper hinge failed through the unfurling of its knuckles from the hinge pin. The lower (still closed) knuckle disengaged from the rotating pin and the 3 upper knuckles unfurled (Figure 27).

Figure 27: Failed hinge knuckles (upper hinge)

Figure 27: Failed hinge knuckles (upper hinge)

Source: ATSB

The mechanism of the failure of the upper hinge provided a specific failure mode for assessment. Loading of the 3 knuckles that unfurled was assumed for the estimation of material stresses in specified loading scenarios and compared against material yield strength. Dimensional assumptions were also made for the unfurling sequence (Figure 28).

Figure 28: Assumed hinge unfurling sequence

Figure 28: Assumed hinge unfurling sequence

Source: ATSB

Outcomes of simplified load analysis

The potential for hinge failure by unfurling of knuckles was assessed against 2 load scenarios; an externally applied quasi static pressure of 2.5 kPa (GM/RT 2100 aerodynamic loading criteria) and a static pressure based on the power car lying on its side (AS7520.1-2022).

Aerodynamic load case of 2.5 kPa

Considering a 2.5 kPa static external pressure, the simplified analysis indicated that the door attachments would withstand the pressure and the knuckles of the upper hinge would not unfurl.

Load case for power car resting on side

An evenly distributed pressure from the self-weight of the power car when on its side, resulted in a static pressure on the cab door of about 11 kPa. Under this load, the simplified load analysis suggested that the upper-hinge knuckles would probably unfurl, or as a minimum commence plastic deformation.

Load case experienced by ST23

Under the dynamic loading conditions experienced by ST23 during the action of overturning and subsequent sliding, the cab door would be expected to have experienced loading significantly greater that the 11 kPa static (resting on side) load case. Based on the probable failure of the upper hinge (by unfurling) in the static (11 kPa) load case, the knuckles of the upper hinge would be expected to unfurl in the dynamic loading experienced by ST23. This analysis therefore confirmed the plausibility of the failure of the upper hinge by unfurling as the possible first point of failure.

Appendix M – Passenger car crashworthiness information

Introduction

This appendix provides a brief description of the observed damage to internal spaces of the passenger cars that formed part of ST23 (Figure 29).

Figure 29: Passenger cars

Figure 29: Passenger cars

Source: Vehicle images supplied by Sydney Trains, annotated by CITS

Passenger car XAM2179 (Car A)

Car A had a sleeper/cabin configuration and was the leading passenger car. The car had 9 cabins that could each seat 3 passengers. Some cabins were fitted with forward-facing seats and others with rear-facing seats.

The car came to rest at an angle of about 30° to its left. External damage included 4 broken exterior windows on the left (passenger aisle) side of the carriage and exterior damage to the roof line above the windows as a result of the car striking pine trees adjacent to the track. Damage within the sleeper car included collapsed interior lining in the passenger aisle. Two cabins had cracked glass partitions, most likely from being struck by luggage or passengers.

Passenger car XL2229 (Car B)

Car B was a first-class car with 56 forward-facing passenger seats in a single open cabin.

The car came to rest at an angle of approximately 17° to its right. There was no evidence of structural failure or dislodged internal fittings acting as projectiles. The only significant damage to the cabin was exterior binding at the front right corner with the car ahead (Car A). This prevented the use of the exits at this location.

Passenger car XBR2155 (Car C)

Car C was half first-class forward-facing seating with the other half being the buffet section. It was near upright when it came to a stop. The car suffered no interior damage of consequence.

Passenger car XF2201 (Car D)

Car D was an economy-class car with 68 forward-facing passenger seats in a single open cabin. It was near upright when it came to a stop. The car suffered no interior damage of consequence.

Passenger car XFH2108 (Car G)

Car G was half economy class forward-facing seating with the other half being the baggage section. It was at an angle of about 10° when it came to a stop. The car suffered no interior damage of consequence.

Appendix N – Passenger safety information

Extract of operator’s procedures on content of verbal briefing

NSW Trains’ procedures specified the following safety content for the verbal briefing:

If you require assistance in an emergency, push the red emergency call button at either end of your carriage.

In the unlikely event of an emergency, please remain seated, stay calm and wait for instructions from the onboard staff.

Staff are trained in emergency procedures and know how to proceed. We will help you exit the train swiftly and safely if an evacuation is necessary.

If instructed to evacuate, leave your luggage behind.

In an emergency, it is often safer to remain on-board rather than to evacuate.

For further information, please refer to the safety card in the seat pocket or table in front of you

Extract of safety information in onboard guide

The section in the onboard guide on emergency procedures stated:

If you’re unable to locate a nearby emergency exit, ask a crew member to show you. All crew members are trained in emergency procedures and can help you exit the carriage or evacuate the train quickly and safely.

What to do in an emergency

1. Push the red emergency call button at either end of your carriage.
2. Alert a crew member immediately.
3. Stay calm and remain seated until you’re instructed by crew members or by rescue, fire or police personnel.
4. When asked to move, leave luggage behind, use handrails and watch out for trip hazards.
5. If told to evacuate the train, please be aware of your surroundings and watch out for hazards. Do not exit the train in a tunnel or on a bridge unless you are told to do so. Follow safety instructions from trained personnel at all times.
6. After leaving the train, move away from the tracks and follow directions to an assembly area organised by crew. Stay together and remain there until further instruction.
 

Appendix O – Countrylink incident response summary

Appendix O – Countrylink incident response summary

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2023

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     A serious injury is defined in the Transport Safety Investigation Regulations 2021 as an injury that requires, or would usually require, admission to hospital within 7 days after the day when the injury is suffered.

[2]     Train authority: an instruction in the prescribed format issued by a network control officer in connection with the movement of a train.

[3]     Train notice: operational information issued by or on behalf of the rail infrastructure manager.

[4]     The points at either end of Wallan Loop were placed in the hand operating mode and clipped in the normal position; With the points at either end of Wallan Loop set to their normal positions, trains would continue on the straight track (No.1 track) rather than being diverted into the loop (No.2 track).

[5]     Residues such as iron oxides can hamper electrical connection between wheel and rail and therefore impact the performance of a signalling system.

[6]     Rail traffic was stopped to permit workers to change the points.

[7]     The normal position of the turnouts was for routing on the straight, and the reverse position was for the loop.

[8]     For these works, the applied track force protection provided for flagmen to warn approaching trains, and for trains to comply with the signals shown by the flagmen.

[9]     ARTC document ANGE 220 Unreliable Track-Circuit Operation dated 11 October 2015 (applicable to NSW).

[10]    Stopping times at stations are those recorded by NSW Trains.

[11]    The ARTC Network Control office for this section of track was located in Junee, NSW.

[12]    An alarm had been received by ARTC Network Control for a possible signal passed at danger (SPAD) at Tallarook, 23 km north-east of Kilmore East. The NCO indicated that there had been power outages at this location, that may have showed up as a SPAD. The driver indicated that all signals had been ‘clear’ through Tallarook.

[13]    The decision around the order of trains through the location was made following discussions between the NCO and their supervisor. NSW Trains operations were informed of the holding of ST23 at Kilmore East and the delay to that service.

[14]    This signal protected the broad-gauge crossover going into the Apex ballast quarry. It was called an ‘Intermediate Home’ because it was in an intermediate location along the passing lane.

[15]    The passing lane (an extended crossing loop) was about 7 km in length.

[16]    Accompanying qualified worker: the term used in train notices for the worker that would accompany the driver between Kilmore East and Donnybrook.

[17]    The AQW’s copy of TN 367 was found within the driver’s cabin.

[18]    A CAN was a warning of an unsafe condition affecting, or potentially affecting, the network.

[19]    Home departure signal KME16 was protecting the turnout at the end of the passing lane.

[20]    In Australia, locomotive and train operating cabs were generally not fitted with voice recording devices.

[21]    The latest version of TN 266 was explicit in not requiring the driver to repeat the contents of the train authority back to the NCO. Also under the train working arrangements described in TN 266, there was no requirement for the NCO to read the content of TA 17 to the driver.

[22]    Within this section, there were 115 km/h speed restrictions applied to some sections of track.

[23]    Speed maintained until approximately the 51 km mark. There was a 115 km/h permanent speed restriction at Heathcote Junction between the 52.00 and 51.21 rail-km locations.

[24]    Active protection on the other level crossings on the Kilmore East-to-Donnybrook section were working normally and it was only the Wallan–Whittlesea Road level crossing that required local operation.

[25]    The person who activated the level crossing protection locally at the crossing, colloquially referred to as the bellhop.

[26]    Range estimated from train recorded data (Appendix K).

[27]    Passenger numbers based on available data from the operator.

[28]    For open radio broadcast on this ARTC corridor, crew were to switch their radios to channel 6. Of the two crew members making emergency calls, one immediately changed to channel 6 and the other a short time later, probably following prompting. The remainder of the crew were then required to also switch to channel 6 to maintain ongoing communications among the crew members.

[29]    V/Line’s network train control centre located in Melbourne.

[30]    The emergency services call centre time stamp.

[31]    Using tools sourced from the train’s emergency breakdown kit.

[32]    A serious injury is defined in the Transport Safety Investigation Regulations 2021 as an injury that requires, or would usually require, admission to hospital within 7 days after the day when the injury is suffered. A minor injury is any other reported physical injury that does not meet the serious injury threshold.

[33]    NSW Trains was an agency of the NSW State Government and was within a division of Transport for NSW (TfNSW).

[34]    Schedule—Rail Safety National Law, Part 1—Preliminary, Section 4 - Interpretation (RSNL version: 3.10.2019 to 30.6.2020)

[35]    Schedule—Rail Safety National Law, Part 3—Regulation of rail safety, Division 3—Rail safety duties Interpretation (RSNL version: 3.10.2019 to 30.6.2020)

[36]    Sydney Trains was part of Transport for NSW.

[37]    Due to the delay in the service on this day, arrival in Melbourne would have been later than the rostered end of shift.

[38]    Health and fitness requirements for Rail Transport Operators and Rail Safety Workers were governed by the Rail Safety National Law (RSNL) and associated Regulations.

[39]    NSW Trains procedures NTTWP100 Responsibilities of Train Crews and NTOSP11 Train evacuation and detraining when not at a station refer to the duties of the driver and the PSS/Guard.

[40]    The training was limited to ‘within work on track work authority limits’ and not the arrangements in place for the train working arrangements between Donnybrook and Kilmore East.

[41]    Detailed work-placement records were available from 2014.

[42]    The ActivateRail representative (contracted by ARTC) was performing the role of signaller at 1530, and had been involved in developing and implementing the safeworking solution for train working between and Donnybrook and Kilmore East.

[43]    ARTC Corporate Plan 2021-22

[44]    VicTrack was a State-owned organisation that owns Victorian rail land, assets and infrastructure.

[45]    Rail Safety National Law, Part 1—Preliminary, Section 4— Interpretation (RSNL version: 3.10.2019 to 30.6.2020)

[46]    Rail Safety National Law, Part 3—Regulation of rail safety, Division 3—Rail safety duties (RSNL version: 3.10.2019 to 30.6.2020)

[47]    Standard gauge trains did not stop at Wallan.

[48]    TA20 ARTC Code of Practice for the Victorian Main Line Operations, Section 2, Rule 13 g.

[49]    Signal ES1712 was located at 51.77 km rail-km from Melbourne

[50]    The indication of this signal at the time ST23 passed is not known with certainty because its state was not recorded. However, broad gauge rail traffic records indicated that the signal was more likely to be at proceed. If not at proceed, the signal would have been at its alternate ‘caution’ indication, a single yellow light.

[51]    13.7 km from Wallan Railway Station

[52]    Azimuth is the clockwise horizontal angle (in degrees, minutes and seconds) from true north to the sun.

[53]    Altitude is the vertical angle (in degrees, minutes and seconds) from an ideal horizon to the sun.

[54]    Computed using National Mapping Division's sunmoonposn program, version 1.1.

[55]    A 45 minute delay would be the result of a 24 km/h average speed compared to a 96 km/h average speed over the 24 km section; The issuing of caution orders and applying other safeworking rules in accordance with TA20 also increased the workload on network control resources.

[56]    ActivateRail offered professional advisory services, project managers as well as worksite supervisors, site managers and track safety personnel.

[57]    Project representatives suggested signals remained lit to assist electrical testing, and as location markers for drivers.

[58]    A CAN notice was issued because the Wallan–Whittlesea Road level crossing protection was affected by the signalling system failure and was being manually operated.

[59]    TA20 Section 5 Rule 5 Clause b stated ‘Light signals not in use are distinguished by a black cross on the front of the lights. The lamps are not to be lit’.

[60]    Some V/Line drivers and the RTBU (Rail Tram and Bus Union) had expressed concern at signals remaining lit within the affected section. On 10 February, a driver refused to pass a lit signal within the section without authority to proceed.

[61]    Rule 1, Section 3, pertained to the process when stopping at and then passing automatic signals that were displaying a stop indication. When applied, the rule required the train to proceed with caution and at a speed not exceeding 25 km/h.

[62]    In doing so, the train authority was issued by the NCO to the signaller rather than a driver.

[63]    Issued because the Wallan–Whittlesea Road level crossing protection was being manually operated. TA20 section 1, clause 7, described the issuing of a CAN warning in a range of scenarios that included faulty or deactivated level crossing warning equipment.

[64]    Figures for train authorities issued includes all notices issued until the derailment of ST23, including those issued after the issue of Train Notice 367.

[65]    The NCO involved was not the NCO on duty at the time ST23 transited the affected area.

[66]    The same ‘anomaly’ existed in the descriptions for southbound travel

[67]    Track Force Protection Coordinator

[68]    There was no available evidence with respect to the communications between the driver of ST23 and the AQW.

[69]    Temporary speed restriction: a speed, less than the maximum allowable permanent signposted speed, applied for track, signal, train equipment, or environmental conditions.

[70]    Preparation and Distribution of Operational Notices OPE-PR-001, Version Number 1.2, 31 May 2019

[71]    In ARTC procedure OPE-PR-001, the acronym NRAMS was used.

[72]    Australian Central Standard Time

[73]    The ARTC procedure specified that proposed standing train notices should be lodged (with ARTC operational staff) at least 10 days prior to their application, although it did not specify a publication timeframe requirement.

[74]    The update of WebRAMS was reported to have been actioned in Adelaide at 1815 central daylight time, which was 1845 eastern daylight time.

[75]    The WON was published by the Office of Rail Safety Manager (a part of MTM) on behalf of MTM and V/Line.

[76]    SAFE Notices are used by ARTC on its NSW and Queensland corridors to give notice of changes or exceptions to ARTC Network information publications.

[77]    Although consistent with the process used by signallers and AQWs in the previous weeks, TN 266 described that ‘the signaller will deliver the Train Authority and CAN to the driver of the rail movement as required’.

[78]    At the time of the derailment, Issue 2.1, 01 July 2018

[79]    Safeworking is an integrated system of operating rules and procedures that defines the interaction between workers and engineered systems. Of primary concern of a rail safeworking system is safe operations including train separation and speed management.

[80]    Rule 1, Section 3 specified proceeding at a speed not exceeding 25 km/h.

[81]    The phrase ‘Train Authority Working’ was used in section 25 of TA20. ARTC advised that this type of working had previously been used in Victoria during commissioning activities following signalling system upgrade.

[82]    The scope of application of train authorities was similarly defined for the Train Order System.

[83]    TA20 section 25 rule 2.f.

[84]    TA20 section 1 rule 8.b.

[85]    There were a number of other scenarios for which a CAN would be issued including a temporary speed restriction.

[86]    The application was, however, inconsistent with the rule that specified that the ‘Network Controller must dictate the CAN warning details direct to the rail traffic crew'. There was provision for relaying the message when direct communication between an NCO and a driver was not possible. However, radio communication was possible.

[87]    Advanced train management system that monitors and manages rail traffic

[88]    ARTC and Rail Corporation New South Wales (RailCorp) entered into an interface agreement in 2011 for RailCorp operations on the ARTC network. The functions of Railcorp were transferred to NSW Trains and other entities on 1 July 2013 and at the time of the derailment of ST23 at Wallan in February 2020, the 2011 interface agreement was the applicable interface agreement between ARTC and NSW Trains.

[89]    ARTC (2019) RSK-PR-001 Risk Management, version 1.4

[90]    The objective of AS ISO 31000:2018 is described within the standard as being to provide guidelines on managing risk faced by organisations. The application of these guidelines can be customised to any organisation and its context, is not industry or sector specific, and the standard also provides a common approach to managing any type of risk.

[91]    ARTC (2019) Application of Risk Management, RSK-WI-001

[92]    Approximate time of risk assessment advised by ARTC.

[93]    The plan did not identify individual risk owners as required by the ARTC risk management procedure.

[94]    The risk assessment reference to ‘piloted’ is different to TN 266 that refers to an accompanying qualified worker (AQW).

[95]    ARTC Glossary Issue 4.0, 15 January 2023, (accessed at www.artc.com.au/uploads/Glossary-I-4-Rev-0.pdf)

[96]    ANRP 710 Piloting Trains and Track Vehicles, Network Procedures (11 October 2015). This document was only applicable to the NSW portion of the ARTC network.

[97]    A competent worker was defined as a worker certified as competent to carry out the relevant task (RISSB).

[98]    Route knowledge: Essential knowledge required to enable rail traffic crew to work safely over a route (Standards Australia 2017).

[99]    The speed display on XP2018 would have been reading about 127 km/h.

[100]   No. 7 points were controlled by a dual-control point machine. They could be operated in motor (remote operation) or hand (manual operation) mode.

[101]  Crossing block: a casting or fabricated steel component that enables a wheel travelling along one rail to pass through the rail of a track which crosses its path.

[102]   Following the derailment, the windscreen was removed by rescuers to improve access to the driver’s cab.

[103]   Given the age of the power car and its apparent compliance with door loading specified in contemporary standards, there was no attempt to assess the door against loading requirements in historical standards.

[104]   AS 7522:2021 Access and Egress, Rail Industry Safety and Standards Board, sections 6.1.6 and 6.3.3.9

[105]   There were also reports of instances of post-traumatic stress disorder (PTSD) that are not included in this injury total.

[106]   A serious injury was defined in the Transport Safety Investigation Regulations 2021 as an injury that required, or would usually require, admission to hospital within 7 days after the day when the injury was suffered. A minor injury was any other reported physical injury that did not meet the serious injury threshold.

[107]   Exits were considered not usable (by height) if the bottom rung of the ladder was more than 1.5 m from the ground.

[108]  NSW Trains Competence Assurance; NSW Trains Risk Based Training Needs Analysis, NSW Trains, 2019.

[109]   The rail safety regulatory functions of this body were transferred to the national regulator, ONRSR.

[110]   Activities were reviewed for the period January 2015 to 20 February 2020.

[111]   Under the ONRSR reporting scheme, overspeed incidents were captured in the broader category of safeworking rule or procedural breach. ONRSR provided details of 262 incidents in this category, and 11 were identified as overspeed.

[112]   Audit activity 3827 (November 2018) referred to the risk of passenger train derailment as a result of overspeed.

[113]   Between 2000 and 2006, the Regional Fast Rail (RFR) project in Victoria upgraded track and signalling infrastructure on major regional lines to allow passenger trains to run at speeds of up to 160 km/h. RFR contractors Thiess-Alstom Joint Venture (TAJV) and Regional Rail Link (RRL) offered the TPWS to provide additional protection from the risk of trains passing signals (at stop) without authority and potentially colliding with other trains or derailing. The rail safety regulator at the time of the project was satisfied that TPWS was a suitable system for use in Victoria based on independent advice that TPWS was compatible with Victorian signalling principles and could be implemented with minimal changes to Victorian rail industry signalling standards, operating rules or maintenance practices, and it was a proven system having been in operation in the UK since 2000.

[114]   The speed display on XP2018 would have been reading about 127 km/h.

[115]   This is a nominal figure incorporating driver reaction to cues and system response. Human reaction times may vary considerably due to individual differences and other factors such as expectation and workload.

[116]   The distance range is an estimate only, and the cues to make a brake application may have presented earlier.

[117]   The ability to observe the points setting would have depended on several factors including the train’s distance from the points, lighting conditions at the time, the environment of the driver’s cab, and the eyesight of the individuals.

[118]   See also (RAIB 2008) and (RAIB 2016).

[119]   With signals initially lit and then several trips with all signals within the section extinguished.

[120]   A conspicuous warning device is a permanent or temporary indication which provides information to, or requires action to be taken by, train crews.

[121]   Rail Safety National Law (SA) Act 2012, Part 3, Division 6.

[122]   ARTC enterprise risk management system

[123]   TA20 section 1, clause 8 b.

[124]   The issuing by NCO of a train authority to the (in-field) signaller and their readback typically took about 2 minutes.

[125]   TA20 section 1, clause 8 b.

[126]   TLIC0030 (Pilot rail traffic with due consideration of route conditions) released in 2022 (after this occurrence).

[127]   For these circumstances, TA20 also specified the use of CTC arrival messages within the section.

[128]   As described in the ARTC Risk Management Overview - Workshop participants guide (2018). This stated that ‘two key factors to consider when determining the effectiveness of a control are: whether the control is adequate, and how susceptible the control is to human error or non-compliance’.

[129]   ARTC risk library ID: 0559

[130]   Such systems can be found on the Country Regional Network (CRN) in NSW that is managed by UGL.

[131]   Track Force Protection involves the use of hand signals and audible track warnings to control the movement of rail traffic through a worksite.

[132]   The same system was used for distributing notices in South Australia and Western Australia

[133]   The ARTC ERMS risk control of advanced train management system (ATMS) was not operating in Victoria, and the risk control of two-person train operation was not applicable to V/Line or NSW Trains passenger train operations which operated with single-person crewing.

[134]   Train enforcement pertains to the forced (automated) initiation of train braking in the case of train overspeed.

[135]   TPWS was used elsewhere in Victoria (on regional and metropolitan networks) to enforce braking of V/Line trains passing a signal at stop or detected as travelling too fast to comply with the next signal.

[136]   TPWS was scheduled for installation at Wallan Loop in 2024.  

[137]   TfNSW advised that the new NSW TrainLink regional trains (Regional Rail Project) will be fitted with automatic train protection (ATP) systems that are compatible with the Sydney Trains network (ETCS Level 2) and provisioned to allow the future fitment of onboard systems to interface with the ARTC advanced train management system (ATMS).

[138]   Examples include the advanced train management system (ATMS) on the ARTC network, the European train control system (ETCS) of various levels, and communications-based train control (CBTC) systems.

[139]   The National Transport Commission (NTC) is progressing a rail interoperability framework through an Interoperability Advisory Group. The NTC was established through the National Transport Commission Act 2003 and the Inter-governmental Agreement for Regulatory and Operational Reform in Road, Rail and Intermodal Transport.

[140]   While AS 7552:2021 states that ‘enclosed cabs of rolling stock shall be fitted with sufficient emergency exits to provide escape paths to the vehicle exterior when the vehicle is upright and when overturned on the side’, these emergency exits may not be accessible at ground level.

[141]   Static testing was conducted on power car XP2018 as the trailer cars immediately behind in the consist were damaged and without significant repairs could not be tested. Some components of XP2018 damaged during the derailment required repair in preparation for the brake testing.

[142]   The variation in the cross-level between two track locations separated by a nominated distance interval.

[143]   Due to the delay in the service on this day, arrival in Melbourne would have been later than the rostered end-of-shift.

[144]   Adopted by ARTC as Code of Practice for the Defined Interstate Rail Network, volume 3 operations and safeworking, Part 1: Rules, ARTC Version 3.0: 01 July 2018 (also referenced Issue 3.0- ARTC Annotated Version)..

[145]   RISSB developed the Australian Network Rules and Procedures into a National Rules Framework. The Framework provided a principles-based platform for rail transport operators in development of their own rulebooks.

[146]   An average wheel diameter was used to accommodate wear and a reducing diameter during the wheel’s life.

[147]   The ICE radio GPS speed is not displayed to the driver in the locomotive cab.

[148]   The speed display on XP2018 would have been reading about 127 km/h.

[149]   Braking data for XPT full-service braking (with 80% average deceleration), full seated load and a 1:150 descending grade indicates a stopping distance from 130 km/h of 1,120 m.

[150]   Includes braking system response and driver reaction. Reaction times of individuals can vary considerably.

[151]   ARTC Route Access Standard D53.

[152]   Actual speed calculated by correcting the recorded speed for actual wheel diameter. The recorded speed was about 2% lower than this estimated actual.

[153]   AS 7527:2015 (amendment 2019) recommended that legacy, tape based data loggers should, as a minimum record the following information: train speed, distance, time, and brake status (i.e. brake pipe pressure or brake cylinder pressure).

Interim report

Report release date: 10/06/2021

This Interim Report details factual information established in the investigation’s evidence collection phase and ATSB interim observations of that evidence. An Interim Report has been prepared to provide progress information to the public and the rail industry, and information on safety actions so far taken. This Interim Report does not contain findings or safety factors, that will be detailed in the Final Report.

The information contained in the Interim Report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 (Cth).

Prior to the occurrence

At about 2343[1] on 3 February 2020, the Australian Rail Track Corporation (ARTC) identified that Centralised Traffic Control (CTC) signalling had been disrupted on the Somerton to Albury line between Donnybrook and Kilmore East. A subsequent investigation by ARTC determined that a road vehicle had struck overhead wiring in Wallan, impacting power supplies to the rail signalling system. A fire in the Wallan signalling hut led to extensive damage to equipment and cabling.

As a result of the damage to the signalling system at Wallan, ARTC commenced managing rail traffic through the location using Caution Orders. Under this instrument, trains were required to proceed cautiously, resulting in significant delays to rail services using this section of the standard-gauge network. As repair of the signalling system was expected to take a significant period of time, alternative train working arrangements to Caution Orders were considered by ARTC.

ARTC commenced managing rail traffic through the location using a Train Authority[2] instrument on the evening of 6 February.[3] The instrument was used for the 24 km section between Kilmore East (at about the 63.8 km[4] mark) and Donnybrook (at about the 40.2 km mark). Wallan Loop was located between these locations, from the 49.058 km mark to the 47.268 km mark.

Notification to network users of the change to the use of Train Authorities was by an ARTC Train Notice.[5] The relevant Train Notice (TN 266) was issued on 6 February, updated on 7 February and further amended on 13 February. In the arrangements established, the points at Wallan Loop had been set for the straight and locked in that position. ARTC did not impose any additional speed restrictions through the section. The maximum permitted speed for the XPT when travelling on the main line through Wallan was 130 km/h.

On 19 February, Train Notice TN 266 was supplemented with a further Train Notice (TN 367) advising of a change at Wallan Loop, with trains to be diverted through the loop for a short period on 20 February. The purpose of routing trains through the loop was to remove any contamination that may have developed on the rail head while the loop track was not being used.[6] This was in preparation for signal system testing and re-establishment of the CTC signalling system over the coming days.

Between 1453 and 1536 on 20 February,[7] the points at either end of Wallan Loop were manually reconfigured from their Normal position to their Reverse position.[8] This change meant that rail traffic travelling in either direction after this time would be diverted from the main line into the crossing loop track (No.2 Road). Train Notice TN 367 reflected this change and also specified a 15 km/h speed limit for entry into the loop, and a limit of 35 km/h when exiting the loop. Between 1600 and 1837, Track Force Protection[9] for the laying of conduit was also in place near Wallan, between the 46.3 km and 45.4 km marks.

The first train to pass through Wallan Loop in this altered configuration was southbound V/Line train 8620. Immediately prior to train 8620 departing Kilmore East, the train controller advised the driver that they were going to be the first train through Wallan Loop in the past 72 hours. It departed Kilmore East at about 1623 and the Train Authority was cancelled at 1647 for its arrival at Donnybrook.

The second train through the loop was northbound V/Line train 8625. When stopped at Donnybrook and during exchanges between the driver and the network controller, there was no mention by either party of transiting through Wallan Loop. The train departed Donnybrook at about 1857. Train ST23 operated by NSW TrainLink was to be the third train through the loop.

Train ST23 from Sydney to Albury

On 20 February 2020, passenger train ST23 departed Central Station in Sydney, New South Wales (NSW) at 0741, just after the scheduled departure time of 0740. ST23 was to travel through NSW, and into Victoria to its destination in Melbourne (Figure 1).The service was scheduled to stop at several stations en-route to arriving at its final destination at Southern Cross Station (Melbourne) at 1830 that evening. ST23 comprised leading power car XP2018, five passenger cars of varying configuration, and a trailing power car.

Figure 1: Train route from Sydney to Melbourne

Train route from Sydney to Melbourne

Source: Google Maps, annotated by CIT

The train proceeded south and arrived at Junee in southern NSW at 1452,[10] about 85 minutes behind schedule. ST23 was a single-driver operation, and there was a change of driver at Junee. The train departed Junee at 1456 and continued south, arriving in Albury on the NSW-Victorian border at 1637. There was a change in passenger services crew at Albury. The new passenger services crew comprised a Passengers Services Supervisor (PSS), a crew member training for the supervisory role, and three passenger attendants.

Train ST23 from Albury

The train departed Albury at 1644, about 89 minutes behind schedule, and entered the Victorian section of its journey. After departing Albury, the PSS made an announcement covering a welcome, the delay, and emergency procedures. Tickets were checked and crew walked through the passenger cars checking door locks and equipment. Later, the driver was provided with a snack while stopped at Wangaratta Railway Station and the train departed that station at 1722.[11] Beyond Benalla, the focus of several attendants was on meal activities in the buffet car. The crew described the journey as normal although passengers were reported to be frustrated with the delays.

At about 1840, ARTC Network Control[12] contacted the driver of ST23 regarding a network alarm that had been received.[13] Later in the communication, the network controller advised the driver that due to the altered train working, ST23 would come into Kilmore East and wait until a V/Line train had passed. As part of this communication, the controller mentioned that ‘you’re going via the loop there at Wallan’. The response from the driver did not reference the train’s route via the Wallan crossing loop.

Train ST23 at Kilmore East

The service continued south before coming to a stand at Intermediate Home[14] signal KME28, that was at Stop. It was about 1856. There was a standard-gauge passing lane at Kilmore East, with designated East and West Lines, and ST23 had been routed via the East Line (Figure 2).[15]

Figure 2: Kilmore East standard-gauge passing lane (shown in black)

Kilmore East standard-gauge passing lane (shown in black)

The schematic shows the track at Kilmore East including the passing lane. Only the signalling for the standard-gauge track is shown.
Source: ARTC, modified and annotated by CITS

The driver of ST23 contacted ARTC Network Control at about 1904 and inquired when they might receive permission to proceed. ST23 was required to wait until the V/Line train 8625 had cleared the single-line section.

At around this time, several rail workers were preparing for the arrival of ST23 at signal KME16. These rail workers were to assist with the alternate train working that had been implemented between Kilmore East and Donnybrook. Amongst these rail workers were an in-field signaller and an Accompanying Qualified Worker (AQW).[16] The AQW would board the train and accompany the driver from Kilmore East to Donnybrook. Both the signaller and the AQW had just started their shift and ST23 was the first train they were assisting that evening.

At about 1915 while ST23 was stopped at signal KME28, the in-field signaller positioned near signal KME16 contacted ARTC Network Control to advise that he had come on shift and taken over from the previous in-field signaller. During this call, Train Authority number 17 (TA17) for ST23 to proceed between Kilmore East and Donnybrook was issued to the on-ground signaller by the network controller. The controller read TA17, describing that the authority was issued in accordance with Train Notices 266 and 367, that the points at Wallan Loop were set and secured for number 2 track, and that there was a maximum speed entering the loop of 15 km/h, and a maximum speed exiting the loop of 35 km/h. There was then a full read back of TA17 by the in-field signaller. The network controller noted the time of the read back as 1920. A Condition Affecting Network[17] number 7 (CAN7) was then completed by the signaller under the instruction of the controller. This notice was to warn train crew of the condition of the Wallan-Whittlesea level crossing protection, and that the protection was being manually operated. The read-back of CAN7 by the in-field signaller was noted by the controller as being completed at 1921.

ST23 was held at signal KME28 on the East Line until the northbound V/line passenger train 8625 had transited the Donnybrook to Kilmore East single-line section, passed signal KME2 and was travelling along the West Line through Kilmore East. The V/Line train was clear of the single-line section by about 1925 and, soon after, ST23 was given permission by the network controller to proceed to Home Departure signal KME16,[18] still on the East Line within the Kilmore East location.

ST23 arrived at signal KME16 at about 1931. The train was met by several rail workers that included the in-field signaller and the AQW. The AQW boarded the lead power car and joined the driver at the head of the train. It was intended that the AQW would accompany the driver of ST23 for the 24 km section to Donnybrook. The XPT cab was not fitted with a cab voice recording facility (and was not required to be), and there is no record of the conversation between the AQW and driver.[19]

At about 1932 while the train was stopped at signal KME16, the driver and ARTC Network Control communicated via the train radio. This exchange included confirmation by the driver that he was in possession of ‘authority 17 and CAN number 7 filled out the same way it has been’.

During this communication between the network controller and driver, the controller did not read the content of TA17 to the driver and there was no read back of the content of TA17 by the driver.[20] The controller commented ‘points all set for the loop’. The driver’s response to the controller did not reference transiting via the crossing loop or number 2 track at Wallan. There was no communication between the controller and driver regarding the maximum speed of 15 km/h for entering the crossing loop.

The derailment of train ST23

The train departed signal KME16 at about 1934 and entered the single-line section towards Wallan. The line speed for the XPT between Kilmore East and Donnybrook was 130 km/h.[21] After departing from signal KME16, the speed of the train was increased and maintained between 100 km/h and 120 km/h.

The AQW was to ensure that the level crossing protection[22] at Wallan–Whittlesea Road in Wallan was in place for the passage of the train.[23] A Level Crossing Keeper (LCK)[24] was located at the crossing to perform the manual activation. The AQW contacted the LCK at approximately 1941, when the train was at about the 52 km mark. The LCK reported activating the crossing protection at Wallan–Whittlesea Road, and confirmed its activation to the AQW. This phone call lasted about 53 seconds and the LCK did not recall anything unusual about the communications with the AQW. The call had been completed when the train was about 4.5 km from the level crossing and 2.7 km from the entry to Wallan Loop.

At about 1943, ST23 was approaching the northern end of Wallan Loop at about the track’s line speed. A brake application was made a short distance before the turnout, probably between 50 and 153 m from the points. This slowed the train a small amount before it entered the turnout travelling at a speed probably between 114 and 127 km/h. The train was not able to negotiate the turnout to the crossing loop track at this speed and derailed. The leading power car rolled onto its left side. All vehicles derailed excepting the rear power car (Figure 3).

Figure 3: Aerial photograph of derailment site

Aerial photograph of derailment site

Source: ATSB

Emergency response

At the time of the derailment, there were 155 passengers,[25] six train crew and the AQW aboard the train. The driver and AQW were in the driver’s cab, four passenger services crew were in the buffet car (the third passenger car) and another passenger services crew member was in the second passenger car.

After the train came to a stop, the PSS called the train crew on a hand-held radio and received responses from the other members of the passenger services crew. However, the driver did not respond and the AQW was not in possession of a NSW Trains issued radio.

Around this time, members of the train crew attempted to report the emergency using their radios. A V/Line signaller based at Wallan heard and responded to one of the emergency calls. The Wallan signaller contacted Centrol[26] and, at about 1945, Centrol contacted ARTC Network Control at Junee relaying the information that the XPT may have derailed. In this conversation, Centrol also advised ARTC that V/Line would stop trains on the broad-gauge tracks that ran parallel to the standard-gauge. In response to the Centrol call, ARTC initiated its response.

Emergency services recorded the first ‘000’ call for assistance from a train passenger, time-stamped 19:45:06.[27] This was followed by a series of calls from other passengers, members of the train crew, and members of V/Line and ARTC.

Around this time or soon after, some passengers started to self-evacuate from the train. A member of the train passenger services crew was allocated to manage passengers on the track, and two services crew members remained on the train to attend to passengers. The other two passenger services crew went to the lead power car. Here, they entered the power car through its the right-side cab door, accessible from the ‘top’ of the car laying on its left side. Finding it difficult to assist from within the cab, they then went to the outside and attempted to gain ground-level access by breaking the windscreen of the driver’s cab.[28] However, attempts by the passenger services crew to gain this ground-level access were unsuccessful.

The first emergency services to arrive on site was Victoria Police at about 2003, followed by further emergency, medical and fire services. However, both the driver and the AQW did not survive the accident.

As a result of the movement of the passenger cars during the derailment, eight passengers were seriously injured and 53 received minor injuries. The five passenger services crew located in the passenger cars also received minor injuries.

__________

  1. All times are Australian Eastern Daylight Time (AEDT) and use the 24-hour clock.
  2. An instruction in the prescribed format issued by the Network Control Officer in connection with the movement of a train. RISSB Glossary of Terms, viewed 30 March 2020, <https://www.rissb.com.au/glossary/>.
  3. The first Train Authority was issued at 2042 on 6 February.
  4. Rail-km from Melbourne.
  5. Operational information issued by or on behalf of the Rail Infrastructure Manager. RISSB Glossary of Terms, viewed 30 March 2020,< https://www.rissb.com.au/glossary/>
  6. Residues such as iron oxides can hamper electrical connection between wheel and rail and impact performance of signalling systems.
  7. A track warrant for this activity was taken between these times.
  8. The Normal position of the turnouts was for ‘straight-through’ traffic, and the Reverse position was for the loop.
  9. A system used to protect a worksite.
  10. Stopping times at stations are as recorded by NSW TrainLink.
  11. 87 minutes behind schedule.
  12. The ARTC Network Control office for this section of track is located in Junee in NSW.
  13. An alarm had been received by network control for a possible signal passed at danger (SPAD) at Tallarook, 23 km NE of Kilmore East. The network controller indicated that there had been power outages at this location, that may have showed up as a SPAD. The driver indicated that all signals had been ‘clear’ through Tallarook.
  14. This signal protected the broad-gauge crossover going into the Apex ballast quarry. It is called an ‘Intermediate Home’ because it is in an intermediate location along the passing lane.
  15. The passing lane was about 7 km in length. A ‘passing lane’ is an extended crossing loop long enough to be considered a short section of bi-directional double track.
  16. The term used in Train Notices for the worker that would accompany the driver between Kilmore East and Donnybrook.
  17. A Condition Affecting Network is a warning provided of an unsafe condition affecting, or potentially affecting, the network.
  18. Home Departure signal KME16 was protecting the turnout at the end of the passing lane. Permission for passing this signal at Stop was included in the Train Authority.
  19. Currently in Australia, locomotive and train operating cabs are generally not fitted with voice recording devices.
  20. In the extant version of Train Notice TN 266, read back of the Train Authority by the driver was not required
  21. Within this section, there were 115 km/h speed restrictions applied to some sections of track.
  22. Boom barriers and flashing lights at this location.
  23. Active protection on the other level crossings on the Kilmore East-to-Donnybrook section were working normally and it was only the Wallan-Whittlesea Road level crossing that required local operation.
  24. The person who activated the level crossing protection locally at the crossing, colloquially referred to as the bellhop.
  25. Passenger numbers based on available data from the operator.
  26. V/Line’s network train control centre located in Melbourne.
  27. The emergency services call centre time stamp.
  28. Using tools sourced from the train’s emergency breakdown kit.

Context

Train operator

ST23 and the XPT fleet was operated by NSW TrainLink, the operating name of NSW Trains, an agency of Transport for NSW (TfNSW).[29] NSW Trains provided passenger services in regional NSW and between the east coast capital cities of Melbourne (Victoria), Sydney (NSW) and Brisbane (Queensland).

Train crew

The driver

The driver of ST23 had been associated with the rail industry for about 40 years, employed in a range of roles including driving, training, and management. They returned to driving in mid-2016 as a Regional Driver with NSW Trains and were assessed as competent on the Junee - Melbourne route in July 2019.The driver had been medically assessed as fit-for duty (unconditional) in accordance with requirements for a Category 1 Safety Critical Worker.[30]

The driver regularly drove the XPT services between Junee and Melbourne. They would run the Junee to Melbourne leg and, following a period of rest in Melbourne, the return leg to Junee. After the commencement of alternate train working through Wallan on 6 February 2020, the driver ran the Junee–Melbourne–Junee round trip (including a rostered rest period in Melbourne) four times between 8 and 19 February. On 20 February, the driver’s shift commenced at Junee at 1315 and the scheduled sign-off time in Melbourne was 1845.[31]

The accompanying qualified worker

The Accompanying Qualified Worker (AQW) aboard ST23 was employed by Programmed: a labour-hire organisation that provided skilled workers across a range of industries including transport. Programmed supplied several personnel to ARTC from 4 February for the management of rail traffic between Kilmore East and Donnybrook.

The AQW had been with Programmed since 2006. Records[32] indicate that the worker had been engaged by several rail operators in Victoria in various roles, in recent years primarily as a Track Force Protection Coordinator or hand signaller. The AQW was certified to Track Protection Coordination level 3.2, most recently renewed in March 2019. They had been medically assessed as fit-for duty (unconditional) in accordance with requirements for a Category 1 Safety Critical Worker.

The AQW had been engaged at Wallan from 4 February, primarily in the role of Level Crossing Keeper at the Wallan–Whittlesea Road crossing. All shifts from February had been night shifts that mostly commenced at about 1900. On 20 February, the AQW had just commenced the night shift. This was their first shift providing AQW services through Wallan, and this was their first train that evening.

Passenger services crew

There were five passenger services crew aboard ST23, one more than the normal complement of four. The passenger services crew consisted of:

  • A Passenger Services Supervisor (PSS) responsible for overall supervision of the passenger operations
  • A Senior Passenger Attendant (SPA) responsible for the buffet operations and ticket sales
  • A Passenger Attendant 2 (PA2) responsible for general passenger duties along the train
  • A Passenger Attendant 4 (PA4) responsible for assisting the SPA in the buffet, and assisting with general passenger duties along the train
  • An additional crew member designated acting Passenger Services Supervisor (aPSS) who was shadowing the PSS as part of on-the-job training.

Train information

The XPT (Express Passenger Train) was first introduced into service in 1982 and was based on the InterCity 125/Class 43 design used in the United Kingdom. The fleet of XPT vehicles were maintained by Sydney Trains.[33]

The XPT operating service ST23 on 20 February 2020 comprised seven vehicles that included five passenger cars (Figure 4). The leading three vehicles were manufactured by ABB Transportation in Dandenong, Victoria and commissioned in 1993. The trailing four vehicles were manufactured by Comeng in Granville, NSW and commissioned between 1981 and 1984.

Figure 4: Train configuration

Train configuration

Source: Vehicle images supplied by Sydney Trains, annotation by CITS

The power car comprised a forward driver’s cab with two seating positions, ahead of the compartment housing propulsive machinery (Figure 5). The primary access to the driver’s cab was via its side doors.

Figure 5: Power car layout and cab seat arrangement

Power car layout and cab seat arrangement

Source: RailCorp (NSW Transport), annotation by CITS

Infrastructure

Track

The XPT service was running on the standard-gauge track that connects Sydney and Melbourne. The track was part of the Defined Interstate Rail Network (DIRN) and was managed by the Australian Rail Track Corporation (ARTC).[34]

The standard-gauge track between Kilmore East and Donnybrook was a single, bi-directional line used by the XPT, V/Line passenger services and rail freight. There were passing lanes at Kilmore East and Donnybrook and a 1,550 m crossing loop at Wallan (Figure 6). The northern entry to this loop was located about 1.8 km north of Wallan–Whittlesea Road. At the southern end of the Wallan loop was Wallan Railway Station that serviced broad-gauge passenger trains.[35]

Figure 6: Standard-gauge track and signals at Wallan Loop

Standard-gauge track and signals at Wallan Loop

The schematic shows the standard-gauge track at Wallan including the crossing loop. The standard-gauge tracks are shown in black, and the adjacent broad-gauge tracks in red. Only the signalling for the standard-gauge track is shown in this figure.
Source: ARTC, modified and annotated by CITS

Wallan Loop northern turnout

The turnout at the northern end of the Wallan Loop was located at the 49.058 km mark. For southbound trains approaching the northern end of Wallan Loop, there was a downhill gradient of approximately 1:150 and the track was tangent (straight) for about the final 800 m of the approach to the turnout. The approach track was comprised of 60 kg/m rail, fastened to concrete sleepers.

The turnout design was rated for a train speed of 25 km/h and the maximum operational speed was 15 km/h in accordance with the ARTC operating code of practice.[36] It consisted of 60 kg/m rail on timber bearers, with a cast V-crossing.

Following the left turnout, the right curve (in the direction of travel) leading onto the No. 2 Road had a radius of about 422 m.[37][38]

Signals

Entry to the northern end of Wallan Loop was normally controlled by signal WLN8. Signal WLN8 was a 3-position Home signal able to authorise movement in the Up direction. When operational, signal WLN8 could provide ‘Clear Normal Speed’, ‘Low Speed Caution’ or ‘Stop” indications (Figure 7). For movements into the crossing loop, the ‘Low Speed Caution’ indication would be used.

At the time of the derailment, signal WLN8 was extinguished and was fitted with a black cross near its base to indicate that it was not functioning (Figure 7).

Figure 7: Signal WLN8 possible indications (left) and on day of occurrence (right)

Signal WLN8 possible indications (left) and on day of occurrence (right)

The figure shows the possible indication for signal WLN8 (when operational), and a photograph of the signal extinguished on the day of the occurrence. The photograph of signal WLN8 also shows the black cross that was attached to the signal post.
Source: CITS

A broad-gauge distant signal was located about 45 m to the north of WLN8 and was probably indicating a Proceed (green) aspect at the time ST23 passed (Figure 8).[39] This broad-gauge signal did not apply to the operation of ST23 that was running on the standard-gauge line.

Figure 8: The tracks and signalling at the northern end of Wallan Loop

The tracks and signalling at the northern end of Wallan Loop

The photograph shows the approach to the Wallan Loop turnout. The photograph has been modified to show the extinguished state of standard-gauge signal WLN8 and the probable Proceed (green) indication of broad-gauge distant signal at the time of the derailment. The black cross that was fitted near the base of signal WLN8 at the time of the derailment is not shown in this figure. 
Source: V/Line training video, with signal indications modified and annotated by CITS

Environmental conditions at Wallan

Weather

The conditions at the derailment location were dry. At 1930 at the nearest weather station at Kilmore Gap,[40] the temperature was recorded as 13°C, and the wind was from the south at 32 km/h.

Location of sun

The derailment occurred about 30 minutes before sunset. At 1943 at Wallan, the sun was at an azimuth[41] of 259°48'28" and altitude[42] of 5°02'59".[43] The direction of travel was 223° from true north, meaning the sun was about 36° to the right of the driver’s direct view ahead.

Management of rail traffic (safeworking)

Safeworking systems and rules

Purpose

Safeworking is an integrated system of operating rules and procedures that defines the interaction between workers and engineered systems for the safe operation of a railway.[44] Of primary concern is safe operations including train separation and speed management.

Operating rules 

ARTC operating rules for Victoria were defined in the ARTC Code of Practice for the Victorian Main Line Operations (TA20).[45] This Code formed part of ARTC’s Safety Management System (SMS).[46] The Code described two safeworking systems, Centralised Traffic Control (CTC) and the Train Order System.[47]

Centralised Traffic Control

Prior to the signalling hut fire at Wallan in February 2020, standard-gauge rail traffic through this section was managed using the CTC system of safeworking described in section 17 of TA20. In the case of signal failure in a CTC system, this section provided for the use of Caution Orders. The Caution Order form used in conjunction with a CTC system required that traffic ‘proceed cautiously’ …. ‘in accordance with Rule 1, Section 3’.[48]

Train Authorities

The procedures associated with Train Authorities were specified in section 25 of TA20, and also in section 17 for the CTC system. The circumstances specified for the use of Train Authority with a CTC system were:[49]

  • To assist a disabled train
  • Train to return to the crossing loop in the rear
  • Working a train to the point of an obstruction on one or both sides.

The Code specified that ‘Train Authority Working[50] must be used as specified by the individual operation of the safeworking system’.

ATSB observation

The use of Train Authorities in the circumstances that were present through Wallan in February 2020 was not provided for in the ARTC Code of Practice for Main Line Operations (TA20).

Use of Train Authority working in previous projects

ARTC advised that Train Authority working had previously been used during commissioning activities, often following signalling system upgrade.

Implementation of Train Authority working at Wallan

Background

Late on 3 February 2020, the Australian Rail Track Corporation (ARTC) identified that signalling had been disrupted between Donnybrook and Kilmore East. As a result of the damage to the signalling system, ARTC commenced managing rail traffic through the section using Caution Orders. To reduce traffic delays associated with Caution Orders, ARTC commenced managing rail traffic through the location using Train Authorities from 1900 on 6 February.[51]

Resourcing for altered train working arrangements

ARTC implementation of altered train working arrangements between Donnybrook and Kilmore East involved the engagement of several contractors. ActivateRail[52] was contracted to provide specialist rail project services, and labour hire firms Programmed and ARG Rail[53] supplied several rail workers.

Establishment of altered train working arrangements

A system of train working was established between Home Departure signals at Donnybrook and Kilmore East and notified by the issue of Train Notice 266. In this notice, operators were advised that rail traffic would operate by means of Train Authority. The notice included the processes that would be used and also advised that the points at either end of Wallan Loop would be clipped in the Normal position. Signage would be located at either end of the affected section advising drivers of the demarcation between CTC and Train Authority working.

Issuing of Train Authorities in the altered train working

The system used in February 2020 for issuing a Train Authority to a driver travelling between Kilmore East and Donnybrook involved the on-duty ARTC Network Control Officer (NCO) at Junee, an in-field signaller and an accompanying qualified worker (AQW). The key steps used in practice were:

  • The in-field signaller was provided with partially completed Train Authority (TA) forms.
  • The in-field signaller positioned themselves at whichever end of the Kilmore East – Donnybrook section that was to receive the next train.
  • Prior to the arrival of the next train, the in-field signaller contacted the NCO to obtain details of the TA specific to the next train movement. The NCO dictated the details of the TA to the signaller and the signaller completed the form accordingly.
  • The in-field signaller would then read back the completed TA to the NCO to verify its contents.
  • A Condition Affecting Network (CAN)[54] notice was also completed by the signaller under the instruction of the controller.
  • The in-field signaller would give the completed TA to the AQW (together with the CAN) and, on the train’s arrival, the AQW would board the driving cab of the train. There was no contact between the in-field signaller and the driver of the train.[55] 
  • Once on board, the AQW would give the TA and CAN notice to the driver. The driver would then contact the NCO to verify the TA. ARTC required the driver to verify the TA by its number. There was no expectation that the driver would read the TA to the NCO.[56]
Train Notice 266[57]

The use of Train Authorities between Kilmore East and Donnybrook in February 2020 was notified in Train Notice 266 (TN 266), issued on 6 February 2020 and commenced at 1900 on that day.

TN 266 was amended and reissued on 7 February. This amended notice advised that, in exception of a rule[58] within TA20, some disarranged signals may be lit, and that they would have a black cross affixed to the signal post.[59]

TN 266 was further amended and re-issued on 13 February 2020. Amendments included:

  • Removal of the advice that signals in the section may remain lit.[4]
  • Addition of text advising that ‘Repeat Back of the Train Authority is not required to be undertaken by the driver of the rail movement’.
  • Replacement of ‘The rail movement may proceed through the section in the normal manner’ with ‘The rail movement may proceed through the section up to track speed as advised by the Accompanying Qualified Worker’.
Train Notice 367[61]

Train Notice 367 was issued on the evening of 19 February 2020 and contained additional instruction to TN 266. It advised that ‘In addition to instructions contained in Train Notice 266 / 2020 issued on 13/02/2020 the following temporary alteration to working will apply’.

TN 367 included advice that:

  • the points at Wallan Loop would be set for the No. 2 Track and that the maximum speed at entering the loop was 15 km/h and the maximum speed exiting the loop was 35 km/h.
  • TN 367 also included advice that ‘The Accompanying Qualified Worker must remind train crews of trains that the train will operate via No. 2 track at Wallan’.[62]

New, part-completed, Train Authority forms that included detail consistent with TN 367 were issued to the in-field signallers and ARTC Network Control, replacing the previous Train Authority forms.

Risk management

Safety Management System

ARTC’s Safety Management Systems (SMS) included procedures requiring risk assessments for standard and ‘out-of-course’ safeworking arrangements.[63] This procedure identified the potential need for a risk study or assessment for a range of activities and system changes. The procedure for risk management specified that formal risk studies were usually undertaken for complex activities where potential impact was likely to be significant. The listed types of activities where a formal risk study may be appropriate included:

  • Significant civil works, such as tunnel construction, bridge construction
  • Technical operational changes, such as introduction of new signal/track infrastructure
  • Safety critical system changes, such as network control system changes.

The procedure also specified that formal risk assessment was undertaken in order to identify potential risks, their causal and contributory factors, the likelihood and consequence of the risk eventuating, and controls that may be implemented to prevent the risk or otherwise minimise the impacts of the risk. It specified that a formal, documented risk assessment must be conducted in various circumstances (including when notifiable changes are planned to the SMS and/or network configuration and as directed in project management procedures). This could include the identification and assessment of risks associated with:

  • Achievement of organisational objectives
  • Operational activities of the organisation
  • Projects
  • Impending changes to the organisation, operational environment or systems.
Risk assessments associated with altered train working through Wallan

Initial risk assessment

A risk assessment for the operation of rail traffic between Donnybrook and Kilmore East by Train Authority working was reported as being conducted at approximately 1600[64] on 6 February 2020 and the associated documentation finalised on 7 February. The risk assessment involved representatives from ARTC and ActivateRail and was based on previous applications of Train Authority working by ARTC.

The risk assessment for Wallan contained 10 identified hazards and associated control measures. Hazards and risks associated with routing trains through Wallan Loop were not directly identified in the risk worksheet. Hazard number 2 (Rail Operators not aware of the altered working) was indirectly relevant to any potential train operations through the loop (Table 1).

Table 1: Extracts of risk assessment for altered train working

 HazardCaused byWorst OutcomeControlRisk Rank
2Rail Operators not aware of the altered workingTrain notices not received by train crews detailing the processes in placeTrain driver accepts the train authority and proceeds into the section not conversant with the altered working

Train Notices will be issued in a timely fashion.

Signals at the interface of the commissioning will have change of Safeworking signage to indicate the interface between CTC and Train Authority working.

Disarranged signals will have black crosses affixed to them.

Train are piloted through the section.[65]

Low

ARTC reported that the risk worksheet was released to V/Line and Programmed. NSW Trains and freight operators were not included in this distribution. The documented risk assessment was not updated after 7 February 2020. However, ARTC has advised that risks relating to the altered train working continued to be informally assessed as feedback was received and that changes were reflected in the amendments made to Train Notice 266.

Risk assessment for travelling through Wallan Loop

There was no documented risk assessment specific to the routing of trains through Wallan Loop on 20 February and the release of Train Notice 367. The risk controls adopted for this change included the provision of information to operators through the issue of TN 367, and a note within that notice that the AQW was to advise the driver that the train will operate via No. 2 Track at Wallan Loop and of the speed limits required (for entry to and exit from the loop).

ATSB observation

Formal risk assessment was not used to identify hazards and available risk controls to manage the risk associated with train overspeed at the entry to Wallan Loop.

Distribution of safety notices

ARTC

Procedures defined the processes to be followed for preparing, reviewing, approving and issuing Operational Notices (including Train Notices) on the ARTC Network.[66] Different processes applied to different parts of the ARTC network.

Approved operational notices for Victoria, South Australia and Western Australia were published on the ARTC WebRAMS (Rail Access Management System) portal.[67],[68] Standing Train Notices were specified as being uploaded to this portal at approximately 1800[69] each evening. Access to WebRAMS was available to ARTC customers and stakeholders via an allocated User ID system. Rail operators were required to access the safety notices through this portal.

For the New South Wales and Queensland network, the ARTC procedures for distribution of operational notices specified direct transmission to selected internal and external stakeholders.

ARTC Distribution of Train Notice 367

Formal distribution of Train Notice 367 by ARTC to rail operators was via the WebRAMS portal. ARTC reported that TN 367 was uploaded to WebRAMS as part of an automated system update at 1815[70] on 19 February 2020.

In addition to the formal release, information regarding transit via Wallan Loop and the release of TN 367 was shared with V/Line. There was no active engagement by ARTC with, or direct release of TN 367 to, NSW Trains or freight operators.

NSW Trains

Sources of safety information for operation on the Victorian network

For its operations within Victoria, NSW Trains drew on Weekly Operational Notices (WONs) prepared by Metro Trains Melbourne (MTM) and issued each Tuesday for the week commencing the Wednesday.[71] The WONs included safety information for metropolitan and regional services. The WONs did not, however, typically include ARTC Train Notices, and reference was instead made within the WON to the ARTC WebRAMS portal.

NSW Trains did not routinely interrogate the ARTC WebRAMS portal for network operational information related to its Victorian operations. For its operations on the NSW portion of the ARTC network, it received train notices directly from ARTC.

ATSB observation

NSW Trains systems for obtaining network safety information for operations within Victoria did not include accessing information via the ARTC web portal.

Distribution of safety information to drivers

Each week, information considered relevant to its Victorian operations was extracted from the WON. This was used to produce an information pack for its regional drivers that would operate in Victorian territory. This information pack was then placed in the pigeon-hole of each driver at their Junee base. It was the driver’s responsibility to collect information from their pigeon-hole.

NSW Trains distribution of Train Notice 367

No evidence has been identified to indicate that NSW Trains was aware of Train Notice 367 prior to the occurrence. WON Issue No. 07 that was published on 18 February 2020 did not include information from TN 367. Extracts from WON 07 were prepared for distribution by 1139 on the morning of 20 February and were reported placed in the pigeon-holes of regional drivers (at Junee) by 1247 the same day.

ATSB observation

NSW Trains and its regional drivers coming on shift were probably not aware of the issuing of Train Notice 367 by ARTC and the possible operation of the ST23 through Wallan Loop on 20 February 2020.

WON Issue No. 07 that was published on 18 February 2020 did contain Train Notice 266 (as amended on 13 February). This was the ongoing operational notice for the Kilmore East to Donnybrook section at the time of the release of WON 07. It’s direct inclusion in the WON was not standard practice, and was the result of V/Line re-issuing ARTC TN 266 (as amended 13 February) within its own system.

V/Line distribution of Train Notice 367

Normal V/Line process entailed driver supervisors checking the WebRAMS portal after the evening publishing of ARTC notices on that portal and distributing train notices to affected drivers.

In this instance, on the evening of 19 February, V/Line also published a V/Line safe working circular (SW.0024.2020) incorporating TN 367, for distribution to all drivers including those running broad-gauge services. The V/Line drivers that ran through Wallan Loop on 20 February were also contacted by their driver supervisor prior to their shift and advised of the change.

Derailment site information

Position of leading vehicles

The derailed train came to rest in a concertinaed arrangement. The lead power car had rolled onto its left side and decelerated at a higher rate than trailing vehicles (Figure 9).

Figure 9: Leading three vehicles in the derailment

Leading three vehicles in the derailment

The photograph shows power car XP2018 on its left side, and first two passenger cars A and B. 
Source: CITS

Of the passenger cars, the first (Car A) had the greatest tilt of about 30 degrees from the vertical. It had come to rest on a row of pine trees and its trailing end had bound with the next car, Car B (Figure 10). The row of pine trees had probably stopped Car A from rolling onto its side.

Figure 10: The derailed position of Car A (left photograph taken after removal of trees)

The derailed position of Car A (left photograph taken after removal of trees)

The left photograph shows Car A rolled to its left and supported by pine trees, and the right photograph shows the trailing end of Car A bound with the leading end of the next car, Car B. 
Source: CITS

Points position and turnout

At the time of the derailment, the points at the northern end of Wallan Loop were in their Reverse position to provide entry to the loop (Figure 11). The point mechanism had been placed into hand-mode [72] and the points locked in the Reverse position. The mechanism was also padlocked.

There were a number of witness marks on rails and within the track that indicated that wheels had derailed within the turnout. There were no derailment marks identified prior to the turnout.

Figure 11: No. 7 points at the northern entrance to Wallan Loop

No. 7 points at the northern entrance to Wallan Loop

Source: CITS

Train recorded information

The Hasler RT recorder

Power cars XP2018 and XP2000 were each fitted with a Hasler RT data recorder. The Hasler RT is an electro-mechanical device that records data onto a waxed paper tape (roll). Data recorded included speed, distance, time, a combined power-vigilance parameter, and brake cylinder pressure. The Hasler equipment included an analogue speedometer located on the driver’s console.

The Hasler tapes from the two power cars were recovered for analysis (Figure 12). During retrieval, the Hasler tape from XP2018 jammed in the recorder and was damaged. However, all information was recovered and data relevant to the investigation was not affected.

Figure 12: Hasler waxed paper rolls removed from power cars XP2018 and XP2000

Hasler waxed paper rolls removed from power cars XP2018 and XP2000

The photograph shows the recovered waxed tapes. The centre roll is the tape from power car XP2000. The left and right rolls are the tape from power car XP2018 that jammed and was torn at one location. 
Source: CITS

Data processing

Unlike modern data logger systems that provide digital information for a wide range of operating parameters, Hasler recorders provide limited information in graphical format. In addition to the limited range of information, the format can introduce a loss of precision in the presentation of recorded data.

To process the data, both tapes were scanned and examined using photographic software. The traces for each recorded parameter were assessed for alignment with key events, such as start/stop points. Some horizontal re-alignment of parameters was required and both the horizontal and vertical scales of the images were calibrated for measurement.

Wheel diameter corrections

The Hasler used a pre-set (average) wheel diameter to calculate both speed and distance from the measured revolutions of the left-hand wheel on the second axle of the power car (wheel 3).[73] Actual speed may deviate from that recorded (and displayed) due to differences between this pre-set diameter and the diameter of the actual wheel providing the feed to the Hasler system. The actual measured wheel diameter for both power cars was larger than the pre-set value, hence recorded speed and distance were lower than the actual values.

The recorded values for speed and distance were corrected for the ratio of actual-to-pre-set wheel diameter (Table 2). The larger actual wheel diameter on the XP2018 (compared to the pre-set) meant that the recorded speed was about 2% lower than the actual train speed.

 XP2018 – leadingXP2000 – trailing
Pre-set diameter (mm)10001000
Measured diameter (mm)1019.21011
Ratio (correction factor)1.01921.011
Uncertainties in recorded data

An initial review identified a likely recording anomaly in the latter part of the XP2018 data. All channels recorded noise in the latter phase. An overlay of the data from the two power cars showed the discrepancy (visible as diverging speed toward the end of the data) and also confirmed that the speed data prior to this occurring was consistent (Figure 13).

Figure 13: Overlay of data recordings from XP2018 and XP2000

Overlay of data recordings from XP2018 and XP2000

The image shows an overlay of speed records from power cars 2018 and 2000. It indicates consistent speed records after departing Kilmore East, then a consistent initial sharp deceleration of both cars followed by diverging speed records during the derailment. 
Source: ST23 Hasler recordings annotated by ATSB

There were also potential inaccuracies in the XP2000 data in the latter stages due to uncertainty in measured wheel rotation being an accurate measure of train speed during this phase.

Other sources of train speed

GPS data from the installed ICE radio system[74] was interrogated and used as a comparator for time, speed and position information. While only coarse GPS data was available due to the system’s polling frequency, it provided a source for comparison with the Hasler data and an enhanced confidence in the assessed train speed. The GPS data was also the primary source for locating the position of ST23 when stopped prior to signal KME16.

Throttle and braking events

One limitation of the fitted Hasler data recorder was that it did not record the positions of the driver’s throttle and brake handles. Instead it recorded a generic power ON-OFF parameter and brake cylinder pressure.

The data from both power cars indicated that, at a point just prior to the commencement of deceleration, the power moved from ON to OFF and there was a rapid increase in brake cylinder pressure. For each recording, the points at which brake cylinder pressure began to rise and then reached a steady state were determined. The steady state pressures were noted for each record and compared with expected values. For both power cars, the recorded pressure was above that expected for a Notch 7 (Full-Service) application (345 kPa). The pressure recorded on XP2018, the leading power car, was about 378 kPa which was in line with the pressure expected for an Emergency application (375 kPa). While the pressure recorded on XP2000 was lower, about 358 kPa, it was still substantially above the Full-Service value. These results indicate that it was very likely that the brake application was an Emergency application. The speed of the train at the commencement of braking was about 129 km/h.[75]

Location of rise in brake cylinder pressure

Due to known limitations and potential anomalies in the Hasler data recording, obtaining position information from the data with respect to fixed points on track was difficult to achieve with high levels of accuracy. Therefore, the position at which brake cylinder pressure began to rise and the speed at which the train entered the turnout could not be directly read from the Hasler data.

Instead, the Hasler speed and distance data was used to calculate estimates of position considering different known stop locations. This was cross-checked using data from other sources to provide greater confidence. The different methods yielded slightly different results, however all indicated that the brake application was commenced before entry to the Wallan Loop (Table 3).

Table 3: Estimated start of braking and speed at entry to turnout

ParameterEstimated closest brakingEstimated furthest braking[76]
Distance from brake cylinder pressure rise to No.7 points50 m153 m
Speed at No. 7 points127 km/h114 km/h

 

Train handling of ST23 during journey

The Hasler recordings and the GPS data were examined to evaluate any potential trend in speed exceedance by ST23 during the Victorian segment of the journey. The ARTC Route Access Standard specified a maximum speed for express passenger trains in Victoria (including the XPT) of 130 km/h in areas where no local speed restrictions applied.[77] The assessment focussed on any identifiable trends and did not include local speed restrictions that were remote from the event.

Review of the GPS data identified 11 speed peaks of between 133 and 137 km/h in the Victorian section. These exceedances within the GPS data were cross-checked with the Hasler recordings and similar peaks identified, including a maximum actual value of about 139 km/h.[78]

None of the over-speeds identified were for a significant duration. These observations suggest that the driver was targeting line speed and occasionally overshooting. There was no evidence identified to suggest unusual train handling.

Vigilance parameter

The locomotive was fitted with a vigilance system. The installed Hasler does not record all information on driver activity associated with the vigilance system and its information is therefore of limited value.[79] However, the Hasler does record a vigilance parameter. The last point at which the vigilance parameter was recorded as active was prior to the stop at signal KME 28. There were no vigilance parameter events recorded between ST23 departure from signal KME 16 and the occurrence.

Cab video and voice recording devices

Power car XP2018 was not fitted with in-cab voice or video recording devices, nor was it required. As a result, there is no available evidence with respect to any communications or interactions that may have taken place between the driver and AQW prior to the occurrence.

Voice and video recording within the driver’s cab would have assisted the investigation in ascertaining the interactions within the cab, and the potential identification and analysis of associated safety factors.

ATSB observation

Voice and video recording within the driver’s cab would have assisted the investigation in the identification and analysis of potential safety factors.

Rolling stock condition assessment

Overview

Scope of condition assessment

The assessment of rolling stock condition was led by OTSI. The assessment involved vehicle inspections, oversight and review of testing conducted by Sydney Trains on behalf of ATSB, and a review of maintenance records. Specific testing was conducted on braking, vigilance and communication systems. The twist characteristics of power car XP2018 were also assessed.

Assessments were conducted at several locations and included observations at the derailment site on 21 February 2021, inspection of vehicles XP2000 and XFH2108 at the Sydenham Maintenance Centre on 6 March 2020 and inspection of vehicles XP2018, XAM2179A, XL2229, XBR2155 and XF2201 at the Auburn UGL facility on 10 March 2020. Further inspection and testing was witnessed by OTSI at the Auburn UGL facility. 

Summary findings of rolling stock condition assessments

Based on post-incident testing of safety critical systems including braking, vigilance and communications systems, vehicle and component inspections, and a review of maintenance records, no rolling stock condition or defect has been identified that was likely to have contributed to the derailment.

ATSB observation

Completed post-incident assessment of ST23 rolling stock did not identify a condition or defect that was likely to have contributed to the derailment. This included braking, vigilance control and radio communications systems.

Incident site observations

General

Observations were made at the derailment site prior to the rolling stock being moved. The preliminary observations did not identify evidence of rolling stock defects or equipment failures potentially causal to the derailment. All vehicles remained mechanically coupled although some couplers had sustained damage in the derailment. All bogies remained attached.

The derailed vehicles exhibited wheel tread damage consistent with (and typical for) running on track ballast. The wheels on the leading passenger vehicle (XAM2179) exhibited significantly more wheel tread damage than those of power car XP2018, suggesting that power car XP2018 had travelled in an upright derailed state for a shorter distance than the following passenger vehicle. This was consistent with the power car overturning early in the derailment sequence.

Brake controller position

At the time the site observations were made, the brake controller in the driver’s cab of power car XP2018 was in the Emergency brake position with the power (throttle) controller in OFF and the reverser direction in Forward.  

Sydney Trains maintenance systems

Maintenance of the XPT fleet was managed using the Sydney Trains Enterprise Asset Management (EAM) system. Work orders were generated within EAM in accordance with the requirements of the Technical Maintenance Plan (TMP). The TMP specified the frequency of tasks required for the power cars and trailer cars. Maintenance inspections included Major Inspections and Trip Inspections (pre-release to service). In addition to the maintenance regime, heavy overhauls were conducted at specified frequencies.

The Major Inspection was typically completed at 90-day intervals and inspected the condition of the carriage in greater detail. The task list for each Major Inspection varied with the inspection cycle, with some tasks completed more frequently than others.

Review of maintenance system

Open work orders

At the time of the derailment of ST23, a number of work orders within the TMP were listed as Open. However, none of the Open orders were found to be relevant to the risk of derailment.

It was also found that vehicles of ST23 entered service with work orders for the Trip Inspection of all cars identified as Open. However, review of the task list identified that most tasks had been completed prior to the train entering service. Those tasks that were not completed were not considered potential contributors to the derailment.

Fault management

Open and closed faults for the 120 days prior to the derailment were reviewed. There were no open faults identified that would suggest the train was operating at increased risk relevant to the derailment sequence. Review of closed faults did not show any recent faults which might have been addressed incorrectly and created increased risk.

Bogies and wheelsets

Bogie overhaul and wheelset records

Review of bogie and wheel set sheets did not identify any areas of concern with the condition of the bogies at the time of overhaul or wheelset change. Assessment of bogie weights at time of overhaul were within specification. Braking components including brake levers and cylinders were within specified dimensions and clamping forces at the time of servicing.

Bogie post-incident overhaul

Overhaul of bogies from ST23 has not identified defects relevant to the derailment. Inspection and overhaul of all bogies was not yet complete at the time of finalising the Interim Report.

Condition of wheels

The last routine wheel measurement indicated flange and rim thickness were within engineering standards.

Wheel profile measurements taken following the incident were compared to the WPR2000 profile specified for these vehicles. No sharp flanges were identified, and profiles were within tolerance and generally close to the WPR2000 profile.

Braking and vigilance systems

Static brake testing and vigilance system

Static brake testing on power car XP2018 was conducted at Auburn, NSW.[80] The purpose of this testing was to determine whether the brakes were degraded prior to the derailment. In preparation for the static brake testing, some of the items damaged during the derailment were repaired and the testing supported by workshop services.[81]

Given the damage sustained by the rollover derailment, the performance of the braking system and the vigilance control system was better than expected. There was no evidence found that the brake system or vigilance control system on XP2018 contributed to the derailment.

Review of maintenance records for braking system

During the (pre) Trip Inspection, the braking system was required to be tested. The test consisted of a functionality check of the braking system including brake pipe pressure, automatic and electro-pneumatic brake function, driver safety system (operator enable handle and pedal) and the vigilance control unit. Sydney Trains was unable to provide brake testing capture sheets from the most recent Level 1 or Level 2 brake testing and advised that the tasks were completed and signed off within the EAM but no paper records were available. The absence of these brake testing sheets prevented a more detailed assessment of the brake condition at the time of these maintenance checks. However, a review of the fault history did not show any known faults.

Additional to the testing, there were no known reports of issues with the braking system during the journey of ST23 prior to the derailment.

Power car XP2018 response to track twist

A twist test on power car XP2018 was conducted at Auburn, NSW. The purpose was to determine this vehicle’s capacity to negotiate track twist. The twist test arrangements were in accordance with the twist (packing) described in RailCorp Standard ESR0001-200 (2013) that represented the standard current at the time of the derailment. For testing, vehicle suspension was retained in its as-derailed condition that included some contained debris, and some suspension damage.

The testing found a maximum wheel unloading of 57.3 per cent, compared to the maximum permissible value of 60 per cent. Given this result, it is unlikely the twist performance of this vehicle contributed to the derailment.

Train radio performance

Post incident function testing and log review

The radio system was function tested and logs reviewed to assess the condition of the radio system just prior to derailment. The train radio system had sustained damage during the derailment and antennas had been removed, resulting in some performance degradation during testing.

Based on results of radio function testing and the review of radio log files, the Sydney Trains specialist maintenance group responsible for the train communications concluded that there was no evidence to suggest that the on-board communications systems were non-operational or defective at the time of the incident.

Assessment of recordings of communication between the train driver and ARTC Network Control were consistent with the train radio system operating normally.

