On the 18 July 2022, at 2110 Coordinated Universal Time, a Qantas Airways Boeing 737-838, registered VH-VZO and operated as flight number QF933, departed Brisbane Airport, Queensland, on a scheduled air transport flight to Perth Airport, Western Australia. There were 174 people on board, including 2 flight crew members.
During the approach to Perth, air traffic control (ATC) advised the crew there were significant delays, over and above the promulgated estimated delay time, for arrivals into Perth. The aircraft did not have enough fuel to hold for the extra time and the flight crew declared a fuel MAYDAY. The aircraft was then given priority for the approach and landed with their final reserve fuel intact.
What the ATSB found
The ATSB found the aircraft had departed with the required fuel onboard. During the cruise, when the aircraft descended from flight level (FL) 340 to FL 280, the aircraft was not flown at the speed schedule displayed on the flight plan. This resulted in the aircraft using more fuel than planned. The fuel burn returned to the planned rate later in the flight however, the aircraft had used an extra 600–700 kg of fuel. Despite that increased usage, as the aircraft passed the decision point, there was sufficient fuel to continue the flight to Perth.
The ATSB also found that ATC had applied the required priority to the aircraft. However, the timing of the advice of airborne delay greater than the promulgated estimate of 10 minutes resulted in the aircraft being unable to land with the required fuel reserve. This left the flight crew with no other option than to declare a fuel MAYDAY to receive priority landing and preserve their required fuel reserve.
Safety message
Sophisticated flight planning and monitoring systems allow fuel usage and aircraft movement to be accurately determined. While operational requirements may necessitate deviation from the plan, this incident illustrates that decisions by flight crew and air traffic controllers that result in higher‑than‑planned fuel usage can reduce available airborne options.
Where flight crew find that they may not have the required fuel reserve, it is vital, as in this case, that flight crew alert air traffic control and if necessary, declare a Fuel MAYDAY. This will ensure that the aircraft receives priority during the approach, preventing an unsafe situation from developing.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
At 2110 Coordinated Universal Time on 18 July 2022, a Qantas Airways Boeing 737-838, registered VH-VZO and operated as flight number QF933, departed Brisbane Airport, Queensland, on a scheduled air transport flight to Perth Airport, Western Australia (Figure 1). There were 174 people on board, including 2 flight crew members.
Due to significant forecast headwinds, the flight was planned to fly south of the direct path, overhead Mildura, Adelaide, across the Great Australian Bight, then to Perth and estimated to take 5 hours and 30 minutes. Early in the cruise, the aircraft encountered stronger headwinds than forecast so the flight crew contacted air traffic control (ATC) and requested, and received, a clearance to fly slightly north of the planned track.
The aircraft was descended earlier than planned from flight level (FL) 340[1] to FL 280, due to turbulence and to also take advantage of lesser headwinds and remained at this level as it passed Adelaide.
Figure 1: Flight path
Source: Google Earth with Flightradar 24 data, annotated by ATSB
At this stage of the flight, the flight crew identified that they were using more fuel than planned and discussed diverting to Adelaide to load more. However, as they would be required to hold while they used fuel to reduce the aircraft’s weight to under the maximum landing weight, and they had sufficient fuel to continue to the destination, they decided to continue to Perth.
To assist their in‑flight planning, the crew assessed the wind speeds using an application on an iPad and requested reports of actual wind strength from flight crew in other aircraft, flying at different altitudes. As they were crossing the Great Australian Bight, they received a report from another crew, advising that the wind at FL360 was about 15 kt less than forecast and consequently they climbed from flight level (FL) 280 to FL 360, again, earlier than planned.
Subsequently, they discussed diverting to Kalgoorlie to load more fuel. However, due to the runway length at Kalgoorlie, they would still be required to hold to reduce the aircraft’s landing weight. The weather forecast for Kalgoorlie was also showing an INTER,[2] where the visibility was reduced to 5,000 m in rain with broken cloud[3] at 800 ft. Consequently, as they still had the required fuel to fly to Perth, they elected to continue.
As they passed the decision point all engines (DPA),[4] they again assessed that as there were no fuel‑related weather requirements at Perth and that they had sufficient fuel on board to continue the flight.
The flight crew continued to request, and receive, track shortening from ATC. Later in the cruise, ATC advised the crew there were significant delays for arrivals into Perth and they could expect around 13 minutes delay before passing BEVLY, a waypoint[5] on the arrival procedure (Figure 2). ATC instructed the crew to reduce to minimum speed and to temporarily turn off-track to delay the BEVLY passing time. The crew had estimated passing BEVLY at 0226 and asked ATC for the expected passing time and were subsequently advised it would be 0242. They advised ATC that they were carrying 10 minutes of traffic holding fuel, which was required for traffic holding at Perth. As such, they could cross the waypoint at 0236 however, they did not have enough fuel on board to cross BEVLY at 0242. They also advised they would need to remain at altitude until they passed HAMTN, a waypoint on the arrival procedure, and to descend at 230 kt in a continual descent to conserve fuel.
ATC advised the flight crew that the order of aircraft in the arrival sequence could not be changed unless they declared a fuel MAYDAY, which the crew subsequently did. The aircraft was then given priority for the approach.
Figure 2: Approach path
Source:Google Earth with Flightradar 24 data, annotated by ATSB
Prior to the approach, the crew briefed on the procedures for a low fuel warning.[6] During the approach, they received a FUEL LOW warning for the right fuel tank when there was about 930 kg of fuel remaining in the tank. The crew followed the non-normal checklist and selected the cross‑feed selector to OPEN and selected fuel pumps to ON. This resulted in fuel being used primarily from the right fuel tank.[7] The low fuel warning activated for the left fuel tank 38 seconds prior to landing. At that stage, there was 676 kg of fuel remaining in the right fuel tank.
The aircraft landed at Perth at 0248 with the required final reserve fuel intact plus 300 kg of fuel, 5 hours and 38 minutes after take-off.
Context
Flight plan
The flight was planned using the operator’s flight planning system. Fuel for the following was included:
taxi
trip (take-off, climb, cruise and descent to 1,500 ft above Perth)
departure allowance to set heading (see the section titled Operator requirements)
contingency fuel (see the section titled Contingency fuel)
10 minutes of fuel for traffic holding at Perth (see the section titled Traffic holding fuel)
approach (see the section titled Operator requirements)
final reserve fuel (see the section titled Final reserve fuel)
extra fuel (see the section titled Operator requirements)
The crew advised that 300 kg of freight was removed from the aircraft to allow the minimum flight planned fuel amount to be carried. The weather forecast for the flight's arrival time was such that no extra fuel was required for weather holding, nor was an alternate airport required.[8]
Contingency fuel
According to the Civil Aviation Safety Regulations (CASR) Part 121 manual of standards (MOS) section 7.03, contingency fuel is ‘the amount of fuel required to compensate for unforeseen factors’. Further, Part 121 MOS subsection 1.04 definitions (1) defined unforeseen factors as
factors that could have an influence on an aeroplane’s fuel consumption to the planned destination aerodrome, including:
(a) the aeroplane’s deviation from the expected fuel consumption data for an aeroplane of that type; and (b) extended delays and deviations from planned routings or cruising levels.
The contingency fuel for a turbine-engine aircraft where a point of in-flight replanning is specified,[9] must include the higher of either:
5% of the trip fuel from the in-flight replanning point to the planned destination,[10] or
not less than the amount of fuel required to fly, in ISA[11] conditions, for 5 minutes at holding speed, at 1,500 ft above the planned destination.
The flight plan included fuel to fly for 5 minutes at 1,500 ft, as this was the greatest amount.
Traffic holding fuel
The Aeronautical Information Package En-route supplement provided an estimate for delays for flights into Perth. This stated that at the time the flight was due to land, they could expect up to 10 minutes airborne delay. This was an advisory time only and the actual holding time could vary.
The flight plan included 10 minutes holding fuel.
Final reserve fuel
A turbine-engine aeroplane is required to carry 30 minutes of fuel to allow the aircraft to fly at holding speed, at 1,500 ft above the aerodrome elevation. This must be available at the completion of the flight.
Operator requirements
The operator’s procedures provided a fuel allowance including:
a departure allowance to allow for a departure from an airport where a known lengthy departure procedure is required prior to joining the flight planned track.
an approach allowance of 300 kg of fuel.
Qantas also had a requirement that a Boeing 737 aircraft have 2,700 kg or 70 minutes of fuel when they arrived overhead the destination airport, whichever was greater. This amount was inclusive of the required contingency, traffic holding, approach and final reserve fuel. Once the aircraft had departed, there was no requirement to preserve the extra fuel to meet this pre‑flight requirement.[12]
The flight plan included almost 700 kg to fulfill this requirement.
Operator fuel planning procedures
According to the operator’s fuel planning procedures, the pilot in command (PIC) should only order discretionary fuel to cater for a known, but unplanned, operational reason. If the PIC believed payload should be offloaded to allow for extra fuel, they were required to consult with the integrated operations centre (IOC), who would assess the commercial implications. They were also required to submit a pilot report.
The pilot advised that as they had the required minimum fuel for the flight, they did not offload any further freight to load extra fuel. They advised if there had been space, they may have added extra fuel. They also advised that if they had decided to take extra fuel, they were confident they would not have encountered any pressure from management. They advised that since the COVID-19 pandemic began, Qantas management had advised flight crews to take their time when conducting pre-flight planning and to take extra fuel if they thought it was required.
Cost index
The cost index (CI) is the ratio between the operating cost of an aircraft and the fuel burn. The lower the cost index the slower the flight and therefore the lower the fuel burn, however the aircraft will be operating longer. Consequently, it will have a higher operating cost. The CI for the maximum range is 0.
Qantas flight administration manual advised that the cost index:
provided on the flight plan is derived from a number of data sources and policy requirements. Based on variations in operating conditions for each flight, the cost index balances various interrelated costs to minimise the total operating expense of the flight. While the pilot in command may vary the cost index, this should only be done based on sound command and commercial judgement.
The CI should be entered into the flight management computer (FMC) during the preparation for the flight and the aircraft should be climbed, cruised and descended[13] at the FMC generated ECON[14] speed/ Mach number. The CI on the flight plan for this flight was 10. The flight crew was required to enter this figure into the FMC prior to the flight.
Flight planning system
The Qantas flight planning system was designed to search for the most efficient route for the flight. The system would select enroute descents and climbs to take account the changing weight of the aircraft and the forecast wind. It would also display the Mach number[15] required for the most efficient cruise at the planned altitude, for the selected cost index. The flight plan showed the forecast wind for 1 flight level above and 2 flight levels below the planned flight level.
The flight plan also displayed the decision point all engines (DPA) (among other relevant decision points) with the expected fuel remaining and the minimum fuel required to fly from this point to the destination. The flight plan showed that the minimum fuel required at the DPA to continue to Perth was 2,600 kg.
Boeing flight plan check
The ATSB did not have access to flight planning software to check the accuracy of the Qantas fuel plan. As such, The Boeing Company (Boeing) was contacted to prepare an independent flight plan, using the forecast weather data. Boeing subcontracted the flight planning to another company. However, their software did not allow them to enter the actual forecast winds over the entire flight plan and consequently they used an average wind vector for the flight. Their flight planning system calculated that the required flight fuel[16] was 15,211 kg. The flight plan produced on the day by the Qantas flight planning system calculated that the flight fuel[17] required was 15,190 kg.
Flight plan track versus actual track
The ATSB downloaded the data from the aircraft’s flight data recorder. Figure 3 shows verified flight data for certain recorded parameters during the flight. The data showed the:
aircraft took off with approximately 170 kg more fuel than planned.
flight crew selected VNAV[18] speed during the climb segments.
flight crew selected speed on the master control panel to control the speed during descent.
FMC generated speed was utilised during the cruise segments.
At approximately 2242, the aircraft descended earlier than planned from FL 340 to FL 280, following assessment of the actual winds. The crew then engaged the FMC for the cruise at FL 280, however, the Mach number did not reduce to that planned, resulting in the aircraft using more fuel than expected in the flight plan.
Figure 3: QF933 flight data
Source: ATSB
The data also showed that at 2348, when the aircraft climbed early from FL 280 to FL 360, the aircraft had approximately 800 kg of fuel less than planned. The actual fuel burn then reduced while the aircraft was flown at a higher level than planned however, the fuel quantity remained approximately 600/700 kg below the planned level for the remainder of the flight.
The review also identified that the Cost Index parameter was not correctly recorded in the flight data.[19]
Table 1 shows the planned Mach number versus the average Mach number for the different altitudes flown.
Table 1: Planned Mach number versus the average Mach number flown
Elapsed time (hr)
Altitude (ft)
Planned Mach
Average Mach
0.37 – 1.47
34,000
0.785
0.792
1.55 – 2.59
28,000
0.713
0.770
3.08 – 4.05
36,000
0.781
0.792
4.14 – 4.50
38,000
0.782
0.788*
*Before speed reduction for sequencing into Perth
The fuel plan in the FMC identified to the flight crew that the aircraft was using more fuel than planned during the first part of the flight and then later in the flight, returned to approximately the expected fuel burn (Figure 4).
Figure 4: Fuel plan as displayed in the aircraft flight management computer
Source: Operator, annotated by ATSB
Data supplied by Qantas showed that at the DPA (KATHI) there was 2,800 kg of fuel remaining on board.
Adherence to the flight plan
The Qantas Flight administration manual (FAM) stated:
Subject to airmanship and other operational influences flight crew are to utilise mid-segment climb (MSC)….
No deviations from flight plans are to be initiated by the pilot in command other than those occasioned by normal operational requirements (e.g. deviations due to weather, safety considerations, etc.).
The operator confirmed that they would expect a flight crew to deviate from a flight plan where there were operational reasons to do so. They also advised that the crew was expected to fly the appropriate speed for the selected level - generally this would be the FMC generated ECON speed for the flight planned cost index.
Perth Airport forecast
The terminal area forecast for Perth at the time of arrival showed that from 2300 the wind was from 100° at 8 kt with visibility greater than 10 km, showers of rain, scattered cloud at 1,500 ft and broken cloud at 2,500 ft.[20] From 0300 on the 18 July, the wind was from 150° at 8 kt with visibility greater than 10 km, no significant weather and scattered cloud at 3,000 ft.
The alternate minima for Perth were a cloud base of 400 ft and 1,600 m visibility.[21]
Air traffic arrival sequence
As the air traffic flow management system[22] was not in operation at the time of this occurrence, there were no pre‑arranged arrival times into Perth.
In accordance with AIP Enroute 1.4 – 8 Assessment of Priorities, during the approach, an aircraft with an emergency will get priority in all circumstances. ATC will then apply priority to ‘an aircraft which is first able to use the desired airspace in the normal course of its operation. Consequently, regardless of where an aircraft departed from, they would be placed in the arrival sequence for an airport in order of their actual time of arrival at the relevant approach points. ATC then used speed control, vectoring or holding to achieve an orderly flow of aircraft.
Order of landing
Table 2 shows the order of landing and the delays[23] applied around the time QF933 arrived.
Table 2: Aircraft order of landing when QF933 landed
Aircraft
Departure
Estimated time due (UTC)
Actual time landed (UTC)
Delay
F100
Paraburdoo
0237
0244
392 seconds
B737 (QF933)
Brisbane
0242
0248
400 seconds
F100
Bunbury
0241
0251
607 seconds
F100
Newman
0247
0253
369 seconds
A320
Newman
0244
0256
725 seconds
DHC-8
Golden Grove
0244
0302
1045 seconds
F100
Coondewanna
0248
0304
975 seconds
QF933 received an actual delay of 400 seconds (6.67 minutes), however they had been allocated a delay of 16 minutes at BEVLY.[24]
Emergency fuel state
Civil Aviation Safety Regulations Part 121 MOS 7.08 stated that the pilot in command (PIC) should advise ATC of a minimum fuel state if they are committed to land at an airport and where any changes to the clearance will result in the aircraft landing with less that the final reserve fuel. The MOS also stated that the flight crew should not expect any form of priority handling as a result of declaring minimum fuel.
Where the PIC has calculated that the aircraft will land with less than the final reserve fuel, the flight crew
must declare a situation of ‘emergency fuel’ by broadcasting ‘MAYDAY MAYDAY MAYDAY FUEL’.
As this is a distress message, the aircraft will be given priority to land.
Safety analysis
The Boeing 737-838 departed Brisbane on a scheduled air transport passenger flight to Perth with the operator‑required minimum fuel onboard. The planned flight fuel was verified independently as being sufficient for the flight. The fuel plan included extra fuel to meet the Qantas requirement that a 737 arrive at 1,500 ft above the destination airport with 2,700 kg or 70 minutes of fuel.
During the cruise segments, a Mach number faster than the planned value was flown, resulting in the aircraft using approximately 700–800 kg of extra fuel in the first part of the flight. The FMC was most likely selected to the ECON speed, which will use the selected cost index to set the best economy speed. The ATSB could not verify what cost index value was selected by the flight crew prior to the flight, as this parameter was not correctly recorded in the flight data.
During the flight, the flight crew detected the extra fuel burn and after consultation with a flight crew in another aircraft climbed the aircraft early. While this resulted in the aircraft having a stronger headwind, the fuel burn reduced to approximately the planned rate.
As the aircraft passed the decision point all engines, the crew assessed that, while less than the planned amount, they had enough fuel to meet the requirements and continued to Perth. They were later advised by air traffic control (ATC) that longer than expected traffic delays were anticipated and they would be delayed by approximately 16 minutes.
A review of the Airservices Australia data indicated ATC had applied the required priority to the aircraft. However, the airborne advice from ATC that the aircraft’s approach would be delayed for longer than the promulgated advisory of 10 minutes, resulted in the aircraft having insufficient holding fuel. Additionally, at the time of that advice the aircraft was relatively close to Perth so there was no opportunity for the crew to reduce fuel consumption by any significant amount over the remaining flight time to comply with the increased holding.
This left the flight crew with no other option than to declare a fuel MAYDAY to receive priority landing and preserve their required fuel reserve.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the fuel MAYDAY declaration involving Boeing 737-838, VH-VZO abeam Wave Rock, Western Australia on 18 July 2022.
Contributing factors
When the aircraft changed flight levels during the cruise, the speed for the lower altitude specified in the flight plan was not flown, resulting in a higher fuel burn than planned, although still sufficient to meet the requirements of the flight as the aircraft passed the decision point.
As the aircraft approached Perth, the crew received a delayed arrival time over and above the published 10 minutes estimated airborne traffic delay, resulting in insufficient fuel to meet the extended delay. This necessitated the declaration of a fuel MAYDAY as the aircraft would have landed with less than the required fixed fuel reserve.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the flight crew
Qantas Airways Pty Ltd
Airservices Australia
The Boeing Company
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the flight crew
Qantas Airways Pty Ltd
Airservices Australia
United States National Transportation Safety Board
The Boeing Company.
Submissions were received from:
the flight crew
Qantas Airways Pty Ltd
Airservices Australia
Civil Aviation Safety Authority
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 340 equates to 34,000 ft.
[2] INTER: an intermittent deterioration in the forecast weather conditions, during which a significant variation in prevailing conditions is expected to last for periods of less than 30 minutes duration.
[3] Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – ‘broken’ indicates that more than half to almost all the sky is covered.
[4] Decision point all engines: The waypoint or waypoints nominated on the flight plan, but not beyond the top of descent, from which the aircraft may divert to a different airport with all engines operating while meeting all inflight fuel requirements.
[5] Waypoint: A defined position of latitude and longitude coordinates, primarily used for navigation.
[6] Due to a Federal Aviation Administration requirement for a low fuel alert when there was 45 minutes of fuel remaining, Boeing had set this alert at 907 kg of fuel remaining in each fuel tank.
[7] The fuel pumps in the aeroplane have allowable variations in output pressure. If there is a sufficient difference in pump output pressures and the cross-feed valve is opened, fuel feeds to the operating engines from the fuel tank with the highest pump output pressure. This may result in fuel unexpectedly coming from the tank with the lowest quantity.
[8] Qantas had a dispensation under arrangements allowing operators to transition from legacy fuel requirements to the requirements of CASR Part 121 (which came into effect on 2 December 2021). This dispensation allowed Qantas to operate under their previous permission in relation to alternate aerodrome requirements and a fuel operational variation. This meant that on the occurrence flight a destination alternate aerodrome was not required, whereas it would have been required for a Part 121 operation. This also allowed Qantas to operate without the 15 minutes holding fuel required under section 7.02 where the destination aerodrome did not require an alternate aerodrome.
[9] Point of in-flight replanning is a point en-route, determined by the operator before the flight commences, at which the aeroplane can:
(a) if it arrives at the point with adequate fuel to complete the flight to the planned destination aerodrome while maintaining the required fuel—continue to that aerodrome; or
(b) otherwise—divert to an en‑route alternate aerodrome while maintaining the required fuel.
[10] Qantas have advised that their flight planning software has not been updated and calculated 10% of the trip fuel from the in-flight replanning point to the planned destination.
[11] International Standard Atmosphere (ISA): hypothetical meteorological conditions that provide standard temperatures and pressures at specified altitudes. ISA conditions are used as a datum for calculating aircraft performance data.
[12] This did not remove the requirement that all regulated fuel requirements must be preserved during the flight.
[13] During the descent, when the aircraft goes below 5,000 ft above ground level, the maximum speed is 250 kt.
[14] The ECON speed uses CI as an input that is based on a detailed accounting of actual costs.
[15] The ratio between the true air speed (TAS) and the local speed of sound (LSS). This ratio, which equals one when the TAS is equal to the LSS, is known as the Mach Number (M) and is very important in aircraft operating at high speed.
[16] Flight fuel included fuel from commencement of take‑off to Perth Airport.
[17] Qantas flight fuel included fuel from commencement of take‑off to 1,500 ft at the destination.
[18] When VNAV is selected, the autopilot will fly the FMC‑programmed speed.
[19] Qantas advised the parameter for the cost index was not recording correctly for all flights.
[20] Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – ‘scattered’ indicates that cloud is covering between a quarter and a half of the sky.
[21] As the flight was operating under the Qantas fuel dispensation, they were not required to comply with the alternate minima requirements for Part 121. For a Boeing 737 aircraft these would be a cloud ceiling of 1,200 ft and visibility of 5,000 m.
[22] Air traffic flow management is a system where depending on the forecast traffic, aircraft are given a departure time to ensure a managed traffic flow to an airport and to reduce airborne delays.
[23] Airservices Australia calculate the flight delay by comparing the estimated flight time (using nominal system track information and nominal aircraft performance data for specific aircraft types) and actual flight time for the portion of the flight within 250 NM of the destination aerodrome.
[24] The flight crew advised the FMC‑generated time of arrival at BEVLY was 3 minutes earlier than the estimate ATC had in their system, possibly due to the track shortening requested by the flight crew and approved by ATC.
Occurrence summary
Investigation number
AO-2022-035
Occurrence date
18/07/2022
Location
Abeam Wave Rock
State
Western Australia
Report release date
08/06/2023
Report status
Final
Investigation level
Short
Investigation type
Occurrence Investigation
Investigation status
Completed
Mode of transport
Aviation
Aviation occurrence category
Fuel - Other
Occurrence class
Incident
Highest injury level
None
Aircraft details
Manufacturer
The Boeing Company
Model
737-838
Registration
VH-VZO
Serial number
34191
Aircraft operator
Qantas Airways
Sector
Jet
Operation type
Part 121 Air transport operations - larger aeroplanes
Section 21 (2) of the Transport Safety Investigation Act 2003 (TSI Act) empowers the ATSB to discontinue an investigation into a transport safety matter at any time. Section 21 (3) of the TSI Act requires the ATSB to publish a statement setting out the reasons for discontinuing an investigation.
Overview of the investigation
The occurrence
On 13 July 2022 at about 0716 local time, V/Line passenger train 8070 departed Echuca on a scheduled service to Southern Cross Station, Melbourne, via Bendigo in Victoria (Figure 1). The 3-car VLocity DMU was operating on the V/Line regional broad gauge network. On board were the driver, conductor and about 40 passengers. The train was scheduled to arrive at Goornong station at 0808. By rail, Goornong was about 28 km before the stop at Bendigo.
Figure 1: Broad gauge rail route from Echuca to Bendigo
Source: Nearmap, annotated by the Office of the Chief Investigator (OCI)
On the morning of the incident, a farmer whose property was located near Goornong was expecting a truck to collect and transport a load of hay to Mansfield. Arrangements had been made for a truck from a local truck depot to use a gated level crossing which provided a route between the Midland Highway and the unsealed Railway Road on the other side of the railway (Figure 2). This level crossing was referred to as the Holmes Road level crossing, although it was not on Holmes Road, which was further north.
Figure 2: Holmes Road level crossing and local area
Source: Google maps, annotated by OCI
The Holmes Road level crossing was about 700 m from the farmhouse and hay shed. In preparation for the truck’s arrival, a farm worker attended the crossing. They opened the gates then returned to the farm leaving the level crossing unattended.
Travelling north along the Midland Highway, the truck arrived at the left turn for the side road to the level crossing at about 0804. The truck’s driver had not previously used this crossing. As the truck commenced the turn, train 8070 was approaching from the north on the single bi-direction track and was about 400 m from the crossing. The truck driver recalled monitoring road traffic approaching from behind as they made the turn and did not observe the approaching train at this point. The driver of train 8070 saw the truck turn and travel towards the level crossing.
After turning their truck onto the short, unsealed road which joined the Midland Highway to Railway Road, the truck driver observed that the gates on either side of the crossing were open, and they had clear access across the crossing (Figure 3). The truck driver recalled that they had been told to expect closed gates on their way to the farm and was surprised to find open gates. The truck then proceeded towards and onto the level crossing. Its driver recalled not seeing the train until the last moment before the collision.
Figure 3: View from truck as it approached the Holmes Road level crossing
Source: Still image from the truck’s video camera, annotated by OCI
The train approached the crossing travelling at about 74 km/h which was below the permitted speed of 80 km/h. The train’s event recorder indicated that the train’s horn was sounded when the train was about 230 m from the crossing and again when about 70 m from the crossing. The truck driver did not recall hearing the train horn.
On seeing the truck drive onto the crossing, the train driver made an emergency brake application. This slowed the train to about 63 km/h before the train collided with the side of the truck. It then travelled a further 90 m before coming to a stop (Figure 4).
Figure 4: The front of train 8070 following impact, looking back towards the crossing
Source: OCI
The collision resulted in significant damage to the front of the train and the derailment of its leading car. Its driver sustained minor injuries. There were no reported injuries to passengers or the conductor.
The truck’s prime mover and trailer were separated and damaged in the collision, and the driver of the truck was seriously injured.
The Holmes Road level crossing
The level crossing was at the intersection of a 6 m wide unsealed road and a single bi‑directional track, about 50 m from the Midland Highway. The approach to the turn‑off from the highway (as taken by the truck) was equipped with standard road signage identifying the presence of the crossing on the side road ahead.
On the truck’s approach to the crossing (from the east), the truck driver’s view of the approaching train was largely unobstructed although a small number of self-seeded trees restricted some views on the approach. Near the crossing, the view of an approaching train was not impeded (Figure 5).
Figure 5: View from eastern gate towards the approach direction of train 8070
Source: OCI
Protection at the crossing included railway crossing identification signage, give way signs and a lockable single swing gate on each side of the crossing to restrict access. Railway crossing and give way signage was located between each gate and the track, with some signage on the east side being knocked over in the incident (Figures 6 and 7).
Figure 6: The crossing when approached from the east, with some signage knocked over
Source: OCI
Figure 7: The undamaged crossing signage on the west side of crossing
This image shows the signage between the gate and track on the western side of the crossing, with the closed eastern gate on the other side of the track in the background. Prior to the collision, the same signage was present on the east side, facing the truck as it approached. Source: OCI
The lockable swing gates were installed at the crossing in 2013 and were a frangible design.[1] Frangible gates allow vehicles to push through the gates in the case of an emergency such as bushfire. Signage on the gates indicated train running information should be sought for transferring livestock or heavy machinery. V/Line advised that this instruction was not intended to apply to normal vehicle traffic including trucks.
The installation of lockable gates followed V/Line consultation with the local shire council and community on the potential for closing the crossing. The gated solution was adopted to restrict access following community opposition to proposed crossing closure. The installed gates were in addition to pre-existing passive give way signage.
To manage use of the crossing, licence agreements were established between V/Line and several farmers in the area.[2] Each agreement nominated authorised users which allowed use of the crossing under conditions set out in the agreement. Keys to the gate’s locks were provided to each of the authorised users.
The agreement described that an authorised user was expected to unlock and open each gate, drive their vehicle across the rail line clear of the track, and return to close and lock both gates. V/Line advised that training in the use of the gates was also provided at the time the licence agreements were established.
Frangible gate level crossings at other locations
There were 6 other level crossings on the V/Line network identified as having frangible gate arrangements. Two of these were located on the Ballarat to Ararat rail line and 4 were located on the Ballarat to Maryborough line. Their local environment, infrastructure configuration and usage arrangements varied.
Restricted-access crossings
The V/Line regional network contained about 450 level crossings which had some form of restricted access or private usage. A large subset of these crossings were occupation crossings which provided access between 2 parcels of land.[3] The Holmes Road level crossing was not an occupation crossing. However, its restricted access and user arrangements placed it within this broad group of restricted-access crossings.
Summary of observations
The review of evidence identified that:
Lockable gates were added to the Holmes Road level crossing in 2013 to restrict its usage. The gates supplemented pre-existing passive level crossing signage.
On the day of the collision, the gates at the Holmes Road level crossing were opened in preparation for the arrival of a truck. The crossing was then left unattended.
The truck subsequently entered the level crossing into the path of train 8070. The driver of the truck did not see the train and was possibly distracted by their lack of familiarity with the gated arrangement and surprise at finding the gates open.
The train was observable from the truck during its turn from the Midland Highway and nearer the crossing. Self-seeded trees restricted the view to the track on part of the truck’s approach.
The V/Line network had about 450 restricted-access crossings including occupation crossings and other private crossings.
Safety actions taken since the event
Following the collision at the Holmes Road level crossing, several safety actions associated with frangible gate crossings have been taken by V/Line. The Holmes Road level crossing has been permanently closed, and a V/Line review identified that 4 of the 6 other frangible gate crossings should be considered for closure. One of these 4 has subsequently received funding to progress its closure.
V/Line has also developed a new level crossing management strategy and associated plan to enhance level crossing safety across regional Victoria.[4] The strategy contains 11 objectives across 3 strategic themes, with several objectives relevant to safety at restricted-access crossings. The plan identifies the further inspection and review of all occupation and private crossings over a 5-year period. The plan also describes the potential use of new technologies for warning systems at such crossings and identifying opportunities for crossing closures.
Reasons for the discontinuation
Based on a review of investigation evidence and the subsequent safety actions taken by V/Line, further investigation is unlikely to yield additional important safety lessons. Consequently, the ATSB has discontinued this investigation.
The evidence collected during this investigation remains available to be used in future investigations or safety studies. The ATSB will also monitor for any similar occurrences that may indicate a need to undertake a further safety investigation.
[1]A frangible gate is equipped with fusible link hinges which break to allow emergency escape or access.
[2]The licence agreement between V/Line and the farmer involved in the incident was dated 27 November 2013.
[3]Occupation crossings were historically granted to a landowner under Section 36 of the Lands Compensation Statute 1869 Vic. Rights also exist under subsequent legislation.
[4]The V/Line strategy developed in 2025 considers the Code of Practice – Train Visibility at Level Crossings, released by the Office of the National Rail Safety Regulator (ONRSR) in December 2024.
Preliminary report
Report release date: 19/09/2022
This preliminary report details factual information established in the investigation’s early evidence collection phase, and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
Prior to the incident
On 13 July 2022 at about 0716, V/Line passenger train 8070 departed Echuca on a scheduled service to Southern Cross Station in Melbourne via Bendigo (Figure 1). The three-car VLocity Diesel Multiple Unit (DMU) was operating on the regional broad gauge line. Onboard were the driver, conductor and 40 passengers.
Figure 1: Broad gauge rail route from Echuca to Bendigo
Source: e-way street directory, Melway 2017, annotated by Chief Investigator, Transport Safety (Victoria)
That same morning, a property owner (farmer) north of Bendigo and near Goornong was expecting a truck to collect and transport a load of hay. The farmer had engaged a local transport company and arrangements were made for the truck to use the Holmes Road level crossing that was near the farm. Use of this crossing provided a route between the Midland Highway and Railway Road on which the farm was located.
The Holmes Road level crossing was a gated, passive level crossing that was not available for normal public access. The gates on both sides of the crossing were fitted with locks, and keys had been provided to authorised property owners.
The farmer reported attending the Holmes Road level crossing shortly before the expected arrival of the truck, unlocking and opening the gates and then returning to the hay shed on their property.
The incident
The truck driver had been instructed to proceed to the farm to load hay for delivery to Mansfield. They travelled north along the Midland Highway from a nearby transport depot and turned left at the access road to the Holmes Road level crossing. Arriving at the level crossing, they found the gates open, and proceeded onto the crossing.
Train 8070 was scheduled to arrive at Goornong Railway Station at 0808. The train driver reported that, on approaching the level crossing, they could see the truck turning off the Midland Highway towards the crossing. With the train travelling at about 70 km/h, the train driver sounded the horn and expected the truck to stop. When it did not, the train driver made an emergency brake application and was in the process of turning their seat away, when the train impacted the truck.
The impact resulted in the derailment of both bogies on the leading car of the train. The lead rail car and the track infrastructure were extensively damaged. The train driver sustained minor injuries. There were no injuries to the passengers on the train.
The truck driver was seriously injured in the collision. The truck was severely damaged, with the semi-trailer separating from the prime mover (Figure 2).
Figure 2: Rear of train, prime mover and semi-trailer of truck after collision
Source: Chief Investigator, Transport Safety (Victoria)
Context
Location
Goornong is about 28 km north of the city of Bendigo in Victoria and the Holmes Road level crossing is about 5 rail-km north of the Goornong Railway Station (Figure 1).
Level crossing
The Holmes Road level crossing connected the Midland Highway and an unsealed local road named Railway Road that ran parallel to the rail track on its western side. Although Holmes Road was about 950 metres north of the level crossing and did not intersect the rail track or the Midland Highway, the crossing was designated the Holmes Road level crossing for V/Line identification purposes.
The Holmes Road level crossing was located about 2.4 km from the transport depot and about 700 m from the hay shed access road that was on the opposite side of the railway (Figure 3).
Figure 3: Location of Holmes Road level crossing
Source: Google maps, annotated by Chief Investigator, Transport Safety (Victoria)
Crossing protection
In 2013, V/Line equipped the level crossing with lockable gates. To provide limited access to the level crossing, V/Line had a formal agreement with local property owners. The agreement provided authorised users access to the level crossing under conditions set out in the agreement, and keys to the gates of the crossing were provided to those authorised users.
The crossing road was about 6 m wide and a single swing gate was installed across the road on either side of the railway. The gates were fitted with signage that included a notice with a telephone number to call before transferring livestock or heavy machinery, a reference number for the level crossing and to advise train control when the crossing was clear.
The level crossing was also fitted with signage typical of a passive (give way) level crossing. The Australian Standard 1742.7[1] specified the signage requirements. W7-12[2] and RX-8[3] signs were located on the Midland Highway before the turn-off to the level crossing (Figure 4).
Figure 4: Signage on approach to and at the level crossing
Source: AS1742.7:2016, annotated by Chief Investigator, Transport Safety (Victoria)
On either side of the crossing, R6-25,[4] R1-2[5] and RX-9[6] signs were installed (Figures 5 and 6).
Figure 5: Holmes Road level crossing access from east of the rail track
Holmes Road level crossing shown from the east side, the approach side of the truck. At the time of incident, the gate was open.
R6-25, R1-2 and RX-9 assemblies to the left of the road were knocked to the ground during the collision.
Source: Chief Investigator, Transport Safety (Victoria)
19 September 2022
Holmes Road level crossing shown from the west side with all signage intact.
Source: Chief Investigator, Transport Safety (Victoria)
Train 8070
Train 8070 was a three-car VLocity set numbered 3VL35, consisting of car 1135 (DMD), 1335 (TM), and 1235 (DM).[7]
In addition to its derailment, the impact with the truck caused damage to the front of the leading car. The laminated safety glass of the windscreen and side windows were shattered, but all windows remained within their frames (Figure 7). The driver’s cab floor was pushed up and the underside of the control desk was deformed.
Figure 7: Damage to the front of the train
Source: Chief Investigator, Transport Safety (Victoria)
The truck
The truck consisted of a 2013 Kenworth T909 prime mover, coupled to a 45-ft drop-deck semi-trailer (Figure 8).
Figure 8: Drop-deck semi-trailer
Source: Chief Investigator, Transport Safety (Victoria)
Further investigation
To date, the ATSB has:
inspected the location of the occurrence
examined train operational information
examined truck operational information
interviewed a number of parties
commenced collection of other relevant information
The investigation is continuing and will include review and examination of:
the arrangements for the use of the Holmes Road level crossing
the use of the level crossing by property owners
the operation of the truck and train
the configuration of the level crossing
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Australian Transport Safety Bureau
About the ATSB
The ATSB is an independent Commonwealth Government statutory agency. It is governed by a Commission and is entirely separate from transport regulators, policy makers and service providers.
The ATSB’s purpose is to improve the safety of, and public confidence in, aviation, rail and marine transport through:
independent investigation of transport accidents and other safety occurrences
safety data recording, analysis and research
fostering safety awareness, knowledge and action.
The ATSB is responsible for investigating accidents and other transport safety matters involving civil aviation, marine and rail operations in Australia, as well as participating in overseas investigations involving Australian-registered aircraft and ships. It prioritises investigations that have the potential to deliver the greatest public benefit through improvements to transport safety.
The ATSB performs its functions in accordance with the provisions of the Transport Safety Investigation Act 2003 and Regulations and, where applicable, international agreements.
Rail safety investigations in Victoria
Most transport safety investigations into rail accidents and incidents in Victoria and New South Wales (NSW) are conducted in accordance with the Collaboration Agreement for Rail Safety Investigations and Other Matters between the Commonwealth Government of Australia, the State Government of Victoria, and the State Government of New South Wales. Under the Collaboration Agreement, rail safety investigations are conducted and resourced in Victoria by the Chief Investigator, Transport Safety (CITS) and in New South Wales by the Office of Transport Safety Investigations (OTSI), on behalf of the ATSB, under the provisions of the Transport Safety Investigation Act 2003.
The Chief Investigator, Transport Safety(CITS) is a statutory position established in 2006 to conduct independent, no-blame investigation of transport safety matters in Victoria. CITS has a broad safety remit that includes the investigation of rail (including tram), marine and bus incidents.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available on the ATSB website. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
On the morning of 9 July 2022, a Bell 206 L-1, registered VH-ZMF departed a private helipad at Cattai, NSW for a private flight. About 9 minutes later, the helicopter impacted terrain about 10 km to the north of the departure point. The helicopter was destroyed, and the pilot, who was the sole occupant, was fatally injured.
What the ATSB found
The ATSB found that shortly after crossing Dargle Ridge at about 500 ft above the ground and while approaching the Richmond airspace control boundary, a wedgetail eagle impacted the helicopter just below the front left windscreen. It was unlikely that the pilot saw or had time to avoid the wedgetail eagle due to sun glare and a required radio frequency change.
The pilot was likely startled and initiated abrupt control inputs leading to the main rotor severing the tail boom. This led to an inflight break-up of the airframe and collision with terrain.
Safety message
Birdstrike is sometimes an unavoidable and relatively common hazard for all aviation operations, one which is more prevalent at lower altitudes. Pilots are reminded that sound lookout and visual scanning processes, as well as avoidance of low-level flight and expected areas of large concentrations of birds are key to reducing the likelihood of birdstrike.
Maintaining effective lookout and taking steps to remove, reduce or eliminate reduced visual effectiveness will assist in maintaining better situational awareness in-flight, and also assist in providing better outcomes to see-and-avoid not only birds, but other airspace users.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
At about 1139 local time on 9 July 2022, a Bell 206L-1 Long Ranger, registered VH-ZMF, departed a private helipad at Cattai, New South Wales, for a private flight to a property at St Albans (Figure 1). The pilot was the sole occupant on board.
The pilot obtained an airways clearance from air traffic control and recorded data showed the helicopter tracked to the north towards St Albans, climbing to about 700 ft above mean sea level (AMSL).
A witness to the south of Dargle Ridge observed the helicopter moments before the accident. They recalled it flying straight and level towards the north, and that weather conditions were good, with clear skies and light winds.
Figure 1: VH-ZMF departure and track
Source: Google Earth, with OzRunways data, annotated by the ATSB
After crossing the Dargle Ridge lookout the helicopter was at about 500 ft above ground level based on the elevation. Several witnesses described seeing VH-ZMF enter into a rapid banking turn to the right while pitching up. They heard several rotor beats change tone before a final louder noise.
Witnesses then recalled the helicopter pitching and rolling while descending, with one witness describing separation of the main rotor blades from the helicopter at about the height of Dargle Ridge shortly before impact.
A short time later, smoke was observed rising from the area where the helicopter descended. The pilot was fatally injured, and the helicopter was destroyed by a post-impact fire.
A nearby news helicopter, filming local flooding, was the first to arrive on scene and landed nearby to render assistance. Camera crew continued filming the accident scene before it was consumed by the post-impact fire. Biological matter was observed in that recorded video on the outside of the left nose cowl of the helicopter (Figure 2).
Figure 2: Locations of biological matter
Source: Bell, United Services, and ATSB
The landowner, who arrived at the accident scene on the top of the Dargle Ridge lookout, identified a mass of biological tissue, which appeared to be a tail section of a bird (Figure 3), which was still warm. During the on-site phase of the investigation, further biological samples were recovered below the escarpment.
Figure 3: Bird matter found near accident site
Source: NSW Police and ATSB
Context
Pilot information
Licencing
The pilot held both commercial (aeroplane and helicopter) pilot licences and was appropriately licenced to fly the Bell 206 LongRanger. The pilot held a valid class 2 medical certificate which included restrictions requiring the wearing of distance vision correction and additionally, that reading correction must also be available whilst exercising the privileges of the licence. Their most recent single engine helicopter flight review and an operational low level helicopter rating renewal was carried out on 2 June 2022.
Aeronautical experience
The pilot’s electronic logbook record showed a total flying experience of 5,398.3 hours up to the last recorded flight on 19 October 2020, when the pilot ceased using electronic logbook software with a helicopter operator. Of the pilot’s total flying experience, about 4,800 hours was in helicopters. VH-ZMF was used regularly by the pilot as a private aircraft, however due to a lack of recent pilot logbook records, ATSB was unable to determine the pilot’s total flight experience in Bell 206 aircraft.
Recent history
The pilot had spent a number of days at their home in Cattai by themselves after returning from Adelaide to assist with the recent flood recovery efforts in the area and to ensure safety of their own property. While no one spoke to the pilot prior to them departing Cattai that morning, several text messages were exchanged with family and friends.
Post-mortem and toxicology
At the time of release of this report, a post-mortem and toxicology results were not available to the investigation.
Aircraft information
General
VH-ZMF was a Bell Helicopter Company B206L-1 Long Ranger, S/N 45258 manufactured in the US in 1979. It was first registered in Australia in October 2012 as VH-MFF and then changed registration to VH-ZMF in May 2013.
VH-ZMF was a helicopter with two-bladed main rotor and tail rotor systems, powered by a single Rolls Royce 250-C30P gas turbine engine. It had hydraulically assisted flight controls, skid type landing gear and seating for a pilot and 6 passengers. The main and tail rotor blades had been replaced with carbon fibre composite blades under a supplemental type certificate (STC).[1] The helicopter was fitted with an emergency locator transmitter.
At the time of the accident, the helicopter had completed 2,964 hours in service and was certified for day VFR[2] flight only.
Airworthiness and maintenance history
A maintenance release was issued for VH-ZMF on 10 September 2021 at an aircraft time in service of 2,938.34 hours and was valid at the time of the accident.
The aircraft was retrofitted with Van Horn tail rotor blades in December 2015 and Van Horn main rotor blades in May 2021. The Van Horn blades are constructed of carbon fibre composite material which differs to the standard aluminium alloy construction by the original manufacturer. The Van Horn tail and main rotor blades were fitted under STC SR02249LA and STC SR02684LA respectively.
Meteorological conditions
Witnesses near the accident site described the weather conditions that morning to be ‘near perfect flying conditions’ with sunny conditions, light winds, blue skies and little cloud.
Another pilot who had operated through the same area about 7 minutes earlier on the day of the accident described the weather conditions as a good day for flying, with blue skies, sunny, no rain and some cloud around.
About the time of the accident, RAAF Base Richmond, located about 20 km to the south-west of the accident site, recorded wind from the west at about 4 kt and visibility greater than 10 km.
Recent heavy rainfall had swollen rivers, flooded the valleys and cut roads as substantial surface water runoff continued in the local area.
Wreckage information
The main accident site, including the engine, main cabin, and fuselage, was located in relatively flat and open farmland, between 2 ridgelines (Figure 5). The tail rotor assembly, vertical stabiliser and a section of the tail boom were found about 93 m to the north, with no signs of pre-existing component failure or damage. However, the main tail boom and drive shaft (Figure 4) were both severed at roughly the same fuselage station, consistent with a main rotor blade strike.
Figure 4: Tail boom impact
Source: ATSB
The main rotor system, including the transmission cowling, gearbox, and main rotor blades, was located about 68 m to the west in a heavily wooded, sloping escarpment. The teetering main rotor head was still attached to the transmission with multiple severed control rods attached to the transmission mounting structure.