Maintenance records of communications system

The maintenance history for the communication equipment fitted to ST23 was reviewed, with the primary focus being power cars XP2018 and XP2000. The review found that the train radio system was within the required maintenance inspection timeframes and compliant at the time of the derailment. The most recent inspection of communications equipment on XP2018 was completed on 6 February 2020, and on 4 February 2020 for XP2000.

Rolling stock crashworthiness and survivability

Scope

The ATSB conducted crashworthiness and survivability inspections of the lead power car and the five passenger cars. Inspections included an examination of features pertinent to the survivability and evacuation of the train crew and passengers. The unoccupied rear power car remained upright and on track and was not inspected for its crashworthiness.

Inspections were conducted at the derailment site on 21 February. Power car XP2018 and the leading passenger (sleeper) car were further examined at the Auburn UGL facility on 10 March 2020.

Power car XP2018

General findings

Damage to the vehicle’s exterior indicated that the lead power car had slid on its side for some distance (Figure 14). The driver’s cab retained its structural integrity. However, the left-side cab door separated from the door frame, and the left-side engine room door at the rear of the power car was dislodged. Fuel tanks on the left side were also breached.

The car’s forward windscreen remained in place during the derailment. The screen was subsequently removed by rescuers to access the driver’s cab. The lower rear corner of the left-side quarter window had detached from the frame, sufficient to allow a limited amount of ground material into the cab.

Internally within the cab, equipment and fittings remained mostly intact. Instruments, control panels and interior linings contained little or no damage. The driver’s side (left-side) headrest was detached from the seat back.

Figure 14: Power car XP2018 at Auburn workshops 10 March 2020

Power car XP2018 at Auburn workshops 10 March 2020

Source: ATSB

Driver’s left-side cab door

The most significant damage to the power car was to the left cab entry door. The cab door had been secured with two hinges on its rear edge and a single door latch on its forward edge. The glass fibre composite doors were a plug shape and rotated inward on the rear door frame. The hinges were attached to the door and frame using bolts secured to embedded plates (Figure 15).

Figure 15: Door and doorframe section drawing

Door and doorframe section drawing

Source: Commonwealth Engineering (NSW) Drawing 022010940-1 annotated by CITS.

The door hinges had failed as a result of the external loading during the sliding event. The door had become disconnected from the door frame and loose within the cabin. The door-side fingers of the upper hinge had peeled open (Figure 16) and the lower hinge had failed by the loss of fastening on the frame-side of the hinge (Figure 17).

With the door aperture open, the rear of the door frame had acted as a scoop for ballast and dirt which accumulated inside the cab. A significant amount of material was found to have entered the cab space.

ATSB observation

The left cab door of the power car did not withstand the external loading associated with power car 2018 rolling on to its side. This resulted in materials entering the driver’s cab of the power car.

Figure 16: Upper internal hinge of left cab door of XP2018

Upper internal hinge of left cab door of XP2018

Source: ATSB

Figure 17: Lower internal hinge of left cab door of XP2018

Lower internal hinge of left cab door of XP2018

Source: ATSB

Evacuation routes from driver’s cab

The normal access to and from the driver’s cab was through the side doors. At the rear of the cab, there was an internal door to the machinery space and at the rear of that space there were a further two door exits either side of the car, and a rear central door. With the power car on its left side, the right driver’s cab door was the most accessible access route to the cabin and the crew inside. The right driver’s cab door remained operable and was used by members of the crew to gain access to the cab. This access route was only accessible by able bodied people climbing on top of the vehicle and there was no practical way to extricate any survivor if they themselves were not ambulatory.

ATSB observation

With power car XP2018 on its left side, there were no points of entry at or near ground-level.

Rear left door

The rear external machinery space entry door on the left side of the power car had also been dislodged but the top hinge did not fully part from the frame (Figure 18). There was a build-up of ballast and dirt at the base of the door.

Figure 18: The rear left-side door of power car XP2018

The rear left-side door of power car XP2018

The left photograph shows a full view of the rear left-side door of XP2018, and the right photograph the base of the door pushed-in by track ballast and dirt.  
Source: ATSB

Passenger cars

Overview

Inspections did not identify any structures that would have generated injuries by their design. In the lead passenger car, some windows had been shattered introducing a hazard. It was also reported that luggage had fallen from overhead racks, some of which struck passengers and service staff causing injury.

Most injuries to passengers were a result of people being unprepared for the sudden deceleration or losing their balance when their car lurched or tilted. Passenger injuries were more prevalent and more severe in the forward passenger cars.

Passenger car XAM2179 (Car A)

XAM2179 was the leading passenger car and had a cabin/sleeper configuration. It consisted of nine cabins which could seat three passengers each. Some cabins had forward facing seats while others were rear facing. This sleeper car came to rest rolled to about 30 degrees to its left. External damage included four broken exterior windows on the left (passenger aisle) side of the carriage and exterior damage to the roof line above the windows from the passenger car striking pine trees adjacent to the track. The trailing end had also bound with the leading end of the following car, XL2229.

Damage within the sleeper car included collapsed interior lining in the passenger aisle. Two cabins had cracked glass partitions most likely from being struck by luggage or passengers (Figure 19).

Figure 19: Passenger car A, left-side corridor (left) and fractured glass partition (right)

Passenger car A, left-side corridor (left) and fractured glass partition (right)

Source: ATSB

Being the most widely spaced seats in the train, these occupants had the largest free-flight distance available that can lead to more serious injuries. The injuries in this car were most likely the result of passengers being thrown a significant distance before impacting structures and fittings. Injuries occurred to people sitting in both forward- and rearward-facing seats.

Passenger car XL2229 (Car B)

This was a first-class car with 56 forward-facing passenger seats in a single open cabin. It was seating an estimated 52 people at the time of the derailment. It was the car with the most reported injuries and the most reported serious injuries. The injuries were most likely the result of passengers being thrown from their seats or being hit by luggage falling from the overhead racks. The car came to rest at an angle of approximately 17 degrees to its right.

There was no evidence of structural failure or dislodged internal fittings acting as projectiles. The only significant damage to the cabin was exterior binding at the front right corner with the car ahead, Car XAM2179. This prevented the use of the exits at this location.

Passenger car XBR2155 (Car C)

This car was half first-class forward-facing seating with the other half being the buffet section. It was near upright when it came to a stop. The car suffered no interior damage of consequence.

Passenger car XF2201 (Car D)

This was an economy-class car with 68 forward facing passenger seats in a single open cabin. It was the most heavily populated car in the set with an estimated 57 passengers in this car at the time of the derailment. Comparatively fewer injuries were reported in this car. It was near upright when it came to a stop. The car suffered no interior damage of consequence.

Passenger car XFH2108 (Car G)

This car was half economy class forward facing seating with the other half being the baggage section. The baggage section was locked meaning there was only one pair of exits (forward) immediately obvious to passengers. A key to the baggage compartment was available behind breakable glass. This would have permitted a second set of exits to be used through the baggage compartment, however in this instance these rear exits were not used. This car was at an angle of about 10 degrees when it came to a stop and had the least number of reported injuries and the lowest injury rate. The car suffered no interior damage of consequence.

Evacuation routes from passenger cars

The majority of exits in passenger cars were available. Six of the 18 exits for passengers could be considered freely available. A further eight exits were operable and available but with some hindrance to their free use due to the distance from the ground, the angle of the access ladder, or some other hazard. Four exits were deemed not to be available, either due to obstruction, jamming or excessive height off the ground.[82]

Most people reported, and general evidence suggests, that the majority of passengers were able to evacuate without or with limited assistance. Some special needs passengers were assisted out of the carriages.

While not obstructing the evacuation, the angle of two carriages slowed some people getting off. The longitudinal angle of most cars was negligible, however the lateral angle (roll) of the front two passenger cars was significant.

Passenger information

Passenger numbers and injuries

Based on information supplied by the rail operator and Victoria Police, the total number of passengers on board ST23 at the time of the derailment was 155.[83]

Available injury information from the operator and police was combined with ATSB passenger survey response data to estimate a total number of passenger physical injuries of 61.[84] ,[85] This total figure was comprised of 8 serious injuries and 53 minor injuries.<[86]

Passenger survey

Overview

The ATSB conducted a survey of passengers that were aboard train ST23 at the time of the derailment. From 155 passengers reported to be on board, 83 responses to the survey were received: a response rate of 54 per cent. The survey included questions on:

  • passenger demographics
  • passenger seating location
  • safety information and briefings
  • experiences during and after the event
  • the nature of injuries.
Safety information

On questions pertaining to safety information:

  • Seventy per cent of passengers who responded to the question about the provision of safety information reported that they either did not receive any safety information or could not recall receiving any.
  • Of the 63 responses about the format of the safety information provided, eight passengers reported that they received the information from a briefing card.
  • Of the 74 responses to a question related to paying attention to the safety information provided, 57 per cent of passengers reported that they did not pay attention. Some passengers mentioned that the reason for not paying attention was that there was no information provided.
  • Seventy per cent of survey respondents reported that, prior to the event, they did not know how to get out of the train in an emergency.

In response to questions on suggestions for improvement in safety information:

  • Ten passengers referred to the way in which safety information is provided by airlines.
  • Some passengers mentioned that better signage on the seat in front of them or at the end of carriages may have been helpful.
  • Other comments included increasing announcements.
The evacuation

There were varied responses about the communication received from crew members following the derailment. This was at least in part due to the distribution of the crew, with four of the five crew being in the buffet car at the time of the derailment. There were no crew members in three of the cars at the time of the derailment. Most of the passengers who responded advised that initial crew instructions were to remain on board the train. Others reported being unsure about what to do. There was no report of any announcements being made via the public address system or the use of loud hailers.

Responses indicated that some passengers self-evacuated before receiving instructions from the crew. Passengers were asked to estimate how long it took to exit the train. The responses ranged from a ‘few minutes’ to up to 30 minutes, supporting other evidence that some passengers self-evacuated prior to being instructed by train crew. About half of the respondents indicated having difficulty exiting the train due to carriage orientation and/or difficulty with getting down to the ground.

Once passengers were out of the train, crew members were observed instructing passengers to move off the adjacent tracks (due to concern of possible rail traffic).

In response to questions on areas for improvement in emergency response, suggestions included:

  • a greater number of staff members to manage an emergency
  • crew training in emergency management
  • leadership and direction, including more information being provided to passengers
  • consistency in the information provided.

Sixteen respondents utilised the free text question to provide praise for the handling of the event by members of the train crew and first responders.

__________

  1. A NSW Government agency constituted by the Transport Administration Act 1988 Part 1A Section 3C.</li
  2. Health and fitness requirements for Rail Transport Operators and Rail Safety Workers were governed by the Rail Safety National Law (RSNL) and associated Regulations.
  3. Due to the delay in the service on this day, arrival in Melbourne would have been significantly later than the rostered end-of-shift.
  4. Detailed work-placement records were available from 2014.
  5. Sydney Trains is an agency of Transport for NSW.
  6. ARTC is a statutory corporation fully owned by the Government of Australia.
  7. Standard-gauge trains did not stop at Wallan.
  8. TA20 ARTC Code of Practice for the Victorian Main Line Operations, Section 2, Rule 13 g.
  9. As recorded in the PTV Pass Assets database, viewed 26 October 2020
  10. A small superelevation of 8 mm was recorded at the commencement of the right-hand curve by the track recording vehicle in August 2019, indicating the left hand rail slightly higher than the right-hand rail in the ‘Up’ (towards Melbourne) direction.
  11. The indication of this signal at the time ST23 passed is not known with certainty, because its state was not recorded. However, broad-gauge rail traffic records indicate that the signal was more likely to be at Proceed. If not at Proceed, the signal would have been at its alternate ‘Caution’ indication, a single yellow light.
  12. 13.7 km from Wallan Railway Station
  13. Azimuth is the clockwise horizontal angle (in degrees minutes and seconds) from true north to the sun.
  14. Altitude is the vertical angle (in degrees minutes and seconds) from an ideal horizon, to the sun. An ideal horizon exists when the surface forming the horizon is at a right angle to the vertical line passing through the observer's position on the earth. If the terrain surrounding the observer was flat and all at the same height above sea level, the horizon seen by the observer standing on the earth would approximate the ideal horizon.
  15. Computed using National Mapping Division's sunmoonposn program, version 1.1.
  16. RISSB Glossary of Terms, viewed 30 March 2020 <https://www.rissb.com.au/glossary/>
  17. At the time of the derailment, Issue 2.1, 01 July 2018
  18. A Safety Management System provides a systemic approach to managing safety risks and includes, amongst other items, codes, policies, standards, procedures and documents.
  19. The CTC system was described in section 17 of TA20 and the Train Order System in section 18.
  20. Rule 1, Section 3 specified proceeding at a speed not exceeding 25 km/h.
  21. The scope of application of Train Authorities was similar for the Train Order System.
  22. The phrase ‘Train Authority Working’ is used in section 25 of TA20.
  23. The first Train Authority was issued at 2042 on 6 February 2020.
  24. ActivateRail describes itself as a rail interface solutions business, formed from the specialist rail project services arm of Sterling Infrastructure. It offers professional advisory services, project managers as well as worksite supervisors, site managers and track safety personnel.
  25. ARG Rail provided labour and recruitment services to the rail infrastructure sector.
  26. Issued because the Wallan-Whittlesea level crossing protection was being manually operated.
  27. TN266 specified that the signaller would deliver the Train Authority and CAN to the driver, although in practice this was done via the AQW. On one occasion (Train Authority number 20 on 14 February 2020), the driver requested that the signaller give him the Train Authority directly rather than via the AQW and the signaller complied with this request.
  28. On this point, the practice of drivers varied. During the period that Train Authority working was being used between Kilmore East and Donnybrook, on 30 occasions out of the 253 Train Authorities issued, the driver ‘repeated back’ the contents of the TA, and had that repeat back verified by the ARTC network controller.
  29. This section is limited to a brief account of notice TN266 and its amendments. The section does not include detail of the distribution of the notice, nor the receipt of the notice or awareness of its information by organisations or individuals.
  30. TA20, Section 5, Rule 5.
  31. TA20 Section 5 Rule 5 Clause b stated ‘Light signals not in use are distinguished by a black cross on the front of the lights. The lamps are not to be lit’.
  32. Some V/Line drivers and the RTBU (Rail Tram and Bus Union) had expressed concern at signals remaining lit within the affected section. On 10 February, a driver refused to pass a lit signal within the section.
  33. This section is limited to a brief account of notice TN367. The section does not include detail of the distribution of the notice, nor the receipt of the notice or awareness of its information by organisations or individuals.
  34. There is no available evidence with respect to the communications between the driver and the AQW.
  35. r RSK-PR-001 Risk Management, version 1.4, 5 April 2019.
  36. Approximate time of risk assessment advised by ARTC
  37. The risk assessment reference to ‘piloted’ is different to TN266 that refers to an Accompanying Qualified Worker.
  38. Preparation and Distribution of Operational Notices OPE-PR-001, Version Number 1.2, 31 May 2019
  39. http://webrams.artc.com.au/
  40. In procedure OPE-PR-001, the acronym NRAMS was used.
  41. Australian Central Standard Time
  42. Adelaide time
  43. The WON was published by the Office of Rail Safety Manager (a part of MTM) on behalf of MTM and V/Line.
  44. No. 7 points were controlled by a dual-control point machine. They could be operated in motor (remote operation) or hand (manual operation) mode.
  45. An average wheel diameter is used to accommodate wear and a reducing diameter during the wheel’s life.
  46. The ICE radio GPS speed is not displayed to the driver in the locomotive cab.
  47. The speed display on XP2018 would have been reading about 127 km/h.
  48. To reduce train speed from 130 km/h to 15 km/h at the turnout would require braking at least 800 m before the turnout.
  49. ARTC Route Access Standard D53.
  50. Actual speed calculated by correcting the recorded speed for actual wheel diameter. The recorded speed was about 2 per cent lower than the estimated actual.
  51. AS 7527:2015 (amendment 2019) Legacy, tape based data loggers should, as a minimum record the following information that included train speed, distance, time, and brake status (i.e. brake pipe pressure or brake cylinder pressure).
  52. Static testing was conducted on XP2018 as the trailer cars immediately behind in the consist were damaged and without significant repairs could not be tested. The main areas of focus were the driver control aspects of XP2018.
  53. During the derailment and subsequent rollover, some pneumatic equipment was dislodged from the power car or damaged, while other equipment remained intact. In preparation for the static brake testing, approval was provided to Sydney Trains to repair some of the items damaged during the derailment in preparation for the test to be undertaken.
  54. Considered not usable in cases where the bottom rung of ladder was more than 1.5 m from the ground
  55. Based on available information.
  56. Some passenger information was incomplete, and this reported data represents a summary of available information.
  57. There were also reports of psychological impacts including instances of post-traumatic stress disorder (PTSD) that are not included in the injury total.
  58. A serious injury is an injury that required, or would usually require, admission to hospital within 7 days of the event.

Safety actions

Australian Rail Track Corporation

ARTC advised[87] that, since the incident, it had taken the following steps to improve the safety of its operations, that are relevant to two ATSB Observations:[88]

  1. ARTC has developed an amendment to TA20 to facilitate an “Alternative Proceed Authority”. Once implemented, TA20 will provide for a new form of safeworking, similar to Train Authority Working, that can be implemented in circumstances where Centralised Traffic Control (CTC) is not operational for an extended period of time. The proposed amendment to TA20 has been the subject of initial user consultation including internal briefing sessions with operational areas within ARTC’s business and external briefing sessions with rail operators. A Human Factors assessment is scheduled to be undertaken in relation to the proposed amendment in Quarter 4 of Calendar Year 2021. The proposed amendment will then be subject to further formal stakeholder consultation and ARTC’s management of change processes prior to implementation.
  2. ARTC is developing a new risk assessment tool for abnormal circumstances, to be known as an Event Flow Work Tool, with a focus on risk scoring and authority escalation requirements. A prototype has been developed and is to be further work shopped with Network Controllers prior to implementation.
  3. Until the steps referred to in 1) and 2) above have been completed, ARTC has implemented an interim requirement that the implementation of any altered method of safeworking, other than Caution Orders, requires a formal Risk Assessment and approval by ARTC’s Executive Risk Committee.
  4. ARTC has developed an amendment to TA20 to include a new rule titled “Train Notices”. Once implemented, the new rule will clarify the manner and circumstances in which the operation of TA20 may be amended through the issue of Train Notices. Implementation of the new rule is subject to consultation wit

NSW Trains

NSW Trains advised[89] that, since the incident, it had undertaken a number of safety actions. Safety actions taken included:

  1. The development of new procedures for the daily access of the ARTC WebRams system
  2. Amendment of procedures to include confirmation of receipt of safety critical information by train crew prior to them starting their day of operations
  3. Additional resources to ensure that NSW Trains has 24/7 frontline leader coverage across the network
  4. The review of interface agreement risks from all rail infrastructure managers (RIMs) to identify and assess NSW Trains' systems and procedures for managing interface safety risks with the relevant RIMs
  5. A range of initiatives to enhance safety critical communications including:
    • the development of a new program to strengthen safety critical communication across NSW Trains (TrainLink) rail safety workers
    • international benchmarking against safety critical communication systems used by other rail operators
    • risk workshops with key internal and external stakeholders to identify opportunities to strengthen safety critical communications
    • the development of a business case for future digital solutions for safety critical communications.
      ____________
  6. 22 April 2021
  7. ATSB Observations: • The use of Train Authorities in the circumstances that were present through Wallan in February 2020 was not provided for in the ARTC Code of Practice for Main Line Operations (TA20) • Formal risk assessment was not used to identify hazards and available risk controls to manage the risk associated with train overspeed at the entry to Wallan Loop.
  8. 22 April 2021

Ongoing investigation

The investigation is continuing and will include further consideration of the following:

  • management of train operations, including implementation of altered train working, risk management and communications
  • distribution of safety critical operational information
  • train operations and further human factors analysis
  • survivability and crashworthiness standards relevant to this type of event
  • finalisation of derailment sequence analysis
  • finalisation of rolling stock and track condition assessments
  • passenger services crew training and preparedness for a derailment event
  • passenger safety information
  • similar occurrences.

Relevant parties are notified of critical safety information identified during the course of the investigation so that appropriate and timely safety action can be taken.

A final report will be released at the conclusion of the investigation.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2021

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 03/04/2020

The information contained in this report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this update. As such, no analysis or findings are included in this report.

The occurrence

On 20 February 2020, passenger train XPT ST23 departed Central Station in Sydney, New South Wales (NSW), at about the scheduled departure time of 0740.[1] The service was scheduled to stop at several stations en-route to its final destination at Southern Cross Station in Melbourne, Victoria that evening at 1830 (Figure 1).

Figure 1: Train route from Sydney to Melbourne

Figure 1: Train route from Sydney to Melbourne.&#13;Source: Google Maps, annotated by Chief Investigator, Transport Safety

Source: Google Maps, annotated by Chief Investigator, Transport Safety

The train proceeded south and arrived at Junee in southern NSW at 1452,[2] about 85 minutes behind schedule. At Junee there was a change of driver before the train continued south, arriving in Albury on the NSW-Victorian border at 1637, still about 85 minutes behind schedule. There was a change in passenger car crew at Albury.

The train departed Albury at 1644 and entered the Victorian section of its journey. The service continued south, stopping at several stations before coming to a stand at Intermediate Home[3] signal KME28 at Kilmore East, at about 1856. Signal KME28 was at Stop, and the driver contacted Network Control at about 1904 to inquire when he might receive permission to proceed. There was a standard-gauge passing lane at Kilmore East, with East and West Lines (Figure 2).[4]

Figure 2: Kilmore East passing lane (standard-gauge track shown in black, with signals)

Figure 2: Kilmore East passing lane (standard-gauge track shown in black, with signals).&#13;Source: ARTC, modified and annotated by Chief Investigator, Transport Safety

Source: ARTC, modified and annotated by Chief Investigator, Transport Safety

The XPT waited at signal KME28 on the East Line until the north-bound V/line passenger train 8625 had transited the Donnybrook to Kilmore East single-line section, passed signal KME2 and was travelling along the West Line through Kilmore East. The V/Line train was clear of the single-line by about 1925 and, soon after, the XPT was given permission by Network Control[5] to proceed to Home Departure signal KME16,[6] still on the East Line within the Kilmore East location.

As a result of damage to signalling equipment, a 24 km section from Kilmore East signal KME16 (at about the 63.8 km mark)[7] to Donnybrook (at about the 40.2 km mark) was being managed using an alternative safeworking system.[8] Wallan was located in this section, about 48 rail-km from Melbourne.

At signal KME16, XPT ST23 was met by several rail workers, including a Signaller and an Accompanying Qualified Worker (AQW).[9] The AQW boarded the lead power car and joined the driver at the head of the train as part of the alternative safeworking system in place for the 24 km section to Donnybrook.

At about 1932 while the train was still stopped at signal KME16, the driver and the Network Control Officer communicated over the radio about the Train Authority[10] for the section through to Donnybrook. The train then departed signal KME16 and entered the single-line towards Wallan. The line speed for the XPT in this section was 130 km/h and after departing, the speed of the train was increased towards this line speed.

One function of the AQW was to ensure that the level crossing protection[11] at Wallan–Whittlesea Road in Wallan was in place for the passage of the train.[12] The Level Crossing Keeper[13] positioned at this level crossing reported receiving a call from the AQW and activating the crossing protection.

The train was now approaching Wallan. Earlier that afternoon, the points at either end of Wallan Loop had been changed from their Normal position to their Reverse position.[14] This change meant that rail traffic, in both directions, would be diverted from the Main Line (straight) into the loop track (No.2 Road). A Train Notice[15] reflected this change and also specified a 15 km/h speed limit for entry into the loop, and a limit of 35 km/h for exiting the loop.

At about 1943, XPT ST23 was approaching the northern end of Wallan Loop at about the track’s line speed. Recordings from the train indicate an Emergency brake application a short distance before the points. This slowed the train a small amount before it entered the turnout travelling at a speed in excess of 100 km/h. The train was not able to negotiate the turnout to the loop track at this speed and derailed. All vehicles derailed excepting the rear power car (Figure 3).

Figure 3: Aerial photograph of derailment site

Figure 3: Aerial photograph of derailment site.&#13;Source: ATSB

Source: ATSB

During the derailment sequence, the leading power car rolled onto its left side and the XPT driver and the AQW sustained fatal injuries. Three passengers were seriously injured and 36 received minor injuries.[16] Five train crew that were in the passenger cars also sustained injuries.

Context

Track information

The XPT service was running on the national standard-gauge track that connects Sydney and Melbourne. The track is part of the Defined Interstate Rail Network (DIRN) and is managed by the Australian Rail Track Corporation (ARTC).[17]

The standard-gauge track between Kilmore East and Donnybrook was a single, bi-directional line that serviced the XPT, V/Line passenger services and rail freight. There were passing lanes at Kilmore East and Donnybrook and a 1,550 m crossing loop at Wallan. The northern entry to this loop was located about 1.8 km north of Wallan–Whittlesea Road (Figure 4).

Figure 4: Wallan Loop (standard-gauge track shown in black, with signals)

Figure 4: Wallan Loop (standard-gauge track shown in black, with signals).&#13;Source: ARTC, modified and annotated by Chief Investigator, Transport Safety

Source: ARTC, modified and annotated by Chief Investigator, Transport Safety

Train information

The first XPT (Express Passenger Train) commenced service in 1982. The XPT fleet is operated by NSW TrainLink[18] and provides passenger services in regional NSW and between the east coast capital cities of Melbourne, Sydney and Brisbane. XPT vehicles are maintained by Sydney Trains[19].

The XPT ST23 running on 20 February 2020 included five passenger cars (Figure 5). The leading three vehicles were manufactured by ABB Transportation in Dandenong, Victoria and commissioned in 1993. The trailing four vehicles were manufactured by Comeng in Granville, NSW and commissioned between 1981 and 1984.

Figure 5: Train configuration

Figure 5: Train configuration.&#13;Source: ATSB, vehicle images supplied by Sydney Trains

Source: ATSB, vehicle images supplied by Sydney Trains

Train data logger

Both power cars were fitted with a Hasler RT data logger. The data logger is an electro-mechanical device that records speed, distance, time, a combined power-vigilance parameter, and brake cylinder pressure parameters. These parameters are recorded on a waxed paper tape (roll). The Hasler system also included an analogue speedometer located on the driver’s console.

The train’s speed is derived from the measurement of the rotation of the left hand wheel on the second axle of the power car. In order for this rotation to be translated into distance (and speed), an average wheel diameter is assumed. Actual speed may deviate from that recorded (and displayed) due to differences between this assumed diameter and the diameter of the actual wheel providing the feed to the Hasler system.

The Hasler tapes from the two power cars were recovered at the accident scene and examined by the ATSB. Corrections to the recorded speed were made to account for the differences between the assumed wheel diameter and the actual wheel diameter on each power car. The results from both recorders indicated a speed of about 130 km/h approaching Wallan Loop.[20] The Hasler analogue speedometer would have read less than this, probably between the 125 km/h and 130 km/h marks.[21]

The data from both recorders indicate that there was an Emergency brake application nearing the turnout to the loop, and an associated small reduction in speed prior to the train entering the loop. The Hasler recordings will be the subject of further detailed analysis and review against other evidence.

Train crew and passengers

The XPT is a single-driver operation. The driver of the XPT was designated as a Regional Driver, and at the time of the derailment, an AQW was also in the driver’s cab. Both the driver and AQW suffered fatal injuries in the derailment.

Within the passenger vehicles, there were five further crew members including a Passenger Service Supervisor, Senior Passenger Attendant and three Passenger Attendants. All five have reported injuries.

There were 153 passengers recorded as being on the train at the time of the derailment, of which 39[22] have reported injuries.

Management of rail traffic (safeworking)

Safeworking is an integrated system of operating rules and procedures that defines the interaction between workers and engineered systems for the safe operation of a railway.[23] Of primary concern is safe operations including train separation and speed management according to infrastructure.

Relevant to this occurrence, the signalling infrastructure used for standard-gauge traffic through Wallan was damaged as a result of a fire in a track-side equipment hut on 3 February 2020. From 6 February, Train Authority Working was established to manage traffic between Home Departure signals DBK6 and DBK18 at Donnybrook[24] and KME4 and KME16 at Kilmore East.[25] The alternative safeworking arrangements permitted only one train in the section between Donnybrook and Kilmore East at any one time, and Wallan Loop was not being used for trains to cross or pass. From the commencement of Train Authority Working on 6 February, Wallan Loop was configured for trains to travel along No.1 Road.[26] This changed to the No.2 Road on 20 February.

Further investigation

The areas explored and requiring further investigation include:

  • Derailment sequence: Further investigation will include a detailed examination and review of available evidence to refine the derailment sequence.
  • Track condition: To date, site observations and preliminary review of track data have not identified adverse conditions directly contributing to the derailment. Further investigation will include the detailed examination of post- and pre-occurrence track geometry and maintenance information.
  • Rolling Stock condition: To date, site observations and vehicle workshop inspections (that commenced 6 March) have not identified adverse conditions directly contributing to the derailment. Inspections are ongoing and include detailed inspection of vehicles and testing of braking and driver safety systems.
  • Crew and passenger survivability: Detailed survivability inspection of the leading power car XP2018 and all passenger vehicles is complete. A passenger survey is being conducted researching passenger experiences of the derailment and subsequent evacuation and emergency response.
  • Train operation: Further investigation will include a detailed examination of the operation of the train drawing on a wide range of evidence sources.
  • Management of train operations: Further investigation will include a detailed examination of the alternative safeworking systems used to manage rail traffic at this location from 6 to 20 February 2020.
  • Other areas of investigation: Further areas of investigation may be identified as the investigation progresses.

Acknowledgements

The ATSB would like to acknowledge the significant assistance provided by all involved parties during the initial investigation, particularly in the context of the impact of COVID-19 on business operations and the community.

Train details

Train operator:NSW TrainLink  
Persons on board:Crew: 6 +1Passengers: 153[27]
Fatalities:Crew: 1+1Passengers: 0
Other Injuries:[28]Crew: 5Passengers: 39
Damage:Substantial, to train and track 

__________

The information contained in this report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this update. As such, no analysis or findings are included in this report.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. All times are Australian Eastern Daylight Time (AEDT).
  2. Stopping times at stations are as recorded by NSW TrainLink.
  3. This signal protected the broad-gauge crossover going into the Apex ballast quarry. It is called an ‘Intermediate Home’ because it is in an intermediate location along the passing lane.
  4. The passing lane was about 7 km in length.
  5. ARTC network control for this section of track is located at Junee, NSW.
  6. This Home Departure signal was protecting the turnout at the end of the passing lane.
  7. Rail-km from Melbourne.
  8. Safeworking is described in this report at section, Management of rail traffic (safeworking).
  9. The term used in Train Notices for the worker that would accompany the driver between Kilmore East and Donnybrook.
  10. An instruction in the prescribed format issued by the Network Control Officer in connection with the movement of a train. RISSB Glossary of Terms, viewed 30 March 2020, <www.rissb.com.au/glossary>.
  11. Boom barriers and flashing lights at this location.
  12. Active protection on the other level crossings on the Kilmore East-to-Donnybrook section were working normally and it was only the Wallan-Whittlesea Road level crossing that required local operation.
  13. The person who activated the level crossing protection locally at the crossing, colloquially referred to as the bellhop.
  14. The Normal position of the turnouts was for ‘straight-through’ traffic, and the Reverse position was for the loop.
  15. Operational information issued by or on behalf of the Rail Infrastructure Manager. RISSB Glossary of Terms, viewed 30 March 2020,<www.rissb.com.au/glossary>
  16. Injury information accounts for physical injuries and does not include non-physical injury or distress.
  17. ARTC is a statutory corporation fully owned by the Government of Australia.
  18. The brand name of NSW Trains, an agency of Transport for NSW.
  19. Sydney Trains maintains trains on behalf of NSW Trains through a service agreement. Sydney Trains is an agency of Transport for NSW.
  20. The results of the interim analysis. Further analysis will be undertaken and reviewed against other evidence sources.
  21. This difference is because the actual wheel diameter was greater than that used as input to the Hasler system.
  22. This figure may be updated during the investigation.
  23. RISSB Glossary of Terms, viewed 30 March 2020 <www.rissb.com.au/glossary>
  24. DBK6 and DBK18 were at a similar km location at Donnybrook, servicing the West Line and East Line respectively.
  25. KME4 and KME16 were at the same km location at Kilmore East, servicing the West Line and East Line respectively.
  26. Utilising manual operation and clipping of the points.
  27. The number of passengers on board at the time of the derailment may be updated during the investigation.
  28. Injury data may be updated during the investigation.

Occurrence summary

Investigation number RO-2020-002
Occurrence date 20/02/2020
Location Wallan
State Victoria
Report release date 09/08/2023
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Accident
Highest injury level Fatal

Train details

Train operator NSW TrainLink
Train number ST23
Type of operation Passenger Service
Departure point Sydney, New South Wales
Destination Melbourne, Victoria
Train damage Substantial

Operational non-compliance involving Airbus A380, 9V-SKQ, near Sydney Airport, New South Wales, on 9 February 2020

Final report

Report release date: 07/04/2021

Safety summary

What happened

On 9 February 2020, an Airbus A380 aircraft, registered 9V-SKQ was being operated by Singapore Airlines on a scheduled passenger service from Singapore to Sydney, New South Wales.

During the approach to runway 16 right at Sydney, the aircraft encountered windshear and in response, the flight crew commenced the windshear recovery procedure and missed approach. During this time, air traffic control (ATC) instructed the flight crew to turn right onto a heading of 270°. The flight crew read back the heading, however, did not include the direction of the turn. Air traffic control did not correct the incomplete readback and the flight crew commenced turning the aircraft left instead of right.

Air traffic control issued a safety alert to the flight crew, advised them of a Bombardier DHC-8 aircraft about 6 NM (11 km) on final for runway 16 left, and instructed them to turn right and climb immediately. Air traffic control then instructed the flight crew of the DHC-8 to make a right turn in order to maintain separation with the A380. This resulted in a loss of separation between the DHC-8 and a Boeing 737 aircraft on approach to runway 16 right.

What the ATSB found

The ATSB found that the flight crew were likely experiencing high workload as a result of conducting the windshear recovery and published missed approach procedure. This, in combination with an expectation that they would be turning left, contributed to them mishearing the ATC instruction to turn right. As a result, the aircraft was turned left. In addition, the flight crew omitted information from their readback and ATC did not correct the flight crew’s incomplete readback, which was a missed opportunity to correct the misheard instruction.

What has been done as a result

Singapore Airlines issued a notice to flight crew, highlighting strategies to manage high workload situations, as well as reiterating the importance of correct readbacks and acknowledgement from ATC.

Safety message

Compliance with ATC published procedures, such as readback procedures, provides assurance that instructions are correctly understood, which is especially important during high workload periods and/or in times of high traffic density. This incident highlights the importance of flight crew completing full readbacks, as well as controllers correcting any readback discrepancies immediately. The ATSB’s aviation research and analysis report Radiotelephony Readback Compliance and its Relationship to Surface Movement Control Frequency Congestion (20060053) provides further information regarding readback compliance.

 

The investigation

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

On the morning of 9 February 2020, an Airbus A380 aircraft, registered 9V-SKQ, was being operated by Singapore Airlines, on a scheduled passenger service from Singapore to Sydney, New South Wales. The captain was the pilot flying and the first officer (FO) was the pilot monitoring.[1] Prior to, and during the flight, the flight crew had noted the deteriorating weather conditions in Sydney and briefed on conducting a missed approach, following the published missed approach procedure.

On arrival at Sydney, the flight crew was cleared by air traffic control (ATC) for an instrument landing system[2] approach to runway 16 right (16R). At about 1122 Eastern Daylight-saving Time,[3] while on approach and descending through about 1,000 ft, the A380 encountered windshear. The flight crew actioned the windshear recovery procedure and in response, commenced a missed approach, which included applying take‑off/go‑around thrust, flaps extended and a rate of climb of 3,000 ft per minute. At 1123:00, the flight crew advised ATC that they were ‘going around due to windshear’. Air traffic control acknowledged the flight crew and at 1123:29, ATC instructed them to turn right onto a heading of 270° and to maintain 3,000 ft.

The FO gave an incomplete readback of the instruction, omitting the direction of the turn. Air traffic control did not correct the incomplete readback.

The flight crew believed that they heard ATC instruct them to turn left. They were also expecting ATC to issue instructions to turn left, once they had completed the published missed approach procedure, to avoid significant weather and aircraft traffic to the west of Sydney. The flight crew therefore commenced turning the aircraft left, crossing the approach path of the parallel runway (runway 16 left (16L)).

Air traffic control noticed the aircraft turning in the opposite direction to the instruction and 30 seconds after issuing the turn instruction, queried the flight crew as to whether the aircraft was turning right. The FO responded that the aircraft was not turning right. During this time, ATC had continuous communications with another aircraft. At 1124:17, ATC instructed the flight crew to turn the aircraft onto a heading of 060° and 19 seconds later, issued a safety alert. The safety alert advised the flight crew about a Bombardier DHC-8 aircraft in their 12 o’clock position,[4] bout 6 NM (11 km) away and on approach to runway 16L. At 1124:40, ATC instructed the flight crew of the DHC-8 to make a right turn in order to maintain separation with the A380. This subsequently resulted in a loss of separation [5] between the DHC-8 and a Boeing 737 aircraft on approach to runway 16R. The minimum distance between the two aircraft reduced to 2.6 NM (4.8 km) laterally and 1,300 ft vertically. Figure 1 shows the representative aircraft tracks at the time of the incident.

Figure 1: Aircraft tracks at the time of incident

Figure 1: Aircraft tracks at the time of incident

Source: Google Earth, modified by the ATSB

Context

Weather

The Sydney Airport automatic terminal information service [6] issued at 1118 and current at the time of the incident, reported wind from an east-south-easterly direction at 20-40 kt, with a maximum crosswind of 29 kt. There was rain present, and a warning for windshear and turbulence on final approach was also current. A previous automatic terminal information service stated that severe windshear had been reported on final approach for runway 16R by the flight crew of another aircraft.

The Bureau of Meteorology[7] defines windshear as ‘a wind direction and/or speed change over a vertical or horizontal distance. It is significant when it causes changes to an aircraft’s headwind or tailwind such that the aircraft is abruptly displaced from its intended flight path and substantial control action is required to correct it’. Although windshear can occur at any level, windshear below 2,000 ft can be particularly problematic to aircraft approaching stall [8] speeds, predominantly seen in the take-off, initial climb, approach or landing phases of flight. This is even more so the case in larger jets, where there is a significant lag between applying and achieving thrust.

Aircraft operations

Published missed approach procedure

A missed approach procedure is to be followed if an approach to land cannot safely continue. It specifies a point where the missed approach begins, and a point or an altitude where it ends. In this case, the missed approach procedure was to initially track on a heading of 155°, when at 600 ft above mean sea level turn right onto a track of 170° and climb to 3,000 ft, or as directed by ATC.

Windshear recovery procedure

A windshear recovery procedure is an operational abnormal manoeuvre used by flight crew to escape a windshear encounter. The Singapore Airlines recovery procedure involved applying take-off/go-around thrust and following the speed reference system until the aircraft was clear of windshear. Such manoeuvres are high in workload due to their dynamic nature, increasing an already high workload of the approach phase of flight.

Air traffic services

Summary of radio calls

The table below (Table 1) summarises the radio calls made by the flight crew of 9V-SKQ (Singapore 231) and ATC.

Table 1: Summary of radio calls

Time (local)CallerSummary
1123:00Singapore 231Singapore 231 communicate they are going around due to windshear
1123:02ATCATC acknowledge the intentions of Singapore 231
1123:29ATCATC instruct Singapore 231 turn right on a heading of 270°, maintaining 3,000 ft
1123:36Singapore 231Singapore 231 reads back the heading and altitude, but omits the direction of the turn
1123:41ATC/Other aircraftContinuous communications between ATC and another aircraft
1123:59ATCATC contact Singapore 231 to confirm turning right on a heading of 270°
1124:03Singapore 231Singapore 231 respond ‘ah negative’
1124:12Singapore 231Singapore 231 request heading from ATC
1124:17ATCATC instruct Singapore 231 to continue flying on a heading of 060°
1124:24Singapore 231Singapore 231 confirm heading
1124:36ATCATC issue ‘safety alert’, advising Singapore 231 of traffic on final and issue instructions to turn immediately on a heading of 060°
1124:45Singapore 231Singapore 231 confirm turning immediately
1124:51ATCATC instructs Singapore 231 to climb immediately to 5,000 ft
1124:55Singapore 231Singapore 231 confirm 5,000 ft
Readbacks

A readback is a procedure whereby the receiver of a message repeats the message or an appropriate part thereof back to the transmitter, in order to obtain confirmation of correct reception and compliance. In aviation, flight crew are required to read back to ATC, safety-related parts of ATC clearances and instructions that are transmitted by voice. These items include, but are not limited to, altitude, direction of turn, heading and speed instructions. Specifically, the Airservices Australia Aeronautical Information Publication, section GEN 4.4, stated that this should include level instructions, direction of turn, heading and speed instructions. In response, the controller will listen to the readback to ascertain that the clearance or instruction has been correctly acknowledged and will take immediate action to correct any discrepancies revealed by the readback.

Safety alert

The Airservices Australia and Department of Defence Manual of Air Traffic Services stated that, ATC will issue a safety alert to flight crew when they become aware that an aircraft is in a position that is considered to place it in unsafe proximity to other aircraft. This is to notify pilots of information that is of a time-sensitive and safety-critical nature. It is important pilots understand the critical nature of these instructions and respond in a timely manner to ensure the safe conduct of flight.

Separation standards

Separation standards are used by ATC to manage air traffic safely. They refer to the minimum horizontal and/or vertical distance, or time apart, that aircraft operating in controlled airspace must maintain. When the separation between two or more aircraft is less than the standard, there is a loss of separation event.

A surveillance separation standard is used when aircraft position information is derived from air traffic services’ surveillance systems (including radar). The Manual of Air Traffic Services stated that, for two aircraft on independent parallel visual approaches, the required separation was 3 NM (5.6 km) horizontally or 1,000 ft vertically. However, Airservices Australia advised that, in accordance with section 9.7.5.2 of the manual, when determining whether an aircraft has passed a level on descent, a 400 ft tolerance was required to be made to the aircraft’s altitude shown on the controller’s situation display. Based on the 400 ft tolerance, a loss of separation occurred when the Boeing 737 and DHC-8 were within 3 NM laterally and less than 1,400 ft vertically.     

Analysis

Workload and misheard instruction

Workload is considered to be ‘the relation between the function relating the mental resources demanded by a task and those resources supplied by the human operator’.[9] Considering the amount of information flight crew can deal with at any one time is limited, particularly during high workload phases of flight, it is possible to exceed individual processing capacity,[10] increasing the risk of errors.

The approach phase of flight is associated with high workload for flight crew during normal operations. The flight crew of the A380 were experiencing a significantly higher level of workload than what is typically experienced during a normal approach, due to the weather and conducting a windshear recovery procedure, following the published missed approach procedure for runway 16R at Sydney. This involved managing a high-energy aircraft state, which included applying take‑off/go‑around thrust, flaps extended, and a rate of climb of 3,000 ft per minute. In addition, the published missed approach requirement for runway 16R at Sydney to level off at 3,000 ft, requiring the flight crew to the reconfigure the aircraft in under a minute. The flight crew also did not expect to receive an instruction from ATC before completing the published missed approach procedure and the instruction to turn right was contrary to their expectations. This, combined with significantly increased workload, likely contributed to them mishearing the ATC instruction.

Readbacks

The flight crew omitted the direction of the turn during readback of the ATC instruction and ATC did not correct the flight crew’s incomplete readback. An uncorrected, incomplete readback may lead to an unintended deviation from ATC instruction and may not be detected until the controller visually observes the deviation. In addition, the absence of ATC correcting a readback is perceived by most flight crews as an implicit confirmation of the readback.[11] Research suggests that ‘errors of omission largely associated with diverse aspects of concurrent task management, when not detected or corrected, are a major threat to aviation safety’.[12] In this incident, the incomplete readback by the flight crew and the absence of a readback correction by ATC was a missed opportunity to identify and correct the misheard instruction. This ultimately resulted in the flight crew turning the aircraft in the opposite direction to that instructed.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the operational non‑compliance involving an Airbus A380 aircraft, registered 9V-SKQ, on 9 February 2020.

Contributing factors

  • The flight crew misheard an air traffic control turn instruction, likely due to a combination of the high cockpit workload associated with the missed approach and their expected turn direction.
  • The flight crew omitted the direction of the turn during the readback, which was not corrected by air traffic control. The absence of the readback correction by air traffic control, combined with the misheard turn instruction, resulted in the aircraft being turned in the wrong direction.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future.

Singapore Airlines

After an internal investigation into the incident, Singapore Airlines issued a notice to flight crew, highlighting strategies to manage high workload situations, as well as reiterating the importance of correct readbacks and acknowledgement from ATC.

Sources and submissions

Submissions

The sources of information during the investigation included the:

  • Singapore Airlines
  • Airservices Australia.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2021

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Pilot flying (PF) and pilot monitoring (PM) are procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances, such as planning for upcoming stages of the flight. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
  2. A precision instrument approach system, which normally consist of the following electronic components: VHF localiser, UHF glideslope, VHF marker beacons.
  3. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  4. The clock code is used to denote the direction of an aircraft or surface feature relative to the current heading of the observer’s aircraft, expressed in terms of position on an analogue clock face. Twelve o’clock is ahead while an aircraft observed abeam to the left would be said to be at 9 o’clock.
  5. An occurrence in which the spacing between two or more aircraft is less than prescribed separation minima in airspace where the aircraft is subject to an air traffic service.
  6. The provision of current, routine information to arriving and departing aircraft by means of continuous and repetitive broadcasts during the hours when the unit responsible for the service is in operation.
  7. Bureau of Meteorology (2014). Hazardous Weather Phenomena Windshear.
  8. Occurs when airflow separates from the wing’s upper surface and becomes turbulent. A stall occurs at high angles of attack, typically 16° to 18°, and results in reduced lift.
  9. Parasuraman, R., Sheridan, T. B., & Wickens, C. D. (2008). Situation Awareness, Mental Workload, and Trust in Automation: Viable, Empirically Supported Cognitive Engineering Constructs. Journal of Cognitive Engineering and Decision Making, 2(2), 140–160. https://doi.org/10.1518/155534308X284417.
  10. Civil Aviation Safety Authority (2006). Civil Aviation Advisory Publication Navigation using Global Navigation Satellite Systems (GNSS) (CAAP 179A-1(1))
  11. Eurocontrol (2006) European Action Plan for Air Ground Communications Safety Edition 1.
  12. Loukopoulos, L. D., Dismukes, K., & Barshi, I. (2009). The multitasking myth: Handling complexity in real-world operations. Farnham, England: Ashgate Pub. Ltd.

Occurrence summary

Investigation number AO-2020-011
Occurrence date 09/02/2020
Location Sydney Airport
State New South Wales
Report release date 07/04/2021
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Operational non-compliance
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A380-841
Registration 9V-SKQ
Serial number 79
Aircraft operator Singapore Airlines
Sector Jet
Operation type Air Transport High Capacity
Departure point Changi, Singapore
Destination Sydney Airport, New South Wales
Damage Nil

Derailment of freight train 4MC2 and subsequent impact with passenger train 8630, at Barnawartha, Victoria, on 29 January 2020

Final report

Report release date: 22/04/2025

Investigation summary

What happened

On 29 January 2020, Pacific National freight train 4MC2 was approaching Barnawartha in northern Victoria when several wagons derailed and the train parted into 3 sections. It had been traveling toward Albury, New South Wales on the interstate rail network managed by the Australian Rail Track Corporation (ARTC). 

The front section, which included 3 derailed wagons, continued until V/Line passenger train 8630 became visible, approaching from the opposite direction, traveling on the adjacent track. The drivers of the freight train reported that they observed a brake pipe airflow indication at about the same time as the passenger train came into view and their train had begun slowing. The driver of the passenger train observed dust ahead and the approaching freight train and responded by applying the brake on their train.

The trains could not be stopped prior to passing which resulted in passenger train 8630 impacting a shipping container on a derailed wagon of 4MC2, sustaining minor damage. There were no injuries to passengers or crew. The passenger train stopped about 50 m short of another container that had fallen from the freight train and was obstructing both tracks.

What the ATSB found

Mid-consist wagons of freight train 4MC2 derailed in response to the geometry of the track. A vertical track geometry defect was present immediately prior to the derailment location and a lateral track misalignment probably formed under train 4MC2.

The vertical track geometry defect was associated with a mud hole. The defect was not identified in the exceedance report generated from ARTC code of practice criteria due to track geometry being assessed against incorrect limits. When assessed against the correct limits, the geometry exceeded defect levels and required a maintenance response. 

A lateral misalignment was present in the track following the derailment although not prior to the passage of the train. The most likely scenario is that a lateral misalignment formed under the train. However, the factors contributing to this probable misalignment could not be fully determined. The extent that rail stress condition may have contributed could not be assessed as ARTC was not monitoring rail stress at this location. 

ARTC was applying a system for reducing the risk of track misalignment. This system and its associated procedures did not lead to locations at or adjacent to the derailment being identified as special locations potentially vulnerable to track instability.

What has been done as a result

ARTC has made several changes to procedures and standards relating to track misalignment, track geometry defects and mud hole management. These safety actions seek to improve ARTC’s capacity to identify locations that may become vulnerable to track instability. In addition, ARTC has undertaken to review available technology to improve its stress‑free temperature testing capability. ARTC has also changed its processes relating to the selection of track speed used to set the appropriate limits for track geometry assessment.

Safety message

This and other occurrences highlight the potential roles of track geometry and instability in derailment. Track managers are encouraged to ensure standards and processes are effective at identifying and rectifying geometry and stability issues to ensure derailment risk is managed. 

 

The occurrence

Introduction

On 29 January 2020, Pacific National freight train 4MC2 was operating on the standard gauge interstate rail network traveling from Melbourne, Victoria to Griffith (via Cootamundra), New South Wales. It had departed Melbourne at 1355 and passed through Wangaratta, Victoria at about 1716 travelling towards Albury, New South Wales (Figure 1). On the same afternoon, V/Line passenger train 8630 departed Albury at 1720 travelling to Melbourne.

Figure 1: Freight train route from Wangaratta (Victoria) to Albury (NSW)

Figure 1: Freight train route from Wangaratta (Victoria) to Albury (NSW)

Source: Google Earth, annotated by the Office of the Chief Investigator (OCI)

Derailment of freight train 4MC2

Train 4MC2 was operated by 2 drivers and consisted of 4 locomotives hauling 46 container wagons. From Wangaratta, 4MC2 was travelling on the East Track. At about 1740, it was approaching Barnawartha travelling on tangent (straight) track and descending a moderate downgrade. 

On the descent, the driver in control was managing the train’s speed between about 114 km/h and 117 km/h with a series of brake applications. Neither member of the locomotive crew recalled observing any track misalignment ahead of their train and front-of-train camera footage similarly did not show any signs of track misalignment. 

Several wagons of 4MC2 derailed commencing at about 277.8 track km.[1] The train parted into 3 sections: the locomotives and wagons 1 to 29 (front), wagons 30 to 40 (middle), and wagons 41 to 46 (rear). The trailing wagon in the rear section came to a stand about 120 m past the derailment location. A schematic of the sections of the separated freight train, derailed wagons and the passenger train is provided in Appendix A.

Figure 2: The middle and rear separated sections of freight train 4MC2

Figure 2: The middle and rear separated sections of freight train 4MC2

Source: ATSB

The locomotives with wagons 1 to 29 attached initially continued for over a kilometre. In this front section of the train, the trailing bogie of wagon 26 and the leading bogie of wagons 28 and 29 were derailed to the left in the direction of travel. It is likely that the trailing bogie of wagon 29 also derailed to the left before it then separated from its wagon at Frying Pan Creek bridge and the rear container from this wagon subsequently fell across both tracks (Figure 3).

Figure 3: Separated trailing bogie from wagon 29 and dislodged container in distance

Figure 3: Separated trailing bogie from wagon 29 and dislodged container in distance

Source: OCI

The locomotive drivers on 4MC2 reported that they were alerted to an issue by a brake pipe airflow indication. At about the same time they observed the approaching passenger train 8630. They recalled that they made attempts to contact the passenger train by radio.

Passenger train 8630 impact with derailed wagon of 4MC2

Train 8630 had departed Albury on schedule. The train consisted of an N-Class locomotive (N474) and 4 passenger cars. Train crew comprised 2 locomotive drivers and 2 conductors, and there were a reported 17 passengers on board. 

Approaching Barnawartha, train 8630 was travelling on the parallel West Track at about 104 km/h. The driver in control recalled observing dust ahead and then train 4MC2. They responded by applying the brake on their train at about 1742 and reported attempting to contact the freight train by radio. The driver estimated their train impacted one derailed container wagon at about 25 to 35 km/h. 

When both trains stopped, at about 1743, the container connected to the last wagon of the front section of 4MC2 was against the end carriage of 8630 and the fallen container was about 50 m in front of the locomotive (Figure 4). The impacted container did not penetrate the passenger compartment and there were no injuries. 

Communication was established between the trains, although it is not clear which communication attempt was ultimately successful, or when it occurred as the radio communication was not recorded. 

Figure 4: Train 8630 passenger car in contact with container of derailed wagon of 4MC2

Figure 4: Train 8630 passenger car in contact with container of derailed wagon of 4MC2

Source: ATSB

Context

Track information 

Overview

The derailment occurred within the Seymour to Albury section of the standard gauge interstate rail network managed by the Australian Rail Track Corporation (ARTC). In the area of the derailment, there were parallel tracks, referred to as the East and West Tracks, both bidirectional. Freight train 4MC2 was travelling on the East Track northbound towards Albury.

The maximum permitted train speeds in the area of the derailment were:[2]

  • 115 km/h for freight trains (with axle load up to 20 t)
  • 130 km/h for passenger trains (with axle load up to 19 t)

There were no Temporary Speed Restrictions (TSR) in force proximate to the derailment location, nor any speed restrictions activated due to heat.

The East Track, in the direction of travel for train 4MC2, leading up to and through the derailment area was tangent (straight) with a moderate downhill grade.[3] There was a turnout about 300 m prior to the derailment location and a 2,400 m radius curve to the left about 200 m beyond it. The curve was about 650 m long, after which the track was straight. There were no other significant track features near to the derailment location. 

Track construction

The East Track utilised continuously welded[4] 60 kg/m rail affixed to concrete sleepers with resilient fasteners. For track with concrete sleepers, ARTC used a nominal sleeper spacing of 667 mm.[5] The engineering code specified 300 mm wide ballast shoulders to either side of the sleeper and ballast height in line with the top of the sleeper (Figure 5Figure 6).[6] Ballast shoulders that conformed to these dimensions were considered ‘full’. Ballast provides support for the sleepers and distributes the loads from the sleepers to the formation to maintain track geometry under vertical, lateral and longitudinal loads.

Figure 5: Ballast shoulder dimensions

Figure 5: Ballast shoulder dimensions

Source: OCI

Track inspection

The track at the derailment location was inspected the day after the derailment. A mud hole was observed within about 10 m of track between 277.780 track km to about 277.790 track km where there was contamination of ballast, a loss of ballast between sleepers, and loss of ballast profile at sleeper ends (Figure 6). A lateral track misalignment was also present, beginning at about the same location as the northern extent of the mud hole (277.790 track km). The visible length of misaligned track was about 65 m although the full extent of the misalignment was likely obscured by subsequent damage from derailed wagons. The misalignment was predominantly toward the left in the direction of travel and the greatest measured lateral deviation was about 0.7 m. Several sets of witness marks from the passage of wheels were identified on the rail head in the section of misaligned track.

Figure 6: Overview of derailment area

Figure 6: Overview of derailment area

Source: ATSB, annotated by OCI

The witness marks consistently indicated that left wheels had ridden up and over the left rail (Figure 7). Related marks were also observed where the corresponding right wheels had dropped between the rails, and where both wheels began contacting sleepers. It was not possible to ascertain which marks were associated with the first derailed wheelset.

Figure 7: Witness mark from a wheel flange climb 

Figure 7: Witness mark from a wheel flange climb

Source: OCI

Within the length of the track misalignment, the ballast had been disturbed by sleeper movement and the impact of derailed wheels. Therefore, the condition of the ballast shoulder could not be assessed. Undisturbed track was inspected at about 277.770 track km. In this area sleeper ends were visible, suggesting that ballast shoulders were less than full (Figure 8).

Figure 8: Sleeper ends protruding from ballast (about 277.770 track km)

Figure 8: Sleeper ends protruding from ballast (about 277.770 track km)

Source: ATSB

Track condition monitoring

Track patrols and inspections

ARTC specified that track patrols were to be conducted every 7 days or as specified in a Track Maintenance Plan. Unscheduled inspections were also carried out in response to ‘defined or abnormal events’ and included those required at special locations where defects were more likely.

ARTC conducted a range of other general and detailed track inspections to monitor the condition of track infrastructure, ranging in frequency from 6 to 24 months. ARTC standards specified that a general inspection of track stability was required as temperatures started to increase after the cold season, normally the end of August, and as close as possible to, or in conjunction with, the ballast general inspection.

A mud hole had been identified during inspection and was recorded in ARTC’s Ellipse maintenance system. It was first identified in 2014 when it was 1 m long and was monitored intermittently through track inspection. The most recent update was on 8 February 2019, at which time the mud hole was listed as a P4 priority defect between 277.780 track km and 277.790 track km (10 m). A defect assigned a P4 priority was to be addressed within 12 months.[7] At the time of the derailment the defect was less than 2 weeks from exceeding this but had not yet been addressed.

Track geometry measurement

Background

The AK car inertial measurement system[8] was utilised by ARTC to measure track geometry without obstructing normal railroad operations. The AK car utilised various sensors to record the lateral and vertical position of the rails at locations along the track. The system processed the information to produce track geometry data for assessment against applicable limits.

ARTC’s Code of Practice (CoP) for track geometry[9] contained the limits applicable for track geometry measurements. It specified that measurements be conducted at least every 4 months by the geometry car (the AK car). The measurements were to be assessed against the CoP limits and the type, size and location of any defects recorded (defects referred to locations where measured track geometry exceeded the relevant limit).

An initial review identified that the measured vertical geometry contained significant variations around the derailment location. Other geometry parameters measured by the AK car were also reviewed but the maximum values proximate to the derailment location were well below CoP defect limits. In some cases, vertical geometry defects may result in elevated track twist.[10] However, that did not occur at the defect location. The vertical geometry values for both rails increased evenly, therefore, no significant twist was present.

Assessment of vertical geometry

Top is a term commonly used to describe variations in the vertical position of an individual rail. The CoP specified three different top parameters, 20 m inertial, Long 20 m chord and Short 4 m chord (Table 1). Notes accompanying the CoP indicated that only the 20 m inertial parameter was applicable to geometry measured by the AK car.

The maintenance response required when a defect level was exceeded changed depending on the speed permitted in a track section. The permitted speeds on this track section were 115 km/h for freight trains and 130 km/h for passenger trains. Therefore, the appropriate speed band reference for geometry limits and corresponding response categories was referred to in the CoP as the 115/160 (freight/passenger) band. This was the highest speed band listed by the CoP and correspondingly had the strictest requirements for defect response.

Table 1: Vertical geometry defect limits and maintenance response categories

Measured parameters in mm under loaded trackMax. speed (Freight/Passenger)
Top100/115115/160
20 m inertialLong 20 m chordShort 4 m chord
>42>90>23E1E1
40-4272-9020-23E1E1
36-3967-7117-19E1E1
33-3557-6615-16E2E1
29-3252-5613-14P1E2
27-2847-5111-12P2P1
24-2638-469-10NP2
Note: The information presented is an extract from the relevant table in the ARTC CoP. Parameters not relevant to the derailment have been removed. 

Where the measured geometry exceeded a limit, it was considered a defect and a response category was assigned that determined what response was required. The responses for each defect response category were provided in the CoP (Table 2).

Table 2: Defect response category and action

Response categoryInspectRepair
E1 (Emergency class 1)Prior to next trainPrior to next train
E2 (Emergency class 2)Within 2 hours or prior to the next train, whichever is greatestWithin 24 hours
P1 (Priority class 1)Within 24 hoursWithin 7 days
P2 (Priority class 2)Within 7 daysWithin 28 days
NNormal scheduled inspection regimeNormal scheduled inspection regime
Note: The information presented is an extract from the relevant table in the ARTC CoP.

ARTC provided 2 exceedance reports for a section of the East Track that included the derailment location. They were generated from track geometry data recorded on 9 October 2019. The exceedance reports identified locations where the measured geometry had exceeded the relevant limit and were therefore considered defects.

Geometry exceedance report 1

Exceedance report 1 was the result of an assessment of measured data against the CoP ‘20 m inertial’ limits. It did not identify any defects close to the identified derailment site (277.795 track km). Information contained within the report indicated that the measured geometry had been assessed against the 100/115 km/h speed band. However, the speed band that should have been applied in this assessment was 115/160 km/h, consistent with the permitted track speeds and as used in a previous assessment.

ARTC advised that the speed band used for assessment had been manually adjusted on the AK car in order to produce reports required for a track upgrade program.[11] This change was still in place when the assessment for geometry exceedance report 1 was undertaken, resulting in the wrong speed band being used.

ARTC also provided an extract from the measured data. It advised that the surface (top) parameter provided in the extract was directly comparable to the ‘Top 20 m inertial’ limits prescribed in the CoP. The local maximum values (at 277.792 track km) were 25.9 mm on the left rail and 24.3 mm on the right rail. Both values exceeded the P2 limit for the 115/160 km/h speed band and were therefore defects at the time of the measurement on 9 October 2019. The CoP required inspection within 7 days and repair within 28 days for a P2 level defect.

Geometry exceedance report 2

A second exceedance report identified a vertical geometry defect at about 277.792 track km. The report was an assessment of the measured data against a 6 m chord top criteria that was not listed in the CoP. ARTC advised that this criteria was to be actioned by local teams as agreed with their managers. Although the defect was recorded in ARTC’s Ellipse maintenance system, there were no records of actions taken in response.

Defect growth

ARTC provided an extract of measured vertical geometry data from the previous AK car measurement run that occurred on 12 June 2019. Local maxima were present at 277.792 km on both rails, albeit that these maxima were less than the lowest defect limit for the 115/160 speed band in the CoP.

The data from the 12 June 2019 measurement was compared to the 9 October 2019 measurement (Figure 9). The comparison showed consistent waveforms between the two sets of measurements and significant growth (38% on the left rail and 48% on the right rail) at the 277.792 km location.

Figure 9: Surface (top) deviation, between June and October 2019 measurements

Figure 9: Surface (top) deviation, between June and October 2019 measurements

 Source: ATSB, generated from ARTC data

The growth of the irregularity in the preceding 4 months (120 days) suggested that it was likely that the defect would have continued to grow in the subsequent period up to the occurrence date (113 days). However, the size of the defect at the time of the occurrence cannot be inferred from this as the growth rate is unlikely to be linear, instead dependent on several factors including prevailing weather and traffic density.

Other geometry standards

The measured vertical track geometry was assessed against the defect severity and maintenance response criteria of other track geometry standards. The standards assessed were:

  • Rail Industry Safety Standards Board (RISSB) AS 7635[12] 
  • RailCorp engineering manual TMC 203[13] 
  • V/Line network infrastructure standard NIST-2706.[14] 

Unlike the CoP, the 3 standards did not use an inertial measurement-based criteria. Instead, they prescribed defect limits for surface geometry irregularities using chord offset measurements. The length of the chord and the offset varied between the standards. 

The inertial vertical geometry measured on 9 October 2019 was reprocessed into the chord offsets relating to each standard. Each result was compared to the defect limit and maintenance response criteria of the applicable standard. Further detail is provided in Appendix B. In all cases this resulted in a defect at the 277.792 track km location with a required response that was more urgent than that required by the ARTC CoP (inspection within 7 days and repair within 28 days). The responses required by each standard are listed below:

  • The long chord criteria in AS 7635 required action (repair or further assessment) within 24 hours.
  • The short chord criteria in AS 7635 required action (repair or further assessment) prior to the passage of the next train.
  • The RailCorp standard required action (repair or further assessment) within 24 hours for both long and short chords.
  • The V/Line standard required an immediate speed restriction and repair within 7 days.

Since the derailment occurred, an updated (2023) version of RISSB AS 7635 has been issued. The new edition emphasised that the table of geometry limits was informative rather than a requirement of the standard. The standard suggests that infrastructure managers:

Should develop appropriate geometry defect limits and intervention thresholds that are appropriate for the class of traffic, infrastructure, configuration, and risk appetite.

Track lateral stability 

Introduction

Track lateral stability is the general term used to describe whether a track is sufficiently restrained against moving sideways under an applied load. The load may be applied in various ways, one significant source being by thermally induced stress in the rails. In ballasted track, the resistance to lateral movement is provided by the ballast, including the shoulder ballast at the ends of the sleepers. A track buckle[15] occurs when stress in the rail overcomes the track structures’ resistance to lateral movement. Therefore, managing track lateral stability involves both the management of rail stress, and the maintenance of track support structures that resist buckling, including ballast.

Rail stress and buckling resistance

Rail stress and stress‑free temperature

Steel rails expand when heated and contract when cooled. In the vertical and lateral directions these changes are small and without consequence. However, in the longitudinal direction, expansion and contraction of continuously welded rail (CWR) is restricted. Instead, changes in temperature cause stress within the rail. If the stress becomes excessive it can cause buckled rail (compressive stress when the temperature is high) or broken rail (tensile stress when the temperature is low). 

At a certain temperature the rail is neither in tension nor in compression, this is its stress‑free temperature (SFT). Rail stress is managed by controlling the temperature at which the rail is stress‑free. ARTC specified a rail SFT of 38°C in track with CWR. The SFT may change with time due to lateral, longitudinal and vertical movement of the track structure. Train forces such as braking and traction create longitudinal movements (creep) in the rail which may also change the in-service SFT (Kish and others 2013). 

The ARTC CoP specified that rail creep monitoring and control measures would not usually be necessary at locations with CWR, concrete sleepers and resilient fastenings. The CoP noted that this type of track structure was known to provide good resistance to longitudinal rail movements, but that ‘practices for the measurement of rail creep should be considered and take into account the influence of fixed points in the track’. There were no creep monitoring facilities through the Barnawartha location.

Changes in a rail SFT are not easily observed in CWR.[16] ARTC did not measure changes to the SFT in CWR affixed to concrete sleepers unless it was identified during inspection that there was a risk that the SFT may have lowered. When identified as being required, ARTC measured rail SFT using VERSE testing.[17] This testing involved unfastening 30 m of rail and lifting it by hydraulic jack. The force required to lift the rail, and the rail temperature at the time was used to calculate the SFT. ARTC had not conducted VERSE testing at the derailment location at any time since it had been rerailed (circa 2010-2011). Subsequently, the SFT of the rails at the time of the derailment and any change in SFT were unknown.

Buckling resistance (ballast)

The Code of Practice (CoP) for ballast[18] specified the required ballast profile, and the corrective action where it was deficient. The response code table notes[19] stated that ‘in concrete sleepers the responses apply where height and width deficiencies occur over 10 m or greater’.

The track proximate to the derailment had not been identified by ARTC as a location requiring ballast rectification. A mud hole was observed in post‑derailment inspections that included sections with deficient ballast (Figure 10). The mud hole was about 10 m long, sufficient length for the CoP to require a response due to ballast deficiency.

Figure 10: Extent of mud hole and light-coloured ballast

Figure 10: Extent of mud hole and light-coloured ballast

Source: ATSB

System for managing track lateral stability

Overview

The system ARTC used for managing track lateral stability was described across multiple documents. Relevant documents included:

  • the ARTC Code of Practice for track lateral stability 
  • related procedure ETM-06-08 – Managing track stability
  • reference document ETGN-06-01 – Track stability handbook

Code of Practice for track lateral stability

The Code of Practice (CoP) for track lateral stability[20] specified the design, maintenance, and inspection actions required in order to provide sufficient lateral stability of the track.

The only applicable design requirement was to install (or adjust) the rail at the target stress‑free temperature. There were no requirements for maintaining concrete sleepered track, though the CoP did suggest that measurement of rail creep should be considered.

The CoP requirements for inspection included:

  • identification of special locations
  • scheduled inspections
  • unscheduled inspection, including:
    • when a temperature threshold was exceeded
    • when a defect was suspected or reported
  • assessment and actions following inspection to verify the track’s capacity to provide adequate lateral stability

The CoP described reasons why track sections should be managed as special locations, including where:

  • reduced lateral stability had been identified (through inspection)
  • a history of lateral track instability existed.

The requirements for assessment and actions included that identified conditions affecting track stability were to be controlled with practices described in other sections of the CoP including ballast (Section 4) and track geometry (Section 5).

Procedure for managing track stability

A procedure for managing track stability[21] contained further requirements and related contextual information. It identified that maintenance of track stability required both management of buckling force (through management of rail stress) and buckling resistance (through maintenance of ballast profile). It described that management of buckling force involved monitoring of changes to stress‑free temperature. The guidance relating to management of buckling resistance focused on identification and assessment of failure or poor condition of components which impact on lateral resistance.

The procedure required a track stability management plan (TSMP) for ‘each section of track’. TSMP’s were to be reviewed at least twice annually (once prior to the onset of hot weather season and once after its conclusion). A TSMP was described as a concise plan of all activities associated with inspecting and managing track to ensure lateral stability that included:

  • requirements for managing buckling force
  • requirements for managing buckling resistance
  • a register of identified special locations.

The procedure described special locations as areas potentially vulnerable to instability, with a history of instability or where stress‑free temperature was suspect. It gave a list of examples that could be special locations that included areas with non-conforming ballast profile and mud holes. A separate list gave examples of mandatory special locations, it included sites with multiple concurrent initiator defects and sites that had previously buckled (where risk of further instability remained).

Information relating to inspection and assessment were contained in the procedure and were largely aligned with the CoP. Inspection to identify and assess localised initiators, including vertical geometry and pumping sleepers[22] (that occur at mud holes) was required at locations that had been identified as special locations. Though not required by either document, the CoP had indicated detailed inspection ‘may be necessary’ for sections of track where reduced lateral stability had been identified. The procedure described that detailed inspections could include measurement of stress‑free temperature or rail creep.

Track stability handbook

The track stability handbook[23] was referenced within the procedure for managing track stability and contained related guidance material. While the handbook addressed special locations, it did so in the context of things to do at identified special locations. It did not provide guidance on the identification of special locations.

The handbook identified that inspection and assessment of track with continuously welded rail, including measurement of stress‑free temperature, could reduce the likelihood of buckles occurring in the hotter months of the year.

Track stability management plan

A track stability management plan (TSMP) existed for the 2019–2020 high temperature season and was last reviewed in November 2019. The TSMP covered multiple track sections including a section of the East Track that contained the derailment location.

The list of stress‑free temperature test locations within the TSMP did not include any within 2 km of the derailment. Several included locations listed vertical geometry or mud holes as reasons for inclusion, but only where lateral geometry, ballast deficiency, or generic ‘rough track’ were also listed.

The TSMP identified that no creep measurements were planned ‘as there is no creep monuments currently installed’. This was justified on the basis that ‘there has been little or no evidence of creep found’ and that tracks ‘have been consolidated and been stable for several years… stress‑free temperature measurements are taken in suspect locations each year’.

With regard to ballast condition, the TSMP required locations with ballast deficiency to be monitored during track patrol for evidence of movement. It instructed inspectors to refer to the Ellipse defect management system for a list of ballast deficient locations. Although a 10 m mud hole had been recorded in the management system, the entry did not reference a ballast deficiency and it was not included in a list of ballast deficient locations provided by ARTC.

Several mud holes and ballast deficient locations were included on the special locations register associated with the TSMP. However, the mud hole proximate to the derailment location was not. The only locations listed with a vertical geometry defect had other defects in combination (e.g. vertical and lateral geometry together, or with an associated ballast deficiency).

Related inspections

Several inspections of the track were conducted in the 6 months prior to the derailment including:

  • inspection for conditions affecting stability (August 2019)
  • 3‑monthly mud hole inspection (October 2019)
  • a 40°C heat patrol inspection (November 2019)
  • a heat patrol inspection after three consecutive 38°C days (December 2019)
  • a front of train inspection (15 January 2020)
  • a track patrol (28 January 2020).

No inspections identified the derailment location as being vulnerable to track instability.

Train information

Freight train 4MC2

Train 4MC2 consisted of 4 locomotives and 46 wagons. The leading locomotive was NR71, followed by a G class locomotive, then 2 further NR class locomotives. 44 of the wagons were single platform container wagons each capable of carrying three 20 ft shipping containers. Wagons in positions 15 and 46 were multi-platform well wagons that had 5 wells each. Each well was able to carry two 20 ft shipping containers on this corridor.

Most wagons were lightly loaded, with axle loads between 5 t and 7.2 t. The wagons with higher loading were well in front of the first derailed wagon. The axle loading for 5 wagons either side of position 26 (the forward-most derailed wagon) was between 6.7 t and 7.2 t.