The composite main rotor blades had separated just outboard of the main rotor grips and had impacted heavily with vegetation and delaminated. One of the main rotor blade tips was located about 150 m before the main wreckage on top of the ridgeline.
Figure 5: VH-ZMF accident site
Source: Google Earth with ATSB RPAS picture overlay, annotated by the ATSB
Recorded data
Data collected from radar and aircraft-based sources indicated that VH-ZMF was travelling in a northerly direction at about 100 kt prior to crossing the Dargle Ridge Lookout. The data then showed a track deviation to the right and an increase in 100 ft of altitude coupled with rapid deceleration and an increased vertical descent rate prior to impact with terrain.
Audio from RAAF Richmond air traffic control recorded that at 1143:37 the air traffic controller advised the pilot of VH-ZMF that they were 2 NM (3.7 km) from the airspace boundary and gave the pilot traffic of another media helicopter in the vicinity of Wisemans Ferry.
Figure 6: Richmond radar overlay
Source: Google Earth with Richmond radar overlay, annotated by the ATSB
At 1143:58, the pilot confirmed that the frequency change. Three seconds later static was heard on the radio which lasted for about 2 seconds with no discernible audio. Recorded radar images show VH-ZMF approaching the control boundary before appearing to slow remarkedly and descend at 1144:12 before disappearing from radar at 1144:45.
The aircraft was also fitted with an in-flight camera system; however this was consumed by fire, and it was reported that the pilot did not usually use the camera system.
Bird information
Recovered biological specimens, including the avian carcass and the biological residue found on external helicopter surfaces, were analysed by the Australian Centre for Wildlife Genomics, Airstrike section of the Australian Museum. The carcass and samples taken from the helicopter’s main transmission cowling were identified as Aquila audax, commonly known as a wedge-tailed eagle.
The Australian Museum identifies the wedge-tailed eagle as Australia’s largest bird of prey with a wingspan of up to 2.3 m, with females growing up to 5.3 kg.
Their habitat is defined as:
The Wedge-tailed Eagle is found from sea level to alpine regions in the mountains, but prefers wooded and forested land and open country, generally avoiding rainforest and coastal heaths. Eagles can be seen perched on trees or poles or soaring overhead to altitudes of up to 2000 m. Wedge-tailed Eagles build their nest in a prominent location with a good view of the surrounding countryside. It may be built in either alive or dead tree, but usually the tallest one in the territory.
The landowner and several local witnesses also described the long-term presence of an indigenous pair of wedgetail eagles known to inhabit the Dargle Ridge escarpment for a number of years, raising 1 or 2 chicks per breeding season and often seen soaring and hunting together over the ridges and valleys.
The landowner also reported seeing another large eagle in the vicinity of Dargle Ridge shortly after witnessing the accident.
Birdstrike Statistics
Over the 15 years between 2008 and 2022, 24,106 birdstrikes were reported to ATSB for all modes of aviation.
The ATSB research paper Australian aviation wildlife strike statistics identified that for the 10 years between 2008 and 2017 that there were 28 reported birdstrikes involving wedge-tail eagles for all aircraft, however there was only one of these that resulted in an aircraft being destroyed.
More recently, for the 5 years between 2018-2022, 212 birdstrikes reported to the ATSB involving helicopters. However, this accident was the only one involving a birdstrike on a helicopter.
Limitations of see-and-avoid
During VFR flight, effective lookout and visual scanning by pilots is used to see and avoid airborne hazards, from other aircraft to wildlife or weather events. However, there are significant limitations of the ‘see and avoid principle’.
These include the limitations of the human visual system itself, cockpit demands in operating the aircraft, and physical and/or environmental conditions which when combined, decrease the likelihood of effective see and avoid.
Visual scanning involves moving the eyes in order to bring successive areas of the visual field onto the small area of sharp vision in the centre of the eye. The process is frequently unsystematic and may leave large areas of the field of view unsearched.
Avoidance of any airborne threat first requires identification by direct visual detection, and then must be identified as a collision risk, before the pilot then needs to decide what action to take. The pilot must then make the required control inputs and allow the aircraft to respond to avoid the object. The physiologically inherent limitations of the human visual and information processing system also increase the time taken to respond to a threat.
Tasks requiring pilot attention inside the cockpit also reduce a pilot’s capacity to visually identify and avoid an airborne threat.
Sun position
After the departure of VH-ZMF from the Cattai helipad, the aircraft tracked north at about 005° towards the St Albans property and climbed to about 700 ft AMSL. Calculation of the time of day and sun position relative to the aircraft’s altitude and track direction indicated that VH-ZMF was flying directly into the sun during the last 30 seconds of straight and level flight. Analysis also identified that due to the size and shape of the helicopter windscreen, that the sun was almost directly at the top of centre of the pilot’s field of view.
Direct glare from an unwanted light source can significantly reduce the identification of potential airborne hazards, an ATSB research report (Hobbs, 1991) stated that:
When the glare source is 5 degrees from the line of sight, visual effectiveness is reduced by 84 per cent (Hawkins, 1987). In general, older pilots will be more sensitive to glare.
The use of helmet visors, sunglasses or glare shields may lessen the severity of the impact of glare; however, it is still likely to significantly degrade visual effectiveness.
It was unable to be determined if the pilot was wearing sunglasses or using a sun visor to mitigate the glare from the sun position.
Helicopter rotor aerodynamics
Under normal flight conditions in two bladed, teetering head type helicopter rotor systems, the risk of the main rotor blades flexing to the point of contact with the tail boom is extremely low. However, the consequences of contact between the spinning rotor and the tail boom are potentially catastrophic. This may also lead to main rotor separation from the mast in-flight.
The amplitude of the blade flexing or flapping is increased by one or more of the following factors:
environmental conditions, such as gusts
sudden attitude changes and abrupt cyclic inputs
maximum speed sideways flight
unloading the main rotor disc with low to negative g[3] conditions.
In a low g situation (for an anticlockwise-rotating main rotor system), aerodynamic forces from the tail rotor often produce a right roll, which if countered with left cyclic further reduces the clearance between the main rotor and the tail boom. Under normal positive g in-flight conditions this would produce the desired effect of rolling the aircraft level. In the case of a low-g load flight manoeuvre this increases the risk of the main rotor hub contacting the main rotor mast, commonly referred to as mast bumping. At the point of mast bump, the main rotor blades can flex further, allowing the main rotor blade/s to contact the tail boom.
Mast bumping is described in many helicopter aerodynamic publications, additionally however Wagtendonk (Wagtendonk, 1996) states:
Airplane pilots who have recently transitioned to helicopters are at a higher risk for mast bumping accidents because reactions honed by years of airplane flying are not necessarily conducive to safe helicopter flying. For example, if the pilot must descend suddenly to avoid another object, say, a bird, helicopter technique is to rapidly lower collective. The airplane/helicopter pilot is prone to push the cyclic forward in the same situation. Lowering the nose of the helicopter into a dive, as he would an airplane. Such a push-over is the exact formula for mast bumping.
Safety analysis
This analysis will explore the circumstances pertaining to the in-flight break-up of VH-ZMF, the probability of an airborne birdstrike, its likely effect on the continued operation of the aircraft, and aircraft operation after the collision.
Sun position and visual effectiveness
The track of VH-ZMF on its way to St Albans placed the cockpit directly into the direction of the sun. It is likely that the position of the sun was almost directly at the top centre of the pilot’s field of vision, increasing the risk of glare from the sun and substantially reducing the pilot’s visual effectiveness.
As VH-ZMF approached the control boundary for Richmond airspace, a radio frequency change was required. The pilot needed to shift their vision and attention from outside of the cockpit to inside cockpit to change the frequency on the radio.
This task, combined with the sun glare likely reduced the chance that the pilot was able to visually identify the airborne threat and take appropriate avoiding action.
Birdstrike
Analysis of biological samples found on external surfaces of the helicopter and nearby the accident site, confirmed the airborne contact with a wedge-tailed eagle (Aquila audax). First responder film footage of the cockpit and fuselage impact site, prior to being consumed by fire, indicated a large external impact of biological matter on the front left nose cowl of VH-ZMF, indicating a likely initial impact point of the birdstrike.
It is almost certain that this initial impact location, approximate weight and speed of the bird would not have been of sufficient magnitude to significantly damage the helicopter and lead to a loss of controlled flight.
In-flight break-up
It was likely that the pilot was startled by seeing the large bird close to impacting or/and the actual birdstrike and attempted avoiding action during a period of reduced visual effectiveness. Witness recollection and analysis of recorded data identified that VH-ZMF began a pronounced climb and right roll before pitching forward.
Abrupt cyclic inputs and low to negative g rotor loading are a well-documented and accepted limitation of two-bladed teetering rotor head systems commonly used in light to medium helicopters. Analysis of the impact marks on the tail boom of VH-ZMF and the separation of rotor blade tips, indicate that the tail boom was impacted and severed by contact with its own main rotor blades. This led to further break-up of the aircraft in flight, such as the main rotor system and transmission due to severe rotational forces of a compromised and unbalanced main rotor assembly. Numerous witnesses observed and heard the impact of the main rotor blades on the tail boom and described the uncontrolled nature of the in-flight break-up.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the birdstrike and in-flight break-up involving a Bell 206L1 Long Ranger, registered VH-ZMF, near Maroota, NSW, on 9 July 2022
Contributing factors
Sun position and pilot workload at the control zone boundary likely resulted in the pilot not identifying a potential airborne collision risk.
While cruising at about 700 ft AMSL, the aircraft struck a wedgetail eagle just below the left windscreen.
The pilot was likely startled by the birdstrike resulting in an abrupt control input, which led to the main rotor blades contacting the tail boom and subsequent in-flight break-up.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
aircraft co-owner
chief pilot of a helicopter operator
Civil Aviation Safety Authority
New South Wales Police Force
aircraft manufacturer
maintenance organisation for VH-ZMF
Airservices Australia
accident witnesses
Australian Defence Force
Australian Museum
OzRunways.
References
Hawkins, F. H. (1987). Human Factors in Flight. Gower: Aldershot.
Hobbs, A. (1991, 04 01). Limitations of See-and-Avoid Principle. Canberra: ATSB. Retrieved from www.atsb.gov.au: /sites/default/files/media/4050593/see_and_avoid_report_print.pdf
Wagtendonk, W. J. (1996). Principles of Helicopter Flight. Washington: Aviation Supplies & Academics, Inc.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Civil Aviation Safety Authority
Bureau de la sécurité des transports du Canada
Australian Defence Force
Bell Helicopter.
Submissions were received from:
Civil Aviation Safety Authority
Bureau de la sécurité des transports du Canada
Bell Helicopter
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] A Supplemental Type Certificate authorises alteration to an aircraft, engine, or other item operating under an approved Type Certificate for the state of manufacture.
[2] Visual flight rules (VFR): a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
[3] G load: the nominal value for acceleration. In flight, g load represents the combined effects of flight manoeuvring loads and turbulence and can have a positive or negative value.
Preliminary report
Report release date: 06/10/2022
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
At about 1135 local time, on 9 July 2022, a Bell 206L1 Long Ranger, registered VH‑ZMF, departed a private helipad at Cattai, New South Wales, for a private flight to a property at St Albans, New South Wales (Figure 1). The pilot was the sole occupant on board.
The pilot departed the private helipad with clearance from air traffic control and tracked to the north towards St Albans, climbing to about 700 ft above mean sea level (AMSL).
A witness to the south of Dargle Ridge observed a helicopter moments before the accident. They recalled it flying straight and level towards the north, and that weather conditions were good, with clear skies and light winds.
Figure 1: VH-ZMF departure and track
Source: Google Earth, with OzRunways data, annotated by the ATSB
After crossing the Dargle Ridge lookout, several witnesses described seeing VH-ZMF enter into a rapid banking turn to the right while pitching up. They heard several rotor beats change tone before a final louder noise.
Witnesses then recalled the helicopter pitching and rolling while descending, with one witness describing separation of the main rotor blades from the helicopter at about the height of Dargle Ridge shortly before impact. A short time later, smoke was observed rising from the area where the helicopter descended. The helicopter was destroyed by a post-impact fire, and the pilot was fatally injured.
Context
Site and wreckage examination
The main accident site, including the engine, main cabin and fuselage, was located in relatively flat and open farmland, between 2 ridgelines (Figure 2). The tail rotor assembly, vertical stabiliser and a section of the tail boom were found about 93 m to the north, also in open farmland. The main rotor system, including the transmission cowling, gearbox and main rotor blades, was located about 68 m to the west in a heavily-wooded, sloping escarpment.
Figure 2: VH-ZMF accident site
Source: Google Earth with ATSB RPAS picture overlay, annotated by the ATSB
The ATSB conducted an examination of the accident site and wreckage, and identified that:
ground impact marks indicated that the main aircraft fuselage had impacted terrain in a nose-down attitude
the vertical stabiliser, aft section of the tail boom, tail rotor and tail rotor gearbox, were severed in flight and found separate to the main wreckage
the main rotor blades, main transmission and cowling had separated in flight and were found separate to the main wreckage
no pre-accident defects were identified with flight controls, aircraft structure or engine
a post-impact fire consumed the cockpit and main wreckage site
the remnants of a quantity of unburnt Jet A1 fuel had sprayed from the fuel tank on impact at the main site and leaked into the soil.
Several items were recovered from the site for further examination, including:
an unidentified avian (bird) carcass
a main rotor blade tip component and section of impacted tail boom
samples of biological residue found on external helicopter surfaces.
Recorded data
Data collected from radar and aircraft-based sources indicated that VH-ZMF was travelling in a northerly direction at about 100 kt prior to crossing the Dargle Ridge Lookout. The data then showed a track deviation to the right and an increase in 100 ft of altitude coupled with rapid deceleration and an increased vertical descent rate prior to impact with terrain.
Other information
Recovered biological specimens, including the avian carcass and the biological residue found on external helicopter surfaces, were analysed by the Australian Centre for Wildlife Genomics, Airstrike section of the Australian Museum. The carcass and samples taken from the helicopter’s main transmission cowling were identified as Aquila audax (commonly known as a wedge-tailed eagle).
Further investigation
To date, the ATSB has finalised its on-site evidence collection, interviewed witnesses and collected aircraft parts and biological specimens from site.
The investigation is continuing and will include:
analysis of recorded flight data
review of aircraft and maintenance documentation
review of pilot qualifications and experience
review of the Australian Museum report on collected biological samples
examination and analysis of the main rotor blade tip and tail boom impact point.
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Acknowledgements
ATSB would like to acknowledge the assistance of the Australian Museum during the on-site and evidence gathering phases of the investigation.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Portland Bay sailed from Port Kembla, New South Wales, on 3 July 2022 as bad weather was impacting its stay in port. It was expected to return when the weather improved. The ship then steamed and intermittently drifted about 12 nautical miles (miles) from the coastline.
In the early hours of 4 July, the main engine developed mechanical problems, which disabled the ship 12 miles from the lee shore. A couple of hours later, after unsuccessful attempts to resolve the engine problems, the ship’s master asked Australian authorities for tug assistance. About 2 hours later, a harbour tug from Sydney was en route but the ship had closed to one mile from the shore. The master made emergency use of both anchors to prevent stranding on the rocky shore about 12 miles south of Port Botany (Sydney) about one hour before the tug arrived to assist.
In the afternoon, 2 more harbour tugs arrived on scene and later began towing the ship away from the coast. A couple of hours later in the evening, one of the tugs’ towlines parted in the rough sea conditions. The ship then drifted towards the shore and the master again anchored about one mile from the shore off Bate Bay near Sydney. Later that night, the state’s nominated emergency towage vessel (ETV) deployed from Newcastle.
The ETV arrived on scene after midday on 5 July and connected a towline in preparation to tow the ship into Sydney. On the morning on 6 July, the ETV (with harbour tugs assisting) towed the ship into Port Botany, where it was berthed in the afternoon for refuge and subsequent repairs.
What the ATSB found
The ATSB investigation found that the ship had remained near the coast instead of safely clearing it in accordance with its safety management system (SMS) procedures. Operating its main engine at low speed while rolling and pitching heavily resulted in engine load fluctuating with turbocharger surge and non‑return flap hammering and distortion. Performance was further degraded by a leaky fuel injector, poor combustion and excessive cylinder lubrication resulting in sludge and deposits. When one of the 2 auxiliary blowers failed in the early hours of 4 July, air for fuel combustion significantly reduced and engine speed was limited to the minimum, effectively disabling the ship in bad weather.
The investigation also identified that when the master reported the situation to the ship’s managers, Pacific Basin Shipping, it provided advice on engineering matters but not about notifying authoritiesas per the SMS procedures. This probably led the master to delay reporting to Port Kembla vessel traffic service (VTS) operated by the Port Authority of New South Wales (Port Authority). This delay was compounded when VTS did not promptly forward the master’s report to the Australian Maritime Safety Authority (AMSA). The various delays resulted in delaying the tug assistance requested and the master had to deploy both anchors to prevent stranding.
In addition, the investigation identified several safety issues associated with the emergency response. Specifically, AMSA procedures to comply with the National Plan for Maritime Environmental Emergencies (National Plan) were not effectively implemented. Similarly, the Port Authority’s procedures to comply with the NSW Coastal Waters Marine Pollution Plan (NSW Plan) and its Port Safety Operating License (PSOL) were not effectively implemented. Further, the coordination of critical elements of the emergency response, including emergency towage, salvage and refuge, between the Port Authority, Transport for NSW (NSW Maritime) and AMSA with their respective roles and responsibilities was inadequate and inconsistent with National Plan principles. These safety issues prolonged the emergency and the exposure to stranding, with potentially severe consequences.
The ATSB also found that the AMSA process to issue directions was inefficient and resulted in excessive time to issue directions to enable Portland Bay to enter Port Botany for shelter. While this delay did not further prolong the emergency, such delays increase risk in time‑critical situations. The investigation also found that United Salvage, the salvor, was severely limited in its ability to provide the salvage services required as it did not own or operate any towage vessels so was reliant on towage providers. This limitation was not made clearly known to the ship’s master, owners or managers or the involved agencies to allow them to properly assess whether the mostsuitable towage vessels, including the ETV, had also been promptly deployed.
A key finding was that the ship’s anchors prevented a catastrophic stranding on the rocky shore in heavy weather, noting that they were not designed for such use but can be used as a last resort in emergencies.
What has been done as a result
Pacific Basin Shipping has revised its SMS crisis management procedures to include at least one exercise each year outside of office hours and conducted 2 such drills since the incident. A fleet‑wide circular emphasising the importance of early reporting to authorities to shipboard staff and office‑based teams was disseminated. In addition, the company produced a case study training video for seafarer training and office‑based teams to enhance emergency response as per its procedures with an emphasis on early reporting to authorities. The ATSB has assessed the safety action as having adequately addressed the safety issue regarding the late reporting of the incident.
While AMSA only partially agreed with the safety issue about response coordination and did not agree with the 3 other safety issues addressed to it, a range of relevant safety action has been taken. This included a review of its procedures, fortnightly incident escalation exercises, review of emergency towage capability, review of emergency coordination arrangements, increased resourcing (staff) and training and a comprehensive review of the National Plan. The ATSB welcomes this action but has recommended that AMSA takes further necessary action to adequately address all 4 safety issues.
The Port Authority advised that as the incident did not involve a spill (pollution), its role as the state’s combat agency was not ‘enlivened’. It added that AMSA and NSW Maritime had roles and responsibilities for this incident. The Port Authority did not advise of any safety action, hence the ATSB has recommended that it take action to address both safety issues addressed to it.
Transport for NSW (NSW Maritime) advised that it had taken action to improve response coordination with the Port Authority, which included discussions and joint exercises. However, given the Port Authority’s response and lack of safety action, the ATSB considers it important that NSW Maritime takes safety action to adequately address the safety issue concerning response coordination and has issued a recommendation accordingly.
Finally, the ATSB has recommended that United Salvage takes action to address the safety issue with respect to clearly informing the master, owners or managers of the ship to be salved of the salvor’s capabilities and limitations in performing the salvage services required.
Although no safety issue was addressed to Svitzer Australia, it has upgraded the towing equipment of its Sydney‑based harbour tug that assisted with the response.
Safety message
Portland Bay’s near stranding provides invaluable lessons on managing emergencies to avoid severe consequences. Optimal emergency management relies on taking a series of appropriate actions in a timely manner, which often determine the degree of success of the response. Failure is usually associated with actions that are ‘too little, too late’. Australia’s National Plan reiterates the principle of over‑escalation in an initial response as it is more effective to scale down than up.
Effective emergency response plans and procedures do not leave outcomes to good fortune, which on rare occasions have contributed to a positive outcome. The National Plan principles and arrangements provided the best available options to manage risks along Australia’s extensive and pristine coastline, which also has inherently limited emergency response resources.
Summary video
The occurrence
Overview
On 3 July 2022, adverse weather that was forecast to further deteriorate had made it unsafe for the bulk carrier Portland Bay (cover) to remain berthed in Port Kembla, New South Wales (Figure 1). Consequently, the decision was made for the ship to leave the port and remain at sea until the weather improved sufficiently to allow a safe return.
Figure 1: Portland Bay’s movements from 3 to 6 July 2022
Source: Australian Hydrographic Office and Portland Bay’s recorded voyage data, annotated by the ATSB
Portland Bay departed the port in the afternoon and steamed on an east‑north‑easterly course until that evening when it was about 12 nautical miles (miles) from the coastline where its main engine was stopped. The ship drifted towards the coast in the south‑easterly winds and seas and the engine was used intermittently that evening and night to avoid getting closer to the coast.
Shortly before 0500 local time on 4 July, the main engine developed mechanical problems, which limited the engine speed to dead slow ahead (the minimum). The problems could not be resolved, resulting in Portland Bay being effectively disabled about 12 miles from a lee shore. In the prevailing conditions, the ship began drifting at a rate of 2–3 knots[1] towards the coast.
Two hours later, at 0657, after attempts to resolve the engine problems were unsuccessful, the ship’s master notified Port Kembla vessel traffic service that the ship’s main engine had failed and requested tug assistance. At 0848, a harbour tug from Sydney[2] left the port for the ship’s location, which was then about 1.5 miles from the coastline about 22 km south of Sydney.
At 0905, when about one mile from the shore, the master deployed the ship’s anchors to prevent stranding on the rocky coastline of Royal National Park (Figure 1, Anchor position 1). Subsequently, unsuccessful attempts were made to evacuate the crew by helicopter.
At 1010, the tug arrived off the ship and, about 4 hours later, 2 other Sydney harbour tugs arrived. By late afternoon, these 2 tugs began towing the ship away from the coast. However, a couple of hours later, one of the tugs parted its towline and the ship again began drifting towards the shore.
At 2035, the ship was anchored about one mile from the shore to prevent stranding in Bate Bay near Sydney (Figure 1, Anchor position 2). Both tugs, one with its towline connected, remained with the ship. Later that night, the nominated emergency towage vessel (ETV) for New South Wales was deployed from Newcastle (about 90 miles north of Bate Bay) to tow the ship to safety.
On 5 July, at about 1300, the ETV arrived off Bate Bay and later connected a towline while plans to tow the ship into Sydney (Port Botany) in daylight on the following day were finalised. The harbour tug with a towline connected remained with the ship.
On 6 July, at about 1100, the ETV and 2 harbour tugs began towing Portland Bay to shelter in Port Botany (Figure 2). By late afternoon, the ship had been safely berthed in the port. Over the following week, the main engine was repaired to make the ship seaworthy.
Figure 2: Portland Bay under tow on 6 July
Source: Port Authority of New South Wales
The following sections outline key events preceding the incident and greater detail of the numerous events that occurred over the course of the incident between 4 and 6 July.
The incident
Background
Portland Bay arrived and anchored off Port Kembla on 19 June 2022, following a voyage from Susaki, Japan, loaded with a cargo of cement. On 21 June, the ship was conducted by a harbour pilot into the port’s inner harbour and, at 1724 local time, secured at berth number 104.
Cargo unloading began that evening, and 8 new crew members, including the relieving master and chief engineer, joined the ship. On 22 June, another 5 relieving crew members joined the ship. The new chief engineer intended to complete several items of main engine maintenance, including a few that had been pending for some time, during the ship’s stay in port.
While unloading cargo between 22 and 26 June, the master obtained permission from the Port Kembla harbour master to immobilise the main engine, from time to time, allowing the engineers to clean the charge air cooler, lubricating oil (LO) cooler and LO filters. When unloading was completed in the evening on 26 June, some maintenance items remained.
On 27 June, Portland Bay departed for sea to clean its cargo holds for the next cargo. The crew was to clean accessible areas of the cargo holds before berthing in Port Kembla on 2 July, where shore labour would clean the upper parts of the holds. The ship anchored or drifted off the port while the holds were cleaned.
On 1 July, the ship’s agent in Port Kembla, Monson Agencies Australia (Monson), advised Pacific Basin Shipping (Pacific Basin), the ship’s Hong Kong‑based management company, of likely disruptions to hold cleaning due to heavy rain and a large north‑easterly swell forecast for 3 and 4 July. Monson advised that the ship might be required to leave port to avoid damage to the berth and ship due to the heavy swell.Pacific Basin decided to continue with the scheduled berthing.
At 0154 on 2 July, Portland Bay was secured starboard side alongside berth number 202 in the outer harbour (Figure 3). At 0410, the Bureau of Meteorology (BoM) issued a forecast for gale force winds up to 35 knots and an easterly swell of 3 to 4 m for the seas off the port on 3 July. At 0500, entries in the ship’s logbook indicated easterly winds at ‘force’[3] 3 (7–10 knots).
Figure 3: Location of berth 202 (wind and swell direction at 1100 on 3 July)
Source: Australian Hydrographic Office, annotated by the ATSB
As forecast, the weather continued worsening and, at 1600, southerly winds at force 6 (22–27 knots) were recorded in the logbook. At 2243, Monson advised the master via email that Port Kembla vessel traffic service (VTS)[4] had issued additional harbour master’s instructions due to worsening weather. They included running additional mooring lines and lowering the outboard anchor to the seabed. In addition, VTS advised that the anchorage was closed and ships drifting off the port were to keep ‘at a safe distance (around 12 miles)’. The anchorage and VTS area were shown on navigational charts.
The charted limits of the VTS area showed its eastern limit lay along longitude 151°04.5’ E and extended south from Garie Beach (about 19 miles north of the port entrance) to a southern limit along latitude 34°30.4’ S, which passed through Perkins Beach south of the port (Figure 1). The line of the eastern limit line passed 8.5 miles east of the port entrance and nautical publications described the ‘VTS area, VTS limit/reporting line or VTS area reporting line’ and detailed requirements to report to VTS when passing a reporting line.[5]
On the morning of 3 July, Portland Bay began to be affected by the swell at its berth in the outer harbour. At 1027, the terminal manager contacted VTS and requested that the duty pilot assess whether it was safe for the ship to remain at the berth in the worsening weather and swell. At 1035, the master requested and received permission from VTS to lower the port anchor to the seabed.
At about 1050, after a risk assessment by the duty pilot and the harbour master, VTS askedthe master to prepare to depart the port to avoid damage to the wharf and ship due to its movement in the swell. The master agreed with the assessment and began preparing for departure. The pre‑departure checks included testing the main engine (ahead and astern propulsion) and steering gear. A south‑easterly wind at force 6 (22–27 knots) was recorded in the logbook at the time.
At 1235, a harbour pilot boarded Portland Bay, conducted a master‑pilot information exchange and confirmed pre‑departure checks had been completed. The ship had maximum water ballast on board, forward and aft draughts of 4.11 m and 5.30 m, respectively (the propeller was fully immersed at an aft draught of 5.1 m) and a displacement of approximately 15,500 tonnes.[6]
At 1300, all was in readiness to depart and, at 1312, the ship was manoeuvred clear of the berth with 2 tugs assisting. By 1334, the shiphad cleared the port’s entrance and the pilot disembarked.
Propulsion failure
After disembarking the pilot, Portland Bay’s master set an east‑north‑easterly course with the main engine at manoeuvring full ahead speed (90 rpm). In the prevailing heavy weather, the engine remained on standby with the engine room manned (the ship was equipped to operate with unattended machinery spaces – UMS). The mates were on usual bridge watches and the master attended periodically. The ship experienced moderate to heavy rolling and pitching and the master recalled having difficulty maintaining a steady course and achieving a speed[7] of 2–3 knots.
At 1800 on 3 July, when the ship was 14 miles east‑north‑east of Port Kembla, the master stopped themain engine and the ship began drifting about 12 miles off the coastline. A south‑easterly wind at force 7 to 8 was recorded in the logbook. The ship was rolling and pitching heavily at times and was drifting in a westerly direction towards the coast at about 3 knots.
At 1937, when the ship was about 8 miles off the coast, the engine was restarted and speed gradually increased to manoeuvring full ahead to again steam on an east‑north‑east course. At midnight, east‑south‑easterly winds at force 7 (28–33 knots or near gale force) were recorded in the logbook. The third mate handed over the navigational watch to the second mate, conducted routine fire and safety rounds[8] and reported nothing untoward.
At 0200 on 4 July, when the ship was 15 miles from the coast (24 miles east‑north‑east of Port Kembla),the engine was stopped. The south‑easterly wind had moderated to force 5 (17–21 knots) but the heavy swell from the gale force winds earlier persisted. At 0330, the ship surged[9] and rolled heavily. Soon after, the second mate put the engine dead slow ahead (42 rpm), the minimum speed. The master came up to the bridge and, at 0337, the engine order was increased to half ahead (80 rpm). At 0344, the master ordered full ahead and a heading[10] of 110°to steam away from the coast (which at that stage was about 10 miles off) before returning to his cabin.
At 0400, when the second mate handed over the watch to the chief mate, a south‑easterly wind at force 6 to 7 was recorded in the logbook. The second mate then completed fire and safety rounds and recorded nothing unusual. During those early hours of the morning, the BoM wave rider buoy off Sydney recorded waves with a ‘significant wave height’ of 5.04 m and a ‘maximum wave height’ of 8.44 m from the east‑south‑east.[11]
At 0450, when Portland Bay was about 12 miles from the coast, an alarm on the bridge fire alarm panel alerted the chief mate to 2 fire detectors in the lower, starboard side of the engine room that had been activated (Figure 4).
Figure 4: Time and location of key events during the incident
Source: Australian Hydrographic Office and Portland Bay’s recorded voyage data, annotated by the ATSB
The second engineer, on watch in the engine control room, and the chief engineer (also in the control room) investigated and found smoke and a burning smell coming from main engine auxiliary blower number 2 (see the section titled Auxiliary blower number 2 under Propulsion). At about 0451, the second engineer returned to the control room, stopped the blower and called the bridge for engine speed to be reduced. The chief mate reduced speed and called the master. At 0453, when the master arrived on the bridge, the speed order was slow ahead (58 rpm).
By 0507, the engine speed had been reduced to dead slow ahead. On the ship’s south‑westerly heading, the wind was on the port beam and pushing it towards the coast. At 0513, the master ordered slow ahead but engine speed remained about 42 rpm (dead slow ahead). The master then ordered a course change to an easterly heading and pointed out to the chief mate that the ship was 3 or 4 hours away from (drifting onto) the coast about 11 miles off.
Ship disabled
At 0519 on 4 July, the master asked the chief mate to get an update from the engine room and was advised that the chief engineer was coming up to the bridge. When the chief engineer arrived at 0522, the master stated that they had one hour to make repairs otherwise tugs would need to be called. The chief engineer advised that the blower could not be repaired in one hour and gave reasons for that assessment. When the master asked if the engine could be run at full ahead, the chief engineer advised that it was not possible due to the active engine alarms and limits.
At 0523, the master asked the chief engineer to call Portland Bay’s dedicated manager (in Pacific Basin’s office) and explain that it was ‘really dangerous’ if the speed could not be increased as the ship was drifting towards the coast (less than 11 miles off) at 3.5 knots. Subsequent attempts to call the ship’s manager via satellite telephone were unsuccessful as the manager was travelling.
At 0533, the chief engineer instead called Pacific Basin’s marine and safety manager (marine manager) and explained the situation. Meanwhile, to help turn the ship on to an easterly heading, the master had unsuccessfully tried increasing engine speed. At 0539, the master (who had joined the call to respond to the marine manager’s questions) advised that it was not possible to steam 50 miles away from the coast as engine speed was limited to dead slow ahead.
Soon after, at 0541, the marine manager called the fleet manager and explained the ship’s situation. Two minutes later, the fleet manager called the ship and suggested that the chief engineer override the engine torque limiter and active alarms to increase speed. While the chief engineer went to the engine room to do so, the master tried turning the ship to an easterly heading away from the coast, now less than 10 miles off. The master voiced concerns to the chief mate a few times about the rate at which the ship was closing the coast.
At 0555, after unsuccessful attempts to increase engine speed, the master asked the chief engineer to come to the bridge and call the fleet manager. From about 0600, the chief engineer discussed options with the fleet manager. When the call ended at 0606, the master told the chief engineer and chief mate that if speed could not be increased and no one helped, they would be on the ‘rock’ in the next hour.
Meanwhile ashore, at about 0615, the marine manager had called Pacific Basin’s designated person ashore (DPA)[12] and provided an appraisal of the ship’s situation.
At 0624, after the engine stopped and could not be restarted, the master ordered ‘not under command’ (NUC)[13] signals be displayed and the disabled ship’s status on the ‘automatic identification system’ (AIS)[14] be set to NUC.
At 0627, the chief engineer updated the fleet manager and was asked to start the engine from the local emergency controls (adjacent to the engine) and increase rpm until the turbocharger became effective (see the section titled Engine combustion air system under Propulsion). At 0631, the master, having asked the chief engineer how long it would take to try the local controls, agreed to trying to start the engine. The master also noted that there was little available time remaining to obtain tug assistance.
At 0634, when the chief engineer started the engine from the local controls, the rpm would not increase beyond about 42 rpm (dead slow ahead). At 0640, the master took the fleet manager’s call and advised that the engine speed had not increased beyond 27 rpm. They discussed the situation for 6 minutes before the master concluded the call, advising that the chief engineer would provide an update shortly. The master then asked the chief mate to check the ship’s emergency procedures for contacts in the Sydney area.
At 0650, the master called the fleet manager and discussed requesting assistance from local authorities. The chief engineer also arrived on the bridge, provided the fleet manager an update and was asked to again try increasing speed to full ahead from the local controls.
At 0655, after the chief engineer’s attempts to increase speed had again been unsuccessful, the master instructed the chief mate to call ‘Marine Rescue Sydney’. At that time, the disabled ship was less than 7 miles from the coast.
Meanwhile, at 0656, Pacific Basin’s management team established a virtual communications group to manage the emergency. The group comprised the marine and safety manager, fleet manager, fleet director and DPA (references to Pacific Basin hereafter mean this group or the company in general).
Tugs called
At 0656 on 4 July, the chief mate called ‘Marine Rescue Sydney’ on very high frequency (VHF) radio channel 16 but received no response. At 0657, the chief mate called Port Kembla VTS and advised that Portland Bay's main engine had failed, that it was drifting towards the coast and required tug assistance. Port Kembla VTS suggested anchoring the ship, which the master ruled out due to the deep water in the ship’s location (see the section titled Bridge procedures under Safety management system).
At 0659, Port Kembla VTS informed the ships’ agent in Port Kembla, Monson, that the ship’s master had asked for tug assistance. The VTS then notified personnel within the Port Authority of New South Wales (Port Authority) of the ship’s situation.
Meanwhile, the master and chief mate discussed whether ‘RCC’[15] should be contacted as no response had been received from ‘Marine Rescue Sydney’. Instead, at 0703, the chief mate called ‘Marine Rescue Port Kembla’ (Marine Rescue) and was advised that relevant authorities would be notified of the situation and to await an update. The ship was about 6 miles from the coast and drifting towards the 3‑mile limit of New South Wales coastal waters (see the section titled Legislation and plans under State level).
While awaiting an update from Marine Rescue,[16] the master and chief mate discussed whether to broadcast an urgency (PAN)[17] or a distress (MAYDAY)[18] message. At 0709, the chief mate informed Marine Rescue that the ship was 1.5 hours away from the ‘shore’ and was advised that Marine Area Command (MAC)[19] and Sydney Water Police had been notified. Marine Rescue also suggested broadcasting a PAN message. Noting this advice, the master told the chief mate that, at the ship’s drift rate of more than 4 knots, it would ground in 1.5 hours.
Ongoing communications with Pacific Basin had continued intermittently and, at 0714, the master advised that the ship was 2 hours from the coast and Australian authorities had been requested to provide tug assistance. At 0716, the chief mate broadcast a PAN message requesting assistance on VHF channel 16, which Marine Rescue acknowledged. At that time, the ship was 5.8 miles from the coast (about 11 miles south of Port Botany).
At about this time, the responsible NSW Maritime manager[20] called the joint rescue coordination centre (JRCC) operated by the Australian Maritime Safety Authority (AMSA)[21], after being earlier alerted by an officer in NSW Maritime’s Port Kembla office who had been advised by Marine Rescue that Portland Bay was drifting off the coast. The manager reported that JRCC ‘was not aware of the incident’.
At 0719, Pacific Basin asked the master to prepare for emergency anchoring while waiting for tug assistance. At the same time, Sydney VTS (which had heard Portland Bay's PAN broadcast) started monitoring the ship’s movement on its electronic displays.
A few minutes later, at 0725, Sydney VTS requested Svitzer Australia (Svitzer), the port’s main towage provider, for ‘emergency tug’ availability (see the section titled Towage licence system under State level). Sydney VTS then asked Port Kembla VTS which emergency services had been notified or activated.
Meanwhile on board, at 0727, the master ordered the second and third mates to report to the bridge wearing working clothes and safety boots. A minute later, when Marine Rescue asked for the ship to be anchored, the master once again advised that anchoring was not possible in the deep water. The master asked if a tug could reach the ship in one hour and was advised that an estimated time of arrival (ETA) would be provided when available.
Sydney VTS followed up Svitzer for an available tug at 0731, and again at 0739, but no tug response time was provided. At 0740, Sydney VTS contacted the port’s other towage provider, Engage Towage, and was advised that a tug would be immediately prepared to deploy.
Meanwhile on board, communications with Pacific Basin had continued with the chief engineer advising that the damaged blower could only be repaired when the engine was not required and not operating. The master advised that preparations were being made for anchoring when water depths permitted. At 0741, the master sounded the ship’s general alarm and instructed the crew to standby inside the accommodation with their lifejackets.
At 0744, Port Kembla VTS called JRCC to report that Portland Bay was drifting towards the coast and ‘could ground in 1.5 hours’. The ship was about 5 miles off the coast in Commonwealth waters and moving rapidly towards New South Wales coastal waters. Immediately afterwards, at 0745, Sydney VTS called JRCC, discussed ‘emergency tug’ activation and advised that Engage Towage was preparing a harbour tug.
On board, at 0746, the master ordered that the boatswain (a senior deck crewmember) go forward along the starboard side (the lee side) and remove the anchors’ lashings. At 0749, another PAN message was broadcast advising that the ship would ground in one hour (the low engine speed allowed little control of the ship’s heading and drift rate). Marine Rescue advised the master that assistance was being arranged and, at 0751, Sydney VTS asked the master to confirm that ‘emergency tug assistance’ was required. Soon after, Svitzer instructed the master of its tug, Bullara, in Port Jackson (Sydney) to prepare to deploy.
At 0752, after Sydney Water Police advised JRCC that 2 water police vessels from Port Botany and Port Kembla were deploying, AMSA took over search and rescue (SAR) coordination for the incident. Soon after, AMSA began identifying air and surface assets to evacuate the crew in case the ship stranded on the rocky coastline. At 0754, AMSA tasked the first asset, a Challenger aeroplane from Essendon Airport, Victoria.
At 0756, Pacific Basin emailed Monson advising that the ship was 1.5 hours away from the shore and asked for an update on tug arrangements. At 0757, Sydney VTS followed up AMSA for the ‘emergency tug’ and was advised that the nominated emergency towage vessel (ETV) for New South Wales (Svitzer Glenrock)was in Newcastle (see the section titled Svitzer Glenrock under Svitzer Australia). Sydney VTS then advised that it would be deploying any available tug(s) in Sydney.
At about 0758, Pacific Basin advised the master that the agent, Monson, was arranging a tug and suggested anchoring when the ship drifted into 45 m depths (expected to be in one hour). At 0800, the master instructed the chief mate to collect important ship certificates and documents and place them in the starboard lifeboat as it was too late for a tug to reach the ship in time.
At about 0800, Engage Towage contacted United Salvage, a salvage services provider, to advise that the disabled ship was drifting towards the shore and it was unlikely a tug could reach the ship before it grounded. As part of an existing agreement between the 2 companies, they decided to mobilise SL Diamantina, an Engage Towage tug in Port Botany with a crew on board. Its most suitable tug, SL Martinique, was not mobilised at that time as it was not crewed (see the section titled Engage Towage).
At 0803, the NSW Maritime manager called JRCC again and was advised that it was ‘trying to organise tugs to assist as soon as possible’.
Meanwhile, Bullara’s crew had boarded at about 0800 and begun preparing to deploy. At 0804, Monson emailed the master (copying AMSA) and advised that a tug was being arranged (Monson had earlier asked Svitzer to provide a tug). A short time later, United Salvage asked Svitzer for Bullara and was advised that it was being prepared for hire by the ship’s owners.
At 0807, Marine Rescue advised the master that a water police vessel was en route and confirmed that the crew had mustered with lifejackets. Between 0800 and 0810, AMSA had contacted the NSW Police, NSW Helicopter Rescue Services, NSW Ambulance Services and the Australian Defence Force (ADF) to request air and surface craft to evacuate the ship’s crew (based on information that a tug could not reach the ship before it drifted on to the shore).
At about this time, the NSW Maritime manager called the Port Authority’s chief operating officer to discuss the information which the manager had obtained from JRCC and the response by New South Wales. They exchanged information, noting that the ship would soon be within New South Wales coastal waters and agreed to convene a meeting of relevant agencies to understand each other’s roles and responsibilities for the response.
Meanwhile, at 0811, the master advised Pacific Basin that a police vessel rather than a tug, was en route to the ship. The master then discussed the anchoring plan with the mates, advising them that when depths reduced to 80 m, 3 shackles[22] of the port anchor cable would be ‘walked back’[23] (veered) and when the depths were 50 m, the anchor would be ‘let go’[24]. The master noted to them that the PAN message suggested by Marine Rescue had not resulted in tug assistance being provided and ordered a distress message (MAYDAY) to be broadcast.
At 0814, the second mate transmitted distress alerts and messages on the ship’s global maritime distress and safety system (GMDSS) equipment. The distress messages were received by AMSA and other stations within one minute. By then, the ship had closed to 3.2 miles off the coastline.
At 0815, Engage Towage advised Sydney VTS that its tug, SL Diamantina, would depart its berth in about 15 minutes (the tug master had advised Engage Towage that its aft towing winch was not operational). Two minutes later, Monson sent an urgent email to the master (copying AMSA) to advise that a tug was being mobilised and Marine Rescue vessels were en route.
At 0822, the master updated Pacific Basin, noting the rocky seabed indicated on the chart in depths of 50 m and advised the intention to anchor in 40 m depths instead. At that time, the ship was 3 miles from the coast and entering New South Wales coastal waters.
In addition to communicating with Monson, Pacific Basin had contacted the ship’s hull and machinery insurance underwriter to seek any immediately available tugs through international salvage companies.
At 0825, Marine Rescue advised the master to expect rescue helicopters in 45 minutes and confirmed that the evacuating crew would assemble on the starboard side of the deck near cargo hold number 5. By 0828, AMSA had tasked 3 rescue helicopters (2 from NSW Ambulance Services and one from Westpac Lifesaver Rescue).
On board, by 0831, the chief mate and crew were on the forecastle and, at 0836, walked back one shackle of both anchor cables. A couple of minutes later, the master advised Pacific Basin that veering further cable with the ship rolling 35° risked fouling (entangling) the 2 chains.
At 0840, AMSA established an incident management team (IMT) for a severity level 3 incident (moderate) as per its internal procedures (see the section titled Maritime Assistance Services procedures under National level). The AMSA Response Centre (ARC)[25] duty manager assumed the incident controller role in this IMT (incident coordinator)[26]. Six minutes later, AMSA formally requested the ADF for assistance indicating that the ‘primary mission is rescue of crew’ because the ship could ground at 0930 on the cliffs south of Wattamolla (Figure 4 and Figure 5). Meanwhile, NSW Police had tasked another helicopter operated by the Rural Fire Service (RFS) to assist with evacuating the ship’s crew.
On board the ship, after further discussion with Pacific Basin, at 0843, the master ordered 2 shackles walked back on both anchor cables. Shortly after, Marine Rescue asked the master to prepare the ship’s towing equipment forward and, if possible, aft.
By 0846, Svitzer had agreed to provide Bullara to Pacific Basin under a ‘TOWHIRE agreement’[27] to assist the disabled ship.
At 0848, SL Diamantina with 3 crew on board departed Port Botany. At 0854, Sydney VTS advised Portland Bay's master that the tug’s ETA was in 90 minutes (about 1025) and to advise when the ship was anchored. Sydney VTS followed up with Svitzer at 0858 and was advised that Bullara was preparing to deploy.
At 0859, SL Diamantina’s master established communications with the ship’s master. Engage Towage advised United Salvage, with which it had partnered to provide assistance, that the tug was en route. The ship was now 1.4 miles from the rocky shore.
Emergency anchoring off Eagle Rock
At 0901 on 4 July, the master advised the chief mate to standby to let go the anchors and, at 0905, ordered the port anchor let go. The anchor cable was secured with 9 shackles out with the engine dead slow ahead to relieve load on the cable. The starboard anchor was let go at 0909 and, by 0915, its cable had been secured with 7 shackles out. Soon afterwards, the engine was stopped. The ship was anchored in depths of 45 m with a sandy seabed about one mile from the shore (Figure 5).
Figure 5: Ship’s anchor position (red marker) off Eagle Rock
Source: Google Maps, annotated by the ATSB
While anchoring, the master provided Port Kembla VTS various information requested, including electrical power and engine status, distance to the shore and helicopter winching information. By the time the ship was anchored, one of the 3 rescue helicopters was in its immediate vicinity and had established communications. The other 2 helicopters arrived on scene a short time later.
Meanwhile, at about 0915, United Salvage and Engage Towage began preparing to deploy SL Martinique. The tug was in White Bay, Sydney, but in addition to food, water and stores, it needed to be provided with suitable towing and salvage equipment before deploying.
At 0925, Marine Rescue advised the master to evacuate all but the essential crew required on board for a towing operation. The master discussed the evacuation with Pacific Basin and advised that the tug’s ETA was in one hour and suggested retaining 8 crew for a towing operation.
At 0926, the Westpac Lifesaver Rescue helicopter crew informed AMSA that a fourth helicopter, which was not expected, was in the area. It was soon identified as the RFS helicopter and AMSA instructed its pilot to return to base to avoid conflict with the other 3 rescue helicopters in the area.
At 0930, United Salvage briefed SL Diamantina’s master (via telephone) about the Lloyds Open Form (LOF) salvage agreement to be made with the ship’s master verbally (see the section titled Law of salvage under Salvage). United Salvage advised the tug master that the tug would need to push on the ship’s stern or midships to assist the ship and keep it away from the shore.
At 0937, the ADF advised AMSA that ADV Reliant was en route but the only assistance that this vessel could provide would be to launch its boats.[28]
Meanwhile on the ship’s bridge, at 0937, the third mate informed the master that the distance to the shore had reduced to 9 ‘cables’[29] (Figure 6). The master was still discussing the situation with Pacific Basin and suggested evacuating all non‑essential crew, including the 2 trainees on board.
Figure 6: The shore seen from the ship’s bridge
Source: Portland Bay’s master
From about 0945, a meeting involving officers from various responding agencies, including the Port Authority, NSW Maritime and AMSA was held (with most attending virtually). The main aim of this multi‑agency meeting was exchanging information and coordinating their respective roles and responsibilities, including the control agency leading the response.
At 0946, after 3 unsuccessful winching attempts due to the ship rolling and pitching heavily and unpredictably, and the master confirming the anchors were holding, the high‑risk evacuation was abandoned and AMSA instructed the 3 helicopters to return to base. The Challenger aeroplane tasked arrived in the area later but remained at high altitude and assisted with ship‑shore communication.
At about 0950, SL Diamantina’s master read out the LOF salvage agreement to which Portland Bay’s master agreed. At 0958, Svitzer advised AMSA that Bullara was available as Monson had advised that the tug was not required. About 10 minutes later, Monson confirmed to AMSA that it had released Bullara from a commercial perspective (the hire contract).
At 1008, Engage Towage emailed the master, Pacific Basin, AMSA, Monson and others confirming that, together with United Salvage, a LOF salvage agreement was in place and its tug, SL Martinique, was also deploying. Subsequently, when Pacific Basin informed the insurance underwriter that a salvage agreement was in place, the efforts to seek tugs from international salvors was discontinued.
At 1010, SL Diamantina arrived near the ship, which was rolling heavily. Over the next 15 minutes, the tug master assessed the situation, estimating that the south‑east swell was 9 m with waves rising to 12 m in the south‑easterly winds gusting to 45 knots. Rain squalls were reducing the visibility to 150 m.
At about 1020, the multi‑agency meeting concluded with the Port Authority assuming the ‘combat agency’[30] role as per the ‘NSW Coastal Waters Marine Pollution Plan’[31] (see the section titled Legislation and plans under State level). The Port Authority then established an incident management team (IMT) that would meet at 2‑hourly intervals and appointed its chief operating officer as the incident controller (IC). An AMSA liaison officer was assigned to this IMT. The NSW Maritime manager responsible was assigned to be a liaison officer for New South Wales and attended JRCC from just before midday.
Meanwhile, the AMSA IMT established earlier in Canberra was not formally dissolved and its team members continued in their roles to support the combat agency (the Port Authority and its IMT). At 1020, AMSA decided to deploy Bullara in case it was required and advised Svitzer that it would task the tug under their contract (see the section titled Emergency towage services contract under Svitzer Australia).
At 1028, after SL Diamantina’s master and the ship’s master agreed that the tug would push on its starboard side to relieve the load on the anchor cables, the tug began pushing along the midships area. However, after colliding with the shipside several times due to the heavy swell, these efforts were abandoned at 1033 to avoid serious damage.
At 1040, the tug master advised the intention to connect the tug’s towline (a synthetic fibre rope) through the ship’s centre fairlead to its mooring lines. Fifteen minutes later, the towline was connected to 2 synthetic fibre mooring ropes using a towing shackle and the tug master took some weight on the towline.
Meanwhile, both Bullara and SL Martinique had nearly completed their deployment preparations. At 1051, a few minutes after Engage Towage had informed AMSA about the salvage agreement in place, AMSA issued Svitzer a tasking direction for Bullara. Two minutes later, AMSA advised that the tug was to proceed to the scene and standby. Bullara left its berth at 1054. Shortly after, at 1058, SL Martinique with 6 crew on board left its berth under the instructions of United Salvage.
After SL Diamantina’s towline was secured, the ship’s engineers started work to repair auxiliary blower number 2. By 1100, they had removed the blower’s impeller and fitted a blank on the blower trunk (to allow the other blower to be used when operating the engine).
At 1140, AMSA became aware that United Salvage intended to replace SL Diamantina with SL Martinique, and AMSA then calculated the pulling power required to hold the ship and to tow it.
At 1158, the ship’s mooring ropes connected to SL Diamantina’s towline parted. After some difficulty, 2 mooring wires were connected to the towline at 1220. However, 10 minutes later, the wires also parted and efforts began to reconnect the towline.
At 1230, AMSA contacted United Salvage and was advised that it intended ‘to only use SL Martinique to tow’ and that there was ‘no requirement for Bullara’.
Meanwhile, the second meeting of the Port Authority’s IMT was held from about 1230. At this meeting, the IC asked the AMSA liaison officer for Svitzer Glenrock to be activated in case it was required for the response.
By 1244, SL Diamantina’s towline had been reconnected. About 20 minutes later, however, it parted again. A few minutes later, the ship’s master asked that no further attempts be made to connect the towline.
At 1324, AMSA released the Challenger aircraft that had remained above the ship’s location and it returned to base.
By 1400, the engineers had fitted a new impeller in the blower. Their attempts to fit a new electric motor had not been successful due to difficulties removing the existing motor’s pulley and the repairs were suspended.
At 1402, SL Martinique arrived near the ship and, shortly after, began connecting its aft towing wire to the ship’s port bow. A few minutes later, Bullara arrived at the scene and, at 1410, AMSA advised Svitzer that it had the option to make Bullara available to United Salvage under the LOF agreement or the AMSA contract(see the section titled Emergency towage services contract under Svitzer Australia). At 1413, AMSA also advised United Salvage that Bullara was available to assist the ship.
The ship’s anchors had continued dragging slowly and it was now about 7 cables from the shore. At 1425, United Salvage requested AMSA for the use of Bullara, which it approved with the same advice about contractual terms provided earlier to Svitzer.
At 1430, Pacific Basin advised AMSA that the ship’s engine could be operated at limited rpm (up to half ahead). By 1433, SL Martinique’s towline had been secured. Shortly after, Bullara began connecting its main aft towline (wire) to the ship’s starboard bow and, by 1455, it was secured. By this time, the IC had decided that the ship would be towed 20 miles from the coast under United Salvage’s direction (ports in and near Sydney were closed due to the bad weather).
Attempted tow to sea
At 1505 on 4 July, Portland Bay’s master began weighing the anchors. The main engine was used to assist and, by 1538, both anchors were home. At 1540, SL Martinique and Bullara started the tow with SL Diamantina following the ship (Figure 4). The engine was at slow ahead to assist, however, it was stopped at 1547 due to high temperatures caused by ‘scavenge space fires’[32].
With the ship under tow, AMSA released ADV Reliant from tasking at 1553. About 20 minutes later, AMSA also released the 2 water police vessels at the scene from SAR tasking.
At 1828, United Salvage asked the IC to open Port Botany for the ship to take shelter there (refuge) as, in the prevailing weather, the tow had progressed parallel to the coast (towards Sydney) rather than away from the coast. Minutes later, at 1835, Bullara’s towline parted at its inboard (tug) end and the wire fell into the water (its other end remained connected to the ship’s bow). SL Martinique was not able to tow the ship on its own but remained connected with little or no weight on the towline. The tug’s master had earlier injured their left shoulder but was able to continue working.
At 1839, United Salvage advised Svitzer and Engage Towage that Bullara’s towline had parted (it had no spare towing wire) and the ship’s engine could not be used. United Salvage then called AMSA and asked it to activate the ETV, Svitzer Glenrock, or to have Port Botany opened (see the section titled Incident management). At 1850, while considering the ETV request, AMSA convened a meeting with Svitzer and United Salvage to discuss whether ocean‑going towing equipment was available in the general area for use by harbour tugs.
Meanwhile, Portland Bay with SL Martinique’s towline connected, was drifting towards Bate Bay (Figure 4). The master decided to anchor again when water depths reduced sufficiently and prepared to deploy both anchors.
At 1901, United Salvage advised Svitzer that a request for refuge in Port Botany had been made and asked if the ETV could be ‘mobilised’. Svitzer advised that if AMSA did not activate it, the tug could be hired under a TOWHIRE agreement (see the section titled Incident management).
Shortly after, the IC called AMSA’s Maritime Emergency Response Commander – MERCOM (see the section titled Response commander under Pollution prevention) to follow up the request for the ETV made that afternoon via the AMSA liaison officer. The MERCOM was unaware of the request but agreed to activate the ETV. The MERCOM also offered to issue a ‘direction’[33] to facilitate the ship to be towed into Port Botany (see the section titled Place of refuge under Pollution prevention). The IC advised that the port was closed due to the weather so the ship could not be towed into port until the weather improved.
At 1945, United Salvage submitted a formal ‘place of refuge’ request via email to the MERCOM to allow the ship to be moved to Port Botany.
At 1957, AMSA issued a tasking direction for Svitzer Glenrock. Svitzer immediately instructed the ETV’s Newcastle‑based crew to prepare to deploy for the nearly 90‑mile passage to the ship’s location off Bate Bay.
At 2010, United Salvage stood down SL Diamantina as it was low on fuel and it returned to Port Botany. Other than its towing lines, the tug had no reported damage. The tug’s chief engineer had injured a knee and shoulder during the deployment but had been able to continue working.
The Port Authority’s IMT considered options to evacuate the ship’s crew if it became necessary due to the risk of stranding and Sydney VTS checked if any other tugs or vessels were available. No tugs were available in Sydney and a naval vessel there would take at least 4 hours to mobilise. By 2015, it was concluded that helicopter rescue operations would not be possible in darkness.
At 2030, Svitzer Glenrock’s crew boarded and began pre‑departure and towing gear checks.
Emergency anchoring off Bate Bay
At 2035 on 4 July, Portland Bay’s port anchor was let go in 40 m water depths where the seabed was sandy and 9 shackles were paid out. Five minutes later, the starboard anchor was let go and 6 shackles were paid out. By 2045, both anchors had been secured with the ship 1.4 miles from the coast. The south‑easterly swell off Sydney recorded at the time was 5.03 m (average) and 8.63 m (maximum).
The IMT continued monitoring the situation through Sydney VTS with a Sydney harbour pilot attending the VTS. SL Martinique maintained a static tow and increased weight on its towline when required to prevent the ship dragging its anchors. Bullara remained near the ship. The 2 tugs were the only surface assets available for a rescue operation if it became necessary.
In Newcastle, Svitzer Glenrock left its berth at 2227. At sea, the ETV’s master reported that in the 40‑knot south‑south‑east winds with 8 m waves and poor visibility, it could only make good a speed of about 5 knots. Meanwhile, AMSA’s search for ocean‑going towing gear had identified that Coral Knight, the level 1 ETV in Queensland, had such equipment.
At 0121 on 5 July, the rate at which the ship was dragging its anchors increased and the pilot asked for the weight on SL Martinique’s towline to be increased slightly to reduce the dragging.
Meanwhile, Svitzer Glenrock continued its passage with an ETA off Bate Bay of about noon.
During the night, AMSA continued monitoring the ETV’s ETA and the position of the ship, which was dragging its anchors at a rate of about 100 m per hour. At 0546, the MERCOM acknowledged United Salvage’s place of refuge request and advised that the ETV was due on scene at about midday with plans underway to move the ship to Port Botany, noting that it had not yet grounded. At 0717, following a request by AMSA Operations for the ‘need to evaluate the port of refuge’, the subject was discussed by its incident management team.
At 0848, the incident was upgraded to level 5 (severe) in accordance with AMSA’s procedures (see the section titled Maritime Assistance Services procedures under National level) noting ‘machinery failure and immediate tasking of ETV’. The ARC duty manager continued coordinating AMSA’s response to the incident with the MERCOM continuing to oversight response activities.
At 0900, the Port Authority IC asked the MERCOM to issue directions to facilitate the ship to be towed into Port Botany in daylight the following day (see the section titled Incident management). At 1145, the IC convened a meeting with United Salvage, Engage Towage and Sydney Pilots to plan the towage operation.
At 1257, AMSA held a meeting where the MERCOM advised the IC that Svitzer Glenrock would remain in AMSA control for the towage operation. Collectively, they decided that the Port Authority would continue managing the incident as the combat (control) agency until the ship was safely berthed. They agreed that AMSA would then exercise its regulatory functions as the safety authority.
At 1300, when Svitzer Glenrock arrived off Bate Bay, United Salvage asked for Bullara’s parted towline to be recovered. The wind had moderated to 30 knots, but the 8 m swell that remained made recovering the 200 m towing wire difficult.
By 1415 Bullara had recovered its towline and Svitzer Glenrock began connecting its towline. By 1515, the towline had been secured through the ship’s forward centre lead. Shortly after, Bullara was dismissed to return to port (other than its parted towline and minor damage on deck, the tug was not damaged). Svitzer Glenrock and SL Martinique remained with the ship and maintained a static tow.
At about 1605, AMSA emailed MERCOM’s directions to Portland Bay’s master, Pacific Basin, United Savage and the Port Authority, requiring the ship to be towed to a suitable berth in Port Botany (see the section titled Incident management).
Later that afternoon, United Salvage presented the towage plan prepared using the ship’s emergency towing procedure (see the section titled Incident management). The plan involved the use of Svitzer Glenrock and 3 Engage Towage tugs (SL Martinique, SL Fitzroy and SL Diamantina). At about 1800, after discussing the plan with the MERCOM, the IC approved it subject to suitable weather conditions (maximum swell 4 m) and daylight hours. They agreed that the operation could start at about 0800 on the following day, 6 July.
Refuge in Port Botany
At 0722 on 6 July, SLFitzroy arrived off Portland Bay in preparation for the tow. At 0845, a pilot vessel arrived with a United Salvage representative, a service engineer (representing the ship’s main engine manufacturer) and 2 Sydney harbour pilots on board.
By 0936, SLFitzroy’s towline had been secured through the ship’s aft centre lead. The pilots, salvor’s representative and service engineer had boarded the ship by 0954 and, at 1000, the master began weighing the anchors.
At 1051, both anchors were home and secured and, soon after, the ship was under tow with 3 tugs connected (Svitzer Glenrock, SL Martinique and SL Fitzroy). The main engine was used at dead slow ahead to assist the tow.
At 1228, the ship entered the port limits of Port Botany. SL Diamantina had arrived to assist with berthing and, at 1312, connected a towline to the ship aft.
At about 1409, the ship was alongside Hayes Dock berth 3. By 1454, all its mooring lines had been secured and all 4 tugs had been cast off and dismissed.
Shortly after, AMSA officers attended Portland Bay and carried out initial inquiries and inspections. At 1650, AMSA issued the master with a notice to detain the ship.[34] The reason for the detention was identified as ‘main propulsion system not able to reliably provide intended propulsion service’, which effectively made the ship unseaworthy. No damage was reported to have occurred due to the ship’s anchoring and towing operations and no‑one on board was injured during the incident.
By this time, various investigations into the incident, including those initiated by the ATSB, AMSA and Pacific Basin, had commenced with their investigators collecting relevant evidence on board the ship.
Inspections and repairs
On 7 July, an AMSA Port State Control inspection identified 14 deficiencies with Portland Bay’s main engine and associated machinery, including:
auxiliary blower number 2 not operational
non‑return flap in scavenge manifold stuck open
piston rings of all main engine units stuck due to excessive carbon deposits.
Pacific Basin submitted a plan to rectify all the deficiencies over the following week while berthed in Port Botany by carrying out the following work under the supervision of the main engine manufacturer:
overhaul of all main engine units
overhaul of auxiliary blower number 2
inspection and cleaning of main engine charge cooler
checking of the condition of main engine turbocharger
ordering spares (blower, non‑return valve and piston rings)
post‑repair main engine tests and ship’s classification society surveys.
The planned repairs were carried out over the following days in accordance with the manufacturer’s recommendations (see the section titled Post‑incident inspections under Propulsion).
On 13 July, the main engine was tested to the satisfaction of the ship’s classification society surveyor and engine manufacturer’s representative with an AMSA surveyor in attendance. The ship was then released from detention and, at about 1700, departed Port Botany for Gisborne, New Zealand.
Context
Portland Bay
General details
Portland Bay was a geared ‘handysize’[35] bulk carrier designed to carry dry bulk cargoes and timber (Cover). At the time of the incident, the ship was owned by Uhland Shipping, British Virgin Islands, and operated and managed by Pacific Basin Shipping, Hong Kong[36] (Pacific Basin). The ship was registered in Hong Kong and classed with Nippon Kaiji Kyokai, Japan (Class NK).
The ship was built in 2004 by Imabari Ship Building Company, Japan. It had a gross tonnage[37] of 16,960, an overall length of 169.26 m, a breadth of 37.20 m and depth of 13.60 m. At a summer draught of 9.78 m, the ship had a deadweight carrying capacity of 28,446 tonnes.
Four cargo cranes serviced the ship’s 5 cargo holds and fixed posts to lash timber cargoes were fitted on both sides of its main deck. The ship’s flush main deck extended to the forecastle where the mooring equipment, including electro‑hydraulic windlasses for the port and starboard anchors were located. Each anchor was fitted with 10 shackles[38] of 70 mm diameter chain cable.
Portland Bay’s navigation bridge (bridge) was equipped with navigational equipment in accordance with SOLAS[39] requirements for a ship of its size. This included 2 radars, 2 electronic chart display and information system (ECDIS) units, 2 very high frequency (VHF) radios and an automatic identification system (AIS) transceiver. A Qingdao Headway Marine model HMT‑100A voyage data recorder (VDR) recorded data for the time of the incident, including bridge audio.
Crew
At the time of the incident, the ship had a crew of 21, including the master. Thirteen of them, including the master and chief engineer, joined the ship in Port Kembla on 21 or 22 June 2022. All the crew, except for the Ukrainian master, were Filipinos.
The officers comprised the master, 3 deck officers (chief, second and third mate) and 3 engineers (chief, second and third engineer), all appropriately qualified for their positions. Others included 5 deck crew, 3 engine crew (a fitter and 2 motormen), one deck cadet and one engine cadet.
The master’s seagoing career began in 1999 with command first gained in 2004. The master had joined Pacific Basin in 2017 and completed 4 assignments as chief mate before being promoted in 2020. In 23 years at sea, the master had mostly worked on bulk carriers and some container ships as well as heavy‑lift cargo ships. The master had not previously sailed on Portland Bay but had on similar ships. The master’s handover notes, checklist and familiarisation, completed on 21 and 22 June, indicated that the ship, its machinery and equipment were in good working condition. That assessment had been confirmed by the outgoing master and chief engineer.
The chief engineer went to sea as a rating in 1992, progressed through the ranks in 3 different companies and, in 2015, obtained chief engineer qualifications. In 2016, he joined Pacific Basin and worked on its ships as a second engineer until being promoted to chief engineer in 2021. He joined Portland Bay for the first time on his second assignment as chief engineer. The chief engineer’s handover checklist indicated that the only major work planned for the following month was the renewal of the exhaust valves on 2 main engine units, with no issues of ongoing concern.
Propulsion
Portland Bay’s propulsion was provided by a Makita Mitsui MAN B&W 6S42MC diesel engine that could deliver 5,850 kW at 129 rpm. The main engine drove a single, fixed‑pitch, four‑bladed, right‑handed propeller. The ship’s designed service speed at 122 rpm (that is, 85% of the engine’s maximum continuous rating) was 14 knots (laden) and 14.5 knots (in ballast).
The ship’s propulsion (single engine and propeller), power and design speed were typical for its size and type with no auxiliary propulsion or thrusters. Table 1 below shows relevant data from the ship’s manoeuvring (harbour speed) table. The indicative speeds in the table were based on full propeller immersion, which occurred when the aft draught was 5.1 m or more.
Table 1: Portland Bay’s manoeuvring speed information
Engine order
Speed (rpm)
Laden speed (knots)
Ballast speed (knots)
Dead slow ahead
42
5.1
5.3
Slow ahead
58
7.1
7.3
Half ahead
80
9.6
9.9
Full ahead
90
10.6
11.1
Engine combustion air system
Air for fuel combustion (scavenge air) was drawn from the engine room through filters into the turbocharger compressor (Figure 7). The turbocharger compressed the air and discharged it to the scavenge air cooler, which cooled and dried the air before passing the outlet via non‑return flaps.
Figure 7: Slow speed MAN B&W diesel engine combustion air and exhaust system
Source: MAN B&W, annotated by the ATSB
Pressurised air from the cooler went into the scavenge air receiver or trunk, which extended the entire length of the engine and was connected to each cylinder through a pipe in the under‑piston scavenge space. As the piston came down, scavenge ports (cutouts) in the lower cylinder liner were exposed, allowing air into the cylinder above the piston. In combination with the now open exhaust valve at the top of the cylinder, the scavenge air cleared the cylinder of combustion gases and provided fresh air for the next combustion cycle. As the cycle continued, the piston moved up, blocking the scavenge ports, the exhaust valve closed, the air was compressed (increasing its temperature), atomised fuel was injected in and when the piston reached top dead centre, combustion occurred. Expanding gases then forced the piston down for the repeat cycle.
Combustion gases were cleared from the cylinder as the exhaust valve opened and the scavenge ports were uncovered. The combustion gases then passed into the exhaust gas receiver and to the turbocharger turbine side to drive the compressor and draw fresh air into the engine. The exhaust gases from the turbocharger discharged to atmosphere through the exhaust trunk (inside the engine room funnel).
At low engine loads (below 30–40% of maximum load), air supply was boosted by 2 electrically‑driven auxiliary fans or blowers. The auxiliary blowers provided air to the engine until there was sufficient exhaust gas to drive the turbocharger and supply the required volume and pressure of air. The blowers generally operated in automatic mode providing air at low engine load (speed) and stopped operating at higher load (speed) when the exhaust gas‑driven turbocharger could meet the demand for air. The blowers drew air from the charge air cooler outlet and discharged it through non‑return flaps, directly into the scavenge trunk (Figure 8). In effect, the blowers pumped air around the turbocharger non‑return flaps.
Figure 8: Air system non‑return flaps
Source: Pacific Basin, annotated by the ATSB
Complete combustion was essential for the efficient operation of the main engine. The combustion, in turn, relied entirely upon a consistent, reliable air supply. It was therefore critical for the scavenge air system to be sufficiently airtight, particularly at low engine load/speed. The following 3 running surfaces in the air system sealed the system from leakage:
Auxiliary blower shaft seal.
Piston rings sealing the cylinder combustion space from the under‑piston scavenge space (loss of this seal could result in piston ring blow by leading to sludge accumulation in the scavenge space, loss of cylinder pressure, poor combustion and scavenge fires).
The seal between the scavenge space and the crankcase (through the diaphragm, sealing around the piston rod), known as the stuffing box.
In addition to scavenge air loss due to leakage, the following could lead to inefficient combustion:
Loss of auxiliary blower effectiveness due to air flow recirculation, such as leaking turbocharger non‑return flap(s) allowing air to flow about the blower, from discharge to suction (disrupts blower throughput and reduces scavenge trunk pressure and air flow for combustion).
Air flow restrictions from:
fouled scavenge ports due to accumulated deposits from piston ring blow by, stuffing box leakage or dirty air,
turbocharge fouling (turbine or compressor),
dirty turbocharger inlet filters,
air cooler fouling.
Scavenge fire (ignition of combustible material accumulated in the scavenge space above the diaphragm).
A scavenge fire consumes air for combustion and can seriously damage components if not extinguished quickly. Poor atomising of fuel, excessive fuel supply (for the available air), piston ring blow by, stuffing box leakage and excessive cylinder lubrication can all produce combustible material.
Ship’s engine performance
After Portland Bay left Port Kembla on 3 July and the pilot disembarked, the main engine order (demand) was set at full ahead (90 rpm). The engine rpm achieved fluctuated widely about the demand (90 rpm) as the ship (in ballast condition) rolled and pitched heavily in the prevailing weather conditions with its propeller not always fully immersed (Figure 9).
Figure 9: Engine speed demand (green or red) and actual speed (blue) on 3 and 4 July
Source: Portland Bay’s recorded voyage data, annotated by the ATSB
Subsequently, the ship drifted and intermittently steamed slowly with both the auxiliary blowers operating. At 0450 on 4 July, when a fire alarm activated, the engineers observed smoke and a burning smell from blower number 2 and manually stopped it (the motor did not trip). Inspections later identified that the blower’s impeller bearings had failed.
After the failure of auxiliary blower number 2, the engine speed continued to follow the demand for dead slow and slow ahead. However, after about 0550, when attempts were made to increase speed beyond slow ahead, the engine did not respond to the speed demand (Figure 10).
Figure 10: Speed demand (green or red) and actual speed (blue) from 0445 to 0700, 4 July
Source: Portland Bay’s recorded voyage data, annotated by the ATSB
The varying engine load and speed led to adverse engine operating conditions, including:
poor combustion
turbocharger surge
scavenge trunk pressure fluctuations
fluctuating, and frequent, excessive and mismatched, fuel and air flow
repetitive opening and closing of scavenge system non‑return flaps
sticky piston rings, blow by and scavenge fires.
These operating conditions eventually resulted in the main engine being unable to achieve more than about 40 rpm. Overriding normal engine operating control limits and attempting to operate the engine locally (emergency control) to manually control the fuel supplied did not improve engine performance.
Main engine maintenance
When inspected after Portland Bay berthed in Port Botany on 6 July, the main engine had recorded 90,388 running hours. The ship’s planned maintenance system (PMS) was consistent with and supported the Class NK continuous machinery survey (CMS) requirements for classed machinery, including the main engine. There were no outstanding engine maintenance requirements and all the engine units had less than 5,000 running hours since their last inspection.
On 3 June (one month before the incident), the scavenge spaces were inspected and cleaned as part of routine maintenance. The inspection report showed the scavenge spaces and ports and the piston crowns and rings were clean and in generally good condition.[40] The report indicated that the auxiliary blowers and non‑return flaps were clean and intact.
Later in June, while en route to Port Kembla, there were difficulties maintaining full sea speed (122 rpm) due to high scavenge air and engine lubricating oil (LO) temperatures. It was therefore decided to clean the LO cooler, LO filter and charge air cooler when berthed in Port Kembla. In addition to these prioritised tasks, other tasks planned for the port stay included replacing the impeller and bearings in auxiliary blower number 2 with new spares.
Auxiliary blower number 2
About 3 years before the incident, in April 2019, auxiliary blower number 2 had failed and been repaired. The blower failed again in November 2019 and was repaired and, in June 2021, its motor and impeller bearings were replaced.
In March 2022, vibration monitoring revealed abnormal vibrations from the blower. The inspection identified a cracked impeller, damaged shaft bearings and worn bearing housings. The impeller was replaced with a previously used impeller. The cracked impeller was weld repaired and about a month later, in April 2022, it was refitted in the blower without rebalancing. New bearings were fitted in the same worn bearing housings as there were no spares on board.
In late May 2022, a new impeller and bearing housings were received when the ship was in China. As the ship’s operations there, and subsequently in Susaki, Japan, did not allow the new spares to be fitted, this task was postponed until the ship was in Port Kembla as noted above. The priority tasks (LO cooler, LO filter and charge air cooler) were completed from 22 to 26 June but the maintenance for auxiliary blower number 2 was outstanding when the ship left port on 3 July.
The impeller’s unbalanced operation was exacerbated by the varying engine load conditions after the ship left Port Kembla, resulting in the blower’s failure on 4 July. Later that day, the engineers removed the impeller and fitted the new impeller and bearings. They assumed that the electric motor was damaged (burnt out), tried removing it but found its belt drive pulley difficult to remove. The repairs were then abandoned without testing the motor with the blower deemed inoperable and remaining out of service for the duration of the incident.
Following the incident, when the ship was in Port Botany, the electric motor was removed and sent ashore for overhaul. Apart from some in‑service wear and tear, the motor was found to be operational.
Post‑incident inspections
After the incident, the main engine manufacturer’s service department, MAN PrimeServ, conducted an engine inspection and service while the ship was in Port Botany to identify reasons for the engine speed not increasing beyond 40 rpm, and carrying out necessary repairs. The inspection and service included:
overhaul of all pistons and calibration of cylinder liners
inspection of scavenge spaces including scavenge air receiver, non‑return flaps and under piston scavenge spaces and stuffing boxes
charge air cooler removal and clean
overhaul of auxiliary blower number 2.
The inspection identified several issues with engine components, including:
piston, ring and ring gap measurements close to wear limits
sticky piston rings on all pistons
cylinder liner measurements all well within limits
carbon build‑up in cylinder liner scavenge ports
a leaky fuel injector
a damaged turbocharger non‑return flap
a non‑return flap for auxiliary blower number 2 stuck open
excessive carbon build‑up and unburnt fuel in the turbocharger
excessive cylinder lubrication and piston blow‑by in some cylinders
dirty scavenge spaces with excessive sludge and carbon build up in the air receiver and around stuffing boxes.
A build‑up of carbon, fuel and deposits throughout the scavenge system, pistons, turbocharger and other engine components was also evident. Figure 11 shows the condition of a piston (a), stuffing box (b), scavenge ports (c) and turbocharger turbine housing (d).
Figure 11: Condition of some engine components
Source: Pacific Basin and MAN PrimeServ, annotated by the ATSB
The build‑up of carbon, fuel and deposits was assessed as probably being the result of:
speed fluctuations resulting in excessive fuel injected into the engine leading to incomplete and unstable combustion
piston blow‑by due to sticky piston rings caused by poor combustion, excessive fuel injection, excessive cylinder lubrication and a leaky fuel injector
excessive cylinder lubrication leading to excess oil in the under‑piston space.
The inspection and service concluded that the principal reason that the engine was unable to increase speed beyond about 40 rpm was insufficient air for combustion.
The condition of each engine component, on its own, was within specifications and was not considered enough to disrupt the combustion air flow to the extent of preventing the engine achieving the speed demanded. However, wear and fouling of multiple engine components, together with the loss of the auxiliary blower and open scavenge system non‑return flaps were considered, in combination, enough to prevent the engine from receiving enough air to increase speed past about 40 rpm, regardless of demand.
Class NK required a performance test to be conducted with a report provided to the engine manufacturer. The engine service described above was followed by an engine trial on 13 July while berthed in Port Botany with the manufacturer’s representative, Class NK surveyor and AMSA surveyor in attendance. A sea performance trial was conducted later to the engine manufacturer’s satisfaction.
Planned maintenance system
The ship’s planned maintenance system (PMS) noted above incorporated Class NK machinery survey requirements and was part of the shipboard safety management system (SMS). The engine manufacturer’s instruction manuals were available for carrying out maintenance and repairs in accordance with the PMS. The procedures and guidance available on board covered necessary engineering matters, including avoiding, detecting and extinguishing scavenge fires.
In addition, Pacific Basin’s dedicated manager for the ship oversighted and supported shipboard engineering matters. As auxiliary blower number 2 had been working satisfactorily, fitting the new spares were not prioritised over other tasks by the ship’s manager and the chief engineer.
Safety management system
Portland Bay’s safety management system (SMS) was intended to cover all shipboard operations with some procedures for navigation (bridge) and emergencies directly relevant to this incident.
Bridge procedures
Navigation‑related procedures were contained in the Bridge Manual of the SMS.[41] The procedures referenced recognised industry standards and guidance, including SOLAS, International Maritime Organization (IMO) guidelines and the Nautical Institute’s Bridge Team Management guide.
The procedures required that, in adverse weather, masters increase distance from navigational dangers to 20~50 miles, as reasonably practicable, to maintain a safety margin. The margin was required to be sufficient to ensure that adequate time would be ‘available to respond to contingencies at sea such as machinery failures (main engine, steering and generators)’.
According to Pacific Basin, it did not encourage drifting to reduce fuel consumption and procedures advised masters to not hesitate adjusting course and/or speed, including ‘heaving‑to’[42], in heavy weather to avoid damage to the ship and its machinery. If the master decided to drift, the ship was required to be about 50 miles from the nearest land or navigational danger, where practicable.
The bridge heavy weather checklist stated that anchors were designed to hold the ship in sheltered waters. It warned against anchoring in adverse weather (wind force 6 or swell higher than 1.5 m). If anchoring in depths less than 40 m, the anchor had to be walked back (veered) within 5 m of the seabed before it was let go. In depths of 40 m or more (defined as deep water), the anchor had to be walked back throughout, with the ship stationary over ground. Anchoring in depths greater than 100 m was prohibited except in an emergency and it was noted that the windlass was only designed to lift the anchor and 3 shackles (about 85 m) of cable.
In general, these SMS procedures and guidance were consistent with recognised practice. Drifting can expose a ship to risks due to bad weather, traffic, land and other hazards. When drifting in bad weather, the ship’s motion cannot be controlled and it is prone to rolling, pitching or surging and consequential damage (hull, machinery or cargo). Passing traffic can pose a risk of collision unless mitigated by having the propulsion and steering in readiness. The proximity of hazards increases the risk of allision, contact or grounding.
While it may be safe to drift in calm weather, far from traffic and land, drifting generally involves risks (which increase significantly in bad weather) and it is generally not considered a prudent option. There may also be commercial considerations, for example, a ship on charter (hire) that immobilises its propulsion to drift might be deemed ‘off hire’. Drifting due to a breakdown means a compromised status (not under command) and a disabled ship close to a lee shore in bad weather may have to make emergency use of its anchors as described above. The ‘Peril at Sea and Salvage: A Guide for Masters’[43] publication, which the procedures referred to also contained relevant guidance for emergency anchoring (see the section titled Shipboard response under Response fundamentals).
Emergency procedures
Pacific Basin’s Crisis Management Manual[44] contained procedures for managing shipboard emergencies. The comprehensive range of subjects in the manual included emergency types, drills (shipboard and ship‑shore), crisis management teams and procedures, shipboard plans, reporting requirements, emergency contacts and guidance on towage and salvage.
The manual required monthly shipboard drills simulating different, realistic scenarios and involving relevant ship’s staff. In addition, ship‑shore drills involving different ships to exercise Pacific Basin’s shore management were to be conducted annually. Checklists and flow charts to make the procedures user‑friendly were included in the manual.
In an emergency, the master was to notify Pacific Basin management through contacts identified in the manual. The order of priority for the contacts was the ship’s dedicated manager, company marine and safety manager, general manager and fleet director. The master could also contact the company’s designated person ashore (DPA). If required, shore management would establish a crisis management team to support and guide the master in managing the emergency.
The master was also responsible for notifying other relevant parties, including authorities. The ‘main engine/power failure’ form listed several parties to be notified. These included the rescue coordination centre (RCC) and authority (including AMSA if the ship was in Australia). In addition, there was a ‘main engine/power failure’ checklist, which included an item for informing nearby ships and VTS/Port Authorities, as appropriate. The checklist completed for this incident indicated that this check was complied with at 0700 on 4 July (Port Kembla VTS was notified at 0657).
The manual warned that a loss of propulsion or steering, grounding or hull breach could result in pollution but emergency towing could prevent a spill or mitigate its impact. It provided general guidance about towing and that ship‑specific towing arrangements were detailed in the ship’s emergency towing booklet. A checklist for a disabled ship under tow was included, noting that further guidance for towing was available in the masters Guide (Peril at Sea and Salvage).
The manual specifically reiterated the master’s overriding authority and responsibility with respect to safety and pollution prevention. It was further stated that this overriding authority extended to agreeing a salvage contract under ‘Lloyd’s Open Form’[45] terms if required by the situation.
Incident location
As previously described, Portland Bay anchored in 2 separate locations, each off a dangerous lee shore (Figure 12).
Figure 12: Anchor positions off Eagle Rock and Bate Bay on 4 July 2022
Source: Google Maps, annotated by the ATSB
Anchor position 1 was about one mile from the cliffs near Eagle Rock south of Wattamolla (Figure 13). Similarly, anchor position 2 was about one mile from the nearest reef in Bate Bay. The ship dragged its anchors towards the shore in both locations. As described in the Admiralty Sailing Directions,[46] the coastline between Port Kembla and Sydney offers little to no shelter. Sydney (Port Botany and Port Jackson) lies about 32 miles (60 km) north‑north‑east of Port Kembla (Figure 1 and Figure 4).
Figure 13: Portland Bay at anchor about one mile from the cliffs near Eagle Rock
Source: Svitzer Australia
The Sailing Directions stated that the coastline from Port Kembla extends in a northerly direction for 10 miles to Bellambi Point and then runs in a north‑north‑easterly direction. The Directions indicated that the shore is generally low up to the vicinity of Coalcliff (19 miles south of Sydney) after which the coastline is dominated by cliff faces and rocky shores. The Directions noted that Garie Beach breaks the line of cliffs fronting the coast between Stanwell Park (near Coalcliff) and Wattamolla (11 miles south of Sydney). It was stated that, between Wattamolla and Port Hacking Point, the coast is a continuous line of cliffs broken only by Marley Beach. The proximity of the cliffs and rocky shores to anchor position 1 made it a very hazardous location (Figure 13).
The ship was anchored off Bate Bay for 2 nights. The Sailing Directions stated that Bate Bay, entered between Glaisher Point and Potter Point, is exposed and of no use as an anchorage. The Direction’s further noted that Osborn Shoal lies in the middle of the entrance to the Bate Bay and the bay’s shore between Glaisher Point and the southwest end of Cronulla Beach is formed by an irregular line of cliffs. It was also stated that the beach, backed by sandhills 12–14 m high, extends about 2.5 miles north‑east to a rocky point, from which Merries Reef (it breaks) extends 6 cables to the south‑west.
The location where the ship broke down in heavy weather exposed it to a very high risk of a catastrophic stranding on the rocky shore and cliffs near anchor position 1. During the first 5 hours that it was there, the anchors dragged about 4cables closer to the shore. Had the ship stranded on the rocky shore and broken up, the 809 tonnes of heavy fuel oil and 133 tonnes of diesel oil on board would probably have escaped and polluted the surrounding water and shoreline. In addition, abandoning the ship in those conditions posed a very high risk of injury to the crew.
Anchor position 2 was comparatively less dangerous but the extended time over which the anchors were once again relied upon to hold the ship in bad weather exposed it to a high risk of stranding, even with a tug connected. In this position too, the anchors dragged and the ship came within a mile of the shore. Once again, a stranding in rough weather posed a risk to the safety of life, with environmental pollution likely.
Maritime emergencies
This section provides details on salvage, towage, intervention and refuge matters, which were prominent features of the incident response.
Peril at sea
The sea can be a harsh environment and seafarers have encountered perils there since they first began sailing across oceans and seas. While modern ships are larger and safer, from time to time they face perils at sea that result in serious casualties.
Serious causalities, such as collision and grounding, which can result in failure of the ship’s hull, or propulsion or steering failures close to the coast can result in strandings. Extreme weather is often a factor in the development of an emergency at sea, complicating the emergency and the response. The number and extent of other factors associated with the emergency influence its complexity, successful resolution and/or the adverse consequences. These can include the loss of the imperilled ship, its crew and cargo, and damage to the environment.
The publication, Peril at Sea and Salvage: A Guide for Masters, provided ship masters essential guidance for the actions to take when confronted with an emergency at sea. The Guide defined a ‘shipping emergency’ as a major incident that has the potential to put at risk the safety of persons, the ship, the environment and the cargo. Many examples of emergencies were listed in the Guide, including collision, grounding or stranding, loss of propulsion, structural failure and pollution.
The Guide also provided essential information for others that interact with masters in an emergency, including ship owners and operators, salvors and maritime authorities. First published in 1979, the Guide has provided practical guidance for masters to effectively manage an emergency, including the subjects of towage and salvage, and was recognised as best practice on the subject.
Salvage
Salvage is the act of saving property from being destroyed and, in the maritime context, it is saving a ship and/or its cargo from being lost, which are then said to have been ‘salved’. The concept of salvage is ancient as ships have encountered perils at sea throughout history. The claim for salvage (the salvors reward) is an ancient right that can be traced to the laws of the ancient Greeks.
Those ancient laws and public policy with respect to salvage were based on encouraging salvors to help imperilled ships in the vast expanses of the world’s oceans and seas by rewarding them for success. The reward also discouraged the temptation to piracy to some extent. This ancient right of salvage is peculiar to maritime law (that is, the right does not apply to saving property on land).
Law of salvage
Historically, the law of salvage has been based on the ‘no cure – no pay’ principle (that is, no reward for failure). The value of the salved property was used to determine the reward and this is generally still the case for fixing the salvage award (remuneration in financial terms). Several other criteria are also used to fix the award.
There are 4 essential elements of a claim for salvage:
the salvor must be a volunteer (that is, no pre‑existing contractual duty or statutory duty to act)
the salvage needs to be successful (or contribute to success)
the subject of salvage can be a ship (any vessel capable of navigation) or other property at sea (such as a ship’s cargo)
there must be an element of danger from which the subject property is saved.
A simple example of a successful salvage is a salvage company or tug that voluntarily salves a ship and/or its cargo that was in danger of being lost. The salved ship’s master and crew do not have a right to salvage because they have a duty to act. Salvage cannot be claimed for saving life as it has long been recognised that every seafarer must go to the assistance of another.
Environmental pollution and protection were not part of early salvage law. The increasing focus on the environment in the latter part of the twentieth century resulted in changes to the long‑standing public policy in order to protect the environment through an appropriate legal framework. Although modern ships, communications and technology have somewhat diluted the basis for the original public policy, historical common law salvage concepts have been retained.
The major catalyst to change the law of salvage was the environmental disaster involving the oil tanker, Amoco Cadiz (Figure 14). On 16 March 1978, the ship, laden with 220,000 tonnes of crude oil, broke down in heavy weather off the coast of north‑west France. The ship drifted onto the lee shore, where it grounded (stranded) and widespread pollution resulted.
Figure 14: The stranding of Amoco Cadiz and resulting environmental disaster
Source: Counterspill.org
A salvage tug had been made fast well before the ship grounded but there was a long delay before the salvage contract was agreed. While many attributed the stranding to the delay, the salvors denied that assertion. The public furore which followed this disaster resulted in the IMO commissioning a review of the 1910 Salvage Convention to ensure that modern needs and protection of the environment were addressed.
The IMO‑commissioned review resulted in changes to the law of salvage through the International Convention on Salvage, 1989 (Salvage Convention)[47]. The Salvage Convention came into force in 1996 and replaced the 1910 Convention, which had codified salvage law based on the existing case law (common law). Since then, the legal framework for salvage has in general been governed by the 1989 Convention, which included provisions to protect the environment by making ‘special compensation’ available to salvors.
Special compensation was intended to encourage salvors to go to the assistance of ships which threatened damage to the environment as salvors would at least recover their expenses. Avoiding or preventing environmental damage was also a clear benefit to owners (ship, cargo and others) and insurers (cargo, hull and others).
The right to claim salvage is not dependant on the existence of a salvage contract. Rendering a salvage service always entitled the salvor to claim salvage under common law. Where there is a salvage contract, the right is covered by statutory law and most salvage in modern times has been carried out under contract. The Lloyd’s Open Form of Salvage Agreement often known as Lloyd’s Open Form (LOF) as referred to previously is the most well‑known and frequently used salvage contract.[48] Its 2020 version, LOF 2020, was current at the time of this incident (Appendix A).
The first LOF ‘no cure – no pay’ salvage agreement was made in 1894 and in 1908, the form was published for international use. Since then, the form has been revised several times and LOF 2020 was the twelfthrevision. The LOF provides a standard contract form that is easily understood and recognised as being fair to salvors, shipowners, cargo owners and insurers. This standard form does not need to be signed to be legally binding with a verbal agreement being sufficient. This feature can be invaluable in time‑critical situations.
Special compensation provisions introduced by the 1989 Salvage Convention were progressively incorporated into successive versions of the LOF. In LOF 2020 (and some previous versions), this was in the form of the Special Compensation P&I Club (SCOPIC) clause.[49], [50] Developed by the International Group of P&I Clubs and International Salvage Union (ISU)[51], the SCOPIC clause comprised 16 sub‑clauses that set out the basic scheme and contractual position between the salvage contractor and the shipowner.
The main purpose of the SCOPIC clause was to ensure fair compensation for the salvor’s efforts to prevent damage to the environment even if salvage was unsuccessful (Article 14.1 of the Salvage Convention).