Empty or lightly‑loaded wagons positioned between fully‑loaded wagons within a train consist can increase derailment risk (ATSB 2020). However, as the wagons close to position 26 were all lightly‑loaded, the marshalling of wagons (their order) was unlikely to have contributed to this derailment.

Recorded information

Key events

Information from the event recorders on the leading locomotive of train 4MC2 and the locomotive of train 8630 was reviewed. A table of events in chronological order is provided in Appendix C. Key events included:

  • The driver of freight train 4MC2 briefly released and reapplied the dynamic brake as the train transitioned the derailment area. Observation of the train speed during this period suggests they were using the dynamic brake to control the train’s speed down a grade.
  • Wagon 26, the forward-most derailed wagon, transitioned the derailment location about 10 s before the first reduction in brake pipe air pressure, this was consistent with a loss of brake pipe air as a result of brake lines parting during the derailment.
  • In response to the speed of train 4MC2 decreasing, the driver of the freight train released the dynamic brake and applied the throttle in an effort to maintain speed.
  • The brake application on passenger train 8630 occurred at about 280 track km. This is before the location where 8630 and 4MC2 crossed and is consistent with the driver of 8630 applying the brakes promptly after observing dust from the freight train in the distance.

Freight train dynamic braking

The driver of train 4MC2 was utilising dynamic brake applications to control train speed on a descending grade. The dynamic brake slows only the locomotives, therefore when it is used, buff (compressive) force is induced between the locomotives and the trailing wagons slowing them in turn. In the vicinity of the derailment, the dynamic brake was released then reapplied 13 seconds later.

Repeated application and release of dynamic brake may contribute to in-train forces[24] that vary in magnitude along the length of the train. However, there was insufficient evidence to support this having contributed to the derailment.

Freight train emergency braking

When a brake pipe parts on a train the pressurised air rapidly vents. It is expected that this reduces brake pipe pressure and results in an automatic emergency brake application. However, in this instance the brake pipe pressure at the lead locomotive did not reduce sufficiently to cause an automatic brake application.[25] This was possibly due to the air volume available from the compressors and main reservoirs on all 4 locomotives being able to supply a sufficient volume of air into the brake pipe to maintain the pressure at the lead locomotive above the automatic brake application pressure while air was venting further along the train. This allowed the front section of the train to continue, and for the driver to apply traction power, after sections of the train and the brake pipe parted.

When the air brake system supplies air to the brake pipe, an airflow meter measures and displays to the driver the amount of airflow. However, the airflow measurement was not recorded by the NR class locomotive event recorder. Therefore, it was not possible to assess whether airflow into the brake pipe was the reason that an emergency brake application did not occur when the brake pipe parted in the derailment.

Wagon inspections

Overview

Wagons 26 and 28 were identified for further inspection. The inspected wagons used the ‘three‑piece’ bogie which is the standard freight bogie in Australia. It consists of 2 side frames and a bogie bolster spanning them. Two side bearers are located on the bogie bolster roughly half-way between the centre and each end. Side bearers provide a degree of control over wagon roll motion (side-to-side tilt) and bogie rotational movement. The inspected wagons utilised constant contact side bearers (CCSBs). As the name implies, when correctly configured, CCSBs are in contact with the wagon body at all times.

Wagon 26

Wagon 26 was found to be in good condition with no items identified that might have contributed to the derailment. There was no indication of improper maintenance, excessive wear or signs of hunting oscillation (cyclic lateral motion).

Wagon 28

The inspection of wagon 28 identified that there was a gap between the side bearer on the left side (in the direction of travel) and the wagon body of the leading bogie. Shims were missing from above the side bearer wear plate creating the gap. Missing side bearer shims could reduce the speed at which the wagon was susceptible to hunting. However, it was not determined whether the shim was missing before the derailment and other indicators of hunting were not present, such as wear on gib[26] contact surfaces (Figure 11).

Figure 11: Wagon 28 lead bogie gib condition

Figure 11: Wagon 28 lead bogie gib condition

Source: OCI

Environmental conditions

Around the time of the derailment, the air temperature measured at the Bureau of Meteorology weather station at Wangaratta, Victoria, was about 36°C. It was clear and dry with SSW wind speeds of around 17 km/h. It is probable that conditions at Barnawartha, located about 45 km from Wangaratta, were similar.

When exposed to direct sunlight rail reaches temperatures considerably higher than the ambient. Published literature suggests that rail temperature can be 50% above the air temperature in direct sunlight (Wu and others, 2010). Using this relationship and the ambient temperature recorded at Wangaratta, the rail temperature was probably about 54°C. This is 16°C above the nominal design stress‑free temperature. 

Similar occurrences

Several investigation reports have been published into occurrences relating to track lateral stability and vertical alignment on Australian railways. Key information from selected reports relevant to this occurrence, including other events on this corridor, is presented below:

On the ARTC network
  • Creighton, Victoria, 21 January 2019: Track lateral instability contributed to a lateral misalignment resulting in a derailment. Mud holes present at the derailment location reduced the track’s resistance to movement. Additionally, the investigation identified that ARTC’s systems for managing track lateral stability did not lead to the location being managed as a special location potentially vulnerable to instability (ATSB investigation RO-2019-003).
  • Locksley, Victoria, 12 February 2013: Track disturbing maintenance activities and a track structure that had reduced capacity to withstand lateral forces (due to ballast fouling) probably contributed to a track misalignment and subsequent derailment. Additionally, the investigation found that despite the location having characteristics consistent with the criteria for a ‘Special Location’ no action had been taken to manage the increased risk (ATSB investigation RO‑2013-006).
  • Ararat, Victoria, 28 November 2003: A small buckle became progressively worse as a train passed over it, resulting in the derailment of 2 wagons. Track disturbing works that had occurred a week prior had probably reduced the lateral resistance provided by the ballast and likely reduced the stress‑free temperature of the rail, although this was not monitored. Additionally, the investigation recommended that ARTC review track maintenance procedures to ensure track geometry and stress‑free temperature were within specified standards (ATSB investigation 2003-006).
On other networks
  • Duaringa, Queensland, 24 January 2018: The driver of a loaded coal train observed a track buckle form as their train approached. It subsequently derailed multiple wagons as it passed over the buckle. Several factors were identified that contributed to the buckle, including track disturbing works and local fixed points. The report also found that a Hazard Location Register was being used as a record of past occurrences rather than as a tool to proactively identify hazard locations (ATSB investigation RO-2018-005)
Summary of similar occurrences

Although each reviewed occurrence investigation report involved unique aspects, thematic similarities included:

  • the formation of lateral track misalignments under (or in one case immediately in front of) the passage of a train
  • locations not being identified on relevant hazard registers
  • track disturbing works occurring prior to the lateral track misalignment occurring 
  • an absence of stress‑free temperature monitoring.

Safety analysis

Introduction

Pacific National freight train 4MC2 was travelling north on the interstate rail network when it derailed at about 277.8 track km near Barnawartha in Victoria. The trailing bogie of wagon 26 was the forward-most derailed bogie. Several wagons behind this position completely or partially derailed and the train separated into three sections.

Initially, the front section of the freight train continued for over a kilometre before being slowed by its driver when alerted to an issue. Concurrently, passenger train 8630 was approaching Barnawartha from the opposite direction on a parallel track. The driver of 8630 observed dust and the headlights of 4MC2 and applied their train’s brakes in response. The trains came together at slowing speeds, with the passenger train impacting a container on derailed wagon 29 of the freight train.

This analysis discusses:

  • factors associated with the derailment of freight train 4MC2
  • management of track geometry
  • management of track lateral stability 
  • the passenger train collision with the derailed freight train.

Derailment of freight train 4MC2

Background

Post‑derailment inspection identified several locations of wheel flange climb over the rail head of the left rail in the direction of travel. Subsequent damage to sleepers was consistent with full wheelset derailment, the furthest south location identified was at 277.795 track km, about 5 m past an observed mud hole. The flange climb marks were consistent with the derailed states of wagons 26 (trailing bogie), 28 (leading bogie) and 29 (both bogies) being toward the left in the direction of travel. While it was not possible to conclusively determine which marks were associated with which wheel derailments, the observation of flange climb marks on the rail head indicate that the initial derailment was probably by the action of a flange climb. 

Flange climb occurs when lateral forces between the wheel and the rail exceed the capacity for vertical forces to restrain, either through excessive lateral force alone, or a combination of increased lateral force and reduced vertical force. 

The presence of wagon hunting was considered as it may affect wheel to rail forces. While higher speed generally increases the potential for hunting, and the derailed train was traveling at or near the maximum speed for this track, there was insufficient evidence to conclude that hunting was occurring in this case.

The features identified that could contribute to flange climb in this instance were:

  • the vertical geometry defect at 277.792 track km
  • the lateral track misalignment.
Derailment mechanism

Contribution of vertical track geometry defect

The vertical geometry defect was in close proximity (and prior) to the derailment location. When a wagon’s wheels pass over an upward vertical geometry defect at speed there is initially an increase in the vertical force between wheels and rails, above the static load value. The load then decreases to below the static force once the wheel is past the highest point of the track geometry defect. This may induce a vertical dynamic response of the wagon body, which in turn can cause further fluctuation in the vertical force between wheels and rails. Therefore, the vertical geometry defect contributed to locations of reduced vertical force in the vicinity where the derailment occurred.

There was no evidence identified that indicated that wheels passing over the vertical geometry defect contributed to an increased lateral force between wheel and rail. The recorded track geometry did not include significant lateral (when both rails move to one side) or twist (where one rail is higher than the other) defects present alongside the vertical defect to initiate lateral motion of the wagons. Therefore, the evidence did not suggest that the wagon transitioning the vertical track geometry defect was sufficient to initiate the derailment on its own but contributed by reducing the vertical force present between wheels and rails.

Contribution of lateral track misalignment

A lateral track misalignment was present after the derailment. It was not present in footage obtained from the forward-facing camera on train 4MC2. The misalignment therefore either occurred during the passage of the train or as a consequence of the derailment. Lateral track misalignments often occur under, and in response to, the passage of a train, as supported by the findings of previous occurrence investigation reports.

When a train is in normal straight running, there is a gap present between the wheel flanges and the side face of the rails. This and the guidance afforded by conical railway wheelsets (steering of the wheels) mean that small lateral misalignments of the rail are overcome without flange contact and large lateral forces. However, when the lateral misalignment is large, the wheel flange contacts the rail. Although other factors are involved, the magnitude of the resulting lateral force is related to the size of the misalignment.

As a lateral track misalignment forms under a train, it creates increasing lateral wheel to rail forces as it grows. It may also induce a lateral (roll) response of the wagon bodies which can contribute to further high lateral forces as well as affecting vertical force between the wheels and rails.

While it is possible that the lateral track misalignment formed as a consequence of the derailment, there was an absence of evidence of other mechanisms for generating lateral force or otherwise initiating the derailment. Therefore, it was probable that the lateral track misalignment formed under the passage of the train and contributed to the derailment by increasing the lateral force present between wheels and rails.

Examining possible causes of lateral track misalignment

Severe lateral track misalignments (commonly referred to as track buckles) occur when longitudinal compressive forces in the rails cause lateral buckling forces to exceed the restraint offered by the track structure. Managing the risk of lateral misalignment therefore requires both the management of longitudinal compressive forces in rails and the maintenance of track ballast that provides restraint.

The hot, sunny condition at the time of the derailment meant that it was almost certain that some longitudinal compressive force was present in the rails at the derailment location. However, the severity of the force and the increase in risk of lateral misalignment are not known as ARTC was not monitoring changes to the stress‑free temperature (SFT) of the rail at the derailment location.

ARTC’s procedure for managing track stability listed locations with increased risk of lateral instability, including locations with:

  • a history of instability
  • bunching points
  • areas with non-conforming ballast profile
  • track disturbing works (such as tamping)
  • localised initiators (including mud holes).

There was no recent history of instability in the vicinity of the lateral track misalignment or record of recent track disturbing works.

Rail bunching occurs when the rails move toward fixed points in the track, typically as a result of train braking and acceleration forces. Bunching results in rails having a reduced SFT. In such circumstances, higher than anticipated longitudinal compressive stresses occur during hot weather at bunching points, which increases the risk of track instability. Turnouts, road crossings and bridge decks are commonly identified as bunching points. The closest turnout was about 300 m south of the derailment and the closest bridge deck was 1075 m to the north, making them both unlikely to have contributed to the misalignment. The mud hole near the derailment was also unlikely to have been a bunching point relevant to this occurrence given the down grade of the track and the location of the buckle after the mud hole (in the direction of travel of train 4MC2). 

Although the mud hole was identified as having deficient (non-conforming) ballast profile, it did not shift laterally. It is possible that some of the section of track that moved laterally had less than full shoulder ballast, consistent with observations of track further south. However, this had not been recorded by ARTC as deficient prior to the derailment, nor was it to the extent of the deficiency present at the mud hole location.

ARTC described localised initiators as ‘additional conditions present that will increase the locations vulnerability to instability’. Track geometry defects and pumping sleepers (that occur at mud holes) were identified as potential localised initiators. However, the mud hole and track geometry defect present at the time of the derailment were at one end of the lateral track misalignment, rather than within the section that had substantially moved. It is therefore unclear whether these contributed to the initiation of lateral track misalignment in this case.

The high rail temperature on the day of the derailment did contribute to the probable lateral track misalignment, by inducing a level of compressive force in the rails. However, if the rails had the nominal SFT and were in track with normal levels of lateral stability, this increased temperature would not have been sufficient to induce misalignment on its own. Whether the SFT had reduced was not known and, of the factors that had been associated with increased risk of lateral instability, several were not present. The presence and contribution of other factors was not known. Therefore, the factors contributing to the track misalignment could not be comprehensively determined based on the available evidence.

Contributing factor

The dynamic motion of wagons as they transitioned a vertical track geometry defect and a probable lateral track misalignment led to the derailment of train 4MC2. The factors contributing to the probable lateral track misalignment could not be fully determined.

Train condition

Wagon 26 was the furthest forward in the train consist to have derailed, with the trailing bogie derailed to the left side in the direction of travel. Its position within the train suggested that it was probably the first wagon to derail. The wagon was inspected post-derailment and no indication of improper maintenance, excessive wear or signs of cyclic dynamic motion (hunting) that may have contributed to the derailment were observed.

The train consist indicated that this wagon was lightly loaded. Wagons adjacent to it were similarly loaded indicating that derailment risk due to in-train forces that exists for lightly loaded wagons adjacent to heavily loaded wagons was not present in this occurrence.

Track geometry

Mud hole

Ballast fouling, associated with a mud hole was present immediately before the derailment location, the northern extent was at 277.790 track km. The ballast profile in the area of the mud hole was deficient, with sleeper ends protruding, indicating that the track support was reduced.

A vertical geometry defect existed at 277.792 track km on both rails. The defect was within 2 m of the northern extent of the mud hole, which indicated that it was associated with the mud hole. The defect was a result of the track level within the mud hole being lower, then rising up at the defect location. The magnitude of the measured geometry rise had grown in 4 months preceding the October 2019 measurement and would have likely continued to grow up to the occurrence date.

Contributing factor

A mud hole resulted in a vertical track geometry defect and localised reduction in track support immediately prior to the derailment location.

Identification of vertical geometry defect

Vertical track geometry defects existed in both rails at 277.792 track km in October 2019 that exceeded ARTC’s P2 level. However, they were not included in the exceedance report generated for this date as it was based on an assessment against limits applicable for a lower speed track. Had this been detected, additional management would have been required as the ARTC CoP required that a P2 severity defect be inspected within 7 days and repaired within 28 days.   

A second exceedance report was generated from the track geometry recorded on the same day. It identified a defect at about 277.792 track km. However, this exceedance report was generated from an assessment against a parameter that was not listed in the CoP. There was no requirement for inspection or maintenance to be performed other than at the discretion of the maintenance team.

Contributing factor

ARTC did not identify and manage the vertical track geometry defect in accordance with its Code of Practice for track geometry. For the October 2019 measurement, track geometry was assessed against limits for the wrong speed band.

 

Comparison with other geometry standards

The measured vertical track geometry was evaluated against other standards. The standards chosen for assessment were the Australian Standard, New South Wales RailCorp standard, and Victorian V/Line standard. The standards used for assessment were those versions current at the time of the derailment. In all cases, the response required was more urgent than required by the ARTC CoP.

Based on the assessment of this defect, the limits prescribed in the CoP for inertial measurement permitted larger defects than comparable chord-based standards for vertical geometry defects. None of the standards provide a methodology detailing how their limit or response levels have been established, nor does the CoP.

A broader assessment of a large sample of possible and actual track recordings against objective safety criteria would be required to establish whether the limits and responses prescribed in the CoP provide a suitable level of safety. Such an assessment would be broadly aligned with the guidance offered by the 2023 update of the Australian Standard.

Other finding

For the track geometry that existed at 277.792 track km, ARTC’s Code of Practice for track geometry was less restrictive in managing vertical geometry than other comparable standards. The suitability of the limits and responses prescribed in the ARTC Code of Practice was not established.

Management of track lateral stability

ARTC’s system for managing track lateral stability was being applied at the time of the derailment. A track stability management plan had been created for the relevant track section. Inspections and stress‑free temperature measurements were occurring at identified special locations and additional general inspections were also occurring. However, no location at or adjacent to the location of the probable lateral track misalignment were identified as a special location or had stress‑free temperature measured. In other words, a location that was potentially vulnerable to track instability was not identified.

The proximity of the mud hole to the derailment appeared to provide the greatest opportunity for the location to be identified as a special location. It is unclear why the mud hole was not identified as a special location given that it had been recorded in ARTC’s maintenance system and had ballast deficiency. Other locations of mud holes and ballast deficiency were identified as special locations.

A vertical track geometry defect also provided an opportunity for identification as a special location. However, both the error that caused it not to be detected, and the lack of other examples of isolated vertical geometry defects (where no lateral defect, ballast deficiency or general rough track were present) being included as special locations, limited the likelihood of this mechanism being useful for the identification of a special location.

The inclusion of a location proximate to the derailment location on the special location register would not guarantee that lateral track misalignment would be prevented. However, it would have provided the opportunity to carry out stress‑free temperature measurement, providing information that was otherwise missing relating to the risk of track instability.

The investigation into a derailment at Creighton, Victoria in 2019 identified that ARTC’s systems for managing track lateral stability did not lead to the location being managed as a location potentially vulnerable to instability. Safety action taken by ARTC at the time did not include changes to improve the system’s ability to prospectively identify vulnerable locations.

Other factor that increased risk

ARTC’s systems for management of track lateral stability did not lead to identification of the location as a special location potentially vulnerable to track instability. (Safety issue)

Passenger train impact

At about the same time that the driver of freight train 4MC2 reported observing a brake pipe airflow indication, V/Line passenger train 8630 approached Barnawartha from the other direction, heading toward Melbourne on the West Track. The driver of 8630 applied the brakes promptly after observing dust from 4MC2 in the distance. Despite this, the distance remaining when the brake application occurred was less than the stopping distance required.

The drivers of both trains described attempting to provide advanced warning by radio to the opposing train. However, it is not clear which communication attempt was ultimately successful, or the exact timing of communication attempts, as the radio channel used was not recorded. It was consistently described that all communication attempts occurred after the trains were first in view of each other and the brake applied on the passenger train. In this scenario, radio communication would not have influenced the outcome as the brake application had already occurred.

The passenger train could not stop in time and impacted a shipping container on derailed wagon 29 of train 4MC2 at a low speed. The passenger train stopped about 50 m short of another container that had fallen from wagon 29 and was obstructing both tracks. There was very little opportunity for any further actions to reduce the risk to safety in this occurrence by stopping passenger train 8630 prior to collision.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the derailment of freight train 4MC2 and subsequent impact with passenger train 8630, at Barnawartha, Victoria on 29 January 2020. 

Contributing factors

  • The dynamic motion of wagons as they transitioned a vertical track geometry defect and a probable lateral track misalignment led to the derailment of train 4MC2. The factors contributing to the probable lateral track misalignment could not be fully determined.
  • A mud hole resulted in a vertical track geometry defect and localised reduction in track support immediately prior to the derailment location.
  • ARTC did not identify and manage the vertical track geometry defect in accordance with its Code of Practice for track geometry. For the October 2019 measurement, track geometry was assessed against limits for the wrong speed band.

Other factors that increased risk

  • ARTC’s systems for management of track lateral stability did not lead to identification of the location as a special location potentially vulnerable to track instability. (Safety issue)

Other findings

  • For the track geometry that existed at 277.792 track km, ARTC’s Code of Practice for track geometry was less restrictive in managing vertical geometry than other comparable standards. The suitability of the limits and responses prescribed in the ARTC Code of Practice was not established.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies. 

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the Rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation. 

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Special location not identified

Safety issue number: RO-2020-001-SI-01

Safety issue description: ARTC’s systems for management of track lateral stability did not lead to identification of the location as a special location potentially vulnerable to track instability.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. The ATSB has been advised of the following proactive safety action in response to this occurrence
Additional safety action taken by ARTC

ARTC has made several changes in response to this derailment including:

  • The Code of Practice for track geometry has been updated to include a 6 m chord top criteria in addition to the 20 m inertial criteria. If assessed against the 6 m chord criteria in the updated standard, the vertical geometry identified in this investigation would have been classified as an E2 level defect (requiring inspection within 2 hours and rectification within 24 hours, or a significant reduction in speed).
  • The mud hole management guideline has been updated to incorporate significant guidance on the identification, assessment and management of mud holes.
  • In response to the use of an incorrect speed band for geometry assessment, ARTC has changed its process regarding the creation of additional reports. This is now achieved as a post-process rather than changing the speed in configuration files used on the AK car. In addition, ARTC is transitioning to a process that automatically assigns speed bands based on a linear referencing system, removing the need for manual configuration of speeds and allowing cross-checking by AK car operators. The automatic assignment of speed bands has been implemented in South Australia, Western Australia and Victoria and is scheduled to be completed in New South Wales by December 2025.

Glossary

ARTCAustralian Rail Track Corporation
CCSBConstant contact side bearer
CoPThe ARTC Track and Civil Code of Practice. Comprised of sections related to specific topics. Sections referenced in this report include: Section 2 – Sleepers and fastenings, Section 4 – Ballast, Section 5 – Track geometry, Section 6 – Track lateral stability 
CWRContinuously welded rail
RISSBRail Industry Safety Standards Board
SFTStress‑free temperature
TSMPTrack stability management plan
TSRTemporary speed restriction

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Australian Rail Track Corporation 
  • Pacific National
  • V/Line
  • the drivers of both involved trains (4MC2 and 8630)
  • data from locomotive event recorders. 

References

  • ATSB. (2020). Derailment and collision between coal trains, Ravenan (25km from Muswellbrook), New South Wales, on 26 September 2018 (RO-2018-017)
  • Wu Y., Munro P., Rasul M.G., Khan M.M.K., A review of Recent Developments in Rail Temperature Prediction for use in Buckling Studies, RTSA Conference on Railway Engineering, Wellington, 2010
  • Kish A, Mui W, Track Buckling Research, John A. Volpe National Transportation Systems Centre (U.S.) 2013., https://rosap.ntl.bts.gov/view/dot/11985.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report. 

A draft of this report was provided to directly involved parties and other relevant organisations. Submissions received were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Appendices

Appendix A – Post derailment location of trains

Appendix A – Post derailment location of train

Appendix B – Comparison of standards for vertical geometry

Introduction

Maintenance response criteria for vertical geometry from the Rail Industry Safety Standards Board (RISSB) AS 7635, RailCorp Engineering Standard ESC 210 and the V/Line Network Infrastructure Standard NIST-2706 were compared with the criteria in the ARTC Code of Practice. 

The length of the chord and the offset used in evaluation (including whether it was symmetric or asymmetric) varied between the standards. The chord offsets[27] used by the selected standards were: 

  • 10 m / 1.8 m (AS 7635 and RailCorp)
  • 5 m / 2 m (AS 7635)
  • 6 m / 3 m (RailCorp)
  • 10 m / 5 m (V/Line)

As the limits nominated for vertical geometry (top) in the 3 standards relate to specific nominated chord lengths, these limits couldn’t be directly compared to ones used with other measurement systems.[28] While it is possible to calculate the geometry for one chord offset from a measurement using a different chord offset, some information is lost in this process meaning it may not closely reflect the results of a direct measurement. However, the inertial measurement generated by the AK car is an estimate of the ‘true’ vertical geometry. Therefore, chord offsets can be calculated from the inertial measurement data without loss of information (providing the chord is of a reasonable length). It is understood that ARTC used this method to generate their 6 m exceedance report.

Results

Results for the vertical geometry using each of the 4 chord offsets were generated from the inertial data provided for the measurement undertaken on 9 October 2019 (Figure B1) The calculation used ARTC supplied formulae. The results vary substantially from the inertial value.  

Figure B1: Comparison of vertical geometry results – Left rail

  Figure B1: Comparison of vertical geometry results – Left rail

Source: ATSB, generated from ARTC data

Results obtained using a symmetric chord offset (10 m / 5 m and 6 m / 3 m) are independent of orientation. In practice, when a real measurement system is used, the same result will be recorded regardless of the direction travelled over the defect. However, for the asymmetric chord offsets (10 m / 1.8 m and 5 m / 2 m) the recorded values are dependent on direction of travel. The orientation implied in the formulas ARTC provided was with the offset closer to the leading end of the chord (in direction of travel) and is therefore the orientation presented. 

The local maxima that occurred near the existing defect location at 277.792 track km were identified for each chord offset approximation. Table B1 presents the maximum value obtained for each rail and the corresponding defect response level based on the limits prescribed in the relevant standard. The defect response level may be different for each rail; when this occurred, the higher response was applied at the location.

Table B1: Summary of maximum value and corresponding response category

MethodLeft  (mm)Left (category)Right (mm)Right (category)Standard
Inertial25.9P224.3P2ARTC
10 m / 5 m33.7A-H32.3A-HV/Line[1] Class 2[2]
10 m / 5 m33.7A-H32.3A-HV/Line[1] Class 2M[2]
10 m / 1.8 m23.3E2 20.4P1 AS 7635 / RailCorp[3]
6 m / 3 m[4]29.4E228.2E2RailCorp
5 m / 2 m23.3E123E1AS7635
  1. V/Line standard uses different intervention levels to ARTC and the AS 7635. Where the ARTC and AS 7635 uses E1, E2, P1, P2 Limits, V/Line uses A (Priority) and B (General), and a subset of A: A-N (Normal) and A-H (High). The definition of required actions for A-N and A-H generally align with the P1 and E2 classes of AS 7635.
  2. V/Line standard uses different track class / permitted speed criteria to ARTC, RailCorp and AS 7635. Class 2 aligns with the maximum speed permitted for V/Line passenger trains on this corridor (115 km/ h). Class 2M aligns with the maximum speed permitted for any passenger trains on this corridor (130 km/h for the XPT). Both were assessed and, in this case, there was no difference in the fault level.
  3. RailCorp standard intervention levels are aligned with ARTC and the AS 7635 with an additional P3 limit. While there are differences between the defect magnitudes and intervention levels between AS 7635 and RailCorp standards, in this case they both resulted in the same response category.
  4. The RailCorp 6 m / 3 m chord is included despite being listed as a ‘manual’ limit as it is believed to be the origin of the ARTC AK car generated exceedance report for 6 m chord top.
Summary 

The method used for categorisation of responses varied between the standards. However, the response actions associated with the categories could be compared. The response categories and actions are listed below:

  • The ARTC standard categorised the vertical geometry as P2 level defects on both rails, requiring action in 28 days. 
  • The V/Line standard (class 2 and 2M) categorised the vertical geometry as class A-H defects for both rails, requiring immediate application of an 80 km/h speed restriction and repair within 7 days. 
  • The AS 7635 10 m / 1.8 m method categorised the vertical geometry as an E2 defect on the left rail and a P1 defect on the right rail. This required action within 24 hours and 7 days respectively or application of appropriate speed restrictions. 
  • The RailCorp standard 10 m / 1.8 m method categorised the vertical geometry as an E2 defect on the left rail and a P1 defect on the right rail. This required action within 24 hours and 7 days respectively or application of appropriate speed restrictions.  
  • The RailCorp standard 6 m / 3 m method categorised the vertical geometry as E2 defects on both rails, requiring action within 24 hours. 
  • The AS 7635 5 m / 2 m method categorised the vertical geometry as E1 defects on both rails, requiring action or application of appropriate speed restrictions prior to the passage of the next train. 

There is difference in the maintenance responses triggered by the same vertical geometry when assessed against the different standards. Assessment against the three chord-based standards (V/Line, RailCorp, and AS 7635) all resulted in a more urgent response than required by the ARTC CoP. Based on the assessment of this defect, the limits prescribed for the CoP permit larger defects than comparable chord-based standards for vertical geometry defects. 

Appendix C – Analysis of recorded information

Introduction 

Information recorded on the event recorders from the leading locomotive of train 4MC2 and the locomotive of train 8630 was reviewed. The times recorded on both were compared to times recorded for key events recorded by the ARTC signalling system. Corrections were applied to align the recordings. 

No correction was applied to the recorded speed or distance. All positions (track km values) were calculated based on the distance from the position that each train stopped relative to Havelock Street level crossing at 279.490 track km.

Table of events

Table C1 below provides contextual events identified from both trains in chronological order.

Table C1: Recorded events in chronological order

TrainTimeSpeed (km/h)Front of train  (track km)Wagon 26 (track km)Comment
863017:29:210299.350 Departs Wodonga 
4MC217:39:41115275.616274.947Initial dynamic brake application on approach to the derailment location
4MC217:40:49116277.800277.131Initial dynamic brake release and front of train 4MC2 closest to derailment location
4MC217:41:02116278.218277.549Second dynamic brake application
4MC217:41:03117278.251277.582Maximum speed
4MC217:41:10116278.478277.809Time when wagon 26 is closest to derailment location
4MC217:41:20111278.797278.128Brake pipe pressure reduced from 496 kPa to 489 kPa
4MC217:41:21112278.829278.160Second dynamic brake release
4MC217:41:27108279.012278.343Throttle on
863017:41:57104280.032 Brake pipe pressure decrease and brake cylinder pressure increase (likely brake applied by driver of 8630)
4MC217:42:0365279.870279.201Throttle off
863017:42:0988279.704 Power knock‑out switch activates, a likely indication that the brake application was an emergency application
4MC217:42:1054279.984279.315Locomotive brake pipe pressure decreases (from 475 kPa to 399 kPa within 2 seconds) and cylinder pressure rise (likely brake applied by driver of 4MC2)
4MC217:42:310280.143279.4744MC2 stops
863017:43:090279.269 8630 stops

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2025

Title: Creative Commons BY - Description: Creative Commons BY

 

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Commonwealth Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this report is licensed under a Creative Commons Attribution 4.0 International licence.

The CC BY 4.0 licence enables you to distribute, remix, adapt, and build upon our material in any medium or format, so long as attribution is given to the Australian Transport Safety Bureau. 

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]      Track kilometre (track km): refers to the distance along a track from a known location. On the Victorian section of the Interstate Rail Network the 0 km reference is Southern Cross Station in Melbourne.

[2]      ARTC, Route access standard, D53 Albury – Somerton, Version 2

[3]      The track gradient was 1:137 from about 277.4 track km extending through the derailment area to 278.5 track km. Gradient and curve data from PASS Assets XBC Public Transport Victoria (PTV)

[4]      Continuously welded rail (CWR): Rail lengths welded end-to-end into strings greater than 400 m.

[5]      ARTC, Engineering (Track & Civil), Code of Practice, Section 2, Sleepers and fastenings, Version 2.0

[6]      ARTC, Engineering (Track & Civil), Code of Practice, Section 4, Ballast, Version 2.4

[7]      ARTC procedure EGP-10-01 Enterprise Asset Management System contained the definition for these priority codes.

[8]      Proprietary measurement system of Vista Instrumentation LLC

[9]      ARTC, Engineering (Track & Civil), Code of Practice, Section 5, Track Geometry, Version 2.12

[10]    Twist: the change in cross-level (the height difference between two rails) measured over a fixed distance. ARTC specify long (14 m) and short (2 m) twist measurement distances.

[11]    The North East Line upgrade was a project undertaken by ARTC to improve the rail line and passenger rail services between Melbourne and Albury. The project was to upgrade the track to a standard consistent with other regional long‑distance rail lines in Victoria.

[12]    RISSB AS 7635 Track Geometry – Appendix B (2013)

[13]    RailCorp Engineering Manual TMC 203 Track inspection – Chapter 5 (version 5.3 - 2013)

[14]    V/Line Network infrastructure standard NIST-2706 – Inspection and assessment: Track geometry. Attachments 2, 3 and 9 (Rev 3 – 2018)

[15]    Buckling is the sudden change of shape of an object when a critical load is exceeded. In the case of long slender beams, such as rails, buckling occurs when compressive force exceeds a critical value. For track, buckling is delayed beyond the critical value for the individual rails by the resistance forces exerted by the sleepers and ballast. 

[16]    By comparison, in jointed track, the expansion and contraction of rail can be observed and simple measurements taken at joints to estimate the stress condition of the rail at temperature extremes.

[17]    VERSE is a proprietary device used for non-destructively measuring the stress‑free temperature in rail.

[18]    ARTC, Engineering (Track & Civil), Code of Practice, Section 4, Ballast, Version 2.4

[19]    ARTC, Engineering (Track & Civil), Code of Practice, Section 4, Ballast, Version 2.4 - Note 2 relating to tables 4.3, 4.4 and 4.5.

[20]    ARTC, Engineering (Track & Civil), Code of Practice, Section 6, Track lateral stability Version 2.5

[21]    ARTC, Track & Civil, Procedure, ETM-06-08 - Managing track stability, Version 1.2

[22]    Pumping sleepers refers to sleepers that move up and down significantly more than intended when trains pass over. In locations where water is present (i.e. where drainage is not sufficient), this action can pump fine soil particles from the formation below up through the ballast to the surface. This is commonly observed where mud holes have formed. 

[23]    ARTC, Track & Civil, Guideline, ETN-06-01 - Track stability handbook, Version 1.

[24]    In-train force: forces propagated longitudinally along a train due to changes in relative speed and acceleration of adjacent locomotives and wagons. These forces occur during braking (run-in or buff), where the rear of the train may compress toward the front, or acceleration (run-out or draft), where the front stretches away from the rear of the train.

[25]    The brake pipe pressure was only recorded at the locomotives. It is likely that the brake pipe pressure did reduce sufficiently to apply the brakes in wagons further back in the front section (closer to the parted location).

[26]    Gibs are lugs on each end of a bolster which face a mating surface on each side frame. The space between these is a contact area between bolster and side frames that limits lateral movement of the bolster within the bogie side frames and inhibits bogie over-rotation.

[27]    The format used describes the chord first and then the offset, which is the distance of the measurement point from one end of the chord. For example: a 5 m / 2 m chord offset uses a 5 m chord, with the measurement point offset from one end of the chord by 2 m.

[28]    Note 2, Table 5-11 – Geometry Defects, ARTC Code of Practice, Track Geometry, Section 5, Version 2.12, reviewed 26 July 2019

Occurrence summary

Investigation number RO-2020-001
Occurrence date 29/01/2020
Location Barnawartha
State Victoria
Report release date 22/04/2025
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Collision, Derailment
Occurrence class Accident
Highest injury level None

Train details

Train operator Pacific National
Train number 4MC2
Type of operation Freight service
Rail vehicle sector Freight
Departure point Melbourne, Victoria
Destination Griffith, New South Wales
Train damage Substantial

Train details

Train operator V/Line
Train number 8630
Type of operation Passenger service
Departure point Albury, New South Wales
Destination Melbourne, Victoria
Train damage Minor

Technical Assistance to RAAus – Collision with terrain, Aeroprakt, A22 Foxbat, 24-4239, 111 km south-south-west of Isisford, Queensland, on 2 December 2019

Summary

On 2 December 2019, an Aeroprakt A22 Foxbat, recreational registration 24-4239, collided with terrain while conducting mustering 111 km SSW of Isisford, Queensland. The pilot sustained serious injuries.

In response to this accident, Recreational Aviation Australia (RAAus) commenced an investigation. As part of its investigations, RAAus requested technical assistance from the ATSB to download flight data from a Garmin GPS.

To protect the information supplied by RAAus to the ATSB and the ATSB's investigative work to assist RAAus, the ATSB initiated an investigation under the Transport Safety Investigation Act 2003.

The ATSB has concluded the examinations of the Garmin GPS and has provided the results of that work to RAAus on 7 February 2020.

Any enquiries relating to the accident investigations should be directed to RAAus at: www.raa.asn.au

Occurrence summary

Investigation number AE-2020-009
Occurrence date 02/12/2019
Location 111 km SSW of Isisford
State Queensland
Report release date 11/02/2020
Report status Final
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Serious

Aircraft details

Manufacturer Aeroprakt Ltd
Model A22 Foxbat
Registration 24-4239
Sector Piston
Operation type Aerial Work
Damage Substantial

Collision with water involving Textron Aviation Inc. (Cessna) 206, VH-AEE, near Happy Valley, Fraser Island, Queensland, on 29 January 2020

Final report

Report release date: 08/07/2021

Safety summary

What happened

At 1322 Eastern Standard Time, on 29 January 2020, a Cessna Aircraft Company U206G, registered VH-AEE and operated by Air Fraser Island with two pilots onboard, was being used for landing emergency procedure training on a beach aircraft landing area (ALA) on Fraser Island, Queensland.

Just after touching down, the aircraft veered significantly to the left, toward the sea. The training pilot took control of the aircraft and conducted a go-around. Once airborne it was identified that the rudder was jammed in the full‑left position and the pilot had to apply full opposite aileron to maintain control. The engine subsequently stopped and the aircraft collided with water. The pilots escaped the aircraft and swam to shore. The aircraft was destroyed.

What the ATSB found

The ATSB found that, following touchdown, a section of the nose landing gear attachment failed, resulting in the rudder becoming jammed in the full‑left position. Due to the aircraft’s significant deviation towards the water, a go-around was initiated. While there was only a short timeframe to make the decision to abort the landing, it resulted in flight over water with significantly reduced aircraft controllability that required uncoordinated flight control inputs to control the aircraft.

It was also identified that fuel starvation, due to either the uncoordinated flight or damage associated with the nose gear failure, led to the engine losing power at a height too low for recovery and the aircraft collided with water.

The ATSB also identified two safety issues associated with the Cessna 206 that, while not contributory to this accident, can lead to fatal consequences in the event of a ditching.

Firstly, the Cessna 206 procedure for ditching and forced landing stated that the flaps were to be extended to 40°. While that permitted the aircraft to land at a slower speed, it also significantly restricts emergency egress via the cargo door. However, there is no warning about that aspect in the ditching or forced landing pilot’s operating handbook emergency procedures.

In addition, the Cessna 206 with the cargo door does not meet the aircraft certification basis for the design of cabin exits, due to the complexity associated with opening the cargo door if it is blocked by the flaps. This significantly hampers emergency egress and has previously resulted in fatalities.

What has been done as a result

The ATSB has recommended that Textron Aviation take safety action to address the procedure for ditching and forced landing in the pilot operating handbook for the Cessna 206, to ensure pilots are aware that extending the flaps beyond 10° will significantly restrict emergency egress via the cargo door.

The ATSB also recommends that the United States Federal Aviation Administration and the Civil Aviation Safety Authority take safety action to address the certification basis for the design of the cargo door in the Cessna 206, as wing flap extension beyond 10° will block the forward portion of the rear double door, significantly hampering emergency egress. 

In addition, and as a result of this accident, the operator has changed their procedures to specify that during emergency procedure training on the beach, no non-company vehicles are permitted to operate within the runway complex. They have also reassessed the company hazard register and included brake failures.

Safety message

This occurrence highlights the issue of evacuation through the cargo door when the flaps are extended in the Cessna 206. Pilots should be aware that lowering the flaps will block this exit and significantly increase the difficulty of opening the door. Consequently, all passenger pre‑flight briefings should include a practical demonstration of how to open a partially‑obstructed cargo door. Additionally, in the event that a ditching is required, pilots should consider not extending the flaps.

Furthermore, in 2009, research by the Transport Safety Board of Canada found that in the previous 20 years, where an aircraft had collided with water, 70 per cent of fatalities were caused by drowning. That statistic reflects the inherently disorientating nature of underwater exit from an often-inverted aircraft.

Transport Canada released TP 2228E-18 (04/2003), an ‘underwater egress’ safety guide which was forwarded to all Canadian operators of passenger carrying operations operating on water. This guide was to be provided to passengers before flight to increase their likelihood of survival in the event of a ditching.

 

The occurrence

At 1322 Eastern Standard Time,[1] on 29 January 2020, a Cessna Aircraft Company[2] (Cessna) U206G aircraft, registered VH-AEE (AEE) and operated by Air Fraser Island, was being used for emergency procedure training at a beach aircraft landing area (ALA), south of Happy Valley, Fraser Island, Queensland (Figure 1). There were two pilots onboard, including a trainee pilot (trainee), who had just commenced flying with the company. The trainee was seated on the left and was flying the aircraft.

Figure 1: Accident location

Accident location

Source: Google Earth annotated by ATSB

The crew were simulating failure of the left main wheel brake during the landing phase. Just after the aircraft touched down, the trainee heard a snapping noise and the aircraft immediately veered left, towards the sea. The training pilot reported that, on taking control of the aircraft, their[3] rudder pedals were ‘lying on the floor’. However, there was no change in the aircraft’s pitch or bank attitude, as would be expected if a major component of the landing gear had failed.

The training pilot immediately applied full power to conduct a go-around. The aircraft lifted off just before the water’s edge and struck a number of waves as it began to climb. The trainee advised that full aileron deflection was required to keep the wings level. The aircraft continued to climb to a height where the training pilot felt comfortable. They then lowered the nose to gain airspeed and reduced the flap, one stage at a time, to 20˚. The training pilot advised that as the airspeed increased above 70 kt they encountered difficulties controlling the aircraft’s roll, despite having full aileron deflection, so they reduced the power to maintain around 65–70 kt. About 150 m from the shore, they turned the aircraft north to parallel the beach. At that stage, the aircraft was maintaining a height of 150–300 ft above the water.

Both pilots then began to troubleshoot the control issues and identified that the flaps had raised symmetrically, and the rudder was jammed and fully deflected to the left. That control position resulted in significant uncoordinated flight (sideslip) to maintain control of the aircraft.

The training pilot advised the trainee that they were going to land back on the beach however, a short time later, estimated to be about 1.5 minutes after commencement of the go‑around, the engine stopped. The trainee advised there was about 5–6 seconds before the aircraft contacted the water. The training pilot had time to lower the nose and change fuel tanks from the right to the left tank, but not enough time to attempt to restart the engine.

After hitting the water, the aircraft remained upright, and the cabin quickly began to fill with water. Both pilots undid their seatbelts and the trainee tried unsuccessfully to open the single front pilot door (see the section titled Emergency egress in the U206). When the door could not be opened, the training pilot climbed over the seats into the rear cabin, kicked the cargo door to force it open, and then tried unsuccessfully to locate the trainee pilot in the aircraft. The training pilot then exited the aircraft via the cargo door.

Once outside, the training pilot could not locate the trainee so they re-entered the aircraft, which was then three quarters submerged. As the trainee could not be located, they exited a second time taking hold of a life jacket as it floated past. During this time, the trainee had opened and climbed out the pilot door window.

The training pilot then observed the trainee on the other side of the aircraft and after making them swim around the aircraft, put the life jacket on them. The training pilot subsequently put their arm through the life jacket and they both started swimming back to shore. They were met by a paramedic from the Happy Valley ambulance station who had entered the water to assist them to shore. Both pilots suffered minor injuries and the aircraft was destroyed (Figure 2).

It was reported that the aircraft’s nosewheel leg was found on the beach on the afternoon of the accident, approximately half-way between where the go‑around commenced and where the aircraft collided with water. The aircraft, without the engine, washed up on the beach the morning after the accident. At the time of writing, the engine had not been recovered (Figure 2).

Figure 2: VH-AEE on the beach at Fraser Island

VH-AEE on the beach at Fraser Island

Source: Operator

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours.
  2. The current type certificate holder is Textron Aviation.
  3. Gender-neutral plural pronouns are used throughout the report to refer to an individual (i.e. they, them and their)

Context

Flight crew

The training pilot held a Commercial Pilot (Aeroplane) Licence with a Class 1 Aviation Medical Certificate. They had accrued over 10,200 hours of which around 5,000 hours were accumulated in the Cessna 206. At the time of the accident, they had been awake for around nine hours and advised feeling ‘fine’ on the day.

The trainee held a Commercial Pilot (Aeroplane) Licence with a Class 1 Aviation Medical Certificate. They had accrued around 500 hours flying. At the time of the accident, they had been awake for about nine hours and had self-assessed their fatigue level at ‘2: very lively’.[4]They advised that as part of their training they had completed the theory section of the emergency procedures training detailed in Civil Aviation Orders 20.11. They had previously been operating as a ground crew member on Fraser Island for the operator for several months and were proficient in the emergency procedure briefing for the aircraft and the use of life jackets.

Aircraft information

General details

The Cessna U206G is a single engine, six seat, high wing aircraft with fixed undercarriage. It is powered by a Teledyne-Continental Motors six-cylinder, horizontally opposed, fuel-injected piston engine with a constant speed propeller. The aircraft had modifications to improve the short take‑off and landing (STOL) capabilities.

AEE was manufactured in the United States in 1979 and first registered in Australia in the same year. The aircraft was maintained in accordance with the Civil Aviation Safety Authority (CASA) maintenance schedule, which required a periodic inspection every 100 hours or twelve months, whichever came first. It had undergone a periodic inspection on the 14 January 2020 and had a valid maintenance release. At the time of this inspection, the aircraft had accumulated about 13,725 hours in service. The operator advised they had purchased the aircraft two weeks prior to the occurrence.

Fuel system

The fuel system consists of left and right wing-mounted fuel tanks, which feed into separate fuel reservoir tanks. The pilot uses the fuel selector to select fuel from either the left or right reservoir tank. The fuel then passes from the selected reservoir tank into the engine through an auxiliary fuel pump, fuel strainer, engine driven fuel pump and fuel control unit.

The pilot operating handbook stated that, with a quarter tank or less, ‘prolonged uncoordinated flight such as slips or skids can uncover the fuel tank outlets, causing fuel starvation and engine stoppage’. This can occur with uncoordinated flight in excess of one minute.

The pilots reported they had departed Sunshine Coast Airport that morning with full fuel tanks. The trainee reported they had conducted approximately 1.5 hours flying before arriving at Hervey Bay Airport. The training pilot advised they had departed Hervey Bay Airport at approximately 1200. The accident occurred at approximately 1322. The training pilot reported that they had been changing fuel tanks every half hour. While the specific amount of fuel at the time of the accident could not be determined, based on the described flight sequences it is likely that each tank was about one third full.

Weight and balance

The aircraft was within the weight and balance limits at all stages of the flight.

Steering and brake system

The rudder pedals of both control positions are interconnected by torque tubes. The nose wheel steering system links the rudder pedals to the nose wheel steering arm, through a spring‑loaded steering bungee. This allows steering control on the ground using the rudder pedals and brakes. The steering bungee limits the turning of the nose wheel to 15-20°. Additionally, the nose wheel is locked straight ahead when there is no weight on the wheel.

The rudder system is also connected to the rudder pedals through the torque tubes. The torque tubes connect directly to the rudder via cables, and to a steering bellcrank, via pushrods, to form a closed loop system.

The brake system consists of a single disc, which has a hydraulically actuated brake, on each main landing gear wheel. The brake is operated by pressing the top of the rudder pedal. The right‑seat brakes are connected to the left-seat brakes by torque tubes located inside the rudder pedal torque tubes. Hence, applying the right brake on the right-seat pedal moves the right brake on the left-seat pedal, which then actuates the right brake master cylinder.

Stowable right-side pedals were an option on some models however, AEE had standard rudder pedals installed.

Damage to aircraft during accident sequence

While the ATSB did not attend the accident site, a review of supplied images identified the following damage to the nose landing gear area (Figure 3 and Figure 4):

  • the nose wheel assembly had detached at the upper strut assembly and the steering bungee had separated
  • the drag link had fractured at both ends
  • both lower trunnion braces had fractured at their attachments
  • the fuel line to the fuel strainer had fractured and fuel strainer bowl was missing.

From the photographs of the aircraft, all fractures appeared to be overstress failures with no evidence of pre-existing damage. However, it could not be determined which failure occurred first.

The rudder cables were also found to be intact and connected at both the forward and aft cable ends.

Figure 3 : Nose landing gear area (image rotated 180˚) and exemplar C206 nose landing gear area

Nose landing gear area (image rotated 180˚) and exemplar C206 nose landing gear area

Source: Supplied, annotated by ATSB

Figure 4: Nose landing gear leg and front of aircraft showing the main fuel line (image rotated 180˚)  

Nose landing gear leg and front of aircraft showing the main fuel line (image rotated 180˚)

Source: Supplied, annotated by ATSB

Recorded information 

The aircraft was not fitted with a recording device, nor was it required to be. A witness supplied video footage of the final portion of the flight. It showed that the aircraft was maintaining level flight before it suddenly lost altitude, which was consistent with both pilots’ recollection of events. It also showed the aircraft initially floated upright on the sea surface, which most likely assisted the pilots to evacuate the aircraft.

Weather conditions

The graphical area forecast for the area indicated visibility was greater than 10 km with scattered[5] cloud above 2,000 ft. The terminal area forecast for Hervey Bay, about 31 km west of the Happy Valley ALA, indicated the wind was from the east-north-east at 8 kt. The supplied video footage showed clear skies with a light sea chop. The training pilot advised the ocean was flat, with 1.2 m sets of waves with no wind. The current was running along the beach, from north to south.

Beach landing area

The operator used the criteria specified in Civil Aviation Advisory Publication 92-1(1) Guidelines for aeroplane landing areas to establish ALAs at various locations on the eastern beach on Fraser Island. These were set up, on the day, by trained ground crew. The pilots reported that the ALA was low on the beach with firm, hard sand. The ATSB did not attend the ALA after the accident and could not verify its condition.

Operator training

The operator regularly conducted sightseeing and passenger transfer flights from different locations along the eastern beach at Fraser Island. Their operations manual required that a passenger briefing be conducted prior to every passenger flight. This was to include the use of life jackets along with the location of, and the procedure to operate the emergency exit.

The operations manual had a section which outlined the training for the ground handling personnel. This section required that ground personnel be proficient in the use of all emergency exits in aircraft used in beach operations.

Newly employed pilots were required to complete pilot induction training, which included at least 15 hours of training in operating on the beach. In addition, pilots were required to undergo a beach-operations check every 90 days and a six-monthly route check.

The operator had a section in their operations manual which outlined their pilot training syllabus, covering all aspects of training. In the pilot induction training section, the syllabus specified that, along with other competencies, brake failure and asymmetric braking would be covered during the theory training, with no mention of simulated brake failure training in the practical syllabus. Despite this, the operator advised they always conducted simulated brake failures on the beach during the practical flying training. There was no information in the operations manual on how the brake failure simulation was to be conducted.

The operator advised they had devised their own method for brake failure training. To simulate the brake failure, after landing and with all three wheels on the ground, the flying pilot would apply full rudder on the side they were simulating as failed and then use the opposite brake to maintain directional control. That is, a simulated left brake failure required full deflection of left rudder pedal and the use of right brake to slow the aircraft and control direction and vice versa for simulation of right brake failure. The training pilot advised that they used this method, as the turning force associated with full brake application on one side was greater that the turning force created by the rudder and could result in the aircraft running off the side of the runway.

CASA had approved the operator’s operations manual, which included the operator’s pilot training syllabus. When questioned about the brake failure training being conducted by the operator, CASA stated ‘all pilots are taught basic “asymmetric brake failure recovery techniques” from an early stage in the flying training…’ but advised they had not observed the operator’s brake failure training method in the aircraft. They advised that brake failure training is normally conducted while taxiing rather than the landing phase of flight. CASA also advised that:

Due to the safety risks associated with the simulation of an asymmetric brake condition different training techniques may be used to simulate the failure that mitigate the safety risks, in the same way CASA expects flight training operators to manage the safety risks associated with flight training activities. As there was no guidance in the aircraft flight manual on the simulation of asymmetric brake failure the operator should have included clear guidance and procedures on how such activities were to be conducted.

The operator used Mahindra Airvan 8 (formerly GippsAero GA8 Airvan), Cessna 206 and 172 aircraft and advised that they conducted simulated brake failure training in all three aircraft types.

The ATSB sought Textron Aviation’s (type certificate holder for the Cessna 206) views on this type of simulated brake failure training. In response, they advised that they did not have an opinion about training.

A search of the ATSB database and CASA defect reporting service, between 2000 and 2020, did not identify any brake failures having been reported by the operator.

Effect of simulated brake failure training on nose wheel

In the Cessna 206 and 172, the nose gear steering is designed so the nose wheel is held with zero steering deflection while the gear strut is fully extended, regardless of rudder pedal deflection. Nose wheel steering is only available once the nose strut deflects and then it is only influenced by the steering bungee loads. The application of full rudder pedal deflection on the ground will only result in 15–20° of nosewheel deflection. However, for aircraft with direct nose gear steering linkages, such as the Airvan 8,[6] this could mean that the steering angles on the nose wheel could be much higher.

Aircraft design requirements account for fore/aft and side loads on the nose gear based on towing and tyre friction over a variety of hard surfaces. The friction properties of sand are likely to be low initially. However, if ploughing were allowed to develop the side loads on the nose wheel could be relatively high. For a wheel that can only turn 15–20°, this effect is not likely to develop to any great extent. However, for aircraft with direct steering linkages, the loads may increase significantly.

Differential braking is permitted and designed into the braking system. It does not produce any additional loads on the airframe other than side load on the nose gear, but this would be proportionally low. Therefore, stopping the aircraft with brakes from one wheel of the aircraft would not be damaging.

It was difficult to determine whether the side loads on the nose wheel would exceed the design requirements in the Airvan 8. As this was not the aircraft type involved in the accident, further consideration of this aspect was outside the scope of the investigation.

Operator training on accident flight

The training being conducted at the beach landing area consisted of flapless landings and simulated brake failures during landing. The crew advised that, as there was very little wind, they were taking off and climbing to 500 ft before conducting a teardrop turn to land back on the ALA in the opposite direction. They were conducting flapless landings when landing to the north and simulating a brake failure during the landing to the south. They advised they had conducted at least five simulated brake failure landings that day, with no problems encountered.

Operator’s safety management system

While not required by CASA, the operator had begun to introduce a safety management system (SMS) into their organisation in about 2013. This was incorporated into their operations manual which was divided into sections including one on the SMS and a section on specialised operations. The SMS section included procedures for a hazard identification process and included the statement ‘hazards can only be mitigated and controlled if their existence is known’.

The specialised operations section included information and procedures for beach operations. It identified that, due to operation in the harsh beach environment, special attention should be paid to the brakes in the pre-flight inspection. Despite this special attention and additional regular brake failure training, the operator had not identified brake failures as a hazard in their hazard register. CASA had approved the operations manual incorporating the SMS in 2015. However, they had not identified that the hazard register did not identify this aspect.

Go-around decision

The approach and touch down on the incident landing were reported to have been normal. The trainee pilot advised that, as they applied left rudder, but before applying the right brake, there was a snapping noise and the aircraft veered left. The training pilot advised that the aircraft veered left between 15–20˚.

They immediately called out ‘taking over’ and assumed control of the aircraft, with the trainee pilot removing their hands and feet from the flight controls. The training pilot assessed that their rudder pedals had collapsed forward, so they had neither rudder nor brake authority. They decided that, as they were heading for the water, which was about 40‑50 m away, and the aircraft was still moving at approximately 50–60 kt, the safest option was to apply full power and conduct a go‑around.

The trainee pilot stated that if they had continued on the ground ‘it would not have been a smooth impact’.

Federal Aviation Administration guidance

The Federal Aviation Administration’s (FAA) publication The art of aeronautical decision-making advises that aviation decision making can be broken down into three parts - to perceive, process and perform.

The FAA publication Airplane flying handbook Chapter 17 Emergency procedures advises that a pilot takes about 4 seconds to perceive and react to an emergency situation. In addition, ‘there are several factors that may interfere with a pilot’s ability to act promptly and properly when faced with an emergency’. These are listed as:

  • reluctance to accept the emergency situation
  • desire to save the airplane
  • undue concern about getting hurt.

It goes on to advise:

A pilot who is faced with an emergency landing in terrain that makes extensive airplane damage inevitable should keep in mind that the avoidance of crash injuries is largely a matter of: (1) keeping the vital structure (cabin area) relatively intact by using dispensable structure (i.e., wings, landing gear, fuselage bottom) to absorb the violence of the stopping process before it affects the occupants (2) avoiding forceful bodily contact with interior structure.

Emergency egress in the U206

The U206[7] has a door adjacent to the left pilot’s seat and a double clamshell cargo/cabin door in the passenger compartment on the right, adjacent to the second and third seat rows (Figure 5).

Figure 5: Cessna U206 showing location of pilot door and double clamshell cargo/cabin door

Cessna U206 showing location of pilot door and double clamshell cargo/cabin door

Source: TSB investigation report A18W0129, adapted by ATSB to match occurrence aircraft 

Operation of rear cargo doors

The forward door of the rear double cargo doors must be opened first to allow the aft door to open (Figure 7). The forward door handle is accessible for passengers in the middle row seats and is difficult to reach by passengers in the back-row seats. The forward door handle has three positions:

  • when the lever is horizontal (with the lever facing forward), the door is locked
  • turned clockwise 90° to the vertical position, the door is closed
  • turned clockwise another 30°, the door is open.

When the flaps are extended, the front half of the clamshell cargo door is blocked by the flap and can only be opened approximately 8 cm (Figure 6).

Figure 6: Cessna U206 with door unable to be opened more than 8 cm when flap is extended

Cessna U206 with door unable to be opened more than 8 cm when flap is extended

Source: TSB investigation report A18W0129, annotated by ATSB 

A red lever, mounted in the aft door leading edge, is used to unlatch the aft door (see Figure 7: Cessna 206 forward cargo door open showing red lever activated on the leading edge of rear door). However, this lever is in line with the backrest of the right middle row seat. As such, it is difficult to reach for the passenger occupying the middle seat and is again difficult to operate by passengers in the back-row seats.

In addition, when the red lever in the leading edge of the aft door, is lowered to the open position, it strikes the slightly open forward door, which prevents the aft door from opening. The lever must therefore be restowed before opening the aft door, being mindful that the aft door latch does not re-engage.

A service bulletin was subsequently released by Cessna to improve the red lever operation so that the lever automatically restowed (see Cessna service bulletin SEB91-4 Cargo door latch improvement in Australian requirements). Having to keep the forward door open to operate the lever in the forward edge of the aft door, adds to the difficulty of the procedure, especially when attempting to open the doors from the rear seats.

Figure 7: Cessna 206 forward cargo door open showing red lever activated on the leading edge of rear door

Cessna 206 forward cargo door open showing red lever activated on the leading edge of rear door

This image shows an aircraft where service bulletin SEB91-4 has not been incorporated and the red handle does not retract automatically. Before the door can be opened, the red lever is required to be restowed without the door relatching. This is not indicative of the accident aircraft.
Source: TSB investigation report A18W0129, annotated by ATSB

In addition, when the doors on the aircraft are locked from the inside, neither the front nor the rear cargo door can be opened from the outside.

Emergency Procedures

The pilot operating handbook (POH) emergency procedures section provided checklist and amplified recommended actions to be taken in the event of an abnormal situation. In the ‘forced landings’ section, the procedure for ditching stated that flaps were to be extended to 40˚. In addition, it noted ‘evacuate through the cabin doors. If necessary, open window and flood cabin to equalise pressure so doors can be opened’.

There was no reference in this section to warn that the cargo door will be blocked if the flaps are extended. The procedures for other forced landings, with or without engine power, also stated that the flaps were to be extended to 40°. Again, there was no reference in that section to warn that the cargo door will be blocked if the flaps are extended.

The amplified procedures section contained a brief description of the ‘cargo door emergency exit’, which included:

if the wing flaps are extended, open the doors in accordance with the instructions shown on the placard (Figure 8) which is mounted on the forward cargo door.

Figure 8: Cargo door emergency exit placard

Cargo door emergency exit placard

Step 4 is not required in aircraft where Cessna service bulletin SEB91-4 has been incorporated.

Source: Cessna 206 pilot operating handbook

Federal Aviation Administration certification requirements

The Cessna 206 was first certified in 1963 under the United States (US) Federal Aviation Administration (FAA) Civil Aviation Regulation Part 3. Section 3.387 which stated:

Closed cabin airplanes carrying more than 5 persons shall be provided with emergency exits consisting of movable windows or panels or of additional doors which provide a clear and unobstructed opening….The exits shall be readily accessible, shall not require exceptional agility of a person using them….The method of opening shall be simple and obvious, and the exits shall be so arranged and marked as to be readily located and operated even in darkness.

There have been a number of revisions made to this standard over the years however, once an aircraft has been certified, the design standard under which it was certified continues to apply.

Australian requirements

In 1988, the Civil Aviation Authority (CAA),[8] released an airworthiness directive AD/Cessna 206/47 that required improved placarding of Cessna 206 emergency exits. Cessna subsequently released service bulletin SEB91-4 Cargo door latch improvement in March 1991, which recommended modifying the handle in the rear door half to include a spring to ensure that the handle would return to the stowed position.

That same year, the CAA issued AD/Cessna 206/47 amendment 2, which allowed SEB91-4 to be an alternate means of compliance to the required placards. In 2011, CASA subsequently issued amendment 3 to AD/Cessna 206/47 which clarified which 206 models the AD applied to, as SEB91-4 had been incorporated at manufacture in some models and other models did not have the cargo door, however, SEB91-4 remained as an alternate means of compliance. AEE complied with this AD.

Transport Safety Board of Canada

In 2018, the Transport Safety Board of Canada (TSB) investigated a collision with water involving a float-equipped U206 (A18W0129). In this occurrence, the aircraft inverted upon impact and became submerged. The pilot and one passenger escaped through the forward door window. Three other passengers survived the impact and were found with their seatbelts undone, however, they did not escape the aircraft and subsequently drowned.

The TSB report noted ‘the rear double cargo doors have been identified as a risk to passengers in emergency situations for many years’. Further, the report documented some of the work which had been conducted to address the risk associated with the design of the cargo door, including:

  • In 1991, Cessna issued Service Bulletin SEB91-4 which provided a service kit to incorporate a spring assembly to automatically retract the handle on the leading edge of the rear half of the door to allow it to pass the front half of the door. It also included improved placarding to clarify the instructions on how to open the door in an emergency.
  • In 1998, Cessna resumed manufacturing the 206 with the 206H. This was certified under the US Federal Aviation Regulations[9] 23.807 legislation. Transport Canada determined that the 206H did not meet the requirements of the legislation, as the rear cargo door could not be considered an emergency exit as the means of opening was not ‘simple and obvious’. As a result of that assessment Transport Canada reduced the number of occupants permitted in the aircraft to five.
  • Between 1999 and 2003, Transport Canada, the FAA and Cessna worked on a design change to address this issue, which could be applied to the 206H, and retrofitted to the previous 206 models. No acceptable solution was found, and the matter was discontinued.
  • In 2005, Transport Canada proposed an airworthiness directive to address the issue of different models allowing different numbers of occupants, despite having the same design. However, following industry consultation, the proposal was withdrawn.

In response to the 2018 Canadian occurrence, TSB released an Aviation Safety Advisory A18W0129-D1-A1 Cessna 206 emergency exit – blocked double cargo door with flaps extended, ‘to bring attention to the significant safety issue involving Cessna 206 series aircraft fitted with double cargo doors’.

Other action taken by regulatory bodies

November 1996

As a safety action in response to an accident in a Cessna U206 where a pilot and three passengers drowned when they could not escape the aircraft after it capsized during the take‑off run (A96Q0114), Transport Canada (TC) wrote to the FAA to express concern about the adequacy of the emergency exit in the Cessna U206 aircraft. In the letter, TC strongly recommended that should production of the U206 resume:

…the FAA require Cessna to incorporate a solution which eliminates the interference problem between the flaps and the emergency exit…

No action was taken by FAA in response to this letter.

March 2020

FAA released an Airworthiness Concern Sheet NOTC0041 asking for information from people who had experience using the 206 cargo door. They subsequently advised that 95 per cent of the respondents did not want action taken on the issue. They also advised that their research had shown that the biggest positive impact to safety was ensuring that pilots briefed their passengers on how to use the door. No further action was planned.

April 2020

Transport Canada released Airworthiness Directive CF 2020-10 which limited the number of seats in Cessna 206 aircraft to five, in other than the 206H and T206H models,[10] and aircraft which had not been modified to FAA supplemental type certificate (STC) SA1470GL (see Right side door below). Additionally, if passengers were seated in the rear row, they must have demonstrated the capability to operate the cargo door on the day of the flight. They must also have been briefed that the cargo doors were only to be used in an emergency if the front left cabin door was obstructed.

The same month, the Civil Aviation Authority of New Zealand released Continuing Airworthiness Notice 25-003 to alert operators of Cessna 206s in New Zealand to CF 2020-10. 

August 2020

The European Union Aviation Safety Agency (EASA) released a Safety information bulletin 2020‑16 to alert European operators of Cessna 206s to CF 2020-10.

Cessna 206 exit modifications

Several organisations have developed solutions to ensure the cargo door can be opened easily in the event of an emergency. Some of these solutions have received approvals from the FAA and are commercially available. Some of these include:

Right side door

FAA STC SA1470GL approves a right-side door in the front cabin, which allows both egress for the front right passenger and emergency egress from the centre row seats in the cabin.

Installation of the Split Forward Cargo Door Window

Transport Canada have approved supplemental type certificate SA20-34. This allows for the forward cargo door to be split allowing the door to open when the flap is extended (Figure 9). This has also been approved in Europe under EASA STC 10074631 and the FAA under STC SA04550NY.

Figure 9: Cessna 206 split cargo/cabin door

Cessna 206 split cargo/cabin door

Source: Coast Dog Aviation, annotated by ATSB

PDQ emergency egress system

At the time of writing this report, the manufacturer reported that the FAA were in the final stages of approval for supplemental type certificate ST02309AK. Under this approval a handle is installed which, when activated, allows the front cargo door to be released (Figure 10). This allows access to the red lever and the aft cargo door can then be opened.

Figure 10: Cessna U206 with emergency egress system

Figure 10: Cessna U206 with emergency egress system

 Source: Airframe Innovations

Similar occurrences

The ATSB conducted a search of aviation investigation databases, and other sources, to identify accidents involving Cessna 206 aircraft, where the impact was likely survivable however, difficulties opening the cargo door resulted in significant delays during the emergency egress, or the cargo door had not been opened. The following accidents were identified: 

Table 1: Similar occurrences

YearInjuriesSummaryLink
2018

5 persons on board (pob)

3 fatalities

During a landing on water, a float equipped U206G nosed over. The pilot and one passenger survived. The three remaining passengers, who received no injuries during the accident, were unable to escape the fuselage and drowned. The passengers were found with their seatbelts unfastened but had not opened the cargo door, which was blocked by 20˚ flap.

TSB

A180129

2012

5 pob

1 fatality

During a landing on water, the float equipped 206 nosed over. The flaps were extended blocking the cargo door. The pilot and three passengers escaped by bending the cargo door. The fourth passenger, found in her seat with the seatbelt on, likely died through injuries caused by the accident.

NTSB

ANC12FA073

2010

5 pob

4 fatalities

During cruise, the engine failed, and the pilot conducted a ditching into Lake Michigan. The pilot did not lower the flap; however, the cargo door had not been opened. The pilot survived. Two passengers were found outside the aircraft however, their life jackets had failed. Of the two passengers found inside the cabin, one had removed their seatbelt.NTSB CEN10FA465
2003

2 pob

1 fatality

During the landing on water, the float equipped 206 flipped over. Contrary to instructions provided by the pilot, the passenger made their way to the rear of the aircraft, was unable to exit, and drowned.TSB aviation occurrence A03Q0083
2001

5 pob

1 fatality

During the landing, the aircraft collided with a hole in the runway, nosed over and slid into a river. The pilot and three passengers escaped with minor injuries, however, one of the passengers drowned trying to escape the aircraft.Aviation Safety Network Wikibase Occurrence 45813
1997

3 pob

2 fatalities

During the landing on water, the float‑equipped aircraft flipped as the landing gear had not been retracted. Two passengers were unable to exit the aircraft and drowned. The door handle was found in the upright closed position.TSB Aviation investigation report  A97C0090
1996

6 pob

4 fatalities

During the take-off on water, the aircraft capsized. The pilot and three passengers drowned in the rear of the aircraft, when the pilot could not open the cargo door. Two passengers escaped through the pilot door. There was evidence that an adult had attempted to open the cargo door.TSB Aviation investigation report A96Q0114
1989

5 pob

4 fatalities

During the landing on water, the float equipped 206 nosed over. The flaps had been extended to 20˚ and then raised to 10° during the accident sequence to prevent the flaps from blocking the cargo door. The pilot survived, however four passengers drowned when the cargo doors could not be opened.[1]Aircraft Accident Investigation Board – Norway 06/99
1985

5 pob

3 fatalities

During the landing on a dam, the float‑equipped 206 nosed over as the landing gear had not been retracted. The pilot and one passenger survived, but three passengers were fatally injured.ATSB 198503550

In March 1999, at Pitt Island, New Zealand, a Cessna 206 had an engine failure and ditched in the sea. The pilot was aware of the issue with deployed flap blocking the rear doors and ditched the aircraft with the flaps retracted. Consequently, all the occupants escaped from the aircraft and swam to shore. (Transport Accident Investigation Commission New Zealand 99‑001)

__________

  1. The ATSB uses the Samn-Perelli fatigue scale from 1 (Fully alert. Wide awake. Extremely peppy) to 7 (Completely exhausted. Unable to function effectively. Ready to drop).
  2. Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – scattered indicates that cloud is covering between a quarter and a half of the sky.
  3. During the operator’s described simulated brake failure training, it was assumed that the initial touchdown was conducted using the rudder inputs required to keep the aircraft straight.
  4. The U206, TU206 and 206H models are designed with the rear double cargo door.
  5. In July 1995, the Civil Aviation Authority separated into the Civil Aviation Safety Authority and Airservices Australia.
  6. The United States Civil Air Regulations were replaced with the Federal Aviation Regulations on 1 February 1965.
  7. Transport Canada had previously reduced the number of passengers permitted in the 206H and T206H models to 5.

Safety analysis

Introduction

On 29 January 2020, at about 1322, the flight crew of a Cessna U206G aircraft, registered VH‑AEE, were conducting simulated brake failure training on a beach at Fraser Island, Queensland. During the landing roll, directional control was lost, and the training pilot conducted a go-around. While the aircraft was flying parallel to the beach, with flight control issues, the engine stopped, and the aircraft collided with the water. Both pilots escaped the aircraft and swam to shore with minor injuries.

This analysis will examine the sequence of failure in the nose landing gear system, the decision to conduct a go-around and the engine stoppage. Further, it will analyse the brake failure training conducted by the operator and the interaction between the landing flaps and cargo door in the context of emergency egress.

Accident sequence

Both pilots reported having conducted several landings involving simulated brake failure, without incident. On this landing, just after touchdown, and as the left rudder was applied the trainee pilot heard a snapping noise, immediately followed by loss of directional control. Examination of the rudder control system after the occurrence established its continuity. As such, it is likely that a partial failure in the nose gear assembly compromised the interconnected rudder and steering controls. The training pilot reported the rudder was jammed in the full left position and use of the brakes was not possible as the right-seat pedals had collapsed.

Despite the nose landing gear being found on the beach between where the aircraft took off and where the collision occurred, it is likely the nose gear leg did not detach from the aircraft while the aircraft was on the ground as this would probably have resulted in the propeller striking the sand and stopping the engine.

Additionally, as the rudder probably jammed due to the partial failure of the nose gear assembly, if the nose gear detached during the take-off or initial climb, control of the rudder would likely have been restored. However, based on the account of the pilots, this did not happen.

Supplied images showed that the fuel strainer was missing, and the fuel line that fed the strainer was fractured. These components were in the nose gear bay and directly fed the engine fuel system. Loss of fuel supply at this location would have resulted in almost immediate engine stoppage. As the engine continued to provide power for approximately 1‑1.5 minutes after take-off, it is highly probable that the nose gear separated and fractured the fuel line, as the aircraft collided with the water.

Examination of the nose gear fracture surfaces revealed they were consistent with the attachments failing in overstress, with no indication of a pre-existing fault. It could not be established which part of the nose landing gear failed first nor why the training pilot’s rudder pedals were affected as described.

Engine failure and collision with water

The engine, and associated components, were not recovered for examination. However, as neither pilot reported issues with the engine before the accident, it is unlikely there was a coincidental mechanical issue with the engine.

The aircraft departed the Sunshine Coast Airport with full fuel and had been flying for approximately three hours, leaving less than half fuel remaining at the time of the accident. The fuel system could only be operated on one tank at a time. As the aircraft collided with water, the exact quantity of fuel in each tank at the time of the accident could not be confirmed, however if the fuel management had maintained roughly equal quantities of fuel, each tank would have been about one third full.

Following the go-around, the training pilot applied full right aileron to prevent the aircraft from rolling. This resulted in the aircraft being flown in a significantly uncoordinated state (sideslip), with right wing low. The pilot operating handbook stated that, with a quarter tank or less, ‘prolonged uncoordinated flight such as slips or skids can uncover the fuel tank outlets, causing fuel starvation and engine stoppage’. The aircraft was flown in an uncoordinated state for between 1‑1.5 minutes before the engine failed. If the fuel usage had not been equalised then it is possible the right tank contained quarter or less fuel, resulting in fuel starvation to the engine. It is also possible that the magnitude of the required sideslip permitted unporting of the fuel tank outlet at greater than one quarter capacity.

It is also possible, although considered less likely, that the damage to the landing gear in turn damaged the fuel strainer/fuel line during the final stages of the flight, again leading to fuel starvation.

Go-around decision

According to the United States Federal Aviation Administration, the typical time taken to realise there is a problem and react to it, is about 4 seconds. In that time frame, the pilot must perceive the problem, process the alternatives, and perform the selected action.

On this occasion, the decision to commence a go-around was influenced by the aircraft’s deviation towards water with little to no directional control or brake function. Taking into consideration that the flight crew were conducting training for emergency procedures (including multiple go-arounds), there may also have been a greater inclination to commence a go-around. While opting for a go‑around on this occasion was understandable, it resulted in flight over water with significantly reduced aircraft controllability.

The FAA’s guidance for emergency procedures advised that accepting there will be an accident may be the safest option and using the aircraft’s dispensable structure to absorb the ground/water impact forces will most likely reduce injuries. In this case, there was about 40‑50 m from when the pilots perceived they had no braking or directional control, to the water’s edge. Allowing the aircraft to continue to slow and using the aircraft structure to absorb the impact would, in hindsight, most likely have been the safest option.

Operator’s safety management system

The operator had determined that their aircraft were susceptible to brake failures because they were operated regularly on the beach. To mitigate this safety concern the operator ensured the brakes were inspected during the pre-flight inspections and conducted regular simulated brake failure training. However, the concern had not been formally documented in the operator’s hazard register.

The CASA booklet: SMS for aviation-a practical guide stated that if an operator identified a specific risk to their operation, appropriate mitigators should be identified and assessed. A risk analysis should be conducted to ensure the risk, after mitigators are applied, has been reduced to a level that is ‘as low as reasonably practicable’. Not documenting the brake failure hazard in the register was a missed opportunity to both:

  • assess the magnitude of the risk, taking in to account that apparent low likelihood of brake failure actually occurring
  • identify any hazards that simulated brake failure training introduced, including the potential for nose wheel damage.

ATSB assessment of the brake failure training, did not identify excess stresses on the Cessna U206 or 172 nose wheel. However, analysis of the stresses on the nose wheel in the Mahindra Airvan 8, also used by the operator, indicated if the nose wheel were fully deflected and the aircraft encountered soft sand, the additional side loads on the nose wheel system may induce damage.

Emergency egress

When the aircraft collided with the water, the extended flap prevented the front cargo door from opening fully. On this occasion, it is likely that when the training pilot kicked the doors open, the edge of it deformed the partially‑extended (20°) flap sufficiently to allow egress.

More generally, the Cessna U206 pilot’s operating handbook (POH) stated that 40° of flap were to be selected during ditching (and forced landings), creating a greater cargo door obstruction than occurred during this accident. Having the flap extended allows the aircraft to land at a slower speed, which has been shown to improve the chances of surviving a ditching. However, the POH emergency procedures did not identify that such a flap selection also prevents the forward cargo door from fully opening.

That situation may leave pilots unaware of the significant consequences of flap deployment. By contrast, at least one accident report shows that where the pilot has understood this issue and has not extended the flap during a ditching, the passengers have been able to readily exit the aircraft.

The aircraft’s certification criteria required that emergency doors be clear, unobstructed and capable of being opened with a simple and obvious method. This is particularly important in the event of ditching, due to the inherently disorientating nature of underwater egress. The Cessna U206 cargo door requires a number of sequential steps to open, and when the flaps are extended, this process is even more complicated. The inability to open the cargo door in this aircraft type has been shown in numerous accidents to have contributed to passengers being unable to exit the aircraft, resulting in fatalities.

Therefore, although the Cessna U206 with cargo door was certified, the method for opening the cargo door is not simple and in some flap configurations the forward door cannot be opened and therefore does not meet the emergency egress requirements.

Steps have been taken by regulators in an attempt to address the hazard presented by the rear double cargo door design, but to date, they have been ineffective at eliminating it. However, approved modifications are now available that remove the flap/door interference issue, despite this, to date no regulatory action has been taken to mandate the application of one of these modifications or remove the hazard by another means.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the collision with water involving a Cessna Aircraft Company U206G aircraft, VH-AEE, near Happy Valley, Fraser Island, Queensland, on the 29 January 2020.

Contributing factors

  • Following touchdown, during a simulated brake failure exercise, a section of the nose landing gear attachment failed, resulting in the rudder becoming jammed in the full‑left position.
  • A go-around was initiated after directional control was lost on the ground. While there was only a short timeframe to make the decision to abort the landing, it resulted in flight over water with significantly reduced aircraft controllability.
  • It is most likely that fuel starvation led to the engine losing power at a height too low for recovery and the aircraft collided with water.

Other factors that increased risk

  • The 20° flap setting blocked the forward portion of the rear double cargo door, delaying the training pilot’s exit via the cargo door.
  • The Cessna 206 procedure for ditching and forced landing states that the flaps are to be extended to 40°. While that permits the aircraft to land at a slower speed, it also significantly restricts emergency egress via the cargo door. However, there is no warning about that aspect in the ditching or forced landing pilot’s operating handbook emergency procedures. (Safety issue)
  • Cessna 206 aircraft, that feature a rear double cargo door, do not meet the aircraft certification basis for the design of cabin exits. Wing flap extensions beyond 10° will block the forward portion of the rear double cargo door, significantly hampering emergency egress. This has previously resulted in fatalities. (Safety issue)

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Cessna 206 emergency procedures 

Safety Issue number: AO-2020-010-SI-01 

Safety issue description: The Cessna 206 procedure for ditching and forced landing states that the flaps are to be extended to 40°. While that permits the aircraft to land at a slower speed, it also significantly restricts emergency egress via the cargo door. However, there is no warning about that aspect in the ditching or forced landing pilot’s operating handbook emergency procedures.

Cabin exit design criteria (Issue owner: United States Federation Aviation Administration) 

Safety issue number: AO-2020-010-SI-02

Safety issue description: Cessna 206 aircraft that feature a rear double cargo door do not meet the aircraft certification basis for the design of cabin exits. Wing flap extensions beyond 10° will block the forward portion of the rear double cargo door, significantly hampering emergency egress. This has previously resulted in fatalities.

Cabin exit design criteria (Issue owner: Civil Aviation Safety Authority)

Safety issue number: AO-2020-010-SI-02

Safety issue description: Cessna 206 aircraft that feature a rear double cargo door do not meet the aircraft certification basis for the design of cabin exits. Wing flap extensions beyond 10° will block the forward portion of the rear double cargo door, significantly hampering emergency egress. This has previously resulted in fatalities.

Additional safety action by Air Fraser Island

As a result of this accident, the operator has changed their procedures to specify that during emergency procedure training on the beach, no non-company vehicles are permitted to operate within the runway complex (the marked section of beach using bollards and witches hats identifying the area which has been identified as a suitable aircraft landing area.)

The operator has also reassessed the company hazard register and included brake failures.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the flight crew
  • Air Fraser Island
  • Civil Aviation Safety Authority
  • United States Federal Aviation Administration
  • Cessna Aircraft Company – Textron Aviation
  • the insurance company
  • video footage of the accident flight and other photographs
  • Transport Canada
  • Transport Safety Board of Canada.

References

Federal Aviation Administration, Airplane flying handbook FAA-H-8083-3B. US Department of Transportation, Federal Aviation Administration. Available on the FAA website www.faa.gov

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the flight crew
  • Air Fraser Island
  • Civil Aviation Safety Authority
  • Federal Aviation Authority
  • United States National Transportation Safety Bureau
  • Transport Safety Board Canada
  • Textron Aviation

Submissions were received from:

  • Air Fraser Island
  • Civil Aviation Safety Authority
  • Transport Safety Board Canada
  • Textron Aviation

The submissions from those parties were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2021

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2020-010
Occurrence date 29/01/2020
Location Near Happy Valley, Fraser Island
State Queensland
Report release date 08/07/2021
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Minor

Aircraft details

Manufacturer Cessna Aircraft Company
Model U206G
Registration VH-AEE
Serial number U20605226
Aircraft operator Beasts Company
Sector Piston
Operation type Business
Departure point near Happy Valley, Queensland
Destination near Happy Valley, Queensland
Damage Destroyed

Technical Assistance to RAAus - Collision with terrain involving BRM Aero Bristell, 24-8555, Kanangra-Boyd National Park, New South Wales, on 16 December 2019

Summary

On 16 December 2019, a BRM Aero Bristell aircraft, recreational registration 24-8555, collided with terrain in Kanangra-Boyd National Park, near Oberon, New South Wales. The pilot was fatally injured.

In response, Recreational Aviation Australia (RAAus) commenced an investigation into the occurrence and requested technical assistance from the ATSB in the recovery of flight data from two instrumentation units – a Dynon SV-D1000 and Garmin aera 795; both of which were subsequently provided by NSW Police.

The ATSB successfully downloaded data from both devices, including flight path information and aircraft operational parameters. Figures 1 and 2 summarise this information.

Both instrumentation units were returned to NSW Police on 23 June 2020 and a technical report and all recovered data provided to RAAus on 24 June 2020.

With the completion of this work, the ATSB has concluded its involvement in the investigation of this accident. Any further enquiries in relation to the investigation should be directed to Recreational Aviation Australia.

The information contained in this update is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

Figure 1: Flight paths from Garmin and Dynon units

Figure 1: Flight paths from Garmin and Dynon units.
Source: Google Earth, GPS points by ATSB

Source: Google Earth, GPS points by ATSB

Figure 2: Selected flight parameters

Figure 2: Selected flight parameters.
Source: ATSB

Source: ATSB

 

Occurrence summary

Investigation number AE-2020-008
Occurrence date 16/12/2019
Location Kanangra-Boyd National Park
State New South Wales
Report release date 03/07/2020
Report status Final
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer BRM Aero S.R.O.
Model Bristell
Registration 24-8555
Serial number 040/2012
Sector Piston
Operation type Sports Aviation
Departure point Shellharbour, New South Wales
Destination Bathurst, New South Wales
Damage Substantial

Loss of separation involving Boeing 777, N2333U and ATR 72, VH-FVQ, near Sydney Airport, New South Wales, on 22 January 2020

Final report

Report release date: 28/07/2020

Safety summary

What happened

On 22 January 2020, a Boeing 777 was being operated by United Airlines as regular public transport flight UA870 from Sydney, Australia to San Francisco, United States.

At about the same time, a GIE Avions de Transport Régional ATR 72 was being operated by Virgin Australia as regular public transport flight VOZ1153 from Sydney to Tamworth, New South Wales.

Sydney Airport was configured for parallel runway operations, including simultaneous independent departures. VOZ1153 departed from runway 34R to an assigned heading of 350º, just prior to UA870 departing from runway 34L. UA870 was required to maintain runway heading (335º) until reaching 1,500 ft, at which point the aircraft was cleared to turn left and track towards Richmond, northwest of Sydney. However, UA870 climbed straight ahead through to about 2,100 ft and then the aircraft turned to the right about 45º from the required heading, resulting in a loss of separation with VOZ1153. At their closest point of approach, the two aircraft were separated by 1,843 m (about 1.0 NM) laterally and 60 m (about 200 ft) vertically.

Air traffic control detected the loss of separation and issued interventional instructions to both aircraft. The required separation was re-established and both flights continued without further incident.

What the ATSB found

The ATSB found that the UA870 pilot flying was expecting a more simplistic procedure often provided to foreign crew departing Sydney for an oceanic route. The pilot flying then became confused regarding aspects of the flight management computer (FMC) coding generated to represent the actual departure clearance provided. This may have been due to an unfamiliarity with radar transitions from a standard instrument departure to an en route track. This led the pilot flying to incorrectly adjust the FMC prior to engine start, and resulted in the aircraft turning right after departure, bringing it into conflict with VOZ1153.

The pilot flying probably did not effectively communicate the changes made to the FMC to the crew. The FMC departure specific coding was also not effectively cross-checked by the pilot monitoring or relief pilots prior to take-off.

Safety message

The ATSB’s SafetyWatch program highlights broad safety concerns that come out of ATSB investigation findings and from the occurrence data reports by industry. One of these safety concerns is data input errors.

This occurrence illustrates the importance of procedural correctness, effective communication and crew coordination towards the conduct of safe flight operations. Any amendment to the flight management computer, particularly those applicable to the more critical phases of flight (departure and arrival procedures) should always be announced, and then carefully and independently verified by at least one other crew member. The incident also outlines that, when possible, air traffic controllers can potentially further assist foreign crew by proactively factoring the crew’s unfamiliarity when providing airways clearances.

 

The investigation

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope, fact-gathering investigation was conducted in order to produce a short summary report, and allow for greater industry awareness of findings that affect safety and possible safety actions.

The occurrence

On the early afternoon of 22 January 2020, a Boeing 777-300ER (777), registered N2333U, was being operated by United Airlines as regular public transport flight UA870 from Sydney, New South Wales to San Francisco, United States.

At about the same time, a GIE Avions de Transport Régional ATR 72-600 (ATR72), registered VH-FVQ, was being operated by Virgin Australia as regular public transport flight VOZ1153 from Sydney to Tamworth, New South Wales.

The Sydney Airport automatic terminal information service (ATIS)[1] indicated to all crews that parallel runway operations were in progress, including simultaneous independent departures[2] from runways 34L and 34R. The weather was fine, with excellent visibility, no cloud below 10,000 ft and a light wind from the northwest.

The flight crew for flight UA870 consisted of a captain and three first officers. The captain was the pilot flying (PF) and one of the first officers was the pilot monitoring (PM).[3] The remaining first officers occupied the two observers’ seats positioned directly behind the PF and PM on the flight deck.

Sydney air traffic control attempt to facilitate expeditious departures to all aircraft, particularly aircraft transiting over extended distances (oceanic crossings). This regularly involves a clearance via the SYDNEY ONE RADAR (SYD1) standard instrument departure (SID).[4] The PF had operated from Sydney Airport on a number of other occasions. While preparing for departure at the gate, after receiving the ATIS, but prior to receiving their pre-departure clearance, the PF configured the flight management computer (FMC)[5] for the SYD1 based on an expectation from prior experience.

At about 1330 Eastern Summer Time (ESuT),[6] Sydney clearance delivery (SCD) air traffic control (ATC) provided a different pre-departure clearance via VHF radio:

United eight seventy (UA870), delivery, cleared to San Francisco via DIPSO,[7] flight planned route, runway three four left (34L), Richmond five departure, radar transition, climb via SID to five thousand (5,000)…

The PM provided a truncated read back of the clearance to ATC, inadvertently not repeating the radar transition[8] component.

At the same time as the UA870 crew were preparing for their departure, VOZ1153 was cleared to depart via the SYD1 radar SID via runway 34R. This procedure required the ATR72 to maintain a heading of 350º after take-off, until directed otherwise by ATC.

The UA870 crew reviewed the RICHMOND FIVE (RIC5) SID chart (Figure 1). That chart included two distinct caution notes about the initial climb. The more detailed caution stated:

Parallel runway operations - DO NOT TURN RIGHT. Track 335⁰. At 1500 [ft] turn LEFT, track direct RIC NDB [Richmond], then follow transition instruction.

Figure 1: RICHMOND 5 Standard Instrument Departure (SID) from runway 34L

Figure 1: RICHMOND 5 Standard Instrument Departure (SID) from runway 34L.&#13;Source: Jeppesen (via United Airlines flight safety). Annotated by the ATSB.

Source: Jeppesen (via United Airlines flight safety). Annotated by the ATSB.

The PF then re-programmed the FMC, replacing the SYD1 procedure with the RIC5. At this point, the PF reported being unsure regarding the coding specific to the two transition options (radar or Richmond) presented by the FMC.

The radar transition option in the FMC included a deliberate discontinuity[9] (gap) in the waypoint[10] sequence (coding). The discontinuity represented the point where air traffic control would provide radar vectors to facilitate a re-join to the oceanic track (to San Francisco) after the aircraft passed 12 NM from Sydney (see Figure 1).

The PF then closed (removed) the discontinuity.[11] In effect, the PF had removed the pre-programmed radar transition procedure, which meant that after the 1,500 ft left turn, the next waypoint on the route was DIPSO, not 12 NM Sydney. The PF recalled communicating removing the discontinuity to the PM, but it was not acknowledged by the PM. The PM did not recall hearing about the coding change.

Later in the pre-departure preparation, the PM reported verifying the new departure in the FMC using the summary route (RTE) page. However, the PM did not review it using the more detailed LEGS page (see Flight management computer discontinuities).

While taxiing to the runway for take-off, the PM recalled that when completing the departure review[12] with the PF, they noted the FMC RTE page read:

Runway 34L, Richmond Five (RIC5), no transition

At 1421:41 the tower controller for runway 34R cleared VOZ1153 for take-off, and 42 seconds later, the tower controller for runway 34L cleared UA870 for take-off.

At 1422:29, VOZ1153 departed runway 34R. About 35 seconds later, as VOZ1153 was climbing through 1,500 ft, UA870 departed runway 34L. (The runway 34L threshold is about 1,000 m north [ahead] of the runway 34R threshold [see Figure 1].)

At about 1424:06, climbing through 1,417 ft, the UA870 crew were instructed to contact Sydney departures control.

At 1424:33, as UA870 was climbing through 2,120 ft, the Sydney departures controller detected that the aircraft was turning right and instructed the crew to immediately turn left, to a heading of 270°. The flight crew had also identified the incorrect turn to the right. The departures controller then issued a separate interventional instruction to VOZ1153 to turn right immediately, to a heading of 090°.

On receiving their instruction, the two UA870 pilots in the observers’ seats identified the traffic (VOZ1153) visually (right-hand observer) and via the traffic alert and collision avoidance system (TCAS)[13] display (left-hand observer).

Recorded flight data showed that the UA870 autopilot was disengaged about 3 seconds after the interventional instruction to UA870 was received, at an altitude of 2,160 ft. Due to the momentum of the 777, the aircraft continued turning right through a further 5 degrees to heading 018º, prior to the PF manually reversing the turn back to the left. The minimum distance between the two aircraft was 1.0 NM laterally and 200 ft vertically (Figure 2).

Both aircraft continued flight to their respective destinations without further incident.

Figure 2: Aircraft tracks showing closest point of approach

Figure 2: Aircraft tracks showing closest point of approach.&#13;Source: Google Earth overlaid with United Airlines and Virgin Australia data. Annotated by the ATSB.

Source: Google Earth overlaid with United Airlines and Virgin Australia data. Annotated by the ATSB.

Context

Flight crew

The flight crew of UA870 was augmented[14] with two cruise in-flight relief pilots (also first officers), due to the duration of the flight and the operator’s flight crew fatigue management framework. Neither the PM or PF reported being fatigued or tired at the time of the incident. Both relief pilots reported minor tiredness at the time of the incident. All the flight crew reported having achieved two separate periods of sleep during their layover in Sydney. UA870 flight crew experience is summarised in General details.

Transition routes

SIDs are designed to allow pilots to navigate away from an airport with minimal radio communication with ATC (departures control). Charted transition routes facilitate the transition from the end of a basic SID to a location in the en route airways structure. In this case, the radar transition allowed for UA870 to join their route to San Francisco at waypoint DIPSO after departing Sydney via the RIC5 procedure.

Normally a transition route includes a course, altitude requirements and distances between waypoints along the transition. Some SIDs have multiple transitions. The Richmond 5 SID had two transition routes.

The radar transition segment relied on the Sydney departures controller providing radar vectors for the aircraft to follow back to the east, after the aircraft passed the ‘12 NM Sydney’ point, but prior to Richmond. The aircraft would then re-join their flight planned (oceanic) route to San Francisco. In the event that a radar vector was not provided by 12 NM northwest of Sydney, the autopilot would simply maintain the aircraft’s heading from that point, until a vector was provided to the crew, or the crew amended the FMC route. The procedure required the aircraft track to initially track to the west to allow for separation with aircraft departing simultaneously from the parallel runway (34R).

The presence of a route discontinuity is unusual in a departure or arrival procedure, but it serves to highlight to the flight crew that at the point of discontinuity, a further clearance or direction is required from ATC.

Flight management computer discontinuities

The PF uploaded the flight plan to the FMC via satellite datalink. Procedurally, the crew (usually the PF), then manually entered the SID based on the departure clearance provided, which is contained within the FMC memory.[15] The majority of procedural SIDs could then be joined to the uploaded route by removing the discontinuity created between the end waypoint defining the departure procedure and the first waypoint of the main route to their destination. This was the normal process dictated by the operator’s procedures, where it was emphasised that for most departures the remaining FMC discontinuities should be rectified (removed) using the FMC legs (LEGS) page (Figure 3).

Guidance was also provided that this should not be completed in isolation from the rest of the crew.

The PF reported some confusion with the coding specific to the radar transition component of the RIC5 SID. That is, misunderstanding the necessity for the pre-programmed discontinuity as it was depicted by the FMC, which represented the radar transition segment during which ATC would provide radar vectors.

A discontinuity can be viewed by either the FMC LEGS page or route (RTE) page. The RTE page is a summary page generated displaying significant waypoints and airways (routes) that, in sequence, define the coded route the aircraft is programmed to fly via either the autopilot, if engaged or the flight director, if flying manually. The RTE page does not contain the same level of detail contained via the FMC LEGS page (Figure 3).

The operator’s supplementary procedures regarding the FMC setup prior to departure also included the following warning:

Do not use the RTE page to repair discontinuities resulting from SID entries. Critical changes in departure ground track may result.

Figure 3: Example of a route discontinuity displayed via the B777 FMC LEGS page

Figure 3: Example of a route discontinuity displayed via the B777 FMC LEGS page.&#13;Source: Boeing B777 supplementary procedures (via United Airlines)

Source: Boeing B777 supplementary procedures (via United Airlines)

United Airlines procedures

The operator’s procedural documentation included guidance and direction specific to departure preparation. They detailed the PF and PM tasks and responsibilities, including the requirement to conduct a pre-departure briefing. The crew were also required to conduct a comprehensive departure review, immediately prior to take-off, which included a final confirmation of the FMC departure route setup. These procedures highlighted the importance of verbalisation, independent review and cross-checking.

The operator also provided guidance specific to Sydney Airport departures, including tailored charts illustrating the RIC5 SID (detailing the radar transition procedure), specifically the requirement to not turn right.

The operator’s procedures also mandated that relief pilots were to remain at their designated stations (observer’s seats) on the flight deck from the commencement of the departure briefing until the aircraft was above flight level 180.[16] More generally, a number of important support duties were also defined for relief pilots including active participation in crew briefings (departure briefing and review) and a specific requirement to ensure compliance with clearances.

Air traffic control information

Separation standards[17] are used by air traffic controllers to manage air traffic safely. They refer to the minimum horizontal and/or vertical distance, or time apart, that aircraft operating in controlled airspace must maintain. When the separation between two or more aircraft is less than the standard, there is a loss of separation.

A surveillance separation standard is used when aircraft position information is derived from air traffic services’ surveillance systems (including radar). When aircraft are operating inside terminal area airspace, such as Sydney, controllers must maintain a minimum separation between aircraft of 3 NM (5.6 km) laterally or 1,000 ft vertically.

A runway separation standard is applied for aircraft taking off from parallel runways. Following take-off, separation is facilitated visually until a surveillance (radar) or vertical separation standard exists. Aerodrome controllers (ADCs) may reduce the radar separation minima in the vicinity of aerodromes when adequate separation can be provided using visual observation and each aircraft is continuously visible to the ADC. However, ADCs are not permitted to provide visual separation if the projected flight paths of the aircraft conflict.

When a significant loss of separation occurs, air traffic control is required to issue a safety alert[18] to notify pilots of information that is of a time-sensitive and safety-critical nature. It is important pilots understand the critical nature of these instructions and respond in a timely manner to ensure the safe conduct of flight.[19]

Traffic alert and collision avoidance system

Modern high-capacity transport aircraft such as the 777 and ATR72 are required to be equipped with an advanced traffic alert and collision avoidance system (TCAS).[20] TCAS is designed to prevent mid-air collisions between aircraft. TCAS operates independently of ATC by using on-board surveillance capability to detect other transponder-equipped traffic and provides:

  • Traffic display (proximate traffic) and traffic advisories (TA) for situational awareness of relatively close aircraft
  • Resolution advisories (RA) for very close aircraft with vertical guidance to resolve the threat.

Both TA and RA are generated based on the projected closest point of approach (CPA) or miss distance and the time to co-altitude (TAU). In general, the thresholds (time and distance) for CPA and TAU increase as altitude increases.

All RA are inhibited when below 1,000 ft (+/- 100) above ground level (AGL) and all TCAS aural alerts are inhibited when below 500 ft (+/- 100).[21] This is to ensure that alerts are not generated during the initial take-off climb for two reasons: to avoid distracting the crew and, because the aircraft is already flying close to the performance limit (body angle/attitude and thrust).

Safety analysis

Flight management computer – departure setup

The foreign captain was expecting to receive a clearance via the SYD1 standard instrument departure and had pre-programmed the FMC in anticipation of this and briefed the other crew accordingly. However, the pre-departure clearance provided by air traffic control was different (RIC5). This was likely due to the captain’s limited exposure to the varying Sydney-centric departure procedures (SYD1 versus RIC5). In addition, the clearance included the radar transition procedure, with which the captain was unfamiliar, due to the predominant use of procedural-based transitions in the United States. Anything non-standard in departures or arrivals can add additional complexity, but particularly for crew that have very limited experience with the location, such as long-haul foreign crew. Air traffic controllers have an opportunity to take into account the likelihood of a crew’s familiarity with the airport when issuing clearances to foreign crew.

The clearance meant the FMC needed to be re-programmed for the RIC5 procedure. During this process, the PF removed the discontinuity that was automatically generated in the FMC flight path, that is, the waypoint sequence to the cleared oceanic route. This would have been appropriate for many procedural transitions but not for a radar transition. The predominance of procedural transitions in the United States likely meant that the PF was focussed on removing the discontinuity (gap) in the FMC coding.

In this case, the purpose of the discontinuity was to represent controller-issued vectors as the aircraft tracked beyond 12 NM northwest of Sydney. In effect, the aircraft was cleared to 12 NM. From that point they were required to wait for a controller initiated radar vector to re-join their cleared oceanic route to San Francisco commencing at waypoint DIPSO (to the east). In removing the discontinuity, the aircraft was re-programmed to track directly to DIPSO after reaching the initial waypoint at 1,500 ft where the aircraft should have turned left (before they reached the 12 NM point). Ultimately, this resulted in a right turn and, therefore, the loss of separation.

Crew coordination

Effective crew coordination is fundamentally dependent upon effective communication. In order for cockpit crew members to share a ‘mental model’, or common understanding of the nature of events relevant to the safety and efficiency of the flight, communication is critical.[22] The operator’s procedures were clear and provided an established framework for the flight crew to communicate and coordinate their activities to ensure a safe and expeditious departure.

A number of opportunities existed not only for the PM, but also the crew positioned in the observers’ seats (in-flight relief pilots), to verify the FMC setup between the departure briefing and entering the runway prior to take-off. The operator’s procedures included a comprehensive process by which crew use different pages (information sources) within the FMC to ensure the departure clearance is reflected accurately by the computer coding (waypoint sequence).

The PM was not aware of the amendment to the radar transition (deletion of the route discontinuity), which indicated that the PF may not have clearly verbalised the change and/or ensured the PM heard and understood the change, in accordance with the operator’s procedures. By not clearly verbalising this misunderstanding or the amendments to the departure route setup, the PF did not provide an opportunity for the rest of the crew to contribute effectively.

However, there were further opportunities for the PM or relief pilots to discover this error. The PM verified the FMC set up, but only used the summary RTE page rather than the LEGS page with greater detail, and therefore the waypoint sequencing error was not detected. Further, in the departure review just before take-off, both the PF and the PM noticed the ‘no transition’ on the FMC RTE page, but no-one recognised this was not in accordance with the radar transition segment of the clearance.

Communication

Effective communications also includes with external sources such as air traffic control. Readbacks of clearances and instructions to crew in the aviation context serves two main purposes; acknowledgement of both the intent and content of the clearance, and to reinforce the message has been acknowledged and understood. In this case, the PM provided a truncated readback to ATC, which did not provide this assurance. The truncated readback was not challenged by the controller. As such, the controller did not have any assurance that the flight crew heard and understood that they were cleared for a radar transition. This increased the risk of errors to the FMC setup and could have led to further confusion during the initial climb.

Findings

Contributing factors

  • The pilot flying incorrectly amended the flight management computer (FMC) for the cleared departure.
  • The amended FMC setup was probably not effectively communicated to the crew or effectively cross-checked by the pilot monitoring or relief pilots.

Other factors increasing risk

  • The pilot monitoring did not complete a full readback of the radar transition component of the pre-departure clearance, nor did the Sydney clearance delivery controller insist on a full readback.

Other findings

  • The Sydney departures controller observed UA870 turning right and towards VOZ1153 and quickly issued unambiguous and immediate instructions to both aircraft to rectify the situation and re-establish the required separation.

Crew details

United Airlines 870

 CaptainSenior FOObserver 1
(FO)
Observer 2
(FO)
Total Flight hours21,07219,00017,60014,200
Flight hours on B7774,3093,5002,5002,600
Flight hours in last 90 days166350175148
Total instrument hours11,00018,500500Not available
Instrument hours last 90 days1003503Not available
MedicalClass 1Class 1Class 1Class 1
Last simulator check*13 Dec 201921 Aug 201928 Jun 201920 Jun 2020

*Note: In United Airlines, crew resource management (CRM) and threat and error management (TEM) is incorporated into training and evaluation events, or simulator checking activities.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Automatic terminal information service (ATIS): continuous broadcast of recorded aeronautical information. ATIS broadcasts contain essential information, such as current weather information, active runways, available approaches, and any other information required by flight crew.
  2. Simultaneous independent departures refers to the delegation of controlling responsibilities to two tower controllers simultaneously, each responsible for either runway 34L, via very high frequency (VHF) 120.5, or the parallel runway (34R) via VHF 124.7.
  3. Pilot flying (PF) and pilot monitoring (PM) are procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for upcoming stages of the flight. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
  4. Standard instrument departure (SID): an air traffic control (ATC) defined procedure, usually coded via the FMC, that simplifies departure tracking while also balancing terrain/obstacle avoidance, noise abatement and airspace management considerations.
  5. Flight management computer (FMC): is a specialised computer system that automates multiple in-flight tasks reducing the workload of the flight crew. The system is able to combine multiple inputs to generate a blended solution regarding the aircrafts position and key flight parameters.
  6. Eastern Summer Time (ESuT): Coordinated Universal Time (UTC) + 11 hours.
  7. DIPSO: the first navigational waypoint beyond the Sydney terminal area, on the aircraft’s flight planned (oceanic) route from Sydney to San Francisco.
  8. See Context – Transition routes.
  9. Discontinuity: exists or is created when two waypoints are not connected by a segment within the FMC route. That is, when a gap exists.
  10. Waypoint: a defined position of late and longitude coordinates, primarily used for navigation.
  11. See Context - Flight management computer discontinuities.
  12. Departure review: is an operator process whereby the crew verbalise and verify key items prior to take-off including; aircraft weight, thrust setting, configuration and the FMC departure setup (cleared runway, SID and transition). Procedurally, the PM verbalises while checking the setup, the PF then ‘verifies’ by also checking the setup.
  13. See Context – Traffic alert and collision avoidance system.
  14. Augmented flight crew: refers to a flight crew complement that comprises more than the minimum number of pilots required to operate the aircraft type. The 777 requires a minimum of two pilots, one being designated the pilot-in-command (PIC) or captain. The additional pilots are referred to as relief pilots.
  15. FMC databases are updated every 28 days in order to capture any changes to any of the data (e.g. airport infrastructure, permanent obstacles, magnetic variation etc.).
  16. Flight level: at altitude above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL180 equates to about 18,000 ft.
  17. These are outlined in the Manual of Standards for Air Traffic Services (MATS).
  18. Safety alert: information issued by ATC that is considered time-sensitive or safety-critical.
  19. Source: Airservices Australia Safety Bulletin, Safety alerts and avoiding action advice, 7 March 2014.
  20. ICAO Annex 6 Part I mandates traffic alert and collision avoidance system type II (TCAS II) be fitted to all aircraft capable of carrying more than 30 passengers. TCAS II includes the capability of generating; ‘proximate traffic’ and both ‘traffic advisory’ and ‘resolution advisory’ if necessary.
  21. Source: Eurocontrol ACAS Guide – Airborne Collision Avoidance, December 2017, p 46.
  22. Sexton, B.J. & Helmreich, R.L. (2000). Analyzing cockpit communication: the links between language, performance, error, and workload. In Human Performance in Extreme Environments, p 63-68.

Occurrence summary

Investigation number AO-2020-005
Occurrence date 22/01/2020
Location 2 km north Sydney Airport
State New South Wales
Report release date 28/07/2020
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Loss of separation
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 777-322ER
Registration N2333U
Serial number 62644 LN:1466
Aircraft operator United Airlines
Sector Jet
Operation type Air Transport High Capacity
Departure point Sydney Airport, New South Wales
Destination San Francisco, United States
Damage Nil

Aircraft details

Manufacturer ATR-GIE Avions de Transport Régional
Model ATR72-212A
Registration VH-FVQ
Serial number 1053
Aircraft operator Virgin Australia Airlines
Sector Turboprop
Operation type Air Transport High Capacity
Departure point Sydney Airport, New South Wales
Destination Tamworth Airport, New South Wales
Damage Nil

Collision with terrain involving Lockheed EC130Q, N134CG, 50 km north-east of Cooma-Snowy Mountains Airport (near Peak View), New South Wales, on 23 January 2020

Final report

Report release date: 29/08/2022

Executive summary

What happened

On 23 January 2020, the crew of a Lockheed Corporation (now Lockheed Martin) EC-130Q large air tanker, registered N134CG, were conducting bushfire control operations in the Snowy Mountains region of New South Wales. After assessing the initial fire-retardant drop site at Adaminaby as not suitable, the crew accepted an alternate tasking to the Good Good (Peak View) fire-ground.

After conducting a partial retardant drop at Peak View, the aircraft was in a left turn and climbed for about 10 seconds to about 170 ft above the drop height. Following this, the aircraft was then observed descending. The aircraft was seen at a very low height above the ground, in a slight left bank, immediately followed by a significant left roll just before ground impact. The 3 crew were fatally injured and the aircraft destroyed.

What the ATSB found

The ATSB found that the forecast and actual weather conditions present in the Snowy Mountains region were hazardous, with strong gusting winds and mountain wave activity, producing turbulence. This was likely exacerbated by the fire and local terrain. Subsequently, the ATSB determined that the conditions were conducive to windshear and downdraft development at a time when the aircraft was most vulnerable, with a low airspeed and at a low altitude.

Despite an awareness of these conditions and that all other fire‑control aircraft (including a Boeing 737 large air tanker) were not operating in the area at the time due to the weather conditions, the New South Wales Rural Fire Service (RFS) continued with their tasking of N134CG to Adaminaby without aerial supervision (birddog). In addition, they relied on the pilot in command to assess the appropriateness of the tasking but did not provide them all the available information to make an informed decision on flight safety. That information for the tasking to Adaminaby should have included details about actual hazardous environmental conditions, resulting in the cessation of local aerial operations, the birddog pilot declining the tasking due to the forecast weather conditions, and a report from the Boeing 737 crew that conditions precluded them from returning to the fire-ground.

The crew of N134CG were therefore very likely not aware that the birddog pilot had declined the tasking to the Adaminaby fire-ground, nor that the smaller fire-control aircraft had ceased operations in the area, due to the hazardous environmental conditions. While this was only one risk factor among others that would be considered by the crew when accepting a task, having this information would have allowed them to make a more informed decision about the weather conditions.

Nonetheless, the pilot in command of N134CG accepted the tasking to the Adaminaby fire‑ground, which was subject to hazardous environmental conditions. After assessing the conditions as unsuitable at Adaminaby, the crew accepted an alternative tasking to continue to the Good Good fire-ground, which had the same weather conditions. The acceptance of these taskings was consistent with the operator’s practices to depart and assess the conditions to find a workable solution rather than rely solely on a weather forecast, which may not necessarily reflect the actual conditions at the fire-ground.

At the Good Good fire-ground, following a partial retardant drop and left turn, the aircraft was very likely subjected to hazardous environmental conditions including low-level windshear and an increased tailwind component. From a combination of witness video, and real-time position and flight path data, it was established that the aircraft’s climb performance degraded. Subsequently, while at a low height and airspeed, it was likely the aircraft aerodynamically stalled, resulting in a collision with terrain. In the limited time available, the remainder of the fire-retardant load was not jettisoned prior to the aircraft stalling.

The ATSB established that, while a safety management system was not required under Australian regulations at the time of the accident, Coulson Aviation's safety risk management processes did not adequately manage the risks associated with large air tanker operations. In particular, they had not conducted formal risk assessments of the hazards identified in their operations manual, and did not maintain a tool, such as a risk register, to track risk acceptance levels. Further, incident reports submitted through the safety reporting system were mainly related to maintenance issues, and therefore operational risks were less likely to be considered or monitored. This limited their ability to identify and implement control measures to manage the risks associated with their aerial firefighting operations.

It is critical that crews can differentiate between a low-risk and high-risk flight during the planning stage to establish the overall risk profile. While identifying it as a high-risk activity, Coulson Aviation had not identified a need for a pre-flight risk assessment for their firefighting large air tanker crews. This would have provided crews with predefined criteria to ensure consistent and objective decision-making with accepting or rejecting tasks, and include factors relating to crew, environment, aircraft and external pressures and factors.

There are a number of mitigators for windshear, including pilot training and procedures, and airborne detection systems. However, Coulson Aviation did not include a windshear recovery procedure in their C‑130 Airplane Flight Manual. Further, it was noted that a briefing on windshear recovery was incorporated into the training syllabus, but there was no requirement to conduct a simulator-based low-level windshear recovery scenario. Combined, these strategies could provide crews with the experience needed to recognise the symptoms of windshear and practice a recovery procedure. In addition, Coulson Aviation had not assessed their fleet of C-130 aircraft for fitment with a windshear detection system. This increased the risk of a windshear encounter and/or delayed response to an encounter.

While the New South Wales RFS was not an aviation organisation or directly responsible for flight safety, they were closely involved in the aerial operation, being responsible for determining the task objectives and selecting aircraft for the task. The ATSB found that the RFS had limited large air tanker policies and procedures for aerial supervision requirements and no procedures for deployment without aerial supervision. In addition, they did not have a policy or procedures in place to manage task rejections, nor to communicate this information internally or to other pilots working in the same area of operation. Such policies and associated procedures would provide frontline personnel with the required steps to effectively and safely manage taskings, and provide guidance for decision-making.

It was also identified that, while not applicable to the accident crew, the RFS procedures allowed aircraft operators to determine when pilots were initial attack capable. This was inconsistent with their intention for pilots to be certified by the United States Department of Agriculture Forest Service certification process.

While not contributing to the accident, the aircraft's cockpit voice recorder did not record the accident flight. This resulted in a valuable source of safety information not being available to the investigation, which not only increased the time taken to determine contributing factors to the accident but also limited the extent to which important safety issues could be identified and analysed.

What has been done as a result

As a result of this investigation, Coulson Aviation have incorporated a windshear recovery procedure into their C-130 Airplane Flight Manuals and plan to introduce simulator-based recurrent windshear training. Related to the consideration of risk in aerial firefighting operations, they have also implemented a pre-flight risk assessment to be completed by the pilot in command prior to the first tasking of the day. They will also be introducing a three-tier risk management approach, of organisational risk, operational risk, and tactical/mission risk, to be utilised during the upcoming fire season in Australia. Further, Coulson Aviation have updated their pre-flight procedures to incorporate a cockpit voice recorder system check before each flight. Lastly, the Retardant Aerial Delivery System software was reprogrammed so that the system will not require re-arming between partial load drops where less than 100% was selected.

The ATSB has issued 2 safety recommendations to Coulson Aviation. These are to further consider:

  • fitment of a windshear detection system to their C-130 aircraft to minimise the time taken for crews to recognise and respond to an encounter particularly when operating at low-level and low speed
  • incorporating foreseeable external factors into their pre-flight assessment tool to ensure the overall risk profile of a tasking can be consistently assessed by crews.

The New South Wales Rural Fire Service advised the ATSB that they intend to take the following actions in response to this accident:

  • Commissioned an independent report into the management of airspace in which aircraft are operating in support of fire-fighting activities.
  • Formalise and establish a ‘Large Air Tanker Co-ordinator’ role description, to be positioned on the State Air Desk during heightened fire activity.
  • Undertake an immediate audit, in conjunction with operators, of pilots qualified as initial attack capable and ensure appropriate records are accessible by RFS personnel.
  • Undertake detailed research to identify best practice (nationally and internationally) relating to task rejection and aerial supervision policies and procedures as well as initial attack training and certification.
  • Undertake a comprehensive review of RFS aviation doctrine to incorporate outcomes of the above-mentioned research into existing policies and procedures.
  • Promulgate the revised doctrine detailing the task rejection policies and procedures and aerial supervision requirements to all operational personnel, pilots/aircrew and other key stakeholders. This is to be reinforced at the aviation operators briefing held annually prior to the bushfire season.
  • Provide the National Aerial Firefighting Centre and national fire-fighting agencies with copies of the updated doctrine relating to these issues.

While the ATSB acknowledges the commitment to undertake reviews and research, at the time of publication, the New South Wales Rural Fire Service had not yet committed to adopting any safety action that would reduce the risk associated with the 3 identified safety issues to an acceptable level. As such, the ATSB has issued three safety recommendations to the RFS to take further action:

  • to address the absence of policies and procedures for personnel to effectively manage and communicate task rejections on the basis of operational safety concerns
  • to address the absence of policies and procedures regarding minimum aerial supervision requirements and the use of initial attack to assist frontline staff with making acceptable risk‑based tasking decisions
  • to address the ambiguity with the interpretation of ‘initial attack’ in the NSW and ACT Aviation Standard Operating Procedures with the intent of this requirement.

Safety message

As noted by the National Aerial Firefighting Centre, aerial firefighting has become a critical capability for the management and suppression of bushfires in Australia. To effectively achieve this, aircraft are flown at low altitudes and low airspeeds, often in challenging environmental conditions. This creates a high-risk environment, which requires a continued focus on risk mitigation.

Previous research conducted by the ATSB emphasised that any decisions made by tasking agencies during the management of an aerial campaigns (firefighting) could influence the level of risk of the operation. Therefore, if safety was to be maintained, this responsibility had to be shared between the tasking agency and the aircraft operator. This accident highlights the importance of having effective risk management processes, supported by robust operating procedures and training to support that shared responsibility.

While the identification of hazards is the initial step in safety risk management, conducting risk assessments, implementing risk mitigators, and having effective oversight of the process through a tool such as a risk register are critical aspects of this process. This provides the mechanism for organisations to consider the specific challenges associated with firefighting operations such as hazardous environmental conditions, and ensure they have the appropriate risk controls in place to support crew decision-making when conducting high-risk activities.

Further, the adoption of good systems for managing risk by the tasking agency could provide an effective additional layer of defences over and above that provided by each aircraft operator to protect against an incident or accident. This also ensures that one aspect of the operation does not compromise another aspect. This may include the development of procedures to support decision-making processes rather than personnel having to exercise judgement to the best of their abilities, based on their experience, skills and knowledge. This would include aspects such as tasking decisions, task rejection policies and procedures, and minimum aerial supervision requirements.

 

The occurrence

Overview

During the Australian ‘black summer’ of 2019-2020, the east coast experienced many severe bushfires. As part of the firefighting efforts, small and large aircraft were used for aerial fire suppression and intelligence gathering. The larger aircraft included large air tankers (LATs),[1] located at the Richmond Royal Australian Air Force (RAAF) Base, New South Wales (NSW). This included a United States-registered Lockheed Martin EC-130Q,[2] registered N134CG, operated by Coulson Aviation. On 23 January 2020, the aircraft was applying retardant for property protection in the Good Good fire-ground (near Peak View) in the Snowy Mountains region of NSW. While attempting to climb away after a partial fire-retardant drop, the aircraft collided with terrain. The 3 crew were fatally injured and the aircraft was destroyed.

Daily briefings at Richmond Base

On 23 January 2020, at about 0900 Eastern Daylight-saving Time,[3] the NSW Rural Fire Service (RFS) Richmond airbase manager (ABM)[4] had conducted a briefing with the crews of the air tanker and birddog[5] aircraft based there. The briefing included the current and anticipated fire activity and discussed fire-related weather conditions across the state. Following the briefing, the crews then remained on standby until they received a tasking from the RFS, with a contracted 15‑minute departure time following the completion of retardant loading.

The operator of two LATs at Richmond, Coulson Aviation, reported[6] that they had also conducted their daily safety management system call between management and crews, which would typically discuss the operations to be conducted on the day, and any reported issues encountered in the previous 24 hours. However, as there were no notes taken for the call, the details of the conversation were unknown.

Fire situation in the Snowy Mountains region

On the day, the Snowy Mountains region in NSW had a severe fire danger rating,[7] due to high temperatures, strong winds and forecast thunderstorms. This region included the Adaminaby and Good Good fire-grounds, which were both under the control of the RFS Cooma Fire Control Centre (FCC).[8]

At about 1100, the Cooma FCC incident controller[9] made a phone call to the RFS State Operations Centre.[10]A number of senior personnel from the State Operations Centre were involved in the conference call. They discussed the escalating fire danger at the Adaminaby fire‑ground, with rural properties under threat and concern the town would be impacted if containment lines did not hold. During that call, RFS personnel stated that there were strong winds, severe fire weather conditions, and that the smaller fire-control aircraft were not operating in the area due to the winds and poor visibility. There was also discussion as to whether a birddog aircraft had already departed to assess the conditions. However, a senior RFS officer stated they should send the Boeing 737 LAT aircraft irrespective, ‘as it can bomb by itself if need be’ and ‘not wait for the birddog assessment’.

Consequently, the State Operations Centre tasked 2 LATs[11] and a birddog to the Adaminaby fire‑ground: a Boeing 737 aircraft, registered N137CG, call sign ‘Bomber 137’ (B137); a Lockheed Martin C-130 aircraft, registered N134CG, call sign ‘Bomber 134’ (B134); and a Rockwell International 690-B aircraft (operating as a birddog). All 3 aircraft were based at the Richmond Base, about 316 km north-east of the Adaminaby fire-ground.

‘B137’ tasking to Adaminaby

Following the 1100 call, the tasking was communicated by the state air desk (SAD)[12] to the Richmond ABM. At 1120, the Cooma aerial operations manager log recorded that LATs were inbound, with no birddog. At about 1121, the crew of B137 had commenced taxiing at Richmond for another task to the north[13] when they were re-tasked to the Adaminaby fire-ground by the ABM.  After the initial coordinates, location details, and information regarding the expected direction of the fire were provided, the pilot in command (PIC) of B137 requested details for the fire common traffic advisory frequency. The Richmond ABM was unable to provide these details immediately, but indicated the SAD  ‘want to get them in the air and down there’. The ABM also advised the crew of the objective to ‘keep the fire out of Adaminaby’, that ‘the fire is burning towards the north-west’, that there were no other aircraft in the area, and that it ‘is very windy down there….take care’. The ABM further advised ‘the birddog won’t be down there’.[14] Therefore, the PIC was aware they would be operating as initial attack.[15] The aircraft subsequently departed at about 1127.

While en route, the crew contacted various fire centres to determine the correct ground-based contact, eventually communicating with the Cooma aviation radio operator (ARO), located at the Cooma FCC. At about 1155, B137 arrived overhead the Adaminaby fire-ground, but the crew were unsure of the actual planned location for the drop. After further discussion with the ARO, it was determined they were overhead the intended location.

Due to the weather conditions and ground-based fire-fighters in the planned drop area, the crew orbited for about 25 minutes. At interview, the PIC reported that, while assessing the conditions in the Adaminaby area, the aircraft encountered uncommanded rolls up to 45° angle of bank (due to wind) and they received a windshear[16] warning from the aircraft’s onboard systems.[17] The PIC elected to operate on the upwind side of the hills to avoid lee side mechanical turbulence.[18] They also reported that the wind speed at the Adaminaby fire-ground was 50 kt at 800 ft above ground level (AGL) and about 37 kt at the fire‑retardant drop height of 200 ft AGL. At about 1225, B137 departed the Adaminaby fire‑ground, having successfully deployed a retardant load.

After completing the retardant drop, the PIC reported that they advised the Cooma ARO to cancel all the aircraft operating in the area, although it was not clear if the ARO had received that message. They also sent a text message to the birddog pilot assigned to the Adaminaby fire‑ground indicating that the conditions were ‘horrible down there. Don’t send anybody and we’re not going back’. During B137’s return flight to Richmond, at about 1232, the PIC contacted the Richmond ABM and stated they were going ‘to put themselves on hold’, but would be available for other taskings. The ABM requested that they reload the aircraft with fire retardant in Canberra and return to Adaminaby. The PIC replied that they would not be returning to Adaminaby due to the weather conditions, as the ‘winds were getting too strong and the visibility is down’, and continued to Richmond. Subsequently, when the ABM communicated B137 PICs decision to the SAD, they indicated the weather was ‘fairly dicey…probably won’t go back’. There was some discussion as to the availability of other LATs to task to Adaminaby, however, the decision was made to wait for a report from B134 before any further tasking.

Birddog rejection of tasking

Meanwhile, at about 1137, the Richmond ABM contacted the SAD to confirm the dispatch of a birddog to Adaminaby. The birddog crew consisted of the birddog pilot and the LAT air attack supervisor.[19] The ABM had also noted in their log at 1130 and 1140 that they were intending to send the birddog to Adaminaby. The 1130 log entry also indicated that the incident air attack supervisor was not operating ‘due to extreme wind conditions’. By the time of the 1137 phone call, B137 had already departed Richmond as initial attack and B134 was being prepared for departure, with the expectation from the RFS that both LATs would do multiple retardant drops. The ABM and SAD discussed that the 2 LATs would beat the birddog to the fire‑ground, but it was considered unlikely ‘they will get through as [it] will be too windy for them’.[20]

The birddog pilot reported having experienced moderate to severe turbulence in the Snowy Mountains region about 2 weeks prior, which resulted in an uncommanded roll up to 30–40° angle of bank. This, combined with a downdraft, required the pilot to execute an escape manoeuvre. On receipt of the tasking to Adaminaby, the birddog pilot reviewed the weather and concluded that the conditions were forecast to be worse than previously experienced, and therefore declined the task. The RFS reported the SAD log recorded the birddog declining the task to Adaminaby at 1204.

At about 1209, the ABM had a conversation with the SAD and discussed that the birddog pilot was ‘questioning the weather conditions’. The SAD instructed the ABM to ‘get them on their way, and then turn them around’ (that is, rather than accept a rejection based on the forecast, they would prefer they re-assess the conditions in-flight). When the ABM communicated this to the birddog pilot, the pilot indicated to the ABM that B137 would arrive overhead Adaminaby shortly, and they could then report the actual conditions. At about 1235, following a report of the conditions from the PIC of B137, the ABM reportedly agreed that the birddog pilot had made an appropriate assessment to reject the task to Adaminaby.

The birddog pilot reported that they had not spoken to the crew of B134 following the receipt of the tasking on the day of the accident as they were both focussing on their pre‑flight planning, which was normal practice. Subsequently, the birddog pilot accepted an alternate tasking at 1259.

Figure 1 provides a timeline of the key communications regarding tasking allocation for B134, B137 and the birddog.

Figure 1: Timeline of tasking communications

Figure 1: Timeline of tasking communications

Source: ATSB

‘B134’ tasking to Adaminaby

At about 1205,[21] while B137 was overhead the Adaminaby fire-ground, and about the same time the SAD logged the birddog rejection, B134 departed Richmond as initial attack. On board were the PIC, the copilot and flight engineer.

In response to the draft report, the RFS provided excerpts from the state operations controller (SOC) log.[22] entry was written in the log by the SOC following the accident.[23] The SOC noted having been advised that the birddog had indicated it was ‘not safe to fly’ and that B137 was not returning to the area until the conditions had eased. However, B134 would continue with the PIC to make the ‘decision of safety of bombing operations’. The RFS advised the ATSB that the SOC had the authority to cancel B134’s tasking, but instead allowed it to proceed, with the intention of gathering additional intelligence to assist in determining whether further aerial operations would proceed. The RFS further reported that this indicated an ongoing intelligence gathering and assessment process by the SOC.

At about 1235, while returning to Richmond, the PIC of B137 heard the PIC of B134 on the Canberra approach frequency and contacted them via their designated operating frequency.  At that time, B134 was about 112 km north-east of Adaminaby, en route to the fire-ground (Figure 2).  In this conversation, the PIC of B137 informed them of the actual conditions and that they would not be returning to Adaminaby. The PIC of B137 reported that they could not recall the specific details of the call, but that the conversation included that they were ‘getting crazy winds’ and ‘you can go take a look’ ’but I am not going back’. It was also noted that the PIC of B134 had asked several questions. It was reported by the majority of the operator’s pilots that, despite receiving information from another pilot, they would have also continued with the tasking under these circumstances, to assess the conditions themselves.

At about 1242, the crew of B134 contacted air traffic control to advise them of the coordinates they would be working at, provide an ‘ops normal’[24] call time, and confirm there was no reported instrument flight rules[25] aircraft in the area. About 5 minutes later, the Richmond ABM also attempted to contact the crew of B134 to confirm ‘ops normal’, firstly by radio, and then by text to the PIC’s mobile phone, but did not receive a response.

The automatic dependent surveillance broadcast (ADS-B) data showed that, after arriving at the Adaminaby fire-ground at about 1251, the crew of B134 completed several circuits at about 2,000 ft AGL.[26] At about 1255, the crew advised the Cooma ARO that it was too smoky and windy to complete a retardant drop at that location. The Cooma ARO then provided the crew with the approximate coordinates of the Good Good fire, about 58 km to the east of Adaminaby. The ARO further indicated that they had no specific requirements, but they could look for targets of opportunity, with the objective of conducting structure and property protection near Peak View.

Figure 2: Flight track of B134 (white line), timing and location of external communications, and key locations, with an inset detailing the circuits at Adaminaby

Figure 2: Flight track of B134 (white line), timing and location of external communications, and key locations, with an inset detailing the circuits at Adaminaby

Source: Google earth, ADS-B data and radio calls, annotated by the ATSB

‘B134’ tasking to the Good Good fire-ground

At about 1259, the crew of B134 contacted air traffic control to advise that they had been re‑tasked to the Good Good fire-ground and provided updated coordinates. At about the same time, the RFS ground firefighters at the Good Good fire-ground, near Feeney’s Road in Peak View, contacted the Cooma FCC and requested additional assets for property protection. They were advised that a LAT would be passing overhead in about 10 minutes. The firefighters acknowledged the intention of a LAT retardant drop and advised the Cooma FCC they would wait in open country on Feeney’s Road, clear of any properties targeted for protection.

At about 1307, B134 arrived overhead the drop area (Figure 3). The drop area was located to the east of a ridgeline, with the fire on the western side of the ridgeline. The aircraft’s recorded track data (SkyTrac) showed that the crew conducted 3 left circuits, at about 1,500 ft, 500 ft and 1,000 ft AGL respectively, prior to commencing the drop circuit (Figure 4). At about 1312, after conducting about 2 circuits, they advised the Cooma ARO of their intention to complete multiple drops on the eastern side of the Good Good fire, and that they would advise the coordinates after the first delivery.

Figure 3: B134’s approach and circuits overhead the drop location; the inset shows the track from the Adaminaby to the Good Good fire‑ground

Figure 3: B134’s approach and circuits overhead the drop location; the inset shows the track from the Adaminaby to the Good Good fire‑ground

Source: Google earth and SkyTrac data, annotated by the ATSB

At 1315:15,[27] a partial retardant drop was conducted on a heading of about 190°, at about 190 ft AGL (3,600 ft above mean sea level). During the drop, about 1,200 US gallons (4,500 L) of fire retardant was released over a period of about 2 seconds. A ground speed of 144 kt was recorded at the time of the drop.

A witness video taken by ground fire-fighters captured the drop and showed the aircraft immediately after the drop in an initial left turn with a positive rate of climb, before it became obscured by smoke[28] While being intermittently obscured by smoke, the aircraft climbed to about 330 ft AGL (3,770 ft above mean sea level). At about this time, ATSB analysis of the video showed that the aircraft was rolling from about 18° left angle of bank to about a 6° right angle of bank. Following this, the aircraft descended and about 17 seconds after the completion of the partial retardant drop, it was seen at a very low height above the ground, in a slight left bank. Video analysis and accident site examination showed there was no further (emergency) drop of retardant. Throughout this period, the recorded groundspeed increased slightly to a maximum of 151 kt. Shortly after, there was a significant left roll just prior to ground impact.

Figure 4: Accident circuit and location of the firefighters and retardant drop

Figure 4: Accident circuit and location of the firefighters and retardant drop

Source: Google earth and SkyTrac data, annotated by the ATSB

At about 1315:37, the aircraft collided with terrain and a post-impact fuel-fed fire ensued. The 3 crew were fatally injured, and the aircraft was destroyed.

A review of the Airservices Australia audio recording of the applicable air traffic control frequency found no distress calls were received by controllers prior to the impact.

________

  1. A large air tanker (LAT) is an aircraft with a minimum suppressant/retardant capacity of 3,000 US gallons (11,356 L).
  2. The aircraft was initially built as an EC-130Q, however, all specialised military equipment had been removed, and it was considered to be the equivalent of a C-130H. Throughout the report, the aircraft is referred to as a C-130.
  3. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours
  4. The airbase manager was responsible for the supervision and coordination of airbase personnel, and the layout and operation of an airbase. There were 2 airbase manager’s operating at Richmond on the morning of the accident.
  5. Birddog aircraft were used to lead large air tanker aircraft across the fire-ground and provide guidance on the release of the water or fire suppressant (retardant or gel).
  6. Provided by Coulson Aviation in response to the draft report on 10 July 2022.
  7. The NSW RFS fire danger ratings provide an indication of the possible consequences of a fire and are based on predicted conditions including but not limited to temperature, humidity, wind, and the dryness of the landscape.
  8. A FCC forms the administrative and operational base of the rural fire district or zone. The coordination and management of local brigade responses to fire and other incidents was undertaken through the FCC.
  9. The incident controller was responsible for all aspects of an emergency response, including the objectives, operations, and application of resources of the FCC.
  10. The State Operations Centre coordinated the NSW multiagency state-wide response and provided a variety of specialised resources to the FCC.
  11. The tasking of B137 and B134 to Adaminaby was annotated in the Richmond ABM’s log, which specifically noted that the birddog was not accompanying either aircraft, the conditions were ‘windy’, and for the crews to ‘only do what they can do safely’. However, this log entry was at 1049, shortly before the phone call between the Cooma FCC incident controller and the RFS State Operations Centre where it was questioned if the birddog had already departed. These time discrepancies could not be resolved by the ATSB.
  12. The state level multiagency team located in the State Operations Centre responsible for coordination of aircraft operations.
  13. B137 was to be accompanied by a birddog for the tasking to the north. Where there was an urgency to dispatch aircraft due to the rapid spread or the impending impact of the fire, it was standard practice to launch the LATs at the same time, or ahead of, tasking the associated birddog.
  14. Where there was an urgency to dispatch aircraft due to the rapid spread or the impending impact of the fire, it was standard practice to launch the LATs at the same time, or ahead of, tasking the associated birddog.
  15. An air tanker initial attack certification allowed a pilot to conduct fire retardant drops without aerial supervision.a>
  16. Windshear is defined as a wind direction and/or speed change over a vertical or horizontal distance.
  17. B137 was fitted with both predictive and reactive windshear warning systems, and it could not be determined, based on the evidence available, which system provided the warning (refer to section titled Windshear risk control systems).
  18. Mechanical turbulence occurs due to frictional forces on the surface wind creating turbulent eddies. The intensity of the turbulence is largely dependent on the wind speed, surface roughness, and atmospheric stability near the surface.
  19. The air attack supervisor was a tactical command position, which ensured that aerial operations were consistent with the procedures and incident controller’s intent.
  20. From this conversation, it was unclear whether the term ‘they’ referred to all 3 aircraft, that is, B134, B137 and the birddog.
  21. The ABM log recorded the departure of B134 at 1140. This time discrepancy could not be resolved by the ATSB.
  22. The SOC maintains an overall awareness of the firefighting effort across the state ensuring information and warnings are being distributed and resources are being allocated where needed.
  23. The SOC’s note was entered into the log following another note written at 1327. The log was provided to the ATSB at the time of the RFS response to the draft investigation report.
  24. ‘Ops normal’ call time provided the next expected transmission time from this aircraft to indicate operations were normal.
  25. Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR). Procedures and training are significantly more complex as a pilot must demonstrate competency in IMC conditions while controlling the aircraft solely by reference to instruments. IFR-capable aircraft have greater equipment and maintenance requirements. a>
  26. When conducting initial attack operations, crews complete several circuits to assess the hazards and drop conditions.
  27. All times in the report are referenced to the ADS-B data, with adjustments based on the recorded locations.
  28. From the witness video, it was unclear if the aircraft flew behind the smoke, or entered the smoke.

Context

Crew information

Pilot in command

Experience

The pilot in command’s (PIC) logbook, combined with the operator’s records for the accident aircraft showed that the PIC had a total flying experience of about 4,010 hours, which included 3,010.3 hours in the C-130 aircraft and 994 air tanker drops. The PIC had also accrued a further 1,616.8 hours as a flight navigator.

The PIC commenced work in Australia on 1 December 2019. In the 30 days prior to the accident, the PIC had flown about 32 hours. In the 72 hours prior, the PIC had flown 4.5 hours, all of which were in B134. The accident flight was the first flight of the day.

The PIC was initially trained as a navigator and pilot in the United States (US) Air National Guard. During this time, the PIC gained experience in firefighting operations through the modular airborne firefighting system (MAFFS)[29] program. The PIC joined Coulson Aviation in 2015 on a part-time basis, before being employed full-time in 2017.

Qualifications

The PIC held a current airline transport pilot certificate with ratings for multi-engine land airplane including the EC-130Q, issued by the US Federal Aviation Administration (FAA) on 13 October 2017. The PIC’s most recent flight instructor certificate with ratings for multi-engine and instrument aircraft was issued by the FAA on 6 April 2019. On 18 April 2019, the PIC’s latest ‘airplane pilot qualification card’ was issued from the US Department of Agriculture, Forest Service,[30] for the C-130 aircraft, which included the authorised missions of:

  • low level (below 500 ft above ground level)
  • mountainous terrain
  • airtanker initial attack.

An air tanker initial attack certification allowed a pilot to conduct fire retardant drops without the supervision of a birddog or air tactical (attack) supervisor.

At interview, other flight crew reported the PIC was ‘methodical’, ‘conservative’, who ‘always did his due diligence’ and was not considered to take unnecessary risks. It was also reported that Coulson Aviation pilots were not being paid per flight or by flying hours, and therefore that was not a motivational factor to accept a tasking. In addition, the PIC had recently resigned from the operator and accepted a US-based position.

Training

The PIC last completed training with Coulson Aviation in March and April 2019,[31] which included annual C-130 simulator training, controlled flight into terrain awareness and crew resource management courses. In addition, the PIC completed 2 assessed training flights in the C-130 on 14‑15 April 2019. The flight on 14 April included approach to aerodynamic stalls[32] in the circuit (with 50% flap) and drop (with 100% flap) configurations, and go-arounds with a full load (water). The flight on 15 April included drop planning (hazards, tactics, ingress, egress, and dry run) and an emergency on the drop run. The drop run emergency was a simulated ‘down air’ [downdraft]. All the assessed sequences, which included jettison of the load during a (simulated) emergency condition,[33] were recorded as satisfactory.

Copilot

The copilot had joined Coulson Aviation in September 2019, after 20 years in the US military, including experience flying the C-130. The copilot’s logbook combined with the operator’s records showed a total flying experience of about 1,744 hours, of which about 1,364 hours were on the C‑130. This was the copilot’s first fire season, and they commenced work in Australia on 1 December 2019. Since the start of the fire season, the copilot had flown about 85 hours, with about 28 hours in the last 30 days and about 4.5 hours in the 72-hour period prior to the accident.

The copilot held a current airline transport pilot certificate and ratings for multi-engine land aircraft, including the EC-130Q (second-in-command privileges only), issued by the FAA on 7 November 2019. The copilot also held a flight instructor certificate with ratings for single, multi‑engine and instrument aircraft, issued by the FAA on 14 August 2019.

The copilot’s C-130 check flight with the operator was completed on 12 September 2019, and was assessed as satisfactory against the qualification standards for second‑in‑command. On 13 September 2019, the copilot completed the crew resource management and controlled flight into terrain awareness courses and reviewed the US Department of Agriculture Forest Service’s air tanker pilot training video.

On 16 September 2019, the copilot was issued with an ‘airplane pilot qualification card’ from the US Department of Agriculture Forest Service for the C-130, which included the authorised missions of:

  • low level (below 500 ft above ground level)
  • mountainous terrain
  • airtanker SIC (second-in-command).
Flight engineer

The flight engineer joined Coulson Aviation in November 2019, after about 25 years in the US military. This was the flight engineer’s first fire season. The flight engineer held a flight engineer certificate with a rating for turbo-propeller powered aircraft, issued by the FAA on 20 November 2019. On the flight engineer application form, the flight engineer reported accruing about 4,050 hours on the C‑130. The flight engineer also held a mechanic certificate with ratings for airframe and powerplant, issued by the FAA on 2 June 2019.

The flight engineer’s check flight was completed with the operator on 20 November 2019. In addition to this flight, the flight engineer completed 2 air tanker drops under supervision in Australia on 12 January 2020. The flight engineer commenced work in Australia on 13 January 2020.

72-hour prior history

In Australia, each crew member’s roster cycle was 14 duty days followed by 2 rest days. The accident flight occurred on the PIC’s 9th day, and the copilot’s and flight engineer’s 11th day of their respective current duty periods.

Table 1, based on the operator’s records, details the crew’s sign-on and sign-off times for the 3 days before the accident. On 23 January 2020, the crew signed on at 0900.

Table 1: B134 crew working hours

 20 January21 January22 January23 January
Sign-on1000080010000900
Sign-off180017001900-
Duty time8 hours9 hours9 hours-

Information from the crew’s telephone and hotel records, in addition to work and flying duties, were used to determine their activities in the previous days. There were no indications of fatigue for the 3 crew members. However, there was insufficient information available to the ATSB about their sleep and non-duty activities to estimate fatigue levels with confidence.

Aircraft information

General information

The C-130 is predominantly an all-metal, high-wing aircraft, designed for military operations. The accident aircraft (Figure 5) was manufactured by the Lockheed Corporation (now Lockheed Martin Corporation) in 1981 and was powered by 4 Allison T56-A-15 turbopropeller engines, fitted with Hamilton Sundstrand 54-H60-91 4-blade propellers. The T56‑A‑15 is a constant speed engine, with a variable pitch propeller. 

Previously owned by the US Navy, the aircraft was transferred to the US National Aeronautics and Space Agency in 1992 and later placed in storage. It was then re‑purposed for firefighting activities by Coulson Aviation and registered in the restricted category.[34] At that time, Coulson Aviation became the type certificate holder and assumed the responsibilities of the aircraft manufacturer for the entire aircraft and any modifications made.

Initially registered as N130CG in 2018, this was later changed to N134CG in April 2019. Modifications to the aircraft included the installation of an avionics package and firefighting tank system, known as the Retardant Aerial Delivery System XXL (RADS).

Figure 5: N134CG

Figure 5: N134CG

Source: Coulson Aviation

Retardant Aerial Delivery System XXL

The RADS included a 4,000 US gallon (15,000 L) tank system located within the aircraft’s fuselage. The system was designed to deliver discrete quantities of retardant, dependant on the coverage factor[35] selected and the duration the doors remained open. This was controlled from the cockpit, with drop controls located on both the PIC and copilot yokes.

The drop quantity was manually controlled by the crew by setting the coverage factor and either selecting a pre-set percentage or setting 100%. The latter option allowed the crew to control the amount of retardant released by holding a button on the yoke until the desired amount was dispensed. The RADS system was designed that, if less than 100% volume was selected, the system would disarm after a partial load drop and the crew would need to re‑arm the system to complete further releases. It was reported that the crew on B134 normally selected 100%.

The system also included a guarded emergency dump (’e-dump’) switch, located in reach of all 3 crew members, which would fully open the doors and jettison the load in a period of about 2 seconds. Following an emergency dump, the doors would remain open until the RADS was reset by the crew.

Maintenance history

The aircraft had a total time-in-service of 11,888 hours and had accrued 683 hours of firefighting operations since the tanker conversion in 2018. The aircraft had a current certificate of airworthiness and was maintained in accordance with an FAA approved program.

N134CG arrived in Australia in November 2019. The last daily inspection conducted on 22 January 2020, at the end of flying activities the day before the accident, identified the propeller anti-icing system on engine number 2 was unserviceable, and rectification had been deferred in accordance with the minimum equipment list.[36]

In addition to a maintenance requirement to perform engine power efficiency checks at 150-hour intervals, the operator reported pilots were required to perform power checks before every take‑off. Operations were only permitted if a minimum performance requirement of 95% was met.

Weight and balance

The last weight and balance report for the aircraft, in April 2019, showed its basic empty weight was 75,794 lb (34,380 kg) and according to the RADS Airplane Flight Manual (AFM) supplement, the maximum take-off weight was 150,718 lb (68,365 kg). The aircraft flight and maintenance log indicated the PIC had the aircraft refuelled to a total of 34,000 lb (15,422 kg) at the completion of flying on 22 January 2020. The operational load monitoring system[37] indicated there was 35,514 lb (16,109 kg) of retardant on board prior to the accident drop, in addition to a 2,000 lb (907 kg) pallet of gel. This resulted in a take-off weight of about 147,308 lb (66,818 kg) and the centre of gravity being at the aft limit on departure from Richmond.

Using the operator’s reported fuel consumption for air tanker drop missions of 5,000 lb/h (2,268 kg/h) for a 70-minute flight, and the retardant drop of 10,764 lb (4,882 kg), the estimated post-drop weight was 130,656 lb (59,265 kg). The centre of gravity remained close to the aft limit. This was consistent with reports from the operator’s other crews that the location of the RADS tank in the aircraft meant there was no appreciable change in the centre of gravity following a retardant drop.

Aerodynamic stall

Stalling

An aircraft’s wing is said to be ‘aerodynamically stalled’ when the airflow over the wing separates from the wing; that is, the airflow no longer follows the contour of the top surface of the wing. This results in a rapid loss of lift, which balances the weight of the aircraft, and the aircraft will rapidly descend. An aerodynamic stall will also normally result in the nose of the aircraft pitching down, often with a left-wing drop.

The aerodynamic characteristics of an aircraft wing are such that the airflow will separate and the wing stalls when the angle of attack, the relative angle between the wing and the airflow, reaches a critical value. The C-130H did not have an angle of attack instrument, however, this could be referenced to an equivalent airspeed. The airspeed at which a stall occurs is not fixed to a single value, and varies depending on the flap setting, aircraft weight, and load factor.[38] The stall speeds are typically presented in the AFM (refer to section titled Aircraft performance).  

The C-130 aircraft has 4 wing mounted engines driving propellers. The placement of the propellers forward of the wings results in the propeller slipstream providing a relative airflow over each of the wings in addition to the forward speed of the aircraft, which varies in strength with the power produced. This is known colloquially as a ‘blown lift’ wing and results in the stall speed lowering as power is increased. For the C-130, the published power-on stall speed with 50% flap is based on maximum power. Therefore, the stall speed will be higher when less than maximum power is applied. The higher power-off stall speeds are based on idle engine power.

Stall characteristics of the C-130

A  C-130 discussion paper (Mizell, 2009), based on data obtained during US Air Force testing, described the aircraft as having a ‘very good natural stall warning... However, once in a stall, the plane becomes much less predictable’. In a clean (no flap) power-off stall:

The flying characteristics of the plane are very benign all the way up to full stall. A significant buffet was experienced 10 knots prior to stall. 3 knots above stall, a deterring buffet was experienced, giving a clear signal to the crew that stall was imminent. Immediately before stall, a yaw acceleration was detected by the data, but nearly imperceptible to the crew.