In practice, the parties to a salvage agreement incorporated the SCOPIC clause by selecting the agreed option in the agreement (Yes/No option in box 7 of LOF 2020). While incorporating the clause is voluntary, it is almost always used by professional salvors when there is a threat to the environment. The Peril at Sea and Salvage: A Guide for Masters publication described key LOF features, including special compensation. The LOF 2020 and SCOPIC clause were reproduced in an appendix to the Guide.
In determining a salvage award, Article 13.1 of the Salvage Convention stated that the following should be considered:
salved value of the vessel and other property
skill and efforts of the salvors in preventing or minimising damage to the environment
measure of success obtained by the salvor
nature and degree of the danger
skill and efforts of the salvors in salving the vessel, other property and life
time taken and expenses and losses incurred by the salvors
risk of liability and other risks by the salvors or their equipment
promptness of the services rendered
availability and use of vessels or other equipment intended for salvage operations
state of readiness and efficiency of the salvors’ equipment and the value thereof.
As applying these 10 criteria to the circumstances of a particular case is rarely straightforward, the remuneration for a salvage award and/or special compensation under an LOF agreement is determined by arbitration in accordance with the agreement’s arbitration clauses.
Duties of the parties
Article 8 of the Salvage Convention set out the duties of the salvor and the owner of the property (ship and cargo) to be salved and are summarised below. They are complementary and intended to ensure the success of the salvage operation and avoid damage to the environment.
The salvor owes a duty to the owner of the ship or other property in danger:
to carry out salvage operations with due care
exercise due care to prevent or minimise damage to the environment
when the circumstances reasonably require, to seek assistance from other salvors
accept the intervention of other salvors when reasonably requested by the owner or master.
Similarly, the owner and master of the ship or other property in danger owe a duty to the salvor:
to cooperate fully during the salvage operations
exercise due care to prevent or minimise damage to the environment
when the ship or other property has been brought to a place of safety, accept redelivery when reasonably requested by the salvor.
Towage
Salvage of a ship disabled at sea almost always involves towing it to a place of safety. However, salvage should not be confused with towage, with the following key differences between them, the first point being the essential difference:
salvage requires an element of danger whereas towage does not
successful salvage claims require ultimate success while towage often does not
salvage gives rise to a maritime ‘lien’[52] while towage only gives rise to a statutory lien
a salvage claim is usually against the shipowner and cargo but towage involves the shipowner
salvage and towage are normally carried out under different contracts and masters.
Regardless of whether a towage or salvage contract is agreed, the conduct of the towing operation will be the same. International guidelines and best practice exist to ensure that towing is safe and effective.
Ocean towing guidelines
The IMO has developed guidelines for international ocean towing that can be used for any other towing operation.[53] They were developed for commercial towage operations, which were not in the nature of salvage. In Australia, the guidelines have been used for AMSA‑contracted emergency towing vessels (see the section titled Emergency towage services contract under Svitzer Australia).
The guidelines specified standards and recommended requirements for towing vessels and equipment and addressed relevant subjects, including manning, planning, preparation, design environmental conditions and bollard pull (BP)[54] testing. In terms of overall capability, the BP was required to be sufficient to tow in weather conditions comprising wind 20 m/s (39 knots), significant wave height 5 m and current 0.5 m/s (1 knot), all acting in the same direction.
The minimum length of the main towline is particularly important. The guidelines specified that, in the absence of other established criteria, the required length should be determined using the following formula (where L is the towline’s minimum length, BL its documented breaking load and BP the vessel’s continuous bollard pull).
L = (BP/BL) x 1800 m
Using this formula, a 162 t BL towline on a 65 t BP tug needs to be at least 720 m long.
The minimum documented breaking load (MBL) of the main towline was generally required to be between 2 and 3 times of the BP. The guidelines provided formulae (based on the BP) to calculate the towline MBL (Table 2).
Table 2: Main towline breaking load
Bollard Pull
BP <40 t
BP 40-90 t
BP >90 t
Minimum Breaking Load (tonnes)
3.0 x BP
(3.8 – BP/50) x BP
2.0 x BP
Source: IMO
When applied to a 60 t BP tug, the formula provides a required MBL of 156 t. It was required that fibre rope pennants (if used) should have an MBL of not less than 2 times that of the towline’s MBL (BP<50 t), 1.5 times (BP>100 t) and linearly interpolated between 1.5 and 2 times for BP between 50 and 100 t. It was also required that the capacity of connecting links (shackles, rings etc.) should be at least 50% more than the towing arrangement’s documented MBL.
The guidelines required that a spare towline satisfying all the requirements of the main towline be carried and stowed on the towing winch if it had 2 drums. Alternatively, the spare line could be arranged to ensure transfer to the main towing drum, provided that it could be conducted safely and quickly. The guidelines recommended that, unless impractical, the vessel was to be equipped with sufficient spare equipment to completely replicate towing arrangements.
Other key towing equipment standards and requirements included that:
the towing winch which can withstand the breaking load of the main towing wire
there must be means to:
release tension on the winch drum(s) in an emergency
effectively spool the towline effectively on the drum(s)
protect towlines from chafing or abrasion
all wire ropes have the same lay (right or left hand)
there are hard eyes for all wire rope terminators.
In addition to safety certification appropriate for the towing vessel’s size, documentation for towing equipment and continuous BP at maximum rated power was required to be carried. Towing vessels also had the following general and equipment requirements.
a documented maintenance system for main and auxiliary machinery, steering and towing gear, and navigation and communication equipment
fitted with radar, electronic positioning device, magnetic steering compass, echo sounder, navigational charts and publications and VHF radios
have self‑sufficient fire suppression capability and a searchlight (directed from the main steering station).
General towing guidance
The masters Guide (Peril at Sea and Salvage) covered towage, including deep sea or ocean towage when the ship was not in imminent danger. It outlined SOLAS requirements for tankers to be fitted with emergency towing arrangements and all cargo and passenger ships to be provided with a ship‑specific emergency towing procedure. The procedure was required to include drawings of towing arrangements, inventory of towing equipment, communication methods and sample procedures for emergency towing.
The Guide provided detail on both planned and emergency towage, and specifically the types of towing equipment and arrangements fitted on ships and how to connect and start a tow. If the ship was in imminent danger, the master was advised to summon immediate salvage assistance and accept LOF salvage terms. Useful guidance on the actions to take if other salvage terms were offered was also provided.
The Guide outlined the use of a dedicated towage vessel, such as an ocean‑going tug. The following list of suitable towing vessels, in order of preference, was included:
ocean‑going salvage tug
anchor‑handling/supply vessels
escort tugs
anchor‑handling tugs
harbour tugs
warships
any other suitable ship.
The Guide noted that warships were not ideal towing vessels but were powerful and had other advantages, such as a relatively large crew and helicopter or rescue craft. By contrast, modern merchant ships were noted as being impractical for towing due to their large size.
Places of refuge
Sheltered waters may be needed for salvage operations but the ship could endanger the coastal state that has jurisdiction over those waters or places of refuge. During the drafting of the Salvage Convention in the 1980s, there was much discussion about places of refuge to achieve a balance between the interests and rights of coastal States and their expected obligations. The result was Article 11 of the Convention:
A State Party shall, whenever regulating or deciding upon matters relating to salvage operations such as admittance to ports of vessels in distress or the provisions of facilities to salvors, take into account the need for co‑operation between salvors, other interested parties and public authorities in order to ensure the efficient and successful performance of salvage operations for the purpose of saving life or property in danger as well as preventing damage to the environment in general.
However, international guidelines that included practical guidance about refuge for ships in danger remained elusive for nearly 2 decades. The subject came to the fore around the turn of the century because of 3 significant and high‑profile environmental incidents, which occurred in relatively quick succession. The incidents involved the tankers Erika,[55]Castor[56]and Prestige. The sinking of Prestige was the final trigger for developing international standards for places of refuge and related matters.
On 13 November 2002, Prestige, carrying 77,000 tonnes of heavy fuel oil had a hull failure during a storm off the Spanish coast. Part of its crew were evacuated and the ship drifted within 4 miles of the coast with its cargo leaking. Spanish, French and Portuguese authorities all refused refuge to the stricken tanker, which was instead towed out to sea. On 19 November, the ship broke in 2 and sank 160 miles off the Spanish coast (Figure 15). Much of its cargo spilled and most of what remained within the hull escaped into the sea over the following days and months, washing up on the coasts of Spain, France and Portugal (to date it remains Spain’s worst ecological disaster).
Figure 15: Prestige sinking
Source: Cedre
In late 2003, the IMO adopted resolutions on Guidelines on Places of Refuge for Ships in Need of Assistance and Maritime Assistance Services (MAS).[57], [58] These guidelines were intended for use when a ship needed assistance but safety of life was not involved (the latter was covered by the Search and Rescue Convention). A coastal state’s MAS were intended to improve reporting, consultation, situation monitoring, and communications, including during a salvage operation. The Guidelines on the Control of Ships in an Emergency provided coastal state governments, masters, companies, salvors and others involved in an emergency with a framework of authority in which they were expected to operate.[59] The masters Guide (Peril at Sea and Salvage) directed readers to the guidelines on the control of ships as well as the guidelines on places of refuge.
Government intervention
The masters Guide (Peril at Sea and Salvage) advised that governments of coastal states could have legislation that allowed them to actively intervene when there was an emergency in waters under their jurisdiction. The Guide advised that masters should comply with any instructions given by the authority with jurisdiction but to question instructions which they considered inadvisable or dangerous.
Coastal states also have a right to intervene beyond their territorial waters and take measures to prevent or reduce pollution, and this was recognised by several international conventions. However, coastal states were required, if possible, to consult with other affected states, including the ship’s flag state, and with the owners of the ship and its cargo.
>Response fundamentals
The information and guidance in relevant Conventions and Guidelines indicated that the effective management of emergencies relied on timely and appropriate actions. The success of an action is often reliant on when it is taken and an emergency response invariably involves time‑critical actions, starting with initial notifications. Good seamanship is central to an optimal outcome.[60]
Notifications
The masters Guide (Peril at Sea and Salvage) emphasised the importance of timely reporting of an emergency: ‘do not delay sending appropriate alerts and notifications’. The Guide provided a list of parties that may need to be notified, with the coastal state listed first.
Prompt notifications enable authorities and relevant parties to take necessary action. Importantly, early action improves the chances of success of the emergency response by coastal state authorities, salvors and others. It is equally important that when a master’s notification(s) is received by any station, it should be relayed to relevant coastal state authorities and agencies, and others that need to respond in accordance with the state’s emergency response plans.
Shipboard response
The shipboard response depends on the type of emergency, but safety of the crew is always paramount. The master’s Guide provided general guidance for responding to emergencies that involve a breach of the hull, a fire or explosion or the risk of an explosion. The Guide detailed the action to take when a ship was disabled but still afloat as well as the action to take if it grounded.
The Guide included information about managing drift if the ship was disabled due to a loss of steering but still had propulsion. Different methods, depending on whether the ship had one or 2 propellers, to bring its head or stern into the weather to reduce drift were described.
In emergencies involving propulsion failure, the Guide noted that anchors could be used to good effect. If the water was too deep for anchoring, it suggested lowering the anchors to create a drogue effect to bring the ship’s head into the weather. However, a warning that the length of cable deployed must always be less than the maximum that the windlass can recover (no more than 3 shackles of cable or about 80 m) was included. It was stated that great care must be taken to retain the use of the anchors in case the ship reached water depths where it could be anchored. If there was a risk of grounding, it was recommended that the anchors be readied before they might be required.
While the use of anchors in emergencies is recommended, masters need to be aware of the inherent limitations of anchoring equipment. These are governed by the requirements of the International Association of Classification Societies (IACS).[61] The requirements stated that the anchoring equipment ‘is intended for the temporary mooring of a ship within a harbour or sheltered area’. It was further stated that ‘the equipment is therefore not designed to hold a ship off fully exposed coasts in rough weather or to stop a ship which is moving or drifting’.
Masters also need to consider the operational condition of the anchoring equipment and the holding ground that the seabed offers. The IACS requirements stated that the equipment was designed to hold a ship in good holding ground and the holding power of anchors is significantly reduced in poor holding ground. Sand and gravel offer good holding ground whereas a rocky bottom does not. In any case, if anchored in rough weather in an emergency, the engine(s), if operational, should be used to reduce load on the cable(s).
Masters should be familiar with their ship’s towing equipment, which depends on the type of ship, size and other factors. For example, large oil tankers are fitted with emergency towing equipment whereas dry cargo ships such as Portland Bay have standard mooring equipment as required by the relevant rules and requirements, which can be used for emergency towing. Masters can rely on the towage/salvage master’s directions, the master’s Guide and their own experience and seamanship when taking a tow.
Shore‑based response
The principles and objectives of shore‑based emergency response by coastal state authorities, salvors and others are generally consistent with those of shipboard response. Safety of life is paramount and evacuating the crew is a key consideration where there is risk to life.
As previously discussed, pollution prevention is central to emergency response. This is achieved by stabilising the ship’s situation to prevent the loss of the ship and/or its cargo. In practice, responders provide services and support, such as salvage or towage and pollution prevention or clean‑up, all aimed at preventing a disaster.
Australia’s National Plan
Overview of national arrangements
The Australian Government recognised the need for a national set of arrangements to manage oil and pollution incidents after the major oil spill from the oil tanker Oceanic Grandeur in 1970 in the Torres Strait.[62] The incident was the main catalyst for developing the National Plan to Combat Pollution of the Sea by Oil, which came into operation in 1973 under the management of the former Department of Transport.[63] In 1990, when AMSA was established, it took control of the National Plan as it is commonly known.[64]
In 2005, in response to the 2004 Ship Salvage Inquiry into Maritime Salvage in Australian Waters,[65] the Australian Government decided that an integrated national approach for the provision of emergency maritime response arrangements was required. The integrated approach would require minimum levels of emergency towage capabilities (ETC) along the Australian coastline and a regulatory framework to support a coordinated approach to emergency response issues. This led to the 2008 Inter‑Governmental Agreement (IGA) on the National Maritime Emergency Response Arrangements (NMERA).[66]
The objective of NMERA was to protect the marine environment from actual or potential ship‑sourced pollution by ensuring an appropriate level of ETC around the coastline and enhancing the response management framework.[67] Governments recognised the benefit of a single national emergency response management role to address any shipping casualties that involved potentially significant pollution and the need to strengthen the powers of intervention.[68] The following were the stated elements of NMERA:
emergency towage vessels (ETVs)
national Maritime Emergency Response Commander (MERCOM)
regulatory arrangements – powers of intervention.[69]
Key features of the IGA were:
the Commonwealth, Northern Territory and all 6 states were parties to the agreement
a greater role for governments to ensure a minimum level of ocean‑going ETC
salvage arrangements to remain within existing commercial arrangements
minimising potentials effects on competitive pressures on harbour towage
primary responsibility for use of NMERA ETC lay with the shipping industry
ETV assets to be available to industry under commercial arrangements
government intervention only to achieve policy outcome (objectives)
MERCOM’s final decision‑making power for casualty management.
It was agreed that the Australian Government would amend its legislation to provide immunity from civil or criminal liability for the MERCOM and persons complying with a MERCOM direction issued with respect to managing an emergency. This immunity would not extend to the obligations and liabilities of shipowners under relevant international conventions and domestic laws related to pollution or other damage. Several other amendments and clarifications to legislation were also agreed.
The ETVs were to be contracted by AMSA and could be called upon by the MERCOM, port authorities, state or Northern Territory governments or the shipping industry in emergencies involving risk of significant pollution. In 2006, AMSA implemented a national emergency towage program. It also appointed the MERCOM as the single national decision‑maker with appropriate statutory powers to act on behalf of the Australian Government during a shipping casualty. Five years later, in 2011, the National Plan was expanded to include maritime casualty response.[70]
In 2012, AMSA’s review of the National Plan and NMERA identified that the 2 would be better integrated into a single document supported by a single IGA.[71] Subsequently that year, the National Plan was retitled as the National Plan for Maritime Environmental Emergencies as it is currently known.[72]
The 2020 edition of the National Plan that was in effect at the time of the incident incorporated the 3 NMERA elements of ETC, MERCOM and powers of intervention as described in the following sections. According to AMSA, the NMERA IGA forms part of the arrangements for the National Plan.[73] The Plan is reviewed every 10 years and AMSA commissioned a review in 2023.[74]
The National Plan implements Australia’s obligations under many international Conventions related to the management of maritime environmental emergencies.[75] The policies, national arrangements and information detailed in the Plan can form the basis for emergency response processes and procedures. Key information derived from the Plan and AMSA’s website is summarised below.
Purpose, principles and scope
The National Plan set out national arrangements, policies and principles for the management of maritime environmental emergencies to provide a comprehensive response regardless of how costs might be attributed or recovered.[76] The Plan’s principles were to:
protect the community, environment and maritime industries
give effect to relevant international conventions
integrate with the Australian Emergency Management Arrangements
The Plan’s geographical scope was the Australian Exclusive Economic Zone.[79] It included offshore islands and territories, and the high seas where an incident had the potential to impact Australian interests. The Plan also applied to internal and coastal waters for which Australian States and the Northern Territory had responsibility.[80]
Governance and management
The National Plan provided a comprehensive approach to emergency management.[81] The document comprised several parts that covered governance and management, and national arrangements to prevent marine pollution incidents as well as to prepare for, respond to and recover from such incidents. The Plan also set out cost recovery arrangements.
Legal and administrative basis
The Plan gave effect to international Conventions that Australia was a party to and included the following:[82]
International Convention on Oil Pollution Preparedness, Response and Cooperation, 1990
International Convention on Civil Liability for Oil Pollution Damage, 1992
United Nations Convention on the Law of the Sea, 1982
International Convention Relating to Intervention on the High Seas in Cases of Oil Pollution Casualties, 1969.
Under the Plan, Australian governments (national and state) were responsible for preparation and response to maritime emergencies within their jurisdictions and certain government agencies had response powers under a range of national and domestic legislation, including the following:[83]
Australian Maritime Safety Authority Act 1990
Protection of the Sea (Prevention of Pollution from Ships) Act 1983
Protection of the Sea (Powers of Intervention) Act 1981
Protection of the Sea (Civil Liability) Act 1981
Maritime Powers Act 2013.
Plan management
The aim of National Plan governance was to ensure a coordinated, integrated and accountable system was in place to manage maritime environmental agencies.[84] The National Plan Strategic Coordination Committee (NPSCC), comprising senior national and state government officials, was responsible for setting the broad policy direction of the Plan, overseeing its implementation and ensuring the effectiveness of arrangements.[85]
The National Plan was managed by AMSA and its functions included:
managing the National Response Team, including training and development
providing secretariat services for the Plan’s committees and technical groups
providing a national response equipment capability
coordinating the national training programme
managing research and development projects
management of trajectory modelling
managing the national emergency towage vessel and fixed‑wing aerial dispersant contracts.[86]
The National Plan was underpinned by policies, guidance and scientific, technical and operational advisories and the NPSCC was responsible for the review and acceptance of these documents.[87] The NPSCC was also responsible for ensuring the Plan remained current and effective, and AMSA was required to conduct an annual review of it for the Committee’s consideration.[88]
Roles and responsibilities
Agencies with jurisdictional or legislative responsibilities for maritime environmental emergencies were required to work closely with the ‘control agency or combat agency’[89] to ensure an adequate response.[90] The control agency was assigned by legislation, administrative arrangement, or within the relevant contingency plan, to control emergency response activities, including appointing an ‘incident controller’.[91] Support agencies provided resources, including equipment, personnel and services to the incident management team.[92]
Emergency coordination
As major emergencies may require significant strategic coordination across governments and stakeholders, nationally and internationally, the Plan provided for the coordination of stakeholders through the application of strategic leadership, coordination across Australian jurisdictions and international governments and processes for the transfer of Control Agency responsibility.[93] An orderly transfer of this responsibility (for example, when the response needed to be upscaled) was considered key to properly managing the emergency.
A nationally significant incident creates additional pressures on the control agency so jurisdictions were asked to support it through the appointment of a senior official to provide strategic leadership and coordination.[94] These officials, referred to as the State Marine Pollution Controller or Coordinator, were expected to assist with communications, situational awareness, strategic coordination and facilitating the Plan and associated emergency arrangements.[95]
Pollution prevention
Arrangements to prevent or minimise pollution due to a maritime casualty and emergency included assignment of responsibilities (shipowner and governments), national emergency towage arrangements, national guidance on places of refuge and an incident management system.[96] Part 3 of the Plan (Prevention of marine pollution incidents) included the subjects outlined below.
Responsibilities
The ship’s owner and master were responsible for taking prompt and effective action to ensure the safety of the ship and cargo, including the engagement of emergency towage, engagement of salvage contractors and effective communication with Australian government authorities on actions being taken to manage the emergency.[97]
Australia was obligated to provide assistance to a ship in accordance with the IMO’s Guidelines on Places of Refuge for Ships in Need of Assistance and Maritime Assistance Services (MAS) previously detailed.[98] The contact point between the ship’s master and the Australian Government for MAS was the AMSA Response Centre (ARC).[99] If the casualty was within the jurisdiction of the Commonwealth Government, AMSA was responsible for managing the emergency.[100] State governments had responsibility when the casualty was within coastal or internal waters.[101]
Response commander
The MERCOM was responsible for the management of emergency intervention issues in response to maritime casualty incidents where there was an actual or potential risk of significant pollution.[102] The MERCOM was appointed by AMSA and was supported by statutory powers under the Protection of the Sea (Powers of Intervention) Act 1981.[103] The MERCOM was required to consider the reasonable views and positions of involved states and stakeholders and the MERCOM’s decisions were to be expeditiously communicated to all relevant stakeholders and fully documented.[104]
Casualty management
The incident management system for maritime casualties was based on the following principles:
operational management rests with towage and salvage contractors
the system was to be scalable and flexible to meet the demands of the incident
Australian governments oversee actions of shipowner, master and towage/salvage contractors
the need to facilitate communication among key stakeholders in relation to appropriate action
separation of maritime casualty and pollution response functions for significant incidents.[105]
A Maritime Casualty Control Unit (MCCU) was to be implemented for significant events where the MERCOM had assumed control.[106] This was consistent with the principles of the Australasian Inter‑service Incident Management System (AIIMS), which provided for multiple incident management teams.[107]
Emergency towage
The national arrangements for emergency towage capability – ETC were managed by AMSA and supported by jurisdictional arrangements to manage risks within a particular jurisdiction.[108] The Australian coast was strategically divided into 11 regions to deliver ETC on the following basis:
level 1 capability – a dedicated ETV in the far north Queensland ETC region
level 2 capability – contracted port towage within the 10 other ETC regions that was capable of open water towage operations
level 3 capability – vessel of opportunity that could be directed or contracted at the time of the incident to assist or supplement the level 1 or 2 capability.[109]
At the time of the incident, the dedicated ETV (level 1 capability) Coral Knight was stationed in far north Queensland and each region had one or more level 2 capability contracted ETVs based in certain ports (Figure 16).[110]Svitzer Glenrock, based in Newcastle, was the sole level 2 capability ETV serving New South Wales. Only AMSA could activate its contracted ETC and activation requests were governed by its procedures (see the section titled Maritime Assistance Services procedures under National level).[111]
Figure 16: Emergency towage capability arrangements at the time of the incident
Source: AMSA (Emergency Towage Capability arrangements as of June 2020)
Place of refuge
The Plan defined a ‘place of refuge’ as one where action can be taken to stabilise the condition of a ship and its cargo, protect life and the environment and reduce hazards to navigation.[112] Agreed national guidance, although optional, advised Australian maritime agencies to provide a place of refuge when necessary and appropriate to protect:
the safety of the ship’s crew, passengers and salvage crew
the safety of human life in the immediate vicinity of the distressed ship
ecological and cultural resources, and marine, coastal and terrestrial environments
economic and socio‑economic infrastructure, within the coastal zone and ports
This guidance included the subjects covered by the IMO guidelines on ‘places of refuge’ previously referred together with additional safety of life considerations.
Preparation, planning and response
The Plan provided for the planning and preparation to respond to marine pollution incidents, with key associated activities including:
Contingency planning at national, state and regional levels underpinned the National Plan arrangements and each jurisdiction was responsible for establishing contingency plans and ensuring they remained current and effective.[115] National pollution response capability included the National Response Team of qualified and trained personnel, state response teams, and response stockpiles of equipment held nationally, regionally and locally.[116]
Exercises
Exercises were intended to be a core component of preparedness and each jurisdiction was responsible for an effective exercise programme.[117] The national response capability was to be exercised on an annual basis and exercise planning and conduct was required to include national and state level representatives.[118]
Response
The Incident Management System under the Plan was consistent with AIIMS to provide for multiple incident management teams, and its fundamental principles were flexibility, functional management, management by objectives, unity of command and span of control.[119] The required response was generally required to be based on the following 3 incident levels:[120]
Level 1 incidents – generally resolved through the application of local or initial resources only.
Level 2 incidents – more complex in size, duration, resource management and risk and may require deployment of jurisdiction resources beyond the initial response.
Level 3 incidents – generally characterised by a degree of complexity that requires the Incident Controller to delegate all incident management functions to focus on strategic leadership. Response coordination may be supplemented by national and international resources.
Guidance for incident classification included various general characteristics for each level to support the development of criteria for evaluating the escalation of the response and these criteria were recommended to be embedded in the relevant contingency plan.[121]
The Plan recognised that timely initiation of a response was critical to achieving an effective outcome. Consequently, it stated that a response should be initiated where there was a need to monitor the incident (potential and actual) and implement measures to mitigate its impacts.[122] It also recognised that pre‑emptive or precautionary response operations might be necessary to protect environmental and community interests where local resources might be insufficient, and the principle of over‑escalation when considering the initial response (more effective to scale down than up).[123]
National Plan implementation
Portland Bay’s propulsion failure and the subsequent emergency unfolded off the coast of New South Wales, initially in waters under Commonwealth (national) jurisdiction and then state waters and involved agencies at both levels.
National level
As AMSA managed the National Plan and controlled the national maritime emergency response arrangements, it had a central role in the response to any maritime emergency. In order to meet its responsibilities in this role, AMSA had developed many procedural and guidance documents, including standard operating procedures and related processes for emergency response and management. Its Maritime Assistance Services procedures directly applied to this incident. In addition, several AMSA guidance publications on casualty management, emergency response and related subjects were relevant and the key ones are summarised in this section.
While Search and Rescue (SAR) arrangements were not part of the National Plan, AMSA used its SAR procedures in its initial response to the incident when attempting to rescue the ship’s crew. These procedures are described first for completeness and to provide the necessary context.
Search and Rescue procedures
At the time of the incident, the SAR procedures and processes were contained in the SAR Operations Procedure Manual covering a comprehensive range of relevant subjects.[124] Some of the broad subject areas addressed in the over 400‑page manual included:
coordination of SAR
tasking assets and jurisdiction
alerts and reporting requirements
distress alerts and procedures
intelligence gathering
search operations
rescue operations
concluding operations.
The SAR coordination procedures addressed determining the mission controller and their responsibilities, accepting coordination (including air coordination) from another SAR authority, and police coordination. Pre‑emptive tasking of assets, tasking of air assets, tasking assets for maritime and aviation incidents and interacting with police in various jurisdictions were detailed.
The manual detailed reporting requirements and the action required on receipt of notifications and distress alerts. Procedures to respond to and manage a distress situation were covered in detail and included flow charts.
Procedures to gather intelligence and information about the incident and situation were provided. Maritime intelligence gathering sections included potential sources such as police, VTS, other vessels and ship agents. Other sections covered interacting with State Police, Maritime Border Command, Australian Defence Force and volunteer marine rescue groups.
An entire section was devoted to operational risk management, including identification, analysis, likelihood assessment, evaluation and risk treatment. Nine broad categories of response mission risk profiles were defined. Recording, monitoring and internal reporting requirements were also provided.
Sections on SAR addressed those operations in detail based on the location and transport mode. Tasking and utilisation of aviation and maritime assets and various considerations were detailed. A section on concluding SAR operations included procedures for asset debriefing, cancellation broadcasts, notifications, final situation reports and formal debriefs.
Maritime Assistance Services procedures
At the time of the incident, the Maritime Assistance Services (MAS) procedures comprised a series of inter-related procedures on a range of relevant matters and subjects.[125] These included subjects covered by the IMO guidelines on MAS and places of refuge for ships previously referred and the National Plan, including the NMERA elements of emergency towing vessels (ETV), powers of intervention and MERCOM. Some of the 32 broad subject areas addressed by the MAS procedures included:
assessing the severity of incidents
monitoring and transitioning to a complex incident
managing incidents, including communication and jurisdiction
jurisdictional matters under the National Plan
response and transition to/from Incident Management Team
command and control
emergency towage.
When the AMSA Response Centre or ARC (JRCC operates within the ARC) was notified of an incident, the actual or potential severity level of the incident (levels 1 to 5) was to be determined in accordance with a severity matrix (Appendix B). The ARC monitored a severity level 1 (negligible) or level 2 (minor) incident to confirm that the ship’s master and owner were managing it appropriately. Where there was concern that their actions would not ensure the safety of the ship, its crew and the environment, the ARC was required to escalate the incident to level 3 (moderate) and trigger a transition to establishing an incident management team (IMT).
Severity levels 3, 4 and 5 (moderate, major and severe incidents, respectively) were defined as complex incidents and were to be managed by an IMT. The severity matrix included guidance on the proportionate and reasonable response that could be necessary based on the incident severity level. For example, a machinery failure that affected the ship’s safe navigation with a low likelihood of rectification within 6 hours and moderate risk for environmental damage would be categorised as a level 3 incident. The matrix indicated that this might require warning the master on possible use of the powers of intervention, alerting the nearest ETV, potential for a place of refuge request, potential deployment of an AMSA maritime casualty officer (MCO) and the possibility of requests from the impacted state(s).
A similar incident scenario to that above, but without prospect of recovering the machinery and a major risk to the environment, was defined as a level 4 incident. The matrix indicated the response would probably include invoking the powers of intervention, tasking the nearest ETV, a place of refuge request, deployment of an MCO and a request from the impacted state(s). If there was no prospect of recovering machinery and critical systems with severe pollution, the incident would be defined as severity level 5 and necessitate all response activities, including invoking the powers of intervention and the immediate tasking of the nearest ETV.
The procedure defined a ‘maritime casualty’ as:
a collision, grounding or stranding
fire or explosion
cargo movement or stability issues
flooding
other navigational incident
other occurrence resulting in material damage (or imminent threat of damage) to a ship or cargo
a ship‑related incident causing or likely to cause, environmental damage due to the loss or potential loss of fuel, cargo or other harmful substances.
In practice, all these types of casualties would be severity level 3, 4 or 5 incidents.
The procedure stated that a maritime casualty is likely to require coordination by the MERCOM. It also stated that under the Protection of the Sea (Powers of Intervention) Act 1981 (POI Act), the MERCOM had the power to take measures that might be necessary to prevent, mitigate or eliminate the risk of significant pollution, including the power to direct a port to release a tug or designate a place of refuge for a ship in emergency situations which presented a risk of pollution (Appendix C). The MERCOM was required to determine AMSA’s preferred response based on the available information and options, which included tasking of an ETV, invoking the POI Act, assessing requests for places of refuge, deploying an MCO, establishing an IMT and tasking of an aviation asset.
Where the MERCOM designated a casualty to be significant or potentially significant requiring broader ongoing management, an IMT was to be established and an incident controller appointed with responsibility for ensuring that the incident was managed in accordance with the National Plan. An IMT would generally have included the MERCOM, ARC duty manager, MAS subject matter expert, pollution advisors, AMSA legal counsel, external salvage expert and delegates of impacted state(s).
Under the National Plan, AMSA had jurisdiction in Commonwealth waters (seaward of 3 miles, except in the Great Barrier Reef Marine Park), which extended to the high seas and as far as the continental shelf (generally up to 200 miles). If a casualty occurred in waters under its jurisdiction, AMSA was required to assume control if the ship master and owner were not discharging their responsibility to effectively manage the casualty in a timely manner and/or to protect the environment and the community. Similarly, AMSA would assume control of a casualty in state jurisdiction if requested by state authorities or if appropriate action to manage it was not being taken.
The procedure covered the subject of a disabled ship’s drift in some detail, including creating drift models to manage the risk of it grounding or stranding. This information was complemented by guidance on AMSA’s emergency towage arrangements, including contractors and ETV locations, the tasking of ETVs and related considerations of commercial towage and salvage arrangements.
The master or owner of a ship requiring assistance were expected to make every possible attempt to enter a commercial towage or salvage agreement to ensure safety. If an agreement was not reached on who should pay, or the cost, then the MERCOM was required not to delay tasking of an ETV. In an urgent situation, the MERCOM could use the powers of intervention to direct that the casualty took a tow line from an ETV to stabilise it and, if necessary, be towed away from danger. This was stated to be the primary operational role of an ETV until being relieved by a tug(s) deployed under a commercial arrangement. Where a tug was already in attendance, or available and time permitted, the master or owner could choose it instead of an AMSA‑tasked ETV (subject to any directions issued by the MERCOM).
The procedure provided for ETV activation in 2 phases: Alert and On Task. The Alert notification provided the ETV with awareness of potential deployment and time to prepare. The On Task direction required the ETV to prepare to depart as soon as practicable within the required response time. The 2 phases were not intended to be used in sequence as an On Task direction might be the appropriate first course of action in some cases.
The procedure indicated that level 1 and level 2 ETC services were provided by Australian Maritime Systems Group (AMSG), Svitzer Australia (Svitzer), Smit Lamnalco and RiverWijs Marine under separate contracts with AMSA. The ETC level 1 service provider, AMSG, provided the dedicated level 1 ETV. Svitzer was identified as the provider of 8 of the 11 contracted level 2 ETC vessels, including one designated vessel for New South Wales based in Newcastle. The map of the ETC regions and ETVs (Figure 16) was included. The ETC level 3 assets were to be sourced from harbour towage, offshore support and anchor handling vessels as required and there was no contract for such vessels of opportunity.
The ETC level 1 and 2 assets could only be activated by AMSA as per the terms of their contracts and any requests for activation were to be made in accordance with internal AMSA procedures,[126] whereas NMERA had foreshadowed in 2008 that ETVs could be called upon by MERCOM, port authorities and others (see the section titled Overview of national arrangements). Each ETC provider’s contract included joint standard operating procedures to address the requirements for availability, command and control, operational role, activation procedures, first strike response and communications (see the section titled Emergency towage services contract under Svitzer Australia).
The MAS procedures included the following annexes and attachments containing standard forms, checklists and other useful information and guidance:
assessment tool for decision to issue a direction to the shipowner under the POI Act
standard form to issue a direction to the owner, master, salvor or any other person
checklist for collecting information for a maritime casualty
checklist for casualty information and intelligence sources
checklist for casualty monitoring
critical equipment systems checklist
considerations for hazardous situations.
The various checklists included the necessary prompts to collect and record information required for emergency response and management of any casualty, including mechanical failure and stranding. Propulsion was the first item in the safety critical equipment list and the main engine and its components were listed at the top of the critical equipment list.
The table listing considerations for hazardous situations included the potential accident type, consequences, associated system failure, mitigation system and redundancy and alternate process. For example, a potential accident due to a loss of propulsion was identified as a grounding with consequential harm to the environment and human life.
Casualty management guidance
The scope of AMSA’s National Maritime Casualty Management Guidance encompassed the response to a maritime casualty as defined in the National Plan.[127] This concise publication noted the national arrangements in place (ETC, MERCOM and powers of intervention) and its 2 main sections addressed the subjects of casualty management responsibilities and casualty response.
In terms of casualty management responsibilities, the guidance stated that the National Plan set out arrangements, policies and principles for the management of environmental emergencies, including casualties. Five key principles of casualty management were identified as:
shipowner’s (and salvage or towage contractor) responsibility for operational management
responsible agency to oversee shipowner, master, salvor and towage contractor actions
scalable and flexible casualty management system to meet demands of the incident
in significant incidents, provide separation of casualty and pollution response
facilitating communication among key stakeholders for appropriate action.
The guidance reiterated the need for the responsible agency to assume control where the ship’s owner and/or master were not discharging their responsibilities and/or to protect the environment and community. National Plan jurisdictional responsibilities and zones were described, including that the responsible agency could request AMSA to assist or to manage the casualty.
Casualty response guidance included the organisation of a response and the different involved roles. It was recommended that the responsible agency establish a maritime casualty incident management team (MCIMT) to coordinate and strategically manage a significant incident. A summary of the role and powers of the MERCOM and establishment and functions of a maritime casualty control unit (MCCU) was also provided.
The guidance included an overview of the response options available to prevent, mitigate or eliminate a casualty. Responsible state (or Northern Territory) agencies were asked to seek AMSA assistance when required, including where an ETV was required to assist the casualty or MERCOM powers considered necessary for a place of refuge request. An overview of the powers of intervention legislation and summary of national emergency towage capability was included. Notwithstanding the primary role of an ETV to stabilise a casualty, its capability to preserve life, prevent or mitigate pollution, assist with firefighting and provide towage to a place of refuge were reiterated. Guidance on places of refuge referred to the national guidelines on the subject (see the section titled Place of refuge guidelines under National level).
This guidance document captured all the relevant key components of the National Plan.
Emergency management handbook
The Complex Maritime Emergency Management handbook published by AMSA provided useful information and guidance to manage casualties and noted that these could range from collisions to offshore spills.[128] The handbook stated that it should be read in conjunction with the National Plan. A complex maritime emergency was defined as a large‑scale and multi‑faceted event that exceeded the resources of a single jurisdiction and posed distinct threats to community safety, the economy, and the environment.
The stated purpose of the handbook was to provide planning guidance and context to users across jurisdictions towards establishing an agreed, structure and coordinated response to a complex emergency. It contained sections that provided high‑level guidance on several essential subjects. These included complexities of the maritime sector, planning (principles, strategies and priorities), coordination (accountabilities, resourcing and governance) and preparedness (training, exercises and lessons management). The handbook’s intended audience included casualty and pollution response control agencies, executives and managers (governments and industry), executive crisis teams and emergency planners.
Information on the complexities of the maritime sector addressed the topics of marine insurance, ship ownership and registration, salvage, legislation and legal considerations. The key principles of planning were summarised, including collaboration and knowledge sharing, addressing any stakeholder capabilities and limitations, willingness to operate in concurrent and connected domains and distributing control in ambiguous operating environments. These principles were stated to complement those for an agile and scalable, adaptable response that was timely and outcomes based. Strategic priorities, starting with protecting human life were spelt out, and the levels of planning (local, state and national) were described, including cross‑sectoral and cross‑jurisdictional challenges.
The section on coordination addressed accountabilities, resourcing and integrated response. The key concepts of integrated governance were stated to be communication, coordination, collaboration and integration, which were to be applied with flexibility including the ability to adapt and respond to evolving events and information. Integrated governance for a complex emergency across agencies was to provide for:
transparency and information sharing
effective issue resolution and decision‑making
defined reporting lines
agreed notification and escalation pathways
avenues for stakeholder engagement
clearly defined objectives
established workstreams / lines of effort
standardised communications.
The handbook included examples of complex emergencies, presented in summary form as guidance. It emphasised the importance of preparedness through training, exercises and learnings and provided important principles for exercises and workshops, decision‑makers and responders.
The handbook complemented the Casualty Management guidance and National Plan.
Place of refuge guidelines
The National Maritime Places of Refuge Risk Assessment Guidance published by AMSA was intended to provide national and state‑level agencies guidance to inform and expedite the decision‑making process in the determination and allocation of a place of refuge.[129] This publication covered all relevant subjects, including requests for a place of refuge, decisions, management issues and powers of intervention at the national and state level.
The guidance described different maritime zones, circumstances for seeking refuge, reasons to provide a place of refuge, process for requesting refuge, granting a request and the MERCOM’s overriding authority. The implications of refusing a request and the handover process between jurisdictions were also addressed. Detailed guidance about the powers of intervention, liability and indemnity was included.
The publication included useful flowcharts, checklists, forms and templates to assist with making requests, assessing risk, making decisions and issuing a directions notice under national or state‑level legislation.
Annual exercises
As previously noted, it was a requirement to exercise the National Plan on an annual basis. Exercises conducted during the 7 years before this incident are summarised below.
In 2015, Exercise Westwind, a 2‑phase exercise to simulate a response to a level 3 (the highest level) emergency by the Australian and Western Australian governments and the offshore oil industry was conducted. Phase 1 was in Canberra on 27 and 28 May while phase 2 was in Perth and Exmouth, Western Australia, from 8 to 12 June. Objectives included exercising: National Plan arrangements in a multi‑jurisdictional, cross‑sectoral setting; strategic interaction operational management of a multi‑agency, multi‑jurisdictional and cross sectoral incident control centre, and tactical deployment of resources and response personnel.
In 2016, Exercise Nautical Twilight, was conducted in 3 phases across September in New South Wales. Phase 1 simulated the NSW IMT working with a MCCU and MERCOM to respond to a shipboard hazardous and noxious substance (HNS) incident with a request to discharge the HNS in a port in New South Wales. Establishing an MCCU, assessing its structure and fitness for purpose and applying refuge guidelines were practised. Phase 2 involved a multi‑agency response to a shipboard fire in Newcastle, including establishing an incident control centre and incident action plan. The effectiveness of multi‑agency functionality, NSW personnel capability and NSW HNS recovery arrangements were assessed. Phase 3 tested the national HNS response capability and fitness for purpose of the HNS reconnaissance team.
In 2017, Exercise Constant Bearing, was conducted in Adelaide, South Australia (SA), from 5 to 7 December to evaluate the state’s response to an oil spill in its waters. The objectives were to strengthen understanding of a level 3 spill consequences, enable response and recovery, use the National Plan for interaction between national and state participants and enable engagement between the SA IMT, industry and state emergency arrangements.
In 2018, Exercise Torres, a multi‑agency, multi‑jurisdictional response to an oil spill in the Torres Strait was conducted in 2 phases. Phase 1, conducted in Cairns, Queensland, on 1 and 2 August, aimed at developing strategic consequence management, community engagement and communication arrangements and strategies of the National Plan and Queensland arrangements for a level 3 spill. Phase 2, conducted from 17 to 21 September, aimed to test spill response arrangements in the Torres Strait.
Annual exercises, AMSA advised, were not conducted in 2019, 2020 and 2021 due to the impact of the COVID‑19 pandemic.[130] According to AMSA, an exercise conducted a few months after the incident in 2022 was planned in advance of pandemic restrictions lifting because their impact on ‘national preparedness’ had been recognised.
Staff training and experience
Four AMSA officers were directly or closely involved with the response to this incident. Two officers from its Response Division and the MERCOM, all based in Canberra, interacted with the Port Authority incident controller (IC) and other stakeholders. An officer from AMSA’s Operations Division in Sydney was its liaison officer in the New South Wales IMT and interacted directly with the IC and team members.
Both officers from the Response Division had completed training in AIIMS and emergency management. The officer that performed the role of AMSA’s incident controller had undertaken such training from time to time since 2005. The officer who performed the response advisor role had completed 2 relevant courses in 2021.
The MERCOM had completed several training courses in emergency management, including AIIMS, since 1997. This training had been undertaken while employed in various senior roles with the State Emergency Services in New South Wales. Before joining AMSA as the Executive Director of the Response Division in December 2018, the MERCOM had more than 30 years of emergency management experience.
The liaison officer was a very experienced AMSA marine surveyor and former seafarer but had not completed AIIMS training before the incident.
State level
Under the National Plan and relevant New South Wales legislation and plans, 2 separate maritime agencies were responsible for managing an emergency response in the state’s coastal and inland waters.
Maritime agencies
Transport for NSW was the state Government’s lead regulatory agency responsible for strategy, planning, policy, regulation and other non‑service functions for all modes of transport. Within Transport for NSW, the operational area responsible for maritime matters was NSW Maritime, which for all practical intents and purposes, was the maritime regulator.
The maritime regulator did not operate or manage the 6 principal ports in New South Wales, which had been progressively privatised. In 1995, the 3 port corporations of Newcastle, Port Kembla and Sydney took over the ownership and operation of the ports of Newcastle, Port Kembla, Sydney and Port Botany. The ports of Eden and Yamba were transferred to Sydney Ports Corporation in 2011. The landside port assets (such as wharves) of Port Botany and Port Kembla were privatised in 2013 and those of Newcastle in 2014.
In 2014, the 3 port corporations were amalgamated into the single state‑owned corporation, Newcastle Port Corporation (NPC) trading as Port Authority of New South Wales (Port Authority). The state Government issued NPC a Port Safety Operating Licence (PSOL) to operate the state’s 6 principal ports. Under the PSOL, the Port Authority was required to manage the navigation, security and operational safety needs of commercial shipping in these ports (see the section titled Port Safety Operating Licence under State level).
Under state legislation and various plans, Transport for NSW and the Port Authority were jointly, and separately in different roles, responsible for managing various types of emergencies, including incidents involving ships and/or pollution.
Legislation and plans
The State Emergency and Rescue Management Act 1989[131] (SERM Act) set out the general legal and governance framework for emergency management across New South Wales. The SERM Act required a State Emergency Management Plan to ensure a coordinated response to emergencies by all the involved responsible agencies.
The New South Wales State Emergency Management Plan was in effect at the time of the incident.[132] The Plan’s stated aim was to describe the state’s approach to emergency management, the governance and coordination arrangements and the roles and responsibilities of responsible agencies. This state‑level plan, also known as the state EMPLAN, had the following objectives:
provide clarity as to command and control, roles and coordination of functions in emergency management across all levels
emphasise risk management across the full spectrum of prevention, preparation, response and recovery
emphasise community engagement in the development and exercise of plans as well as in their operational employment
ensure that the capability and resourcing requirements of these responsibilities were understood.[133]
The state EMPLAN was supported by hazard‑specific sub‑plans and functional area supporting plans at state, regional or local levels (Figure 17). The supporting plans were prepared by state government agencies or functional areas. Sub‑plans were prepared when arrangements to deal with a hazard, critical task or special event differed from those set out in the main or supporting plan for the area.
Figure 17: Legislative and planning framework for emergency management
Source: NSW EMPLAN, paragraph 305
The state EMPLAN stated that functional areas represent key sectors and support a ‘combat agency’, which was defined as the ‘agency responsible for controlling the response of a particular emergency’. A ‘lead agency’ was defined as one that ‘has overall leadership in a given situation’, which could be a combat agency, a functional area or another agency.
While the SERM Act did not reference the National Plan, the state EMPLAN acknowledged that the ‘Commonwealth is responsible for a number of national plans’. The state EMPLAN identified certain emergencies, including hazardous material incidents and emergencies in inland or state waters and marine oil and chemical spills.[134] Annexure 3 of the state EMPLAN identified the agencies with specific control responsibilities for each type of emergency. The ‘relevant port authority’ was responsible for hazardous material occurrences in state waters while responsibility for ‘marine oil and chemical spills’ was assigned to the Roads and Maritime Authority (the predecessor of Transport for NSW)[135] or the Port Authority of New South Wales. The NSW Coastal Waters Marine Pollution Plan,[136] a sub‑plan of the state EMPLAN, detailed the specific responsibilities of both agencies for marine spills.
The NSW Coastal Waters Marine Pollution Plan (commonly known as the NSW Plan) was also a sub‑plan of the National Plan. Transport for NSW (NSW Maritime) was the statutory agency for New South Wales (as defined in the National Plan) with responsibility for ensuring that the state was prepared for and could respond appropriately to an incident in New South Wales coastal waters (in accordance with the NSW Plan). The stated aim of the NSW Plan was ‘to outline the arrangements to deal with marine oil or chemical spills and maritime incidents, such as groundings, collisions, disabled vessel or fire on a vessel that could result in an oil or chemical spill into the coastal waters of NSW’. Coastal waters were defined as ‘those waters seaward for 3 nautical miles’ and included several harbours, ports and rivers listed in the NSW Plan.
An important inclusion in the scope of the NSW Plan required ‘procedures to ensure that the NSW Government’s resources were integrated with the National Plan and effectively mobilised in the event of a maritime incident in or adjacent to NSW coastal waters’. The typical sequence of responding to an incident (in summary) included:
notification to agencies
initial assessment of distribution of information to relevant agencies
establishment of an incident control centre and incident management team using AIIMS
an extensive list of actions (safety of life, pollution prevention, salvage matters etc.)
termination of response.
A section of the NSW Plan identified necessary notifications based on AIIMS incident levels 1, 2 and 3. The list of the agencies that were to be notified included the Port Authority, NSW Maritime and AMSA. The guidance stated: ‘shipping incidents less than 20 nautical miles offshore should be treated as a potentially significant incident’ (that is, level 2 or 3). It was further stated that the initial response would depend on the location of the incident that might lead to a spill and, where the incident or emergency was in Commonwealth waters (more than 3 miles offshore), AMSA was the initial ‘combat agency’[137]. A notification sequence flow chart was provided, which required AMSA to be notified if the incident or emergency was more than 3 miles offshore (Figure 18).
Figure 18: Notification sequence for reporting a spill incident or emergency
The NSW Plan stated that the aim of responding to an incident was to minimise damage to the environmental and socio‑economic resources and reduce the time for recovery. It was noted that as each incident or emergency was different, the Plan must be flexible in its implementation to respond in the most effective and timely manner. A map titled ‘regions and their boundaries for the purposes of notification and response’ allocated the area between Gerroa (located south of Port Kembla) and Fingal Head (located north of Newcastle) to the Port Authority (Figure 19).
Figure 19: Regions and their boundaries for the purposes of notification and response
The NSW Plan stated that the Ports and Maritime Administration Act 1995 (NSW) described the Port Authority’s ‘port safety functions’ as including ‘providing or arranging emergency environment protection services for dealing with pollution incidents in relevant waters’. It further stated that the PSOL set out emergency response requirements for the Port Authority, including responding to incidents as required by the NSW Plan or the relevant state emergency management plans in the area of operations set out in appendix 2 of the PSOL. The detail in that appendix replicated the map in Figure 19 (see the section titled Port Safety Operating Licence under State level).
Where an incident or emergency occurred outside the 3‑mile limit, but the ship was likely to enter coastal waters, AMSA had to make a request to the state’s Marine Pollution Controller (MPC) for New South Wales to assume responsibility for the incident. The MPC (an NSW Maritime officer) would, in consultation with the Port Authority, determine which of the 2 agencies would take the combat agency role. The other agency was required to take on a support agency role. Their respective responsibilities in these roles were defined. Where NSW Maritime was the combat agency, it was required to:
provide an incident controller
provide trained response staff to fill AIIMS positions to control the response
make available emergency response equipment under its control
provide trained equipment operators
notify the appropriate agencies and higher control within the agency
establish an incident control centre from which the incident would be controlled.
The Port Authority’s responsibilities as a combat agency were the same as those listed above. Additionally, it was required to provide additional staff if needed in smaller ports. When supporting the combat agency, the Port Authority was required to:
provide trained emergency staff
make available emergency response equipment under its control
provide a liaison officer if required.
Where NSW Maritime was supporting the combat agency, its responsibilities were the same as those listed above for the Port Authority. As the state’s statutory agency under the National Plan, its responsibilities included assisting the incident controller in coordinating resources from NSW Maritime, the Port Authority and AMSA (if requested), and supporting the MPC when monitoring or supporting the response to an incident or emergency.
The NSW Plan stated that as part of National Plan arrangements, all combat agencies for maritime incidents had agreed to use AIIMS to control and manage the incident/emergency response. The incident controller was generally responsible for incident activities, including the development and implementation of strategic decisions and for ordering and releasing resources. Specific responsibilities included:
assume control
assess the incident/emergency
conduct initial briefing
advise NSW Maritime, Port Authority and AMSA
activate AIIMS elements and appoint staff
conduct planning meetings
implement incident action plan (IAP)
control incident operations and review IAP, and
authorise additional resources and release requests.
The NSW Plan contained guidance on important subjects, including the role of the MERCOM, powers of intervention, places of refuge, salvage and ETVs under NMERA. The Plan was maintained by NSW Maritime and it was required to exercise it annually, ensure sufficient staff were trained for spill response and clean up and to provide necessary training. In addition, NSW Maritime contributed to the National Plan, including pollution response equipment located in the state. The Port Authority and NSW Maritime maintained response equipment stockpiles.
As a shipboard fire at sea or in port may involve hazardous material (pollution), the NSW Plan referred to the guidelines to respond to such incidents using a multi‑agency incident control team (MAICT) approach. The Plan indicated that these guidelines complemented a memorandum of understanding (MoU) between the Port Authority, NSW Maritime and Fire and Rescue New South Wales (FRNSW) to respond to hazardous materials incidents in inland and state waters.
Inter‑agency memorandum of understanding
In 2010, a 5‑year inter‑agency MoU in relation to hazardous materials incidents in inland and state waters was agreed between the New South Wales Fire Brigades (NSWFB), the regulator (NSW Maritime) and the 3 separate port corporations of Newcastle, Sydney and Port Kembla.[138] The Fire Brigades Act 1989 (New South Wales) defined a ‘hazardous materials incident’ as ‘an actual or impending land‑based spillage or other escape of hazardous materials that causes or threatens to cause injury or death or damage to property’. This definition was extended in the context of the MoU to include ‘water‑based spillages’.
The MoU referred to the SERM Act and various state emergency plans, including the NSW State Waters Marine Oil and Chemical Spill Contingency Plan, as the NSW Plan discussed above was titled at that time. The MoU set out the roles of NSWFB, NSW Maritime and the port corporations for responding to a hazardous materials incident either as the combat agency or the supporting agency based on incident location (MAICT approach). It also defined their responsibilities in these roles.
In inland waters, NSWFB would be the combat agency and NSW Maritime and one of the port corporations (depending on location) would be supporting agencies. Conversely, the combat agency in state waters would be either NSW Maritime or a port corporation (again location dependent) and NSWFB would be the supporting agency. The areas of responsibility in state waters to determine the combat agency were the same as those that existed at the time of this incident (Figure 19).
The MoU was intended to define roles when responding to pollution incidents where NSWFB was, or likely to be, involved as the combat agency. The MoU did not describe a situation where either NSW Maritime or a port corporation was the combat agency and the other a supporting agency.
The ‘expiry date’ of the 2010 MoU was 5 years from its commencement, unless terminated earlier. No provision to extend it had been documented. When the MoU expired in 2015, it was not formally renewed or renegotiated. In the years since it expired, the legal teams of the 3 parties to the MoU had attempted to redraft the document and formalise the MoU.
At the time of the incident, the original 2010 version of the MoU continued to be used informally by the relevant agencies, albeit under different names, on the understanding that its terms applied in practice where appropriate.
Port Safety Operating Licence
At the time of the incident, the Port Safety Operating Licence 2019–2024 (PSOL)[139] governed the Port Authority’s operations. The stated purpose of the PSOL was to detail the required port safety functions, performance standards, quality assurance and applicable terms and conditions. Key requirements of the licence included risk assessments for port safety functions specified in the legislation for all 6 ports and safety management systems. The functions that were particularly relevant to this incident included VTS, emergency response and towage services licensing.
The Port Authority was required to provide a 24/7 VTS in Port Kembla, Botany Bay, Sydney and Newcastle. A port communications service was required for the smaller ports of Eden and Yamba. Appropriate procedures for these services had to be implemented and maintained.
The PSOL assigned responsibility for emergency response to port‑related emergencies within port boundaries to the Port Authority. Appendix 1 of the licence included maps of the boundaries of all the ports. Botany Bay boundaries extended along a 4‑mile radius centred on Henry Head at the bay’s northern entrance and Sydney Harbour boundaries extended along a 4‑mile radius centred on Hornby Lighthouse at the harbour’s southern entrance (Appendix D).
These boundaries meant that waters within Botany Bay and Sydney Harbour and a few miles from the ports’ entrances were the Port Authority’s licensed areas of operation. The Port Authority’s VTS, harbour master’s directions and towage licence system described in the following section would have been operable or enforceable within these boundaries.
Section 11 of the licence was titled Emergency Response and listed the following requirements:
The licensee must respond to port‑related emergencies, in accordance with the licensee’s role in the relevant NSW emergency management plans, within the areas of operations set out in appendix 1.
The licensee must respond to incidents as required by the NSW Plan and the response guidelines, or the relevant NSW emergency management plans, in the area of operations set out in appendix 2.
The licensee shall comply with the emergency response requirements set out in appendix 5.
Appendix 2 of the licence replicated the regions and boundaries map from the NSW Plan for notifications and response purposes (Figure 19) and was titled ‘area of operations for out of port oil and chemical spill responses’ to show the separate areas within coastal waters that were allocated to the Port Authority and NSW Maritime. Most of these waters lay outside port boundaries, where the Port Authority’s towage licence system and VTS operated.
In addition, the licence referred to the National Plan, NSW Plan, Port Authority emergency response plan and other relevant plans. Appendix 5 (Emergency Response) of the licence outlined response capability, response plans and response time, assistance to other agencies and exercises.
The Port Authority was also responsible for promoting the provision of safe and efficient towage services in Port Kembla, Botany Bay, Sydney and Newcastle. This requirement was to be met by implementing a ‘towage licence system’ to license third party towage providers in these 4 ports.
Towage licence system
The Port Authority had implemented a ‘towage licence system’ to license towage providers that met licensing requirements. During the emergency response to this incident, harbour tugs from Port Botany were deployed and relevant requirements from the ‘Port of Botany Bay unrestricted towage licence’[140] are described below.
Clause 5 of the Botany Bay unrestricted towage licence required the towage provider to provide emergency services 24 hours a day every day of the year in accordance with ‘schedule two’ of the licence. The provider was required to have at least 4 omnidirectional tugs with a bollard pull (BP) of not less than 55 tonnes. Schedule two required all tugs in a provider’s minimum tug fleet to be available to respond to an emergency within the applicable response time. The applicable time for a manned emergency tug was 15 minutes, 2 hours for any other tug and 24 hours for an ‘ocean towing’ tug.
An ‘ocean towing’ tug was defined in schedule two as one that was capable of safe ocean towing, equipped with an aft tow winch and towline suitable for emergency towage, and meeting survey standards for a Class 2B vessel.[141] The emergency tug specifications in the schedule defined an emergency tug as an ocean towing tug with a minimum fire‑fighting capacity of not less than 600 m3 per hour with a range of 80 m and a water deluge system. One tug in a provider’s minimum fleet had to meet the emergency tug specifications.
A harbour tug from Sydney Harbour (Port Jackson) was also deployed in the emergency response and, as such, requirements from the ‘Port of Sydney Harbour unrestricted towage licence’[142] were also relevant. In many respects, the requirements in the unrestricted towage licences for Sydney Harbour and Port Botany were the same or similar, but with some important differences.
Clause 5 of the Sydney Harbour licence and Port Botany licence was the same but schedule two of the licences were significantly different. Two omnidirectional tugs with a minimum BP of 45 t were required for Sydney Harbour and one tug had to meet the emergency tug specifications. The specifications required the emergency tug to have firefighting capability but an ‘ocean towing tug’ was not required. The response time for a manned emergency tug was 60 minutes and 2 hours for any other tug.
Annexure one of the towage licences for Port Botany and Sydney Harbour defined the boundaries of the ports by replicating the maps included in the PSOL. As such, the Port Authority could direct a towage provider’s tugs, including emergency tugs, within the port boundaries that extended about 4 miles for the port entrances.
The towage licences did not refer to the National Plan or the emergency towage vessels (ETVs) defined in the Plan. The emergency tug specifications under the licences were not the same as those for AMSA‑contracted ETVs (see the section titled Emergency towage services contract under Svitzer Australia). As such, the harbour tugs in Port Botany and Sydney Harbour were ‘vessels of opportunity’ under the National Plan.
Port Authority procedures
The safety management systems (SMSs) of Port Authority‑managed ports included incident and emergency response plans and procedures to meet its obligation to comply with the NSW Plan and its PSOL. The following documents from the Port Kembla, Port Botany and Sydney SMSs were relevant and were used to respond to the incident:
Port Kembla Marine Oil & Chemical Spill Contingency Plan, 2021[143]
Emergency Response Checklist – First Strike Oil Spill (Sydney & Port Botany), 2020[152]
The Port Kembla Marine Oil & Chemical Spill Contingency Plan derived much of its content from the 2012 version of the NSW Plan. This comprehensive document stated that the Plan had been established under the authority of the IGA between the National Plan and NSW Plan (2012). The Plan referred to the National Plan, AMSA, intervention and salvage but did not describe the role of MERCOM. Its stated aim was to outline the response arrangements for spills and potential spills in Port Kembla’s boundaries and it specified that the Port Authority was the combat agency in state waters defined in the NSW Plan.
The stated purpose of the Incident Management Procedure was to establish a common basis for incident management. The scope referred to incidents as defined in AIIMS and the procedure was intended to cover different incident types, including those that the Authority was obliged to respond to or where its staff were called to intervene, indicating a broad scope.
The procedure referred to the 5 fundamental AIIMS principles of flexibility, management by objectives, functional management, unity of command and span of control. An outline of applying these principles was provided followed by guidance on the following subjects:
incident notification (requirements)
incident controller (tasks and responsibilities)
incident management team (team functions and tasks)
incident classification (characteristics, processes and notifications for the 3 incident levels)
reporting to external agencies
location for incident management (the control centre)
incident action plan (functions of a plan and items to consider for inclusion)
incident conclusion (the process)
debriefing (for learnings and improvements)
incident investigation (if considered necessary).
The Sydney Harbour and Port Botany Marine Emergency Response Plan stated that it had been developed in accordance with the EMPLAN, NSW Plan, Sydney Harbour Marine Emergency Plan and the MoU between the Port Authority, NSW Maritime and FRNSW. The Plan was developed to comply with relevant New South Wales legislation and the PSOL and its scope covered both marine incidents and port sites where the Port Authority had safety oversight. Guidance to respond to incidents and emergencies such as groundings, collisions and fires was outlined. The Plan was intended to complement various other plans and procedures, including the Incident Management Procedure above.
The Port Kembla Emergency Response Plan was similar to the plan for Sydney described above with the same key details, including references to the same legislation and higher‑level state plans.
The Port Botany and Sydney pollution response plans were the same in several key respects with their respective geographical scope focused on specific sites in each port and certain pollutants handled there. Both plans referred to the higher‑level state plans, legislation, PSOL and MoU referred to above.
The VTS Operations Procedures, Marine Pollution, and Marine Pollution Prompt, respectively, were complimentary documents. The procedure was intended to ensure compliance with the PSOL, NSW Plan and the related Port Kembla plan. Its stated scope was Port Kembla VTS and the related prompt was intended as an aide‑mémoire for the VTS operator. The prompt covered subjects such as notifications required (including informing AMSA if the incident was outside state waters and FRNSW if in inland waters). A map with the Port Authority’s area of responsibility in coastal waters was provided and guidance on information to be obtained and logging events was included.
The Marine Pollution Emergency Checklist provided an extensive checklist and guidance on immediate response actions for Sydney VTS, including required notifications. Harbour master and VTS manager actions included setting up an IMT if the incident was in the Port Authority’s area of responsibility and, if outside state waters, informing AMSA. A template for an event log was included. The Emergency Response Checklist (First Strike Oil Spill) for Sydney and Port Botany referred to the NSW Plan (2016 version) and provided a list of information to be collected, checks to be completed and an event log template.
These Port Authority plans and procedures collectively contained enough information to enable compliance with the NSW Plan and National Plan.
Staff training and experience
Several Port Authority officers, most based in Sydney, were part of its IMT for this incident. Key team members had completed AIIMS and emergency management training, were experienced former seafarers with shipboard senior management experience followed by significant port management experience, including as harbour masters. They had participated in routine emergency exercises, appropriate for their day‑to‑day port management duties.
The Port Authority’s chief operating officer (COO) was the incident controller (IC) and assisted by the harbour masters that reported to him. In addition to experience as a shipmaster, the IC had extensive experience in senior port management roles in Queensland, Western Australia and New South Wales.
Towage and salvage providers
Tugs operated by the towage providers Svitzer Australia (Svitzer) and Engage Towage were deployed to assist Portland Bay over the course of the incident. In addition, Svitzer provided AMSA‑contracted emergency towage capability (ETC) services under the National Plan. The salvage operation was carried out by United Salvage, using Engage Towage’s Sydney‑based harbour tugs.
Svitzer Australia
Svitzer Australia (Svitzer) was the Australian subsidiary of a global company with the same name that has provided marine services, including towage, in many countries for several decades. Svitzer provided harbour towage services across Australia in several states, including New South Wales.
At the time of the incident, 7 of Svitzer’s Sydney‑based tugs, including Bullara, serviced Port Botany and Port Jackson.[153] Nine other tugs, including Svitzer Glenrock, serviced the Port of Newcastle while 3 tugs provided harbour towage in Port Kembla. The Port Authority’s towage licence system requirements applied to harbour tugs in these ports, including the provision of ‘emergency tugs’ under that system as previously described.
In addition, Svitzer was contracted by AMSA to provide emergency towage vessels (ETVs) under the National Plan arrangements in most of the strategic regions identified in the Plan.
Emergency towage services contract
Under the level 2 ETC services contract with AMSA, Svitzer provided services in 9 of the 11 strategic regions.[154] The contract identified 9 specific level 2 capability ETVs and their home ports (usual location). Svitzer Glenrock was identified as the nominated level 2 capability ETV for the New South Wales region with Newcastle being its home port.
The various ETVs met the level 2 capability requirements for their respective regions, which were different in terms of minimum bollard pull (BP) and fuel capacities. The minimum required BP for the ETVs ranged from 35 t to 60 t (the minimum required for the New South Wales region, serviced by Svitzer Glenrock, was 60 t).
Under the contract, Svitzer was required to nominate a vessel to provide ‘on task services’ in accordance with a contract‑defined ‘specification’ for the provision of ETC services. Reference to ‘on task’ meant that AMSA had activated Svitzer in accordance with the contract at the relevant rate (hire). The activation required AMSA to issue an ‘on task direction’ as per the contract. The ‘specification’ comprised 11 subjects, including ETC operations and services, operational performance, quality management and work, health and safety management.
The nominated ETV for a region was required to remain in the region unless directed or approved by AMSA. Svitzer could alter the nominated vessel by notifying AMSA in writing. This formal process would be used, for example, if the nominated vessel was to be taken out of service and replaced by another that could fulfil the contractual terms and conditions, which are summarised in this section.
Under the contract, Svitzer could ask AMSA to allow a vessel providing on task services to cease providing those services and be used by Svitzer for its own commercial purposes, such as to provide commercial salvage or towage services to third parties (identified as ‘related services’). If AMSA consented, the vessel was considered a ‘released vessel’. Importantly, on task services and related services could not be provided at the same time.
Schedules annexed to the contract provided various ETC specifications. At least one ETV in a region had to meet or exceed the survey standard for a Class 2B vessel. The nominated ETV(s) in a region had to be capable of performing (at all times) all operational roles in the region from the home port. The operational roles included providing ‘first strike capabilities’ in the event of a shipping incident or casualty. First strike capabilities in this context were defined as including:
fighting fire
preserving life
towing a ship out of immediate danger
stabilising a casualty to prevent further damage to the ship or the environment
towing or escorting a casualty to a place of refuge (as opposed to a place of repair)
protecting the marine environment from pollution
providing related services as directed by AMSA.
The main requirements and specifications for performing the operational roles outlined above included the following:
meet the IMO Guidelines for Safe Ocean Towing, specifically requirements in paragraph 11 of the guidelines (see the section titled Ocean towing guidelines under Towage)
availability to respond to any incident on a 24/7 basis
ability to respond to an on‑task direction within the required timeframe (2 hours)
equipped to facilitate emergency towage for vessels likely to be in the region
an aft tow winch with a suitable towing line capable of safe ocean towage
at least 2 functional towage kits, including a stretcher tow line, messenger line and shackles
a functional aft tow winch with at least 300 m of tow wire or equivalent
towage equipment capable of connecting from fore or aft
classed as a ‘sea going’ or escort tug
a fully laden speed exceeding 8 knots
the minimum BP specified for each of the regions
appropriately trained, competent and certified crew
capability to conduct operations in excess of 7 days
capability to operate 200 miles from shore (Class 2B Survey or equivalent), and
a global maritime distress and safety system communication suite or Fleet One Inmarsat system for voice and data services.
The contract also included key performance indicators (KPIs) for items under the broad categories of availability, equipment and ETC training and drills.
Standard operating procedures
A separate document containing AMSA‑approved standard operating procedures (SOPs) for ETV operations was deemed to be part of the contract.[155] Svitzer was required to comply with these SOPs and compliance was to be audited using relevant KPIs. The procedures applied to all level 2 ETVs in the 9 strategic regions.
The SOPs covered 14 subjects, including:
ETV availability
positioning
command and control
operational role
alerting and tasking procedure
communications
reporting
training and exercises
emergency towing procedures.
The procedures reiterated that the primary operational role of an ETV was stabilising a casualty to avoid danger until relieved by a vessel operating under a commercial arrangement, as well as the obligation of the master or owner to make such a salvage or towage arrangement. There were multiple references to MERCOM directions for ETV tasking and utilisation, which were consistent with AMSA’s Maritime Assistance Services procedures. All ETV requests were to be made to the MERCOM via AMSA, which would issue an ‘on task’ direction if the request was approved.
Training and drills
Training records indicated that Svitzer tug crews in the different regions had attended 2‑day training courses in emergency towage. Course documentation indicated that they comprised a 1‑day session in classroom learning followed by one day of practical training on board Svitzer tugs. The documentation indicated that each course was identical in relevant respects. All training courses were delivered by salvage experts from the salvage service provider, United Salvage.
The records indicated that a standard 2‑day training course, attended by 11 Svitzer tug crewmembers and involving Svitzer Glenrock was conducted in Newcastle on 30 and 31 March 2022 (3 months before the incident). On 30 June and 1 July 2022 (3 days before the incident), the standard course was delivered to 15 attendees in Sydney and involved Bullara in Port Jackson.
These 2‑day courses had largely been the format of training since 2019. A large number of ‘audit and drill reports’ provided by AMSA showed that, until 2016, regular audits of the KPIs under the contract were being conducted. Other records provided by AMSA largely comprised the routine fire and other drills conducted on ETVs, which were not directly relevant to emergency towage training. A substantial proportion of the records provided indicated detailed recent emergency towage training associated with AMSA’s level 1 capability ETV, Coral Knight, which serviced the Great Barrier Reef region in Queensland.
Records obtained from Svitzer confirmed that annual exercises under National Plan requirements were conducted after this incident in 2022 and 2023. The last annual exercise before the incident was conducted in 2018, about 4 years prior as previously described (see the section titled Annual exercises under National level).
Svitzer Glenrock
Svitzer Glenrock had a length of 32 m, beam of 12 m and enough propulsive power to provide a BP of 85 t (Figure 20). The tug was built in 2018 and began operating in Newcastle that year. In 2019, it was contracted to AMSA under the ETC level 2 services contract as the nominated ETV for the New South Wales region based in Newcastle, where it was at the time of the incident.
Figure 20: Svitzer Glenrock
Source: Svitzer Australia
The modern tug met all level 2 ETC contract requirements and specifications described above. In addition to a BP about 40% more than the minimum required, it was equipped with a 54 mm diameter, 800 m long towing wire with ‘Veethane’[156] sleeves and other equipment required under the contract. Table 3 lists some key items of its emergency towing equipment.
Bullara was a 32 m tug built in 2000. In 2020, the tug’s BP was tested in both propulsion directions. A steady BP of about 51 t (ahead) and 55 t (astern) and a maximum BP of about 55 t (ahead) and 56 t (astern) was recorded and certified.
At the time of the incident on 4 July, the tug was in Port Jackson (Sydney Harbour). It was one of the harbour tugs that met the ‘emergency tug’ requirements under the Port Authority’s towage licence system as previously described.
On 4 July, Bullara was not equipped as an ETC level 2 tug. Table 4 below lists key items of its emergency towing equipment at the time, which included a 275 m long towing wire with no Veethane sleeves. Under the National Plan arrangements, it was a level 3 capability tug or a ‘vessel of opportunity’ that could be tasked under a suitable arrangement. On 4 July, AMSA used its existing contract with Svitzer to task the tug to assist Portland Bay.
Engage Towage was a joint venture with Engage Marine, a large company that delivered various marine services, including towage, across Australia. Engage Marine owned and operated a large fleet of vessels, including tugs, in several Australian ports. Engage Towage was a smaller operation with 5 tugs, which provided harbour towage in the ports of Sydney and Geelong, Victoria.
Tugs used
The Port Botany‑based SL Diamantina (Figure 21) initially deployed on 4 July to assist Portland Bay at the request of the Port Authority. It was the first tug to arrive near the anchored ship by which time United Salvage had partnered with Engage Towage for the salvage operation and directed the tug.
Figure 21: SL Diamantina off the ship on 4 July
Source: Portland Bay’s master
The 2 other Engage Towage Sydney‑based tugs, SL Martinique and SL Fitzroy, were also used in the salvage operation as previously described. All 3 Engage Towage tugs were of similar size with a length between 28 and 32 m. All were built in 2008, had similar capabilities in terms of BP (build design was about 65 t) and had towing lines suited for their harbour towage operations in Sydney.
The Port Authority’s towage licence system requirements previously described, including the emergency deployment of tugs, were applicable to Engage Towage. When it deployed on 4 July, SL Diamantina’s aft towing winch was not operational, which made it unsuitable for emergency towage. Before it was deployed on 4 July, SL Martinique was provided with additional towing equipment, including a towing stretcher and towing shackles, in consultation with United Salvage.
SL Martinique connected an emergency soft towline to the ship’s port shoulder (Bullara’s line was connected to the starboard shoulder) for the attempted tow to sea on 4 July as previously described. On 6 July, in addition to SL Martinique, SL Fitzroy connected to the ship’s port quarter with a soft towline from its forward towing winch for the tow into Port Botany as per the towage plan. When the tow was in port limits, SL Diamantina connected through ship’s aft centre lead.
The Engage Towage tugs were used under United Salvage’s LOF agreement for the salvage operation. They were not tasked as ‘vessels of opportunity’ (level 3 ETC) under National Plan arrangements.
United Salvage
According to United Salvage,[157] its history as a salvage services provider dated back to 1938 and following ownership by the Australian companies Howard Smith and Adsteam,[158] it became part of Svitzer. United Salvage reported that it ceased operations in 2007 before reactivating in 2020 to continue providing salvage and emergency services.
While any towage provider could have provided salvage services or made tugs available for salvage, United Salvage was the only dedicated salvage and emergency response service provider based in Australia at the time of the incident. United Salvage was a member of the International Salvage Union (ISU) and the only such salvage company in Australia at the time. The company stated that its managing director was an executive member of the ISU and had been a professional salvor since about 2000. The company reported that it provided specialised emergency response, salvage, wreck removal, decommissioning and environment support services in Australia, New Zealand and the South Pacific.
United Salvage’s head office was in Port Kembla, New South Wales, where it maintained a warehouse for salvage equipment. The company had strategically located bases in Queensland (Cairns and Mackay) and Western Australia (Dampier) that held oil spill capture and containment equipment. It provided related services to industry and towage providers, such as the 2‑day training courses in emergency towage as previously described.
United Salvage did not own or operate any tugs or other vessels that could be used for emergency towage and relied on procuring these services from towage providers when required. As previously noted, United Salvage had an existing agreement with Engage Towage with which it partnered for the use of its tugs throughout the salvage operation. While United Salvage was the salvage contractor identified in the LOF agreement, Engage Towage and its tugs were the other parties included in the salvage award to be arbitrated (see the section titled Law of salvage under Salvage).
Both Svitzer tugs, Bullara and Svitzer Glenrock, which assisted with the ship’s emergency towage, operated under the terms of Svitzer’s ETC (level 2) contract with AMSA throughout and were not part of any salvage award. On 4 July, AMSA tasked Bullara but later advised Svitzer that its use should be included under the existing LOF salvage agreement (Svitzer however did not accept this). Svitzer Glenrock was tasked by AMSAand not released or offered under LOF terms.
Emergency towage availability
As noted above, United Salvage relied on procuring emergency towage from a towage provider to perform salvage operations. Throughout its early history, the company had always had ready access to the significant towage assets of its owners and, as such, was not limited in this critical aspect for the provision of salvage services.
In 2002, when United Salvage was a wholly owned subsidiary of Adsteam Marine, the latter made a submission to the Productivity Commission following the preliminary findings of its inquiry into harbour towage.[159] Adsteam Marine submitted, in part, that a comprehensive privately funded ocean salvage and coastal protection capability existed across Australia at that time, but it was concerned that if port authorities were allowed to issue exclusive towage licences, the existing national and salvage and coastal protection capability could be undermined.
Adsteam Marine’s submission included a paper, titled ‘Adsteam Marine Limited Salvage Capability and Capacity, June 2002’. This salvage capability and capacity paper addressed various salvage matters and included important details about United Salvage’s operations. At that time, United Salvage had ’13 frontline salvage/harbour tugs with offshore capabilities’ stationed in strategic locations across Australia. In addition, it operated a large fleet of harbour tugs, the majority of which had some ability to provide emergency support. Adsteam Marine reported that between 1 January 1999 and 27 March 2002, United Salvage had attended 27 casualties (most had required towage).
As previously described in the section titled Overview of national arrangements, NMERA was based on having a minimum level of emergency towage capability (ETC) along the Australian coast and a regulatory framework to support a coordinated approach to emergency response. At the time of the incident, the AMSA‑managed ETC arrangements under the National Plan were provided by 12 contracted ETVs (one ETC level 1 and 11 level 2 ETVs). ‘Vessels of opportunity’ (level 3 ETVs) were exactly that and would have to be sourced from available vessels with no assurance of their capability for offshore salvage operations. While anchor handling and offshore support vessels operating in some regions, such as north‑west Western Australia, are inherently more capable and better equipped for towing operations as vessels of opportunity, this was not the case in other regions, including the east coast of Australia.
In practice, the emergency towage assets available at the time of the incident comprised the ETC arrangements under the National Plan. A party intending emergency use of a contracted ETV had to make such a request to AMSA, which had direct control and could either release the ETV or task it. As such, the actual emergency towage available in general was essentially the same as the minimum ETC required under the National Plan. This situation would have been fully understood by AMSA, its contracted towage providers and United Salvage.
Emergency response
This section provides additional background and context to the actions and decisions taken in relation to significant events and matters previously detailed (see the section titled The incident). This additional information is based on various sources of evidence, including recorded data, documented records and recollections (interviews and statements) of key personnel that managed or were directly involved in the response.
Emergency develops
When interviewed by the ATSB, Portland Bay’s master stated that the decision to put to sea on the afternoon of 3 July was appropriate as the berth was close to the port’s entrance and the increasing swell made it ‘dangerous’ to remain there. Neither the master nor the chief engineer had any concerns about putting to sea, including the maintenance on auxiliary blower number 2 that was postponed on the previous day due to the worsening weather.
The master reported that, at sea, the ship rolled and pitched heavily and slamming reduced speed to less than 3 knots with the main engine at full ahead. The ship steamed and drifted intermittently and remained 8–15 miles from the coast. According to the master, it had been ‘impossible’ to steam 50 miles away from the coast (as required by the ship’s SMS procedures).
The master noted that some other ships were drifting in the general area and some were 4 miles from the shore. Port Kembla VTS had advised that ships drifting off the port could do so at a safe distance of ‘around 12 miles’. Neither Port Kembla VTS nor Sydney VTS were monitoring Portland Bay or other ships outside their respective port limits or boundaries (about 3 to 4 miles from port entrances). According to the Port Authority, its VTS’ were ‘certified by AMSA within geographical areas (either approximately or slightly larger than the port boundaries)’ and stated that it did ‘not manage a coastal VTS’.
The master recalled that after the engine was restarted following the heavy rolling at 0330, the ship was put on a ‘110° heading’ and experienced ‘less rolling’. By 0450, the distance from the coast had increased to 12 miles and the ship was steaming directly away from it until auxiliary blower number 2 failed and engine speed had to be reduced. Table 5 lists significant events while the emergency was developing.
Table 5: Events from 0400 to 0719 on 4 July
4 July
Event
Notes and remarks
0400
Portland Bay steaming ~12 miles off the coast
Advice from VTS was to remain ~12 miles off coast
0450
Auxiliary blower number 2 fails, speed reduced
Blower repairs in Port Kembla were postponed
0513
Speed limited to dead slow ahead (42 rpm)
Ship effectively disabled in rough weather
0523
Unsuccessful attempts to notify Pacific Basin
Ship’s dedicated manager was traveling
0533
Pacific Basin notified of ship’s situation
Marine manager advises steaming away from coast
0543
Fleet manager provides engineering advice
Chief engineer actioning advice; Coast <10 miles off
0606
Master voiced concern about stranding
Efforts to increase speed have not succeeded
0624
Portland Bay displaying NUC signals
Ship drifting rapidly towards coast ~8 miles off
0634
Efforts start to use engine local controls
Master considering requesting tug assistance
0650
Master and fleet manager discuss calling tugs
Fleet manager asks full speed to be tried locally
0655
Master orders Marine Rescue to be called
Efforts to increase speed were unsuccessful
0657
Port Kembla VTS notified and tug(s) requested
Coast <7 miles off; Marine Rescue did not respond
0659
Port Kembla VTS informs Monson about tug(s)
VTS makes notifications within the Port Authority
0703
Marine Rescue notified and tug(s) requested
Marine Rescue advises authorities will be informed
0708
Master considering PAN or MAYDAY broadcast
Coast 6 miles (NSW waters limit extend 3 miles)
0709
Marine Rescue suggests PAN broadcast
Drifting at ~4 knots towards coast and NSW waters
0716
Portland Bay’s PAN broadcast on VHF radio
Ship 5.8 miles from coast, 11 miles south of Sydney
0719
Pacific Basin asks master to prepare to anchor
Sydney VTS starts monitoring ship’s movement
By 0513, it became apparent that, with one operational blower, speed could not be increased past dead slow ahead (42 rpm). The master decided to inform Pacific Basin (overseas) of the engine issue that had disabled Portland Bay in bad weather off the lee shore (then 11 miles off). While there were some initial difficulties contacting Pacific Basin (see table 5) by 0533, it was notified.
The following 85 minutes were largely devoted to unsuccessful attempts to increase engine speed with Pacific Basin providing engineering advice. The master voiced increasing concerns from time to time as the ship drifted towards the shore at about 3 knots and tug assistance became more urgent.
At 0655, after further discussion with Pacific Basin, the master decided to notify Australian authorities. The disabled ship was less than 7 miles from the shore and potentially 2 hours from stranding. Port Kembla VTS was notified at 0657 and tug assistance requested. Two minutes later, VTS passed the request for a tug to the local agent, Monson, in Port Kembla.
At 0703, intending to notify the rescue coordination centre, the master notified Marine Rescue Port Kembla. Marine Rescue advised that relevant authorities would be notified and, a few minutes later, suggested transmitting a PAN message. At 0716, when the PAN message was broadcast, the ship was drifting relatively quickly towards the shore 5.8 miles off. Three minutes later, Pacific Basin asked the master to prepare for emergency anchoring.
Initial response
After contacting the ship’s local agent, Monson, Port Kembla VTS made internal notifications within the Port Authority. Sydney VTS, alerted by the PAN message, identified Portland Bay about 11 miles from Sydney and began actively monitoring the ship’s movement. At 0725, Sydney VTS sought tugs in the port that could assist the ship (Table 6).
Table 6: Events from 0725 to 1020 on 4 July
4 July
Event
Notes and remarks
0725
Sydney VTS calls Svitzer for tug assistance
Svitzer is the port’s main towage provider
0740
Sydney VTS calls Engage Towage for a tug
Svitzer tug not confirmed; Engage Towage agrees
0744
Port Kembla VTS notifies AMSA
Kembla VTS advises ship could ground in 1.5 hours
0745
Sydney VTS calls AMSA to discuss tugs
Sydney VTS advises Engage Towage readying tug
0749
PAN broadcast from ship again
Broadcast states ship would ground in one hour
0751
Sydney VTS asks if emergency tug needed
Master confirms emergency tug assistance needed
0752
AMSA takes over SAR coordination for rescue
Sydney water police deploying 2 rescue vessels
0757
Sydney VTS follows up AMSA about tugs
AMSA advises the State’s ETV is in Newcastle
0758
Pacific Basin advises master agent seeking tug
Monson has asked Svitzer for a tug
0804
Monson advises master tug is being arranged
Svitzer has asked Bullara’s master to deploy
0810
AMSA has sought helicopters etc. for rescue
Tugs cannot reach ship before likely stranding
0811
Master advises Pacific Basin no tug en route
Master notes PAN did not lead to tug deploying
0814
Portland Bay’s MAYDAY broadcast
NSW Maritime has contacted Port Authority
0828
Three rescue helicopters en route to ship
Tasked by AMSA; Ship is <3 miles off coast
0836
Ship in readiness for emergency anchoring
With both anchors when water depths permit
0840
AMSA incident management team established
For a moderate incident (AMSA level 3)
0848
SL Diamantina (Engage Towage) deploys
Aft towing winch is inoperable; ETA to ship 1025
0905
Portland Bay starts anchoring 1 mile from shore
Svitzer offered Bullara under a commercial contract
0915
Brought up to both anchors off Eagle Rock
United Salvage has partnered with Engage Towage
0930
United Salvage briefs SL Diamantina’smaster
About LOF salvage agreement and pushing ship
0945~
Port Authority/ NSW Maritime/AMSA meeting
Establish lead agency and agree roles
0946
Rescue helicopters abandon rescue attempt
After 3 high-risk, unsuccessful winching attempts
0950
Master agrees to LOF salvage agreement
With United Salvage via SL Diamantina’s master
1010
SL Diamantina arrives off ship
Anchors holding ship 0.9 mile from the shore
1020
Port Authority assumes combat agency role
AMSA and NSW Maritime are support agencies
When interviewed, the responsible NSW Maritime manager (Manager Marine Pollution and Emergency Response) stated becoming aware of the incident when an officer from NSW Maritime in Port Kembla called and advised that Marine Rescue Port Kembla had ‘informally advised’ about Portland Bay drifting off the coast (Marine Rescue started informing various agencies from about 0710). Soon after, at about 0715, the NSW Maritime manager called JRCC to obtain information and reported being advised that JRCC ‘was not aware of the incident’.
Port Kembla VTS notified JRCC at 0744, after which AMSA quickly initiated a rescue operation to evacuate the ship’s crew before it stranded on the rocky shore (which was likely to occur by about 0915). The efforts to seek tug assistance remained with Sydney VTS and Monson. After initial confusion about the reason for master’s request for a tug, Monson had sought a tug from Svitzer. Meanwhile Engage Towage had agreed to provide a tug but Sydney VTS also asked AMSA for an emergency tug and was advised that the state’s ETV (Svitzer Glenrock) was in Newcastle.
At about 0800, Engage Towage also contacted United Salvage to assist and decided to deploy SL Diamantina from Port Botany as it had a crew on board. SL Martinique was not crewed and would therefore have taken longer to deploy. By the time United Salvage asked Svitzer for Bullara a short while later, the tug had already been offered for hire to the ship’s managers/owners (via Monson).
At 0803, the NSW Maritime manager called JRCC again and was advised that it was ‘trying to organise tugs to assist as soon as possible’. A few minutes later, the manager called the Port Authority’s chief operating officer (COO) to exchange information and they decided to convene an inter‑agency meeting to discuss the response by New South Wales agencies and AMSA.
At 0810, when planning for the helicopter rescue operation was well progressed, it became evident that no tug could reach the ship in time. The master had already broadcast another PAN message and, at 0814, a MAYDAY message.
At 0822, the ship was 3 miles from the coastline (moving from Commonwealth waters into New South Wales coastal waters) and all ports in the area remained closed. At that time, no tug or helicopter was en route nor had any agency formally assumed responsibility to lead the incident response. On board the ship, emergency anchoring preparations were underway to avoid a stranding.
While Monson was arranging to hire Bullara, Pacific Basin also asked the ship’s hull and machinery insurance underwriter to seek immediately available tugs from international salvage companies.
In submission to the draft of this report, NSW Maritime stated that after contacting the Port Authority, the NSW Maritime manager had ‘numerous discussions’ with MERCOM and provided briefings to the NSW Marine Pollution Controller (MPC). According to NSW Maritime, once the ship entered state waters, the response would be led by New South Wales and that planning for a pollution response was undertaken in case the ship stranded or a pollution incident occurred.
At 0840, AMSA established an incident management team (IMT) for an AMSA level 3 incident (moderate) in accordance with its procedures (detailed in the section titled Maritime Assistance Services proceduresunder National level). The AMSA Response Centre (ARC) duty manager assumed the incident coordinator role and among various roles assigned to team members, the response advisor was assigned responsibility for MAS and ETV matters. This IMT mainly focused on the rescue operation with 3 helicopters en route. Before Portland Bay anchored at 0905, SL Diamantina had left Port Botany (directed by United Salvage) and 2 other tugs were being prepared. One of them (SL Martinique) would be directed by United Salvage while the other (Bullara) was to be hired from Svitzer by Pacific Basin through Monson.
The planned inter‑agency meeting was held from about 0945, where the Port Authority, NSW Maritime and AMSA discussed establishing the control agency (combat agency). Before this meeting, NSW Maritime held an internal meeting where its MPC and senior leadership team were briefed. While the ship had been moving from Commonwealth waters towards and into New South Wales coastal waters, AMSA had not made the required request to the MPC for New South Wales to assume responsibility for the incident. Nevertheless, NSW Maritime advised the Port Authority that it should be leading the response as the combat agency designated by the NSW Plan and its PSOL. The Port Authority’s COO, however, believed that while the ship had drifted into New South Wales waters, managing the incident was not necessarily within the Port Authority’s jurisdiction or responsibility.
At 0946, the helicopter rescue was attempted but abandoned as too hazardous and the anchors seemed to be holding the ship. In addition, SL Diamantina was approaching and, although incapable of towing, it could provide some assistance and would be on scene if the crew abandoned the ship.
After 0950, when Pacific Basin informed the insurance underwriter that an LOF salvage agreement had been made with United Salvage, the insurer’s attempts to seek tugs from international salvors was discontinued.
At about 1020, after further discussion at the inter‑agency meeting, the Port Authority assumed the combat agency role. According to the COO, this decision was based on the Port Authority having better capability to perform that role than NSW Maritime and to assist the latter under the inter‑agency MoU previously described. The responsible NSW Maritime manager, however, stated that the agency was equally capable of performing the combat agency role. The manager further advised that the incident was within the Port Authority’s area of responsibility, which was explicitly defined in its PSOL and the NSW Plan, and the MoU was not relevant in this case.
Incident management
4 July
After the Port Authority assumed the combat agency role at 1020, its COO took charge as the IC and established an IMT, which would be supported by AMSA and NSW Maritime officers. The first IMT meeting followed from about 1030 and United Salvage representatives attending provided an update of the ship’s situation. The IC developed an incident action plan (IAP) with NSW Maritime. With nearby ports closed, the IAP was based on towing the ship away from the coast (the anchors were dragging slowly and it was about 0.9 of a mile from the shore at the time) and the IC directed the salvor, United Salvage, accordingly.