However, the 50% flap and 100% flap power-on stall ‘present a much larger hazard..’. Specifically, the paper noted that:

Similar to 0% flap, but with less buffet warning, the left-wing stalls first resulting in large, uncontrolled bank excursions and subsequent nose low attitudes. In some cases, the aircraft remained uncontrollable until the bank exceeded 100 degrees and the nose approached 75 degrees down. This caused massive altitude loss and overspeed of airframe components.

The approach to stall at 50% and 100% configurations also exhibited high descent rates.

The accident aircraft was not fitted with a stall warning system, nor was one required or available. However, according to the C-130 pilots consulted during the investigation, the aircraft had a noticeable pre-stall buffet through the rudder pedals and control column, and this was reported as being distinct from a turbulence-induced buffet, which could be felt throughout the aircraft. In addition, the flight controls become less effective at these lower speeds, described by pilots as ‘sluggish’ and ‘unresponsive’. The Lockheed Martin AFM also indicated that:

With flight idle power, stall warning buffet initially occurs at 4% to 15% above stall speed, depending upon configuration, and progresses to moderate or heavy buffet at the stall. The greatest stall warning airspeed margin exists in the take-off and approach configuration and less margin exists in the landing and cruise configurations. The stall of the C-130 is characterized by either a mild pitch down or a mild roll-off to the right or left depending on slightly unequal power settings.

Stall recovery

The Lockheed Martin AFM described the recovery actions for a stall as:

If in climbing or bank attitude, immediately drop the nose, level the wings, and apply power to limit loss of altitude. Move controls smoothly and avoid abrupt actions. Avoid diving the airplane and avoid abrupt or accelerated pull-up after recovery.

While the ATSB did not find a published procedure in the operator’s AFM (refer to section titled Operating documents) for stall symptoms and recovery actions, their C-130 pilots all reported that approaches to stall (start of the buffet) training[39] was conducted in the aircraft on an annual basis in various configurations. According to the operator’s Company Operations Manual (COM),[40] training for approaches to the stall were conducted in the clean, take-off and landing configurations.[41] The recovery procedure referred to both low altitude (ground contact imminent) and higher altitude (ground contact irrelevant) scenarios.

The C-130 pilots’ descriptions of the symptoms and recovery actions were consistent with the manufacturer’s published material, with some additions specific to their operation. These included the addition of load jettison and flying the aircraft towards their pre-briefed escape route from the release point. Although their recovery descriptions for a pre-stall buffet, following a fire-retardant drop, was to apply maximum power by pushing the power levers full forward, this was not a procedure that could be practically trained in the aircraft. The engine power was managed manually, therefore, pushing the power levers full forward during training could result in an over‑torque or over‑temperature condition for the engines. However, they reported they would apply as much power as needed and as quickly as possible in a real low-level stall situation.

Aircraft performance

Stall speeds

The aircraft stall speeds were contained in the respective performance charts in the Lockheed Martin AFM. The ATSB calculated the power-on and power-off stall speeds for an aircraft weight of 131,000 lbs (59,420 kg), in level flight and with 50% flap at 83 kt (IAS)[42] and 101 kt (IAS) respectively. This configuration and attitude were considered most representative of the aircraft state just prior to the observed descent (refer to sections titled Weight and balance, Wreckage and impact information, and Recorded information sections), noting that a pitch-up attitude, any bank angle above 0° and a decreasing flap setting would increase the stall speed. It was a standard operating procedure for the crew to calculate the power-off stall speeds at the take-off weight for 0-flap, 50% flap and 100% flap, for 0° and 45° angle of bank for each flight. A 25,000 lb (11,340 kg) weight reduction from a jettison of the remaining fire retardant would have reduced the power‑on stall speed to 76 kt.

Turbulence will also affect an aircraft’s stall speed. According to the Bureau of Meteorology, moderate turbulence is associated with a load factor increase of 0.5 to 0.99 G[43] with appreciable changes in attitude and/or altitude, while severe turbulence is associated with a load factor increase of 1.0 G to 1.99 G with large abrupt changes in attitude and/or altitude. Turbulence was forecast (refer to section titled Bureau of Meteorology forecasts) and likely experienced (refer to section titled Bureau of Meteorology analysis) at the accident location. Applying the moderate turbulence load factors as boundary conditions to the 50% flap power-on stall speed at 59,420 kg produced a range of 101-117 kt (IAS). Similarly, for severe turbulence, this produced a power-on stall speed range of 117-143 kt (IAS) at 59,420 kg.

Regarding turbulence, the airspeeds limitation section of the operator’s AFM stated that:

The aircraft should not be operated in conditions of severe turbulence [actual conditions] because gusts can be encountered that may impose excessive loads. However, if flight in severe turbulence cannot be avoided, flight should be in the range of 65 knots above the power-off stall speed (not to exceed 180 KIAS) for the operating gross weight.[44]

Emergency climb performance

The aircraft’s emergency climb performance with maximum power at 131,000 lb (59,420 kg) and 50% flap was about 1,500 ft/min. With a reduced weight from a jettison of the remaining fire retardant, the emergency climb performance would have increased to about 2,250 ft/min, representing a 50% improvement. This was the absolute best rate of climb that could have been achieved.

Meteorological information

Bureau of Meteorology forecasts

A Bureau of Meteorology graphical area forecast was issued at 0924 and was valid for the time of the flight. It forecast moderate mountain wave activity[45] above 3,000 ft above mean sea level (AMSL) and severe turbulence below 8,000 ft AMSL in the area of operation from Richmond to Cooma. This included the Adaminaby and Good Good fire-grounds. In addition, a SIGMET[46] issued at 0947, and valid for the flight, forecast severe turbulence[47] below 10,000 ft AMSL for the area. Of note, when commenting on the general nature of forecasts, some of the operator’s pilots indicated that they could be broad and cover a large area of the state, which may not accurately reflect the actual conditions over the fire-ground. The only operational limitation cited at interview by the pilots were related to thunderstorm activity.

The aerodrome forecast for the Cooma-Snowy Mountains Airport,[48] located 50 km south-west of the accident site was amended at 0948. It indicated wind speeds of 25 kt, gusting to 48 kt, with a mean wind direction of 300° from 1100 and visibility reduced to 8,000 m in light showers. Severe turbulence below 5,000 ft AGL was forecast from 0900-1500. A PROB30[49] for visibility reduced to 2,000 m in blowing dust and a broken[50] layer of cloud at 1,000 ft AGL was forecast for the period 1100–1700.

At 1012, the Richmond airbase manager (ABM) sent a text message to the air tanker and birddog pilots to advise them of an airport warning at Richmond for wind gusts in excess of 35 kt between 1000 and 1700.

Observations of the weather in the area

Other fire-control aircraft

On the day of the accident, several fire-control aircraft, primarily consisting of fixed-wing Air Tractors (single-engine air tankers) and Bell 206 helicopters, were operating from the Polo Flat airstrip, located 33 km south-west of the accident site. The Cooma Fire Control Centre (FCC) aviation radio operator (ARO) received reports of strong winds in the area from the fire-control pilots in the early morning. This included winds of 30-40 kt at 0839, 40-50 kt at 0902, and 52 kt at 0937. The ARO recorded in their operations log that, due to the weather conditions, all fire‑control aircraft had departed the area or landed by 1030.

In addition, the crew of B137 reported that the wind conditions at Adaminaby at about 1200 were 50 kt at 800 ft AGL and about 37 kt at 200 ft AGL.

Witness reports

Following the accident, the ATSB received multiple witness reports of the weather conditions at Peak View. They all consistently reported very strong winds from the north-west, with gusts up to 43 kt recorded at ground level. One resident noted that, although the prevailing wind was from the north-west, the direction and strength at ground level were also being influenced by the local terrain.

Glider pilots familiar with the area commented that, due to the local terrain, the area was often subject to turbulence and rotor conditions (refer to section titled Mountain wave activity). It was also a well-known area for mountain wave activity and that on the day of the accident it was a ‘terrible wave day’.

Weather station recorded conditions

About 12 minutes prior to the accident, the Cooma-Snowy Mountains Airport weather station indicated a wind speed of 25 kt, gusting to 39 kt, from a direction of 320°. The visibility was 6,000 m, with a QNH[51] of 1002 hPa, and temperature of 26 °C.

A personal weather station at Peak View, located about 1.3 km from both the drop and accident sites (Figure 6), recorded the conditions twice per hour. At about 1309 (7 minutes prior to the accident), the station recorded a mean wind of 15 kt from the west and a peak gust of 32 kt from the north, a temperature of 30 °C, and a QNH of 995 hPa.[52] At about 1330 (14 minutes after the accident), the station recorded a mean wind of 16 kt from the west and a peak gust of 42 kt from the north-west.

Figure 6: Accident circuit with predominant wind direction, direction of travel (DOT), and terrain

Figure 6: Accident circuit with predominant wind direction, direction of travel (DOT), and terrain

Source: Google earth, Peak View weather station and SkyTrac data, annotated by the ATSB

Bureau of Meteorology analysis

The Bureau of Meteorology analysed the conditions on the day and indicated that a cold front was approaching the accident location, with hot and strong north to north-westerly winds ahead of the front. High resolution weather model data indicated the winds at 5,000 ft AMSL were about 45 kt from the north-west, increasing in strength with height up to 80 kt from the north-west at 10,000 ft AMSL.

Gusting winds had produced some areas of blowing dust, which likely reduced visibility. Bushfire smoke in the area had also affected visibility. While nearby observations at the Cooma-Snowy Mountains Airport showed intermittent reductions in visibility, it was noted that measuring equipment may not have accurately reported visibility in smoke conditions. Therefore, it was likely that the actual visibility was lower than that reported by the instruments.

The strong winds over the terrain likely resulted in severe turbulence and mountain wave development. Satellite imagery of cloud formations confirmed the presence of mountain wave activity during the day. The conditions in the area at the time were generally favourable for mountain wave development, however, the Bureau of Meteorology were unable to determine the severity of this from the data available.

The Bureau of Meteorology considered that the conditions at the Cooma-Snowy Mountains Airport were likely representative of the general conditions experienced at the accident location. Further, their analysis of the weather conditions in the area was consistent with what was forecast on the day.

Accessing meteorological information

For operations in NSW, following the briefing with the Richmond ABM each morning, the crews would return to their own operational areas until they received a tasking from the RFS. On receipt of a tasking, crews would conduct their flight planning. It was reported that the operator’s crews used an electronic flight bag (their company issued iPad including the Foreflight app) to submit their flight plan to Airservices Australia, which also provided access to the required weather forecasts. While specific weather data access could not be confirmed, as the flight plan had been submitted, it was considered very likely that the crew of B134 would have also accessed the relevant weather information at that time.

In addition, the operator outlined that conditions at a fire could change rapidly, and when the fire was an hour or more flight time away, reported weather conditions were likely to be inconsistent with the actual conditions on arrival.

Weather systems: Mountain waves and windshear

Mountain wave activity

Mountain waves[53] are the result of flowing air being forced to rise up the windward side of a mountain range, then as a result of certain atmospheric conditions, sinking down the leeward side (ATSB, 2009). Immediately downwind of the range there is a strong downdraft followed quickly by an updraft, which produces the wave motion. According to Underdown and Standen (2003), mountain waves can develop when the wind direction is near perpendicular to a continuous mountain range and at a speed of 15 kt or more[54] at the summit, and increasing with height in a stable atmosphere. Aircraft may encounter severe turbulence in mountain wave systems.

Rotors or eddies can also be found embedded in mountain waves. Their formation usually occurs where wind speeds change in a wave or where friction slows the wind near to the ground. Often these rotors will be experienced as wind gusts or windshear (ATSB, 2009). According to the FAA (1997), localised gusts of 50 kt, with downdrafts greater than 1,500 ft/min, are not unusual in mountain wave systems. Although this phenomenon is usually forecast reasonably well by the Bureau of Meteorology, many local factors may also affect the formation of mountain wave activity.

When discussing the consequence on aircraft performance, the ATSB’s safety publication Mountain wave turbulence noted that (ATSB, 2009):

Many dangers lie in the effects of mountain waves and associated turbulence on aircraft performance and control. In addition to generating turbulence that has demonstrated sufficient ferocity to significantly damage aircraft or lead to loss of aircraft control, the more prevailing danger to aircraft in the lower levels in Australia seems to be the effect on the climb rate of an aircraft.

Study of mountain waves associated with bushfires

According to the Bushfire and Natural Hazards Cooperative Research Centre,[55] one of the most challenging situations in fire management was when relatively benign weather conditions were expected, but a severe fire eventuated. In December 2016, the centre released Hazard note issue 24: Fire escalation by downslope winds. The note, authored by specialists from the Bureau of Meteorology, investigated the meteorology of unexpected severe fire behaviour associated with mountain wave activity and identified 3 relevant bushfires. A detailed case study of the New South Wales (NSW) Blue Mountains fires of October 2013 was undertaken, focussing on 17 October at 1300. Of interest was the behaviour of the winds in the vicinity of the State Mine fire.

Figure 7 shows a cross-section of the horizontal wind speeds (left image) and vertical wind speeds (right image) along a section passing from the north-west to the south-east through the State Mine fire‑ground. The red circled region in the left image shows strong horizontal winds extending downwards towards the surface in the vicinity of the fire. Downwind (to the right) of the fire are oscillations (left image) in the wind speeds and alternating bands of ascending and descending air (right image), both of which are characteristic features of mountain waves. The note described mountain waves as:

Mountain waves are oscillations that can occur when the wind blows across a mountain or hill. They are somewhat similar to water flowing over a rock in a stream, but are much more complex because their existence and amplitude is sensitive to the atmospheric temperature structure (stability) and vertical variation of the wind (wind shear). They often lead to strongly accelerated flow attached to the lee slope of the mountain or hill, known as downslope winds…

Figure 7: North-west to south-east cross section of fire, illustrating horizontal (left image) and vertical (right image) wind speed changes, with the fire located near the number 6 on the horizontal axis

Figure 7: North-west to south-east cross section of fire, illustrating horizontal (left image) and vertical (right image) wind speed changes, with the fire located near the number 6 on the horizontal axis

Source: Bushfire and Natural Hazards Cooperative Research Centre

While the purpose of the note was to consider the wind effect on the severity of a fire, this has potential implications for firefighting aircraft, particularly if low-level windshear was present. As a comparison, at position 1 on the horizontal axis (left image), the wind speed band of 45–55 kt would not be encountered until reaching a height greater than 8,000 ft (2,450 m) above the surface. However, at the fire-ground at position 6, these wind speeds could be encountered within a few hundred feet above the surface. The note also highlighted that this research revealed features at the location of the fire-ground that might not have been captured or possibly filtered out of broader‑scale forecasts.   

Windshear

Windshear is defined by the Bureau of Meteorology (2014) as a ‘wind direction and/or speed change over a vertical or horizontal distance’. It is always present in turbulent air but can also occur without turbulence being present. This phenomenon becomes particularly significant when an aircraft is abruptly displaced from its intended flight path and substantial corrective action is required by the pilot. This is more so at lower levels and low speed, such as during take-off and landing. The hazards are a rapidly changing headwind and tailwind, strong side gusts, and a change in lift on the wings, all during a time when an aircraft is most vulnerable (Minor, 2000). Specifically, the Bureau of Meteorology (2014) noted that:

During the climb-out and approach phases of flight, aircraft airspeed and height are near critical values, rendering the aircraft especially susceptible to the adverse effects of wind shear.

Aircraft taking-off may be significantly affected by changes in headwind and tailwind components which create changes in the amount of lift experienced. A decrease in the vertical headwind component, or an increase in the tailwind component, will result in a reduction in airspeed, and in extreme cases the resulting loss of lift may be enough to cause the aircraft to stall or fly into the ground.

Likewise, the adverse effects on aircraft performance from low-level windshear was also discussed by Bowles (1990), when analysing airborne forward-looking windshear detection systems:  

The hazard of windshear arises principally from its deceptive nature: In a windshear situation, from a microburst[56] or any other source, the pilot may be confronted with a performance-increasing headwind, followed a few seconds later by a powerful, performance-decreasing tailwind. To cope with the headwind, the pilot may take actions to prevent the plane from climbing. These actions are then compounded by performance loss caused by the tailwind and downdraft, so that it may be impossible to avoid ground impact.

Depending on crew action, a typical low altitude windshear may result in reduced airspeed and rate‑of-climb, which often result in significant altitude loss and possible ground impact. Full performance capability depends on two key factors: timely recognition and appropriate response.

Windshear controls

Aviation specific windshear research

In 1985, the FAA contracted a consortium of aviation specialists to study windshear. As a result of that work, a windshear training aid was developed. The aid provided an effective means of training crews to minimise the windshear threat through avoidance, cockpit recognition, and recovery techniques. This included the 1988 publication Pilot windshear guide (FAA advisory circular 00‑54). This outlined the limitations in pilot avoidance, with a reliance on visual indications, which can be complicated by marginal weather, and reports from other aircraft in high density traffic areas.

According to the advisory circular, between 1964 and 1986, there were at least 32 air transport accidents and incidents in which windshear was identified as a contributing factor, resulting in over 600 fatalities. There was also evidence to suggest that this figure was underestimated as it did not include undocumented ‘close calls’ and general aviation statistics.

Generally, the research showed that only 5 to 15 seconds may be available for the crew to recognise and respond to a windshear encounter. In describing a typical encounter shortly after take-off, with windshear encountered prior to a stabilised climb (Figure 8), for the first 5 seconds the take-off appeared normal, with early trends in airspeed, pitch attitude, vertical speed and altitude appearing normal. However, as airspeed decreased, pitch attitude was reduced, limiting performance capability, and resulting in a loss of altitude.

Figure 8: Effect of a windshear encounter on the aircraft flight path during take-off

Figure 8: Effect of a windshear encounter on the aircraft flight path during take-off

Source: US Federal Aviation Administration

The timeframe mentioned above was consistent with windshear research reported by Tsukagoshi (1999) conducted following a 1993 Douglas DC-9-41 hard landing accident in Japan following windshear during the landing approach (while crossing the runway threshold in Japan). Following the occurrence, the Japan Federation of Flight Crew Unions established a project to obtain objective and quantitative data on flight crews’ reactions to windshear. The research was supervised by Dr Sado Horino from Kanagawa University, Japan, and was conducted on a DC-9 flight simulator at Northwest Aerospace Training Corporation near Minneapolis, US.

Eight DC-9 pilots completed 35 test approaches to land on the simulator. Windshear was encountered at random heights, from 50 ft to 900 ft. Of particular note, the results demonstrated that the average recognition time for a windshear encounter was about 5.5 seconds. Recognition time was defined as the time between the windshear encounter and when the pilot first moved the elevator control.

Windshear risk control systems

Windshear avoidance, based on pilot awareness and training, cannot be 100% effective. There are also limitations in recognition and recovery procedures, as this requires the aircraft to have entered the windshear condition, which can potentially exceed the aircraft’s performance capability, regardless of pilot actions. Therefore, ground-based and airborne detection systems have also been introduced to reduce the hazard of an inadvertent windshear encounter (Bowles, 1990).

Ground-based low-level windshear alerting systems were developed and introduced at selected airports, predominantly in the US. However, there were 2 prominent windshear accidents in the 1980s (a Pan Am Boeing 727 on 9 July 1982; and a Delta Airlines Lockheed L-1011 on 2 August 1985), which prompted the FAA, in 1988, to mandate the use of airborne windshear detection systems for passenger aircraft.

The initial airborne windshear detection systems were reactive systems, which relied on the aircraft performance instruments, combined with attitude, angle of attack and accelerometer inputs. According to FAA advisory circular 25-12, Airworthiness Criteria for the Approval of Airborne Windshear Warning Systems in Transport Category Airplanes, even reactive systems ‘provide a valuable service in the detection, timely annunciation, and confirmation of a potentially hazardous windshear condition generally in advance of human pilot recognition time’. With the development of digital signal processors in the 1990s, weather radar with forward-looking (predictive) windshear detection became possible and the first system was certified by the FAA in 1994. The requirement was to provide at least 10 seconds advance warning to the crew of a microburst. These systems used doppler weather radar and the moisture in the atmosphere to collect wind velocity data. Therefore, drier air would reduce the reflectivity and windshear warning time.

An article published by Honeywell Aerospace (2019), Radar Corner: Understanding Airborne Windshear Detection Systems, Part One, emphasised that ‘It is the advanced warning time that saves the aircraft’. This time allowed the pilot to increase engine power, and retract the flaps and landing gear, thereby increasing the aircraft’s energy state and climbing, so that the windshear encounter would occur at a higher, ‘more survivable altitude’. The article further indicated that, during studies evaluating windshear recovery manoeuvres, it was found that when a windshear recovery manoeuvre was delayed by 5 seconds, the average altitude loss increased by 300 ft.

Another study on Wind-Shear System Cost-Benefit Analysis (Hallowell and Cho, 2010) reviewed the effectiveness of various detection systems, as the FAA considered the options for managing aging systems and evaluating new systems. The study also considered windshear mitigation strategies, which were categorised into 3 groups: pilot recognition and recovery training, airborne (aircraft systems), and ground‑based systems.[57] While noting the difficulties in determining the effectiveness of pilot training in recognition and avoidance, for comparative purposes, this was estimated to be effective about 25% of the time. Conversely, while only measured in simulated environments, the effectiveness of predictive windshear (airborne) systems had often exceeded 95%, although this may be reduced in dry environments.

Notably, Hallowell and Cho (2010) identified that each of these categories provided their own advantages, with the greatest benefit achieved when multiple categories were combined. It also noted that air taxi and aerial work operations, which included firefighting aircraft, operated at low‑level and low‑speed outside the ground-based protection areas more frequently than air transport. Further, airborne systems including both reactive and predictive windshear systems, were not routinely available on air taxi, aerial work or general aviation aircraft.

While there are limitations to reactive and predictive systems, where these systems were fitted to firefighting aircraft, and warnings had activated in the low-level environment, several pilots reported at interview this had a positive effect on their management of the situation. In addition, in 2018, Lockheed Martin developed a civil-certified firefighting air tanker, which was a variant of the C-130J. The LM‑100J ‘FireHerc’ had numerous advanced features that provided increased situational awareness and modern safety features to protect and guide crews through challenging flight conditions. Of most relevance to this investigation was the inclusion of warning systems with visual and aural alerts for windshear detection.

The accident aircraft was not fitted with a windshear detection system as it was built in 1981, prior to such technology becoming available. Likewise, the operator’s other C-130 aircraft did not have this system. Retrofitted systems suitable for the C-130 have since become available.[58] However, the operator advised that they had not considered installing these systems into their C-130 fleet. Further, it was not required by regulation or contract to be installed.

On 10 July 2022, in response to the draft report, Coulson Aviation advised that aerial firefighting operate in very dry environments conducive to active fires. Therefore, with minimal or nil moisture present in the atmosphere it could be concluded that a forward-looking windshear detection system would provide little to no advance warning of a windshear event. They further indicated that their crews were highly experienced in recognising windshear events and crew reaction times would be as timely, if not quicker than a reactive-based system. The operator further advised that this statement was based on ‘rational conclusion’ based on experience supported by informed opinion. The ATSB was unable identify any research that supported this comment.

Lockheed Martin Airplane Flight Manual

The Lockheed Martin AFM contained a section on adverse environmental conditions, which defined windshear as ‘any rapid change in wind direction or velocity that results in an airspeed change of more than 10 knots’. Severe windshear was defined as ‘a rapid change in wind direction or velocity causing airspeed changes greater than 15 knots, or vertical speed changes greater than 500 fpm [ft/min]’.

The AFM also warned pilots that severe windshear, particularly those with downdrafts, could exceed aircraft performance capability. It was considered to be most dangerous at low levels when encountering a decreasing headwind (or increasing tail wind) such as during take-off and approach. At these times, the aircraft is at low-level and low speed, and the initial reaction of the aircraft will be a drop in indicated airspeed and a decrease in pitch attitude, resulting in a loss of altitude.

By 2010, the Lockheed Martin AFM had introduced a recovery procedure for severe windshear encountered during approach to land as:

1. Announce a go around.

2.Set maximum power and select a go around (G/A) flight director mode, if applicable. Best initial pitch attitude will be a function of the conditions. If ground impact is a concern, rotate above the G/A flight director cue, as necessary, to target threshold speed until safe altitude above the ground is reached.

3.The co-pilot will monitor and call sink rate (VVI/VSI) and airspeed as appropriate.

4.The navigator/engineer will monitor and call out radar altimeter.

5.If flaps are at 100%, transition to 50% flaps after assuring continued positive rate of climb at no lower than Obstacle Clearance Speed.

6.Do not retract the landing gear until recovery is complete with positive climb rate and increasing terrain separation.

7.When clear of the wind shear, adjust pitch and power for normal climbout.

8. When conditions permit, report the encounter with ATC.

Coulson Aviation’s Airplane Flight Manual and Company Operations Manual

On 10 July 2022, in response to the draft report, Coulson Aviation stated that the precursors that generally defined windshear would be routinely encountered in normal aerial firefighting operations due to the hot, dry, and windy conditions that lead to most bushfires. Therefore, the procedures, experience, and training to deal with, and respond to these conditions were in-built for their aerial firefighting operations. However, the ATSB noted that there was no windshear recovery procedure published in the operator’s AFM, nor did it contain a section on adverse environmental conditions.

The manual did contain a warning associated with the go-around procedure, which was described by the operator’s pilots as similar to the post-retardant drop climb out:

Retracting flaps from 100 percent to 50 percent will increase stall speed. Without proper power and attitude corrections, sink rate will also increase. This is particularly noticeable at lower than normal airspeeds. If safe altitude and airspeed are not attained, inadvertent touchdown and/or stall may occur.[59]

The COM contained information on windshear in the departure procedures section, which stated:

…wind shear may create a severe hazard for aircraft below 1,000 ft…the best defence is to avoid downdrafts altogether as it could be beyond you or your aircraft’s capability… If wind shear is encountered, prompt action is required. In the EC-130Q/L382G, the recovery requires full power and pitch attitude consistent with the maximum angle of attack for the aircraft.

The majority of the crew interviewed provided accounts of personal experiences with either a real or simulated windshear event in the low-level airdrop environment. It was noted that in-aircraft training was conducted by the operator for emergency scenarios with a focus on jettisoning the retardant. These descriptions were consistent with the manufacturer’s procedures for windshear recovery, with additional consideration of jettisoning the load if aircraft performance did not improve after maximum power was applied.

Coulson Aviation windshear training

A review of the operator’s C-130 simulator training syllabus noted there was no specific training item for a low-level windshear recovery scenario. The syllabus only noted that a briefing on recovery from windshear was to be conducted.

The operator conducted yearly training that consisted of ground school, simulator training, and in-aircraft flight training. Included in the ground school training were ‘consider the load’ discussions, where if there was an emergency or performance concern, they could jettison the load to improve aircraft performance. Further, in-aircraft training was conducted where each PIC completed a ‘consider the load’ scenario, with a focus on jettisoning the retardant. Any applicable emergency or non-normal event could be used for this purpose, which at times included a simulated ‘down air’ (downdraft) scenario.

At interview, it was noted by at least one pilot that the air drop[60] scenario was quite different between the firefighting and military scenarios, and that standardisation for completing these operations occurred through the operator’s yearly training sessions.

On 10 July 2022, in response to the draft report, Coulson Aviation indicated that the response to a downdraft was consistent with the windshear escape manoeuvre for most large aircraft, with the added protection of being able to jettison the load to increase aircraft performance. In addition, the operator emphasised that the majority of their C-130 crews were current or former military pilots, where windshear recovery training was conducted on a bi‑annual basis. Therefore, the operator considered their pilots to be ‘extremely familiar’ with the procedure.

Wreckage and impact information

Accident site

The accident site was located on slightly sloping, partially wooded terrain, near Peak View, 50 km north-east of the Cooma-Snowy Mountains Airport. The wreckage trail (Figure 9) was approximately on a heading of 100°, with the initial impact at an elevation of about 3,440 ft AMSL. The debris trail began at the lower end of the slope, with the wreckage distributed linearly over about 180 m.

Figure 9: Accident site overview showing the wreckage trail

Figure 9: Accident site overview showing the wreckage trail

Source: ATSB

Wreckage examination

The ATSB’s on-site examination of the wreckage, damage to the surrounding vegetation, and ground markings, all indicated that the aircraft initially impacted a tree in a left wing down attitude of about 55°, before colliding with the ground. An intense post-impact fuel-fed fire destroyed the aircraft. The ATSB’s on-site examination also found (Figure 10):

  • no pre-existing airframe issues
  • all major sections of the aircraft’s structure were identified and there was no evidence of an in‑flight break-up or pre-impact structural damage[61]
  • the cockpit and associated avionics were identified about two-thirds of the way along the wreckage trail
  • the cockpit and forward section of the airframe had separated from the fuselage, was inverted, and had been destroyed in the impact and fire
  • sections of the wing skin, leading edge spar, wing tips and portions of the wings were identified along the wreckage trail, having fragmented during the impact sequence, and sustained further damage during the fire
  • all flight control surfaces were identified, however, flight control continuity could not be established due to the impact and fire
  • the vertical and horizontal stabilisers had remained attached to the aft section of the fuselage
  • the 4 engines and 16 propeller blades were located on-site and some of the propeller blades remained attached to the propeller hubs, while others had detached through impact forces
  • there were varying degrees of damage observed across the 4 engines, likely due to the impact sequence of each engine, with the damage indicating the engines were rotating at impact.

The RADS tank remained upright, with no fire retardant identified between the drop area and the initial impact location. However, a large amount of retardant was located in the wreckage near the tank. The system was badly damaged, with the doors fragmented throughout the wreckage, and its operational state could not be established. 

Figure 10: Main aircraft wreckage components

Figure 10: Main aircraft wreckage components

Source: ATSB

Aircraft configuration

The aircraft was equipped with 4 trailing edge flaps. All flaps had separated from the aircraft during the impact sequence. On-site measurements of the flap screw jacks indicated the flaps were set at 50% at impact. This was consistent with the expected setting following a retardant drop. Due to the extent of damage, the elevator, aileron, and rudder trim settings could not be established.

Fuel testing

Fuel samples were retained from the 2 fuel tankers that last serviced the aircraft and from the refuelling storage tank at Richmond. The fuel samples were independently tested by a commercial fuel company for correct specifications, with nil abnormal indications found. In addition, there were no reports of fuel quality concerns with any other aircraft using the same fuel source.

Engine and propeller examinations

With the assistance of the Australian Army, the engines, partial remnants of the reduction gearboxes, and propeller assemblies and blades were transported to a secure hangar at Richmond Royal Australian Air Force (RAAF) Base for further examination. The engine manufacturer attended the inspections, where it was confirmed that all engines were rotating at impact, and there were no noted pre‑existing issues. As power changes were controlled by changes to the propeller blade pitch while maintaining a constant engine speed, the engine power levels were determined from the blade pitch angle at impact.

During the propeller hub assembly inspection, measurements of the internal components were recorded. The ATSB consulted the propeller manufacturer to determine the propeller blade angles at impact, and establish engine power levels. The propeller manufacturer concluded the following:

The calculations indicate that, based on the operating conditions estimated by the ATSB,[62] all the propellers were absorbing power from their respective engines and were producing positive thrust. The horsepower computed for each of the four engines are within the normal operating range for the T56 engine installed on this aircraft.

Recorded information

General information

The aircraft was not fitted with a flight data recorder, nor was it required to be by Australian or US regulations. However, there were devices on board that recorded information relevant to the flight path, as well as data that was transmitted in real time. Further, 2 firefighters located near the accident had videoed the aircraft. An analysis of these sources are presented below.

Witness video

Two firefighters were located on Feeney’s Road (800 m from the accident site), and both videoed the aircraft during the retardant drop. One video was taken in the landscape orientation and had a duration of 18 seconds. This video captured the drop and stopped as the aircraft was descending). The other video was taken in the portrait orientation and was 37 seconds in duration. It captured the aircraft descending into the drop zone and ended after the aircraft impacted with terrain. Collectively, the videos captured the aircraft from 10 seconds prior to the retardant drop, the drop, and the 5 seconds after the drop when the aircraft became obscured by smoke and was only intermittently visible (Figure 11). From the witness video, it was unclear if the aircraft flew behind the smoke, or entered the smoke. Seventeen seconds after the drop, the aircraft was seen at low-level, followed by the collision with terrain and post-impact fire.

The videos were analysed by the ATSB using commercial camera tracking software[63] to estimate the aircraft’s flight path and attitude. The RAAF Aircraft Research and Development Unit also analysed the video to evaluate the aircraft attitude. These analyses indicated that:

  • at 1315:15 (commencement of the drop), the aircraft was at a left bank angle of 10°, with a pitch of 0°
  • at 1315:17 (end of the drop), the aircraft was at a left bank of 17° and a pitch-up of 6°
  • at 1315:21, the aircraft reached its maximum left bank of 31°and maximum pitch-up of 12°
  • at 1315:22 and 1315:23, the aircraft was obscured by smoke and the attitude could not be determined
  • at 1315:25, the aircraft was at a left bank of 18° and a pitch-up of 8°
  • at 1315:26, the aircraft was at a left bank of 5° and a pitch-up of 6°
  • at 1315:27, the aircraft was at a right bank of 6° and pitch-up of 5°.

From 1315:27 the aircraft was obscured by smoke, and the attitude could not be determined using SynthEyes. The general attitude could be determined from basic photogrammetry at limited points from this time.

Figure 11: Aircraft attitude and approximate flight path at key times

Figure 11: Aircraft attitude and approximate flight path at key times

Source: Google earth and SkyTrac data, annotated by the ATSB

For about 10 seconds after the completion of the drop, a positive rate of climb was achieved, with the aircraft climbing about 170 ft (to 3,770 ft AMSL) from the drop height. Following this, the aircraft was then observed descending. At 1315:34, the aircraft was seen at a very low height above the ground, in a slight left bank, immediately followed by a significant left roll just before ground impact. The elevation of the terrain, while undulating, also increased by about 40 ft from the drop site to the accident site.

The footage was also used to review aircraft control and configuration changes, such as flap positions and aileron movement. Shortly after the drop, the flap position was assessed as being 100%, consistent with the operator’s AFM supplement drop procedure. However, further assessments could not be made due to limitations with the video quality, visibility, and aircraft attitude. At various points in the video, both left and right aileron movement could be seen, but actual deflections could not be determined.

The videos also provided a general understanding of the low-level wind conditions at the time, with significant audible and visual movement of the surrounding trees and smoke, and blowing dust at ground level. It was also noted that there was no video evidence of any retardant being dropped between the initial drop location and the impact site.

Operational load monitoring system

Aerial firefighting contract requirements in the US required the aircraft be fitted with an operational load monitoring system (OLMS), predominantly for monitoring aircraft loading during operation. The OLMS was located behind the centre wing section in the fuselage and recorded data at a rate of 32 Hz (32 times per second). This recording device had no impact or fire protection, and was destroyed in the accident sequence.

Six months of historical data for B134 was made available to the ATSB, to allow for a comparison of the available accident flight data with previous flights. This review identified that the pitch and angle of bank data was not recorded correctly by the OLMS. Therefore, only the flap retraction timing and duration, and the vertical speed (rate of climb/descent) could be compared. While there was no comparable data available for flights with the entire accident crew, a review of the PIC’s recent flights and comparison with other crews indicated that the flap retraction was generally initiated between 2.5 and 5.5 seconds (with an average of 3 seconds) after the drop was completed. It also showed that the actual flap retraction from 100% to 50% flap took about 4-5 seconds and was completed, on average, about 7-8 seconds after the drop.

The rate of climb post‑drop varied between 500 ft/min and 2,400 ft/min, with the majority of the flights between 1,100‑1,500 ft/min. These variations were possibly related to weather patterns, terrain limitations, and the operational requirements, which were unique to each drop. 

SkyTrac and automatic dependent surveillance broadcast (ADS-B) data

Aerial firefighting contracting requirements in Australia required the aircraft to be fitted with a tracking capability. The aircraft was fitted with SkyTrac, a system that could transmit the aircraft’s position in real-time, and was monitored by the NSW Rural Fire Service (RFS). The SkyTrac unit was recovered from the wreckage and transported to the ATSB’s technical facility for examination and download. The Canadian Transportation Safety Board assisted in the conversion of the downloaded data.[64] The SkyTrac unit recorded data at 5 second intervals.

Data broadcast by the automatic dependent surveillance broadcast (ADS-B) equipment fitted to the aircraft for air traffic control purposes was also obtained from various providers. This system determined the aircraft’s position using GPS and then broadcast this information, along with pressure altitude,[65] ground speed,[66] and other data, at regular intervals. ADS-B data was transmitted every 0.5 seconds, however, not all transmissions were available, with gaps of up to 5 seconds during the accident flight. Aside from the difference in recording intervals, the data provided for the common parameters across both sources was identical.[67] Table 2 shows the parameters recorded by SkyTrac and ADS-B.

Table 2: SkyTrac and ADS-B recorded parameters

SkyTracADS-B
·      time·        time
·      latitude and longitude (position)·        latitude and longitude (position)
·      ground speed·        ground speed
·      track·        track
·      GPS altitude (AMSL)·        pressure altitude
 ·        vertical rate of climb/descent
Airspeed calculations

Using the ground speed from the SkyTrac and ADS-B data, and the weather observations from Peak View, the wind speeds of 15, 30 and 40 kt from the north-west were used to estimate the aircraft’s true airspeed.[68] These values were consistent with a review of the aircraft ground speed in the drop planning circuits. These circuits showed a periodic variation consistent with the aircraft flying into, and then with, the wind, and indicated that the wind speed was likely of a magnitude of 20-40 kt from a north‑westerly direction during their drop planning circuits.

The calculated true airspeed values were then converted to a computed calibrated airspeed (CAS)[69] using temperature and pressure data also from Peak View. The airspeed calibration charts in the operator’s C-130 AFM showed that there was a negligible difference between the CAS and indicated airspeed at the airspeed range being considered. Therefore, the CAS was equivalent to the indicated airspeed that would have been presented to the crew on the airspeed indicator.

The data showed a limited increase in the ground speed from 144 kt at the start of the drop, to 149 kt during the post-drop climb-out period, to a maximum of 151 kt just prior to the collision with terrain. However, the CAS (Figure 12) can be seen to be significantly lower, and with a much smaller increase during the climb. In the last 15 seconds of the available data, the calculated CAS was between 100 and 123 kt.

Vertical speed

From the SkyTrac data, a positive rate of climb was recorded for the 10 seconds following the drop, with the aircraft climbing to about 170 ft above the drop height, which was consistent with the witness video. The derived vertical speed,[70] while noting its limitations (as described above for the operational load monitoring system), increased from zero at the end of the drop to about 1,000 ft/min in the 8-10 seconds after the drop, then decreased to about 0 over the next 5 second period. At the last data point, the aircraft was descending at about 2,000 ft/min.   

Aircraft track

From both SkyTrac and ADS-B data, the retardant drop was conducted on a track of about 190°. The aircraft was then turned through 160° as the climb rate peaked, with the last recorded track of 133°, about 3 seconds prior to impact.

The recorded ground speed, calculated CAS, track, derived vertical rate, and altitude for the last 30 seconds of flight is shown in Figure 12.

Figure 12: Recorded flight path data, derived airspeed, and rate of climb for the last 30 seconds of flight

Figure 12: Recorded flight path data, derived airspeed, and rate of climb for the last 30 seconds of flight

Source: SkyTrac and Geoscience Australia digital elevation data, annotated by the ATSB

Low pressure spike

Prior to the drop, the ADS-B pressure altitude was, on average, about 250 ft above the SkyTrac GPS altitude (Figure 13), which was consistent with the QNH on the day. It was noted that there was a small increase in the ADS‑B pressure altitude immediately following the drop. This was consistent with the RADS tank doors closing on previous drops, but this returned to about a 250 ft difference with the GPS-based SkyTrac altitude.

However, at about 1315:24, the ADS-B pressure altitude and the vertical rate began to diverge significantly, with a low atmospheric pressure spike at about 1315:29. This was identified by an abrupt increase in both the pressure altitude[71] and barometric vertical speed. In comparison, the SkyTrac GPS-based derived vertical speed showed a smaller increase, which correlated with the SkyTrac altitude.

As there were several data points associated with this spike, this was considered more likely to be associated with a real event, rather than an erroneous reading. The abrupt rise and fall in these parameters suggested the aircraft encountered a region of low pressure, relative to the surrounding air, with a steep pressure altitude gradient during the climb‑out.

The reason for the localised pressure change could not be determined by the ATSB. Aircraft configuration changes (the RADS tank doors opening or closing, and flap changes) were excluded based on a review of the historical OLMS data. Several other potential factors were considered, including localised turbulence, wind gusts, terrain effects, temperature changes, and fire driven changes associated with smoke plumes. However, limitations in the available evidence prevented a determination.

Figure 13: Comparison of SkyTrac and ADS-B altitude and vertical rate data showing the low-pressure spike

Figure 13: Comparison of SkyTrac and ADS-B altitude and vertical rate data showing the low-pressure spike

Note: ADS-B pressure altitude shown as recorded references the international standard atmosphere QNH rather than actual QNH.

Source: ADS-B and SkyTrac, annotated by the ATSB

Cockpit voice recorder

The cockpit voice recorder (CVR) fitted to the aircraft was a solid-state memory Universal Avionics Model CVR-30B, part number 1603-02-03 (Figure 14). CVRs are designed on an endless loop principle, with the oldest audio continuously overwritten by the most recent audio. In this case, the CVR recorded crew and cockpit audio for a duration of at least 30 minutes. While the aircraft was not required to be fitted with a CVR under the US or Australian regulations, it was a contract requirement with the US Department of Agriculture, Forest Service (USFS). 

Figure 14: N134CG cockpit voice recorder

Figure 14: N134CG cockpit voice recorder

Source: ATSB

The CVR was recovered from the aircraft and transported to the ATSB’s technical facility in Canberra on 25 January 2020 for examination and download. Thirty‑one minutes of audio data was successfully downloaded. However, the audio was from a previous flight when the aircraft was operating in the US. No audio from the accident flight was recorded on the CVR.

Inertia switch

The power supply to the CVR was fitted with an inertia switch. Inertia switches are designed to stop the recording function by removing power to the CVR when a pre-set deceleration force was detected. The recovered audio was of crew training flights undertaken on 7 May 2019 near Sacramento McClellan Airport, California. The audio included 4 landings conducted as part of that training. The recording ceased immediately after the fourth landing, and the post-landing taxi and engine shutdowns were not recorded. It was likely that the inertia switch was activated during this landing and consequently disconnected power to the CVR.

Pre-flight testing

Following installation in an aircraft, supplemental material related to the operation of the CVR must be attached to the approved AFM. The supplement for the accident aircraft indicated that the CVR conducted a self-test at power up, and the status of the system would be presented to the crew on the CVR control unit, located on the copilot side console. A CVR system check for crew was also included in the operator’s AFM supplement, but was not included in their pre-flight checklists. None of the operator’s C-130 flight crew interviewed were aware of the need to check this system status prior to flight.

CVR maintenance

A review of the aircraft’s maintenance logs indicated that the underwater locating beacon attached to the front of the CVR was replaced on 24 December 2019. This was a self-contained, replaceable unit, and a full maintenance service check was not required with this replacement. A maintenance check was conducted yearly, and had last been performed in February 2019.

Medical and pathological information

Pilot in command

The PIC held a first-class medical certificate that was issued on 5 September 2019 by the FAA, with a limitation to wear corrective lenses. The PIC’s aviation medical records were provided for the period 2013 to 2019. Overall, these examinations reported no significant medical conditions or abnormal physical findings. Of note, the PICs last electrocardiogram (ECG),[72] conducted as part of their annual medical examinations, showed indications of an inter-atrial conduction delay,[73] while previous ECGs noted sinus bradycardia.[74] Otherwise, the ECGs were considered normal and were ‘cleared’ by the FAA medical officer.

The PIC was reported to be fit and active, with no known medical conditions. On the morning of the accident flight, the PIC’s behaviour appeared normal and there was no evidence to indicate any concerns regarding their general health. While limited, the post‑mortem examination did not identify any pre‑existing medical conditions that could have contributed to the accident nor detect any commonly used drugs or alcohol. Due to limited blood samples, carbon monoxide testing could not be conducted.

Copilot

The copilot’s most recent first-class medical examination was issued on 17 July 2019 with no limitations. The copilot’s aviation medical records were provided for 2018 and 2019. The records reported no significant medical conditions or abnormal physical findings. The records noted that they were taking prescribed medication to lower blood cholesterol and reduce the risk of heart disease. The copilot’s last ECG noted several common anomalies,[75] but it was ‘cleared’ by the FAA medical officer.

The post-mortem examination identified narrowing and areas of calcification[76] in both the left anterior descending artery and right coronary artery of the heart. However, the muscle layer of the heart showed no identifiable scarring and there was no indication of an acute coronary artery occlusion (blockage). While no other evidence of significant natural disease was identified, the examination concluded that, the significance of the narrowing, in the absence of any evidence to indicate a blockage in the heart, was unclear. In addition, toxicology testing did not detect the presence of any alcohol, or common medications and illicit drugs. Carbon monoxide testing could not be conducted due to the lack of a suitable sample material.

Flight engineer

The flight engineer’s most recent second-class medical examination was issued on 27 August 2019 with no limitations. From their 2019 aviation medical records, there were no reported medical conditions or abnormal physical findings that could have affected aircraft operations. While limited, the post‑mortem examination did not identify any pre‑existing medical conditions that could have contributed to the accident. The toxicological analysis identified traces of a commonly used over-the-counter antihistamine. Carbon monoxide testing could not be conducted due to the lack of suitable sample material.

Aviation medical specialist

The ATSB engaged an aviation medical specialist to review the crew’s aviation medical records and post-mortem examinations. Noting the limited evidence that could be collected from the examinations due to the nature of the accident, the specialist concluded that:

  • As best as could be determined, there was no suggestion of in-flight incapacitation.
  • The copilot’s examination identified that 2 of the arteries in their heart showed evidence of narrowing and calcification, but there was no pathological evidence of acute coronary occlusion. The copilot had been taking prescribed medication to treat elevated cholesterol levels for several years. This medication was approved for use by flight crew in both the US and Australia. Further, the copilot’s blood pressure readings and last ECG tracing were all within normal limits.
  • The detection of the antihistamine and the reported concentration could not be used to determine with any certainty if the flight engineer was using the medication at the time of the accident or during non-flying periods. This was considered an ‘incidental’ finding.
  • While any exposure to carbon monoxide from the fires could not be determined in this case, limited research on a small cohort of ground fire-fighters many years earlier, determined that carboxyhaemoglobin[77] levels of around 6% were indicative of fire-ground exposures. This level, had it been present in the crew, was not likely to have caused in‑flight incapacitation.

Test and research

Reconstruction flight

On 24 January 2021, at about 1300, the operator reconstructed the flight path from the drop location to the accident site. The intention was to record the perspective and challenges of the terrain, while acknowledging the lack of bushfire smoke and environmental conditions. The flight was in a Cessna Citation 550 (business jet), with the Director of Flight Operations on board. They flew the path twice, firstly at 3,665 ft AMSL and then at 3,610 ft AMSL (noting the accident flight path was at about 3,600 ft AMSL). They noted that, as they turned toward the drop exit and were flying towards the accident site, they experienced an airspeed decay, even as engine power was increasing. While this was not considered ‘extreme’ on the day, it was ‘a bit surprising’. Further, they stated that the path flown by the crew of B134 from the drop to the accident site was into slightly rising terrain.

At the time of the flight, the METAR[78] for the Cooma-Snowy Mountains Airport recorded wind was 13 kt at 250°, with the direction varying between 200° and 290°. However, at 1143, a SPECI[79] recorded winds of 15 kt gusting to 29 kt at 260°, and the aerodrome forecast issued from 1200 indicated winds of 14 kt gusting to 25 kt at 270°.

C-130 simulator testing

Purpose

A series of tests were undertaken in a simulator representative of the accident aircraft, the RAAF C-130J-30 full flight mission simulator. The purpose of the testing was to determine if, and under what conditions, wind speeds representative of the strength and prevailing direction reported on the day of the accident could potentially affect aircraft performance. In particular, if the airspeed of the simulator could decay to the power‑on stall speed given the accident flight profile, of a climbing turn from 200 ft AGL. In addition, tests were also conducted to evaluate the effect following a weight reduction of 25,000 lbs (11,340 kg), from a jettison of the remaining fire retardant.

The testing was performed by RAAF Aircraft Research and Development Unit C-130 qualified test pilots (QTPs), supported by the simulator fidelity manager, under the direction of the ATSB. There were no recordings available of the accident crew’s actions. Therefore, the testing was limited to attempting to replicate the known flight path and aircraft attitude, with crew inputs (configuration and power setting changes) described as typical by the operator’s crew. The accident site and drop location were in the simulator database, which enabled a recreation of the accident flight profile from the start of the drop to be used for the tests. The intent was not to recreate the accident flight in full, or review the crew’s potential response to the situation, but focussed on the aircraft performance in the environmental conditions.

Aircraft differences

Access to a C-130H model simulator was limited, with none located in Australia and restrictions imposed by the COVID-19 pandemic. However, a C‑130J model simulator was offered to the ATSB. The C-130H (accident aircraft) and the C-130J were both listed on the same FAA Type Certificate. A discussion of the differences and limitations was held with the RAAF’s Aircraft Research and Development Unit chief of flight test, which considered the airframe, engines, aircraft controls, wings, aircraft systems and modelling limitations. The primary differences with respect to the aircraft were that the C-130J simulator had:

  • a longer airframe affecting some aircraft handling qualities
  • significant upgrades to the propulsion units
  • stall speeds likely to be slightly lower
  • aural and visual stall warnings, tactile stall warning (stick shaker) and stall avoidance (stick pusher) systems (not installed on the H model).

As control effectiveness was not being tested, the differences in aircraft handling qualities were of little impact to the proposed assessment. Similarly, an equivalent thrust level could be used to determine the necessary power settings, and limited to the available C-130H levels. To characterise the potential differences in stall speeds, a series of tests were completed, documented in the Results below. The stick shaker and stick pusher functions were both turned off during testing.

Simulator limitations

The ATSB also considered the limitations of the simulator, noting that they are designed for flight training, with the following being of most importance:

  • it had a pre-programmed stall characteristic of a 50° left wing drop
  • the stall was not considered to be well modelled
  • complex weather phenomena such as mountain waves and rotors could not be modelled
  • pre-programmed windshear models had a tailwind of 60 kt
  • wind gusts could be modelled, but the timing of the gusts could not be controlled.

As the test objectives were to characterise the flight profile with wind speeds that could reduce the airspeed to the stall speed, the pre‑programmed stall behaviour and modelling did not impose any limitations on the assessment. As the pre-programmed windshear model was in excess of the planned test conditions, the simulator fidelity manager developed a method to simulate windshear using the wind gradient tool. This resulted in the wind magnitude changing linearly, proportional to the altitude increase. This also required the test runs to commence in level flight at the drop height of 200 ft AGL, rather than from a descent profile to avoid a pre-drop windshear disrupting the climb-out test profile. A consequence of this methodology was that, on the occasions the simulator entered a pre-stall sink, it exited the windshear condition, which allowed it to recover airspeed and fly-away.

Test summary

The planned test criteria included constant winds of increasing strength, windshear of increasing strength, followed by the addition of turbulence[80] and gusts to each of these base conditions. Three thrust settings were calculated, based on the calculated true airspeeds (refer to section titled SkyTrac and automatic dependent surveillance broadcast (ADS-B) data) and propeller blade angles (refer to section titled Engine and propeller examinations) considered to provide reasonable boundary conditions.

Fourteen test profiles were developed, which included:

  • Three initial tests to establish the equivalent power settings, and comparison of the stall values against the C-130J and C130H flight manuals. It also included the development of the flight profile for the QTPs to practice using the pitch changes, bank angles and heading changes provided by the ATSB.
  • Eight profiles were planned for the QTPs to fly the accident profile under various wind conditions. These conditions included constant wind speed environments of varying strengths, windshear environments of varying strength, followed by the addition of turbulence and wind gust profiles.
  • Three profiles were developed to test the effect on the stall speed of a reduction of 25,000 lbs, simulating the emergency dump of the remaining fire retardant.

Multiple flight runs were then undertaken for each test profile by 2 QTPs.

Results

The RAAF simulator for the C-130J-30 demonstrated stall speeds comparable to those published for the C-130H at the approximate weight of the accident, 131,000 lb (59,420 kg), in the unaccelerated level flight condition. The power-off stall speeds were 98 kt (simulator) and 101 kt (C-130H), and power-on stall speeds were 82 kt (simulator) and 83 kt (C-130H).

The simulator provided useful insight into the potential for a significant loss of airspeed to occur when a combined maximum wind speed (mean wind plus gust) of 50 kt was used as the control variable. Although this was greater than the surface wind speed recorded at Peak View of 43 kt, it was consistent with the pilot reports from the smaller fire-control aircraft earlier on the day of the accident.

The key outcomes from the simulator testing were:

  • A constant strong (40 kt) north-westerly wind resulted in a small loss of airspeed during the climb-out, with minimum airspeeds of about 113 kt IAS, and a ground speed of about 160 kt. There were no aural stall warnings activated, the pilots reported no indications of any pre‑stall buffet or other warnings, and was a notably higher ground speeds than the accident flight.
  • A moderate (15 kt) north-westerly wind, combined with a 15 kt windshear, a 25 kt windshear and a 35 kt windshear during the climb-out resulted in an airspeed decay to between 98 kt and 104 kt, with intermittent aural stall warnings. The pilots also reported the controls were less responsive in the higher wind speed scenarios, indicative of approaching the stall.
  • A moderate (15 kt) north-westerly wind, with +10 kt gust and +25 kt windshear during climb‑out produced similar ground speeds to the accident flight. This consistently resulted in the airspeed decaying into the stall speed region between power-on (82 kt IAS) and power‑off (98 kt IAS) with repeated stall warnings. The minimum airspeed was in the range 84–98 kt IAS and the ground speed was in the range 141–151 kt.
  • When simulating an emergency dump of the remaining fire retardant, the rapid weight reduction, if made after the aural stall warning activation,[81] but prior to aerodynamic stall, reduced the stall speed. The simulator exited the stall warning/pre-buffet stall regime and improved the performance as expected.

Aerial firefighting in Australia

Overview

The National Aerial Firefighting Centre (NAFC) was formed by the Australian States and Territories in 2003 to provide a cooperative national arrangement for combating bushfires by facilitating the coordination and procurement of specialised firefighting aircraft.

The NAFC contracted aircraft on behalf of all the states and territories, with leasing arrangements allowing for aircraft to be moved around the country to address the prevailing bushfire risk. For each aircraft, a state or territory then assumed primary responsibility, and managed the operation and deployment of that aircraft.

As detailed in the National Aerial Firefighting Strategy 2021–26 (National Aerial Firefighting Centre, 2021), firefighters operate in an escalating risk environment frequently challenged by ‘changing fuel, vegetation and vulnerabilities’. At the same time, they strive to meet the community, government, and media expectations for protecting lives, properties, and the environment. This has resulted in:

…situations where aerial assets can provide effective support are increasing, and with them, community expectations. Meeting these expectations is a risk. Aerial firefighting has grown from ‘just another tool in the toolbox’ to a point where the community expect firefighting aircraft over every fire (especially ‘their’ fire).

Consequently, aerial firefighting has become a critical capability for the management and suppression of bushfires in Australia. To effectively achieve this, aircraft are flown at low altitudes and low airspeeds, often over inhospitable terrain with reduced visibility from smoke. This creates a high-risk environment, which ‘requires an enduring focus on training, compliance, and risk mitigation’ (National Aerial Firefighting Centre, 2021).

Operating environment and limitations

In 2020, although born out of the 2019-2020 bushfires, an inquiry into Australia’s national natural disaster coordination arrangements was conducted. The final report, Royal Commission into National Natural Disaster Arrangements, was published in October 2020. The report noted that the effectiveness of aerial firefighting was dependent on a number of factors including the distance and time to travel to the fire-ground, the type of aircraft used, pilot skill, weather conditions, fire‑fuel type, intensity and size of the fire, type of suppressant use, and the tactics employed to respond to the fire. Specifically, the report identified the following limitations:   

Aircraft alone are not a solution to fighting bushfires. Interaction between aircraft and fire crews is necessary to bring a fire fully under control…

…poor weather conditions can limit and sometimes prevent the use of aircraft. For example, requirements for pilots to maintain visibility of terrain can limit the use of aircraft in severe conditions (eg low visibility in heavy smoke or cloud); and turbulence caused by strong winds and the terrain can make operating aircraft unsafe, especially at low altitude.

Poor weather conditions can also restrict the effectiveness and use of aerial firefighting. For example, during the 2019 SA [South Australian] Cudlee Creek and Kangaroo Island fires, weather conditions prevented all attempts by aircraft, including LATs, from containing the forward spread of the fires. Furthermore, extreme weather conditions experienced periodically throughout the 2019-2020 bushfire season meant there were a number of days when aerial firefighting could not be employed.

Activity

According to research conducted by the ATSB (2020), A safety analysis of aerial firefighting occurrences in Australia, the number of occurrences per financial year increased steadily between 2016–17 and the bushfire season 2019-20. However, data collected by the NAFC and presented in the Australian and New Zealand National Council for fire and emergency services’ (AFAC) 2019-20 annual report, estimated that aerial firefighting activity for the 2019-20 season was around 4 times higher than previous seasons. Given the increased activity, the rising trend in the number of occurrences could be expected and probably did not indicate a significant increase in the risk per flight.

In addition, the ATSB research report identified that half of all reported aerial firefighting occurrences and four fifths of more severe aerial firefighting occurrences were operational in nature, typically terrain collisions, with around one quarter of the more severe occurrences associated with aircraft control. Further, there were 2 fatal accidents between August 2018 and the report publication in May 2020, whereas the previous 17 years only had 3 fatal accidents.

While there have been various deployments and trials of larger aircraft over many years, the current LAT program including the use of C-130 aircraft was evaluated during the 2014-2015 bushfire season. Since commencing operations in Australia in 2015, these LATs have been operating between North America and Australia over alternate bushfire seasons.

On 1 June 2022, in response to the draft report, the RFS reported that the 2019-2020 bush fire season was unprecedented, which meant that a large contingent of aerial resources was required for firefighting, personnel and resource movement, and for surveillance and reconnaissance missions. The RFS acknowledged that aircraft were particularly valuable for fires in difficult terrain or fast-moving fires that were too dangerous for ground personnel to confront.

Over the season, there were 317 aircraft engaged in firefighting activities including 2 very large air tankers (VLATs)[82] and 4 LATs. Together, the LATs and VLATs completed a total of 1,708 missions and dropped more than 24 million litres of fire suppressant. This represented the largest contingent of VLAT and LAT used in Australia to date.

The RFS further noted:

The season also challenged assumptions about how agencies fight fires - techniques and strategies that worked in previous seasons often did not work as well in the 2019-20 season. The scale of the fires stretched the capacity of fire authorities with many ignitions started by lightning in remote and rugged terrain, quickly spreading to the point where suppression was extremely difficult.

For the 2019-2020 season, the RFS contracted one C-130 and one Boeing 737 from Coulson Aviation via a service agreement subject to the NAFC contract.

Coulson Aviation

General information

Coulson Aircrane Ltd. was a privately-owned company based in British Columbia, Canada. The company had been involved in aviation for over 36 years, operating both fixed-wing and rotary‑wing aircraft. The company's operations included helicopter logging, forest fire suppression, power-line construction, airliner passenger, transport, and other industrial heavy lift operations. Coulson Aviation (USA) Inc. was a subsidiary of Coulson Aircrane Ltd., and contracted rotary and fixed-wing aircraft to the US and Australia.

Coulson Aviation (Australia) PTY Ltd. was formed in 2010 to support Coulson Aircrane's long-term commitment in Australia. The company provided aircraft personnel for Coulson’s rotary and fixed‑wing aircraft operating under contract in Australia for the 2019-2020 bushfire season through the National Aerial Firefighting Centre (NAFC). At the time of the accident, they had a fixed‑wing fleet in Australia consisting of two C-130 aircraft and one Boeing 737 aircraft. They also provided crews for the NSW Rural Fire Service (RFS) Boeing 737, which had previously been purchased from Coulson Aviation in 2019. Following the Australian bushfire season, the aircraft and crews returned to North America for heavy maintenance and recurrent training prior to the US season.

B134 was contracted on an absolute availability requirement. This included standing charges, paid on an hourly availability, with additional charges for flight time (to account for fuel and other costs). Flight time charges were paid regardless of the fire retardant or suppressant being used.

Operating documents

Coulson Aviation maintained a suite of documents, which provided the necessary information for conducting operations in Australia and for operating the C-130 aircraft including N134CG. These were:

  • Company operations manual (COM): The COM contained the procedures, instructions and information required by CASA necessary to enable the operations personnel, including crews, to perform their duties safely and ensure the safe conduct of flight operations. The COM was for Australian operations only and applied to both fixed-wing and rotary-wing aircraft.
  • Airplane flight manual (AFM): Coulson Aviation, as the type certificate holder, developed their own C-130 AFM for FAA acceptance and approval. The manual was derived from the 1989 US Naval Air System Command document for the EC‑130Q. It detailed the recommended procedures for normal and emergency operations, operating limitations, aircraft systems and equipment, weight and balance, and the aircraft performance that should be achieved when operating in accordance with these procedures. The AFM was approved by the FAA in 2013 with a supplement for the RADS later approved in 2016, and a supplement for an avionics upgrade, which included the CVR installation, approved in 2018.

The FAA advised the ATSB that, for restricted category/military surplus aircraft, the original equipment manufacturer (in this case, Lockheed Martin) did not usually provide any support to the operator, or issue amendments or offer a subscription service, as would normally occur for transport category aircraft. Rather, the source for documents and manuals was normally the military service, although Lockheed Martin may have originally prepared the manuals for the military.  

While the COM contained some procedures applicable to all aircraft operations, at least one of the operator’s C-130 PICs did not consider this manual as the reference document for operating the aircraft. Instead, they considered the AFM and checklists were the appropriate source.

Retardant drop procedures

The operator’s RADS AFM supplement outlined the operating limitations and configuration for the retardant drop procedure. This included 100% flap selection, the landing gear retracted, and airspeed lower and upper limits of 118 kt and 170 kt respectively.

At interview, the operator’s pilots reported the targeted parameters for the C-130 drop were 200 ft above ground level (AGL) and an indicated airspeed target of 120 kt. On completion of the drop, the climb-out procedure was for the PIC to increase power and request the copilot retract the flaps to the 50% position, while the flight engineer monitored and called the engine parameters (temperature and torque). The operator’s crews also reported that they typically targeted 150 kt during the climb-out, with an initial climb to at least 500 ft. The crews who had previously flown with the accident PIC, indicated there was about a 2-3 second period from the completion of the drop to the start of the flap retraction when flying with the PIC.

Where the retardant drop was conducted without a birddog or aerial supervision (refer to section title Aerial supervision), prior to conducting the drop, the LAT crew conduct a number of assessment circuits at various altitudes. These circuits were for drop planning purposes, and as outlined in the COM, would include identifying hazards, the retardant drop plan, entry and exit strategies, as well as a dry run at 500 ft AGL and 150 kt.

Safety management system

Coulson Aviation had introduced a safety management system (SMS) in 2013. At the time of the accident, it was not mandated under either the CASA[83] or FAA regulations, although it was required under the USFS contract. The International Civil Aviation Organization (ICAO, 2018) defined SMS as:

A systematic approach to managing safety, including the necessary organizational structures, accountability, responsibilities, policies and procedures.

It is designed to continuously improve safety performance through the identification of hazards, the collection and analysis of safety data and safety information, and the continuous assessment of safety risks. The SMS seeks to proactively mitigate safety risks before they result in aviation accidents and incidents.

An SMS comprised 4 components: safety policy and objectives, safety risk management, safety assurance, and safety promotion. The component of most relevance to this investigation was safety risk management, which included hazard identification, and safety risk assessment and mitigation.

From an Australian perspective, the NAFC indicated that an operator with an SMS would be highly regarded, but it was not compulsory. If an operator had an SMS, a requirement was included in their contract, to ensure the operator maintained the same safety standard throughout the contract period. The NAFC also indicated that they would not review or evaluate the SMS, with the expectation, if required for safety regulation purposes, that this would be undertaken by CASA. A review of CASA records found that, while surveillance had been conducted on the operator, these did not include an audit of the SMS, nor was it required as the system was not mandated.

The operator’s SMS manual outlined the company’s safety policy, processes, and procedures for implementing the SMS and safety management plan. It also included information regarding safety oversight, which included their safety reporting processes.

Safety risk management process

ICAO (2018) described the safety risk management process as:

… a key component of safety management and includes hazard identification, safety risk assessment, safety risk mitigation and risk acceptance. SRM [safety risk management] is a continuous activity because the aviation system is constantly changing, new hazards can be introduced, and some hazards and associated safety risks may change over time. In addition, the effectiveness of implemented safety risk mitigation strategies must be monitored to determine if further action is required.

The process allows validation of decisions, evaluation of the results, and provides an opportunity to assess the need for further risk mitigation. Where risks cannot be reasonably eliminated, risk management enables the tasking to be accomplished by controlling risks to acceptable levels.

The operator’s safety and risk management processes were detailed in the COM and were described as:

…safety management processes provide a structure for Coulson to exercise its appropriate duty of care to minimise the risks involved.

…provide a formal mechanism that are designed to capture all aspects of safety performance, conformance with approved procedures, continued improvement of procedures, regulatory compliance and operational risks that have the potential to adversely affect the operation.

Risk management is a structured approach to managing uncertainty related to a threat or hazard through a sequence of activities including risk assessments, strategies developed to manage the threat and mitigation of risk...

Hazard identification

According to ICAO (2018), a hazard can be considered as a dormant potential for harm, which is present in one form or another within the system or its environment. Therefore, hazard identification is the first step in the safety risk management process. The intention is to proactively identify hazards before they lead to accidents, incidents, or other safety‑related occurrences. Hazard identification may also consider hazards that are generated outside of the organisation and outside their direct control, such as weather (ICAO, 2018).

The COM stated that ‘Coulson acknowledges that a certain element of risk exists in all aspects of its business’ and that ‘the implementation of a comprehensive safety system can greatly assist in reducing risk’. As part of their fatigue risk management system, the COM outlined the potential hazards crews may encounter in all types of operations (Table 3).

Table 3: Some hazards identified in the Company Operations Manual

·        Unfamiliarity or low experience with the type of operation·        Operations at low altitude
·        Lack of experience in operating under specific operational conditions·        Operations in reduced visibility
·        Lack of familiarity with, or low experience on, specific aircraft equipment·        Operations at high density altitude
·        Operations in high wind or turbulent conditions, particularly if accompanied by high ambient temperatures

·        Operations at high ambient temperatures

 

·        Operations in areas of mountainous or hilly terrain·        Contact of flight crew with high-demand clients

In addition to the hazards identified above, the ATSB’s review of the COM found numerous references to other hazards. The fire-bombing procedures made references to factors such as prevailing winds (particularly with mountain flying), turbulence and downdrafts associated with either mountain or fire generated conditions, and visibility. Further, the training and checking, and standard operating procedures sections for fixed-wing aircraft also referred to windshear.

Hazards are detectable through many sources including reporting systems, inspections, audits, brainstorming sessions, and expert judgement. These sources are categorised as being either formal or informal methods and can be used to detect hazards at all levels of an organisation. The operator’s SMS used both informal and formal methods for hazard identification. This included a safety reporting system where all employees were encouraged to report issues, hazards and incidents that affected flight or ground safety. Further, the operator had a daily SMS conference call at the start of the day, which discussed the previous days operations, and the operations to be conducted that day. Present on the call were senior management, the safety manager, and the crew. They would discuss the current status of the crew and aircraft, any reported issues, and would often end with a relevant safety message or topical discussion. On 10 July 2022, in response to the draft report, the operator reported that this process allowed the group to tactically manage the risks in a dynamic environment providing an opportunity to discuss actual or emerging hazards and risks in an open and supportive environment.

Safety reporting system and daily SMS calls

The operator’s safety reports for the period 2019 and 2020[84] were provided to the ATSB. A review of these 32 reports found that around 60% were related to maintenance issues, while only 9% were operationally focused. These operational events included aircraft separation issues and retardant overload events. While previous years’ data was unavailable, the operator had conducted yearly SMS reviews, and these summaries were provided for the earlier period. Although the individual reports were not available, based on these summaries, it was likely the previous years’ safety reports followed a similar reporting pattern, with a majority being maintenance related.

During the investigation, several of the operator’s crew provided the ATSB with accounts of previous windshear encounters they had experienced:

  • In the previous firefighting season, while conducting structure protection, they encountered a windshear event, which resulted in an uncommanded bank angle of 80°. The crew recovered the situation by flying the planned exit into an area of lower terrain (valley).
  • In the season of the accident, while climbing out after completing a drop, the airspeed fluctuated ‘quite a bit’ (10 kt) and the aircraft sank slightly, while being ‘tossed around’. This was while working with the birddog. After this encounter, the decision was made not to return to the drop area.
  • On the day of the accident, the crew of B137 received a windshear warning and uncommanded bank angles up to 45° in the Adaminaby area.[85]

These encounters were not recorded in the operator’s safety reporting system, nor were any other weather-related incidents found in the reports provided to the ATSB. Neither the former[86] nor current safety manager recalled any such reports in the system. At interview, one pilot reported that the online SMS program was used for issues that were considered applicable across the company. Issues that could be resolved within the small group of fixed-wing pilots, or could be taken directly to the chief pilot, noting they spoke on a daily basis, would not necessarily be included in the system.

In addition, the ATSB reviewed the daily SMS call notes from 2018 to 2020. While limited in detail, the topics most frequently discussed were maintenance issues. In the days preceding the accident, the hot and severe weather conditions were noted. These were the only occasions where the weather conditions were noted in the calls. In response to the draft report, the operator advised that they considered the incident reporting numbers discussed above were mitigated by the daily SMS calls’ impact on flight risk awareness.

Risk assessment

A risk assessment is a process where sources of potential harm (hazards) and the chances of an adverse event happening due to the hazard were identified, analysed, and evaluated (CASA, 2021). This evaluation was expressed in terms of likelihood and consequence, and should highlight the risks to be considered before and while carrying out an operation.

Organisations should have multiple layers of controls or defences in place (CASA, 2014) to manage their identified hazards. Risk assessments should be carried out across all levels of an organisation and at different stages in the operation. These could consist of a formal, documented process or a continuous ongoing mental assessment carried out by a pilot, or a combination of both. Examples of a formal risk assessment may include an operational risk assessment conducted by the operator to consider and evaluate the risks associated with the type of work being undertaken, and pre-flight risk assessments, conducted by the PIC and associated with a specific tasking. An example of continuous processes could include in-flight tactical[87] risk assessments.[88]

The operator’s SMS manual stated that, if a risk assessment was required, the SMS manager would conduct and document the process by completing the risk management worksheet. The associated risk matrix categorised the risk as either acceptable, mitigable or unacceptable, although there was no guidance on how to categorise the risk. These risk assessments only applied to the safety reports and change management processes that were captured in the operator’s online SMS program. At interview, both the former and current safety managers indicated there was no formal risk assessments conducted on the identified operational hazards, such as those listed in the COM.

Prior to the accident, the operator had voluntarily initiated the International Standard for Business Aircraft Operations audit phase II,[89] which was conducted between December 2019 and March 2020. This audit identified significant growth since the stage 1 audit completed in 2017, and that the SMS had not fully matured to be as effective as it could be. Of note, it identified that the operator could not provide a process for assessing risk potential in terms of likelihood and severity.

After the safety risks have been assessed, the appropriate risk controls can be implemented. ICAO (2018) noted that:

It is important to involve the “end users” and subject matter experts in determining appropriate safety risk controls. Ensuring the right people are involved will maximize the practicality of safety risk chosen mitigations. A determination of any unintended consequences, particularly the introduction of new hazards, should be made prior to the implementation of any safety risk controls.

In response to the draft report, Coulson Aviation stated that aerial firefighting was conducted within an ‘unforgiving, dynamic, and complex operational and meteorological environment’. Consequently, they considered aerial firefighting lends itself to a more tactical approach to risk identification and mitigation.

Risk register

Safety risk management activities should be documented, including any assumptions underlying the probability and severity assessment, decisions made, and risk controls implemented (ICAO, 2018). A tool such as a risk register could be used to ensure identified hazards were tracked and mitigated as part of a formal risk management process of prioritisation, documentation, and assessment. The register could include the hazard, potential consequences, assessment of the associated risks, and any controls put in place to manage the risk. This not only allowed for ongoing tracking and monitoring of the identified hazards, but also (ICAO, 2018):

…becomes a historical source of organizational safety knowledge which can be used as reference when making safety decisions and for safety information exchange. This safety knowledge provides material for safety trend analyses and safety training and communication. It is also useful for internal audits to assess whether safety risk controls and actions have been implemented and are effective.

At the time of the accident, the operator did not maintain a risk register, or any alternate means to track the identified hazards and associated controls, as part of their SMS.