United Salvage intended to substitute SL Diamantina (with no operational aft towing winch and towing capability) with SL Martinique and providing it additional towing gear. Meanwhile, Svitzer had been preparing Bullara in anticipation of Pacific Basin hiring the tug. However, after Monson decided not to hire Bullara, AMSA started planning to task the tug as it had low confidence in the capability of SL Diamantina and considered the combined capabilities of the Engage Towage tugs were insufficient. In submission to the draft of this report, Pacific Basin advised that it had not instructed Monson not to hire Bullara or other Svitzer tugs.
By 1033, it had become evident that the salvor’s plan for SL Diamantina to push on the ship’s hull was not practical in the rough seas and swell and involved high risk of serious collision damage. At 1051, after the MERCOM and ARC duty manager approved it, a tasking direction for Bullara was issued to Svitzer with advice that it was to proceed to the scene and standby to assist. Soon after, at 1054, Bullara deployed followed by SL Martinique 4 minutes later (Table 7).
Table 7: Events from 1033 to 2227 on 4 July
4 July
Event
Notes and remarks
1033
SL Diamantina’s master abandons pushing
The tug had collided with the shipside many times
1054
Bullara deploys (tasked by AMSA)
Monson is not contracting the Svitzer tug
1055
SL Diamantina connects soft towline to ship
Attempting to reduce load on anchor cables
1058
SL Martinique deploys
United Salvage direction and additional towing gear
1230
Port Authority requests tasking of State’s ETV
Via AMSA liaison officer in Port Authority’s IMT
1305
SL Diamantina abandoned efforts to secure line
Towline had parted 3 times
1400
Ship engineers abandon blower repairs
Impeller replaced but motor could not be removed
1402
SL Martinique arrives near ship
Tug starts connecting towline to ship’s port bow
1410
Bullara arrives near ship
AMSA advises the tug is available under LOF terms
1433
SL Martinique’s towline is connected
Bullara connecting towline to ship’s starboard bow
1455
Bullara’s towline is connected
Port Authority incident controller directs tow to sea
1540
Tow started (after weighing anchors)
Incident controller (IC) directs tow 20 miles to sea
1828
United Salvage asks IC to open Port Botany
Tow not progressing away from land
1835
Bullara’s towline parts at its inboard (tug) end
The tug has no spare towing wire
1839
United Salvage asks AMSA to activate the ETV
Alternatively have Port Botany opened
1901
United Salvage calls Svitzer for mobilising ETV
Svitzer offers ETV for hire if not tasked by AMSA
1905~
IC calls MERCOM to ask if ETV tasked
MERCOM not aware of IC request that afternoon
1957
AMSA issues tasking direction for ETV
Svitzer starts preparing ETV Svitzer Glenrock
2015
Portland Bay closing on Bate Bay near Sydney
Master has prepared for emergency anchoring
2035
Ship starts anchoring 1.4 mile from land
IMT has ruled out night helicopter rescue operations
2045
Brought up to both anchors off Bate Bay
Heavy swell >8 m persists
2227
Svitzer Glenrock deploys from Newcastle
ETA 5 July 1200 (speed 5 knots in bad weather)
An incident control centre (ICC) was established at Port Botany to hold 2‑hourly IMT meetings. The Sydney‑based AMSA liaison officer embedded in the IMT structure attended the meetings virtually (as did representatives from some other agencies). Meanwhile, AMSA’s IMT continued operating from the JRCC in Canberra and the responsible NSW Maritime manager physically attended JRCC as the NSW liaison officer from just before midday. The AMSA liaison officer was in contact with AMSA Canberra (both its Operations and Response divisions, including JRCC). The Port Authority was thus to be supported by AMSA and NSW Maritime in oversighting the salvage operation while it managed the incident as required by the NSW Plan (and National Plan).
In submission to the draft of this report, United Salvage advised that while the tugs were en route, it had several phone discussions with various parties, including the Port Authority’s IC, Svitzer, MERCOM and the responsible NSW Maritime manager. According to United Salvage, when it followed up the IC’s advice that ADV Reliant had a BP of 120 t, it found that the vessel had no towing line and was unsuitable.
United Salvage asked Svitzer for Bullara and was advised that it had no objection to the tug connecting a towing line but that it should contact AMSA. United Salvage reported advising the IC, NSW Maritime manager and MERCOM of the intention to tow the ship into deeper water and, as soon as possible, seeking a place of refuge. When the IC and NSW Maritime manager indicated that they were working on plans based on the ship grounding, United Salvage reported advising them that Garie Beach was the only likely access point in case the ship started leaking fuel oil.
By 1149, after AMSA had become aware of United Salvage’s intention to replace SL Diamantina with SL Martinique, it had calculated that a total BP of 120 t was needed to hold the ship and 130 t to move (tow) it. At 1230, AMSA contacted United Salvage and was advised that it intended ‘to only use SL Martinique to tow’ and that there was no requirement for Bullara.
At the IMT meeting held from 1230, the IC asked the AMSA liaison officer to have Svitzer Glenrock activated as the IC felt the state’s nominated ETV might be needed and it was best to activate it early. The liaison officer reportedly passed this request on to AMSA, Canberra. By this time, SL Diamantina had connected a line to the ship’s bow to maintain a static tow, but the line parted repeatedly and efforts to resecure it were unsuccessful, so the tug then stood by while awaiting SL Martinique.
The ship had continued dragging its anchors and recorded data showed that, between 0940 and 1300, the ship moved 665 m closer to the shore (Figure 22). At about 1300, Portland Bay’s master reported adjusting the starboard anchor cable and effectively arresting the dragging of the anchors. The ship’s movement then slowed and, over the next hour, it moved 70 m.
Figure 22: Portland Bay’s movement towards the shore as its anchors dragged
Source: Australian Hydrographic Office and Portland Bay’s recorded voyage data, annotated by the ATSB
At about 1410, after both SL Martinique and Bullara had arrived off the ship, AMSA advised Svitzer and United Salvage that Bullara was available to assist. It also advised Svitzer that it could opt for a commercial agreement (LOF or other terms) with United Salvage. At 1425, United Salvage requested the use of Bullara, which AMSA approved and repeated the earlier advice provided to Svitzer about contractual terms.
Subsequently, AMSA also discussed with Svitzer whether Svitzer Glenrock would need to replace Bullara at some stage due to the latter’s limited fuel (about 40 hours of operation) and decided to revisit the subject at 0700 on the following day, 5 July.
Pacific Basin had opted out of the SCOPIC clause in the LOF salvage agreement which was documented after the master had verbally agreed to the LOF terms (see the section titled Law of salvage under Salvage). While in theory this meant that the salvor would not be entitled to greater special compensation if the salvage was unsuccessful, United Salvage believed that it could invoke the SCOPIC clause as the initial agreement had been verbal.
The NSW Maritime liaison officer attending JRCC reported that Svitzer Glenrock was discussed that afternoon but could not recall details about what was discussed about its activation.
By 1500, both SL Martinique and Bullara had connected a towline at the ship’s port and starboard bow, respectively, to tow the ship. At 1540, when the ship was 0.7 of a mile from the shore, the tow began under United Salvage’s guidance. The IC had directed that the ship be towed 20 miles from the coast to allow engine repairs to be conducted on board in a relatively safe location. The ship’s engine was run at slow speed to assist the tow, but within minutes it failed.
At 1730, AMSA advised Svitzer that it considered Bullara to have been operating under a commercial agreement since 1400. Svitzer, however, advised that the tug had continued to operate under AMSA’s tasking direction. After further correspondence, AMSA advised that it considered the tug was operating under LOF terms from about 1500. Svitzer did not agree with that assertion and the matter remained unresolved.
Over the next couple of hours, with the ship’s engine not operational and the rough seas and heavy swell, the tow made little progress away from the coast. By 1828, it was about 2.5 miles from the coast south of Port Botany, when the salvor asked the IC to open the port so the ship could be towed there for shelter given the lack of progress to tow it to sea (at that rate, it would have taken over 28 hours to be 20 miles from the coast). However, before this request could be considered, Bullara’s towline parted at 1835.
Bullara’s towline parting triggered various actions and decisions to manage the unstable situation and the ship’s certain drift towards the shore in the prevailing weather. The towline could not be recovered, the tug had no spare towing line and the load on SL Martinique’s towline had to be reduced to prevent it also parting.
At about 1839, after informing Svitzer and Engage Towage about the situation, United Salvage called AMSA and asked for Svitzer Glenrock to be activated or have Port Botany opened. At 1901, while AMSA was considering the ETV request, United Salvage asked Svitzer via email whether it could mobilise the ETV. Svitzer replied soon afterwards, advising that AMSA would follow the ETV activation process if it required to task the ETV or it could be hired by the shipowner under a TOWHIRE agreement. According to United Salvage, the best available tugs should always be made available for salvage by their owners.
At about the same time, the Port Authority’s IC called the MERCOM to get an update on the ETV request that had been made after 1230 via the AMSA LO. The MERCOM was not aware of the request but agreed to activate the ETV and offered to issue directions to allow the ship to shelter in Port Botany. The IC, however, advised that the directions could be issued but would not be actioned until the weather had abated sufficiently for the port to reopen and the ship to be safely towed there. The MERCOM also asked if NSW legislation or harbour master directions could be used to direct the ship into port. The IC advised that the harbour master’s directions only applied inside port limits and powers available under state legislation were limited.[160]
At 1945, United Salvage emailed the MERCOM stating: ‘formally request permission to enter a place of refuge being Port Botany to remove this tug and casualty from their current situation’.
At 1957, after MERCOM approval, AMSA issued a tasking direction to activate Svitzer Glenrock. Svitzer felt that due to the preparation and travel time, the ETV could have been activated earlier. Meanwhile, the Port Authority’s IMT monitored the ship’s movement towards Bate Bay. Its engine was not operational and the only available option was emergency anchoring again, this time with SL Martinique connected. The bad weather continued with waves in the south‑easterly swell and seas about 5 m high on average and rising to more than 8 m at times.
At 2028, Svitzer acknowledged United Salvage’s email advising that it had asked AMSA to activate Svitzer Glenrock and requested Port Botany as a place of refuge. At 2037, United Salvage asked Svitzer if any of its tugs in Port Botany with an aft towing line could assist.
By 2045, Portland Bay’s anchors had been deployed off Bate Bay with the ship a little more than one mile from land. Stranding remained a realistic possibility with related considerations such as managing a crew evacuation in bad weather and darkness. There were no practical, safe options as helicopters were not able to conduct night‑time rescues and tugs, navy ships and police rescue vessels were not readily available. Lifeboats were also considered but it was decided that it would be safer for the crew to remain on board the ship. After its master advised being low on fuel, SL Diamantina was allowed to return to port leaving 2 tugs to stand by the ship.
Shortly after 2200, Sydney VTS received a call from the master asking about the availability of an ‘emergency response vessel’. The ship’s engine was unable to be used to reduce dragging with SL Martinique’s master maintaining a low load on the towline to ensure that it did not part.
Svitzer Glenrock departed Newcastle at 2227, but the bad weather meant its best ETA off Bate Bay was noon on the following day. Concerned with this timeframe, AMSA started seeking any available ocean towing gear for use by other tugs in the area closer to the ship’s location.
Just before midnight, Sydney VTS received another call from the master again asking about the availability of an ‘emergency response vessel’. There were no other tugs available in Sydney.
5 July
Shortly after 0100 on 5 July, Portland Bay’s anchors started dragging at a greater rate (about 100 m per hour). In response, the IMT directed SL Martinique’s master to increase weight on its towline to stop the ship dragging onto the shore (Table 8). The tug remained the only available risk mitigation resource given any rescue operation in the conditions would be extremely difficult.
Table 8: Key events on 5 July
5 July
Event
Notes and remarks
0121
Portland Bay anchors drag rate increases
SL Martinique slightly increases load on towline
0848
AMSA upgrades incident to severe (level 5)
MERCOM takes over as AMSA’s incident controller
0900
Port Authority IC asks for MERCOM directions
For Port Botany under POI legislation
1300
Svitzer Glenrock arrives off Bate Bay
MERCOM directs ETV to remain AMSA-tasked
1415
Bullara’s towline recovered
Recovered with difficulty in rough weather
1515
Svitzer Glenrock’s towline fast at ship’s bow
Bullara dismissed; 2 tugs maintained static tow
1607
AMSA emails MERCOM POI directions
To all parties (4) for entering Port Botany
1800
Port Authority IC approves towage plan
United Salvage plan for daylight tow on 6 July
In addition to the Port Authority’s IMT, AMSA’s team continued to monitor the ship’s situation and the Svitzer Glenrock’s ETA, with its master advising that it was operating at its best speed in a 9 m swell. The efforts to locate ocean towing gear in the area for use on scene were proving unsuccessful as the level 1 capability ETV in northern Queensland was the only vessel on the east coast with suitable equipment.
At about 0300, the ship’s engine was successfully started and, over the next hour, the master used it intermittently to assist SL Martinique to reduce the dragging of the anchors. The ship had dragged to within one mile of the shore.
At 0546, the MERCOM responded to United Salvage’s place of refuge request noting that events late on 4 July had taken precedence and that the ETV was due on scene at about midday with plans underway to move the ship to Port Botany. The MERCOM noted that the ship was slowly dragging its anchors but had not yet grounded.
At 0848, the level of the incident in AMSA’s internal systems was upgraded from 3 (moderate) to 5 (severe) noting ‘machinery failure [ship] and immediate tasking of ETV’ (see the section titled Maritime Assistance Services procedures under National level). The ARC duty manager continued coordinating AMSA’s response to the incident with the MERCOM continuing to oversight response activities.
At 0900, the Port Authority’s IC called the MERCOM and requested that a direction be issued to facilitate the ship to be towed into Port Botany. They discussed whether one direction was to be issued or directions to the harbour master and others were also necessary. Shortly after, the response advisor in AMSA’s IMT began drafting the direction(s).
At about 1300, when Svitzer Glenrock had arrived on scene, the MERCOM and IC had another meeting. The MERCOM advised that AMSA would retain control of the ETV for the duration of the incident (as opposed to offering it to United Salvage under the LOF or other commercial terms) to be utilised as required by the salvor and IC. The ETV would connect a towline once Bullara had recovered its line, which had not been possible earlier due to the weather. Weather conditions were moderating and expected to ease further by the next morning to allow the opening of Port Botany. The IC expected the tow could be safely undertaken in daylight. The drafting of the MERCOM’s directions, with advice from AMSA’s legal team, was still ongoing.
The NSW Maritime liaison officer attending JRCC recalled that drafting of the directions took a long time, much of it with AMSA’s legal team. The manager also observed that streamlining of the process would be beneficial as issuing a direction can be time critical.
After 1515, when Svitzer Glenrock’s towline was secured, AMSA released Bullara. By that time, United Salvage was preparing a towage plan to meet the IC’s requirements using Portland Bay’s emergency towing procedure booklet (emailed by Pacific Basin).
At about 1600, the final versions of the MERCOM directions to Portland Bay’s master, Pacific Basin, United Savage and the Port Authority were approved. Shortly after, the directions were emailed to all the recipients (Appendix E).
United Salvage presented and discussed the towage plan with the IC between 1600 and 1700 and agreed some refinements to it. At about 1800, the plan was distributed to the IC and relevant stakeholders. After consulting with the MERCOM, the IC approved the plan to start the tow from about 0800 on 6 July if the swell had subsided to no more than 4 m.
With the towlines of 2 tugs easing the load on the ship’s anchor cables, and the weather moderating, the risk had significantly decreased.
6 July
In preparation for the tow, SLFitzroy arrived on scene shortly by 0730. During the next couple of hours, it had connected a towline to the ship aft and 2 harbour pilots, a salvor’s representative and a main engine service engineer had boarded the ship from a pilot vessel (Table 9). The weather and other conditions for the tow as per the towage plan had been assessed as acceptable.
Table 9: Key events on 6 July
6 July
Event
Notes and remarks
0954
Two Sydney harbour pilots board ship
SL Fitzroy has secured towline at ship’s stern
1000
Portland Bay starts weighing anchors
Salvor and engine maker representatives on ship
1051
Anchors home and towage started
ETV and 2 Engage Towage tugs towing
1228
Portland Bay enters Port Botany limits
SL Diamantina arrives and, at 1312, secured a line
1409
Portland Bay alongside Hayes Dock berth 3
Nominated berth for ship’s engine repair work
1454
Portland Bay secured at berth
All 4 tugs dismissed
1650
AMSA formally detains ship
On grounds of its unreliable propulsion
The master began weighing the anchors at 1000. Svitzer Glenrock’s had deployed 570 m of its towline and advised that it had up to 900 m available. Once the anchors had been weighed an hour later, the 3 tugs coordinated the tow as per the salvor’s towage plan. The ship’s engine was used at dead slow ahead to assist the tow.
By 1230, the tow was inside Port Botany limits and SL Diamantina joined the tow. The towage plan progressed uneventfully and, by 1500, the ship was secured at Hayes Dock and the tugs were dismissed. The ship was later detained by AMSA as unseaworthy and engine repairs as previously described progressed over the following week.
Svitzer Glenrock berthed in Port Botany overnight on 6 July so that its crew could rest. The ETV sailed at about 0630 on 7 July for Newcastle, where it arrived at 1400 that day.
Debriefings and reviews
In the weeks and months following the incident, organisations involved in the incident and the response conducted their reviews or investigations and joint and separate debriefings. Their reports, including AMSA’s comprehensive evaluation of its response,[161] formed part of the evidence for this investigation. Some of the subjects discussed in these reports provided useful insights into the response.
The response agencies involved noted that the master’s delayed incident notification to VTS took away valuable time for their respective responses. In addition, NSW Maritime noted that the notification was not passed on, which initially kept it in the dark.
The Port Authority advised that it was unaware of the planned helicopter rescue, which created confusion as it had deployed tugs with the expectation of connecting towlines to the ship.
The deployment of Svitzer Glenrock was a recurrent subject of discussion. According to AMSA, the ETV could have been deployed earlier if it had had oversight of the Port Authority’s IAP. The Port Authority, however, stated that it had kept JRCC updated on all tug deployments. Pacific Basin noted a lack of availability of ‘proper salvage tugs’ until the Svitzer Glenrock arrived on scene. Acknowledging the differing observations, the universal conclusion among the involved parties following review of the occurrence was that the ETV should have been deployed much earlier.
There were different understandings of salvage matters and how the LOF salvage agreement worked with incident management. Other subjects of discussion included different understandings of place of refuge directions issued under national legislation, difficulties in drafting directions and the long delays in issuing them.
In general, it was acknowledged that a good measure of ‘luck’ helped avoid a disaster (stranding with potentially severe consequences).
Overall, these debriefings and reviews indicate inadequate coordination and confusion. None of them identified any of the safety issues identified in the Findings section of this report.
Submissions to draft report
In response to the draft of this investigation report provided to directly involved parties, substantive submissions were received from several parties. Submission comments that have not been addressed in other sections of this report are described below to provide useful context.
Portland Bay’s master
Portland Bay’s master advised being unaware of the previous problems with main engine auxiliary blower number 2. The master noted that because of the ship’s light draught, it had been ‘crucial to avoid pitching and slamming’ to avoid main engine overload and, as the weather further offshore was worse, the ship had been manoeuvred accordingly with the engine at low rpm.
Pacific Basin
Pacific Basin submitted that Svitzer Glenrock, the only ETV in the area arrived 18 hours after the ship first anchored. With respect to the emergency towage capability described in the report and shown in Figure 16, it stated that ‘the lack of quick availability of proper salvage tugs close to Port Kembla is concerning’ and proper positioning of salvage tugs should be considered.
Pacific Basin advised that following the master’s request to Port Kembla VTS for tug assistance, it had followed up with the ship’s agent, Monson, who had confirmed that Svitzer was preparing a tug (Bullara). It further advised that the ship’s hull and machinery insurance underwriter was asked to seek tugs from international salvors but this was discontinued after the LOF salvage agreement with United Salvage. Pacific Basin pointed out that under the LOF terms, the salvor was ‘obliged to take whatsoever measures feasible and reasonable under the prevailing circumstances, including mobilising whatever equipment or device or labours, to salve the vessel’.
With respect to Monson instructing Svitzer (after the salvage agreement was made) that its tug, Bullara, was not required, Pacific Basin stated that it did not give such instruction to the agent (Monson advised the ATSB that it did not intend to make a submission to the draft report).
United Salvage
United Salvage submitted that soon after advising Engage Towage to deploy its tugs, it had contacted Svitzer for Bullara but was advised that a towage contract with the ship’s owners was being agreed. According to United Salvage, Bullara was therefore not available to take on hire and it did not know why the tug was not made available to United Salvage.
In addition, United Salvage stated that it ‘mobilised on speculation to render salvage assistance with the towing vessels that were immediately available’ and ‘took advantage of Bullara when AMSA made it possible’. It pointed out that ‘when the owner of a tug will not make it available, salvors must move on to find other tugs’. United Salvage noted that it ‘exercised our best endeavours to render maximum assistance to the casualty to tow it out of harm’s way under an LOF agreement as a professional salvor’.
Engage Marine
Engage Marine, the parent company of Engage Towage, advised that it believed the draft ‘report is accurate and captures all elements that need to be highlighted and addressed’.
Svitzer Australia
Svitzer submitted that it offered Svitzer Glenrock as well as other tugs to United Salvage, however this was declined as existing arrangements had been made with Engage Marine/Towage. Svitzer further clarified this by indicating that it wanted an arrangement in place (from a commercial perspective)[162] before deploying Bullara and needed to ensure the safety of the tug crew.
In addition, Svitzer confirmed that Bullara would need to have been appropriately equipped and prepared for it to be an alternate ETV under AMSA’s ETC contract. The tug was fitted with a higher level of towing equipment after the incident (see the section titled Safety issues and actions).
Australian Maritime Safety Authority
According to AMSA, the draft report included a disproportionate focus on the incident response. It felt that the responsibilities of the ship’s master and owner, particularly with regard to engaging commercial towage at the earliest, should have been further considered.
In addition, AMSA stated that once the ship entered New South Wales waters, the state was responsible for managing the casualty. It noted that there was no request to AMSA to manage the casualty on behalf of New South Wales so AMSA supported the Port Authority and the salvor.
According to AMSA, Svitzer Glenrock could have been deployed by the Port Authority as it had daily operational control of the tug under its contract (harbour towage). It further noted that the ETV was also available to ‘private industry’ under commercial arrangements. Bullara, AMSA claimed, was the designated tug with alternate capability for the New South Wales region and that it met all the conditions of the ETC contract, including appropriate towing gear, equipment, crewing and training.
With respect to the suspension of National Plan annual exercises during the pandemic, AMSA advised that the National Plan Strategic Coordination Committee (NPSCC) chaired by the Department of Infrastructure, Transport, Regional Development, Communications and the Arts had made a risk‑based decision not to hold these exercises and established a reporting system to monitor the Plan’s capability and manage risks. It pointed out that the NPSCC was responsible for overseeing the Plan’s implementation and ensuring the effectiveness of its arrangements. Further, AMSA advised that it had participated in 3 desktop exercises conducted by Maritime Safety Queensland in 2020 and one exercise conducted by NSW Maritime in 2021.
In relation to emergency towage, AMSA invited the ATSB to consider whether state and Northern Territory governments were sufficiently considering emergency towage requirements through port [towage] licensing arrangements and whether this was contributing to a safety failure along the Australian coastline.
Transport for NSW (NSW Maritime)
Transport for NSW (NSW Maritime) submitted that the provisions most relevant to this incident were contained in the emergency response section of the Port Authority’s Port Safety Operating License (PSOL). According to NSW Maritime, once the ship entered state waters, the response had to be led by New South Wales and noted that planning for a pollution response was undertaken in case the ship stranded or pollution occurred.
With respect to its actions after becoming aware of the incident, NSW Maritime claimed that it proactively followed up with AMSA and the Port Authority and had numerous discussions with the MERCOM. It advised that briefings were subsequently provided to internal and external stakeholders and support provided to the Port Authority’s incident management team.
Further, NSW Maritime advised that, in addition to informing the Port Authority’s chief operating officer at the inter‑agency meeting at about 0945 that it was the designated combat agency under the PSOL and NSW Plan, the Executive Director of NSW Maritime who was the Marine Pollution Controller (MPC) formally reaffirmed to the chief executive officer of the Port Authority that it was the designated combat agency under the PSOL.
According to NSW Maritime, once the Port Authority assumed the combat agency role, the response was well managed but the ‘lack of salvage (tug) capability and release of the ETV was ineffective’. It advised that the liaison officers were limited in their capacities as there are always some aspects and discussions that they will not be privy to, such as internal legal advice provided to incident management or response teams. In addition, NSW Maritime questioned if a place of refuge was requested, who requested it and to whom was the request submitted.[163]
Port Authority of New South Wales
The Port Authority claimed that as per appendix 2 of its PSOL it was required ‘to respond to oil and chemical spills, not emergencies’. It stated that the ‘area of operations’ defined by the NSW Plan (Figure 19) ‘were limited to marine pollution incidents, not maritime emergencies such as a disabled vessel’. It argued that the emergency response requirements in the PSOL for ‘port‑related emergencies’ within ports should be distinguished from a response to ‘incidents’ in coastal waters as per the NSW Plan. It stated that ‘incidents’ should be interpreted as involving oil or chemical pollution and that this interpretation was supported by the text in the title of appendix 2 being: ‘Area of operations for out of port oil and chemical responses’.
According to the Port Authority, the National Plan required that ‘no agency should assume responsibility for an incident until it was determined that the master failed in their responsibility to manage the maritime casualty’. It stated that, under the National Plan, AMSA was responsible for managing a casualty that originated in Commonwealth waters but it did not transfer management or control of the incident to the Port Authority as required. The Port Authority claimed that it had only held primary obligations for pollution response, which were ultimately not required to be exercised, but had accepted an informal transfer of prevention obligations (casualty management of the disabled ship) from AMSA.
The Port Authority further argued that even if the casualty was deemed to have originated in New South Wales waters, the National Plan assigned responsibility for that to the state government through Transport for NSW (NSW Maritime). It pointed out that the state EMPLAN assigned various roles to NSW Maritime with responsibility for pollution prevention, emergency towage and refuge arrangements, and response, including incident assessment/monitoring and assessment of refuge requests, but the Port Authority was not responsible for these activities. It noted that the EMPLAN and NSW Plan assigned responsibility for emergency response to the MPC and NSW Maritime, not the Port Authority, which could be the combat agency for pollution incidents but not for emergency response.
According to the Port Authority, under the NSW Plan, its ‘obligations as a combat agency were not enlivened in respect of the Portland Bay as the ship did not create an oil pollution spill, nor was there a situation in which an oil pollution spill was imminent and a pollution response could be usefully assembled’. It submitted that, under the NSW Plan, intervention in relation to a disabled ship in coastal waters outside port areas was a role for the MERCOM with the MPC and NSW Maritime supporting the response to incidents and emergencies whereas the role of the Port Authority was ‘to provide marine pollution responses, if required’.
Lessons from casualties
Historical context
As described in the section titled Peril at sea, shipping casualties and disasters have occurred throughout maritime history. Although the frequency of serious casualties resulting in the loss of ships has declined since the 1800s when steel‑hulled, power‑driven ships were introduced, their consequences have become more severe with many disasters, including in the twentieth century. The main reasons include the increasing size of ships, the quantities and types of cargoes carried and the passenger numbers carried. At the same time, tolerance for serious casualties, particularly those involving environmental damage and/or loss of life has progressively declined.
Lessons from casualties in modern times have often resulted in safety enhancements. The 1912 sinking of Titanic with the loss of more than 1,500 lives led to maritime nations adopting the first international convention on safety of life at sea in 1914 to prevent a similar catastrophe.[164] In 1948, when the IMO was established,[165] it adopted that convention, retaining its name and has since continued developing the SOLAS Convention as the main pillar to enhance maritime safety. Casualties continue to offer valuable lessons to improve standards, regulations and seamanship to help avoid disasters.
Incidents in Australia
The waters off Australia’s coastline are not as congested as many waterways overseas such as the Mediterranean Sea, English Channel and Singapore Strait. However, Australia’s coastline is extensive, with large distances between ports with resources such as ETVs and harbour tugs few and far between. This aspect presents challenges when managing emergencies in accordance with the National Plan.
Since it was developed in 1973, the National Plan has been used to manage numerous casualties and pollution incidents. Since 1991, AMSA has managed the Plan and many incidents, including those that involved Sanko Harvest and Kirki in 1991, Era in 1992, Iron Baron in 1994, Laura D’Amato in 1999, Global Peace in 2006, Pacific Adventurer in 2009 and Shen Neng 1 in 2010. The principal contributing factors to these incidents were different and included hull failure, hull damage and stranding, however all resulted in oil spills. Even relatively limited pollution in an environmentally sensitive area is significant, such as the 4 tonnes spilled from Shen Neng 1 in the Great Barrier Reef (Figure 23).
Figure 23: Shen Neng 1 stranded on Douglas Shoal, Great Barrier Reef, Queensland
Source: Maritime Safety Queensland
Many serious incidents, including groundings, strandings and near strandings, have not resulted in pollution. The more recent incidents, some of which occurred in the Great Barrier Reef region, include those involving Bunga Teratai Satu in 2000, Doric Chariot in 2002, Crimson Mars in 2006, Pasha Bulker in 2007, MSC Lugano, Atlantic Eagle and Iron King in 2008, Atlantic Blue in 2009, ID Integrity in 2012, Maersk Garonne in 2015, Aquadiva in 2017, Bulk India in 2018, Trinity Bay in 2021 and Rosco Poplar in 2022. The ATSB investigated these incidents and some of the circumstances in the cases are comparable to those of this incident, including the application of National Plan arrangements.
In 2007, Pasha Bulker did not clear the coast in a storm, which drove it on to Nobbys Beach, Newcastle (Figure 24). Two other ships narrowly avoided stranding by resorting to emergency use of their anchors. The salvage operation to refloat Pasha Bulker was monitored by AMSA and succeeded after a couple of months. There was no pollution but the incident’s location on the beach of a major city made it significant.
Figure 24: Pasha Bulker stranded on Nobbys Beach, Newcastle, New South Wales
Source: ATSB
In 2008, MSC Lugano lost propulsion after an engine room fire about 100 miles south‑east of Esperance, Western Australia (WA). The disabled ship drifted towards the coastline and harbour tugs from Esperance were deployed by AMSA when worsening weather increased the risk of grounding. The tugs were able to prevent a grounding on shoals about 6 miles off until a salvor’s tug from Fremantle, WA, took the ship in tow and safely towed it to there for repairs.
In 2012, ID Integrity lost propulsion due to mechanical issues with its engine in the Coral Sea and drifted towards the Great Barrier Reef. The dedicated ETV in Queensland was tasked by AMSA and the ship’s managers arranged 2 tugs from nearby ports. Contingencies, including the use of anchors, were put in place while waiting for the tugs. The ETV towed the ship to Cairns for repairs with the other tugs assisting as escorts.
Each year, thousands of ships call at Australian ports (AMSA data indicates that 6,042 individual ships made 26,744 calls in 2022). A small number of these voyages involve a ship breaking down in Australian waters. Most breakdowns are rectified relatively quickly, however, at times, a ship is disabled close to a lee shore in bad weather with the risk of stranding.
An assessment of oil pollution risk in 2011 based on a data set of incidents in Australia found that the proportion of spills due to drift groundings and powered groundings were 22% and 20% of the total, respectively.[166] The drift groundings were typically due to loss of propulsion and/or anchors in adverse weather while the powered groundings were typically the result of navigational errors.
Causes of strandings
Historically, the consequences of strandings have often been severe. A significant proportion of very serious casualties in modern times have also been strandings with hull damage and consequential pollution. The Nautical Institute publication, Strandings and their Causes,[167] described the various causes and includes many case studies with useful lessons. Chapter 8 of the publication (Loss of Propulsion and Stranding) is directly relevant to this incident:
Human error accounts for the overwhelming part of strandings, but a not insignificant number of such casualties result from steering or propulsion machinery failure. Yet even in such cases the element of human error is often dominant though usually unconnected with those responsible for the navigation of the vessel. Unfortunately, there is ordinarily little the master can do to forestall mistakes in an area in which he not only usually lacks competence but also will not have direct access to the relevant information and facts. As far as the propulsion of his ship is concerned he is little more than a passenger. It is prudent, therefore, for him to include in his planning of a passage for the possibility of a loss of steering or propulsion or both. In most cases such an eventuality will not expose the vessel to immediate hazard, as more often than not the vessel be on the open sea and the machinery will be restored to operation in good time. Where the vessel is incapacitated close to land, however, failure to take this possibility into account beforehand could mean the difference between a close call and standing.[168]
The following observations from this publication also offer the following insights:
Occasionally it will happen out of a single mistake or momentary lapse of judgement, but far too often the stranding is only the climax of a chain of errors and oversights coloured, if not determined, by bad judgement.[169]
With strandings, as with collisions, it is rare that a single fault or mistake is responsible. Luck will often allow a lone mistake to pass unpunished and in most cases the casualty is the end of a chain of errors.[170]
The learnings from casualties, albeit with the benefit of hindsight, invariably provide invaluable lessons. The lessons learned provide the knowledge and foresight to make prudent decisions not only to avoid an emergency but to effectively manage one.
Safety analysis
Introduction
Incident
Portland Bay sailed from Port Kembla, New South Wales, on 3 July 2022 as bad weather was impacting its stay in port and was expected to return there when the weather improved. The ship steamed and intermittently drifted about 12 nautical miles (miles) from the coastline.
In the early hours of 4 July, the main engine developed mechanical problems, which disabled the ship 12 miles from the lee shore. A couple of hours later, after unsuccessful attempts to resolve the engine problems, the ship’s master notified Port Kembla vessel traffic service that the main engine had failed and requested tug assistance. About 2 hours later, a harbour tug from Sydney was en route but the ship had closed to one mile from the shore. The master made emergency use of both anchors to prevent stranding on the rocky shore about 12 miles south of Port Botany (Sydney).
About one hour after the ship anchored, the harbour tug arrived and attempted to assist. Some 4 hours later, 2 more harbour tugs from Sydney arrived. By late afternoon, these 2 tugs began towing the ship away from the coast but a couple of hours later in the evening, one parted its towline. The ship then drifted towards the shore and the master again anchored about one mile from the shore off Bate Bay near Sydney. Later that night, the state’s nominated emergency towage vessel (ETV) deployed from Newcastle.
The ETV arrived on scene after midday on the following day, 5 July, and connected a towline that evening in preparation to tow the ship into port. On the morning of 6 July, the ETV (with harbour tugs assisting) towed the ship into Port Botany, where it was berthed in the afternoon for refuge and repairs.
Analysis
This analysis firstly details the factors that contributed to Portland Bay’s propulsion failure and disabling in bad weather, which led to the emergency. A major part of the analysis necessarily examines the response to the emergency by authorities from the initial activities and events to its subsequent management over the next 2 days and identifies 7 associated safety issues.
Development of emergency
The emergency developed over a period of about 18 hours after Portland Bay departed Port Kembla on 3 July. The ship’s situation then progressively became more precarious.
Coast not cleared
The master had taken command of the ship on 22 June, 2 weeks before the incident. The handover and subsequent ship operations indicated that the ship and its machinery were in operational condition. In addition, a week before the incident, the ship had left Port Kembla to clean its cargo holds and anchored or drifted off the port for a couple of days.
After the ship berthed again on 2 July, the master observed the worsening weather and complied with the harbour master’s weather‑related precautions. When the weather deteriorated on 3 July, the master agreed with the Port Authority’s decision for the ship to put to sea to avoid damage to the ship and berth. Maintenance for main engine auxiliary blower number 2 was pending, but the chief engineer and the master were not concerned about this affecting the engine’s performance.
After the ship sailed on 3 July, the master noted several ships drifting in the general area off the coast. The master was aware of Port Kembla vessel traffic service’s (VTS) advice to masters to keep ‘at a safe distance (around 12 miles)’ from the coast. The ship steamed on an east‑north‑easterly course that slightly diverged from the coast and, when it was 12 miles off, the engine was stopped to drift (Figure 1). For the rest of that day and night, the ship drifted and steamed intermittently, remaining 8–15 miles off the coast. In submission to the draft of this report, the master advised that the weather further offshore was worse, hence the ship was manoeuvred to avoid main engine damage from sudden load fluctuations due to the propeller not being fully immersed when pitching.
However, the shipboard safety management system (SMS) procedures required that, in bad weather, masters remain 50 miles from the coast where possible, which was consistent with good practice and seamanship. While the master stated that the heavy weather had made this ‘impossible’, the evidence indicates that it had been possible to attempt to clear the coast.
When the ship had got underway again at 0330 on 4 July, it was put on a true heading (course) of about 110°. The master found that the ship experienced less rolling on this course. It also began moving directly away from the coast at about 3 knots. The reduced rolling and progress away from the coast were attributable to the weather being on the ship’s starboard bow (as opposed to nearly abeam earlier while it was steaming or drifting).
Therefore, after putting to sea, had an attempt been made to clear the coast on a 110° or similar course at the same engine speed, the ship could have been 50 miles from the coast by 0500 on 4 July. The master’s decision to drift and steam intermittently 12 miles off the coast was probably influenced by the advice from VTS, other ships drifting in the area, an expectation to return to Port Kembla and having no concerns about the engine. However, remaining there exposed the ship to the risks that the SMS procedures were intended to address. It was also not consistent with good practice and seamanship.
Contributing factor
After departing Port Kembla in adverse weather on 3 July 2022, Portland Bay’s master steamed slowly or drifted about 12 miles off the coast instead of safely clearing it in accordance with the ship’s safety management system procedures.
Main engine problems
Degraded engine performance
With the ship’s east‑north‑easterly course and the seas and swell nearly abeam, the main engine rpm achieved fluctuated widely as the ship rolled and pitched heavily (Figure 9). The fluctuating engine load would have led to turbocharger surge and repetitive opening and closing of scavenge system non‑return flaps. The load fluctuations resulted in excessive fuel being injected into the engine with incomplete and unstable combustion and build‑up of carbon and fuel deposits. Piston blow‑by due to sticky piston rings caused by poor combustion, excessive fuel injection, excessive cylinder lubrication and a leaky fuel injector further increased the build‑up of fuel deposits and sludge. In addition, excessive cylinder lubrication resulted in excess oil in the under‑piston space.
Continuous operation with these factors and conditions progressively degraded the performance of the engine.
Contributing factor
Operating the main engine at low speed while the ship was rolling and pitching heavily exacerbated engine load fluctuations due to turbocharger surge and non‑return flap hammering. Engine performance was further degraded by a leaky fuel injector, poor combustion and excessive cylinder lubrication, which resulted in sludge and deposits accumulating in the engine scavenge spaces, blow by and sticky piston rings.
Auxiliary blower failure
The electric motor and impeller bearings of auxiliary blower number 2 were replaced in June 2021. In March 2022, an inspection had identified a cracked impeller, damaged shaft bearings and worn bearing housings. A previously used impeller was fitted and the cracked one was weld repaired. In April 2022, the welded impeller was refitted without rebalancing. New bearings were fitted in the same worn bearing housings because there were no spares on board at the time.
A new impeller and bearing housings were to be fitted in Port Kembla but, before this could be done, the ship put to sea on 3 July. Therefore, the blower had been operating with an unbalanced impeller and oversized bearing housing since April. Its unbalanced operation was exacerbated by the varying engine load conditions at sea and eventually resulted in the blower’s failure on 4 July when the impeller bearings failed.
Contributing factor
The main engine auxiliary blower number 2 impeller bearings failed in the early hours of 4 July. This was most probably due to prolonged operation with an unbalanced impeller and oversized bearing housing, aggravated by varying engine load due to the ship's rolling and pitching.
Engine speed limited
After the ship put to sea on 3 July, a combination of:
main engine speed fluctuations
incomplete and unstable combustion
excessive fuel injection
piston blow‑by
excessive cylinder lubrication
a leaky fuel injector
resulted in a build‑up of carbon, fuel and deposits that progressively degraded engine performance. In addition, combustion airflow reduced as some air was recirculating to the auxiliary blower through a distorted turbocharger delivery non‑return flap. When auxiliary blower number 2 failed, airflow reduced to the point that the engine could not achieve a speed of more than about 42 rpm (dead slow ahead setting).
The engine manufacturer’s conclusions based on its inspection and service following the incident were consistent with the evidence and the operating conditions on 3 and 4 July. The manufacturer concluded that the main reason limiting the engine speed had been insufficient combustion air. The condition of each engine component, on its own, was not considered enough to disrupt airflow and limit engine speed. However, the combination of component wear and fouling of multiple components, limited the operation of the engine to about 42 rpm.
Contributing factor
The failure of auxiliary blower number 2 substantially reduced the normal airflow to the engine. In addition, some air was recirculating to the blower inlet through a distorted turbocharger delivery non‑return flap. The resulting low airflow limited the engine speed to 42 rpm (dead slow ahead setting) and significantly reduced the propulsive power available.
Ship disabled
Portland Bay’s significant loss of propulsive power in the rough weather conditions effectively disabled the ship. With no steerage way and the wind on its port beam, the ship began drifting towards the shore about 12 miles off (Figure 4).
The master arrived on the bridge 2 minutes after failure of the auxiliary blower. Over the next 20 minutes, it became evident that the ship was disabled in very unfavourable conditions and drifting rapidly towards the shore. The engine speed available was too low to steer the ship (which was stationary in the water) on to a course to put the weather on the bow to reduce drift and rolling or to attempt steaming away from the shore. At 0513 on 4 July, the master assessed that the ship was 3–4 hours away from drifting on to the shore about 11 miles off.
Contributing factor
The significant loss of Portland Bay’s propulsive power in the prevailing gale force winds, very rough seas and heavy swell effectively disabled the ship and resulted in it drifting towards the lee shore.
Delayed notification
The master’s assessment that the ship was 3–4 hours from the shore if propulsion was not restored and the chief engineer’s advice that the auxiliary blower could not be quickly repaired indicated that prompt emergency notifications were necessary to obtain tug assistance in time.
About 30 minutes after the engine developed problems, the master notified the ship’s managers, Pacific Basin, about the emergency and being 10 miles from the lee shore in heavy weather. Over the following 85 minutes, its senior management, including the fleet director and the marine and safety manager largely provided engineering advice to resolve the problem. Except for briefly asking about steaming 50 miles away from the coast, other SMS requirements such as notifying authorities as per the company’s crisis management manual, were not raised with the master.
Although the master voiced increasing concerns to those on the bridge about the ship closing the coast and the need to obtain tug assistance, those concerns were not specifically raised with Pacific Basin, which focused on providing engineering advice. While the focus on restoring usable engine power was understandable, attempting to resolve the engine issue and notifying authorities could have been done simultaneously. The emergency required prompt notification to authorities in accordance with the SMS procedures to maximise the available response time.
However, this did not occur even after Pacific Basin’s designated person ashore (DPA) was informed at 0615. The fleet director, marine and safety manager and DPA were required to be completely familiar with the company’s crisis management and SMS requirements. They were also expected to ensure critical actions, such as notifying authorities to manage the worsening emergency, were promptly taken.
At 0624, when the engine could not be restarted, the disabled ship began displaying ‘not under command’ (NUC) signals and the corresponding NUC status on the automatic identification system (AIS). However, authorities ashore were not notified and Pacific Basin continued directing efforts to start the engine. It was not until 0650, when the master again raised the subject of tug assistance with Pacific Basin, that this was properly considered. Five minutes later, Pacific Basin agreed to the master requesting tug assistance. Soon after, at 0656, Pacific Basin established a virtual team to manage the emergency and one minute later, the master notified Port Kembla VTS of the engine failure and requested tug assistance.
Had the master raised the concerns with Pacific Basin explicitly and strongly much earlier, it would have been compelled to respond appropriately. However, the master would also have reasonably expected Pacific Basin to raise the subject of notifying authorities as per its SMS emergency procedures. When the subject was not raised and only engineering advice was offered, the master probably deferred to the managers ashore on the basis that they were aware of the situation but not recommending or encouraging notifying authorities.
The delay in notifying authorities was contrary to the SMS procedures, good practice and recognised guidance. It also highlights the importance of the warning: ‘do not delay sending appropriate alerts and notifications’ in the publication ‘Peril at Sea and Salvage: A Guide for Masters’ (master’s Guide) previously discussed. Notifying authorities should have been a priority for both the master and Pacific Basin’s senior management.
Contributing factor
Portland Bay’s master notified Port Kembla vessel traffic service that the main engine had failed and requested tug assistance about 2 hours after the ship was disabled. This delay significantly reduced the time available to Australian authorities to respond and for tugs to assist the ship in time to avoid a stranding.
Contributing factor
Portland Bay’s manager, Pacific Basin Shipping, did not provide the master advice about notifying authorities as per the ship’s safety management system emergency procedures, instead focusing on the engineering matters. This probably led to the master delaying the notification and the request for tug assistance. (Safety issue)
Initial response
The following sections examine the response during the 3.5 hours after the master notified Port Kembla VTS. The National Plan for Maritime Environmental Emergencies (National Plan) and the NSW Coastal Waters Marine Pollution Plan (NSW Plan) are referred to extensively.
Notifications
At about 0700 on 4 July, Port Kembla VTS informed the ship’s agent in Port Kembla (Monson) that the master had requested tug assistance. It then made internal notifications within the Port Authority of New South Wales (Port Authority). However, neither the Australian Maritime Safety Authority (AMSA) nor NSW Maritime were notified as required by the VTS procedures and NSW Plan (Figure 18).
The NSW Plan assigned VTS sole responsibility for making the required notifications. It also warned that incidents less than 20 miles offshore were potentially significant (when the master notified Port Kembla VTS, the ship was less than 7 miles from the shore in Commonwealth waters). Therefore, VTS was required to promptly notify AMSA and NSW Maritime.
However, the master also notified Marine Rescue Port Kembla at 0703. Although the NSW Plan did not apply to Marine Rescue, it informed the NSW Police and NSW Maritime about the incident at about 0710. Shortly afterwards, NSW Maritime contacted AMSA, found that it was not aware of the incident but did not contact Port Kembla VTS or the Port Authority at that time (instead NSW Maritime contacted AMSA again at 0803, when it was provided available information after which it contacted the Port Authority).
At 0744, some 45 minutes after the master notified it, Port Kembla VTS reported the incident to AMSA. This delay reduced the time available to AMSA to initiate and coordinate a response. In addition, during the intervening time, the ship had drifted to within 5 miles of the coast. This also increased the jurisdictional complexity for an AMSA response under the National Plan to the emergency in Commonwealth waters, yet close to coastal waters in which New South Wales was responsible.
Contributing factor
Port Kembla vessel traffic service delayed notifying the Australian Maritime Safety Authority (AMSA) about the incident for 45 minutes. This delay reduced the time available to AMSA to initiate and coordinate an emergency response.
Tug assistance
The urgency message (PAN) broadcast by Portland Bay’s crewat 0716, as suggested by Marine Rescue, was probably also intended to expedite the deployment of tugs. Soon after the PAN broadcast, Sydney VTS began monitoring the ship’s movement and seeking tugs in the port. Engage Towage confirmed that it would immediately prepare a tug.
Sydney VTS contacted AMSA at 0745 to arrange an ‘emergency tug’ and advised that Engage Towage was preparing a tug. In response, AMSA (which had been notified by Port Kembla VTS one minute earlier) advised that the ETV, Svitzer Glenrock, was in Newcastle. Consequently, Sydney VTS advised that it would arrange an available tug(s) from Sydney.
Meanwhile, Monson was aware of the master’s request for tug assistance, but did not know that the ship had broken down. By the time Monson followed up the tug assistance request with the master and Pacific Basin it was nearly 0800. Soon after, realising the urgency, Monson contacted Svitzer Australia (Svitzer) for a tug. Svitzer then began preparing to provide its tug, Bullara.
Notwithstanding their limited emergency towing capabilities, the Sydney harbour tugs were the only immediately available options as the ETV was several hours steaming away. However, at that stage no tug could have arrived in time to prevent the disabled ship drifting on to the shore. Emergency anchoring was the only means of preventing a stranding.
Emergency anchoring
Soon after the PAN broadcast at 0716, Pacific Basin asked the master to prepare for emergency anchoring. Over the next 2 hours, it provided the master with guidance for anchoring, consistent with the safety management system (SMS) procedures.
While Marine Rescue had suggested anchoring immediately, the master had rejected the suggestion as anchoring in deep water was contrary to the SMS procedures and the master’s Guide (Peril at Sea and Salvage). In deep water, the master’s Guide suggested that the anchors could be lowered to reduce drift rate. However, the master did not consider this, probably due to the risk of the anchors holing the hull as the ship rolled heavily and/or to avoid fouling the anchor cables (the chains becoming entangled).
Anchoring equipment is intended to be used in a harbour or sheltered area and is not designed to hold a ship in rough weather. However, the use of anchors in emergencies is recognised and has been used as a last resort to prevent strandings.
The master’s planning and preparation for anchoring, including the instructions to the chief mate and others indicated a good understanding of the SMS procedures and the inherent limitations of anchoring equipment. This resulted in the appropriate and effective deployment of the anchors shortly after 0900, consistent with good seamanship.
Most importantly, anchoring prevented a likely catastrophic stranding on the rocky shore less than one mile off.
Other finding
Portland Bay's emergency anchoring prevented a catastrophic stranding on the rocky shore in heavy weather (anchoring equipment is not designed to hold a ship in rough weather).
Crew rescue attempt
Soon after AMSA was notified at 0744, it took over search and rescue (SAR) coordination. Within minutes, AMSA determined that a stranding was probably imminent. As the consequences could include loss of life, evacuating the crew became the primary mission. By 0800, AMSA had initiated an operation to rescue the ship’s crew in accordance with its SAR procedures.
Consequently, by the time the ship was anchoring, 3 AMSA‑tasked rescue helicopters were en route. Some confusion ensued when they arrived on scene to find a fourth helicopter (unknowingly arranged by NSW Police) but AMSA soon resolved this by standing it down. There were no tugs or police vessels on scene at the time.
After about 0930, the helicopters attempted to winch crew off the ship’s deck, but heavy rolling and pitching and the structures on deck made the operation very hazardous. Consequently, after 3 unsuccessful attempts, the rescue was abandoned as the anchors were reported to be holding at that time. In addition, surface assets, including the tug SL Diamantina, were due soon.
While the rescue attempt was consistent with the overriding consideration for safety of life, some matters were inadvertently overlooked. In addition to the uncoordinated arrival of the fourth helicopter, the subject of the crew that would remain on board for a towing operation was not discussed between AMSA, the Port Authority, the master and Pacific Basin. While this had no material consequences as the rescue was abandoned, it created unnecessary confusion and uncertainty about emergency towage matters.
Other finding
The attempt to rescue Portland Bay's crew by helicopter in case it stranded was appropriate, as was its risk‑assessed suspension after the ship’s anchors reduced the risk of stranding.
Assuming control
Soon after the Port Authority’s Sydney VTS began monitoring the ship’s movement at 0720, it became evident that it would enter the state’s coastal waters after about one hour. The ship would then be in the region where the Port Authority was responsible for response (Figure 19). The only action taken by the Port Authority at that stage was seeking tugs and, at 0744, notifying AMSA.
In submission to the draft of this report, the Port Authority argued that, under the National Plan, neither AMSA nor the New South Wales Government were permitted to assume control of a casualty unless it was determined that the shipowner or master had failed in their responsibility to manage the casualty effectively, in a timely manner or in the interests of protecting the community and the environment. It reiterated its views about the responsibilities of governments as previously described (see the section titled Submissions to draft report) and pointed out that AMSA was responsible for managing the casualty, which had originated in Commonwealth waters, but did not follow the process for a change of control agency under the National Plan. The Port Authority stated that if the casualty was found to have originated in coastal waters, then the New South Wales Government through NSW Maritime was responsible/accountable.
However, when the master notified the Port Authority’s VTS at 0657 about the main engine failure and requested tug assistance with the ship less than 7 miles from the shore, it was evident that prompt action was critical to mitigate the ship’s perilous situation, which was plausibly the result of the master not having managed it effectively. Despite having the necessary information to make that conclusion, the Port Authority did not notify AMSA for more than 45 minutes and never notified NSW Maritime as was required.
However, the Port Authority did seek tugs, which indicated understanding the emergency situation but an inability to follow the relevant plans and procedures to ensure that the appropriate authorities could oversee or manage the casualty and, if necessary, assume control to avoid an impending disaster. Suggesting that the National Plan did not permit any authority to assume control in that situation while, at the same time, asserting that only AMSA or NSW Maritime were responsible and accountable is disingenuous.
Shortly after about 0810, the Port Authority and NSW Maritime first discussed national and state roles and responsibilities when the ship entered state waters. No request had been received from AMSA for New South Wales to assume control nor did they know if AMSA had assumed control under the National Plan. Instead of taking decisive action to confirm the combat (control) agency, they deferred the decision to a multi‑agency meeting to be convened, effectively postponing this important matter. Consequently, when the ship entered New South Wales waters at 0822, no agency had assumed the control agency role.
In submission to the draft report, AMSA argued that as the Port Authority had been arranging tugs with the ship moving towards New South Wales waters, the state had assumed control of the casualty and that this was formally confirmed at the inter‑agency meeting later.
At 0840, while progressing the SAR operation, AMSA established an incident management team (IMT) for an AMSA level 3 incident (moderate severity level) but did not inform the Port Authority. As a result, there was no coordination between the 2 agencies and AMSA’s IMT continued to focus entirely on rescuing the ship’s crew.
Consequently, it was only after the multi‑agency meeting began at about 0945, that it became clear that AMSA had only taken charge of the rescue operation, which was then abandoned. At that meeting, NSW Maritime indicated to the Port Authority that it should assume control of the incident with which AMSA agreed. This resulted in further discussions until, at about 1020, the Port Authority agreed to assume control.
According to the Port Authority, it assumed control as it was obliged to assist NSW Maritime to manage incidents in state waters under the inter‑agency memorandum of understanding (MoU) previously described and considered itself more capable of managing the incident. This was not a correct interpretation of the MoU or a proper understanding of the Port Authority’s area of responsibility for this incident as defined in the NSW Plan and its PSOL.
While the Port Authority had previously consistently insisted that the MoU was the basis of its decision for assuming control, its submission did not refer to the MoU. Instead, it presented the jurisdictional argument above, which serves to reiterate that the Port Authority did not, and does not, have a proper understanding of its role and responsibilities for emergency response under the NSW Plan and PSOL.
The delay in the Port Authority assuming control in large part contributed to no agency formally controlling and coordinating the response until 1020. This compounded the complexity of managing the emergency, which had continued to worsen over the previous 5 hours.
Emergency management
After the Port Authority formally assumed control, the emergency continued for a further 2 days. The following section examines the management of the situation through to its conclusion.
Australian Maritime Safety Authority
As previously noted, when AMSA was notified of the emergency, Portland Bay was in Commonwealth waters in its area of responsibility under the National Plan.
Relevant procedures
As described in the National level section, AMSA had developed a comprehensive set of procedures and guidance for an optimal emergency response under national arrangements. Its Maritime Assistance Services (MAS) procedures were directly applicable to this incident. These procedures provided detailed guidance about the proportionate and reasonable response based on a 5‑level incident severity categorisation. While the levels were not consistent with the 3 levels defined by the Australasian Inter‑service Incident Management System (AIIMS), the guidance was adequate to initiate an appropriate response.
The National Plan highlighted that a timely response was critical and suggested over‑escalation and pre‑emptive or precautionary moves in the initial response as it was more effective to scale down than up.
The MAS procedures and incident severity matrix (Appendix B) categorised a machinery failure where multiple critical systems had failed with no redundancy and no prospect of recovering them as a level 4 (major) incident. Where all critical systems had failed without prospect of recovering them (dead ship), it was to be categorised as a level 5 (severe) incident. The matrix had the following guidance for level 4 and level 5 [in brackets] incidents:
probable tasking of nearest ETV [immediate tasking]
probable place of refuge request [request received]
probable request from impacted state(s) [request received]
probable deployment of AMSA maritime casualty officer – MCO [MCO deployed, if safe]
media coverage is expected [is occurring].
However, as previously noted, AMSA categorised the incident as level 3 (moderate severity). This meant that the ship’s propulsion failure had been assessed as affecting its safe navigation with a low likelihood of rectification within 6 hours and a moderate risk for environmental damage. Given that AMSA was notified that the ship’s main engine had failed and it could ground in 1.5 hours, its procedures required the incident to conservatively be assessed as level 5 but no less than level 4.
In any case, alerting and tasking the state’s ETV should have been a first response while seeking the nearest, available harbour tug(s) as ‘vessel(s) of opportunity’. Further, given the casualty was in Commonwealth waters, AMSA was obliged to immediately assess the situation, take necessary action/intervene as per the National Plan and its MAS procedures and, if it decided to hand control of managing the casualty to New South Wales, make a formal request to NSW Maritime’s MPC. None of these critical actions were taken, nor any preparations made to respond to a ‘place of refuge request’ as flagged by its procedures.
In submission to the draft of this report, AMSA stated that the failure [of the ship’s master and Port Kembla VTS] to make prompt notifications resulted in AMSA being unable to respond consistent with its responsibilities for 2.9 hours, after which the casualty remained in Commonwealth waters for ‘only 38 minutes’. It further stated that the response was effectively under New South Wales Government control since Port Kembla VTS was notified, the state agencies had initiated a response and were fully aware that the casualty would drift into the state’s waters.
According to AMSA, New South Wales agencies not seeking to transfer control to AMSA was ‘a strong indicator that they believed that continuity was important with the impending impacts upon their jurisdiction’. Once it was notified, AMSA stated that it supported the New South Wales response, including tasking and contracting assets, establishing a management team to coordinate support and intervened to direct the ship into Port Botany.
The ATSB acknowledges AMSA’s position, however, as discussed previously and above, it does not consider AMSA took adequate and timely action for the optimal management of this casualty given its central role as the manager of the National Plan with direct control of the key national arrangements, including towage assets. This contributed significantly to prolonging the emergency.
Emergency towage vessel activation
While AMSA’s initial focus was the SAR operation, it did task Bullara after becoming aware that the tug would not be hired to assist the ship. Bullara’s location and earlier preparation to deploy meant that it could join other tugs deployed to assist. However, the ETV, Svitzer Glenrock, was not tasked or alerted.
In submission to the draft report, AMSA stated that Bullara was the designated tug with alternate capability for the New South Wales region and met all conditions of the ETC contract, including appropriate towing gear and equipment. However, the contract did not refer to any alternate tug or Bullara, which did not meet all the contractual requirements, including its towing equipment which failed. Nor had Svitzer equipped or nominated it as the ETV for the New South Wales region.
The Port Authority asked AMSA’s liaison officer at 1230 on 4 July to activate the ETV but a communication breakdown within AMSA resulted in the request not being actioned. When the request was followed up more than 6 hours later, it took AMSA another hour to issue an ‘on task direction’ for the ETV at 1957. Since the ETV had not been alerted earlier, its crew then needed a couple of hours to prepare for deployment.
Consequently, the ETV deployed at 2230, about 15 hours after AMSA was first notified of the emergency. The passage to Bate Bay in bad weather then consumed another 15 hours. By the time it arrived on scene and connected a towline late on 5 July, it was deemed to be too late to conduct a safe tow into Port Botany that day, further prolonging the emergency.
In submission, AMSA argued that the Port Authority could have deployed Svitzer Glenrock under its harbour towage contract if it had deemed its deployment to be necessary. In addition, AMSA stated that the ETV was available to ‘private industry’ under commercial arrangements. However, this assertion does not consider the relevant terms of the ETC contract and the requirement that only AMSA could activate the ETV (as documented in the National Plan and MAS procedures). It is also inconsistent with the general understanding of other parties, including the Port Authority, NSW Maritime, United Salvage and Svitzer, about the tasking or release of the ETV.
Given that the heavy weather was always going to delay Svitzer Glenrock’s passage from Newcastle, the delay of more than 12 hours in tasking the ETV unnecessarily prolonged the emergency. The delay was largely the result of the ineffective implementation of the MAS procedures, which was also evident in AMSA’s subsequent actions, and its understanding that the ETV was readily available to other parties.
On 5 July, some 12 hours after the ETV was activated, AMSA upgraded the incident to severity level 5 as per the MAS procedures, documenting ‘machinery failure and immediate tasking of ETV’. However, the incident’s severity level and its potential consequences had been high since the emergency developed and not significantly changed in the preceding 24 hours. At no stage, including during the attempted tow, was the risk low enough to make the tasking of the ETV unnecessary.
Contributing factor
The Australian Maritime Safety Authority’s Maritime Assistance Services procedures to support the National Plan for Maritime Environmental Emergencies (National Plan) were not effectively implemented. Consequently, there was a 12‑hour delay in tasking the state’s nominated emergency towage vessel, Svitzer Glenrock, which significantly prolonged the emergency. (Safety issue)
Directions to enter Port Botany
A request for a place of refuge direction became increasingly likely as the emergency continued. Despite the planned tow away from the coast, there was no assurance that the ship’s propulsion would be restored. Given the ship’s general location, seeking refuge in Port Botany was always likely. This became almost certain at 1828 on 4 July when United Salvage asked the Port Authority’s incident controller (IC) to open the port for the ship to shelter as it was proving impossible to tow it clear of the coast. Shortly afterwards, when Bullara’s towline parted, United Salvage asked AMSA to have the port opened and, at 1945, submitted a formal ‘place of refuge’ request to the Maritime Emergency Response Commander (MERCOM).
Although the MAS procedures advised a place of refuge request was to be expected, AMSA had not prepared for a request or made a related assessment. Soon after 1900, when the IC followed up the earlier ETV request with the MERCOM, they also discussed the issue of directions under national and state legislation and concluded that the former would be required. However, the IC advised that as the port was closed, the ship could not be towed there until the weather improved. No action was taken to prepare for, or draft, directions then or after United Salvage’s request.
Consequently, when the IC requested the MERCOM to issue necessary directions on the morning of 5 July, they first discussed which parties would need to be issued the directions. The MAS procedures included guidance for issuing directions, including an assessment tool for decision‑making and a standard form. With no prior preparation, assessment and drafting of directions, which included discussions between AMSA divisions, took many hours before their issue late that afternoon.
The directions themselves (Appendix E) were brief and relatively straightforward and appeared not to be contentious as they allowed recipients (the master, shipowner, salvor and the Port Authority) to achieve their shared objective of providing safe refuge to the ship. In this context, the 7 hours taken to issue the directions that were central to resolving the emergency was considered to be excessive and indicative of an inefficient process.
In submission, AMSA stated that ‘a direction can only be issued when the delegate is satisfied that the conditions of the Protection of the Sea (Powers of Intervention) Act 1981 (POI Act) have been established’ and ‘whether a direction is simple or non‑contentious is of no relevance’. It noted that ‘the first consideration of the delegate is to determine (in this case) is whether pollution is likely, and then to consider (amongst other things) whether a direction is necessary and proportionate’. In this regard, AMSA highlighted section 10 of the POI Act (Appendix C) and the criteria that it required a delegate to consider.
On 5 July, when the direction was being considered, AMSA stated that the weather had abated and the Port Authority was planning to reopen ports. According to AMSA, substantial analysis and legal review was therefore required to determine if the direction could be issued based on being satisfied that oil or noxious substance was likely to escape from the ship and noting that the Port Authority had the authority to allow the ship to enter the port, leading to questions whether the direction was proportional and reasonably necessary. In addition, AMSA invited the ATSB to consider whether the POI Act was ‘fit for purpose to effectively address maritime casualty situations’.
In acknowledging AMSA’s perspective, the ATSB notes that the formal place of refuge request was submitted on 4 July during the continuing emergency when the ETV had not been tasked. Therefore, the requirements of the POI Act could have been reasonably and promptly assessed using the MAS procedures, place of refuge guidelines and other relevant guidance. The argument presented by AMSA and the time taken to issue the directions following the IC’s request when the ETV was en route suggests that it was not completely satisfied that the directions were necessary or proportional. In this case, concerns should have been raised in detail with the IC, particularly as AMSA had offered to issue the directions the previous day, which had been opposed by the IC due to port closure. The salvor’s request for refuge should also have been addressed in a timely manner.
Other factor that increased risk
The Australian Maritime Safety Authority’s process to issue directions was inefficient and resulted in excessive time to issue directions allowing Portland Bay to enter Port Botany as a place of refuge. While this delay did not further prolong the emergency, such delays increase risk in time‑critical situations. (Safety issue)
National Plan management
The National Plan’s principles included:
a single integrated response
comprehensive management
use of a risk‑managed approach
effective stakeholder engagement
integration of Australasian emergency management systems.
The first 2 of these principles underpinned optimal management of incidents through effective coordination of salvage, emergency towage and intervention matters. As AMSA has managed the National Plan since 1990, it has been central to managing any incident (either as the control agency or in a supporting role depending on incident location), particularly as it has had direct control of the key national arrangements comprising emergency towage capabilities (ETC), MERCOM and powers of intervention. Its responsibilities also included maintaining national contingency plans, managing the national response team, coordinating training and providing response equipment.
The scope of the plan included potential and actual pollution, environmental harm, casualties and salvage. As such, the MERCOM was expected to assume control of significant incidents and, if necessary, establish a casualty control unit to work with the IMT. In addition, the plan required a comprehensive response to any incident, regardless of how costs were attributed or recovered.
As previously detailed, there was delay in activating the ETV and using intervention powers under national legislation, which provided broad powers with effective mechanisms to take necessary action, including to prevent actual or potential pollution (Appendix C).
A key reason for the ineffective implementation of AMSA’s procedures and guidelines was probably because annual exercises had not been conducted. As emergencies are rare, these exercises, drills and training were intended to provide AMSA and state‑level agencies with regular opportunities to confirm that their respective response plans and procedures were effectively implemented. In addition, these exercises provided opportunities to practice effective coordination between jurisdictions and different parties and to adequately prepare for an emergency.
However, the last annual exercise before the incident was conducted in 2018 and AMSA advised that the COVID‑19 pandemic had prevented exercises during those 4 years. Notwithstanding this, desktop exercises during that time could have been used to achieve most objectives, other than physically exercising oil or chemical spill containment.
In submission to the draft report, AMSA advised that the National Plan Strategic Coordination Committee (NPSCC) made a risk‑based decision to not hold the annual exercises and established a reporting system to monitor National Plan capability and manage risks. It further stated that the NPSCC was responsible for overseeing the plan’s implementation and ensuring the effectiveness of its arrangements. In addition, AMSA noted its participation in 4 desktop exercises conducted by states in 2020 and 2021.
In acknowledging AMSA’s submission, the ATSB reiterates that, as the manager of the National Plan, AMSA was central to its ongoing management and the effectiveness of key arrangements by carrying out its many important functions. On the other hand, the NPSCC set the broad policy direction of the plan, oversaw its implementation and the effectiveness of its arrangements. In this oversight role, the NPSCC was reliant on AMSA effectively managing the plan, including conducting annual reviews on its behalf to inform it about the plan’s effectiveness. This was directly related to the management of the plan and key AMSA‑controlled arrangements, such as ETC, over a long period, which was clearly linked to the MAS procedures and their implementation that could only have benefited from suitable exercises. In this regard, participation in the state‑run desktop exercises, including with NSW Maritime, did not result in appropriate action and coordination during the response to this incident.
It should also be noted that a feature of the annual exercises before their suspension in 2019 was a focus on the response to pollution instead of its prevention through the effective management of a casualty, such as a disabled ship. Two of the 4 exercises conducted from 2015 to 2018 focused on pollution response and both exercises conducted after the incident had a similar focus.
Other drill and training records indicated that AMSA had not conducted any ETC contract compliance audits after 2016. However, since 2019, Svitzer tug crews had undertaken the 2‑day emergency towage training. The only detailed emergency towage training was associated with the level 1 capability ETV based in Queensland.
The AMSA staff directly involved with this incident, except the liaison officer, had relevant emergency management training. However, the liaison officer was a very experienced AMSA surveyor and former seafarer. It was not possible to determine whether relevant training for the liaison officer would have ensured the early activation of the ETV as other factors influenced its late activation and response coordination. Nevertheless, all AMSA staff with key roles and responsibilities should have been provided the required training.
Adequate management of the National Plan, including appropriate and regular exercises, would have better enabled the effective implementation of the MAS procedures.
Contributing factor
The Australian Maritime Safety Authority had not adequately managed the National Plan and annual exercises required to prepare for such incidents had not been conducted for 4 years before the incident. This probably resulted in the ineffective implementation of its Maritime Assistance Services procedures, the inefficient process for issuing directions and inadequate coordination of the incident with state authorities. (Safety issue)
Port Authority of New South Wales
The Port Authority’s involvement began before it assumed the combat agency role, including the period before and during the development of the emergency. As was the case for AMSA, a comprehensive set of plans, procedures, licenses and guidance covered the Port Authority’s responsibilities. Its incident controller had several specific responsibilities, including:
assuming control
assessing the emergency
conducting an initial briefing
advising NSW Maritime and AMSA
planning, implementing and reviewing the incident action plan.
While the Port Authority had assessed that it was safer for Portland Bay to put to sea due to the bad weather with advice that the ship remain ‘at safe distance (around 12 miles)’ from the coast, this was not complemented by VTS monitoring its position and status in the area adjacent to the port limits and VTS area limits. Effectively, it was relying solely on the master keeping clear of the coast and reporting any difficulties in doing so, including a breakdown.
As the master did not report when the ship broke down, it closed the coast unnoticed by VTS for 2 hours. Therefore, when the master did report, it was imperative for VTS to promptly notify AMSA and NSW Maritime. Instead, AMSA was notified after 45 minutes and NSW Maritime was not notified. Some internal notifications were made but this did not result in required external notifications as the Port Authority’s procedures were not effectively implemented.
Significantly, there was also extensive and unnecessary delay in the Port Authority assuming the combat agency role at 1020, about 2 hours after the ship entered New South Wales waters, towards which it had been drifting. Therefore, in the 3.5 hours following the master’s notification, no agency had assumed control of the response with little coordination between agencies. This compounded the impact of the master’s late reporting and opportunities to effectively mitigate risks in the first 5 hours after the ship became disabled were lost.
The NSW Plan, Port Safety Operating Licence (PSOL) and various procedures documented the requirements for the Port Authority to assume the combat agency role given the location and movement of Portland Bay. The basis provided by the Port Authority for not assuming control initially, mainly the inter‑agency MoU previously described, was incorrect. This fundamental misunderstanding of its documented responsibilities indicated that its procedures, plans and processes to comply with these responsibilities were not effectively implemented.
In submission to the draft report, the Port Authority argued that its roles and responsibilities under the state EMPLAN, NSW Plan and PSOL were essentially limited to responding to a spill, that this did not occur nor did a situation where a spill was imminent. Therefore, it claimed that its role as a combat agency under the NSW Plan was ‘not enlivened’ whereas the MERCOM, MPC and NSW Maritime had roles related to intervention and incident or emergency response. The Port Authority stated that it had no prevention obligations (pollution) under the National Plan and that ‘incidents’ in the emergency response requirements of the PSOL referred only to spills and was distinct from ‘emergencies’.
However, these claims are not an accurate or reasonable interpretation of the Port Authority’s roles and responsibilities under the PSOL, state EMPLAN and NSW Plan as previously detailed in this report. Further, the NSW Plan was a sub‑plan of both the state EMPLAN and the National Plan and suggesting that the Port Authority had little or no role under the National Plan indicates a poor understanding of the national emergency framework for maritime emergencies. Similarly, its interpretation of the purpose of the areas of responsibility assigned to either the Port Authority or NSW Maritime under the PSOL and NSW Plan (Figure 19) was incorrect. Further, its submission made no mention of the inter‑agency MoU that its incident controller had insisted was the basis of decisions at the time.
As the combat agency, the effectiveness of the Port Authority’s response depended on the success of the salvage operation, which completely relied on effective towage. Therefore, it was necessary to deploy the most capable tugs, including the ETV, in a timely manner. However, it did not adequately coordinate the response with the salvor, AMSA and NSW Maritime. The harbour tugs on scene or en route were not adequately equipped and the ETV was not activated by AMSA. Although the Port Authority requested its activation a couple of hours after assuming control, it only followed up on the request more than 6 hours later, most probably because the attempted tow had failed.
The late activation of the ETV, discussions related to directions for the ship to enter Port Botany, including its closure and reopening with AMSA, and the generally inadequate coordination indicate that the Port Authority had not effectively implemented its procedures to comply with the NSW Plan and PSOL with respect to incident and emergency response. The resultant sub‑optimal response prolonged the emergency.
Contributing factor
Port Authority of New South Wales procedures to comply with its Port Safety Operating Licence and the NSW Coastal Waters Marine Pollution Plan were not effectively implemented. This resulted in delays to the required notifications and incident response, which contributed to prolonging the emergency. (Safety issue)
Prolonged emergency
Factors, additional to those discussed above, that prolonged the emergency are discussed below.
Long exposure to stranding risk
The emergency unfolded over an extensive offshore area south of Sydney. However, it was the gale force onshore winds, rough seas and heavy swell that prevailed in the area which were the dominant factors in making the hazardous lee shore more dangerous. The longer the ship remained anchored in heavy weather, the greater the risks and the exposure to them.
Had the anchors not reduced Portland Bay’s rapid movement about one mile from the rocky lee shore (Figure 12, anchor position 1), it would have stranded there and almost certainly broken up resulting in the likely loss of life and oil pollution from the 950 tonnes of fuel oil and diesel oil on board. For most of the time when it was anchored in that location, a tug that could effectively relieve the load on the anchor cables was not secured to the ship. The anchors dragged slowly and the ship closed to within 0.7 of a mile of the shore before it could be towed away.
The attempt to address the risk of stranding by towing the ship 20 miles from the coast failed after 3 hours when the ship was 2.5 miles from the coast. Once again, the master resorted to deploying the anchors about one mile off the shore. Although there was a comparatively less dangerous lee shore near anchor position 2, the ship remained there for an extended period, including 2 nights. The risk of stranding, even with a tug connected, was high on the first night due to the weather and the ship dragged its anchors to less than one mile off the shore. Securing the ETV for the second night at anchor there reduced the risk.
However, the disabled ship was still in an exposed location with no certainty that the weather would continue improving or that the anchors and/or their cables would not fail. Abandoning the ship in rough weather presented high risks to the crew. These risks were higher at night because a rescue in darkness is much more difficult, with restrictions on available resources and rescue methods. Essentially, the risks were not reduced to an acceptable level until the ship was sheltered in Port Botany.
Contributing factor
Portland Bay was exposed to a high risk of stranding, with its anchors deployed for prolonged periods about one mile from a dangerous lee shore in 2 separate locations.
Unsuccessful blower repairs
As previously discussed, the failure of auxiliary blower number 2 significantly reduced normal airflow to the main engine for fuel combustion, which was the principal cause of the substantial reduction in propulsive power. Therefore, repairing the blower was the immediate priority for the ship’s engineers after the ship was anchored on the morning of 4 July.
The engineers believed that the blower’s electric motor had also failed due to a burning smell and the smoke observed. In repairing the blower, they also tried removing the suspect electric motor but were unable to as its belt drive pulley was difficult to remove. Consequently, the engineers abandoned the repairs without testing the motor and deemed the blower to be inoperable.
The blower remained out of service for the duration of the incident and the propulsion issues continued to manifest over the next 2 days with the engine either operating at low speeds for short periods or not starting. The unreliable engine was a significant factor that prolonged the emergency because a tow was almost completely reliant on the capability of the tugs.
However, when the electric motor was subsequently overhauled ashore in Port Botany, it was found to be operational. Therefore, had the motor been tested on board, the effectively ‘dead ship’ situation over the 2‑day emergency could have been avoided. Had this been done and engine performance improved, it would have mitigated some risks and thus reduced the duration and seriousness of the emergency.
Contributing factor
Having assessed that the failed blower’s electric motor was also unserviceable, the ship’s engineers were unable to remove it and abandoned the repairs without testing it. Had the motor been tested, it would have been found operational and the blower returned to service to improve engine performance and reduce the seriousness and duration of the emergency.
Tug capabilities
During the initial response, the tugs SL Diamantina, SL Martinique and Bullara deployed from Sydney. Despite the best efforts of their crew, the assistance provided by the tugs had limited success in the prevailing weather conditions due to their limited ocean towing capability.
As previously described, the capability and towing equipment of these tugs was generally similar and appropriate for the harbour towage services that they routinely provided. However, on 4 July, the particular circumstances applicable to each tug and the operating conditions resulted in different capabilities to perform the required tasks.
SL Diamantina’s aft towing winch was not operational, making it unsuitable for emergency towage. Its attempts to push on the ship’s hull, as suggested by United Salvage, led to significant collisions and had to be abandoned. Multiple attempts to secure the soft towline from its forward winch then failed. Consequently, the tug was not able to provide any useful assistance.
In submission to the draft of this report, United Salvage acknowledged that SL Diamantina’s towing limitation was known but pointed out that it was a towing asset that could push. However, the salvor also noted that Portland Bay’s pitching resulted in the attempted pushing not remaining an option and claimed that connecting the towline successfully stopped its movement towards the shore.
On the other hand, Portland Bay’s master submitted that, in addition to the tug’s efforts being ‘completely ineffective’, it was pushing near the midships area where there were no designated tug pushing marks and repeatedly colliding with the ship’s hull. The master, therefore, reported ordering those ‘improper and potentially dangerous actions’ to be stopped. The master stated that adjusting the starboard anchor cable at about 1300 stopped the anchors dragging, which had continued to drag after anchoring at 0905 (including when the towline was connected) and provided recorded data in support (Figure 22).
In submission, Pacific Basin stated that the master had advised that the tug master should have permitted securing the towline to a bollard instead of requiring it connected to the ship’s mooring lines, which was not an effective arrangement. It acknowledged, however, that the tug’s aft winch being unavailable may have been the reason why its master required that arrangement.
SL Martinique arrived on scene subsequently with additional towing equipment, including a towing stretcher. Bullara had similar capability and towing equipment. Both tugs then attempted to tow the dead ship clear of the coast under United Salvage guidance but were unsuccessful as this was beyond their combined capabilities in the weather conditions with the towing lines deployed.
Bullara and SL Martinique each had an effective bollard pull (BP) of about 55 tonnes. Together, this could provide a BP of about 110 t, which was 85% of the AMSA‑calculated 130 t required to tow the dead ship (approximately 15,500 tonnes). In addition to the BP, the length of a towline significantly affects towing capability. A sufficiently long towline that has a normal towing load forms a distinct catenary, which allows it to absorb shock loads. Based on formulae provided in the IMO ocean towing guidelines, these 55 t BP tugs required approximately 670 m towlines. However, Bullara’s 275 m towing wire with a 50 m towing stretcher provided a 325 m towline, which was about 50% of the minimum required.
Essentially, towing the dead ship into the rough weather exceeded the combined towing capabilities of Bullara and SL Martinique with the towlines deployed. Consequently, the tow made little progress away from the coast and Bullara’s relatively short towline, with no Veethane protective sleeves to prevent chafing, parted.
In comparison, Svitzer Glenrock with its 85 t BP and effectively 900 m towline with Veethane protective sleeves was far better suited for the tow with the assistance of one or more other tugs. The ETV was a superior tug that met or exceeded level 2 ETC requirements.
In conclusion, SL Diamantina, SL Martinique and Bullara performed to their respective capabilities and limitations (including towing equipment) as ‘vessels of opportunity’. The latter 2 tugs, with their temporary towing equipment and lines, were capable of relieving load on the ship’s anchor cables. However, effectively towing the ship in the heavy weather with the towing lines that they deployed was not a realistic or achievable expectation. Therefore, as previously discussed, timely deployment of the ETV was needed to manage the emergency optimally and effectively.
Contributing factor
SL Diamantina, the harbour tug that arrived about one hour after the ship anchored, was not capable of providing any useful assistance in the rough weather. About 6 hours later, SL Martinique and Bullara, harbour tugs temporarily equipped with additional towing equipment, began an attempt to tow the ship clear of the coast, but this was beyond their combined capabilities in the weather conditions with the towing lines deployed.
Salvage operation
Under the Salvage Convention, United Salvage was dutybound to Pacific Basin. Its duties as a salvor included carrying out the salvage operation with due care, preventing and/or minimising pollution, seeking assistance from other salvors if required and accepting their intervention (if requested by Pacific Basin or the master).
In submission to the draft of this report, United Salvage advised that it mobilised with the intent of providing its ‘best endeavours to assist the casualty with available assets’ and ‘continued these endeavours in mobilising any asset available either under the LOF agreement or AMSA tasking’. United Salvage also reported that when it requested Svitzer for Bullara while mobilising Engage Towage tugs, Svitzer did not make it available. It pointed out that Bullara was utilised later until its towline parted, after which United Salvage requested mobilisation of the ETV, Svitzer Glenrock, and asked if any other Svitzer tugs in Port Botany could assist.
While United Salvage’s submission captures events during the salvage operation in general, the evidence indicates that it could and should have flagged crucial matters that it was aware of with involved parties to avoid unnecessary difficulties and confusion. This included the limitations of SL Diamantina previously discussed and also that it was critical that at least one other tug (Bullara) be mobilised to supplement SL Martinique.
Soon after Portland Bay’s master agreed to the LOF salvage agreement, the ship’s agent, Monson, decided (without Pacific Basin’s authorisation) that it was not necessary to hire Bullara. However, as AMSA had determined that SL Martinique would not be able to hold the ship (without its anchors deployed), it tasked Bullara. Meanwhile, Pacific Basin was expecting United Salvage to take whatever measures feasible and reasonable in the prevailing circumstances, including mobilising whatever equipment or device or labours, to salve the vessel. Therefore, it reasonably believed that suitable and capable tugs (potentially including the ETV) would be deployed. If this was not the case, then it was reasonable that the ship’s master and Pacific Basin were informed accordingly.
It is of note that while Bullara was en route at 1230 on 4 July, AMSA reported being advised by United Salvage that it intended to only use SL Martinique to tow and that there was no requirement for Bullara. However, at 1410, when Bullara had arrived on scene, AMSA offered its use to United Salvage, which it accepted.
Subsequently, AMSA deemed Bullara to be operating under the LOF salvage agreement but Svitzer did not accept this proposition. It should be noted that Svitzer remained prepared to offer its tugs to Pacific Basin under a towage contract or to AMSA under the ETC contract, and this was its prerogative. Given that Bullara was initially to be hired by Pacific Basin, it was reasonable for it to expect being made aware of the option of securing a Svitzer tug(s) to assist the salvage. Pacific Basin’s sole interest was the salving of the ship and its crew with no or minimal damage to the ship and environment. Notwithstanding the ‘no cure – no pay’ principle of salvage, any shipowner or manager justifiably will expect a high degree of assurance for the ‘cure’ aspect and the degree of success from a dedicated salvage provider offering professional services under LOF terms.
Importantly, while both Engage Towage (with United Salvage) and Svitzer provided tugs, only the former were part of the salvage agreement and award, if successful. As noted, Svitzer wanted the security (commercial) of an arrangement in place before deploying its tug(s) and also assuring the safety of the tug crew before deployment. Svitzer’s sizable tug fleet in New South Wales, including the state’s ETV, meant that it was well‑equipped from a towage capability perspective.
On the other hand, United Salvage did not own, operate or directly control any towage vessels and was reliant on procuring these from their operators if and when they made them available (including AMSA‑contracted or tasked vessels). This severely limited United Salvage’s ability to provide/perform salvage services, particularly as the emergency towage available was essentially the same as the minimum ETC under the National Plan (detailed in the section titled Emergency towage availability). While United Salvage advised providing its best endeavours to assist with ‘available assets’ either under LOF terms or AMSA tasking, this qualification (available assets) was critical.[171]
Had United Salvage clearly flagged its limitation with the master, Pacific Basin and involved agencies, they could have made their own assessments, although AMSA, in particular, should have known about this limitation. These assessments could have informed everyone involved if the intended tow of the ship to sea was realistic in those weather conditions. It was only after the tow proved difficult and the ship was approaching Sydney that shelter there was requested. Soon after, when Bullara’s towline parted, the significant risk of not tasking Svitzer Glenrock was realised.
The success of the salvage operation would determine whether the incident management team achieved its objectives but the operation also had to be consistent with the team’s plan. However, the salvor’s actions were not the only factors which influenced the incident’s management and, on balance, by themselves probably did not further prolong the emergency. It is also recognised that salvage inherently involves risk in a dynamic environment. While taking calculated risks are part of a salvage operation, unnecessary risks must be avoided. Careful and continuous monitoring of the operation with ongoing risk assessments and re‑evaluation, particularly by the salvor and incident controller, is crucial.
Notwithstanding United Salvage’s inherent limitations that put certain matters beyond its control, providing the master, Pacific Basin and the incident controller explicit clarity about the limitations would have assisted in better managing the incident and salvage operation. In any case, these limitations made it very difficult to fully and properly carry out a salvor’s duties and obligations under the salvage agreement and Salvage Convention.
Other factor that increased risk
United Salvage was severely limited in its ability to provide the required salvage services as it did not own, operate or directly control any towage vessels for which it relied on towage providers. This limitation was not made clearly known to Portland Bay’s master, owners or managers or involved authorities to allow them to properly assess whether the most suitable towage vessels, including the emergency towage vessel, had also been promptly deployed for salvage and emergency response. (Safety issue)
Response coordination
The National Plan required single, integrated and comprehensive response arrangements regardless of how costs were attributed. Effective coordination was central to an optimal response, including the application of the National Maritime Emergency Response Arrangements (NMERA) elements of ETC, powers of intervention and MERCOM.
Notwithstanding the master’s late notification, there were comprehensive plans, procedures and guidance to enable the Port Authority, NSW Maritime and AMSA to manage the response and its coordination. Had these largely been followed, the Port Authority should have promptly notified AMSA (by about 0700 on 4 July) which should then have followed its MAS procedures (including alerting/tasking the ETV, expecting a refuge request and engaging with NSW Maritime). Given the very serious emergency, it was crucial that a control agency take charge as soon as possible and coordinate the required response. While AMSA initiated the rescue attempt, it did not inform NSW Maritime or the Port Authority that this was its only focus (this created confusion about emergency towage planning).
However, instead of a quick response to manage the casualty, there were unnecessary delays until the Port Authority assumed control at 1020. This resulted in sub‑optimal coordination of the critical elements of emergency towage, salvage and refuge despite the AMSA liaison officer in the incident management team and the NSW Maritime liaison officer in the AMSA Response Centre (ARC). The most significant impact was the late activation of the ETV. The NSW Maritime liaison officer recalled discussions in the ARC about the ETV but not their details. The liaison officer also recalled that the issue of directions took a long time with AMSA’s legal team but did not know if a place of refuge request was in fact submitted (the salvor submitted it at 1945 on 4 July).
As previously discussed, inadequate coordination was an underlying feature of the response that prolonged the emergency for more than 2 days, specifically including:
the late emergency notification to AMSA delayed its rescue effort and probably resulted in the lack of coordination of the rescue effort with the Port Authority’s response and the late establishment of AMSA’s incident management team with unclear objectives
when informally advised of the incident, NSW Maritime contacted AMSA for information and found it was not aware but did not follow up information until some 45 minutes later
the delay in the Port Authority assuming control meant that no agency was coordinating the response in the first 3.5 hours
late activation of the ETV, resulting in it deploying more than 15 hours after the master reported the emergency, which significantly impacted the salvage operation
delays in issuing of directions to allow the ship to enter Port Botany for shelter.
In addition to the actions of the Port Authority, NSW Maritime and AMSA in their respective roles as the combat (control) agency and support agencies as previously described, their submissions to the draft of this report detailed their understanding of their roles and responsibilities. However, none showed a proper understanding of their responsibilities or an adequate understanding of the responsibilities of the others. The evidence indicates the following issues:
The Port Authority had a poor and incorrect understanding of its responsibilities for emergency response, casualty management and combat (control) agency role as required by its Port Safety Operating Licence and the NSW Plan, including as a sub‑plan of the National Plan.
NSW Maritime, as the statutory agency responsible for ensuring that New South Wales was prepared to respond to an incident in accordance with the NSW Plan, had not effectively met this obligation.
As the manager of the National Plan with control of the key elements of NMERA, AMSA did not have the required understanding of its central role in any emergency response, regardless of location.
Collectively, these underlying issues significantly contributed to the inadequate coordination of the critical emergency response elements comprising emergency towage, salvage and refuge required for a single, integrated and comprehensive response.
Contributing factor
The Port Authority of New South Wales did not have a proper and correct understanding of its responsibilities for emergency response under its operating licence and relevant state plans. This contributed to the inadequate coordination of emergency towage, salvage and refuge, which were critical for the single, integrated and comprehensive response required and significantly prolonged the emergency. (Safety issue)
Contributing factor
Transport for NSW (NSW Maritime), as the statutory agency responsible for ensuring that New South Wales was prepared to respond to an incident in accordance with the state’s plan that it maintained, had not effectively met this obligation. This resulted in the long delay in New South Wales assuming control of the incident and contributed to the inadequate coordination of the emergency response required for a single, integrated and comprehensive response and significantly prolonged the emergency. (Safety issue)
Contributing factor
The Australian Maritime Safety Authority, with direct control of key national emergency response arrangements, did not have the required understanding of its central role in any response, regardless of location. Consequently, its support to, and coordination with, the control agency in relation to emergency towage, salvage and refuge was inadequate, inconsistent with National Plan principles of a single, integrated and comprehensive response and significantly prolonged the emergency. (Safety issue)
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the propulsion failure and near stranding of Portland Bay on the coast 22 km south of Port Botany (Sydney), New South Wales, on 4 July 2022.
Contributing factors
After departing Port Kembla in adverse weather on 3 July 2022, Portland Bay’s master steamed slowly or drifted about 12 miles off the coast instead of safely clearing it in accordance with the ship’s safety management system procedures.
Operating the main engine at low speed while the ship was rolling and pitching heavily exacerbated engine load fluctuations due to turbocharger surge and non‑return flap hammering. Engine performance was further degraded by a leaky fuel injector, poor combustion and excessive cylinder lubrication, which resulted in sludge and deposits accumulating in the engine scavenge spaces, blow by and sticky piston rings.
The main engine auxiliary blower number 2 impeller bearings failed in the early hours of 4 July. This was most probably due to prolonged operation with an unbalanced impeller and oversized bearing housing, aggravated by varying engine load due to the ship's rolling and pitching.
The failure of auxiliary blower number 2 substantially reduced the normal airflow to the engine. In addition, some air was recirculating to the blower inlet through a distorted turbocharger delivery non‑return flap. The resulting low airflow limited the engine speed to 42 rpm (dead slow ahead setting) and significantly reduced the propulsive power available.
The significant loss of Portland Bay’s propulsive power in the prevailing gale force winds, very rough seas and heavy swell effectively disabled the ship and resulted in it drifting towards the lee shore.