Assessing pre-flight risk

Flight risk assessment tool

Aerial firefighting activities, like other aerial work operations, are subject to elevated risks. A 2014 National Transportation Safety Board study of agricultural (aerial work) accidents in the US found the following:

…the mission priorities…present pilots with unique hazards, challenges and constraints, some of which cannot be completely eliminated. For example, pilots must manoeuvre their aircraft at very low altitude over terrain and must therefore accept an elevated risk of terrain and obstacle collisions, as well as having limited time to safely respond to an aircraft mechanical anomaly or recover from an inadvertent aerodynamic stall.

Risk management is a decision-making process by which pilots can systematically identify hazards, assess the degree of risk, and determine the best course of action. Effective risk management involves good decision-making that allows a pilot to identify personal attitudes that are hazardous to safe flying, apply behavioural modification techniques, recognize and cope with stress, and effectively use all resources. Risk management strategies can help pilots apply a systematic process that can help them resist pressures that can adversely affect their decision-making and performance and can help them mitigate other hazards that could adversely affect the safety of flight.

The study also concluded that risk management guidelines and best practices specific to agricultural aircraft operations were necessary tools to help operators and pilots mitigate the unique risks associated with their operations. In addition to the safety risk management processes discussed above, another such tool was a flight risk assessment tool (FRAT). In 2016, the FAA Safety Team released their FRAT with the introduction:

When implementing a Safety Management System (SMS), one of the most critical components to develop is a Flight Risk Assessment Tool (FRAT). Because every flight has some level of risk, it is critical that pilots are able to differentiate, in advance, between a low-risk flight and a high risk flight, and then establish a review process and develop risk mitigation strategies. A FRAT enables proactive hazard identification, is easy to use, and can visually depict risk. It is an invaluable tool in helping pilots make better go/no-go decisions and should be a part of every flight.

This was consistent with the USFS 2016 National Aviation Safety Management System Guide, which stated that:

Every flight has hazards and some level of risk associated with it. It is critical that management and pilots are able to differentiate, in advance, between a low-risk flight and a high-risk flight using a risk assessment tool that allows pilots, managers and dispatchers to see the risk profile of a flight in its planning stages. When the risk for a flight exceeds the defined acceptable level, the flight will be further evaluated and risk decisions made by appropriate leadership.

The USFS (Forest Service Manual: Aviation Management Handbook) also recognised that risk management was a critical component of their SMS, and the identification of new hazards, determination of risk levels and effectiveness of mitigations ‘must be collaborated’ from the local level to aviation staff in their headquarters. Noting this, they discussed the different types of risk assessments, which included a ‘time critical risk assessment’:

Time critical risk assessment is the tool that pilots and managers use to assess actual risks specific to the day of flight. The product representing a time critical risk assessment is a Flight Risk Assessment Tool (FRAT)… While completing a FRAT, if an emerging hazard or higher than expected risk level is identified, the Aviation Manager (for example a helicopter manager, flight manager, project aviation manager, pilot in command), must follow up with the appropriate management level before a mission commences.

A FRAT was an efficient and structured process that allowed for a consistent and objective evaluation of flight risks, and could be adapted to manage the unique risks present for a specific operation or tasking. The tool established the risk profile for an individual flight and prompted the pilot or operator to take appropriate mitigation actions. It also allowed for better visibility by the operator, as to crew decisions made in accepting or rejecting tasks. However, it should be noted that a FRAT cannot anticipate all the hazards and corresponding risks that may emerge during a flight.

The FRAT could incorporate factors relating to the crew, such as operational experience and fatigue; environmental conditions, both at the airport and en route; aircraft factors, such as equipment serviceability; and any external pressures or factors, such as task rejection by another pilot or operator. Each of these factors was then assigned a numerical risk value and a total risk score was calculated. Based on this score, the risk profile was determined using predefined criteria for acceptable levels of risk, elevated levels of risk that required mitigation such as escalation to a more senior pilot, or task rejection.

The operator’s COM acknowledged the risks associated with their operations, stating ‘the combination of terrain, weather, fire occurrence patterns, and visibility can make firebombing extremely challenging’. The COM also required their rotary-wing pilots conducting firefighting activities using night vision goggles to complete a pre-flight risk assessment. However, the operator relied on the LAT crews to conduct their normal pre-flight planning and make their own assessment of the suitability of a tasking, without the need for a formal pre‑flight risk assessment. The former safety manager also confirmed that, while the LAT operation was considered high risk, there was no FRAT available for the crews.

Accident flight estimated risk profile

Following the change in safety managers in 2020, the operator introduced a FRAT into their LAT operations, with the criteria for an acceptable level of risk (score <30), a level of risk that required mitigation or escalation (30–39), and a ‘no-go’ level of risk (40+). Using this tool, the ATSB calculated a score within the range that required mitigation or escalation for the accident flight. However, the ATSB noted that the FRAT did not consider factors such as a weather‑related task rejection by another pilot, in this case, by the birddog pilot. Task rejection was a potential risk indicator for a FRAT, as explained in the US FAA advisory circular 135-14B for helicopter air ambulance operators:

Declined HAA [helicopter air ambulance] Flight Requests. The operator must establish a procedure for determining whether another HAA operator has declined the flight request under consideration and if so, for what reason (weather, maintenance, etc.). If applicable, the reason for the declined flight must be factored into the required risk assessment process, i.e., do not include a declined flight due to a maintenance issue or pilot not available. This could be as simple as asking the requestor whether or not this specific flight request has previously been made and declined and why. 

Similarly, the Helicopter Association International’s FRAT tool included the risk factor of ‘Flight Turned Down By Other Operators Due to Weather’, which had the highest risk score of all the example factors.

Civil Aviation Safety Authority

When operating in Australia, Coulson Aviation aircraft were operated under a short-term air operator certificate authorisation issued by CASA, involving the use of foreign aircraft under relevant legislation and national aviation authorities. The certificate permitted aerial work including aerial spotting (fire and flood), dropping (water and fire retardant), and other activities such as search and rescue and surveillance.

As part of this process, CASA required Coulson to have a Company Operations Manual (COM) for Australian operations. CASA required Coulson Aviation to comply with their COM, which included reference to the FAA approved AFM. In these circumstances, CASA relies on the FAA approval process, and has no role in reviewing the AFM.

CASA had conducted 5 surveillance events in the past 5 years across 3 different short-term AOCs for this operator. All events were level 2[90] operational checks and no safety findings were raised. No CASA surveillance events were performed on Coulson during the 2019-2020 firefighting season. The short-term AOCs were not included in CASA’s national surveillance selection process, and therefore no level 1[91] surveillance activities were conducted.

New South Wales Rural Fire Service

General

The NSW Rural Fire Service (RFS) was the lead combat agency for bushfires in NSW. They worked closely with other agencies to respond to a range of emergencies including bush and grass fires, bushfire mitigation, structure fires, search and rescue, motor vehicle accidents, and storms that occurred within rural fire districts. The RFS was primarily made up of volunteers, with paid staff members managing day-to-day operations, Fire Control Centres (FCCs), and operational support, among other roles. There were many roles involved in the RFS emergency management response; for simplicity, only those roles applicable on the day of the accident are discussed below.

The multiagency state-wide response to large bushfire emergencies were overseen and coordinated by the State Operations Centre, located at NSW RFS Headquarters in Sydney Olympic Park (Sydney). The State Operations Centre provided a variety of specialised resources to the FCCs, including but not limited to, aviation resources. The state operations controller (SOC), located in the State Operations Centre, maintained an overall awareness of the firefighting effort across the state, and ensured resources were allocated as needed. The State Operations Centre also contained the state air desk (SAD), which was the state level multiagency team responsible for coordination of aircraft operations.

FCCs were the administrative and operational base of each rural fire district or zone. The coordination and management of local brigade responses to fires and other incidents was undertaken through the incident management team, led by the incident controller. For each emergency response, an incident controller was responsible for that response, including the objectives, operations, and application of resources. Where necessary, an aviation unit was established to manage and support deployment of aviation resources within the rural district, including an aviation radio operator (ARO).

The LATs were based at an airbase overseen by an airbase manager (ABM). The ABM was responsible for the supervision and coordination of airbase personnel and the layout and operation of the airbase. They operated as a liaison for the RFS SAD, and could be from another organisation.

Aircraft management procedures

The RFS maintained a suite of documents, which detailed the procedures for managing aerial firefighting. The 2 primary documents for air tanker operations were the NSW and ACT Aviation Standard Operating Procedures (operating procedures), which outlined the basic procedure of all air tanker operations, and the Operating guidelines for air tanker operations (operating guidelines), which provided further details specifically for the LAT program.[92] The preface to the operating procedures stated it was ‘produced to assist all members…in the safe, efficient, and effective management and use of aircraft for operational purposes’. This should be read in conjunction with other relevant documents, ‘which may contain more comprehensive information, specification and overarching operational and incident management procedures’. Additional procedures and forms were contained in the Operational management procedures and Incident management procedures.

While the RFS were responsible for coordinating aircraft and conducted training on various aviation aspects, they did not claim to be aviation experts. Therefore, it was possible that the frontline staff may have had a limited understanding of the operational capabilities and constraints for the varied aircraft used. The ATSB noted that there was limited information contained in any documentation provided to the frontline staff regarding the capabilities and constraints of each aircraft type within the LAT category. Where a LAT was requested by an incident management team, the asset was selected based on availability, location, and response time, rather than aircraft type. There was no distinction of capability between LAT aircraft types aside from information related to tank capacity, delivery system, and cruise capability. It did not contain any performance capability information related to operating conditions. However, the documents acknowledged that, ‘it is essential that all personnel seek specialist advice when planning or conducting air operations’. It also stated that ‘any agency members, contractors or air crew may decline to carry out tasks for which they are unfamiliar, unprepared or consider unsafe’.

On 1 June 2022, in response to the draft report, the RFS acknowledged that aerial ‘operations are risky, made more so as weather conditions deteriorated. However, when assessing tasking decisions, the RFS must balance this against the risk posed by fire to civilians and [ground] fire fighters… with the ability of aerial operations to achieve far greater gain’ than ground-based firefighting. Further, they considered that the tasking of large air tankers ‘may be sufficiently safe in circumstances that were not necessarily safe for other aircraft.’ They also indicated that ‘B134 had greater flight capability than other aircraft’ used by the RFS and was able to make a different assessment of risk. ‘Therefore, conditions that may have been unsafe for other aircraft, including B137, may not have been so for B134.’

Aerial supervision

The air attack supervisor (AAS) was a tactical command position, which ensured that aerial operations were consistent with the procedures and incident controller’s intent. This included maintaining communications with relevant incident management team personnel, and coordinating ground and air communications to achieve these objectives.

An incident AAS would be in an independent local aircraft overseeing the fire-ground, responsible for coordinating the aviation assets over an incident. They were responsible for coordinating the smaller aircraft and overall strategy, and in place when there were 3 or more aircraft operating on an incident. When LATs were involved, the incident AAS would normally communicate to another AAS onboard the birddog aircraft (LAT AAS).

A LAT AAS was located in the birddog aircraft, and coordinated the LAT movement with the incident AAS. Their role included briefing the LAT crew on the specific assignment, identify hazards, tactics and manage communications with the incident AAS. In practice, the LAT AAS established contact with the assigned LAT crews as they approached the relevant fire-ground to provide this information.

Requirements

When discussing aerial supervision for air tanker firefighting operations, the RFS operating procedures stated the following requirements:

Generally, Air Tanker Suppression operations, training flights and evaluation flights should not be undertaken without the supervision of an authorised AAS [air attack supervisor]. The AAS provides tactical aircraft coordination with the Incident AAS and/or IMT [incident management team] and directs the firebombing aircraft to critical areas of a fire for suppressant or retardant drops.

The only exception to the above may be in the event that an Air Tanker has an ‘initial’ attack’ certified crew on board who understand the mission requirements, Agency Air Tanker Procedures and there are operational advantages to the LAT commencing operations prior to an AAS arriving.

Operational advantages, while not defined or outlined in any documentation, were described at interview as including aspects such as the faster LAT transit times,[93] when a birddog was not available due to resourcing constraints, or a crew specific concern such as fatigue or exceeded duty times. There were no further requirements or considerations in either the operating procedures or guidelines regarding aerial supervision for LATs, or its use when an AAS was not available due to an operational safety concern. It was also noted that there was no policy, procedure or guidance identified in the provided documentation for tasking air tankers with initial attack certified crew in the case where a birddog pilot, and therefore the associated AAS, had rejected the tasking.

On 1 June 2022, in response to the draft report, the RFS advised that it was always their intention to send a birddog when possible. However, due to the constantly changing circumstances on the day, this was not possible to do. The decision to deploy the LATs without the birddog was based on an evaluation of the available information at the time and the unavailability of the birddog. In addition, the RFS stated that prohibiting LATs from operating if a birddog had not assessed the conditions, or if it was considered unsafe for smaller aircraft to operate would have severe impacts on firefighting operations across the state, and the resultant safety of people and property on the ground.

Initial attack certification recognition

The ATSB was unable to find a definition for the term ‘initial attack certified’ within the RFS documentation and sought clarification from the RFS. The RFS advised that it was their intention to recognise the initial attack certification endorsed by the US Forest Service (USFS). Broadly, this certification required a minimum flight time as a PIC in the specified aircraft type; a minimum flight time conducting low-level retardant drops; ground school training on relevant aspects such as hazard identification, ingress and egress strategies, and communications; and the satisfactory completion of 25 supervised drops.

In addition, the RFS advised that they did not maintain a register of initial attack certified pilots, and did not confirm the crew were initial attack certified when issuing the tasking. Rather, they relied on the individual aircraft operators for ensuring pilots held and maintained the necessary licences and certification. When the ATSB discussed the initial attack certification with Coulson Aviation, they also noted that this had not been defined by the RFS. Therefore, they utilised their own internal training framework to determine when a PIC was capable of operating without aerial supervision. One such example cited was the PIC of the Boeing 737 (B137) who had received the requisite internal training, but had not yet completed the required number of supervised drops to gain the USFS certification.

Tasking large air tankers

The operating procedures, and more so the operating guidelines, detailed the process for the tasking and mission management of air tankers. This included what aspects were to be considered when tasking an air tanker, the request and approval process, and dispatch. The ATSB noted that some functions during this process could be completed by multiple RFS positions. However, for simplicity, only those roles applicable on the day of the accident are discussed below.

Considerations and request

The operating procedures noted that air tankers could provide large volumes of suppressant, and careful planning and supervision was needed to ensure this was used effectively. The first step involved the incident controller (incident management team in the FCC) advising the intent to consider a tanker to the SAD, and outlining a strategy in conjunction with the SAD who could provide ‘guidance on availability and suitability’.

When considering tasking air tankers, the operating procedures stated the incident controller was to consider the following:

  • incident objectives
  • threats (life/property, assets, forests)
  • a proposed strategy
  • prevailing and/or forecast weather conditions
  • the likely period of deployment or loads [suppressant/retardant] required
  • the terrain and fuel (grass, urban, forest) type
  • possible risks and safety issues
  • time of day (last light considerations)
  • the mission alternatives.

A similar list of considerations was also included in the operating guidelines (for both air tanker and birddog taskings), with the addition of the elapsed time for the aircraft to arrive onsite. The operating guidelines stated that these considerations were a ‘risk assessment’. However, there was no further guidance on assessing each of these considerations.

Approval

The SAD would then brief the SOC. The SAD would provide advice on the availability, competing priorities, strategies, and load requirements for the LAT. The SOC then decided on the mission approval. Following that approval, the SAD would advise the LAT airbase manager (ABM) of the approval and mission objectives.

In this case, the Cooma incident controller did not request the tasking of the LATs. Rather, the decision to task a LAT was determined during the 1100 conference call discussing the fire situation at Adaminaby with senior personnel from the State Operations Centre (which included the RFS Commissioner and Deputy Commissioner). On that 3.5-minute conference call, while aware that the smaller fire-control aircraft were not flying due to the weather conditions, it was decided to send the LATs. They were unsure if a birddog had been launched to assess the conditions due to the known visibility and weather conditions, but determined that rather than wait for the birddog assessment, they could send a LAT ‘as it can bomb by itself if need be, if the opportunity presents’. The tasking decision was then communicated to the SAD, who then communicated the tasking for B137, B134, and the birddog from Richmond airbase to the Richmond ABM.

While the tasking on the day did not follow the RFS procedure outlined above, it was very likely that the LATs and birddog would have still been tasked if the above procedures had been followed.

Dispatch

The LAT ABM then conducted a pre-mission briefing with the crew, providing the required tasking details. The RFS operating guidelines indicated that these details would include, at a minimum, the latitude and longitude, a geographic location (referencing a map or chart), the incident air attack supervisor’s contact details, communication details for the incident controller radio channel and fire location’s common traffic advisory frequency, information on any aircraft working in the same location, and the type of load product.  

Generally, the birddog with an aerial attack supervisor would arrive at the fire-ground ahead of the LATs. Given that the smaller birddog aircraft would generally fly slower than a LAT, it was common for the birddog to depart before the LATs. However, where there was an urgency to dispatch aircraft due to the rapid spread or the impending impact of the fire, and the crew were appropriately certified, it was standard practice to launch the LATs at the same time, or ahead of, tasking the associated birddog.

Re-tasking   

Generally, re-tasking would be managed through the SAD in consultation with the incident management team and the LAT AAS, noting that the LAT crew would take on the AAS role when flying initial attack operations. On the day of the accident, the re‑tasking from the Adaminaby fire‑ground to the Good Good fire-ground was managed by the Cooma incident management team, who were in direct contact with the crew via the Cooma aviation radio operator (ARO). This re-tasking was considered within scope, as both fires were being managed by the Cooma team, and therefore, they could direct the crew as necessary at the local level.

Task rejections

The ATSB were provided with an example of a previous occasion where a task was stopped in‑flight, while operating in Australia. In that case, an aircraft had a number of warnings activated, and the crew elected not to continue. This decision was communicated among the other crews involved in the tasking, who were in continual contact with each other, and the task was subsequently stopped by the AAS.

For the tasking related to the accident, a task rejection had been made on the ground by the birddog pilot (due to weather-related safety concerns) and no communication had been established with other crews. The birddog pilot reported that they had not conveyed the decision to the crew of B134, but expected the RFS personnel would relay this information in their continued coordination of the tasking, or cancel the tasking.

A review of the available radio recordings provided by the RFS found no evidence to indicate that the birddog pilot’s rejection of the tasking had been communicated to the LAT crews (B134 and B137) by either the Richmond ABM or the SAD. In addition, the Cooma ARO, who could reasonably be expected to be in contact with the crews, reported that they were not aware of the birddog rejection. However, it was noted that not all radio communications were recorded.

At interview, mixed responses were received from pilots regarding their expectations on task rejections. All were consistent in that, there was a need to be informed of, and the reason for, the rejection decision, so this could be factored into their decision-making, in line with their company policies and procedures. Others stated that a weather-related rejection should result in cancellation of the tasking. The operator indicated that while a birddog can provide valuable risk mitigations, when the PIC is initial attack trained, they do not consider it to be a requirement. However, for a tasking without the birddog, the reason for this would need to be factored into the PIC’s pre-flight planning.

In addition, the birddog pilot had also reported that, after making the decision to reject the tasking based on the weather conditions, an air attack supervisor had advised them that the smaller fire‑control aircraft had earlier ceased operations due the wind conditions. The birddog pilot further stated that this information was generally not passed on to the pilots by the RFS.

The ATSB reviewed the available RFS documentation and procedures. No policy or procedure was in place to support the ABM or SAD’s management and communication of a task rejection by any of the crews operating in the tasking area that day or involved in the task.

In response to the draft report, the RFS stated they were of the view that ultimate responsibility for assessing risk, and accepting or rejecting a task, was the responsibility of the PIC. For the RFS to make such assessments on behalf of the PIC would constitute a shift in RFS responsibility.

United States firefighting practices

For comparison, the ATSB reviewed the aerial firefighting practices currently in place in the US. This was particularly relevant as many of the LAT operators worked in both the US and Australia, and the NSW RFS reviewed the practices from the US Department of Agriculture, Forest Service (USFS) when implementing their current LAT program.

Task rejections

The USFS placed a significant focus on managing risk exposure. They outlined their safety expectations in a statement of intent, placing emphasis on implementing:

…strategies and tactics that commit responders only to operations where and when they can be successful…[and that] understanding and acceptance that intense fire behaviour may mean we can’t protect values at risk under all circumstances…this direction also requires greater focus on identification of unnecessary exposure.

These expectations were then supported in the USFS Forest Service Manual – Aviation Management Handbook, which included the following statement:

Pilots and aviation users are expected to make sound decisions, including cancelling a flight, when conditions or circumstances may cause undue risk…

Forest Service employees perform challenging work in very high-risk and dynamic environments that are not always predictable. This responsibility can only be realized through participation of every employee. Safety is the first priority, and leadership at all levels must foster a culture that encourages employees to communicate unsafe conditions, policies, or acts that could lead to accidents without fear of reprisal...

The USFS 2019 Standards for Airtanker Operations detailed the processes and procedures to be followed by staff, supervisors, specialists, and managers when planning, administering and conducting airtanker operations. When discussing aviation safety, one aspect considered was task rejections or a ‘turn down’. Notably, the document stated:

Every individual (government and contracted employees) has the right and obligation to report safety problems affecting his or her safety and has the right to contribute ideas to correct the hazard. In return, supervisors are expected to give these concerns and ideas serious consideration. When an individual feels an assignment is unsafe, he or she also has the obligation to identify, to the degree possible, safe alternatives for completing that assignment. Turning down an assignment is one possible outcome of managing risk.

A “turn down” is a situation where an individual has determined he or she cannot undertake an assignment as given and is unable to negotiate an alternative solution. The turn down of an assignment must be based on assessment of risks and the ability of the individual or organization to control or mitigate those risks. Individuals may turn down an assignment because of safety reasons…

The standards further indicated that those individuals who turned down a task were to directly advise their supervisor. That supervisor would then communicate this information to others associated with the management of fire control activities. In addition, when a tasking had been turned down and the supervisor then asked another individual (resource) to perform the task:

…he or she [the supervisor] is responsible to inform the new resource that the assignment had been turned down and the reasons why. Furthermore, personnel need to realize that a “turn down” does not stop the completion of the assigned operation. The “turn down” protocol is an integral element that improves the effective management of risk, for it provides timely identification of hazards within the chain of command, raises risk awareness for both leaders and subordinates, and promotes accountability.

Proper handling of turn downs provides accountability for decisions and initiates communication of safety concerns within the incident organization.

Task rejections, including those related to weather, was also recognised within the Alaskan USFS Forest Service Handbook – Flight Operations Handbook: 33.1 - Forest Service Flight Operations, as follows:

If a flight is cancelled or refused by one operator or pilot because of weather or other operating conditions, the flight will be postponed until the weather improves. Forest Service employees shall not “shop” for an operator that will make the trip when another operator has refused.

Aerial supervision

The USFS Standards for Airtanker Operations outlined the circumstances and minimum supervision required based on the following situations:

  • number of aircraft assigned to an incident
  • drops conducted in high traffic areas
  • low light conditions
  • use of the modular airborne firefighting system or very large air tankers
  • airtanker flight crews not initial attack carded
  • combination of different types of aircraft operating simultaneously
  • use of foreign aircraft
  • periods of marginal weather, poor visibility or turbulence
  • night operations
  • if requested by the airtanker, birddog or others involved.

It also noted that initial attack certified pilots were authorised to drop retardant without the supervision of a birddog and/or AAS. However, the standard stated that:

Aerial supervision resources must be launched together with the airtanker on the initial order to maximize safety, effectiveness, and efficiency of incident operations. Incidents with 3 or more aircraft over/assigned will have aerial supervision over/assigned the incident.

Likewise, The US National Wildfire Coordinating Group[94] document, Standards for Aerial Supervision, stated that ‘a safe aviation operation depends on accurate risk assessment and informed decision making’. It further indicated that, often, incident response flights were conducted under adverse flight conditions, and this complexity dictated the level of supervision required to conduct aerial operations safely and effectively. While noting factors similar to those listed above, it outlined:

There is no way to define an exact trigger point for adjusting, downsizing, or completely suspending aviation operations. The factors listed below [similar to those listed above] should be evaluated to determine whether additional Aerial Supervision resources are needed, or tactical/logistical missions need to be modified/suspended.

The standard further stated that, in some cases, the aerial supervisor would be required to shut down or suspend operations. In this case, ‘air operations must not proceed until risk mitigations are in place’.

Flight risk assessment tool

When considering aviation safety, the USFS 2019 Standards for Airtanker Operations, stated that a FRAT was required for every flight conducted for the USFS. They also recommended that a FRAT sheet be used when planning a mission and that this should be updated as necessary. The tool, provided as an appendix to the standards, contained the following note:

Because the overall cumulative score is a composite of individual flight, environmental, and operational values, it may not fully emphasize a heightened level of risk that may be associated with an individual category. For example, extremely adverse weather in itself, exclusive of the other categories, may alone merit the suspension of operations. Conditions also change over time and distance, therefore, this tool should be used periodically throughout a mission as conditions change to assure that individual or overall risks have not measurably increased.

Lessons learnt from aerial campaign management

In response to 3 accidents involving helicopters undertaking locust control operations in 2004, the ATSB commenced a research investigation (B2004/0337) into the practices used by Government organisations to contract aerial operators. While focused on locust control, the report findings were also applicable to fire control, other pest management, and emergency service operations. Collectively referred to as ‘aerial campaigns’, these types of operations were generally conducted in relatively hazardous environments that also had the potential to be high-risk environments characterised by:

  • a significant community need for the operation, possibly urgent
  • requiring the coordination of significant numbers of resources and organisations
  • a degree of irregularity or unpredictability as to when the operation will be required and the size the operation
  • requiring aerial operations with a relatively high hazard level
  • a regularly changing operational environment throughout the course of the campaign.

The report identified that organisations that contracted aerial operators were directly involved in the management of significant parts of the aerial campaign, such as assigning tasks and briefing pilots. Therefore, decisions made in the management process had the capacity to influence the level of risk of the operations. If safety was to be maintained, that capacity had to be monitored and managed: leaving responsibility for safety to another party that was not managing the overall campaign would not be effective.

In addition, the organisational complexity of aerial campaigns and the subsequent coordination effort required may lead to a diffusion of responsibility among the parties involved. This complexity was further increased when staff from different organisations were working together towards a joint outcome.

The report concluded that, while the aerial component of the operation was provided by an aerial contractor, the campaign control organisation was in a central position to understand the big picture. The adoption of good systems for managing risk by the contracting organisation could provide an effective additional layer of defences over and above that provided by each operator to protect against an incident or accident. An effective overall management system could ensure that no one aspect of the operation compromised another aspect.

Similar occurrences

This accident was the first occurrence of a collision with terrain involving a LAT in Australia. However, the ATSB identified another C-130H firefighting weather‑related accident, and a windshear encounter during firefighting operations in the US where the retardant was not jettisoned. A summary of these reports is provided below.

US Air Force Aircraft Accident Investigation Board investigation

On 1 July 2012, the crew of a US Air Force Lockheed Martin C-130H aircraft was conducting wildland firefighting operations near Edgemont, South Dakota, US. While following a lead aircraft (birddog) and positioning for a fire-retardant drop, both aircraft encountered a microburst.

The pilot of the lead aircraft conducted a ‘show me’ run,[95] and shortly after, the crew of the C-130 established a 0.5 NM (1 km) trail formation for the first drop. About 7 minutes later, while setting up for the second drop, the C-130 was in about a 1 NM (1.9 km) trail formation when the lead aircraft hit a ‘bad sinker’, resulting in a loss of altitude and airspeed. The lead aircraft came within 10 ft of the ground, and the pilot called ‘I got to go around’. One second later, the C-130 crew also elected to go-around, and 16 seconds after, they called ‘E-dump, E-dump’. Despite completing an emergency dump of the remaining retardant, the C-130 collided with terrain shortly after, fatally injuring 4 crew and seriously injuring 2 crew.

The investigation found that an inadequate assessment of the operational conditions resulted in the aircraft impacting the ground after flying into a microburst. In addition, it was established that there was a failure to communicate critical operational information from the lead aircraft and air attack crew to the C-130 crew, and there was conflicting guidance concerning thunderstorm avoidance.

SAFECOM report

The USFS and Department of the Interior maintained an aviation safety reporting system as part of its safety program and published a yearly safety summary. On average, it was noted there were about 8 weather-related events reported in the database yearly, with an incident of significance to this investigation described below.

On 17 June 2017, the flight crew of a British Aerospace BAe-146 aircraft were conducting firefighting operations in northern New Mexico, US. The pilot reported that, during a fire-retardant drop, they experienced significant ‘down air’, which resulted in them coming close to terrain. While slowing the aircraft through 130 kt when about 500 ft above the planned drop height, ‘the bottom fell out’ resulting in a loss of about 10 kt airspeed and 300 ft altitude. The pilot applied engine power and manoeuvred the aircraft toward lower terrain, but they did not achieve the expected climb performance and passed just above the tree line. The pilot indicated that the event took less than 10 seconds, and while they should have jettisoned the load in hindsight, they did not consider this at the time as they were focused on flying the escape manoeuvre.

________

  1.  
    1. MAFFS were portable fire-retardant delivery systems that could be inserted in C-130 aircraft without major structural modifications to convert them to air tankers when needed.
    2. When operating in the US as an air tanker, the aircraft was considered a public use asset, and the US Department of Agriculture Forest Service assumed the regulatory role, and defined and issued initial attack qualifications.
    3. This was the operator’s spring training period in preparation for the North American fire season.
    4. Aerodynamic stall: occurs when airflow separates from the wing’s upper surface and becomes turbulent. A stall occurs at high angles of attack, typically 16˚ to 18˚, and results in reduced lift.
    5. Although the emergency condition for the jettison was a simulated scenario, the pilot was still required to perform a live jettison of the load (water) in this training sequence.
    6. Restricted category in this instance referred to an aircraft type that had been manufactured in accordance with the requirements of, and accepted for use by, an Armed Force of the US and was later modified for a special purpose. It becomes a restricted category aircraft on entry to the civilian register.
    7. Coverage factor refers to the amount of retardant released over a specified area. The higher the coverage factor, the larger amount of retardant dropped in the specified area.
    8. A minimum equipment list is a list that identifies items, subject to specific conditions, which may have been unserviceable at the commencement of a flight, and is approved by the FAA.
    9. The operational load monitoring system transmitted various parameters in-flight, including the status of the RADS tank at the start and completion of the drop. The system was introduced to monitor the actual structural loads in the firefighting operational environment, and therefore to better manage the maintenance regime and monitor the structural elements of the aircraft. It was introduced after multiple in-flight break ups of firefighting aircraft.
    10. The load factor is the ratio of the normal acceleration to the acceleration due to gravity. All else being equal, this is equivalent to the ratio of the lift to the weight.
    11. Approach to stall training is conducted for pilots to recognise the incipient stall symptoms. Fully developed stall training was not practically trained in the aircraft due to the significant height loss and potential unusual attitudes when the C 130 entered a stall.
    12. The COM was developed to contain the procedures, instructions and information required by CASA for the conduct of operations for all the operator’s aircraft in Australia.
    13. The clean configuration refers to 0 flap and gear retracted, take-off refers to 50% flap and landing gear down, landing configuration refers to 100% flap and landing gear down.
    14. Indicated airspeed is the airspeed read directly from the airspeed indicator in the cockpit. This speed is an important value for the pilot as it is the indicated airspeeds that are specified in the AFM for important performance information such as stall speeds.
    15. G load: the nominal value for acceleration. In flight, g load represents the combined effects of flight manoeuvring loads and turbulence and can have a positive or negative value
    16. This was consistent with the limitations published by the original manufacturer.
    17. Mountain waves form above and downwind of topographic barriers when strong winds blow with a significant vector component perpendicular to the barrier in a stable environment. If air is being forced over terrain, it will move downward along the lee slopes, then oscillate in a series of waves as it moves downstream, sometimes propagating long distances downwind.
    18. Significant meteorological information (SIGMET): a weather advisory service that provides the location, extent, expected movement and change in intensity of potentially hazardous (significant) or extreme meteorological conditions that are dangerous to most aircraft, such as thunderstorms or severe turbulence.
    19. Severe turbulence can result in large abrupt changes to an aircraft’s attitude and/or altitude, and potentially a momentary loss of control..
    20. The Cooma-Snowy Mountains Airport has an elevation of 3,106 ft AMSL.
    21. PROB30 means 30 per cent chance of forecast conditions occurring.
    22. Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – broken indicates that more than half to almost all the sky is covered.
    23. QNH: the altimeter barometric pressure subscale setting used to indicate the height above mean sea level.
    24. This was the average and peak speed recorded for the previous 10 minutes.
    25. Also known as lee wave or standing wave systems.
    26. Other publications may cite higher values up to 25 kt.
    27. Formed in 2013, the Bushfire and Natural Hazards Cooperative Research Centre is a national research centre funded by the Australian Government.
    28. A small, localised severe downdraft generally associated with a thunderstorm, which induces a horizontal burst of damaging wind at the surface, as the air hits the ground and spreads out.
    29. As ground-based systems were not relevant to firefighting operations, this has not been discussed any further.
    30. These predictive systems rely on a minimum moisture level to detect windshear. The performance specifications for minimum threshold moisture on the system available to be retrofitted to the C-130 were the same as the system fitted to B137.
    31. This was in accordance with the manufacturer’s published procedure.
    32. An air drop is generally defined as a delivery of cargo, supplies or personnel by parachute from an aircraft in-flight.
    33. In July 2018, the aircraft manufacturer published service bulletin 382-57-97 to address accelerated structural fatigue for C-130 aircraft performing air tanker operations.
    34. To calculate thrust, the ATSB provided the propeller manufacturer with a true airspeed range of 110–135 kt to account for a tailwind component in the range 15–40 kt at impact.
    35. SynthEyes is a program for 3D camera tracking, also known as match-moving. It required a minimum number of visible reference point to resolve the attitude and path.
    36. The SkyTrac unit was a Canadian built device, and the intellectual property had been provided previously to the Canadian Transportation Safety Board.
    37. The ADS-B data had output the pressure altitude and barometric vertical speed, both of which were derived from the air data computer, an avionics component which calculates airspeed and altitude trend data, based on the aircrafts pitot static system. Pressure altitude is the altitude referenced to the international standard atmosphere, at 1013.25 hPa, atmospheric pressure at mean sea level.
    38. Ground speed is the speed of an aircraft relative to the surface of the Earth.
    39. ADS-B data recorded an additional ground speed of 132 kt immediately prior to impact, however, this was not used in the performance analysis.
    40. True airspeed is the airspeed of an aircraft relative to the air through which it is moving.
    41. The calibrated airspeed (CAS) is indicated airspeed corrected for installation and instrument errors.
    42. The SkyTrac vertical speed data was derived from the time and altitude information.
    43. A higher-pressure altitude results in a decrease in aerodynamic performance.
    44. An ECG detects heart problems by measuring the electrical activity generated by the heart as it contracts. ECGs from healthy hearts have a characteristic shape. If the ECG shows a different shape it could suggest a heart problem.
    45. Interatrial conduction delay is an electrical abnormality, which is very prevalent in general hospital patients with sinus rhythm (such as sinus bradycardia), and is considered a marker of an electromechanical dysfunction in the left atrium.
    46. Sinus bradycardia was a slower than normal heart rate typically resulting from good physical fitness, taking medications, or from a heart blockage.
    47. The ECG anomalies noted were commonly found in the general population and did not necessarily represent a medical condition.
    48. Calcification causes the artery walls to become more hardened.
    49. When carbon monoxide is absorbed into the bloodstream, it readily binds with haemoglobin to form carboxyhaemoglobin. This reduces the oxygen carrying capacity of the blood and in turn decreases the release of oxygen to the tissues.
    50. A METAR is a routine report of meteorological conditions at an aerodrome.
    51. A SPECI is a special report of meteorological conditions, issued when one or more elements meet specified criteria significant to aviation.
    52. The review of the data post-testing showed the maximum g load applied when modelling severe turbulence was 0.3 G. This was significantly less than the expected additional load factor (0.5-1 G). Therefore, the impact on the stall speed was lower than expected, and is not discussed in the results.
    53. The aural stall warnings generally occurred within 1-2 kt of the pre-stall buffet being felt by the QTPs.
    54. A very large air tanker refers to fixed-wing aircraft with at least 8,000 US gallons (30,283 L) tanks.
    55. Regulatory change that commenced on 2 December 2021 re-categorised this operation under Civil Aviation Safety Regulation Part 138, and aerial work operators in Australia with multi-engine aircraft over 5,700 kg will be required to have an SMS as part of these regulations.
    56. Due to a change in the operator’s SMS program, only 2 years of data was able to be provided. .
    57. It was noted that the accident occurred shortly after this incident.
    58. In 2020, after the accident, the safety manager at the time of the accident retired and was replaced.
    59. In this context, the ATSB understands tactical risk management is the continual assessment of risk in the changing circumstances of a tasking in real-time. This allows crews to perform a contemporaneous assessment of the risks and implement control measures to ensure an appropriate level of safety is maintained throughout the tasking.
    60. With the introduction of new CASA regulations in December 2021 for aerial work operations, operators such as Coulson Aviation would be required to conduct a risk assessment. This would involve a pre-operational risk assessment, the development of a flight risk management plan, and pre-flight and post-flight risk reviews.
    61. International standard for business aircraft operations was a recommended code of best practices designed to help operators achieve high levels of safety and professionalism. A phase II audit reviewed the established SMS, with the focus on ensuring the safety risks were being effectively managed.
    62. A level 2 surveillance event relates to less formal interactions with authorisation holders and may be in the form of checklist-based compliance and product check of a specific section of its systems.
    63. A level 1 surveillance event is a structured, forward-planned, larger-type surveillance event and covers systems audits, health checks and post-authorisation reviews.
    64. The NSW Large Air Tanker program is managed by NSW RFS of behalf of NSW agencies in consultation with NAFC, and included the LAT and very large air tanker (VLAT) aircraft.
    65. It was noted that the C-130 was recorded as having a loaded cruise speed of 300 kt in the operating guidelines, however, due to the limitations imposed through the aircraft manufacturer published service bulletin 382-57-97, they generally operated at about 190 kt. The birddog aircraft was listed as having a cruise speed of 285 kt.
    66. The group provides national leadership to enable interoperable wildland fire operations among coordinated operations among federal, state, local, tribal, and territorial partners in the US. The USFS was a member agency of the group.
    67. ‘Show me’ run referred to a simulated bombing run made by the birddog to demonstrate the run and identify the target for the air tanker.

Safety analysis

Introduction

About midday on 23 January 2020, a Lockheed Martin C-130 aircraft, call sign ‘Bomber 134’ (B134), departed the Richmond Royal Australian Air Force Base, New South Wales (NSW) on a firefighting tasking to Adaminaby. On arrival at Adaminaby, the crew determined that the conditions were unsuitable for a fire-retardant drop and were subsequently re-tasked to the Good Good fire near Peak View. Shortly after conducting a partial drop, and while in a left turn, the aircraft stopped climbing. The pitch attitude reduced, followed by a slight right wing down attitude. Shortly after, the aircraft was observed left wing down at low-level before colliding with terrain. The 3 crew were fatally injured and the aircraft was destroyed.

The extent of the impact damage and post‑impact fire meant the ATSB was unable to verify the operation of every aircraft system. However, there were no known defects that would have affected the aircraft’s serviceability, with the only item noted relating to the propeller anti-icing system on engine number 2, with rectification deferred in accordance with the minimum equipment list. There was no evidence of pre-impact structural damage, and detailed examination showed all engines were operational and producing power at the time of impact.

The ATSB established that the crew were appropriately qualified to perform the flight and there was no evidence of fatigue. While the post-mortem examination identified abnormalities with the copilot’s heart, there was no pathological evidence of scarring or a blockage suggesting a pre‑existing heart condition. Although elevated blood cholesterol levels increase the risk of coronary heart disease, the copilot had been appropriately treated for several years prior to the accident, and their blood pressure readings and last electrocardiogram were all within normal limits. In addition, ATSB research into pilot incapacitation occurrences (AR-2015-096) emphasised that multi-pilot operations provide a safety net if one crew member becomes incapacitated and that such events had a minimal effect on flight. Therefore, noting the medical information above and that the copilot was not the pilot flying, it was considered very unlikely that they had experienced a heart‑related condition that contributed to the accident.

This analysis will examine the environmental conditions and how this influenced the aircraft’s degraded performance and subsequent stall. The tasking process, management of task rejections, and the crew’s awareness of such on the day will also be discussed. It will also consider the risk management of large air tankers, the use of a flight risk assessment tool, and the aerial supervision and initial attack certification requirements in place. Further, the impact of limited recorded flight data and cockpit voice recordings, along with the benefits of on-board windshear systems will also be discussed.

Hazardous weather conditions

The Bureau of Meteorology graphical area forecasts for the area of operation contained strong winds, mountain wave activity and severe turbulence, which extended from Richmond to the Adaminaby and Good Good (at Peak View) fire‑grounds. The Cooma-Snowy Mountains Airport (50 km from the accident site) aerodrome forecast also indicated gusting winds nearing 50 kt and reduced visibility from blowing dust. These forecasts were consistent with the Peak View weather station recordings, witness reports, and video of the actual conditions. The ATSB’s analysis of the aircraft’s ground speed from the automatic dependent surveillance broadcast (ADS-B) data also showed that the wind speed was likely of a magnitude of 20-40 kt from a north‑westerly direction during their drop planning circuits at Peak View.

Overall, the Bureau of Meteorology concluded that the actual conditions in the accident area were consistent with the forecasts. This was reinforced by the pilot reports in the morning, which resulted in the smaller fire-control aircraft ceasing operations due to winds of about 50 kt. In addition, the pilot in command (PIC) of the Boeing 737 (B137) reported similar winds and experiencing a windshear warning and uncommanded roll when at Adaminaby. Of note, the birddog pilot had rejected the tasking to Adaminaby as the forecast conditions were worse than what they had experienced 2 weeks prior, where they were subjected to moderate to severe turbulence and downdrafts.

At Peak View, the crew had followed their procedures and conducted a number of circuits over the drop location, which was on the eastern side of a ridgeline. As the crew had elected to conduct the drop, this would indicate that they had assessed the meteorological conditions during these circuits as suitable to continue. However, the lowest circuit height of 500 ft may not have been low enough for the crew to accurately assess the conditions at the drop height and identify any localised terrain or fire effects.

The low-pressure spike recorded in the ADS-B data potentially indicated the aircraft had been subjected to localised weather effects, but due to limited information the reason for this could not be conclusively determined. The drop was located on the lee side of a ridgeline, an area prone to turbulence and potential development of mountain waves. However, while mountain waves were confirmed by the Bureau of Meteorology analysis to be present across the Snowy Mountains region at the time of the accident, the severity of this could not be ascertained from the available information. In addition, the drop was in an area noted by local glider pilots to be subject to turbulence and rotor conditions.

Strong winds and mountain waves are considered hazardous conditions due to their ability to generate strong downdrafts that may adversely affect an aircraft’s climb performance. They may also create windshear, which is of particular significance when it results in an increased tailwind component, with a subsequent reduction in airspeed. At the same time, moderate to severe turbulence would increase the stall speed.

In addition, the presence of a large fire will produce smoke and heat plumes, and potentially fire‑driven winds, that is likely to exacerbate the forecast conditions. The Blue Mountains fire case study suggested the possibility of fires drawing strong winds down closer to the surface than might otherwise be forecast.

Therefore, the environmental conditions in the accident area were conducive to windshear and downdraft development at a time when the aircraft was most vulnerable, with low airspeed and low height.

Tasking continuation by the Rural Fire Service

In the 1100 conference call between the Cooma incident controller and several senior personnel from the State Operations Centre, they discussed the severe fire weather conditions and escalating fire threat at Adaminaby. They also acknowledged that the smaller fire-control aircraft (which included the incident air attack supervisor), had stopped operations due to strong winds, with pilots reports of winds up to 52 kt and limited visibility. In that same conference call, a senior NSW Rural Fire Service (RFS) officer indicated that they should send B137 rather than wait for a birddog assessment. That is, they elected to send the LATs as initial attack to determine if they could work the fire-ground, rather than wait for an assessment prior to re-starting aerial operations. Following this, the State Operations Centre tasked 2 large air tankers (LATs), and subsequently the birddog, from Richmond to Adaminaby knowing the conditions were marginal, and that the LATs would arrive prior to the birddog.

During the initial crew tasking, the Richmond airbase manager (ABM) had mentioned the wind conditions to the crew of B137 and advised them to ‘take care’. Similarly, subsequent calls made between the ABM and the state air desk (SAD) at 1137 and 1209 discussed the adverse environmental conditions and that the birddog pilot was questioning the suitability of the weather. When the birddog pilot rejected the tasking, based on operational safety concerns, there was an expectation from them and the operator’s pilots that the tasking for the LATs would be cancelled, or at least reconsidered. This was consistent with the normal practice for a ‘turn down’ in the United States (US), and the need for aerial supervision in marginal weather conditions as outlined in the US Department of Agriculture, Forest Service (USFS) Standards for Airtanker Operations and Forest Service Handbook. However, despite an awareness of the hazardous environmental conditions, the earlier withdrawal of the smaller fire-control aircraft and the birddog pilot rejection, the tasking was continued, and this information was not relayed to either B137 or B134 crews.

Subsequently, following the drop at Adaminaby, the PIC of B137 reportedly advised the RFS Cooma aviation radio operator to cancel all aircraft operating in the area and indicated to the ABM (at about 1232) that they would not be returning due to the weather. While the crew of B134 had already been tasked and were en route to Adaminaby, this was another opportunity for the RFS to reassess the suitability of the tasking. In addition, the RFS, having received information that further operations in the Adaminaby area were unsuitable for LAT operations, did not communicate this information to the Cooma aviation radio operator or B134. In response to the ATSB draft report, the RFS noted that, while the State Operations Controller was aware of these rejections, they elected to allow B134 to continue, for further intelligence gathering purposes.

It was recognised that RFS personnel may have a limited understanding of aviation operations and therefore, there was a reliance on aircraft operators and crew to manage safety. However, in this case, the crew were not provided with a full awareness of the situation, with no knowledge of the birddog pilot rejection or that the smaller fire‑control aircraft were no longer flying. In addition, while B134 had been in contact with B137 and received advice on the conditions, this was unknown to the RFS at the time.

While some RFS personnel considered it unlikely that the LATs would be able to achieve the planned objectives due to the weather conditions, they continued with the tasking, relying on the crews to independently assess the conditions and cancel the tasking while airborne. As highlighted in the ATSB’s research into aerial campaign management, leaving the responsibility of safety to another party (the operator and crew in this instance) who are not managing the overall campaign is not effective. When there is a high-level decision to proceed with a tasking despite known elevated risk factors, providing information on those risks would allow crews and operators to make more informed decisions.

Crew awareness of task rejection

As discussed above, the smaller fire-control aircraft had ceased operations in the area earlier that day, which had been acknowledged by the RFS personnel from the State Operations Centre in the 1100 conference call. Also, the birddog pilot had rejected the tasking to Adaminaby, unaware that the smaller aircraft had stopped flying at that time. The birddog pilot indicated that it was not routine to talk to the other pilots about taskings. Therefore, they did not communicate with the crew of B134 that they had declined the tasking, but expected the RFS personnel would relay this information.

In addition, there was no indication in the available radio calls or at interview that the cessation of operations earlier that day or the birddog pilot task rejection was communicated to the crew of B134 by any RFS personnel. It was noted that this information was not required to be passed on in any of the tasking or dispatch procedures. While not directly communicated to the crew, there was the potential that they may have been monitoring the radio call between the SAD and the Richmond ABM at 1209, shortly after they had departed. However, there was no clear statement of the rejection in that call, rather, they only discussed the birddog pilot’s uncertainty about the weather conditions.

Therefore, while known to RFS personnel, it was very unlikely that the crew of B134 were aware that the birddog pilot had rejected the tasking, or that the smaller fire‑control aircraft were no longer operating in the area, due to the hazardous environmental conditions. While this was only one risk factor among others that would be considered by the crew, having this information would have allowed them to make a more informed decision about the weather conditions and task acceptance.

Nevertheless, as the tasking to Adaminaby for B134 had been provided prior to the assignment of the birddog, it was likely the crew expected to be departing as initial attack. In which case, even if they were aware of this information, it was possible that they may have still departed to self‑assess the conditions, particularly given the fire-ground was at least 45 minutes away. However, as this was an individual judgement, it could not be established how this information alone would have influenced their decision on the day.

Task acceptance by the crew

The weather forecasts applicable at the time of the flight contained mountain wave activity and severe turbulence, which extended from Richmond to both the Adaminaby and Good Good fire‑grounds. While the crew’s access to weather information on the day could not be determined, the usual practice of filing a flight plan through the operator’s electronic flight bag provided access to the required forecasts. They had also attended the morning RFS briefing with the Richmond ABM in which the weather conditions across the state were discussed. In addition, the PIC was one of the recipients of the ABM’s text message for the weather alert for Richmond in the morning prior to the tasking.

Although the PIC of B137 was made aware by the ABM at the time of the initial tasking that there no other aircraft operating at Adaminaby, they were not aware of the reason for this. Therefore, it was plausible that the crew of B134 were also not aware of this information and were not able to factor in the actual conditions to their decision when accepting the initial tasking to Adaminaby. Further, as discussed above, they were very likely unaware of the birddog pilot’s rejection of the task. Irrespective, it was reasonable to conclude that the crew of B134 were at least aware of the forecast conditions for the area of operation before departing Richmond.

While both the operator’s and manufacturer’s documents stated that flight was prohibited in known severe turbulence, this did not prevent crews from departing when severe turbulence was forecast. The only weather-related operational limitations were associated with thunderstorm activity. Therefore, it was considered normal practice to accept a tasking in these forecast conditions. Most of the operator’s LAT pilots interviewed indicated a preference to depart and assess the actual conditions to determine if they could find a workable solution rather than rely solely on a forecast, which could cover a large area and time frame, and may not necessarily reflect the actual conditions at the fire‑ground.

When B134 was en route to Adaminaby, the PIC of B137 (returning to Richmond) discussed the actual conditions with the PIC of B134, and advised they were not returning. Although B134 continued to Adaminaby, the crew discontinued the task once there as they experienced similar conditions. Despite this, knowing the decision made by the PIC of B137 and the forecast conditions for the area, the crew of B134 accepted the alternate tasking to the nearby Good Good fire‑ground, consistent with company practice. Circuits were conducted at Good Good, as per the standard retardant drop planning, to identify the asset for protection and the suitability for a drop. While the details of the assessment were unknown, the crew elected to continue with the retardant drop. Ultimately, the decisions to accept the initial and alternate tasking, and proceed with the retardant drop by the crew exposed the aircraft to a situation where it experienced degraded performance following the drop.

Degraded aircraft climb performance

Witness video, ADS-B and SkyTrac data showed that, following the completion of the drop, the aircraft climbed about 170 ft over a period of about 10 seconds, which was comparable to previous climb rates from the operational load management system. It was reported by the operator’s pilots that, at this stage of the flight, they would be targeting an airspeed increase from the drop at 120 kt indicated airspeed (IAS) to 150 kt IAS, while climbing from the drop height of 200 ft to at least 500 ft above ground level. However, during this period, the ATSB calculated a calibrated airspeed (CAS) range of between 100 and 123 kt (comparable to the IAS), which indicated the airspeed likely stagnated or reduced over this period.

Following this initial 10 seconds, the climb ceased, and altitude appeared to be maintained for about 3 seconds before the aircraft began to sink with an estimated descent rate increasing to 2,000 ft/min. The CAS also continued to stagnate after the initial 10 seconds. The reduction in vertical speed and estimated airspeed stagnation occurred at the time it would be expected that the engine power would be increasing. This increase in power would either translate to an increased height (while maintaining IAS) or maintained altitude (with an increase in IAS). Of note, the ATSB had established that there were no indications of mechanical or technical failures with the aircraft.

After the drop, the aircraft was turned from a predominant crosswind to a predominant tailwind, based on the recorded mean wind direction. This would have resulted in an initial slight decrease in the IAS. At the same time, as previously established, there were strong gusting winds, turbulence, and mountain wave activity present at the time of the accident, and these conditions were conducive to windshear.

If there was an additional increase in this tailwind component from windshear, this would have resulted in a further reduction of the airspeed. There would also be a corresponding decrease in pitch attitude and rate of climb, with a subsequent loss in altitude, as highlighted in the Lockheed Martin C-130 Airplane Flight Manual (AFM), and by the Bureau of Meteorology (2014) and Bowles (1990). These descriptions were consistent with the ATSB’s analysis of the recorded information. The witness video showed that the maximum pitch-up angle occurred 4 seconds after the completion of the drop and from this point it decreased. Likewise, the aircraft initially had a rate of climb up to 1,000 ft/min, but this also decreased, and the aircraft descended.

For comparison, the simulator testing showed that a strong constant mean wind during the climb‑out resulted in a small loss of IAS, but a significantly higher ground speed than was seen in the accident sequence. However, scenarios that used a moderate (15 kt) mean wind with gusts and windshear between 15 kt and 35 kt (similar to the total wind speeds recorded on the day), produced similar ground speeds to the recorded accident data. They also consistently resulted in the IAS decaying into the stall speed region, with minimum speeds between 84 kt and 98 kt.

In addition, observations made on the reconstruction flight noted an airspeed decay when they turned and were flying toward the accident site, even though the engine power was increasing. This was consistent with the glider pilot comments that there could be localised effects in this area due to the terrain. On the day of the accident, while the reason could not be determined, the ADS‑B data recorded a low‑pressure spike, which also had the potential to result in decreased aircraft performance.

The intensity of the environmental conditions (including mountain wave activity, strong gusting winds and turbulence) and therefore the windshear, could not be determined. However, the ATSB’s analysis of the available recorded data showed that the aircraft’s performance had degraded during the climb-out, consistent with encountering windshear, while concurrently turning into an increased tailwind, based on the mean wind direction. This was supported by the C‑130 simulator testing. With the limitations of the available recordings, and the absence of a cockpit voice recorder, it could not be determined if the crew had identified the conditions or initiated a recovery procedure. As cautioned in the Lockheed Martin AFM, severe windshear could exceed aircraft performance capability.

Stall at low altitude

About 10 seconds after the completion of the drop, the aircraft had climbed to about 330 ft above ground level but then ceased climbing, and the altitude was maintained for a few seconds. Although the aircraft was in a nose-up attitude, the aircraft was sinking and developed a high sink rate up to 2,000 ft/min. This was followed by a significant left roll just prior to impact. This was consistent with the stall characteristics as outlined in the C-130 discussion paper (Mizell 2009), where the approach to the stall in this configuration exhibited high descent rates, before the left wing stalled resulting in a large angle of bank excursion.

The ATSB calculated the power-on stall speed, with 50% flap and at the post-drop weight, as 83 kt. Consideration was also given to the potential effect of turbulence, which increased the stall speed to between 101-117 kt for moderate turbulence and 117-143 kt for severe turbulence. Noting that the ATSB derived CAS for the accident flight was between 100 and 123 kt in the last 10 seconds of the available data, this presented a significant overlap with the calculated stall speeds. It was also noted that, in the simulator test scenario that was most consistent with the accident flight, the IAS consistently decayed into the stall speed region with repeated stall warnings activated.

In the absence of the cockpit audio recording, it was unknown if the PIC, as the pilot flying, had initiated a response to the stall. Despite this, in consideration of the observed high sink rate followed by a significant left-wing roll, and the overlap in the stall speed and CAS, it was likely that the aircraft aerodynamically stalled at a height that was insufficient to recover before colliding with terrain.

Coulson Aviation risk management of large air tankers

While there was no regulatory requirement at the time of the accident, Coulson Aviation had implemented a safety management system (SMS), it was a contract requirement in the US, and which was viewed favourably by the National Aerial Firefighting Centre. However, as the system was not mandated, it was not assessed by the Civil Aviation Safety Authority or the Federal Aviation Administration. The ATSB acknowledges that any operator’s SMS will evolve and mature with time. However, significant events like accidents need to be used to explore whether their SMS is operating in a way that can assure the highest level of safety given the nature of their operations.

Acknowledging the element of risk associated with firefighting operations, the ATSB reviewed the safety risk management component of the SMS. Although the operator’s SMS manual outlined that the online SMS program would record the identified hazards, this was limited to submitted incident reports, and did not contain previously identified hazards. Although, the Company Operations Manual had detailed several operational hazards, the current and previous safety managers indicated that no risk assessments for the identified hazards associated with the LAT operations had been conducted. However, it was noted that risk assessments were included in the SMS manual, but these only applied to safety reports and change management contained within the online SMS program. While some of these hazards may have been discussed during the daily SMS conference call, this process was not formalised.

Without formal operational risk assessments of the recognised hazards applicable to the LAT operation, there was no identified risk mitigation strategies nor was there any assurance that the risks were at an acceptable level. For example, windshear and downdrafts had been recognised as a potential hazard in the Company Operations Manual. However, as no formal assessment for the C-130 aircraft had been conducted, there was no opportunity to formally identify and assess potential risk mitigators, such as those discussed by Hallowell and Cho (2010).

As noted by ICAO (2018), safety risk management activities such as operational risk assessments should be documented. Both the current and previous safety managers indicated that the operator did not have a risk register as part of their SMS, or an alternative process, at the time of the accident. This limited their ability to track, monitor, and mitigate the identified hazards, and assess the effectiveness of any risk controls.

Another important element of safety risk management was the use of reporting systems for hazard identification. The ATSB’s review of the operator’s safety reporting system found that there were few reports related to flight operations, and there were no reports of weather-related incidents. This was despite several of the crews interviewed having recalled encountering windshear during firefighting operations, which affected the aircraft. Given the operator’s draft report response comments that they considered the incident reporting numbers were mitigated by the daily SMS calls, it was likely they relied on this informal process for flight risk awareness, rather than incident reporting. Although the weather conditions were mentioned in the days prior to the accident, there was minimal detail of the discussions recorded in the daily SMS conference calls. Therefore, as there was limited information on operational issues recorded in the SMS, there was limited ability to conduct risk assessments of any identified hazards, to gain an understanding of their potential impacts on operations and mitigate the associated risks, or to perform any safety trend analysis.

As established above, aerial firefighting operations were subjected to elevated risks. Therefore, the supporting risk management practices should consider risk assessments at all levels of the organisation and all stages of the operation. Acknowledging that the risks cannot be entirely eliminated, an operational risk assessment would have provided an opportunity to identify the need to establish acceptable risk levels associated with firefighting taskings. While elevated risks were individually identified, there was no clear process for pilots to review or assess all the factors collectively and consistently. Instead, the operator’s risk management process relied predominately on crews conducting their individual, undocumented risk assessments for each task as part of their normal pre-flight planning and tactical assessment during flight. In particular, there was no identification of the need for a risk-based decision‑making framework to support pilot decision‑making when accepting potentially high-risk taskings.

The operator’s voluntary audit had identified significant growth in the company since the initial audit 2 years earlier, but it also noted that the SMS had not yet fully matured. While it was recognised there was no requirement for Coulson Aviation to have an SMS in Australia, the ATSB identified that there was very limited oversight of the identified hazards. Without operational risk assessments for the LAT operations or a method to monitor identified hazards, associated risk assessments, or risk mitigation, this limited Coulson Aviation’s ability to manage the risks related to their LAT operation.  

Pre-flight risk assessment tool

As noted by the US National Transportation Safety Board, effective risk management involves good decision-making. These skills are important in most work domains but are especially critical in high-risk settings when individuals may be functioning under time pressure and stress, such as firefighting operations.

The LAT operation was a 15-minute notice standby tasking arrangement, which could send the aircraft to any location within the bounds of the tasking authority. The retardant drop task was a response to a possibly urgent threat that involved low-level, low-speed operations in a potentially hazardous and challenging environment. This made it a comparatively high-risk activity, in addition to which pilots were also responding to an external tasking agency, a potential source of external pressure.

At the start of each day, the RFS conducted a briefing for the LAT and birddog crews, which provided an overview of the weather, likely areas of operation, and fire conditions. However, on receiving a tasking, crews were still required to conduct their own flight planning specific to the area of operation, in a timely manner, to determine what was an acceptable level of risk.

The only consideration provided at interview as no-go criteria by the Coulson Aviation crews was a thunderstorm. Consequently, there could be several flight planning factors, which individually were not a no-go criterion, but collectively elevated the risk to higher-than-normal for the LAT operation. There could also be additional external factors, such as task rejections or cancellations by other pilots, which could elevate the risk if they were known to the LAT crew.

While acknowledging that LAT operations had inherent risks, Coulson Aviation had not introduced a pre-flight risk assessment tool for their LATs. Instead, there was a reliance on the PIC to assess the acceptability of the task based on their assessment of the conditions. However, this process may not have necessarily detected the cumulative effect of several indicators of elevated risk.

On the day of the accident, there were multiple pre-flight risk indicators, which included:

  • forecast strong winds, severe turbulence, and mountain waves in the area of operation
  • operating in mountainous terrain
  • the Richmond Airport weather warning sent to the LAT crews by the ABM prior to the Adaminaby tasking
  • the cessation of the smaller fire-control aircraft due to the actual weather conditions in the Snowy Mountains
  • the birddog pilot’s rejection of the task following assessment of the forecast weather conditions for the area compared with a previous experience
  • the copilot and flight engineer were in their first firefighting season
  • potential pressure to respond to the bush-fire risk to the town of Adaminaby.

While it could not be determined if all factors were known to the crew of B134, or their assessment of each factor, none of the above risk indicators were likely to be individually sufficient for the PIC to reject the task. However, when assessed collectively against pre-defined criteria, they would have produced an elevated score, as identified in the ATSB’s estimate of the accident flight risk profile using the operators recently introduced pre-flight risk assessment tool. However, it was noted that this tool did not include weather-related task rejections, considered one of the highest risk indicators for helicopter operations by the Helicopter Association International.

While there was no regulatory requirement at the time, the use of a pre-flight risk assessment tool was a contract requirement with the USFS. A 2014 NTSB study of aerial work accidents outlined that risk management guidelines and best practices specific to aerial work aircraft operations included a pre-flight risk assessment tool. These help operators and pilots mitigate the unique risks associated with their operations, in particular, when the operation is often conducted in high‑risk circumstances. As emphasised by both the US Federal Aviation Administration (FAA) and USFS, every flight has some level of risk. Therefore, it is critical that crews can differentiate between a low-risk and high‑risk flight during the planning stage to establish the overall risk profile. Risk management strategies, such as a pre-flight risk assessment tool, can assist pilots with applying a systematic process that helps them resist pressures that can adversely affect their decision-making and identify risks that could affect the safety of the flight.

In this case, the availability of such a tool would have assisted the PIC with making a more informed go/no-go decision for the initial tasking to Adaminaby. This almost certainly would have resulted in the PIC identifying the elevated risk associated with the tasking, and having to consider implementing risk mitigations, or escalation of the decision-making, if not rejection of the task. In addition, the PIC was reported to be conservative, therefore, the knowledge of the cessation of aerial operations due to strong winds and limited visibility and followed by subsequent weather‑related rejections due to safety concerns, would have likely increased the risk above an acceptable level.

Rural Fire Service aerial supervision requirements

Although it was acknowledged that the RFS was not an aviation operator, they were responsible for tasking a variety of aerial assets, with substantially different operating capabilities, often in high pressure situations in challenging environmental conditions. It could be foreseen that there will be community expectations that the RFS respond to fire threats, and use all available aerial assets to achieve the planned objectives. Accordingly, the tasking agency needs to define the acceptable level of risk for the overall operation, to provide an effective additional layer of defence above that provided by the aircraft operator. Such systems and policies have been implemented in firefighting operations in the US.

Operationally, the tasking-related risk assessment noted in the RFS Aviation Standard Operating Procedures (operating procedures), predominantly focused on the use of the aircraft to manage the fire threat rather than ensuring the safe use of those aircraft. The RFS had identified considerations to ensure the effective use of LATs, and acknowledged that certain task environments had higher risks. However, there was no guidance provided to frontline RFS personnel on how to assess these risks as part of the tasking process, such as those noted by the USFS and the US National Wildfire Coordinating Group.

For example, the RFS tasking considerations included weather as a potential threat, but there was no further guidance around how to assess the environmental conditions, or under what circumstances taskings should be considered acceptable or not acceptable. For the tasking to Adaminaby, it was noted in the 1100 conference call and various logs that the weather conditions were hazardous and that no aircraft were flying in the area due to the wind and visibility conditions. Despite this, there was an expectation that the LATs had greater flight capabilities and the pilots could make their own assessment of the conditions. Therefore, the decision was to send the LATs, and see if an opportunity presented itself that allowed for their assistance.

However, if the RFS had implemented policies and supporting procedures applicable to minimum aerial supervision requirements, similar to those in place in the US, this would have provided guidance to the front-line staff to assist with tasking decision making. For example, the USFS documents outlined the requirement for aerial supervision in marginal weather, including limited visibility and turbulence, and further, where the aerial supervisor suspended operations, they must not proceed with further taskings until risk mitigations are in place. If such policies were in place, it was likely that RFS personnel would have identified the higher risk environment, and therefore the need for aerial supervision on this tasking. In turn, this would have likely identified that an initial attack deployment was not suitable in the elevated risk environment.

The operating procedures indicated that aerial supervision was generally required for LAT firefighting operations unless the crew were initial attack certified and there were operational advantages to commencing operations prior to aerial supervision arriving. Those advantages included considering the speed differential between a birddog and LAT, or when a birddog was not available due to resourcing constraints, such as diversion to another tasking. However, there was no differentiation between the use of an initial attack deployment where aerial supervision was not available, in comparison to the rejection or cessation of a tasking due to safety concerns.

While the initial deployment of B137 ahead of the birddog could reasonably be accepted as meeting an operational advantage, the departure of the smaller fire-control aircraft and subsequent rejection of the birddog should have resulted in reconsidering the use of ‘initial attack’. However, there was no supporting procedure or guidance on the use of ‘initial attack’ deployment in these elevated risk circumstances, such as when the task was rejected by the birddog due to safety concerns. In the case of the accident, this rejection occurred shortly prior to B134 departing Richmond, and there would have been sufficient opportunity to reassess the task, and potentially redirect the LAT elsewhere, prior to their arrival overhead Adaminaby.

Policies and procedures on aerial supervision should include consideration of the known factors that elevate risk associated with aerial firefighting tasks, and would ensure the RFS have minimum aerial supervision requirements in place for each tasking circumstance. It would also include policies and procedures for the deployment of LATs without aerial supervision (initial attack), and in what circumstances this would be acceptable. In order to make acceptable risk‑based tasking decisions, these considerations need to be enshrined in policies and procedures, to assist with time-critical decisions during the fire season by frontline staff. The RFS personnel would have to assess that the tasking meets the minimum aerial supervision requirements prior to approaching operators with taskings, to ensure the taskings can be conducted within their defined, accepted risk levels.

Rural Fire Service management of task rejections

The ATSB’s 2004 research into aerial campaign management stated that organisations that contracted aerial operations (such as the RFS) were directly involved in the management of significant parts of the aerial campaign and were in a central position to understand the big picture. Decisions made during this process had the capacity to influence the level of risk of the operations.

It could be reasonably expected that there will be situations in which tasks are declined for safety reasons. While the RFS Aviation Standard Operating Procedures and the Operating Guidelines for Air Tanker Operations outlined some initial considerations regarding the tasking of LATs, there was no further policies or procedures following the initial tasking process to support the ongoing task. Consequently, there was no process in place to support RFS frontline personnel on managing a task rejection by crews or operators.

These policies and procedures would detail when task rejections should be considered as a risk indicator, such as when flights were declined due to weather-related safety concerns. For comparison with the USFS Standards for Airtanker Operations, this may also include communication of this information to other crews, reassessment of the tasking, incorporation of appropriate mitigations, or cancellation of the task. They should also encourage pilots and operators to communicate unsafe conditions without fear of reprisal.

On the day of the accident, neither the Richmond ABM nor the SAD communicated to either of the LAT crews or the birddog pilot tasked to Adaminaby, information regarding the smaller fire-control aircraft ceasing operations due to unsuitable weather. Nor did they communicate the task rejection by the birddog pilot to the crew of B134 shortly prior to take-off from Richmond (noting this occurred about the time B137 was overhead Adaminaby). The LAT AAS (who would have been on board the birddog) also did not communicate this to the LAT crews, as their communication role did not commence due to the birddog aircraft not departing. In addition, this rejection was not communicated by RFS personnel to the Cooma Fire Control Centre aviation radio operator, who could reasonably be expected to be in contact with the LAT crew as they were operating as initial attack, and they were the appropriate local ground contact to coordinate the task. While acknowledging the LAT’s, birddogs, and the smaller fire‑control aircraft have different capabilities and performance limitations, this was relevant information (specifically, reported strong winds and limited visibility, and the rejection based on safety concerns) that could reasonably have been communicated to the crews. As previously discussed, there was an expectation from the birddog pilot and the operator’s pilots that the RFS would either relay this information to them so it could be included in their decision-making processes, or the task would be cancelled by the RFS.

The subsequent rejection of further tasking by B137 as the conditions were worsening and reportedly unsuitable for LAT operations, was also not communicated by either the ABM or SAD to the crew of B134 nor to the Cooma incident management team. In addition, shortly after this rejection, the ABM and SAD discussed sending an alternative LAT to Adaminaby. None of these rejections resulted in a reassessment or cancellation of the tasking for B134 to Adaminaby. Rather, the RFS allowed B134 to proceed with the intention of gathering additional intelligence to assist in determining whether further aerial operations would proceed. Subsequently, the Cooma aviation radio operator was also unaware of this rejection of further tasking by B137, or their assessment of the conditions when providing the secondary tasking to the B134 crew.

As outlined above, while some crews were initial attack certified and could operate without aerial supervision, the RFS operating procedures indicated that this was only to occur when there were operational advantages prior to an air attack supervisor (AAS) arriving. However, the operating procedures did not reference any circumstances, such as in the case of the accident flight, where a tasking had been rejected due to safety concerns, such as unsuitable weather. While initial attack crews were trained to conduct operations without the AAS, continuing a tasking where the local AAS had departed or grounded due to weather concerns, and/or the birddog pilot (and therefore LAT AAS) rejected the tasking, appeared outside of the intended scope of ‘initial attack’ deployments.

As the task rejections were on the basis of weather or fire-ground safety concerns, which equally applied to B134, appropriate policies and procedures regarding task rejection should have resulted in the initial tasking to Adaminaby being cancelled following the rejections. There were 2 opportunities for this. The first was at the time of the birddog rejection when B134 was departing Richmond, which, at the very least (noting the RFS understanding of differing capabilities between the birddog and the LATs) should have resulted in communication of that information to allow the LAT pilots to make their own more informed risk assessment. The second was when B134 was transiting over the Canberra region and the RFS received advice from B137 which indicated that it was not suitable for LAT operations. Task cancellation would have also been consistent with the RFS intended use of initial attack and the general operating principles in the US.

While the RFS was not an aviation organisation or directly responsible for flight safety, they were closely involved in the aerial operation, being responsible for determining the task objectives and selecting the aircraft category for the task. Policies and associated procedures for task rejections would provide RFS personnel with the required steps to effectively and safely manage taskings, and provide guidance for decision-making. It would allow for consideration of a rejection by other crews, resulting in clear communication from RFS personnel of crew rejection decisions both internally, and to all aircraft on the tasking, and additional risk treatments being implemented up to task cancellation. A policy would also provide all RFS personnel with an objective mechanism to cancel taskings on the basis of safety.

Retardant load not jettisoned

Although the aircraft was obscured by smoke at various points, the witness video showed no further retardant dispersal after the initial drop, nor was any found between the drop area and the accident location. At the site, the operational state of the retardant aerial delivery system could not be determined due to the damage sustained, but a large amount of retardant was found in the wreckage near the tank.

However, as there was only about 10 seconds between the climb performance degrading and the likely stall, there was limited time available for the crew to identify and respond to the situation. Past research shows pilot recognition time of windshear can be expected to be about 5 seconds, and the emergency dump function would take a further 2 seconds. However, in the absence of the cockpit audio recording, it could not be determined if the crew had considered or called for an emergency dump of the remaining load. Therefore, for reasons undetermined, the remaining 11,340 kg of retardant was not jettisoned during the accident sequence.

The ATSB established that jettisoning the remaining load would have lowered the stall speed and optimised the aircraft’s climb performance. This was also confirmed from the simulator testing. Nonetheless, it was not possible to determine if jettisoning the remaining load, taking into account the time available, and typical recognition and response times, would have prevented the collision with terrain. The outcome of the US Air Force C-130 accident, where the crew did jettison the load, is an example of when this action may not be sufficient to avoid a collision with terrain.

Windshear recovery procedure and training  

It is acknowledged throughout the aerial firefighting industry that they operate in a challenging environment with elevated risk conditions. Windshear was a known phenomenon, which could be exacerbated by fire-associated winds that may be difficult to forecast and could be influenced by local terrain effects. Most of the operator’s crews interviewed reported encountering a windshear event during firefighting operations. The FAA study published in 2010 identified 3 categories of windshear mitigators: ground-based alerting systems, pilot training, and airborne detection systems.

Large air tanker firefighting operations were generally conducted away from airports often over inhospitable terrain. Therefore, it would be unlikely the ground-based systems, or weather-based monitoring from airports would be available for windshear alerting during a retardant drop.

The Lockheed Martin C-130 AFM had been updated prior to 2010 to include a section on adverse environmental conditions, which included a windshear recovery procedure. Although the FAA had approved the Coulson Aviation C-130 AFM in 2013, the operator had used an earlier version (1989) of a military document to develop the manual. This was consistent with comments provided by the FAA to the ATSB, where the documents and manuals for military surplus aircraft would normally be sourced from the military rather than the manufacturer. Therefore, the windshear recovery procedure was not included in the Coulson Aviation C-130 AFM.

While both the departures and standard operating procedures sections of the Company Operations Manual provided basic windshear recovery guidance for the C-130, it was not presented as an emergency procedure, nor did it consider any specific requirements for firefighting activities, such as the potential jettison capability offered by the retardant aerial delivery system. In addition, while this manual was applicable to all aircraft types, it was specifically developed for Australian operations only, although the company operated internationally. At least one of the operator’s C-130 pilots stated that they did not consider this manual to be the reference document for operating the aircraft, rather, the AFM and checklists were the appropriate source. This was consistent with the purpose of an AFM, which was to provide the procedures for operating the aircraft.

Although the PIC of B134 had completed an in-flight training scenario in 2019 that incorporated a simulated downdraft, the training generally focussed on responding to an emergency on the drop run, rather than specific to windshear. While a windshear encounter could be simulated airborne in the aircraft, it was not possible to replicate the effect on aircraft performance. Therefore, this would not provide pilots with the performance instrument indications that would be typically experienced. However, the operator provided their C-130 pilots with annual simulator training. While it was noted that a briefing on windshear recovery was incorporated into the training syllabus, there was no requirement to conduct a simulator-based low-level windshear recovery scenario as part of initial or recurrent training. This could provide crews with the experience needed to recognise the symptoms of windshear and practice a recovery procedure.

The operator also noted that most of their crews were former or current military pilots and would have received windshear training on a bi-annual basis when serving members. However, for those pilots no longer in the military, no recurrent training was provided by the operator to maintain proficiency in windshear recovery. Further, it was also recognised that the air drop scenario conducted in the military differed somewhat from a retardant drop. Most notably was the inclusion of the retardant aerial delivery system and capability to conduct an emergency dump to improve aircraft performance.

Research conducted on behalf of the FAA found that there was only about 5-15 seconds available for pilots to recognise and respond to a windshear encounter. Japanese research into pilot reactions to windshear on landing approach found that about 5.5 seconds was the average time to recognise a windshear event. As such, when in a low airspeed and low height scenario associated with a retardant drop, recognition and reaction to a significant windshear event must be prompt to avoid a collision. However, as no cockpit audio recording was available for the accident flight, it could not be determined if the crew had recognised that they very likely experienced a windshear event and/or had initiated a recovery. Despite this, an effective training program, using a combination of theory and practice, could provide pilots with the necessary skills and experience to recognise and respond to a low-level windshear encounter with minimal delay.

In multi-pilot operations, effective crew coordination and performance depends on the crew having a shared mental model of the task. This mental model is founded on operating procedures (ICAO, 2015). Such procedures are designed to help reduce variation within a given process and ensure operations are performed correctly. Without formal procedures, pilots are required to exercise judgement to the best of their abilities, based on their experience, skills and knowledge. Together, a recovery procedure specific to the nature of the operation supported by training, should provide pilots with a shared mental model of the symptoms and recovery actions for a windshear encounter.

Windshear system not fitted

Where it has been recognised that pilot awareness and training are not 100% effective for windshear avoidance, advanced warning systems are designed to detect and confirm the hazardous condition prior to the encounter. This provides additional time for the crew to increase the aircraft’s energy state and climb, so that any windshear encountered is at a higher, safer altitude. Alternatively, reactive systems alert the crew that they are experiencing windshear so that they can respond immediately, thereby minimising the time required for the crew to identify the situation before responding. These systems are particularly relevant to aerial firefighting aircraft, where there is an increased risk of encountering windshear, which is most hazardous in the low-level low‑speed environment where they regularly conduct operations. As noted by some pilots interviewed, the fitment of such a system was reported to have had a positive effect on their management of a windshear encounter.

While a birddog pilot could provide advanced warning of a windshear condition, there may not be enough time for the LAT crew to respond and avoid the encounter. In the 2012 US Air Force C‑130H accident, the birddog aircraft was about 1 NM (about 2 km) ahead when a warning was provided. This was insufficient for the C-130 crew to prevent a collision with terrain after experiencing low‑level windshear, despite conducting an emergency retardant jettison. It was also noted that LATs deployed as initial attack, such as in the case of the accident, will not have aerial supervision, or an aircraft providing a ‘show me’ run.

Airborne forward-looking, or predictive, windshear detection systems have been developed in response to commercial aviation accidents and have been shown to be around 95% effective (in simulator studies). It is acknowledged that the bushfire environment will be dry (low relative humidity) and the effectiveness of a forward-looking system may be reduced. However, the Lockheed Martin FireHerc aircraft, a civilian-certified aerial firefighting tanker is fitted with a windshear warning system. This would suggest these systems offer an enhanced level of safety for firefighting operations, in particular where operations are at low level in windshear prone environments, which would assist pilots in the early identification and/or potential avoidance of windshear, minimising any loss of aircraft performance. In addition, reactive systems are considered capable of confirming potentially hazardous windshear conditions in advance of human pilot recognition time. The activation of the warning on B137 at Adaminaby, and the crew’s subsequent response and adjustment of the drop location indicated a standard response to a windshear warning in aerial firefighting operations.

B134 and the operator’s other C-130 aircraft were not fitted with any windshear warning systems as these were not available at the time of manufacture and there was no regulatory or contract requirement to have them. The operator also indicated that they had not considered installing windshear detection systems into their C‑130 fleet when they were re‑purposed for firefighting activities.

Given the local weather conditions, the fact that B134 was very likely subjected to windshear, and the activation of the warning on B137 in similar environmental circumstances, it was possible that the crew of B134 would have also received a warning. If a warning had triggered, it was reasonable to expect that the crew would have responded. In addition, if this had occurred during the drop planning phase, it would have also assisted the crew in their hazard assessment and identification that the location was possibly unsuitable before committing to the drop run. If it had occurred during, or following the drop at Peak View, it would have provided immediate identification to all crew of the situation, assisting with timely recognition and response.

However, in the absence of an airborne system, windshear detection is reliant on the pilot’s assessment of the conditions based on the information available and their interpretation of that information. Without any known weather phenomena or reports from that location, detection is likely to be reactive, and dependent on the crew identifying a loss of aircraft performance. The recovery is subject to timely recognition and response, which could take 5 to 15 seconds and potentially result in further altitude loss. In this case, there was only 10-15 seconds and 330 ft between the degradation in climb performance and the impact.

Either a reactive or a predictive windshear detection system may have warned the crew of B134 of the actual or impending windshear and allowed for an earlier response. However, given the limited time and height available, it could not be determined if this would have been sufficient to have reduced the performance loss and prevent the accident. Despite this, research conducted on behalf of the FAA indicated that the risks associated with a windshear encounter would be reduced through a combination of pilot training and the use of on-board systems.

Initial attack certification

The NSW and ACT Aviation Standard Operating Procedures stated that aerial supervision was generally required for air tanker firefighting operations, except for those crew who were ‘initial attack certified’. While the RFS documentation did not define the requirements for this, their intention was to recognise the US Department of Agriculture, Forest Service (USFS) certification and for operators to ensure crews held this certification. However, without a definition, or any reference to the USFS certification in the procedures, this allowed individual operators to determine when pilots were initial attack capable, without necessarily having the official USFS certification. This was consistent with Coulson Aviation’s understanding, where they determined if a pilot was initial attack capable based on their internal training framework, rather than relying on the USFS certification. Despite this, this did not influence the development of the accident as the PIC of B134 held the initial attack certification from the USFS.

Standard operating procedures, among other risks controls, are fundamental for safe operations. They provide a common ground for users by ensuring consistency and predictability across all aspects of an operation. However, if procedures are not clearly defined, this results in a risk control not being applied as intended, lessening their effectiveness in managing safety. In this case, an individual operator may assess the capability of their pilots as satisfactory based on their own training, but it may not necessarily reflect the same requirements as that achieved through the USFS certification process.  

Lack of recorded data

While the aircraft was not required to be fitted with a cockpit voice recorder (CVR) under the Australian or US regulations, it was a contract requirement in the US.

As detailed in the AFM supplement, when power was applied to the CVR, the system conducted a self-test, and the status of that test was presented to the crew. However, the CVR did not record the accident flight as a result of the inertia switch activating on a previous flight about 8 months prior. Subsequently, the aircraft was operated on multiple flights by several crews in the intervening period with the CVR in an unserviceable condition. It was very likely that the inertia switch had not been reset during that time as the checklist being used in B134 did not include the requirement for the crew to check the status of the CVR. None of the operator’s C‑130 crew interviewed were aware of this requirement.

While this had no influence on the accident, the CVR being inoperable resulted in a valuable source of information not being available to the investigation. This increased the time taken to determine the contributing safety factors, and restricted the extent to which important safety issues could be identified and analysed. The benefits of flight recorders were further outlined in the ATSB publication Black box flight recorders, which highlighted recorders, such as the CVR, could be an invaluable tool to assist in identifying the factors behind an accident. The CVR captured more than crew communications, it also captured the audio environment in the cockpit, which could include radio transmissions, aural alarms, switch activations and engine noise.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the collision with terrain involving Lockheed EC-130Q, registered N134CG (call sign B134), that occurred near Peak View, New South Wales, on 23 January 2020.

Contributing factors

  • Hazardous weather conditions were forecast and present at the drop site near Peak View, which included strong gusting winds and mountain wave activity, producing turbulence. These conditions were likely exacerbated by the fire and local terrain.
  • The Rural Fire Service continued the B134 tasking to Adaminaby when they learned that no other aircraft would continue to operate due to the environmental conditions. In addition, they relied on the pilot in command to assess the appropriateness of the tasking to Adaminaby without providing them all the available information to make an informed decision on flight safety.
  • The pilot in command of B134 accepted the Adaminaby fire-ground tasking, which was in an area of forecast mountain wave activity and severe turbulence. After assessing the conditions as unsuitable, the crew accepted an alternate tasking to continue to the Good Good (Peak View) fire-ground, which was subject to the same weather conditions. The acceptance of these taskings were consistent with company practices.
  • Following the partial retardant drop and left turn, the aircraft was very likely subjected to hazardous environmental conditions including low-level windshear and an increased tailwind component, which degraded the aircraft’s climb performance.
  • While at a low height and airspeed, it was likely the aircraft aerodynamically stalled, leading to a collision with terrain.
  • Coulson Aviation's safety risk management processes did not adequately manage the risks associated with large air tanker operations. There were no operational risk assessments conducted or a risk register maintained. Further, as safety incident reports submitted were mainly related to maintenance issues, operational risks were less likely to be considered or monitored. Overall, this limited their ability to identify and implement mitigations to manage the risks associated with their aerial firefighting operations. (Safety issue)
  • Coulson Aviation did not provide a pre-flight risk assessment for their firefighting large air tanker crews. This would provide predefined criteria to ensure consistent and objective decision-making with accepting or rejecting tasks, including factors relating to crew, environment, aircraft and external pressures. (Safety issue)
  • The New South Wales Rural Fire Service had limited large air tanker policies and procedures for aerial supervision requirements and no procedures for deployment without aerial supervision. (Safety issue)
  • The New South Wales Rural Fire Service did not have a policy or procedures in place to manage task rejections, nor to communicate this information internally or to other pilots working in the same area of operation. (Safety issue)

Other factors that increased risk

  • The B134 crew were very likely not aware that the 'birddog' pilot had declined the tasking to Adaminaby fire-ground, and the smaller fire-control aircraft had ceased operations in the area, due to the hazardous environmental conditions
  • In the limited time available, the remainder of the fire-retardant load was not jettisoned prior to the aircraft stalling.
  • Coulson Aviation did not include a windshear recovery procedure or scenario in their C‑130 Airplane Flight Manual and annual simulator training respectively, to ensure that crews consistently and correctly responded to a windshear encounter with minimal delay. (Safety issue)
  • Coulson Aviation fleet of C-130 aircraft were not fitted with a windshear detection system, which increased the risk of a windshear encounter and/or delayed response to a windshear encounter during low level operations. (Safety issue)
  • The New South Wales Rural Fire Service procedures allowed operators to determine when pilots were initial attack capable. However, they intended for the pilot in command to be certified by the United States Department of Agriculture Forest Service certification process. (Safety issue)

Other findings

  • The aircraft's cockpit voice recorder did not record the accident flight, which resulted in a valuable source of safety information not being available. This limited the extent to which potential factors contributing to the accident could be identified.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action. 

Rural Fire Service task rejection management

Safety issue number: AO-2020-007-SI-01
Safety issue description: The New South Wales Rural Fire Service did not have a policy or procedures in place to manage task rejections, nor to communicate this information internally or to other pilots working in the same area of operation.Safety issue description: The New South Wales Rural Fire Service did not have a policy or procedures in place to manage task rejections, nor to communicate this information internally or to other pilots working in the same area of operation.

Rural Fire Service aerial supervision requirements

Safety issue number: AO-2020-007-SI-02
Safety issue description: The New South Wales Rural Fire Service had limited large air tanker policies and procedures for aerial supervision requirements and no procedures for deployment without aerial supervision.

Initial attack certification

Safety issue number: AO-2020-007-SI-07
Safety issue description: The New South Wales Rural Fire Service procedures allowed operators to determine when pilots were initial attack capable. However, they intended for the pilot in command to be certified by the United States Department of Agriculture Forest Service certification process.

Coulson Aviation’s risk management processes

Safety issue number: AO-2020-007-SI-05
Safety issue description: Coulson Aviation's safety risk management processes did not adequately manage the risks associated with large air tanker operations. There were no operational risk assessments conducted or a risk register maintained. Further, as safety incident reports submitted were mainly related to maintenance issues, operational risks were less likely to be considered or monitored. Overall, this limited their ability to identify and implement mitigations to manage the risks associated with their aerial firefighting operations.

Windshear procedures and training

Safety issue number: AO-2020-007-SI-06
Safety issue description: Coulson Aviation did not include a windshear recovery procedure or scenario in their C‑130 Airplane Flight Manual and annual simulator training respectively, to ensure that crews consistently and correctly responded to a windshear encounter with minimal delay.

Windshear warning systems

Safety issue number: AO-2020-007-SI-04
Safety issue description: Coulson Aviation fleet of C-130 aircraft were not fitted with a windshear detection system, which increased the risk of a windshear encounter and/or delayed response to a windshear encounter during low level operations.

Pre-flight risk assessment tool 

Safety issue number: AO-2020-007-SI-03
Safety issue description: Coulson Aviation did not provide a pre-flight risk assessment for their fire-fighting large air tanker crews. This would provide predefined criteria to ensure consistent and objective decision-making with accepting or rejecting tasks, including factors relating to crew, environment, aircraft and external pressures.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Additional safety action by Coulson Aviation

The ATSB has been advised of the following proactive safety action taken by Coulson Aviation in response to this accident:

  • The Retardant Aerial Delivery system (RADS) software was reprogrammed so that the system would not require re-arming between partial load drops where less than 100% volume was selected.
  • Updated their pre-flight procedures to incorporate a cockpit voice recorder system check in their abbreviated checklist before each flight.

Glossary

ABMAirbase manager, responsible for the supervision and coordination of airbase personnel and the layout and operation of an airbase.
ADS-BAutomatic dependent surveillance broadcast
AFMAirplane Flight Manual. The aircraft manufacturer, Lockheed Martin, produced a C-130 AFM for military operations. When introducing the aircraft to the civilian register, the FAA required the operator to produce an AFM, meeting the FAA requirements. The operator’s AFM was based on the US Navy flight manual, but incorporated procedures and limitations for the intended use of the aircraft.
AGLAbove ground level
AMSLAbove mean sea level
AROAviation radio operator
ATCAir traffic control
B134A Lockheed Martin C-130H aircraft, registered N134CG, a large air tanker with the callsign ‘Bomber 134’.
B137A Boeing 737 aircraft, registered N137CG, large air tanker with the callsign ‘Bomber 137’.
BirddogBirddog aircraft were used to lead large air tanker aircraft across the fire‑ground and provide guidance on the release of the water or fire suppressant (retardant or gel). The birddog crew consisted of a birddog pilot and a large air tanker air attack supervisor (LAT AAS).
CASCalibrated airspeed
CASACivil Aviation Safety Authority
COMCompany Operations Manual (Coulson Aviation). The COM was developed to contain the procedures, instructions and information required by CASA for the conduct of operations in Australia.
CVRCockpit voice recorder
ECGElectrocardiogram
FAAFederal Aviation Administration (US)
FCCA Fire Control Centre forms the administrative and operational base of the rural fire district or zone. The coordination and management of local brigade responses to fire and other incidents was undertaken through the Fire Control Centre.
FRATFlight risk assessment tool
GPSGlobal positioning system
IASIndicated airspeed
ICAOInternational Civil Aviation Organization
Incident controllerThe incident controller was responsible for all aspects of an emergency response, and managed the response, including the objectives, operations, and application of resources of the FCC.
Incident management teamThe coordination and management of local brigade responses to fire and other incidents was undertaken through the incident management team, led by the incident controller.
Incident AASIncident air attack supervisor
LATLarge air tanker. An aircraft with a minimum suppressant/retardant capacity of 3,000 US gallons (11,356 L).
LAT AASLarge air tanker air attack supervisor (onboard the birddog aircraft)
MAFFSModular airborne firefighting system
NAFCNational Aerial Firefighting Centre. Formed by the Australian States and Territories in 2003, NAFC provided a cooperative national arrangement for combating bushfires by facilitating the coordination and procurement of specialised firefighting aircraft.
NSWNew South Wales
OLMSOperational load monitoring system
PICPilot in command
RAAFRoyal Australian Air Force
RADSRetardant aerial delivery system XXL
RFSRural Fire Service (NSW)
SADState air desk. The state level multi agency team located in the State Operations Centre responsible for coordination of aircraft operations.
SMSSafety management system. A systematic approach to organisational safety encompassing safety policy and objectives, risk management, safety assurance, safety promotion, third party interfaces, internal investigation and SMS implementation.
SOCState operations controller roles was to maintain overall awareness of the firefighting effort across the state ensuring information and warnings are being distributed and resources are being allocated where needed. The SOC was located within the State Operations Centre.
State Operations CentreState Operations Centre was located at NSW RFS Headquarters in Lidcombe and allows the RFS and its partners to effectively oversee and coordinate incidents. The staff within the Centre monitor developments, analyse their potential and provide a variety of specialised resources to the incident management teams and firefighters on the ground.
TASTrue airspeed
USUnited States
USFSUS Department of Agriculture, Forest Service 

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Coulson Aviation
  • Coulson Aviation current and former personnel
  • other C-130 crews and maintenance staff
  • New South Wales Rural Fire Service
  • Lockheed Martin
  • a number of witnesses
  • Royal Australian Air Force
  • Defence Flight Safety Bureau
  • the Bureau of Meteorology
  • ATSB aviation medical specialist
  • Rolls Royce
  • Hamilton Sundstrand
  • National Aerial Firefighting Centre
  • CAL FIRE
  • Airservices Australia
  • United States Federal Aviation Administration
  • United States Department of Agriculture, Forest Service
  • Canadian Transportation Safety Board
  • next-of-kin
  • video footage of the accident flight
  • recorded data from automatic dependent surveillance broadcast (ADS-B), SkyTrac and historic data for the operational load monitoring system.

References

Australian Transport Safety Bureau (2009). Mountain wave turbulence. Retrieved from /publications/2005/mountain_wave_turbulence/

Australian Transport Safety Bureau (2020). A safety analysis of aerial firefighting occurrences in Australia (AR-2020-022). Retrieved from https://www.atsb.gov.au/media/5777923/ar-2020022_final.pdf

Australian Transport Safety Bureau (2004) Risks associated with aerial campaign management: Lesson from a case study of aerial locust control. Retrieved from /publications/2005/aerial_locust_control/

Australian Transport Safety Bureau (2015) Pilot incapacitation occurrences 2010-2014. Retrieved from /publications/2015/ar-2015-096/

Australian Transport Safety Bureau (2014) Black box flight recorders. Retrieved from /publications/2014/black-box-flight-recorders/

Bureau of Meteorology (2014) Hazardous weather phenomena – Wind shear. Retrieved from http://www.bom.gov.au/aviation/data/education/wind-shear.pdf

Bowles, R. L. (1990) Reducing Windshear Risk Through Airborne Systems Technology. Proceedings of 17th Congress of the International Council of the Aeronautical Sciences, pp 1603-1630.

Civil Aviation Safety Authority (2021) Aerial work risk management (advisory circular AC138-05 v1.1) Retrieved from https://www.casa.gov.au/aerial-work-risk-management

Civil Aviation Safety Authority (2014) SMS for aviation – a practical guide, Safety Risk Management Retrieved from https://www.casa.gov.au/search-centre/safety-kits/resource-kit-develop-your-safety-management-system

Federal Aviation Administration (2020) Safety management system, 8000.369C, FAA: Washington, DC..

Federal Aviation Administration (2016) Safety Flight Risk Assessment Tools.

Federal Aviation Administration (1997) Hazardous mountain winds and their visual indicators (advisory circular 00-57). FAA: Washington, DC.

Federal Aviation Administration (1988) Pilot Windshear Guide (advisory Circular 00-54). FAA: Washington, DC.

Federal Aviation Administration (2015) Helicopter Air Ambulance Operations (advisory circular 135-14B). FAA: Washington, DC.

Federal Aviation Administration (1987) Airworthiness Criteria for the Approval of Airborne Windshear Warning Systems in Transport Category (advisory circular 25-12). FAA: Washington, DC.

International Civil Aviation Organization (2015). Model advisory circular for air operator's: Standard Operating Procedures for Flight Deck Crewmembers, Montreal: ICAO.

International Civil Aviation Organization (2018) Safety Management Manual (4th ed). ICAO Doc 9859, Montreal.

Kepert, J, Tory, K, Thurston, W, Ching, S, Fawcett, R, Yeo, C (2016) Fire escalation by downslope winds. Retrieved from https://www.bnhcrc.com.au/hazardnotes/24

Minor, T (2000) Judgement versus windshear. The Mobility Forum: The Journal of the Air Mobility Command, 9, 27-33.

Mizell, G (2009) C-130 Discussion Items. Retrieved from http://www.baseops.net/wp-content/uploads/2015/08/C-130-Discussion-Items-2009Mar.pdf

Mosier, KL, Fischer, U, Cunningham, K, Munc, A, Reich, K, Tomko, L, and Orasanu, J (2012) Aviation decision making issues and outcomes: Evidence from ASRS and NTSB reports, Proceedings of the Human Factors and Ergonomics Society Annual Meeting, 56(1):1794-1798.

National Aerial Firefighting Centre, (2021), National Aerial Firefighting Strategy 2021–26. Retrieved from https://www.nafc.org.au/wp-content/uploads/2021/07/NAFF_Strategy_Webversion_2021-07-30_v1.1.pdf

National Transportation Safety Board (2014) Special Investigation Report on the Safety of Agricultural Aircraft Operations. Retrieved from https://www.ntsb.gov/safety/safety-studies/pages/sir1401.aspx

Commonwealth of Australia (2020) Royal Commission into National Natural Disaster Arrangements – Report. Retrieved from https://www.royalcommission.gov.au/system/files/2020-12/Royal%20Commission%20into%20National%20Natural%20Disaster%20Arrangements%20-%20Report%20%20%5Baccessible%5D.pdf

Tsukagoshi, H. (1999) Another look at windshear accidents. Proceedings of the International Society of Air Safety Investigators annual seminar, pp 67-86.

Underdown RB, Standon J, (2003) Meteorology (3rd Ed.). Blackwell Science, Oxford UK.

United States Forest Service (2016) National Aviation Safety Management System Guide. Retrieved from https://gacc.nifc.gov/swcc/dc/azpdc/operations/documents/aircraft/safety/SMS%20Guide_2016_508compliant.pdf

United States Forest Service (2006) Forest Service Manual – Aviation Management Handbook. Alaska Region. Retrieved from https://www.fs.fed.us/im/directives/field/r10/fsh/5709.16/5709.16_30.doc

US Air Force (2012) Aircraft accident investigation, C-130H3, T/N 93-1458, Edgemont, South Dakota, 1 July 2012. United States Air Force Aircraft Accident Investigation Board Report.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • Coulson Aviation
  • New South Wales Rural Fire Service
  • Coulson Aviation personnel
  • Lockheed Martin
  • Royal Australian Air Force Aircraft Research and Development Unit
  • the Bureau of Meteorology
  • ATSB aviation medical specialist
  • National Aerial Firefighting Centre
  • Civil Aviation Safety Authority
  • United States National Transportation Safety Board
  • the birddog pilot.

In addition, the draft report was sent to the NSW State Coroner for information.

Submissions were received from:

  • Coulson Aviation
  • New South Wales Rural Fire Service
  • Royal Australian Air Force Aircraft Research and Development Unit
  • the Bureau of Meteorology
  • Civil Aviation Safety Authority
  • the birddog pilot.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Interim report

Report release date: 24/09/2020

This interim report details factual information established in the investigation’s evidence collection phase and has been prepared to provide timely information to the industry and public. Interim reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this interim report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

Fire situation in the Snowy Mountains region

On 23 January 2020, the Snowy Mountains region in New South Wales (NSW) had a severe fire danger rating,[1] due to high temperatures, strong winds and forecast thunderstorms. This region included the Adaminaby and Good Good fire-grounds, which were both under the control of the Cooma Fire Control Centre (FCC).

At about 1100 Eastern Daylight-saving Time,[2] the Cooma FCC incident commander made a call to the NSW Rural Fire Service (RFS) State Operations Centre, to discuss the escalating fire danger at the Adaminaby fire-ground. During that call, it was noted that the smaller firefighting aircraft were not flying in the area due to strong winds and poor visibility. Consequently, a birddog[3] and two large air tankers (LAT) were tasked by the State Operations Centre to the Adaminaby fire-ground: a Rockwell International 690-B aircraft; a Boeing 737 aircraft, registered N137CG, call sign ‘Bomber 137’ (B137); and a Lockheed EC130Q[4] aircraft, registered N134CG, call sign ‘Bomber 134’ (B134). All three aircraft were based at Richmond Royal Australian Air Force (RAAF) Base, NSW, about 316 km north-east of the Adaminaby fire-ground.

‘B137’ tasking to Adaminaby

At about 1121, B137 had commenced taxiing at Richmond for a task when the crew were re‑tasked to the Adaminaby fire-ground. The aircraft subsequently departed at 1127, with the crew having been notified by the Richmond airbase manager[5] that there was no birddog in the area, and that it ‘is very windy down there’.

The birddog pilot had experienced moderate to severe turbulence in the Snowy Mountains region about 2 weeks prior to the day of the accident. On receipt of the tasking to Adaminaby, the birddog pilot reviewed the weather and concluded that the conditions were forecast to be worse than previously experienced, and therefore declined the task. In addition, as B137 was already en route to Adaminaby, the crew of that aircraft would be able to provide a report to the birddog pilot and other crews of the actual conditions.

At about 1155, B137 arrived overhead the Adaminaby fire-ground. At interview, the pilot in command (PIC) of B137 reported the wind speed at the Adaminaby fire-ground was 50 kt[6] at 800 ft above ground level (AGL), and about 37 kt at the retardant drop height of 200 ft AGL. While assessing the conditions in the Adaminaby area, the crew reported experiencing uncommanded aircraft rolls up to 45° angle of bank (due to wind) and a windshear[7] warning from the aircraft on‑board systems. The PIC of B137 elected to operate on the upwind side of the hills to avoid lee‑side mechanical turbulence.[8] At about 1225, B137 departed the Adaminaby fire‑ground, having successfully deployed a retardant load.

After completing the retardant drop, the B137 crew sent a text message to the birddog pilot assigned to the Adaminaby fire-ground indicating that the conditions were ‘horrible down there. Don’t send anybody and we’re not going back’. They also reported to the Cooma FCC that the conditions were unsuitable for firebombing operations. During B137’s return flight to Richmond, the Richmond air base manager requested that they reload the aircraft in Canberra and return to Adaminaby. The PIC replied that they would not be returning to Adaminaby due to the weather conditions.

‘B134’ tasking at Adaminaby

While B137 was still at the fire-ground, at about 1205, B134 departed Richmond with the PIC, co‑pilot and flight engineer on board.

At about 1235, the PIC of B137 had a conversation with the PIC of B134 on their designated operating frequency, to inform them of the actual conditions, and that they would not be returning to Adaminaby. At that time, B134 was about 112 km north-east of Adaminaby, en route to the Adaminaby fire-ground.

At about 1242, the crew of B134 contacted air traffic control (ATC), advising them of the co‑ordinates they would be working at, provided an ‘ops normal’[9] call time, and confirmed there was no reported instrument flight rules[10] traffic in the area. About 5 minutes later, the Richmond air base manager also attempted to contact B134 to confirm ‘ops normal’, firstly by radio, and then by text to the PIC’s mobile phone, but did not receive a response.

The automatic dependent surveillance broadcast (ADS-B) data showed that after arriving at the Adaminaby fire-ground (Figure 1), the crew of B134 completed several circuits at about 2,000 ft AGL.[11] At about 1255, the crew contacted the air operations officer at the Cooma FCC by radio and advised them that it was too smoky and windy to complete a retardant drop at that location. The Cooma air operations officer then provided the crew with the location details (co‑ordinates) of the Good Good fire, about 58 km to the east of Adaminaby, with the objective of conducting structure and property protection near Peak View.

Figure 1: Flight path overview (in white), including the times and locations of where the crew of B134 was in communication with others

Figure 1: Flight path overview (in white), including the times and locations of where the crew of B134 was in communication with others.&#13;Source: Google earth and ADS-B data, annotated by the ATSB

Source: Google earth and ADS-B data, annotated by the ATSB

‘B134’ tasking at the Good Good fire-ground

At 1259, the crew of B134 contacted ATC, to advise them that they had been re‑tasked to the Good Good fire-ground for a retardant drop and provided the updated co‑ordinates. At about the same time, the RFS ground firefighters at the Good Good fire-ground, near Feeney’s Road in Peak View, contacted the Cooma FCC and requested additional assets for property protection. They were advised that a LAT would be passing overhead in about 10 minutes. The firefighters acknowledged the intention of a LAT drop, and advised the Cooma FCC they would wait in open country on Feeney’s Road, clear of the properties targeted for protection.

At about 1307, B134 arrived overhead the drop area (Figure 2). From the aircraft’s recorded tracking data, the crew conducted three left circuits, at about 1,500 ft, 500 ft and 1,000 ft AGL respectively, prior to commencing the drop circuit.

At 1315:15,[12] the retardant drop was conducted on a heading of about 190° and at about 190 ft AGL (3,595 above mean sea level (AMSL)) with a drop time of about 2 seconds. During the drop, about 1,200 US gallons (4,500 L) of fire retardant was released. Witness video footage and images showed that at the commencement of the drop, the aircraft was at an approximate bank angle of 10°, with the flaps set at 100 per cent. A ground speed of 144 kt was recorded at the time of the drop.

Figure 2: B134’s approach and circuits overhead the drop location, and the position of the firefighters

Figure 2: B134’s approach and circuits overhead the drop location, and the position of the firefighters.&#13;Source: Google earth and Skytrac data, annotated by the ATSB

Source: Google earth and Skytrac data, annotated by the ATSB

The ATSB’s analysis of the witness videos found that, at the completion of the drop at 1315:17, the aircraft was observed to be banked about 17° to the left (Figure 3). About 4 seconds after the drop at 1315:21, the aircraft had a pitch-up attitude of about 12°, with an increase to about 30° angle of bank. Over the next 1.5 seconds, the aircraft’s angle of bank and pitch attitude reduced to about 22° and 10° respectively. The aircraft then became obscured by smoke.[13]

While being intermittently obscured by smoke, a positive rate of climb was achieved for about 10 seconds, with the aircraft climbing to about 330 ft AGL (3,770 ft AMSL) at 1315:27. Just prior to this, from about 1315:25, a right roll was observed on the video. The video captured the aircraft at about an 18° left angle of bank at 13:15:25, and then at about a 6° right angle of bank at 13:15:27. At the same time, the aircraft pitch attitude had decreased to about 6°. Following this, the aircraft was then observed descending. A further 7 seconds after this, at 1315:34, the aircraft was seen at a very low height above the ground, in a left bank. Throughout this period, the recorded groundspeed increased slightly to a maximum of 151 kt.

Shortly after, at about 1315:37, the aircraft collided with terrain and a post-impact fuel-fed fire ensued. The three crew were fatally injured and the aircraft destroyed.

A review of the Airservices Australia audio recording of the applicable air traffic control frequency found no distress calls were received by ATC prior to the impact.

Figure 3: Aircraft attitude and approximate flight path at key times

Figure 3: Aircraft attitude and approximate flight path at key times.&#13;Source: Google earth, witness videos and Skytrac data, annotated by the ATSB

Source: Google earth, witness videos and Skytrac data, annotated by the ATSB

Context

Operator

Coulson Aviation are a USA (US) based operator, with US registered aircraft and US licensed crew contracted to Australia for the 2019/2020 fire season through the National Aerial Firefighting Centre. At the time of the accident, Coulson Aviation had a fixed wing fleet in Australia consisting of two C130 aircraft, and one Boeing 737 aircraft. They also provided flight crews for the NSW RFS Boeing 737 which had previously been purchased from Coulson Aviation in 2019.

The RFS subsequently contracted one C130 and one 737 from Coulson Aviation via a service agreement subject to the National Aerial Firefighting Centre contract. Following the Australian fire season, the aircraft and crews then return to North America for heavy maintenance and recurrent training prior to the US fire season.

Crew information

Pilot in command

Qualifications and experience

The PIC was initially trained as a navigator and pilot in the United States Air National Guard. During this time, the PIC gained experience in firefighting operations through the modular airborne firefighting system (MAFFS)[14] program. The PIC subsequently joined the operator in 2015 on a part-time basis, before being employed full-time in 2017.

The PIC’s logbook, combined with the operator’s records for the accident aircraft showed that the pilot had a total flying experience of about 4,010 hours, which included 3,010.3 hours in the C130 aircraft, and 994 air tanker drops. The PIC had also accrued a further 1,616.8 hours as a flight navigator.

The PIC held a current airline transport pilot certificate with ratings for multi-engine land aircraft including the EC130Q, issued by the US Federal Aviation Administration (FAA) on 13 October 2017. The PIC’s most recent flight instructor certificate with ratings for multi-engine and instrument aircraft was issued by the FAA on 6 April 2019. On 18 April 2019, the PIC’s latest airplane pilot qualification card was issued from the US Department of Agriculture, Forest Service,[15] for the C130 aircraft, which included the authorised missions of: Low level (below 500 ft above ground level); Mountainous terrain; and Airtanker Initial Attack. An air tanker initial attack qualification allows a pilot to conduct fire retardant drops without the supervision of a birddog or air tactical supervisor.

The PIC’s most recent first-class medical examination was on 5 September 2019, with the certificate issued with a limitation to wear corrective lenses.

Training

The PIC’s training with the operator in March and April 2019[16] included annual C130 simulator training, controlled flight into terrain awareness, and crew resource management. In addition, the PIC completed two assessed training flights with the operator in the C130 on 14‑15 April 2019. The training flight on 14 April included approach to stalls in the circuit (50 per cent flap) and drop (100 per cent flap) configurations, and go-arounds with a full load. The flight on 15 April included drop planning (hazards, tactics, ingress, egress and dry run) and an emergency on the drop run. The drop run emergency was a simulated ‘down air’ [downdraught] with the comment ‘Jettison for down air’. All the assessed sequences, which included jettison of the load during an emergency condition,[17] were recorded as satisfactory.

Co-pilot

The co-pilot had joined the operator in September 2019, after 20 years in the military, including experience flying the C130. This was the co-pilot’s first fire season. The co-pilot’s logbook combined with the operator’s records showed a total flying experience of about 1,744 hours, of which about 1,364 were on the C130. The co-pilot held a current airline transport pilot certificate and ratings for multi-engine land aircraft, including the EC130Q (second-in-command privileges only), issued by the FAA on 7 November 2019. The co-pilot also held a flight instructor certificate with ratings for single, multi-engine and instrument aircraft, issued by the FAA on 14 August 2019. The co-pilot’s most recent first-class medical examination was issued on 17 July 2019 with no limitations.

The co-pilot’s check flight with the operator was completed on the C130 on 12 September 2019, and was assessed as satisfactory against the qualification standards for second-in-command. On 13 September 2019, the co-pilot completed the operator’s crew resource management and controlled flight into terrain awareness courses, and reviewed the US Department of Agriculture Forest Service’s air tanker pilot training video.

On 16 September 2019, the co-pilot was issued with an airplane pilot qualification card from the US Department of Agriculture Forest Service for the C130 aircraft, which included the authorised missions of: Low level (below 500 ft above ground level); Mountainous terrain; and Airtanker SIC (second-in-command).

Flight engineer

The flight engineer joined the operator in November 2019, after about 25 years in the US military. This was the flight engineer’s first fire season. The flight engineer held a flight engineer certificate with a rating for turbo-propeller powered aircraft, issued by the FAA on 20 November 2019. On the flight engineer application form, the flight engineer reported accruing 4,050 hours on the C130 aircraft. The flight engineer also held a mechanic certificate with ratings for airframe and powerplant, issued by the FAA on 2 June 2019. The flight engineer’s most recent second-class medical examination was issued on 27 August 2019 with no limitations.

The flight engineer’s check flight was completed with the operator on 20 November 2019. In addition to this check flight, the FE completed two air tanker drops with a supervising flight engineer in Australia on 12 January 2020.

72 hour prior history

The PIC and co-pilot commenced work in Australia on 1 December 2019 and the flight engineer on 13 January 2020. Each crew member’s roster cycle was 14 duty days followed by two rest days. The operator’s records show they signed on between 0800 and 1000, and signed off between 1700 and 2100, with their duty times varied between 7.5 and 12 hours per day.

The accident flight occurred on the PIC’s 9th day, and the co-pilot’s and flight engineer’s 11th day of their respective current duty periods.

Table 1, based on the operator’s records, details the crew’s sign on and sign off times for the 3 days before the accident. On 23 January 2020, the crew signed on at 0900.

Table 1: B134 crew working hours

 20 January21 January22 January
Sign on100008001000
Sign off180017001900

 

Information from the crew’s telephones and hotel records, in addition to work and flying duties, were used to determine their activities in the previous days. There were no indications of fatigue for the three crew members. However, there was insufficient information available to the ATSB about their sleep and non-duty activities to estimate fatigue levels with confidence.

Aircraft information

General information

The C130 is predominantly an all-metal, high-wing aircraft, designed for military operations. The accident aircraft (Figure 4) was manufactured in 1981 and was powered by four Allison T56-A-15 turboprop engines, fitted with Hamilton Sundstrand 54-H60-91 four blade propellers. The T56‑A‑15 is a constant speed engine, with a variable pitch propeller.

Previously owned by the US Navy, the aircraft was transferred to the US National Aeronautics and Space Agency (NASA) in 1992 and later placed in storage. It was removed from storage, re‑purposed for firefighting activities by the operator and registered in the restricted category.[18] Initially registered as N130CG in 2018, its registration was later changed to N134CG in April 2019. The modifications included the installation of an avionics package and firefighting tank system, known as the Retardant Aerial Delivery System XXL (RADS).

Figure 4: N134CG

Figure 4: N134CG.&#13;Source: Coulson Aviation

Source: Coulson Aviation

Maintenance history

The aircraft had a total time-in-service of 11,888 hours and had accrued 683 hours of firefighting operations since the tanker conversion in 2018.

N134CG arrived in Australia in November 2019. The aircraft had a current certificate of airworthiness, and was maintained in accordance with an FAA approved program. The last daily inspection conducted on 22 January 2020, at the end of the day’s flying activities the day before the accident, identified the propeller anti-icing system on engine number 2 was unserviceable, and rectification had been deferred in accordance with the minimum equipment list.[19]

In addition to a maintenance requirement to perform engine power efficiency checks at 150-hour intervals, the operator reported pilots were required to perform power checks before every take off, with operations only permitted if a minimum performance requirement of 95 per cent was met.

Retardant Aerial Delivery System XXL

The Retardant Aerial Delivery system (RADS) included a 4,000 US gallon (15,000 L) tank system located within the aircraft’s fuselage. The system could deliver discrete quantities of retardant, dependant on the duration that the doors remained open. It was controlled from the cockpit, with drop controls located on both the PIC and co-pilot yokes.

The drop quantity could be controlled either as a pre-set percentage by the crew, or alternatively, if selected at 100 per cent, the crew could control the amount of retardant released by holding the button until the desired amount was dispensed. The RADS system was designed that, if less than 100 per cent volume was selected, the system would disarm after a partial load drop, and the crew would need to re-arm the system to complete further releases. It was reported that the crew on B134 normally selected 100 per cent volume and released the drop button once the desired amount had been dispensed.

The system also included a guarded emergency dump switch, located in reach of all three crew members, which would fully open the doors and jettison the load in a period of about 2 seconds. Following an emergency dump, the doors would remain open until the RADS was reset by the crew.

Weight and balance

The last weight and balance report for the aircraft, in April 2019, showed its basic empty weight was 75,794 lb (35,380 kg) and according to the RADS flight manual supplement, the maximum take-off weight was 150,718 lb (68,365 kg). The aircraft flight and maintenance log entry for 22 January 2020 indicated the PIC had the aircraft refuelled to a total of 34,000 lb (15,422 kg) at the completion of flying the previous day. The operational load monitoring system[20] indicated there was 35,514 lb (16,109 kg) of retardant on board prior to the drop, in addition to which the aircraft carried a 2,000 lb (907 kg) pallet of gel. This resulted in a take-off weight of about 147,253 lb (66,826 kg) and centre of gravity at the aft limit.

Using the operator’s reported fuel consumption for air tanker drop missions of 5,000 lb/h (2,268 kg/h) for a 70 minute flight, and the retardant drop of 10,764 lb (4,882 kg), the estimated post-drop weight was 130,656 lb (59,265 kg). The centre of gravity remained close to the aft limit, which was consistent with the reports from the operator’s other crews that the location of the RADS tank in the aircraft meant there was no appreciable change in the centre of gravity following a retardant drop.

Meteorological information

Bureau of Meteorology forecasts

A Bureau of Meteorology graphical area forecast was issued at 0924 and was valid for the time of the flight. It forecast moderate mountain wave activity[21] above 3,000 ft AMSL and severe turbulence below 8,000 ft AMSL in the area of operation from Richmond to Cooma. This included the Adaminaby and Good Good fire-grounds. In addition, a SIGMET[22] issued at 0947, and valid for the flight, forecast severe turbulence[23] below 10,000 ft AMSL for the area.

The aerodrome forecast for the Cooma-Snowy Mountains Airport,[24] located 50 km south-west of the accident site was amended at 0948. It indicated wind speeds of 25 kt, gusting to 48 kt, with a mean wind direction of 300° from 1100 and visibility reduced to 8,000 m in light showers. Severe turbulence below 5,000 ft AGL was forecast from 0900-1500, and a PROB30[25] for visibility reduced to 2,000 m in blowing dust and a broken[26] layer of cloud at 1,000 ft AGL was forecast for the period 1100–1700.

At 1012, the Richmond air base manager sent a text message to the air tanker and birddog pilots to advise them of an airport warning for wind gusts in excess of 35 kt between 1000 and 1700 at the Richmond base.

Observations of the weather in the area

Other fire control aircraft

On the day of the accident, several fire-control aircraft, primarily consisting of fixed-wing Air Tractors and Bell 206 helicopters, were operating from the Polo Flat airstrip, located 33 km south-west of the accident site. The Cooma FCC received reports of strong winds in the area from the fire-control pilots in the early morning. This included winds of 30-40 kt at 0839, 40-50 kt at 0902, and 52 kt at 0937. All fire-control aircraft had departed the area or landed by 1030.

Additionally, the flight crew of B137 reported that the wind conditions at Adaminaby at about 1200 were 50 kt at 800 ft AGL, and about 37 kt at 200 ft AGL.

Witness reports

Following the accident, the ATSB received multiple witness reports of the weather conditions at Peak View. They all consistently reported very strong winds from the north-west, with gusts up to 43 kt recorded at ground level. One resident noted that, although the prevailing wind was from the north-west, the direction and strength at ground level were also being influenced by the local terrain.

Weather station recorded conditions

About 12 minutes prior to the accident, the Cooma-Snowy Mountains Airport weather station indicated a wind speed of 25 kt, gusting to 39 kt, from a direction of 320°. The visibility was 6,000 m, with a QNH[27] of 1002 hPa and temperature of 26 °C.

A personal weather station at Peak View, located about 1.3 km from both the drop and accident sites (Figure 5) recorded the conditions twice per hour. At about 1309 (7 minutes prior to the accident), the station recorded a mean wind of 15 kt from the west and a peak gust of 32 kt from the north.[28] At about 1330 (14 minutes after the accident), the station recorded a mean wind of 16 kt from the west and a peak gust of 42 kt from the north-west.

Figure 5: Accident circuit with predominant wind direction and terrain

Figure 5: Accident circuit with predominant wind direction and terrain.&#13;Source: Google earth and SkyTrac data, annotated by the ATSB

Source: Google earth and SkyTrac data, annotated by the ATSB

Bureau of Meteorology analysis

The Bureau of Meteorology analysed the conditions on the day and indicated that a cold front was approaching the accident location, with hot and strong north to north-westerly winds ahead of the front. High resolution weather model data indicated the winds at 5,000 ft AMSL were about 45 kt from the north-west, increasing in strength with height up to 80 kt from the north-west at 10,000 ft AMSL. They reported that their analysis of the weather conditions in the accident area was consistent with what was forecast on the day.

The Bureau of Meteorology considered the conditions on the day were favourable for mountain wave development, and satellite imagery of cloud formations confirmed their presence in the general area of the accident. However, they were unable to determine the severity of the mountain wave activity from the data available.

Recorded information

Cockpit voice recorder

Cockpit voice recorders (CVR) are designed on an endless loop principle, where the oldest audio is continuously overwritten by the most recent audio. The CVR fitted to the aircraft was a Universal Avionics Model CVR-30B, part number 1603-02-03 (Figure 6). This solid-state memory CVR recorded crew and cockpit audio for a recording duration of at least 30 minutes. While the aircraft was not required to be fitted with a CVR under US or Australian regulations, it was required under contract requirements in the US.

Figure 6: N134CG cockpit voice recorder

Figure 6: N134CG cockpit voice recorder.&#13;Source: ATSB

Source: ATSB

The CVR was recovered from the aircraft and transported to the ATSB’s technical facility in Canberra, Australian Capital Territory, on 25 January 2020 for examination and download. The CVR was successfully downloaded, and the recording downloaded contained 31 minutes of audio. However, the audio was from a previous flight when the aircraft was operating in the US. No audio from the accident flight was recorded on the CVR.

Inertia switch

The power supply for the CVR was fitted with an inertia switch. Inertia switches are designed to stop the recording function by removing power to the CVR when a pre-set deceleration force is detected. The recovered audio was of crew training flights undertaken on 7 May 2019 near Sacramento McClellan Airport, California. The audio included four landings conducted as part of the training in the aircraft on that day. The recording ceased immediately after the fourth landing, and the post-landing taxi and engine shutdowns were not recorded. It was likely that the inertia switch was activated during this landing and consequently disconnected power to the CVR.

Pre-flight testing

Following a CVR installation in an aircraft, supplemental material related to the operation of the CVR must be attached to the approved airplane flight manual. The supplement for the aircraft indicated the CVR conducted a self-test at power up, and the status of the CVR would be presented to the crew on the CVR control unit, located on the co-pilot side console. A CVR system check was not included in any of the operator’s checklists, and none of the operator’s flight crew were aware of the need to check this system status prior to flight.

Flight data

The aircraft was not fitted with a flight data recorder, nor was it required to be by Australian or US regulations. However, contracting requirements in the US required the aircraft be fitted with an operational load monitoring system, which was located behind the centre wing section in the fuselage. This recording device had no impact or fire protection and was destroyed in the accident sequence.

The aircraft was also fitted with SkyTrac, a tracking system that can transmit the aircraft’s position in real-time. This system was able to be monitored by the NSW RFS, and generally had an update rate of about 1 minute. The SkyTrac unit was recovered from the wreckage and transported to the ATSB’s technical facility for examination and download. The SkyTrac unit recorded data at 5 second intervals.

Data broadcast by the ADS-B equipment fitted to the aircraft for ATC purposes was also obtained from various providers. ADS-B data is transmitted nominally every 0.5 seconds; not all transmission were available, with gaps of up to 5 seconds during the accident flight. Table 2 shows the parameters recorded by SkyTrac and ADS-B.

Table 2: SkyTrac and ADS-B recorded parameters

SkyTracADS-B
timetime
latitude and longitudelatitude and longitude
groundspeed (GPS)groundspeed
altitude (GPS)pressure altitude
track (GPS course)track
 vertical rate of climb/descent

A detailed review of the available recorded data is ongoing and will be included in the ATSB’s final investigation report.

Witness video

Two firefighters were located on Feeney’s Road (800 m from the accident site), and videoed the aircraft during the retardant drop and subsequent accident. Overall, the video footage had a duration of 37 seconds. It captured the aircraft from 10 seconds prior to the drop, the drop, and 4 seconds after the drop, when the aircraft became obscured by smoke, and was only intermittently visible. Eleven seconds after being obscured by the smoke, the aircraft was seen at low level, followed by a collision with terrain and post-impact fire. The ATSB’s analysis of this footage is continuing and will be included in the final investigation report.

Wreckage and impact information

Accident site

The accident site was located on slightly sloping, partially wooded terrain, near Peak View, 50 km north-east of Cooma-Snowy Mountains Airport. The wreckage trail (Figure 7) was approximately on a heading of 100°, with the initial impact at an elevation of about 3,440 ft AMSL. The debris trail began at the lower end of the slope, with the wreckage distributed linearly over about 180 m.

Figure 7: Accident site overview showing the wreckage trail

Figure 7: Accident site overview showing the wreckage trail.&#13;Source: ATSB

Source: ATSB

Wreckage examination

The ATSB’s on-site examination of the wreckage, damage to the surrounding vegetation, and ground markings, indicated that the aircraft initially impacted a tree in a left wing down attitude, of about 55°, before colliding with the ground. An intense post-impact fuel-fed fire destroyed the aircraft. The ATSB’s on-site examination (Figure 8) also found:

  • no pre-existing airframe issues
  • all major sections of the aircraft’s structure were identified and there was no evidence of an in‑flight break-up or pre-impact structural damage[29]
  • the cockpit and associated avionics were identified about two-thirds of the way along the wreckage trail
  • the cockpit and forward section of the airframe had separated from the fuselage, was inverted, and had been destroyed in the impact and subsequent fire
  • sections of the wing skin, leading edge spar, wing tips and portions of the wings were identified along the wreckage trail, having fragmented during the impact sequence, and sustained further damage during the resultant fire
  • all flight control surfaces were identified, however, due to the impact and fire, flight control continuity could not be established
  • the four engines and 16 propeller blades were located on-site and some of the propeller blades remained attached to the propeller hubs, while others had detached through impact forces
  • there were varying degrees of damage observed across the four engines, likely due to the impact sequence of each engine, with the damage indicating the engines were rotating at impact.

The RADS tank remained upright (Figure 8), along with the aft section of the fuselage, with the vertical and horizontal stabilisers attached. There was no retardant identified between the drop area and the initial impact location, however, a large amount of retardant was located in the wreckage near the tank. The system was badly damaged, with the doors fragmented throughout the wreckage, and its operational state could not be established.

Figure 8: Main aircraft wreckage components

Figure 8: Main aircraft wreckage components.&#13;Source: ATSB

Source: ATSB

Aircraft configuration

The aircraft was equipped with four trailing edge flaps. All flaps had separated from the aircraft during the impact sequence. On-site measurements of the flap screw jacks indicated the flaps were set at 50 per cent at impact. This was consistent with the expected setting following a retardant drop. Due to the extent of damage, the elevator, aileron and rudder trim settings could not be established.

Fuel testing

Fuel samples were retained from the two fuel tankers that last serviced the aircraft and from the refuelling storage tank at Richmond. The fuel samples were independently tested by a commercial fuel company for correct specifications, with nil abnormal indications found. In addition, there were no reports of fuel quality concerns with any other aircraft using the same fuel source.

Engine and propeller examinations

With the assistance of the Australian Army, the engines, partial remnants of the reduction gearboxes, propeller assemblies and blades were transported to a secure hangar at Richmond RAAF Base for further examination.

The engine manufacturer attended the engine inspections, where it was confirmed that all engines were rotating at impact, and there were no noted pre-existing issues. As power changes are controlled by changes to the propeller blade pitch while maintaining a constant engine speed, the engine power levels were determined from the blade pitch angle at impact.

During the propeller hub assembly inspection, measurements of the internal components were recorded. The ATSB consulted the propeller manufacturer to determine the propeller blade angles at impact and establish engine power levels. The propeller manufacturer concluded the following:

The calculations indicate that, based on the operating conditions estimated by the ATSB, all the propellers were absorbing power from their respective engines and were producing positive thrust. The horsepower computed for each of the four engines are within the normal operating range for the T56 engine installed on this aircraft.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk.

The ATSB has been advised of the following proactive safety action taken by Coulson Aviation in response to this accident:

  • The Retardant Aerial Delivery system (RADS) software was reprogrammed so that the system will not require re-arming between partial load drops where less than 100 per cent volume is selected.
  • Updated their pre-flight procedures to incorporate a cockpit voice recorder system check before each flight.

Ongoing investigation

To-date, the ATSB has interviewed Coulson Aviation pilots and key personnel, NSW RFS personnel involved in the large air tanker and aviation operations, witnesses, C130 and other aerial firefighting pilots, and key personnel in overseas aerial firefighting operations. In addition, the ATSB has conducted a detailed examination of the aircraft, engines and propellers; reviewed recorded RFS radio calls; and engaged C130 subject matter experts.

The investigation is continuing and will include consideration of the following:

  • ongoing analysis of recorded data, including the on-board systems and witness videos
  • aircraft performance and handling characteristics
  • review and analysis of environmental influences
  • operating policies and procedures
  • aircraft maintenance history
  • cockpit instruments examination
  • crew health and medical history
  • similar occurrences.

Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.

A final report will be released at the conclusion of the investigation.

This interim report details factual information established in the investigation’s evidence collection phase and has been prepared to provide timely information to the industry and public. Interim reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this interim report is released in accordance with section 26 of the Transport Safety Investigation Act 2003.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. The NSW Rural Fire Service fire danger ratings provide an indication of the possible consequences of a fire and are based on predicted conditions including but not limited to temperature, humidity, wind and the dryness of the landscape.
  2. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  3. Birddog aircraft are used to lead air tankers and provide guidance on the release of the fire retardant. The RFS procedures stipulated that an air tanker with an initial attack certified crew (refer to section titled Pilot in command) were able to conduct operations without a birddog.
  4. The aircraft was initially built as an EC130Q, however, all specialised military equipment had been removed, and it was considered to be the equivalent of a C130H. Throughout the report, the aircraft is referred to as a C130.
  5. The airbase manager is responsible for the supervision and co-ordination of airbase personnel, and the layout and operation of an airbase
  6. 1 kt equals 1.852 km/h.
  7. Windshear is defined as a wind direction and/or speed change over a vertical or horizontal distance.
  8. Mechanical turbulence results from airflow over or around irregular terrain or man-made objects.
  9. ‘Ops normal’ call time provides the next expected transmission time from this aircraft to indicate operations are normal.
  10. Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR). Procedures and training are significantly more complex as a pilot must demonstrate competency in IMC conditions while controlling the aircraft solely by reference to instruments. IFR-capable aircraft have greater equipment and maintenance requirements.
  11. When conducting initial attack operations, crews complete several circuits to assess hazards and drop conditions.
  12. All times in the report are referenced to the ADS-B data, with adjustments based on the recorded locations.
  13. From the witness video, it was unclear if the aircraft flew behind the smoke or entered the smoke.
  14. MAFFS are portable fire retardant delivery systems that can be inserted in C130 aircraft without major structural modifications to convert them to air tankers when needed.
  15. When operating in the US as an air tanker, the aircraft is considered a public use asset, and the US Department of Agriculture Forest Service assumes the regulatory role, and defines and issues initial attack qualifications.
  16. This was the operator’s spring training period in preparation for the North American fire season.
  17. Although the emergency condition for the jettison was a simulated scenario, the pilot was still required to perform a live jettison of the load (water) in this training sequence.
  18. Restricted category in this instance refers to a type that has been manufactured in accordance with the requirements of, and accepted for use by, an Armed Force of the US and has been later modified for a special purpose.
  19. A minimum equipment list is a list that identifies items, subject to specific conditions, which may be unserviceable at the commencement of a flight, and is approved by the FAA.
  20. The operational load monitoring system transmitted various parameters in-flight, including the status of the RADS tank at the start and completion of the drop.
  21. Mountain waves form above and downwind of topographic barriers when strong winds blow with a significant vector component perpendicular to the barrier in a stable environment. If air is being forced over terrain, it will move downward along the lee slopes, then oscillate in a series of waves as it moves downstream, sometimes propagating long distances downwind.
  22. Significant meteorological information (SIGMET): a weather advisory service that provides the location, extent, expected movement and change in intensity of potentially hazardous (significant) or extreme meteorological conditions that are dangerous to most aircraft, such as thunderstorms or severe turbulence.
  23. Severe turbulence can result in large abrupt changes to an aircraft’s attitude and/or altitude, and potentially a momentary loss of control.
  24. The Cooma-Snowy Mountains Airport has an elevation of 3,106 ft AMSL.
  25. PROB30 means 30 per cent chance of forecast conditions occurring.
  26. Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – broken indicates that more than half to almost all the sky is covered.
  27. QNH: the altimeter barometric pressure subscale setting used to indicate the height above mean sea level.
  28. This is the average and peak speed recorded for the previous 10 minutes.
  29. In July 2018, the aircraft manufacturer published service bulletin 382-57-97 to address accelerated structural fatigue for C130 aircraft performing air tanker operations.

Preliminary report

Report release date: 28/02/2020

This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

Sequence of events

On 23 January 2020, at about 1205 Eastern Daylight-saving Time,[1] a Lockheed EC130Q (C‑130) aircraft, registered N134CG and contracted to the New South Wales (NSW) Rural Fire Service, departed Richmond RAAF Base, NSW. The crew had been tasked with a fire retardant drop over the ‘Adaminaby Complex’ bush fire.

After approaching the Adaminaby complex fire, the drop was unable to be completed and the aircraft was diverted to a secondary tasking, to drop retardant on the ‘Good Good’ fire (Figure 1). Witnesses reported seeing the aircraft complete a number of circuits, prior to completing the retardant drop. The drop was conducted on a heading of about 190°, at about 200 ft above ground level, with a drop time of approximately 2 seconds. The crew released about 1,200 US gallons (4,500 L) of fire retardant during the drop.

Figure 1: Flight path of N134CG (white)

Figure 1: Flight path of N134CG (white). Source: Google Earth, Aireon and RFS tracking data, annotated by the ATSB

Source: Google Earth, Aireon and RFS tracking data, annotated by the ATSB

Witness videos taken of the aircraft leading up to the accident showed a number of passes conducted at varying heights prior to the retardant drop. Following the retardant drop (Figure 2), the aircraft was observed to bank left, before becoming obscured by smoke[2] after about 5 seconds. A further 15 seconds after this, the aircraft was seen flying at a very low height above the ground, in a left wing down attitude. Shortly after, at about 1316, the aircraft collided with terrain and a post-impact fuel-fed fire ensued. The three crew were fatally injured and the aircraft was destroyed.

Figure 2: Overview of the drop zone (red fire retardant) and accident location

Figure 2: Overview of the drop zone (red fire retardant) and accident location.&#13;Source: ATSB

Source: ATSB

A review of the Airservices Australia audio recording of the applicable air traffic control frequency found no distress calls were made by the crew prior to the impact.

Wreckage and impact information

The accident site was located on slightly sloping, partially wooded terrain, about 50 km north-east of the Cooma-Snowy Mountains Airport. The wreckage trail (Figure 3) was approximately on a heading of 100°, with the initial impact at an elevation of about 3,440 ft above mean sea level.

The ATSB’s on-site examination of the wreckage, damage to the surrounding vegetation, and ground markings indicated that the aircraft initially impacted a tree in a left wing down attitude, before colliding with the ground. The post-impact fuel-fed fire destroyed the aircraft. The examination also found that an emergency dump of the fire retardant had not been activated.

The engines, propellers, and several other components have been retained by the ATSB for further examination.

Figure 3: Aircraft impact and wreckage

Figure 3: Aircraft impact and wreckage.&#13;Source: ATSB

Source: ATSB

Aircraft information

The Lockheed C-130 is predominantly an all-metal, high-wing aircraft, largely designed for military operations. The aircraft was manufactured in 1981 and was powered by four Allison T56-A-15 turboprop engines, fitted with Hamilton Sundstrand 54-H60-91 four blade propellers. Previously owned by the United States Navy, the aircraft was re-purposed for firefighting activities and registered as N134CG in 2018 (Figure 4). The modifications included the installation of an avionics package and firefighting tank system known as Retardant Aerial Delivery System XXL (RADS).

The RADS included a 4,000 US gallons (15,000 L) tank system located within the aircraft’s fuselage. The system was capable of delivering discrete quantities of retardant, dependent on the duration that the doors remained open. It was controlled from the cockpit, with drop controls located on both the pilot and copilot yokes. The system also included an emergency dump switch, which, when activated, fully opened the doors and jettisoned the load. The doors remained open until the RADS was reset by the crew.

N134CG arrived in Australia in November 2019, but had previously operated in the country during the 2018‑2019 fire season. The aircraft was designated as a ‘large air tanker’.

Figure 4: N134CG

Figure 4: N134CG. Source: Coulson Aviation

Source: Coulson Aviation

Meteorological information

A Bureau of Meteorology graphical area forecast, issued at 0924 and valid for the time of the flight, forecast moderate mountain wave activity above 3,000 ft (above mean sea level) in the area of operation from Richmond to Cooma, and included the Adaminaby and Good Good fire grounds. A SIGMET[3] issued at 0947 forecast severe turbulence below 10,000 ft.

The aerodrome forecast for the Cooma-Snowy Mountains Airport[4] was amended at 0948, and indicated wind speeds of 30 kt, gusting to 48 kt, with a mean wind direction of 320°. It also included blowing dust and visibility of 2,000 m, with severe turbulence below 5,000 ft above ground level.

The weather observations recorded at the airport about 11 minutes prior to the accident, indicated a wind speed of 25 kt, gusting to 39 kt, from a direction of 320°, with visibility reduced to 6,000 m.

Cockpit voice recorder

Cockpit voice recorders (CVR) are designed on an endless loop principle, where the oldest audio is continuously overwritten by the most recent audio. The CVR fitted to the aircraft was a Universal model CVR-30B, part number 1603-02-03, serial number 1541. This model of recorder used solid-state memory to record cockpit audio and had a recording duration of 30 minutes.

The CVR was recovered from the aircraft and transported to the ATSB’s technical facility in Canberra, Australian Capital Territory, on 25 January 2020 for examination and download. The CVR was successfully downloaded, however, no audio from the accident flight had been recorded. All recovered audio was from a previous flight when the aircraft was operating in the United States.

Further investigation

The investigation is continuing and will include consideration of the following:

  • engine, gearbox and propeller component examinations
  • aircraft maintenance history
  • aircraft performance and handling characteristics
  • impact sequence
  • analysis of numerous witness reports
  • review and analysis of the available recorded data, including witness videos, aircraft tracking data, audio recordings and any onboard systems
  • review and analysis of environmental influences
  • the crew's qualifications, experience and medical information
  • the nature of aerial fire-fighting operations
  • operating policies and procedures
  • exploring the possible reasons why the CVR did not record the accident flight
  • similar occurrences.

The ATSB will continue to consult with the engine and airframe type certificate holders. Accredited representatives from the United States National Transportation Safety Board (NTSB) have been appointed to participate in the investigation.

Acknowledgments

The ATSB acknowledges the support of the NSW Police Force, NSW Rural Fire Service, NSW Fire and Rescue, the Australian Defence Force, and those involved with facilitating safe access to an active fire ground and supporting the ATSB’s on-site investigation team.

_________

The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this preliminary report. As such, no analysis or findings are included.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

_________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. From the video, it was unclear if the aircraft flew behind the smoke or entered the smoke.
  3. Significant meteorological information (SIGMET): a weather advisory service that provides the location, extent, expected movement and change in intensity of potentially hazardous (significant) or extreme meteorological conditions that are dangerous to most aircraft, such as thunderstorms or severe turbulence.
  4. The Cooma-Snowy Mountains Airport has an elevation of 3,106 ft.

Occurrence summary

Investigation number AO-2020-007
Occurrence date 23/01/2020
Location 50 km north-east of Cooma-Snowy Mountains Airport, near Peak View
State New South Wales
Report release date 29/08/2022
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer Lockheed Aircraft Corp
Model EC130Q
Registration N134CG
Serial number 382-4904
Aircraft operator Coulson Aviation (Australia) PTY LTD
Sector Turboprop
Departure point Richmond Royal Australian Air Force Base, New South Wales
Destination Richmond Royal Australian Air Force Base, New South Wales
Damage Destroyed

Collision with water involving Cessna 182, VH-WNR, 6 km north-west of Moreton Island, Queensland, on 22 January 2020

Final report

Report release date: 10/02/2022

Safety summary

What happened

On 22 January 2020, a Cessna 182Q, registered VH-WNR, took off from Caloundra Aerodrome, Queensland. The pilot was conducting a private sightseeing flight with one passenger on board. At 1624, the aircraft passed the northern tip of Moreton Island at about 1,200 ft in a shallow descent towards nearby Flinders Reef.

The aircraft’s descent rate began to increase with no significant changes to direction or speed. At 1626:26, the pilot made a MAYDAY call identifying the aircraft but not its position or nature of the emergency. At this time, the aircraft was east of Flinders Reef and descending at about 1,400 ft/min through 300 ft with a groundspeed of about 115 kt. The aircraft continued north-east for 15–20 seconds after the MAYDAY call before colliding with water.

On 29 January 2020, the aircraft was located on the ocean floor to the north-east of Flinders Reef, about 45 m from the estimated point of impact with water. The pilot and passenger were not located.

What the ATSB found

The nature of any in-flight emergency or abnormal situation, and any effect it had on the pilot’s ability to control and configure the aircraft for ditching, could not be established.

ATSB analysis found that the engine’s power was reducing over the last part of the flight, over a period of about 100 seconds. At the time of the accident, the weather conditions were conducive to carburettor icing. These conditions are common in the region. However, a conclusion regarding the possible influence of carburettor icing on the development of the accident could not be drawn with any certainty.

The ATSB also found that the pilot had descended over water beyond the glide range of a suitable landing area twice on a previous flight, limiting the options for a forced landing in the event of an emergency.

Safety message

Although it could not be determined whether the aircraft’s descent out of glide range was intentional, pilots are reminded that the operation of single engine aircraft over water should at all times be conducted with consideration of the aircraft’s glide distance to a suitable landing area.

 

The occurrence

On 22 January 2020, at about 1530 Australian Eastern Standard Time,[1] a Cessna 182Q, registered VH‑WNR, took off from Caloundra Aerodrome, Queensland. The pilot was conducting a private sightseeing flight with one passenger on board. The flight was being conducted under visual flight rules (VFR).[2] Weather observations and the short-term forecasts for the area indicated that good visual flying conditions existed at the time of the flight.

The aircraft flew south to the VFR route[3] at Bribie Island, climbing to transit at 3,500 ft to Moreton Island. At 1606, the pilot reported on the Brisbane Centre air traffic control (ATC) frequency that the aircraft’s position was overhead Tangalooma at 2,500 ft. The pilot broadcast their intention to track south to the southern end of Moreton Island and then north up the eastern side of the island.

Recorded radar data at 5-second intervals indicated that, from about 1613, the aircraft flew north along Moreton Island’s eastern coastline at 1,400–1,500 ft above mean sea level with a groundspeed of 100–110 kt (Figure 1). The wind was about 19 kt from the north-north-east, meaning the aircraft’s airspeed would have been about 120–130 kt.

Figure 1: Flight path of VH-WNR on the accident flight

ao-2020-006-pic-1.png

Source: Google Earth, modified by the ATSB

At 1623, the aircraft commenced a shallow descent (about 162 ft/min) from 1,500 ft. At 1625, the aircraft passed Cape Moreton at the northern tip of the island at about 1,300 ft and continued north-east towards Flinders Reef, at a similar airspeed and descent rate (Figure 2).

Figure 2: Flight path of VH-WNR, near Flinders Reef

ao-2020-006-pic-2.png

Source: Google Earth, modified by the ATSB

At 1625:09, the aircraft passed through an altitude of 1,200 ft and the descent rate began to increase with a concurrent reduction in engine power. At 1626:26, the pilot made a MAYDAY[4] call on the Brisbane Centre ATC frequency, identifying the aircraft’s callsign but not its position or the nature of the emergency. At this time, the aircraft was east of Flinders Reef and descending at about 1,400 ft/min through 300 ft with a groundspeed of about 115 kt. The air traffic controller attempted to establish contact with the pilot; however, no further transmissions from the aircraft were received.

The aircraft’s transponder continued to transmit. Analysis of the recorded radar data indicated that the aircraft continued north-east for 15–20 seconds, while still descending, after the MAYDAY call. There were no witnesses.

An aerial and marine search was immediately initiated. The aircraft was located on the ocean floor on 29 January 2020, north-east of Flinders Reef (Figure 2). The pilot and passenger were not located.

__________

  1. Australian Eastern Standard Time (AEST) is Coordinated Universal Time (UTC) + 10 hours.
  2. Visual flight rules (VFR): a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
  3. VFR routes are transit lanes for aircraft operating under VFR.
  4. MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.

Context

Pilot information 

The pilot was reported to have flown aircraft overseas and in Australia decades earlier. Logbook records showed that the pilot had an extended break from flying and resumed in late 2019. After conducting 13.5 hours of flight training, the pilot was issued a Civil Aviation Safety Regulation Part 61 Private Pilot (Aeroplane) Licence on 17 October 2019 with a class rating for single engine aeroplanes.

The pilot held a Class 2 Aviation Medical Certificate that was issued on 17 October 2019 and valid until 17 October 2021, with a condition requiring reading correction be available when exercising the privileges of the licence. A review of the pilot’s medical records and interview with a close family member identified no significant medical conditions.

The pilot’s logbook records showed about 1,700 hours total aeronautical experience and previous night VFR[5] and instrument flight rules[6] experience. The pilot was also reported to have significant experience on the Cessna 182 type and had flown VH‑WNR 6 times over the previous fortnight, including around Moreton Island (see also Previous flights in VH-WNR). Prior to the accident flight, the pilot’s last logged flight was on 19 January 2020.

Aircraft information

General

The Cessna 182Q is a high-wing, all-metal, unpressurised aircraft with a fixed landing gear. The accident aircraft had a single, Continental O-470-U reciprocating piston engine driving a constant-speed propeller. The engine ignition system comprised two magnetos that provided a self-generated charge to the engine spark plugs and was independent of the aircraft electrical system.

An engine driven alternator supplied electrical power to aircraft systems. The alternator was also used to charge the battery and was controlled by a voltage regulator. A battery supplied power for engine starting and was a reserve source of power in the event of alternator failure.

VH-WNR (Figure 3) was manufactured in 1978 and was first registered in Australia in the same year. The aircraft was privately hired by the pilot for the flight.

Figure 3: VH-WNR in 2019

ao-2020-006-pic-3.png

Source: Aircraft operator

Maintenance history

At the time of the accident, VH-WNR had about 3,318 hours total time in service and had flown about 73 hours since the previous periodic inspection (100 hourly), which was conducted on 21 August 2019. The engine was installed new in December 2013 and had accumulated about 742 hours time in service.

During a flight on 19 January 2020,[7] the aircraft began to experience electrical issues over a period of about 3 minutes, resulting in the loss of some aircraft systems including the radio and transponder. After landing, engineers identified that the aircraft charging system was unserviceable and the battery had discharged. The battery was charged for the return flight to Caloundra. A new voltage regulator and alternator were fitted and the battery was charged again. On the morning of 22 January 2020, 6–7 ground runs were carried out to test and adjust the replaced components before the aircraft was released to service.

Weight and balance

According to a witness, the pilot visually checked the aircraft’s fuel quantity prior to the accident flight with the aid of a dipstick, which showed there was 135 L on board. A correction was made to the fuel record, which had been incorrectly annotated as 130 L. This amount was more than sufficient fuel for the intended flight.

Based on witness observations as well as estimates of fuel and occupant weights, the aircraft was likely within its weight and balance limits for the entire flight.

Meteorological information

The nearest weather station to the flight path of the aircraft was at Cape Moreton, at the northern end of Moreton Island, 328 ft above sea level. Observations taken at 1600 and 1630 both showed the wind speed at 19 kt from 030°, gusting to 24 kt, with no recorded precipitation.

Other observations at 1630 were:

  • temperature – 27.1 °C
  • dewpoint – 24.9 °C
  • relative humidity – 88%
  • QNH[8] – 1,009.5 hPa.

Satellite images taken at 1620 and 1630 indicated visual meteorological conditions in the vicinity of the northern end of Moreton Island. The 1630 meteorological aerodrome report for Brisbane Airport, about 53 km south-west of Cape Moreton, stated the cloud cover as ‘few’ at 2,000 ft and ‘broken’ at 27,000 ft.[9]

Another pilot was conducting a training flight in the vicinity of Bribie Island shortly before the accident. That pilot described the conditions and visibility as good for VFR operations with some low-level turbulence. Above 1,000 ft the conditions were smoother with a north-westerly wind at about 18 kt.

Wreckage and impact information

Wreckage location

Immediately after the accident, after being advised by Airservices Australia that contact was lost with VH-WNR, the Queensland Police Service (QPS) and the Australian Maritime Safety Authority (AMSA) commenced an aerial and marine search operation. That evening, floating debris from the aircraft was found and recovered. The following day the marine search focused on a position near Flinders Reef, but the aircraft could not be located.

At the request of the QPS, the ATSB analysed the supplied radar data and refined the estimated position of the aircraft on 28 January 2020. The wreckage was located by the QPS on the morning of 29 January 2020, about 45 m from the supplied coordinates in about 30 m of water. The engine and propeller were found about 10 m north-east of the main wreckage. The QPS took underwater video of the wreckage on 29–30 January 2020.

Partial wreckage recovery

On 6 February, with assistance from the QPS, specialists from the New South Wales Police Force and the Queensland National Parks and Wildlife Service, the ATSB recovered various aircraft components including the engine, propeller and instruments for detailed examination.

Wreckage examination

ATSB examination of the underwater video identified that the aircraft was likely destroyed by collision with water at a moderately high speed (Figure 4). Damage to the aircraft cabin from the collision with water indicated that it was unlikely to be survivable. There was no evidence of fire.

All major aircraft components were accounted for, and there was no evidence of pre-impact defects or structural failure. As far as could be established, cockpit switch positions were configured as expected for normal flight.

The flap control and right flap were found in the ‘up’ position. The left flap was observed to be displaced towards the down position from disruption caused during accident sequence to the adjacent wing structure. One of the front seats was found floating some distance from the wreckage, and the other front seat was not located. The seatbelts for both front seats were found to be attached to the airframe and latched.

The carburettor heat control, used to prevent or recover from engine icing, was in the ‘off’ position. However, due to the disruption of the wreckage, this may not have been indicative of its position prior to the accident.

Figure 4: Wreckage of VH-WNR on the ocean floor

ao-2020-006-pic-4.png

A weight, rope and buoy had been attached to the aircraft tail by the divers.

Source: Queensland Police Service

Engine examination

The engine was disassembled and examined at a Civil Aviation Safety Authority (CASA) approved overhaul facility under the supervision of the ATSB. Apart from impact and submersion damage, the engine was generally in good condition. Some components such as the magnetos, alternator and voltage regulator were extensively damaged by their immersion in seawater and their function could not be tested. No pre-existing defects were evident, and there was no evidence of fire or overheating (Figure 5).

Figure 5: Corrosion damage to the magnetos

ao-2020-006-pic-5.png

Source: ATSB

Propeller examination

The propeller was disassembled and examined at a CASA-approved overhaul facility under the supervision of the ATSB. No pre-existing defects or irregularities were identified. The propeller could not be functionally tested because of internal damage that occurred during the accident sequence.

The propeller blades were observed to be progressively bent out of plane (Figure 6), in a manner indicative of low but non-zero power. The pitch change lugs on all three blades were sheared off, with the direction of the fracture surface smearing being consistent with the blades being forcibly rotated towards low (fine) pitch, which is an indication of low power or windmilling.

Preload plates are fitted to each propeller blade at their base, within the propeller hub. Each blade pitch change lug transverses through a cut-out in the plates. Using damage signatures made by the propeller blade pitch change lugs onto the preload plates (Figure 6, inset), and estimating the propeller speed from the known velocity of the aircraft in the moments prior to impact, an estimate of power and the blade angle at impact was made using established datums with the assistance of the propeller manufacturer. These calculations were limited in accuracy as the preload plates are not indexed (such as with a key or slot), and so during assembly there could be slight variations with their position. The results of the calculations indicated that the propeller was rotating under low power, and with a blade angle at or near the low pitch stop.

Figure 6: VH-WNR propeller blade bending and inset image of example preload plate damage signatures

ao-2020-006-pic-6.png

Source: ATSB

Recorded data

Accident flight radar data

Airservices Australia provided radar data for the accident flight. This data combined primary surveillance radar (PSR) and secondary surveillance radar (SSR) data into a single, smoothed track. PSR has a shorter range than SSR, and is generally less reliable, but it is used to enhance the accuracy of SSR tracks and provide position information when SSR is not available.

Position data for the accident flight was generally recorded at 5‑second intervals, and occasionally at a 4- or 6-second interval. It included Mode C altitude data that was obtained from the aircraft static system referenced to the standard atmospheric pressure (1,013.25 hPa) and rounded to the nearest 100 ft. The aircraft’s average groundspeed between data points was derived from the position and time data.

The approximate position the aircraft collided with water was determined from the system track by extrapolating the estimate of groundspeed and a fitted altitude curve to sea level.

Engine monitoring recorder

The ATSB identified that the only item on the aircraft that was likely to record any data was a J.P. Instruments EDM-700 engine monitoring recorder. The ATSB recovered the instrument, however the recorded data it contained did not include the accident flight.

Additional information

Previous flights in VH-WNR

In the weeks prior to the accident, the pilot flew VH-WNR on the following 6 return flights from Caloundra Aerodrome, with available aircraft tracks shown in Figure 7:

  • 1 hours on 8 January as a proficiency check with an instructor (radar data not available)
  • 8 hours with one passenger on 11 January (radar data not available)
  • 8 hours with two passengers on 14 January (radar data not available)
  • 4 hours with two passengers on 15 January (blue line)
  • 2 hours with two passengers on 17 January (orange line)
  • 1 hours with two passengers on 19 January (red line).

Figure 7: Accident pilot’s previous flights in VH-WNR

ao-2020-006-pic-7.png

Source: Google Earth, modified by the ATSB

On the 15 January flight, the pilot transited between Bribie Island and Moreton Island at about 2,000 ft and 80–90 kt groundspeed. The flight profile was broadly similar to the accident flight past Cape Moreton towards Flinders Reef (Figure 8). On the return leg, the pilot flew from Flinders Reef direct to Bribie Island at about 1,800 ft.

Figure 8: Previous flights and the accident flight compared

ao-2020-006-pic-8.png

Source: Google Earth, modified by the ATSB

ATSB analysis indicated that two segments of the 15 January flight, including between Moreton Island and Flinders Reef, were further from land than the aircraft was capable of gliding with no engine power. Although complete analysis of glide distances was not feasible, the ATSB estimated that the aircraft was also flown near or beyond the limits of its glide range to land on other flights in this area. During the accident flight on 22 January, the aircraft similarly reached a point further from glide distance to land about halfway between Moreton Island and Flinders Reef.

On the 19 January flight, when the aircraft was approaching Moreton Island, the Brisbane Centre controller attempted to contact the pilot to advise that the aircraft was 2 NM west of Moreton Island at 3,900 ft (that is, they had entered controlled airspace by climbing above 3,500 ft in that area). After receiving assistance from the pilot of another aircraft in the area, the pilot of VH-WNR made contact with the controller, who explained the problem. The pilot apologised and stated that the entry to controlled airspace was unintentional, and they confirmed they were now at 3,000 ft approaching the eastern side of the island. The controller reminded the pilot to keep at or below 3,500 ft on the way back to Caloundra. On that flight, the pilot did not descend when travelling along the eastern side of Moreton Island.

As noted in The occurrence, during the accident flight on 22 January, the pilot contacted Brisbane Centre to report they were at 2,500 ft approaching Moreton Island. There was no requirement for the pilot to make a call on that frequency in that area while they remained at or below 3,500 ft.

Analysis of thrust required

A performance analysis was carried out on the last minutes of the accident flight based on the radar data, documented performance characteristics of the aircraft type (such as lift and drag coefficients), and estimates of aircraft weight. The analysis calculated the propulsive power that would be required for the aircraft’s estimated airspeed and altitude. For the section of flight analysed, the aircraft was flown with likely minor changes in heading and pitch, for which the radar data was considered sufficiently accurate. The analysis provided an estimate of the thrust power, not engine power, as efficiencies and other power losses were not calculated.

The analysis relied on the following assumptions:

  • Thrust opposed drag along the longitudinal axis of the aircraft.
  • The aircraft was not accelerating longitudinally (as indicated by the relatively constant groundspeed).
  • The aircraft was not banking, slipping, or accelerating vertically (turbulence).
  • Wing flaps were retracted.
  • Wind did not vary.

The analysis indicated that there was a reduction in thrust during the last 100 seconds of the flight.[10] At the end of the recorded data, due to the flight path being flown, the thrust power required by the aircraft was approximately zero.

Speech analysis

The ATSB conducted a basic speech analysis on the pilot’s ATC and Caloundra Aerodrome common traffic advisory frequency (CTAF)[11] radio transmissions. The pilot’s response times, delay between microphone keying and speaking, microphone un-keying delay, duration to annunciate the aircraft callsign, average speech rate, and voice pitch were analysed. The analysis was inconclusive regarding whether there were any changes to the pilot’s speech during the accident flight.

Carburettor icing

According to the CASA Visual Flight Rules Guide:

Carburettor icing is of particular concern because, unlike airframe icing, the risk of ice build-up in the carburettor can be high even with no visible moisture and an OAT [outside air temperature] of up to 38°C.

Carburettor icing occurs when the air temperature adiabatically decreases sufficiently to condense water vapour and for the localised air temperature to reduce below freezing. Ice builds up as the chilled condensed water makes contact with localised surfaces, such as the butterfly valve and the venturi walls. Carburettors experience additional cooling because of the evaporation of fuel. Furthermore, the risk of carburettor icing is significantly increased at partial power settings (for example, when power is reduced during descent), because of the cooling effect of a partly-closed throttle.

The effect of carburettor icing on aircraft may result in reduced power output, poor engine performance, rough running and in extreme cases engine failure. The onset of this may be evidenced by an unexplained drop in manifold pressure.

The pilot’s operating handbook (POH) for VH-WNR was not recovered. A reviewed sample of Cessna 182Q POHs required pilots who suspect carburettor icing to apply full throttle and set the carburettor heat control to ‘on’ until the engine ran smoothly.

To assist pilots in anticipating the potential for carburettor icing, CASA published a carburettor icing probability chart (Figure 9). The temperature recorded at Cape Moreton at the time of the accident was 27.1 °C, and the dewpoint 24.9 °C. This gave a dewpoint depression of 2.2 °C. The intersection between the resulting temperature and dewpoint lines was just inside the shaded area where ‘serious’ icing under descent power is possible.

Figure 9: Carburettor icing probability chart with local observations

ao-2020-006-pic-9.png

Source: CASA, annotated by the ATSB

An ATSB review of temperature and dewpoint observations for the south-east Queensland region showed that, over a 12-month period, carburettor icing conditions are frequent.

Previous ATSB investigations found to be, or potentially be, related to carburettor icing include:

  • AO-2018-050, Wirestrike and collision with terrain involving Cessna 172RG, VH-LCZ, Parafield Airport, South Australia, on 3 July 2018
  • AO-2016-059, Engine failure involving Piper PA-28, VH-IPO, Mangalore Airport, Victoria, on 16 June 2016
  • AO-2014-149, Collision with terrain involving Van's Aircraft RV-6, VH-TXF near Mudgee Airport, NSW on 14 September 2014
  • AO-2012-078, Collision with terrain - Robinson R44, VH-HOU, 93 km S Alice Springs Airport, NT, 10 June 2012.

Flights over water

Civil Aviation Regulation (CAR) 258 (Flights over water) stated:

The pilot in command of the aircraft must not fly over water at a distance from land greater than the distance from which the aircraft could reach land if the engine… were inoperative.

The Aeronautical Information Publication (AIP) stated in ENR 1.1 (section 11.11) that CAR 258 did not apply to charter, aerial work or private operations if each occupant was wearing a life jacket, unless they were exempted from doing so under Civil Aviation Order (CAO) 20.11 (Emergency and life saving equipment and passenger control in emergencies). CAO 20.11 paragraph 5.1.1 (a) stated that a single engine aircraft must carry a life jacket for each occupant when the aircraft was operated over water at a distance from land greater than that it could reach with its engine inoperative. In such cases, paragraph 5.1.7 also stated that each occupant shall wear a life jacket, but this was not required for occupants of aeroplanes during flight above 2,000 ft.  

The operator stated that the pilot was briefed to transit between Bribie Island and Moreton Island (a distance of about 15 km) at 3,500 ft using the VFR route. The operator also stated that, after some previous flights, it briefed the pilot that its preference for the pilot was to not operate on the northern side of Cape Moreton.

The operator stated that it encouraged the pilot to take life jackets on board the aircraft, which was done on previous flights. However, witnesses reported that no life jackets were taken on the accident flight.

Carriage of emergency locator transmitter

The aircraft was fitted with a deceleration-activated emergency locator transmitter (ELT), which was not serviceable at the time of the accident. The carriage of an ELT was not required for flights within 50 NM of the origin. A personal locator beacon was carried on board the aircraft at the time, in the glove box of the aircraft.

Cessna 182 emergency procedures

Engine failure

The POH for the Cessna 182Q contained an emergency procedure for an engine failure in flight. For this scenario, pilots were required to establish a best glide speed of 70 kt with the wing flaps retracted, and to identify a suitable landing area (Figure 10).

Figure 10: Cessna 182Q maximum glide distance chart

ao-2020-006-pic-10.png

Source: Cessna, annotated by the ATSB

Ditching

The POH procedure for ditching included transmitting a MAYDAY message over the radio, unlatching the cabin doors, and establishing a level attitude during descent. If engine power was available, the flaps were to be set to 20–40° and the aircraft established in a 60 kt and 300 ft/min descent. In an engine failure situation, the glide speed and configuration should be 70 kt with flaps up or 65 kt with 10° of flap.

__________

  1. Night VFR: flight at night that meets the visibility requirements for VFR operations.
  2. Instrument flight rules: a set of regulations that permit the pilot to operate an aircraft to operate in instrument meteorological conditions, which have much lower weather minimums than VFR. Procedures and training are significantly more complex as a pilot must demonstrate competency in instrument meteorological conditions while controlling the aircraft solely by reference to instruments.
  3. This flight was conducted by a different pilot to that of the accident flight.
  4. QNH: the altimeter barometric pressure subscale setting used to indicate the height above mean seal level.
  5. Cloud cover: in aviation, cloud cover of the sky is reported using words/abbreviations that denote the extent of the cover. ‘Sky clear’ (SKC) indicates no cloud, ‘few’ (FEW) indicates 1–2 oktas (or eighths) is covered, ‘scattered’ (SCT) indicates 3–4 oktas is covered, ‘broken’ (BKN) indicates 5–7 oktas is covered, and ‘overcast’ (OVC) indicates that 8 oktas is covered.
  6. This type of analysis cannot always distinguish between an increase in drag and a decrease in thrust. However, with no evidence of in-flight damage and the aircraft’s flaps likely retracted, there would have been no significant source of increased drag.
  7. A common traffic advisory frequency is a designated frequency on which pilots make positional broadcasts when operating in the vicinity of a non-controlled aerodrome or within a broadcast area.

Safety analysis

Descent and impact with water

The aircraft’s flight path was not indicative of uncontrolled flight, and no pre-existing defects with the aircraft could be identified. Other than a likely gradual loss of engine power, discussed below, there was no evidence of engine overheating, fire, loss of control, or other in-flight emergencies. However, as the entire aircraft could not be recovered, it was not possible to verify the operation of all aircraft systems.

The existence of secondary surveillance radar data for the aircraft almost to its collision with water, as well as the reception of the MAYDAY call, indicated that the aircraft’s electrical systems were receiving power. However, it was not possible to determine whether this was battery or alternator power. In any case, electrical power was not necessary for flight or ditching.

Analysis of the radar data showed there was likely a gradual reduction in thrust (and therefore engine power) during the last 100 seconds of the flight, and that this correlated with the increasing descent rate. The impact signatures on the propeller and propeller pitch change lugs were also consistent with a low level of engine power or windmilling at impact. Although the power reduction may have been due to pilot action, no reason for doing so at this point in the flight could be identified.

The aircraft maintained a moderately high speed until radar contact was lost at about 180 ft. Had the engine been inoperative, the radar data would have indicated a significantly steeper descent profile.

Regardless, a gradual reduction in engine power should not necessarily lead to very serious consequences. If detected early enough, with a suitable emergency landing area within range, a pilot could attempt to land. If no such landing area was available, a pilot could attempt a forced landing or ditching.

In this case, the aircraft maintained course away from suitable landing areas at a speed well above the aircraft’s best glide speed. The pilot may have been initially unaware of the gradual reduction in power and resulting descent. Although this would have been indicated on the aircraft’s instruments, the constant-speed propeller would maintain engine and propeller speed, and a gradual power loss would result in little or no change in sound and feel.

The MAYDAY call shortly before the impact indicated that the pilot was not totally incapacitated. However, in the absence of other evidence, a partial incapacitation could not be excluded.

The aircraft’s final position on the sea floor close to the last radar position strongly indicated that it continued along the established flight path without turning or, more critically, reducing descent rate and speed for a ditching. Furthermore, examination of the video footage of the wreckage on the sea floor showed the flaps were likely up at impact and that the aircraft had been significantly disrupted by a relatively high-speed collision with water.

In summary, the nature of any in-flight emergency or abnormal situation, and any effect it had on the pilot’s ability to control and configure the aircraft for ditching, could not be established.

Descent over water beyond glide range

On 15 January 2020, the pilot descended over water beyond the maximum glide distance of a suitable landing area for a Cessna 182Q during two segments of that flight. However, there was insufficient evidence to determine if an emergency landing on Moreton Island was possible had the pilot been able to turn the aircraft and establish the optimal glide speed. Nevertheless, flight outside of the glide range of a suitable landing area limits the opportunities for recovery in the event of an engine failure or other emergency. The same situation occurred on the accident flight, although the extent to which this was intentional could not be determined.

Carburettor icing

Carburettor icing can be insidious in its development and have serious consequences. Weather observations taken at Cape Moreton at the time of the accident, and plotted on the carburettor icing probability chart, showed that carburettor icing was possible. The plotted point was just inside the serious icing range at descent power and adjacent to the light icing range in cruise or descent power.

The likely reduction in power in the last 100 seconds of recorded flight could plausibly have been due to carburettor icing. However, carburettor icing conditions are frequently encountered in the region, and prevention and management of carburettor icing is easily done through use of carburettor heating. As the pilot had significant experience on the Cessna 182, they would very likely have been familiar with the use of carburettor heating. Due to wreckage disruption during the impact sequence, the position of the carburettor heat control during the accident flight could not be established. Overall, a conclusion regarding carburettor icing could not be drawn with any certainty.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the collision with water involving Cessna 182, registered VH-WNR, 6 km north-west of Moreton Island, Queensland, on 22 January 2020.

Contributing factors

  • After passing the northern end of Moreton Island at 1,200 ft, the aircraft continued descending away from the island at about 110 kt groundspeed, with no significant change in direction and with reducing engine power. The pilot broadcast a MAYDAY when passing 300 ft; however, for reasons that could not be determined, the flight path and speed of the aircraft did not significantly change after this point until it collided with water.

Other factors that increased risk

  • The pilot had descended over water beyond the glide range of a suitable landing area twice on a previous flight, limiting the options for a forced landing in the event of an emergency.
  • At the time of the accident, the meteorological conditions were conducive to carburettor icing. However, such conditions are common in the region, and able to be easily managed with the aircraft’s carburettor heat control.

Other findings

  • From the limited evidence available, no pre-existing aircraft defects could be identified.

Glossary

AMSA              Australian Maritime Safety Authority

ATC                 Air traffic control

CASA              Civil Aviation Safety Authority

POH                Pilot’s operating handbook

PSR                Primary surveillance radar

QPS                Queensland Police Service

SSR                Secondary surveillance radar

VFR                Visual flight rules

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • another pilot who flew VH-WNR
  • the aircraft operator
  • Civil Aviation Safety Authority
  • Queensland Police Service
  • the maintenance provider
  • Hartzell propeller
  • Airservices Australia
  • Bureau of Meteorology.

References

National Aeronautics and Space Administration 1973, Point and path performance of light aircraft, Contractor report NASA CR-2272.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the aircraft operator
  • the maintenance provider
  • Civil Aviation Safety Authority
  • US National Transportation Safety Board
  • Hartzell propeller.

Submissions were received from the aircraft operator, the Civil Aviation Safety Authority, and Hartzell propeller. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 15/04/2020

This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

The occurrence

On 22 January 2020, at about 1530 Eastern Standard Time,[1] a Cessna 182Q, registered VH‑WNR, took off from Caloundra aerodrome, Queensland. The pilot was conducting a private sightseeing flight with one passenger on board.

The aircraft flew south to the light aircraft lane at Woorim on Bribie Island, climbing to transit to Moreton Island. At 1606, the pilot reported on the Brisbane air traffic control (ATC) frequency that the aircraft’s position was overhead Tangalooma resort, Moreton Island, at 2,500 ft. He also stated that his intention was to track south to the end of Moreton Island and then north up the eastern side of the island.

Recorded radar data at 5-second intervals indicated that, from about 1613, the aircraft flew north along Moreton Island’s eastern coastline at 1400–1500 ft above mean sea level (AMSL) with a groundspeed of 100–110 kt (Figure 1). The wind at the time was about 19 kt from the north-north-east, so the aircraft’s airspeed would have been about 120–130 kt.

Figure 1: Preliminary representation of the flight path of VH-WNR

Figure 1: Preliminary representation of the flight path of VH-WNR. &#13;Source: Google Earth, modified by the ATSB.

Source: Google Earth, modified by the ATSB.

At 1624, the aircraft passed the northern tip of the island at about 1,100 ft in a shallow descent (about 160 ft/minute). It then continued north-east towards Flinders Reef, 6 km away (Figure 2), at a similar airspeed and descent rate.

Figure 2: Preliminary representation of the flight path of VH-WNR, near Flinders Reef

Figure 2: Preliminary representation of the flight path of VH-WNR, near Flinders Reef.&#13;Source: Google Earth, modified by the ATSB.

Source: Google Earth, modified by the ATSB.

The aircraft’s descent rate began to increase from 1625:09. At 1626:26, the pilot made a MAYDAY[2] call on the Brisbane ATC frequency, without identifying the nature of the problem. At this time, the aircraft was east of Flinders Reef and descending at about 1,400 ft/minute through 300 ft with a groundspeed of about 115 kt. The air traffic controller attempted to establish contact with the pilot; however, no further transmissions from the aircraft were received.

The aircraft’s transponder continued to transmit. Later analysis of the recorded radar data indicated that the aircraft probably continued north-east for 15–20 seconds after the MAYDAY call before colliding with water. There were no witnesses.

An aerial and marine search was initiated. The aircraft was located on the ocean floor on 29 January 2020, north-east of Flinders Reef. The pilot and passenger have not been located.

Context

Pilot information

  • The pilot was reported to have flown in Africa and Australia decades earlier. He then had an extended break from flying and resumed in late 2019. After conducting 13.5 hours flying training he was reissued a Private Pilot Licence (Aeroplane) on 17 October 2019 with a class rating for single engine aeroplanes.
  • The pilot held a Class 2 Aviation Medical Certificate that was issued on 17 October 2019 and valid until 17 October 2021.
  • The available information from the pilot’s records indicated that he had about 1,700 hours total aeronautical experience and had previously held night VFR[3] and instrument ratings. He was also reported to have significant experience on the Cessna 182 type and had flown VH‑WNR several times over the previous week, including around Moreton Island. His last flight prior to the accident flight was on 19 January.

Aircraft information

  • The aircraft (Figure 3) was manufactured in 1978 and was first registered in Australia in the same year.
  • The aircraft was fitted a Continental O-470-U piston engine, installed new in December 2013. It had been operated for approximately 742 hours before the accident flight.
  • The aircraft was operated by a flying school. It was privately hired to the pilot for the flight.
  • The aircraft’s last periodic (100 hourly) inspection was conducted on 21 August 2019 and the last maintenance release was issued on the same date. At the time of the accident, the aircraft had about 3,318 hours total time in service and 73 hours time in service since the previous periodic inspection.
  • The last maintenance conducted on the aircraft was on 21-22 January 2020, when the alternator and regulator were replaced to rectify an electrical defect reported by another pilot on 20 January.

Figure 3: Cessna 182, registered VH-WNR, in 2019

Figure 3: Cessna 182, registered VH-WNR, in 2019.&#13;Source: Aircraft operator.

Source: Aircraft operator.

Site and wreckage

  • The wreckage was located in about 30 m of water. The engine and propeller were found about 10 m away from the main wreckage.
  • The Queensland Police Service (QPS) took underwater video footage of the wreckage on 29–30 January 2020. The ATSB examination of the video footage identified that the aircraft was destroyed by impact with water (Figure 4). Damage to the cabin indicated that the impact was unlikely to be survivable. One of the front seats was found floating some distance from the wreckage, and the other front seat was not located. Both of the front seats’ seat belts were found to be attached to the airframe and latched. All major aircraft components were accounted for in the video footage.
  • On 6 February, with assistance from the QPS and the Queensland National Parks and Wildlife Service, the ATSB recovered some aircraft components including the engine, propeller and instruments for examination. No pre-existing defects were identified during workshop examinations of the engine and propeller.
  • The ATSB identified that the only item on the aircraft that was likely to record any data was a J.P. Instruments EDM-700 engine monitoring recorder. The ATSB recovered the instrument and obtained data from it. Further analysis will be required to determine whether the data is relevant to the accident flight.

Figure 4: Wreckage of VH-WNR on ocean floor

Figure 4: Wreckage of VH-WNR on ocean floor.&#13;Source: Queensland Police Service.

Source: Queensland Police Service.

Meteorological information

  • Relevant aviation weather forecast(s) indicated good visual flying conditions would have existed at the time of the flight.
  • The nearest weather station to the aircraft’s flight path was at Cape Moreton, at the northern end of Moreton Island and a height of 328 ft AMSL. Observations taken at 1600 and 1630 showed the wind speed was 19 kt, gusting to 24 kt. No precipitation was recorded. The temperature at 1630 was 27.1 °C, dew point 24.9 °C and QNH 1,009.5 hPa. Other nearby weather stations recorded similar observations.
  • Satellite images taken at 1620 and 1630 indicated no significant cloud in the vicinity of the northern end of Moreton Island. The 1630 METAR (meteorological aerodrome report) for Brisbane Airport, 29 NM south-west of Cape Moreton, reported few cloud at 2,000 ft and broken cloud[4] at 27,000 ft.
  • A pilot, who was flying over Bribie Island at about 1600, recalled the visibility over Tangalooma on Moreton Island was clear.

Further investigation

The investigation is continuing and will include further examination and analysis of the:

  • recovered components including engines and propellers
  • aircraft’s maintenance and operational records
  • video footage of the wreckage
  • pilot qualifications, experience and medical history
  • recorded radio, radar and engine monitoring data.

Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.

A final report will be released at the conclusion of the investigation.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Standard Time (EST) is Coordinated Universal Time (UTC) + 10 hours.
  2. MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.
  3. Visual flight rules (VFR): a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
  4. Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – ‘few’ indicates 1–2 oktas (or eighths) is covered, ‘scattered’ (SCT) indicates 3–4 oktas is covered, ‘broken’ (BKN) indicates 5–7 oktas is covered, and ‘overcast’ (OVC) indicates that 8 oktas is covered.

Occurrence summary

Investigation number AO-2020-006
Occurrence date 22/01/2020
Location 6 km north-east of Moreton Island
State Queensland
Report release date 10/02/2022
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer Cessna Aircraft Company
Model 182Q
Registration VH-WNR
Serial number 18266543
Aircraft operator Inspire Aviation
Sector Piston
Operation type Private
Departure point Caloundra Airport, Queensland
Destination Caloundra Airport, Queensland
Damage Destroyed

VFR into IMC and loss of control involving Wittman Tailwind, VH-TWQ, Tooloom National Park, New South Wales, on 12 January 2020

Final report

Report release date: 02/03/2021

Safety summary

What happened

On the afternoon of 12 January 2020, the pilot of an amateur-built Wittman Tailwind aircraft, registered VH-TWQ (TWQ), departed Evans Head Airport, New South Wales, with one passenger on board. The pilot was conducting a private flight under the visual flight rules from Evans Head, to Boonah, Queensland.

The pilot flew in a north-north-westerly direction towards Boonah via the Richmond River valley. At 1353, the pilot commenced a 180° turn overhead the township of Kyogle and diverted, due to the weather, south back down the valley to Casino Aerodrome, landing at 1406.

At 1454, the pilot took off from Casino and flew in a west-north-westerly direction. At 1512 TWQ commenced a series of rapid descents and climbs followed by a descending left turn. The turn and descent continued until TWQ collided with terrain. The pilot and passenger were fatally injured, and the aircraft was destroyed.

What the ATSB found

The ATSB found that the pilot departed an interim landing site for Boonah under the visual flight rules with a high risk of encountering forecast cloud. En route to Boonah, the aircraft entered an area of reduced visibility and the pilot likely became spatially disorientated resulting in a loss of control and collision with terrain.

Safety message

Weather-related accidents remain one of the most significant causes of fatal accidents in general aviation and continues to be a focus of the ATSB’s SafetyWatch initiative. SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported to us by industry. One of the safety concerns relates to inflight decision making, particularly involving pilots flying with reduced visual reference. SafetyWatch provides information about each safety concern, and strategies to help manage risk areas, along with links to safety resources. In relation to visual flight rules (VFR) pilots flying into areas of reduced visibility, some key messages are:

  • Pilots should avoid deteriorating weather by conducting thorough pre-flight planning. They should ensure they have alternate plans in case of an unexpected deterioration in the weather and make timely decisions to turn back, divert or hold in an area of good weather.
  • VFR pilots should use a ‘personal minimums’ checklist to help control and manage flight risks through identifying risk factors that include marginal weather conditions and only fly in environments that do not exceed their capabilities.
  • Pilot’s should consider reducing speed and/or altering the configuration of the aircraft to allow more time for decision making and manoeuvring in areas of deteriorating or marginal weather conditions
  • Pressing on into instrument meteorological conditions without a current instrument rating carries a significant risk of severe spatial disorientation due to powerful and misleading orientation sensations with reduced visual cues. Disorientation can affect any pilot, no matter what their level of experience.
  • If VFR pilots find themselves in marginal weather and becoming disoriented or lost, they should seek whatever help is available. Air Traffic Services (ATS) may be able to provide assistance, especially if the aircraft is in ATS surveillance coverage. There have been a number of reported occurrences where this simple action has averted potential disaster.

 

The occurrence

On Friday, 10 January 2020 the pilot of an amateur-built Wittman Tailwind aircraft, registered VH‑TWQ (TWQ), departed Toowoomba, Queensland, and flew via Boonah, to Evans Head, New South Wales. The purpose of the flight was to pick up a passenger at Boonah and then attend the Great Eastern Fly-In (Fly-In) at Evans Head. The Fly-In was planned for the weekend of 11‑12 January. However, due to poor weather, the event program was significantly disrupted.

On the morning of 12 January 2020, the pilot attended the Fly-In event briefing which included the meteorology for the day. The event was cancelled at 0830 due to the cloud base at Evans Head being approximately 1,000 ft above ground level (AGL) with a reduction to 600 ft AGL forecast during the day. Due to the cancellation of the event the pilot elected to return to Toowoomba and contacted relatives there for an update on the weather. They sent photos of the local conditions and said the cloud at Toowoomba was not really low, there was no wind and there had been some rain. At 1336 Eastern Daylight-saving Time,[1] the pilot departed Evans Head Airport , with one passenger on board. The pilot was conducting a private flight under the visual flight rules[2] to Toowoomba via Boonah (Figure 1).

Figure 1 - Accident flight departure, destination and accident locations

Figure 1 - Accident flight departure, destination and accident locations

 Source: Google Earth, annotated by the ATSB

The pilot flew in a north-north-westerly direction towards Boonah via the Richmond River valley (Figure 2). The aircraft reached a maximum altitude of 1,950 ft above mean sea level[3] just prior to reaching Kyogle. At 1353, the pilot commenced a 180° turn overhead the township of Kyogle and diverted, likely due to low cloud on their intended flight path. At 1357 a family member contacted the passenger as they had seen the turnaround overhead Kyogle on OzRunways.[4] The passenger replied to say they were ‘going home due low cloud’. The pilot flew south back down the valley to Casino Aerodrome, landing at 1406.

During the time on the ground at Casino, the pilot contacted a friend in the area and left a voice message. The message stated they could not get past Kyogle due to the weather, so they had landed at Casino. (refer to the section titled Meteorological information below.)

Figure 2 - Flight tracks for VH-TWQ on 12 January 2020

Figure 2 - Flight tracks for VH-TWQ on 12 January 2020

Source: Flightradar24 and Google Earth, annotated by the ATSB

At 1454, the pilot took off from Casino and flew in a west-north-westerly direction. At 1510 TWQ commenced a series of rapid descents and climbs, between 3,100 and 4,000 ft, followed by a left descending turn. Shortly afterwards TWQ collided with terrain. The pilot and passenger were fatally injured, and the aircraft was destroyed. There were no witnesses to the accident.

__________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) +11 hours.
  2. Visual flight rules (VFR): a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
  3. Above mean sea level (AMSL): All altitudes and heights will be referenced to AMSL unless otherwise stated.
  4. The OzRunways application is an electronic flight bag. An electronic flight bag is a portable information system for flight deck crew members which allows storing, updating, delivering, displaying and/or computing digital data to support flight operations or duties. It provides the option for live flight tracking by transmitting the device’s position and altitude

Context

Pilot information

General information

The pilot held a Private Pilot Licence (Aeroplane) issued in July 1982 and was qualified to fly by day under the visual flight rules. The pilot also held a single-engine aeroplane class rating. The pilot last conducted a single-engine aeroplane flight review in June 2018 that was valid until June 2020. The pilot had about 1,200 hours flying experience recorded in the pilot’s logbook with a total of about 140 hours on the Wittman Tailwind. In the 90 days prior to the accident, the pilot had flown 12.4 hours total, of which 11.2 hours were in TWQ.

The pilot’s logbook showed a total of 8.4 hours instrument flying experience. Of these, 5 hours were accumulated between 1982 and 1983. The remaining 3.4 hours were accumulated from 1986 to 2015. The pilot did not hold an instrument rating.

Medical information

The pilot held a Class 2 aviation medical certificate that was valid until October 2021 with two restrictions noted. One restriction required distance vision correction be worn and the other required reading correction to be available during flight.

The pilot was reported to be in good health and not taking any medications at the time of the accident.

Due to the pilot being away from home for the days preceding the accident, a detailed 72-hour history could not be obtained. From the limited information available there were no fatigue‑related concerns identified.

A limited post-mortem examination and toxicological screening was performed. There was nothing found to support incapacitation.

Aircraft information

Overview

VH-TWQ (TWQ) was a Wittman Tailwind, an amateur-built aircraft in the experimental category. TWQ had a two seat, side-by-side seating arrangement. The structure was a combination of tubular steel frames and fabric covering on the fuselage. Wooden wing ribs had a bonded plywood skin covering. The flight controls consisted of push-pull type control tubes. All flight controls and flaps were fabric covered. The Wittman had a fixed undercarriage in a taildragger configuration.

TWQ was fitted with a Lycoming XIO-320[5] four cylinder, horizontally opposed piston engine and was fitted with a ground adjustable Whirlwind two-bladed composite propeller.

Entries in the logbook indicated that the owner-pilot commenced construction of the aircraft as an amateur builder in January 2006. The aircraft was completed in August 2018. A CASA authorised person issued a special certificate of airworthiness in the experimental category on 25 December 2018.

On 28 June 2019, the pilot issued a maintenance release that was valid for 12 months. This allowed the aircraft to be operated privately under the day visual flight rules. The aircraft flew for 33.3 hours between 28 June 2019 and the day of the accident. No defects or unserviceable equipment endorsements were recorded on the maintenance release.

The last entry in the aircraft’s maintenance records was the change, by the pilot, of the engine oil and filter in October 2019. The pilot changed the engine oil filter in accordance with the maintenance schedule.

Operating limitations

Aircraft operating limitations were contained within the flight manual for the aircraft and relevant limitations are detailed in Table 1 and Table 2.

Table 1 – Airspeed limitations

SpeedKnots indicated airspeed (KIAS)Remarks
Vne – Never exceed174Do not exceed this speed in any operation
Vno – Max structural cruising155Do not exceed this speed except in smooth air, then only with caution
Va – Manoeuvring155Do not make full or abrupt control movement above this speed, because under certain conditions the aircraft may be overstressed.

Table 2 - Stall speeds

ConfigurationPower off (KIAS)Power on (KIAS)
Clean5249
Flaps Land4740
Navigation / cockpit instruments

The aircraft was fitted with a Garmin G3X (G3X) flight display, capable of displaying the engine monitoring instruments, primary flight instruments and navigation information.

The pilot was reported to navigate primarily by using paper maps, using the main Garmin screen to display attitude and heading information as well as engine parameters. The pilot had an iPad mounted beside the G3X unit running the OzRunways application. It was reported that the pilot’s use of OzRunways navigation and flight planning features was limited to using the direct to function which plotted a track from the aircraft’s current location to a desired destination. The pilot was also reported to use the weather radar overlay function on OzRunways. This overlay displayed rain when detected by radar but did not display the presence of clouds.

Wreckage and accident site information

Accident site

The accident site was located in dense rainforest, about 72 km west-north-west of Casino, within the Tooloom National Park (Figure 2). The New South Wales Police Rescue and Bomb Disposal Unit assisted ATSB investigators to access the site on foot.

The accident site was on the eastern side of a ridgeline at an elevation of 3,170 ft. The highest ground in the immediate area of the accident site was approximately 3,200 ft.

Wreckage examination

The aircraft’s structure was substantially disrupted (Figure 3). The wreckage trail was about 120 m long on a bearing of approximately 270°. All major aircraft components were located at the accident site. ATSB investigators did not identify any signs of pre-existing airframe damage. Due to the disruption of the airframe, the aircraft’s attitude when it entered the tree canopy could not be determined. There was no evidence of fire. Site and wreckage examination did not identify any defects or anomalies that might have contributed to the accident.

Figure 3 - VH-TWQ’s empennage at the accident site

Figure 3 - VH-TWQ’s empennage at the accident site

Source: ATSB

Engine and propeller

On-site examination of the engine and propeller did not identify any defects that could have contributed to the accident. Damage noted to the propeller, during this examination, were consistent with the engine producing significant power at the time of the accident.

Flight control system

All primary and secondary flight controls were located on-site. An examination of the flight control systems did not identify any faults that could have contributed to the accident.

Fuel

The fuel tank was located toward the end of the wreckage trail. It was torn from the fuselage and had ruptured. Rain had entered the tank post-accident, therefore the fuel that remained in the tank was not tested.

Weight and balance

The on-site examination found a small amount of lightweight cargo. It was reported that the occupants took minimal cargo with them when they departed for the weekend. Weight and balance was calculated using full fuel and maximum baggage on departure out of Toowoomba and was calculated to be within limits. The aircraft did not refuel again after departing Toowoomba. Weight and balance was also calculated for the expected fuel remaining at the time of the accident and was also within limits.

Emergency locator transmitter

The aircraft was not fitted with an ELT, nor was it required to be. An Emergency Position Indicating Radio Beacon was located in the wreckage and had not been activated. This unit was tested on-site and functioned as required.

Operational Information

The flight from Evans Head to Boonah required the pilot to cross the McPherson Range (Figure 4). The McPherson Range is a spur of the Great Dividing Range, heading in an easterly direction from near Wallangarra, Queensland, to the coast. It also forms part of the border between New South Wales and Queensland.

Figure 4 - Accident site and McPherson Range

Figure 4 - Accident site and McPherson Range

 Source: Google Earth and Flightradar24, annotated by the ATSB

Terrain across the range varies in altitude with several areas above 3,000 ft and some peaks above 4,000 ft.

The initial flight from Evans Head to Casino, indicated that the aircraft was attempting to cross the ranges via a route known as the ‘border loop’. The border loop is a route commonly used by VFR pilots to transit the range. Tracking is north up the Richmond River valley, past the town of Kyogle, then over the ranges where the railway cuts through the high ground.

Another common route over the ranges is to fly via the Toonumbar Dam, then Killarney to Warwick, which is similar to the track of the second flight. Another pilot who attended the Fly‑In reported that when attempting to fly over the ranges they use a minimum of 4,000 ft, and normally fly over the range at about 5,000 ft.

Meteorological information

Bureau of Meteorology forecast

The planned flight from Evans Head to Boonah traversed two Graphical Area Forecast (GAF)[6] areas. The accident site was located on the border of the GAF NSW East (NSW-E) and the GAF QLD South (QLD-S). 

Forecast weather conditions in the GAF for NSW-E, valid from 1000 to 1600 on 12 January 2020, that potentially affected the flight included:

  • Average conditions of greater than 10 km visibility with areas of broken[7] stratocumulus clouds between 3,000 and 6,000 ft
  • Widespread smoke reducing visibility to 8,000 m
  • Isolated showers of rain reducing visibility to 4,000 m with associated cloud including broken stratus 1,000 to 2,000 ft and broken cumulus, stratocumulus 2,000 to 8,000 ft
  • Isolated thunderstorms and rain reducing visibility to 2,000 m with associated cloud including isolated cumulonimbus 6,000 to above 10,000 ft, broken stratus 500 to 2,000 ft and broken stratocumulus 2,000 to 6,000 ft
  • Isolated smoke over land reducing visibility to 1,000 m
  • Moderate turbulence is implied in cumulous, stratocumulus and altocumulus cloud. Severe turbulence is implied in thunderstorms, cumulonimbus and towering cumulus

The GAF for QLD-S was valid from 0900 to 1500. Forecast conditions that potentially affected the flight included:

  • Average conditions of greater than 10 km visibility with areas of scattered stratus 1,500 to 3,000 ft, scattered cumulus and stratocumulus 2,500 to 7,000 ft, and further cloud layers above 8,000 ft
  • Isolated dust and smoke reducing visibility to 7,000 m and 5,000 m respectively
  • Scattered rain reducing visibility to 5,000 m with associated broken stratus 1,200 to 4,000 ft, broken stratocumulus 5,000 to 8,000 ft and broken altocumulus and altostratus 8,000 to above 10,000 ft
  • Scattered showers of rain reducing visibility to 3,000 m with associated occasional towering cumulus 5,000 to above 10,000 ft and broken stratus 1,200 to 3,000 ft
  • Isolated thunderstorms and rain reducing visibility to 2,000 m with associated isolated cumulonimbus 4,000 to above 10,000 ft, broken stratus 1,500 to 4,000 ft and broken stratocumulus 4,000 to 6,000 ft
  • Moderate turbulence is implied in cumulous, stratocumulus and altocumulus cloud. Severe turbulence is implied in thunderstorms, cumulonimbus and towering cumulus

Neither of the GAFs were corrected and no SIGMETs or AIRMETs affecting the QLD-S area were issued during the validity period. An AIRMET was issued for the NSW-E GAF region, however this was for an area to the west of the flight path and did not affect the conduct of this flight.

The Bureau of Meteorology (BoM) Grid Point Wind and Temperature forecast valid at the time of the flight, forecast the wind to be 20 kt from 160° at 2,000 ft and 19 kt from 130° at 5,000 ft.

The BoM also provided an aerodrome forecast (TAF)[8] for Ballina and Lismore. Lismore Aerodrome was the closest aerodrome to the flight path with a TAF available. TWQ flew within 9.7 km of Lismore aerodrome on the flight from Evans Head to Casino. Lismore is located 20 km east north east of Casino with an elevation of 35 ft. The amended Lismore TAF, issued at 1145 on 12 January 2020, was valid from 1300 on the day of the accident. The TAF forecast 14 kt winds from 160°, visibility greater than 10 km and light showers of rain. Cloud was forecast to be scattered with a base of 2,000 ft above the aerodrome and broken with a base 3,000 ft above the aerodrome. The forecast indicated that between 1300 and 1700 there would be temporary periods, greater than 30 minutes but less than 60 minutes in duration, of deteriorating weather conditions. These conditions included visibility reducing to 4,000 m, showers of rain and broken cloud with a base of 1,000 ft above the aerodrome.

Great Eastern Fly-In event meteorology

On the morning of 12 January 2020, the pilot of TWQ attended the Fly-In pilot’s briefing which included the meteorology for the day. The briefing, delivered by event staff, included weather information based on forecasts available from the BoM for Evans Head, the surrounding airfields and the GAF NSW-E. The display was cancelled at 0830 during the briefing due to the cloud base at Evans Head being approximately 1,000 ft above ground level (AGL) with a reduction to 600 ft AGL forecast during the day.

Bureau of Meteorology observations and analysis

The BoM reported that there were no observations of the actual conditions at the location of the accident. The BoM commented that the winds south of the McPherson Range, below 5,000 ft, would have been south-west to south-easterly. The generally southerly wind flow, heading towards the range, would be consistent with orographic cloud[9] formation. The BoM noted that the forecast broken cloud at 3,000 ft was likely to be a reasonable representation of the conditions. The BoM also stated that the summits of Wilsons Peak at 4,030 ft and Mount Barney 4,430 ft are higher than the bases of the cloud forecast in this area. No thunderstorm activity was detected near the flight path from Casino.

Lismore airport observations

Half hourly observations[10] were recorded at Lismore Airport on the day of the accident. At 1500, the wind was from 170° at an average speed of 11.1 kt, with a gust of 15.9 kt recorded. The temperature was 23.2 °C and the mean seal level pressure was 1014.4 hectopascals (hPa). Cloud was overcast with a base of 3,300 ft. 

Casino aerodrome weather recordings

The Casino Automatic Weather Station (AWS) recorded several weather parameters on the day of the accident. At 1500, the wind at Casino Aerodrome was from 170° at an average speed of 6 kt and the temperature was 23.6 °C. No cloud data is available for Casino AWS, as no ceilometer is installed at this location.

Witness observations of weather

Local residents

Residents in the vicinity of the accident location confirmed that the top of the ridgeline, where the accident site was located, was in cloud on the afternoon of the accident. Several of the witnesses commented they could see about three quarters of the way up the ridgeline, which was calculated to be approximately 2,800 ft. These residents commented that it was an overcast day and it had been raining on and off throughout the day.

Tooloom fire tower weather observations 

The Forestry Corporation of New South Wales has several observation towers positioned in the region of the flight. The Tooloom tower is located closest to the flight path from Casino, at an elevation of 2,619 ft (Figure 5).

An observer was positioned in the tower on 12 January from 0900 to 1500 and recorded weather conditions on the hour. Throughout the day, visibility remained at 0 km, with the cloud recorded as 8 oktas. In addition, the relative humidity was recorded at 98 per cent or above throughout the day. The wind was from the south-south-east around 9 kt with an average gust of 19 kt.

Figure 5 – Tooloom fire tower location and proximity to flight track

Figure 5 – Tooloom fire tower location and proximity to flight track

Source: Google Earth and Flightradar24, annotated by the ATSB

Flight track proximity to Tooloom Fire Tower

At 1509, TWQ, at its closest, passed 4.23 km to the west-south-west of the Tooloom Fire Tower (Figure 5). The aircraft was tracking from the south-east to the north-west. At 1509 the aircraft was at 3,575 ft, with a ground speed of 141 kt and tracking 332°. Tooloom Fire Tower has an elevation of 2,619 ft, and was in cloud at 1500, as it had been since 0900.

Pilot access to weather information

On the morning of the accident, the pilot attended the Fly-In event briefing which included weather for the event and the area. There was no log recorded indicating that the pilot accessed the weather information through the National Aeronautical Information Processing System (NAIPS) on the day of the accident. However, it is possible that the pilot obtained additional weather information from other sources.

Recorded data

Overview

The aircraft was fitted with a Mode S transponder that broadcast ADS-B[11] data which included the position and altitude of the aircraft. The data was received by Flightradar24 and provided to the ATSB. Also on-board was a mobile device with the OzRunways electronic flight bag (EFB) application installed. The application had an option enabled for live flight tracking by transmitting the device’s position and altitude. OzRunways information was also obtained by the ATSB. This data had a sampling rate of every 5 seconds.

The ATSB compared the data from both sources and they were found to be consistent. The flight data from OzRunways was plotted for the accident flight along with the terrain elevation. (Figure 6).

Figure 6 - OzRunways data and terrain elevations for the final flight of TWQ

Figure 6 - OzRunways data and terrain elevations for the final flight of TWQ

Figure 5 shows the aircraft’s flight data from OzRunways. Groundspeed is annotated in red, altitude in light blue and track in black. The altitude of Tooloom fire tower is also marked in blue. This line starts from the time where TWQ was abeam the fire tower. Terrain directly underneath the flight path is marked in green.

Source: OzRunways, US National Aeronautics and Space Administration Shuttle Radar Topography Mission data and ATSB

The first climb on the graph is part of the departure from Casino aerodrome. On a track generally to the north-west. The aircraft reached 3,000 ft and then descended to 2,200 ft.

The climb that commenced at approximately 1502 corresponded with the first range of high ground en route. A groundspeed of about 145 kt was maintained during this climb. The climb commenced at 2,200 ft and reached a peak of 4,100 ft.

The following descent from 4,100 ft to 3,100 ft, corresponded to a ground speed increase from 145 kt to 173 kt and a rate of descent of about 600 feet per minute. The altitude of TWQ at the bottom of this descent was above the altitude of Tooloom Fire Tower (Figure 6).

Over the last 4 minutes of the flight, the aircraft’s recorded groundspeed, rate of climb/descent and altitude oscillated significantly over short periods with the aircraft’s:

  • ground speed varying rapidly between 109 and 175 kt,
  • rate of climb and descent being between maximum values of +2,400 ft per minute and -2,400 ft per minute,
  • altitude oscillating between 4,000 and 3,100 ft.

At approximately 1512 the final descent and turn towards the high ground commenced. The descent commenced from 4,000 feet with the aircraft travelling at 133 kt groundspeed and tracking 316°.

The last data point was recorded at 1512:49. The aircraft was passing 3,100 ft with an 1,800 feet per minute rate of descent. It was travelling at 172 kt groundspeed and tracking 276°.

Of note, during the last few minutes of flight, prior to the collision with terrain, TWQ maintained more than 1,000 ft clearance with the ground and in most places more than 2,000 ft above the ground.

G3X flight display

The G3X unit can log flight and engine data on a removable SD card, or additionally to an internal Flight Log. The G3X unit was badly damaged in the accident sequence. The SD card and a number of circuit boards from the G3X unit were recovered from the accident site. The SD card was found in the read only mode and therefore did not contain any data from the accident flight. While some flight data was able to be recovered from the internal memory, the last recovered flight data was from 30 December 2019.

Air Traffic Control

TWQ was operating outside controlled airspace at the time of the accident. The Brisbane Centre audio recording was obtained from Airservices for the New England area, which covered the accident flight path. There were no radio calls recorded from TWQ, however, they were not required to make any routine radio calls on this frequency.

Additional information

Visual Flight Rules

The CASA Visual Flight Rules Guide outlined that flight under the visual flight rules (VFR) can only be conducted in Visual Meteorological Conditions (VMC).[12] Additionally, when operating at or below 2,000 ft above the ground or water, the pilot must be able to navigate by visual reference to the ground or water.

The flight, and the location of the accident, were in (non‑controlled) Class G airspace. The following conditions were stipulated for flight under the VFR in Class G airspace when below 10,000 ft and above 3,000 ft or 1,000 ft above ground level (whichever is higher):

  • a flight visibility of 5,000 m
  • a minimum vertical distance of 1,000 ft and horizontal distance of 1,500 m from cloud.

In the case of aeroplane operations in Class G at or below 3,000 ft or 1,000 ft above ground level (whichever is higher), the following minimum conditions were stipulated:

  • a flight visibility of 5,000 m
  • that the aeroplane shall be maintained clear of cloud and in sight of the ground or water

In addition to minimum visibility and distance from cloud, a pilot is also required to maintain a minimum height above the ground. CAR 157 details that a pilot in command must not fly the aircraft over:

  • any city, town, or populous area at a height lower than 1,000 ft; or
  • any other area at a height lower than 500 ft.

This does not apply if through stress of weather or any other unavoidable cause it is essential that a lower height be maintained.

Risks of flying in areas of reduced visual cues

The safety risks of VFR pilots flying from VMC conditions into instrument meteorological conditions (IMC)[13] are well documented. This has been the focus of numerous ATSB reports and publications, as VFR pilots flying into IMC represents a significant cause of aircraft accidents and fatalities. In 2013, the ATSB Avoidable Accidents series was re-published. Of these publications, the booklet titled Accidents involving pilots in Instrument Meteorological Conditions outlined that:

In the 5 years 2006–2010, there were 72 occurrences of visual flight rules (VFR) pilots flying in instrument meteorological conditions (IMC) reported to the ATSB…About one in ten VFR into IMC events result in a fatal outcome.

In another occurrence investigation,[14] the ATSB has found that the ‘continuation of flight towards an area of low cloud and rain was likely influenced by the inherent challenges of assessing low visibility conditions, particularly without instrument flying proficiency.’ This finding was based on the following references.

The United States National Transportation Safety Board (NTSB) (2005) found that ‘reduced-visibility weather represents a particularly high risk to [general aviation] operations’ and that ‘weather may…test the limits of pilot knowledge, training, and skill to the point that underlying issues are identified.’ The NTSB study also outlined that historically, about two-thirds of all general aviation (GA) accidents that occur in IMC are fatal, a rate much higher than the overall fatality rate for GA accidents.

Wiegmann and Goh (2000) explained that pilots may make errors in assessing the deteriorating weather conditions and decide to continue to VFR flight into the adverse weather. The previously mentioned NTSB report (2005) added that in these cases, pilots who might appear to intentionally engage in risky behaviour may actually be making choices that they mistakenly believe to be safe by underestimating the risks associated or overestimating their ability to handle the risks.

Wiggins and O’Hare (1995) further explained how errors in assessment can take place, acknowledging that weather-related decision making can be highly complex and therefore more prone to errors:

Because of the variable nature of operations in the aviation environment, weather-related decision making is often considered a skill that cannot be prescribed during training. Rather it is expected to develop gradually through practical experience. However, in developing this type of experience, relatively inexperienced pilots may be exposed to hazardous situations with which they are ill‑equipped to cope.

ATSB Aviation Research and Analysis Report B20070063, An overview of spatial disorientation as a factor in aviation accidents and incidents, stated that pilots should not attempt to fly into instrument meteorological conditions under the VFR. Pilots should develop a plan prior to take-off on what to do if the weather en route is different from that expected or deteriorates. This plan should consider a requirement to divert or turn back prior to entering instrument meteorological conditions. However, this depends on a pilot correctly assessing the weather conditions. The NTSB (2005) noted that targeted weather-related training programs have had some success in teaching pilots to recognise and respond to deteriorating weather conditions.

A cue-based training system called Weatherwise, was made available to pilots by the Civil Aviation Safety Authority (CASA). Additionally, CASA produced a Weather to Fly education program which focuses on topics such as the importance of pre-flight preparation, making decisions early, and talking to ATC.

One of the ATSB’s SafetyWatch priorities concerns in-flight decision making in relation to VFR flight in environments with reduced visual references. One of the key messages is for pilots to avoid deteriorating weather by conducting thorough pre-flight planning and to have alternate plans in case of an unexpected deterioration in the weather and making timely decisions to turn back or divert.

Spatial disorientation

Spatial disorientation is a type of loss of situation awareness, and is different to geographical disorientation, or incorrectly perceiving the aircraft’s distance or bearing from a fixed location. Spatial disorientation occurs when pilots do not correctly sense their aircraft’s attitude, airspeed or altitude in relation to the earth’s surface. In terms of an aircraft’s attitude, spatial disorientation is often described simply as the inability to determine ‘which way is up’, although the effects can often be more subtle than implied by that description.

Spatial disorientation occurs when the brain receives conflicting or ambiguous information from the sensory systems. It is likely to happen in conditions in which visual cues are poor or absent, such as in adverse weather or at night.[15] Spatial disorientation presents a danger to pilots, as the resulting confusion can often lead to incorrect control inputs and resultant loss of aircraft control.

Research on spatial disorientation indicates that, for pilots who are not instrument rated, loss of control will likely occur between about 60 seconds (Benson, 1988 in Gibb, Gray and Scharff, 2010) and 178 seconds on average (Bryan, Stonecipher, & Aron, 1954) after the loss of visual reference. These studies led to the FAA’s and CASA’s ‘178 seconds to live’ educational campaigns. Gibb, Gray and Scharff (2010) also stated that ‘spatial disorientation accidents have fatality rates of 90–91 percent, which indicates how compelling the misperceptions can be.’

Related Occurrences

There have been a number of accidents relating to VFR pilots flying into reduced visibility conditions. Many of these occurrences have been summarised in the research reports previously mentioned (B2005/0127 and AR-2011-050) as well as in ATSB accident reports (for example, AO‑2015-131 and AO-2016-006). Of particular interest are those occurrences where pilots have avoided an accident outcome by seeking assistance from other aircraft or from ATC. Of note are two occurrences that occurred on the same day in a similar location but with a very different outcome. See below for details.

ATSB Investigation AO-2017-061

On 16 June 2017, a Cessna Aircraft Company C172M, registered VH-FYN, was being operated on a private flight from Southport Mason Field, Queensland to Ballina Airport, New South Wales. The purpose of the flight was to ferry the aircraft to Ballina for scheduled maintenance. Enroute, near the town of Bangalow New South Wales, the aircraft entered an area of reduced visibility, including low cloud, fog and drizzle. The aircraft diverted off the initial track and was last seen disappearing into cloud heading inland. A short time later the aircraft collided with terrain and the pilot was fatally injured.

ATSB occurrence 201702740

On 16 June 2017, the pilot of a light aircraft was flying under VFR from Taree, New South Wales, to Southport, Queensland. While near Ballina, New South Wales the weather suddenly deteriorated and the pilot attempted to turn back to land at Coffs Harbor, New South Wales. However, the weather continued to close in, at which point the pilot reported to ATC that he was now flying in instrument meteorological conditions (IMC). ATC observed a sporadic radar return in the position described by the pilot and advised that the pilot gain altitude, which assisted with radar identification. ATC then guided the aircraft to Evans Head, New South Wales where the weather had cleared sufficiently for the aircraft to land safely.

__________

  1. The X designation is added to the engine model when used in the amateur built or experimental aircraft category.
  2. TGraphical Area Forecast (GAF) provides information on weather, cloud, visibility, icing, turbulence and freezing level in a graphical layout with supporting text. These are produced for 10 areas across Australia, broadly State-based.
  3. Broken cloud: used to describe an amount of cloud covering the sky of between five and seven oktas (eighths).
  4. Aerodrome Forecast (TAF): a statement of meteorological conditions expected for a specific period of time in the airspace within a radius of 5 NM (9 km) of the aerodrome reference point. The heights referenced in TAFs are heights above the aerodrome reference point (ground).
  5. Orographic cloud forms when airflow encounters a mountain or hill and is forced to rise. If the flow (air) is sufficiently humid, clouds form on the windward side of mountains and are called orographic clouds
  6. Observations for Lismore Airport, including for cloud, are automated using information from sensors only.
  7. ADS-B: Automatic Dependent Surveillance–Broadcast is a surveillance technology in which an aircraft determines its position via satellite navigation and periodically broadcasts it, enabling it to be tracked.
  8. Visual Meteorological Conditions (VMC): a meteorological condition in which visual flight rules (VFR) flight is permitted – that is, conditions in which pilots have sufficient visibility to fly the aircraft while maintaining visual separation from terrain and other aircraft.
  9. Instrument meteorological conditions (IMC): weather conditions that require pilots to fly primarily by reference to instruments, and therefore under Instrument Flight Rules (IFR), rather than by outside visual reference. Typically, this means flying in cloud or limited visibility.
  10. AO-2016-006 Loss of control and collision with water involving Piper Aircraft Corp PA-28-235, VH-PXD. A copy of this report is available from www.atsb.gov.au
  11. More information about spatial disorientation can be found in the ATSB aviation research and analysis report:
    B2007/0063, An overview of spatial disorientation as a factor in aviation accidents and incidents.

Safety analysis

Introduction

While en route from Evans Head, New South Wales, to Boonah, Queensland, the pilot of amateur-built Wittman Tailwind aircraft, registered VH-TWQ (TWQ), diverted to Casino, New South Wales, due to low cloud on the McPherson range. The pilot then took off after approximately fifty minutes on the ground and attempted to reach Boonah via a different route across the range. During the flight TWQ entered an area of reduced visibility. Approximately fifteen minutes after take-off TWQ commenced a series of rapid climbs and descents followed by a descending left turn which continued until TWQ collided with terrain.

Site and wreckage examination did not identify any defects or anomalies that might have contributed to the accident. Additionally, there was no evidence to support the pilot being incapacitated. Therefore, this analysis will focus on the examination of the factors that led to a visual flight rules (VFR) pilot entering an area of reduced visibility and losing control of the aircraft.

Decisions to depart Evans Head and Casino

After the Fly-In was called off due to the poor forecast weather the pilot and passenger elected to fly home to Boonah and Toowoomba. The pilot had attended the Fly-In event briefing that morning and was therefore aware of the local weather conditions and forecast. Neither the pilot’s nor the passenger’s family could identify a time pressure for the aircraft to return to Boonah and Toowoomba that day.

The relevant Graphical Area Forecasts did not preclude a departure under the VFR from Evans Head via Boonah to Toowoomba. However, they indicated the possibility of encountering areas of cloud, dust and rain in which visibility would reduce below that required for VFR flight. The inland route to Boonah, required the aircraft fly across the McPherson Range. Several of the peaks along this range are greater than 3,000 ft and a few are greater than 4,000 ft.

The generally south-south-easterly wind flow, heading towards the range, would have had the effect of pushing the weather up against the McPherson Range and reducing the visibility. So, while it was possible to depart under the VFR, the forecast conditions would have indicated that it was likely there would have been cloud on the ranges and have necessitated planning for an alternate route or diversion to avoid the area if the actual conditions reflected the forecast.

The pilot’s decision to depart the interim landing site can be interpreted as likely taking advantage of acceptable conditions at Casino with the notion that the weather further inland may have allowed for VFR flight over the ranges.

Once airborne, the pilot would have been in a position to assess the in-flight visibility and cloud and rain in the intended direction of travel. However, as discussed in the United States National Transportation Safety Board report (2005), it is possible that the continuation of flight towards the area of low cloud was influenced by the inherent challenges of assessing low visibility conditions.

The ATSB was unable to determine the pilot’s understanding of the weather conditions ahead of the aircraft prior to entering an area of low visibility conditions. However, the pilot had demonstrated an awareness of the risk posed by the weather and the need to maintain visual reference by diverting from the original track and turning back from the first attempt to cross the Ranges.

Development of the accident

Flying into an area of reduced visibility

The majority of the flight from Casino was conducted between 2,000 and 4,000 ft. Approximately 30 km north-west of Casino the aircraft began a climb over the first area of high ground. Terrain in this area is approximately 1,800 ft high. At about 1506, the aircraft reached a maximum altitude of 4,100 ft then entered a 600 ft/min descent where the groundspeed rapidly increased from 145 kt to 173 kt. It is likely that the pilot initiated the climb to clear terrain and then descended when the cloud conditions became unsuitable. This climb took TWQ above the forecast and observed cloud heights in the area, which indicated a cloud base of around 2,600 - 2,800 ft. The descent levelled out at 3,100 ft, and the terrain underneath was about 1,430 ft, allowing the pilot to continue the descent a further 1,670 ft and remain clear of the terrain, if the pilot was visual with terrain. It is possible that the pilot entered an area of deteriorating visibility at this time leading to the rapid descent and level off well above terrain.

From this point on, the pilot flew no lower than 3,100 ft, which was around the height of the some of the ridge lines in the area. It is therefore possible that the pilot was aware of the spot heights of terrain in the area and was attempting to stay above them.

At about 1508, in the vicinity of the Tooloom Fire Tower, the pilot commenced another climb. As the fire tower was in cloud, it is likely that the pilot entered an area of cloud during this climb. Flight data showed that the final turn and descent of TWQ was towards the high ground. The accident site was located near the top of the ridgeline. Either side of this ridgeline were areas of low ground, which the pilot could have manoeuvred towards if visual with terrain. The direction of turn as well as the descent and acceleration towards the terrain indicate the pilot was not visual with terrain at the time of the accident.

Spatial disorientation resulting from a loss of visual cues

Flight data from the last 4 minutes of the flight recorded the aircraft’s groundspeed speed varying between 109 and 175 kt. The aircraft’s rate of climb and descent varied between +2,400 ft/min and -2,400 ft/min. The aircraft’s altitude varied between 4,000 and 3,100 ft.

Of note, the speed recorded by the data is ground speed. Forecast winds for the area were up to 20 kt in the direction of travel of TWQ and could be considered all tail wind. If the actual winds were as forecast, the aircraft was being operated above the published manoeuvring speed limit of 130 kt indicated airspeed KIAS and likely up to the maximum structural cruising speed at some points.

The final data point showed the aircraft descending through 3,100 ft and travelling at 172 kt groundspeed. The aircraft was descending at 1,800 ft/min and was tracking towards the high ground.

The flight data from the last 4 minutes of flight was not consistent with normal operations of a Wittman Tailwind. The abrupt speed and altitude reversals and the operation of the aircraft over and near these speed limitations are indicative of a loss of control.

It is therefore likely that within 4 minutes of flying into conditions of reduced visibility, without adequate visual reference to the horizon, the pilot of TWQ became spatially disorientated leading to a loss of control and collision with terrain. It is possible that the pilot of TWQ was able to maintain some control initially upon entering cloud due to the pilot’s previous instrument flying experience. However, without recent experience and the training and qualification of an instrument rating the pilot was unlikely to have been able to maintain control in cloud for an extended period of time.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the loss of control and collision with terrain involving Wittman Tailwind, VH-TWQ, which occurred in Tooloom National Park, New South Wales, 12 January 2020.

Contributing factors

  • The pilot departed an interim landing site for Boonah under the visual flight rules with a high risk of encountering forecast cloud that reduced conditions below that required for visual flight.
  • It is likely the pilot encountered conditions of reduced visual cues and became spatially disorientated which led to a loss of control and collision with terrain.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Bureau of Meteorology
  • Civil Aviation Safety Authority
  • Airservices Australia
  • A number of witnesses
  • recorded data from Flightradar24 and OzRunways

References

Australian Transport Safety Bureau, 2011, Avoidable Accidents No. 4 Accidents involving Visual Flight Rules pilots in Instrument Meteorological Conditions, Aviation Research and Analysis publication AR-2011-050.

Australian Transport Safety Bureau, 2017, Loss of control and collision with water involving Piper Aircraft Corporation, PA-28-235, VH-PXD, AO-2016-006.

Benson, AJ, 1999a, “Spatial disorientation – general aspects”, in J Ernsting, AN Nicholson & DJ Rainford (Eds.), Aviation Medicine (3rd ed.), Oxford, England, Butterworth Heinemann, pp. 419-436.

Gibb, R, Gray, R and Scharff, L, 2010, Aviation Visual Perception: Research, Misperceptions and Mishaps, Ashgate Publishing Limited, Surrey, United Kingdom.

Newman, DG, 2007, An overview of spatial disorientation as a factor in aviation accidents and incidents, Australian Transport Safety Bureau, Aviation Research and Analysis Report B2007/0063.

National Transportation Safety Board 2005, Risk Factors Associated with Weather-Related General Aviation Accidents, National Transportation Safety Board Safety Study NTSB/SS-05/01, Washington DC, United States.

Wiegmann, D and Goh, J, 2000, Visual Flight Rules (VFR) Flight into Adverse Weather: An Empirical Investigation of Factors Affecting Pilot Decision Making, Federal Aviation Administration research DTFA 00-G-010, Illinois, United States.

Wiggins, M and O’Hare, D, 1995, “Expertise in Aeronautical Weather-Related Decision Making: A Cross-Sectional Analysis of General Aviation Pilots”, Journal of Experimental Psychology: Applied Vol. 1 No. 4, pp. 305-320.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • Family of the pilot
  • Civil Aviation Safety Authority
  • Fly-In Event Organiser
  • Fly-In Chief Marshall
  • Bureau of Meteorology
  • Coroner’s representative

Submissions were received from:

  • Bureau of Meteorology.

The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2021

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 11/03/2020

What happened

On 12 January 2020, at 1336 Eastern Daylight-saving Time,[1] the pilot of an amateur-built Wittman Tailwind aircraft, registered VH-TWQ (TWQ), departed Evans Head Airport, New South Wales, with one passenger on board (Figure 1). The pilot was conducting a private flight under the visual flight rules[2] from Evans Head, New South Wales to Boonah, Queensland.

The pilot flew in a north-north-westerly direction towards Boonah via the Richmond River valley. At 1353, the pilot commenced a 180° turn overhead the township of Kyogle and diverted south back down the valley to Casino aerodrome, landing at 1406.

At 1454, the pilot took off from Casino and flew in a west-north-westerly direction. At 1511, TWQ commenced a left turn and, shortly afterwards, collided with terrain. The pilot and passenger were fatally injured, and the aircraft was destroyed.

Figure 1: Flight tracks for VH-TWQ on 12 January 2020

Figure 2 - Flight tracks for VH-TWQ on 12 January 2020

Source: Flightradar24 and Google Earth, annotated by the ATSB

Recorded data

The aircraft was fitted with a Mode S transponder that broadcast ADS-B data. This information included the position and altitude of the aircraft and was received by Flightradar24 and provided to the ATSB. Also on board was a mobile device with the OzRunways application installed. This application provides the option for live flight tracking by transmitting the device’s position and altitude and that option was enabled for this flight. OzRunways information was also obtained by the ATSB. The data indicated that the aircraft was travelling at approximately 170 kt ground speed and in a descending left turn just prior to the collision with terrain.

Wreckage examination

The accident site was located in rainforest, about 72 km west-north-west of Casino, within the Tooloom National Park. Examination of the wreckage indicated that the aircraft collided with a number of trees before coming to rest on the rainforest floor at an elevation of 996 m (3,169 ft) (Figure 2).

Figure 2: VH-TWQ’s empennage at the accident site

Figure 3 - VH-TWQ’s empennage at the accident site


Source: ATSB

The aircraft’s structure was substantially disrupted, with the wreckage trail on an approximate east to west heading and covering a length of about 120 metres. All major components were located at the accident site. Due to the disruption of the airframe, the aircraft’s attitude when it entered the tree canopy could not be determined. There was no evidence of fire.

Pilot details

The pilot held a Private Pilot (Aeroplane) Licence and was qualified to fly by day under the visual flight rules. The pilot also held a single-engine aeroplane class rating. The pilot last conducted a single-engine aeroplane flight review in June 2018 that was valid until June 2020. His logbook indicated he had a total of about 1,200 hours flying experience. The pilot held a Class 2 aviation medical certificate that was valid until October 2021.

Weather conditions

Forecast meteorological conditions valid for the accident flight included visibility of 10 km or greater and broken[3] cloud from 3,000 to 6,000 ft above mean sea level. Isolated rain and thunderstorms were also forecast, with associated reduced visibility and lower cloud bases. Widespread smoke was also forecast due to bush fires in the area, reducing visibility to 1,000‑8,000 m.

Ongoing investigation

The investigation is continuing and will include examination of:

  • meteorological conditions and pre‑flight preparation
  • pilot qualifications, experience
  • recovered wreckage, aircraft performance characteristics and recorded flight data
  • aircraft maintenance documentation and operational records.

Acknowledgement

The ATSB acknowledges the significant assistance provided by the New South Wales Police Force during the on-site phase of this investigation.

The information contained in this update is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this update. As such, no analysis or findings are included. 

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Broken cloud is defined as cloud totalling 5 to 7 OKTAS meaning 5 to 7 eighths of the sky obscured by cloud.
  2. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) +11 hours
  3. Visual flight rules (VFR): a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.

Occurrence summary

Investigation number AO-2020-004
Occurrence date 12/01/2020
Location Tooloom National Park, 53 km east-north-east from Stanthorpe
State New South Wales
Report release date 02/03/2021
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category VFR into IMC
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer Amateur Built Aircraft
Model Wittman Tailwind W10
Registration VH-TWQ
Serial number 05-1305
Sector Piston
Operation type Private
Departure point Casino Airport, New South Wales
Destination Boonah Airport, Queensland
Damage Destroyed