Portland Bay’s manager, Pacific Basin Shipping, did not provide the master advice about notifying authorities as per the ship’s safety management system emergency procedures, instead focusing on the engineering matters. This probably led to the master delaying the notification and the request for tug assistance. (Safety issue)
Portland Bay’s master notified Port Kembla vessel traffic service that the main engine had failed and requested tug assistance about 2 hours after the ship was disabled. This delay significantly reduced the time available to Australian authorities to respond and for tugs to assist the ship in time to avoid a stranding.
Port Kembla vessel traffic service delayed notifying the Australian Maritime Safety Authority (AMSA) about the incident for 45 minutes. This delay reduced the time available to AMSA to initiate and coordinate an emergency response.
SL Diamantina, the harbour tug that arrived about one hour after the ship anchored, was not capable of providing any useful assistance in the rough weather. About 6 hours later, SL Martinique and Bullara, harbour tugs temporarily equipped with additional towing equipment, began an attempt to tow the ship clear of the coast, but this was beyond their combined capabilities in the weather conditions with the towing lines deployed.
The Australian Maritime Safety Authority’s Maritime Assistance Services procedures to support the National Plan for Maritime Environmental Emergencies (National Plan) were not effectively implemented. Consequently, there was a 12‑hour delay in tasking the state’s nominated emergency towage vessel, Svitzer Glenrock, which significantly prolonged the emergency. (Safety issue)
Portland Bay was exposed to a high risk of stranding, with its anchors deployed for prolonged periods about one mile from a dangerous lee shore in 2 separate locations.
Having assessed that the failed blower’s electric motor was also unserviceable, the ship’s engineers were unable to remove it and abandoned the repairs without testing it. Had the motor been tested, it would have been found operational and the blower returned to service to improve engine performance and reduce the seriousness and duration of the emergency.
Port Authority of New South Wales procedures to comply with its Port Safety Operating Licence and the NSW Coastal Waters Marine Pollution Plan were not effectively implemented. This resulted in delays to the required notifications and incident response, which contributed to prolonging the emergency. (Safety issue)
The Port Authority of New South Wales did not have a proper and correct understanding of its responsibilities for emergency response under its operating licence and relevant state plans. This contributed to the inadequate coordination of emergency towage, salvage and refuge, which were critical for the single, integrated and comprehensive response required and significantly prolonged the emergency. (Safety issue)
Transport for NSW (NSW Maritime), as the statutory agency responsible for ensuring that New South Wales was prepared to respond to an incident in accordance with the state’s plan that it maintained, had not effectively met this obligation. This resulted in the long delay in New South Wales assuming control of the incident and contributed to the inadequate coordination of the emergency response required for a single, integrated and comprehensive response and significantly prolonged the emergency. (Safety issue)
The Australian Maritime Safety Authority, with direct control of key national emergency response arrangements, did not have the required understanding of its central role in any response, regardless of location. Consequently, its support to, and coordination with, the control agency in relation to emergency towage, salvage and refuge was inadequate, inconsistent with National Plan principles of a single, integrated and comprehensive response and significantly prolonged the emergency. (Safety issue)
The Australian Maritime Safety Authority had not adequately managed the National Plan and annual exercises required to prepare for such incidents had not been conducted for 4 years before the incident. This probably resulted in the ineffective implementation of its Maritime Assistance Services procedures, the inefficient process for issuing directions and inadequate coordination of the incident with state authorities. (Safety issue)
Other factors that increased risk
United Salvage was severely limited in its ability to provide the required salvage services as it did not own, operate or directly control any towage vessels for which it relied on towage providers. This limitation was not made clearly known to Portland Bay’s master, owners or managers or involved authorities to allow them to properly assess whether the most suitable towage vessels, including the emergency towage vessel, had also been promptly deployed for salvage and emergency response. (Safety issue)
The Australian Maritime Safety Authority’s process to issue directions was inefficient and resulted in excessive time to issue directions allowing Portland Bay to enter Port Botany as a place of refuge. While this delay did not further prolong the emergency, such delays increase risk in time‑critical situations. (Safety issue)
Other findings
Portland Bay's emergency anchoring prevented a catastrophic stranding on the rocky shore in heavy weather (anchoring equipment is not designed to hold a ship in rough weather).
The attempt to rescue Portland Bay's crew by helicopter in case it stranded was appropriate, as was its risk‑assessed suspension after the ship’s anchors reduced the risk of stranding.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the marine industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description:Portland Bay’s manager, Pacific Basin Shipping, did not provide the master advice about notifying authorities as per the ship’s safety management system emergency procedures, instead focusing on the engineering matters. This probably led to the master delaying the notification and the request for tug assistance.
Safety issue description: The Australian Maritime Safety Authority’s Maritime Assistance Services procedures to support the National Plan for Maritime Environmental Emergencies (National Plan) were not effectively implemented. Consequently, there was a 12‑hour delay in tasking the state’s nominated emergency towage vessel, Svitzer Glenrock, which significantly prolonged the emergency.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Australian Maritime Safety Authority (AMSA) takes further safety action to address this safety issue in conjunction with action to address the other safety issues addressed to AMSA in this report.
Safety issue description: Port Authority of New South Wales procedures to comply with its Port Safety Operating Licence and the NSW Coastal Waters Marine Pollution Plan were not effectively implemented. This resulted in delays to the required notifications and incident response, which contributed to prolonging the emergency.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Port Authority of New South Wales takes safety action to adequately address this safety issue.
Emergency response coordination (Port Authority of NSW)
Safety issue description: The Port Authority of New South Wales did not have a proper and correct understanding of its responsibilities for emergency response under its operating licence and relevant state plans. This contributed to the inadequate coordination of emergency towage, salvage and refuge, which were critical for the single, integrated and comprehensive response required and significantly prolonged the emergency.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Port Authority of New South Wales takes safety action to adequately address this safety issue.
Safety issue description: Transport for NSW (NSW Maritime), as the statutory agency responsible for ensuring that New South Wales was prepared to respond to an incident in accordance with the state’s plan that it maintained, had not effectively met this obligation. This resulted in the long delay in New South Wales assuming control of the incident and contributed to the inadequate coordination of the emergency response required for a single, integrated and comprehensive response and significantly prolonged the emergency.
Safety recommendation description: The Australian Transport Safety Bureau recommends that Transport for NSW (NSW Maritime) takes safety action to adequately address this safety issue and ensure that New South Wales is prepared to effectively respond to an incident in accordance with the state’s plan.
Safety issue description: The Australian Maritime Safety Authority, with direct control of key national emergency response arrangements, did not have the required understanding of its central role in any response, regardless of location. Consequently, its support to, and coordination with, the control agency in relation to emergency towage, salvage and refuge was inadequate, inconsistent with National Plan principles of a single, integrated and comprehensive response and significantly prolonged the emergency.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Australian Maritime Safety Authority (AMSA) completes the safety action proposed to address this safety issue in conjunction with action to address the other safety issues addressed to AMSA in this report.
Safety issue description: The Australian Maritime Safety Authority had not adequately managed the National Plan and annual exercises required to prepare for such incidents had not been conducted for 4 years before the incident. This probably resulted in the ineffective implementation of its Maritime Assistance Services procedures, the inefficient process for issuing directions and inadequate coordination of the incident with state authorities.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Australian Maritime Safety Authority (AMSA) progresses safety action to address this safety issue in conjunction with action to address the other safety issues addressed to AMSA in this report.
Safety issue description: United Salvage was severely limited in its ability to provide the required salvage services as it did not own, operate or directly control any towage vessels for which it relied on towage providers. This limitation was not made clearly known to Portland Bay’s master, owners or managers or involved authorities to allow them to properly assess whether the most suitable towage vessels, including the emergency towage vessel, had also been promptly deployed for salvage and emergency response.
Safety recommendation description: The Australian Transport Safety Bureau recommends that United Salvage takes safety action to address this safety issue by ensuring that its capabilities and limitations to provide professional salvage services are made clearly known to the master, owners and managers of the ship to be salved under a salvage agreement.
Safety issue description: The Australian Maritime Safety Authority’s process to issue directions was inefficient and resulted in excessive time to issue directions allowing Portland Bay to enter Port Botany as a place of refuge. While this delay did not further prolong the emergency, such delays increase risk in time‑critical situations.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Australian Maritime Safety Authority (AMSA) takes safety action to adequately address this safety issue.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Svitzer Australia
Svitzer Australia (Svitzer) identified that the shorter length of the towing wire of its tug Bullara while towing Portland Bay on 4 July 2022 contributed to the wire’s failure. Bullara was a sister vessel of Svitzer’s Queensland‑based emergency towage vessels, Beltana and Clontarf, which had different towing arrangements (specifically, longer length and diameter of the towing wire on the aft towing winch). Therefore, as proactive safety action, Svitzer has fitted Bullara with new towing equipment that is aligned to the tug’s bollard pull and is similar to its sister vessels.
Glossary
ADF
Australian Defence Force
ADV
Australian defence vessel
AIIMS
Australasian Inter‑service Incident Management System
AIS
Automatic Identification System
AMSA
Australian Maritime Safety Authority
AMSG
Australian Maritime Services Group
ARC
Australian Maritime Safety Authority Response Centre
BIMCO
Baltic and International Maritime Council
BL
Breaking load
BoM
Australian Bureau of Meteorology
BP
Bollard pull
Class NK
Nippon Kaiji Kyokai
COLREGs
The International Regulations for Preventing Collisions at Sea, 1972, as amended
COO
Chief Operating Officer
DPA
Designated person ashore
ECDIS
Electronic chart display and information system
EMPLAN
New South Wales State Emergency Management Plan
ETA
Estimated time of arrival
ETC
Emergency towage capability
ETV
Emergency towage vessel
FRNSW
Fire and Rescue New South Wales
GMDSS
Global Maritime Distress and Safety System
HNS
Hazardous and noxious substance
IACS
International Association of Classification Societies
IAP
Incident action plan
IC
Incident controller
ICS
International Chamber of Shipping
IGA
Inter‑Governmental Agreement on the National Maritime Emergency Response Arrangements
IMO
International Maritime Organization
IMT
Incident management team
ISM
International Management Code for the Safe Operation of Ships and for Pollution Prevention, 1995, as amended
ISU
International Salvage Union
JRCC
Joint Rescue Coordination Centre
LO
Lubricating oil
LOF
Lloyd’s open form of salvage agreement
MAC
New South Wales Police Marine Area Command
MAICT
Multi‑agency incident control team
MAS
Maritime Assistance Services
MBL
Minimum breaking load
MCCU
Maritime casualty control unit
MCIMT
Maritime casualty incident management team
MCO
Maritime casualty officer
MERCOM
Maritime emergency response commander
MPC
Marine Pollution Controller
National Plan
National Plan for Maritime Environmental Emergencies
NMERA
National Maritime Emergency Response Arrangements
NPSCC
The National Plan Strategic Coordination Committee
NSWFB
New South Wales Fire Brigades
NUC
Not under command
OCIMF
Oil Companies International Marine Forum
P&I
Protection and indemnity
Port Authority
Port Authority of New South Wales
PMS
Planned maintenance system
PSOL
Port safety operating licence
RCC
Rescue Coordination Centre
RFS
New South Wales Rural Fire Service
RPM
Revolutions per minute
SAR
Search and rescue
SCOPIC
Special Compensation P&I Club
SERM Act
State Emergency and Rescue Management Act 1989 (NSW)
SMS
Safety management system
SOLAS
The International Convention for the Safety of Life at Sea, 1974, as amended
TOWHIRE
The BIMCO TOWHIRE 2021 ocean towage agreement
UMS
Unattended machinery spaces
VDR
Voyage data recorder
VHF
Very high frequency (radio)
VTS
Vessel traffic service
WHO
World Health Organization
Sources and submissions
Sources of information
The sources of information during the investigation included:
Portland Bay’s master and chief engineer
Pacific Basin Shipping, Hong Kong (Portland Bay’s manager)
recorded data from the ship’s voyage data recorder
MAN PrimeServ, the ship’s main engine manufacturer’s service department
Monson Agencies Australia, the ship’s local agent
Australian Maritime Safety Authority
Transport for NSW (NSW Maritime)
Port Authority of New South Wales
United Salvage
Engage Marine, the parent company of Engage Towage
Svitzer Australia
Nippon Kaiji Kyokai (Class NK)
Bureau of Meteorology.
References
Adsteam Marine. (2002, June 24). Submission to the Productivity Commission inquiry into Harbour Towage.
Australian Maritime Safety Authority Act 1990 (Cth)
Australian Maritime Safety Authority. (2012, October). Report on the 2011/12 Review of the National Plan to Combat Pollution of the Sea by Oil and Other Hazardous and Noxious Substances and the National Maritime Emergency Response Arrangements, AMSA 92 (11/12), Canberra, Australia.
Australian Maritime Safety Authority. (2015, November). National Maritime Places of Refuge Risk Assessment Guidance as endorsed by the National Plan Strategic Co‑ordination Committee, ref. NP‑GUI‑018, AMSA 485 (12/21) Canberra, Australia.
Australian Maritime Safety Authority. (2018, 27 April). National Maritime Casualty Management Guidance, Canberra, Australia.
Australian Maritime Safety Authority. (2020). National Plan for Environmental Emergencies, Canberra, Australia.
Australian Maritime Safety Authority. (2021, January). Maritime Assistance Services Standard Operating Procedures, MAS SOP 01/2021, Canberra, Australia.
Centre of Documentation, Research and Experimentation on Accidental Water Pollution (Cedre), Information Bulletin #43 September 2022, Bulletin‑43‑EN.pdf, accessed 4 July 2024.
Department of the House of Representatives Standing Committee on Transport and Regional Services. (2004, June). Ship Salvage; Inquiry into Maritime Salvage in Australian Waters, Parliament of Australia, Canberra.
Det Norske Veritas, Assessment of the Risk of Pollution from marine Oil Spills in Australian Ports and Waters, Prepared for AMSA, 14 December 2021.
International Association of Classification Societies. (2007). Requirements concerning Mooring, Anchoring and Towing, IACS Req. A1.1 ‑ Design of the anchoring equipment.
International Chamber of Shipping and Oil Companies International Marine Forum. (2020). Peril at Sea and Salvage: A Guide for Masters, 6th Ed. Oil Companies International Marine Forum (OCIMF).
International Maritime Organization. (1972). International Regulations for Preventing Collisions at Sea as amended (COLREGs), IMO, London. Available at www.imo.org.
International Maritime Organization. (1974). The International Convention for the Safety of Life at Sea (SOLAS).
International Maritime Organization. (1989). International Convention on Salvage, IMO, London.
International Maritime Organization. (1995). International Management Code for the Safe Operation of Ships and for Pollution Prevention (ISM Code) as amended, IMO, London.
International Maritime Organization. (1998, December). Guidelines for Safe Ocean Towing, MSC/Circ.884.
International Maritime Organization. (2004, 5 March). Guidelines on Places of Refuge for Ships in Need of Assistance, A 23/Res.949 (revoked by revised guidelines A 33/Res.1184 on 17 January 2024, IMO).
International Maritime Organization. (2004,February). Maritime Assistance Services (MAS), A 23/Res.950.
International Maritime Organization. (2007, 19 October). Guidelines on the Control of Ships in an Emergency, MSC.1/Circ.1251.
New South Wales Fire Brigades, Maritime Authority of New South Wales, Newcastle Port Corporation, Port Kembla Port Corporation and Sydney Ports Corporation. (2010, October). Memorandum of Understanding in Relation to Hazardous Materials Incidents on Inland and State Waters.
Newcastle Port Corporation (Trading as Port Authority of New South Wales). (2019, January). Port Safety Operating Licence 2019–2024, issued under the Ports and Maritime Administration Act 1995 (New South Wales).
Newcastle Port Corporation (Trading as Port Authority of New South Wales). (2020, 22 May). Towage Licence, Port of Botany Bay (unrestricted), Ver. 1.0.
Ports and Maritime Administration Act 1995 (New South Wales)
Port Authority of New South Wales. (2020, 16 January). Emergency Response Checklist – First Strike Oil Spill (Sydney & Port Botany), Rev. 7.
Port Authority of New South Wales. (2021, 18 October). Marine Pollution Emergency Checklist, VTS Operations Procedures 5.2.09, Rev. 1.
Port Authority of New South Wales. (2021, 18 October). VTS Operations Procedure 3.2.2 – 01, Marine Pollution.
Port Authority of New South Wales. (2021, 19 October). Sydney Harbour and Port Botany Marine Emergency Response Plan, Rev. 5.
Port Authority of New South Wales. (2021, 19 October). VTS Operations Procedure 3.2.2 – 01, Marine Pollution.
Port Authority of New South Wales. (2021, 2 November). Incident Management Procedure.
Port Authority of New South Wales. (2021, 30 November). Port Kembla Marine Oil & Chemical Spill Contingency Plan; A Sub‑plan of the Illawarra Emergency Management Plan, Rev. 12.
Port Authority of New South Wales. (2021, 8 December). Port Kembla Emergency Response Plan, Rev. 2.
Port Authority of New South Wales. (2022, 10 May). Pollution Response Plan Botany, Ver. 3.
Port Authority of New South Wales. (2022, 10 May). Pollution Response Plan Sydney, Ver. 3.
Port Authority of New South Wales. (2022). Harbour Master Directions, Port Kembla, August 2022.
Protection of the Sea (Civil Liability) Act 1981 (Cth)
Protection of the Sea (Prevention of Pollution from Ships) Act 1983 (Cth)
State Emergency and Rescue Management Act 1989, No 165 (NSW)
State of New South Wales Premier’s Department. (2018, December). New South Wales State Emergency Management Plan, Government of New South Wales.
State of New South Wales Premier’s Department. (2021, December). New South Wales Coastal Waters Marine Pollution Plan as endorsed by the State Emergency Management Committee, Government of New South Wales.
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Portland Bay’s master and chief engineer
Pacific Basin Shipping, Hong Kong
the ship’s flag State administration, Hong Kong
Australian Maritime Safety Authority
Transport for NSW (NSW Maritime)
Port Authority of New South Wales
United Salvage
Engage Marine, the parent company of Engage Towage
Svitzer Australia
MAN PrimeServ
Monson Agencies Australia
Nippon Kaiji Kyokai (Class NK).
Submissions were received from:
Pacific Basin Shipping, Hong Kong
the ship’s flag State administration, Hong Kong
Australian Maritime Safety Authority
Transport for NSW (NSW Maritime)
Port Authority of New South Wales
United Salvage
Engage Marine (Engage Towage)
Svitzer Australia
MAN Energy Solutions on behalf of MAN PrimeServ and MAN B&W
Monson Agencies Australia
Nippon Kaiji Kyokai (Class NK)
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Appendices
Appendix A – Lloyd’s standard salvage agreement
The standard LOF 2020 form below was used for the salvage agreement in this incident.
Appendix B – Incident severity matrix (AMSA)
Maritime incident severity matrix (version 17 November 2021) appended to the Maritime Assistance Services procedure, 01/2021, at the time of incident.
Appendix C – Protection of the Sea (Powers of Intervention) Act 1981
Sections of the Protection of the Sea (Powers of Intervention) Act 1981 (No. 33, 1981, Compilation No. 13, 1 July 2019)
8 Taking of measures to prevent pollution of sea by oil—maritime casualty on the high seas
(1) Where the Authority is satisfied that, following upon a maritime casualty on the high seas or acts related to such a casualty, there is grave and imminent danger to the coastline of Australia, or to the related interests of Australia, from pollution or threat of pollution of the sea by oil which may reasonably be expected to result in major harmful consequences, the Authority may take such measures, whether on the high seas or elsewhere, as it considers necessary to prevent, mitigate or eliminate the danger.
(2) Without limiting the generality of subsection (1), the measures that the Authority may take under this section in relation to the ship, or any of the ships, involved in the maritime casualty include:
a) the taking of action, whether or not directions have been issued under paragraph (b) in relation to the ship:
i. to move the ship or part of the ship to another place;
ii. to remove cargo from the ship;
iii. to salvage the ship, part of the ship or any of the ship’s cargo;
iv. to sink or destroy the ship or part of the ship;
v. to sink, destroy or discharge into the sea any of the ship’s cargo; or
vi. to take over control of the ship or part of the ship; or
b) the issuing of directions of the kind authorized by section 11:
i. to the owner of the ship;
ii. to the master of the ship; or
iii. to any salvor in possession of the ship; or
iv. to any other person.
10 Taking of measures to prevent pollution of sea by oil or noxious substances—general powers
(1) This section (other than subsections (3B) and (3C)) applies in relation to:
a) any ship in internal waters, where…
b) any ship in the Australian coastal sea; and
ba) any ship in the exclusive economic zone of Australia; and
c) any Australian ship on the high seas
(2) Where oil or a noxious substance is escaping, or has escaped, from a ship in relation to which this section applies, or the Authority is satisfied that oil or a noxious substance is likely to escape from such a ship, the Authority may, subject to subsection (4), take such measures as it considers necessary:
a) to prevent, or reduce the extent of, the pollution or likely pollution, by the oil or noxious substance, of any Australian waters, any part of the Australian coast or any Australian reef;
b) to prevent damage, or reduce the extent, or likely extent, of damage, to any of the related interests of Australia by reason of the pollution, or likely pollution, of the sea by the oil or noxious substance;
c) to protect any Australian waters, any part of the Australian coast or any Australian reef from pollution or likely pollution by the oil or noxious substance;
d) to protect any other related interests of Australia from damage by reason of the pollution, or likely pollution, of the sea by the oil or noxious substance; or
e) in a case where the oil or noxious substance has escaped—to remove or reduce the effects, or likely effects, of pollution or likely pollution, by the oil or noxious substance, on any Australian waters, any part of the Australian coast, any Australian reef or any of the related interests of Australia.
(3) Without limiting the generality of subsection (2), the measures that the Authority may take under this section in relation to the ship include:
a) the taking of action, whether or not directions have been issued under paragraph (b) in relation to the ship:
i. to move the ship or part of the ship to another place;
ii. to remove cargo from the ship;
iii. to salvage the ship, part of the ship or any of the ship’s cargo;
iv. to sink or destroy the ship or part of the ship;
v. to sink, destroy or discharge into the sea any of the ship’s cargo; or
vi. to take over control of the ship or part of the ship; or
b) the issuing of directions of the kind authorized by section 11…
(4) The Minister and the Authority shall, in the exercise of powers under this section, act in accordance with the following principles:
a) measures taken under this section shall be in proportion to the damage, whether actual or threatened, in relation to which the measures are taken:
b) in determining whether measures are in proportion to the damage in relation to which the measures are taken, regard shall be had to:
i. the extent and probability of imminent damage if the measures are not taken move the ship or part of the ship to another place;
ii. the likelihood of those measures being effective; and remove cargo from the ship;
iii. the extent of the damage which may be caused by the measures;
c) measures taken under this section shall not exceed those reasonably necessary to achieve the end sought to be achieved by the measures and shall cease as soon as that end has been achieved;
d) measures taken under this section shall not unnecessarily interfere with the rights and interests of other countries, and of any persons, likely to be affected by the measures;
e) in taking measures under this section, any risk to human life shall, as far as possible, be avoided.
Appendix D – Port boundaries
Sydney Harbour and Botany Bay boundaries
Port boundary maps appended to the Port Safety Operating Licence (2019–2024) issued to the Port Authority of New South Wales, annotated by the ATSB.
Appendix E – Direction for Portland Bay
Direction – Protection of the Sea (Powers of Intervention) Act 1981
Redacted copy of direction issued to the owner and master of Portland Bay on 5 July 2022.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Commonwealth Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this report is licensed under a Creative Commons Attribution 4.0 International licence.
The CC BY 4.0 licence enables you to distribute, remix, adapt, and build upon our material in any medium or format, so long as attribution is given to the Australian Transport Safety Bureau.
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1]One knot, or one nautical mile per hour, equals 1.852 kilometres per hour.
[2]Sydney hereafter generally refers to its ports, Port Botany and Port Jackson (Sydney Harbour).
[3]The Beaufort scale of wind force, developed in 1805 by Admiral Sir Francis Beaufort, enables sailors to estimate wind speeds through visual observations of sea states.
[4]The Port Authority of New South Wales operated the VTS in Port Kembla and Sydney.
[5]Including the Admiralty Sailing Directions, Admiralty List of Radio Signals and Port Kembla harbour master’s directions.
[6]A ship’s displacement is the weight of water that it displaces, which equals its own weight (mass).
[7]Unless stated otherwise, all speeds in the report are over the ground.
[8]Fire and safety rounds conducted in the ship’s accommodation spaces at regular intervals, especially in hours of darkness, to check for fire hazards or other hazards, such as unsecured equipment and open watertight doors.
[9]Surge is the forward and aft motion of the vessel due to rapid acceleration and deceleration.
[10]The ship’s gyrocompass heading in degrees (practically the true heading).
[11]Significant wave height has been defined as the average height of the highest one-third of waves experienced over time. Also referred to as ‘total wave height’, about 14% (1 in every 7 waves) will be higher than the significant wave height. Maximum wave height (Hmax) can be up to twice the significant wave height.
[12]The International Safety Management (ISM) Code requires a ship’s managers to have a Designated Person Ashore (DPA) who should aim to ensure the ship’s safe operation and provide a link between all those on board and the highest level of management ashore.
[13]Not Under Command (NUC) – A vessel, which due to exceptional circumstances is not able to manoeuvre as required by the rules under Convention on the International Regulations for Preventing Collisions at Sea, 1972, as amended (COLREGs), and is therefore unable to keep out of the way of another vessel.
[14]The automatic identification system (AIS) is a very high frequency (VHF) radio broadcasting system which enables AIS equipped vessels and shore-based stations to send and receive identifying information.
[15]The Australian Maritime Safety Authority-operated Joint Rescue Coordination Centre or JRCC in Canberra.
[16]Marine Rescue NSW provided a 24/7 emergency service for the boating community and monitored marine radio. It was an independent, non-governmental, not-for-profit organisation that largely relied on volunteers.
[17]The urgency signal consists of the words ‘PAN PAN’ and indicates that the station sending it has a very urgent message to transmit concerning the safety of a vessel, aircraft, or person.
[18]MAYDAY is the internationally recognised radio call announcing a distress condition where a ship or its occupants are being threatened by serious and/or imminent danger and the master and crew require immediate assistance.
[19]The NSW Police Marine Area Command (MAC) duties include protecting life and property and coordinating search and rescue in waters up to 200 miles from the coastline.
[20]The Manager Marine Pollution and Emergency Response in NSW Maritime, which is the operational area responsible for maritime matters within Transport for NSW, the state’s transport regulator.
[21]Hereafter, references to AMSA include its ‘Operations’ or ‘Response’ divisions (JRCC is part of the Response division and is specifically referred to where appropriate for clarity).
[23]Walking back the anchor means lowering it under windlass power (the term ‘veered’ is also used and refers to paying out anchor cable under power using the windlass).
[24]Let go the anchor means releasing the windlass brake to allow the anchor and cable to pay out under their own weight.
[25]The AMSA Response Centre (ARC) had a functional role as JRCC Australia (JRCC), which operated within the ARC.
[26]The AMSA incident controller is referred to hereafter as the incident coordinator to avoid confusion with the Port Authority’s incident controller.
[27]The Baltic and International Maritime Council (BIMCO) TOWHIRE 2021 was an ocean towage agreement on a daily hire basis (not intended for port towing).
[28]The Royal Australian Navy’s support vessel ADV Reliant was a 103 m offshore support vessel that could be used for maritime support, including aid and disaster relief, and search and rescue activities.
[29]One cable equals one tenth of a nautical mile or 185.2 m.
[30]The combat agency was responsible for controlling the emergency response and defined as the ‘control agency’ by the National Plan for Maritime Environmental Emergencies, 2020 (National Plan).
[31]The ‘NSW Coastal Waters Marine Pollution Plan, December 2021’ (endorsed by the State Emergency Management Committee on 2 December 2021), New South Wales Government.
[32]A scavenge space fire occurs when flammable mixture (cylinder oil, unburnt fuel and carbon) collects in the engine’s scavenge space ignites. The fire can be extinguished by steam, water mist or CO2.
[33]The Protection of the Sea (Powers of Intervention) Act 1981 provides AMSA powers to take measures and issue directions to prevent or respond to pollution of the sea by oil or other substances.
[34]A detention is an intervention action taken by the port State when the condition of the ship or its crew does not correspond substantially with the applicable conventions. The action is taken to ensure that the ship will not sail until it can proceed to sea without presenting a danger to the ship or persons on board, or without presenting an unreasonable threat of harm to the marine environment, whether or not such action will affect the scheduled departure of the ship.
[35]A smaller size bulk carrier with a deadweight carrying capacity up to 50,000 t.
[36]The Hong Kong Special Administrative Region of the People’s Republic of China.
[37]Gross tonnage is a measurement of the enclosed internal volume of a ship and its superstructure with certain spaces exempted.
[39]The International Convention for the Safety of Life at Sea, 1974, as amended.
[40]The regular inspection involved inspection of piston rings and liners, scavenge manifold, under piston space, exhaust manifold and economiser tubes, and cleaning as required (the inspection report included a photographic record).
[42]Heaving-to refers to manoeuvring the ship to ride out heavy weather in the most comfortable position and avoid heavy rolling and pitching. Often, this will be with the weather on the bow and speed reduced to the minimum for steering.
[43]Peril at Sea and Salvage: A Guide for Masters, Sixth Edition, International Chamber of Shipping (ICS) & Oil Companies International Marine Forum (OCIMF), 2020.
[44]Pacific Basin, Crisis Management Manual, Issue 20 Dec 04.
[45]The most well-known and frequently used salvage contract is the Lloyd’s Open Form of Salvage Agreement commonly known as Lloyd’s Open Form or LOF.
[46]Admiralty Sailing Directions, Australia Pilot Volume 2, NP14, 12 Edition, 2013.
[47]International Convention on Salvage, 1989, International Maritime Organization, London.
[48]Lloyd’s is the worlds’ leading insurance marketplace. www.lloyds.com
[49]Protection and Indemnity (P&I) is a type of insurance that shipowners purchase to cover the potentially huge costs of any harm they accidentally cause to people, property and the environment. This type of insurance is separate from others, such as hull and machinery insurance and cargo insurance.
[50]The International Group of P&I Clubs comprised 12 clubs, which between them provided marine liability cover for approximately 90% of the world’s ocean-going tonnage.
[51]The International Salvage Union (ISU) has stated that it is the trusted and unified global voice of its members who facilitate world trade by providing services which save life, protect the environment, mitigate risk and reduce loss. The ISU had a membership of about 55 marine salvage companies from more than 30 countries.
[52]A lien is a charge against property, in most cases this is a ship. A maritime lien is a common law charge and adheres to the property from when the event giving rise to the claim happens (events that raise this lien are limited but include collision and salvage). Statutory liens against property are established by statute.
[53]Guidelines for Safe Ocean Towing, MSC/Circ.884, 21 December 1998, IMO.
[54]The pulling power of a tug, expressed in tonnes.
[55]In December 1999, Erika, laden with 31,000 tonnes of heavy fuel oil, broke in 2 while in the Bay of Biscay, spilling nearly 20,000 tonnes of oil which washed up on the French coast. All the ship’s crew were rescued.
[56]In December 2000, Castor, laden with 29,500 tonnes of petrol developed a 24 m crack on its main deck while in the Mediterranean Sea. The ship’s crew were evacuated and salvors towed it around for 40 days as various Mediterranean ports refused the structurally unsound tanker entry until eventually its cargo was transferred off the coast of Tunisia.
[57]Guidelines on Places of Refuge for Ships in Need of Assistance, A 23/Res.949, 5 March 2004, IMO (this document was valid at the time of the incident but were revoked by revised guidelines. A 33/Res.1184, 17 January 2024, IMO).
[58]Maritime Assistance Services (MAS), A 23/Res.950, 26 February 2004, IMO.
[59]Guidelines on the Control of Ships in an Emergency, MSC.1/Circ.1251, 19 October 2007, IMO.
[60]Good seamanship can be described as the best practice for carrying out any operation, work or task related to a ship’s operation. It has been learned and developed over time and recognised best practice is incorporated into maritime rules, regulations, codes or guidance aimed at ensuring safety of operations.
[61]Requirements concerning Mooring, Anchoring and Towing, IACS Req. 2007, A1.1, Design of the anchoring equipment.
[65]The 2004 House of Representatives Standing Committee on Transport and Regional Services, Ship Salvage Inquiry into Maritime Salvage in Australian Waters (the Neville Report).
[66]Australian Transport Council, Inter-Governmental Agreement on the National Maritime Emergency Response Arrangements, 29 February 2008.
[71]AMSA, Report on the 2011/12 Review of the National Plan to Combat Pollution of the Sea by Oil and Other Hazardous and Noxious Substances and the National Maritime Emergency Response Arrangements, October 2012, p1.
[124]Search and Rescue Operations Procedure Manual, SOM SOP 02/2022, AMSA.
[125]Maritime Assistance Services Standard Operating Procedures, MAS SOP 01/2021, AMSA.
[126]National Plan for Maritime Environmental Emergencies, 2020 edition, p 32.
[127]National Maritime Casualty Management Guidance, 27 April 2018, AMSA.
[128]Complex Maritime Emergency Management Guidance, 3 February 2022, AMSA.
[129]National Maritime Places of Refuge Risk Assessment Guidance, endorsed by NPSCC November 2015, AMSA.
[130]Coronavirus disease (COVID-19) was an infectious disease caused by a newly discovered coronavirus. The World Health Organization (WHO) first learned of this new virus on 31 December 2019. International and domestic responses to manage the pandemic included restrictions to activities and operations in the maritime industry.
[131]State Emergency and Rescue Management Act 1989, No 165, New South Wales.
[132]New South Wales State Emergency Management Plan, December 2018, New South Wales Government.
[134]Regional and local EMPLANS were not directly relevant to maritime emergencies in New South Wales coastal waters.
[135]The Roads and Maritime Authority was dissolved in 2019 after Transport for NSW took over all its functions.
[136]NSW Coastal Waters Marine Pollution Plan, December 2021 (endorsed by the State Emergency Management Committee on 2 December 2021), New South Wales Government.
[137]The National Plan defined a control agency being the same as a combat agency, which is mainly used in this report, with both terms having the same meaning.
[138]Memorandum of Understanding in Relation to Hazardous Materials Incidents on Inland and State Waters between: New South Wales Fire Brigades, Maritime Authority of New South Wales, Newcastle Port Corporation, Port Kembla Port Corporation and Sydney Ports Corporation, October 2010), New South Wales Government.
[139]Port Safety Operating Licence 2019–2024, Newcastle Port Corporation (Trading as Port Authority of New South Wales) issued under the Ports and Maritime administration Act 1995, 1 January 2019, commenced on 1 July 2022.
[140]Towage Licence, Port of Botany Bay (unrestricted), v1.0, 22 May 2020, Newcastle Port Corporation trading as Port Authority of New South Wales.
[141]A Class 2 B vessel is essentially a non-passenger vessel for offshore operations (generally within 200 miles from land).
[142]Towage Licence, Port of Sydney Harbour (unrestricted), v1.0, 22 May 2020, Newcastle Port Corporation trading as Port Authority of New South Wales.
[143]Port Kembla Marine Oil & Chemical Spill Contingency Plan, A Sub-plan of the Illawarra Emergency Management Plan (Illawarra EMPLAN), Revision 12, 30 November 2021, Port Authority of New South Wales.
[144]Incident Management Procedure, Issued 2 November 2021, Port Authority of New South Wales.
[145]Sydney Harbour and Port Botany Marine Emergency Response Plan, Revision 5, 19 October 2021, Port Authority of New South Wales.
[146]Port Kembla Emergency Response Plan, Revision 2, 8 December 2021, Port Authority of New South Wales.
[147]Pollution Response Plan Botany, Version 3, 10 May 2022, Port Authority of New South Wales.
[148]Pollution Response Plan Sydney, Version 3, 10 May 2022, Port Authority of New South Wales.
[149]VTS Operations Procedure 3.2.2 – 01, Marine Pollution, Revision 1, 18 October 2021, Port Authority of New South Wales.
[150]VTS Operations Procedure 3.2.2 – 01, Marine Pollution, Revision 1, 19 October 2021, Port Authority of New South Wales.
[151]Marine Pollution Emergency Checklist, VTS Operations Procedures 5.2-09, Revision 1, 18 October 2021, Port Authority of New South Wales.
[152]Emergency Response Checklist – First Strike Oil Spill (Sydney & Port Botany), Revision 7, 16 January 2020, Port Authority of New South Wales.
[153]Svitzer operated another 2 Commonwealth-owned tugs there on behalf of the Australian Defence Force (these tugs were not used or available for commercial purposes).
[154]Contract for Level 2 Emergency Towage Capability Services between AMSA and Svitzer Australia, 1 March 2019.
[155]Standard Operating Procedures for the Contract for Level 2 Emergency Towage Services between AMSA and Svitzer Australia, 1 April 2019.
[156]Veethane (also known as V-Thane) polyurethane is a very hard‑wearing but flexible thermoplastic. Veethane sleeves or tow wire protectors prevent abrasion and chafing of the wire against fairleads and bulwarks.
[158]Adsteam refers to Adsteam Marine, which was acquired by Svitzer Australia in 2007.
[159]Adsteam Marine, Submission to the Productivity Commission inquiry into Harbour Towage, 24 June 2002.
[160]Under the relevant New South Wales legislation, the incident ship/master could be directed (for example to take a towline, to enter a port or to not enter state waters). However, there were no powers to direct another ship, tug or salvor to assist another ship. In addition, there was no provision in the legislation to direct the owner or lessee of a port facility or berth to accommodate a ship in need of refuge. The Port Authority did not own any such port facility or berth.
[161]Lessons Report for MV Portland Bay, NSW South Coast, 2022, AMSA, 19 October 2022.
[162]Documented evidence shows that Svitzer consistently offered to make its tugs available to Pacific Basin under a TOWHIRE agreement unless tasked by AMSA under its ETC contract.
[163]As previously described, United Salvage submitted a formal place of refuge request to the MERCOM at 1945 on 4 July.
[164]On 14 April 1912, Titanic was on its maiden voyage from Southampton, England, to New York, United States, when it struck an iceberg in the North Atlantic Ocean and sank some hours later with the loss of more than 1,500 lives. The British passenger liner was then the largest, most modern and celebrated ship but the catastrophe transformed its name into one forever associated with disaster.
[165]In 1948, the United Nations established the Inter-Governmental Consultative Organization (IMCO) as a permanent international body to promote maritime safety and set international safety standards. In 1982, the name of IMCO was changed to the International Maritime Organization (IMO), which continues its work.
[166]Det Norske Veritas, Assessment of the Risk of Pollution from marine Oil Spills in Australian Ports and Waters, Prepared for AMSA, 14 December 2021.
[167]The Nautical Institute, Strandings and their Causes, Captain RA Cahill, Second Edition, 2002.
[168]ibid, Chapter 8, Loss of Propulsion and Stranding, p 65.
[171]United Salvage did not indicate if commercial towage arrangements or contracts were acceptable or considered.
Interim report
Report release date: 28/03/2023
This interim report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Interim reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
Background
At 0824 local time on 19 June 2022, Portland Bay (Figure 1) arrived off Port Kembla, New South Wales (NSW) following a voyage from Susaki, Japan. The ship was loaded with a cargo of cement and anchored off the port to wait for a berth to discharge the cargo.
At 1606 on 21 June, Portland Bay’s anchor was weighed and shortly after, a pilot boarded to conduct it to berth number 104 in Port Kembla’s inner harbour. By about 1724, the ship was safely alongside (starboard side to) its berth and, by 1930, cargo discharge had commenced. On the same evening, 8 new crew members joined the ship, including the relieving master and chief engineer. A further 5 relieving crew members joined the next day.
Figure 1: Portland Bay
Source: ATSB
By 2100 on 26 June, cargo discharge had been completed and Portland Bay departed Port Kembla the following day at 1240. The plan was to berth the ship in Port Kembla again on 2 July for cleaning of the upper parts of the cargo hold using shore labour. During the intervening period, the accessible areas of the cargo holds were to be cleaned by the ship’s crew while at anchorage. The ship anchored briefly off the port before weighing anchor at about 1430. The ship then drifted off Port Kembla for about a day before anchoring again on 28 June for the crew to carry out the cargo hold cleaning.
On 1 July, Portland Bay's local agent advised the ship’s managers (Pacific Basin) of potential disruptions to its planned hold cleaning in Port Kembla due to heavy rain and a large north‑easterly swell forecast for 3‑ 4 July. The advice noted that the ship might have to depart Port Kembla to avoid damage to both the ship and the wharf if the forecast swell eventuated.Theship’s managers, however, decided to continue with the planned berthing and at 0154 on 2 July, the ship was all fast (starboard side to) at berth number 202 in the outer harbour (Figure 2).
Figure 2: Port Kembla Harbour (Portland Bay at berth 202;wind and swell at 1100, 3 July)
Source: Australian Hydrographic Office (AHO) and annotated by ATSB
At 0410, a Bureau of Meteorology (BoM) forecast was issued predicting gale force winds of up to 35 knots[1] and an easterly swell of 3‑ 4 metres for the seas off Port Kembla for the following day. Entries in the ship’s logbook for 0500 recorded easterly winds at force 3 (7 to 10 knots).[2] At 1600 that day, a southerly wind at force 6 (22 to 27 knots) was recorded in the logbook.
At about 2243, Portland Bay's agent notified the master of additional measures required by the Port Kembla vessel traffic service (VTS) for ships in the port in anticipation of the forecast heavy weather. These measures included the lowering of an anchor to the seabed and the use of additional mooring lines. Port Kembla VTS also advised that the port’s anchorage was closed and that it required vessels drifting to remain at a safe distance off the coast (12 miles[3] or more).
The occurrence
On 3 July 2022, Portland Bay began to be affected by the swell at its berth in the outer harbour (Figure 2). At 1027, the terminal manager contacted VTS for an assessment by the duty pilot on whether it was safe for the ship to remain at its berth in the deteriorating weather conditions. At 1035, the ship’s master requested and received permission from VTS to lower the port anchor to the seabed.
At about 1050, following a risk assessment by the duty pilot and the harbour master, VTS instructedthe ship’s master to prepare to depart to avoid damaging the wharf and the ship due to its movement in the swell. The master concurred with the decision and began preparing for departure. Pre-departure checks included the testing of the ship’s steering gear and main engine (ahead and astern propulsion). A strong south-easterly breeze at force 6 (22 to 27 knots) was recorded in the ship’s logbook at that time.
At 1235, a pilot boarded Portland Bay and, by 1300, the pre-departure checks and master-pilot information exchange had been completed with the main engine on stand-by. The ship departed the berth at 1312 assisted by two tugs. The ship had maximum water ballast on board and its draught was 4.11 m forward and 5.30 m aft (aft draught for full propeller immersion was 5.1 m).
By 1334, Portland Bay had cleared the breakwater and the pilot disembarked. Due to the prevailing and forecast heavy weather, the engine room was kept manned with the engine on stand-by. The ship steamed east-north-east with the engine at manoeuvring full ahead (90 rpm). The ship experienced moderate to heavy rolling and pitching and the master recalled having difficulty maintaining a steady course and achieving a speed[4] of just 2‑ 3 knots.
At 1800, when Portland Bay was 14 miles east-north-east of Port Kembla, the master stopped themain engine to begin drifting. The weather had not improved with south-easterly force 7-8 winds recorded in the logbook. At about 1937, the main engine was restarted (probably to reduce rolling and pitching and arrest the ship’s westerly drift). The engine order setting was gradually increased to manoeuvring full ahead. At midnight, east-south-easterly winds at force 7 (28 to 33 knots, near gale force) were recorded in the logbook. The third mate handed over the ship’s navigation watch to the second mate and then conducted fire rounds[5] with nothing untoward reported.
At 0200 on the following day, 4 July, Portland Bay’s main engine was stopped, and the ship resumed drifting in a position 24 miles east-north-east of Port Kembla (15 miles from the nearest coastline). Although the south-easterly wind strength had reduced to force 5 (17 to 21 knots), the swell generated earlier by the stronger winds persisted. At about 0330, the ship surged[6] and rolled heavily, after which, the second mate restarted the main engine at dead slow ahead (42 rpm). By 0337, the engine order setting had been increased to half ahead (about 80 rpm) and, and by 0344, to full ahead (90 rpm).
Shortly after 0400, the second mate handed over the watch to the chief mate. The wind at the time was recorded as south-easterly, force 6-7. The second mate then completed fire and safety rounds and found nothing unusual. During those early hours of the morning, the BoM wave rider buoy off Sydney recorded waves with a significant wave height[7] of 5.04 m and a maximum wave height[8] of 8.44 m from the east-south-east.
At 0450, an alarm on the ship’s bridge fire detection panel alerted the chief mate to the activation of two fire detectors in the starboard side of the lower engine room. The second engineer, who was on watch in the engine control room and the chief engineer (also in the control room) found that the smoke from the main engine auxiliary blower no.2 had activated the fire detectors. A minute later, the second engineer returned to the engine control room, called the bridge and asked the chief mate to reduce main engine speed, and stopped blower no.2.
The chief mate began slowing down the main engine and, by 0453, when the master arrived on the bridge, the engine was set at slow ahead (58 rpm). At 0507, the engine setting was reduced further to dead slow ahead. Shortly after, various engine orders up to half ahead (80 rpm) were tried, but the master noted that the maximum rpm achieved was only 42.
At 0600, the master notified the ship’s managers of the ‘main engine failure’ and the ship’s situation. Shortly after, the engine was stopped and by 0624, the ship was displaying ‘not under command’ (NUC)[9] signals. The status of the disabled ship was also updated to NUC on its ‘automatic identification system’ unit.[10] At 0635, the engineers operated the main engine from the local emergency controls (adjacent to the main engine) in an attempt to increase rpm sufficiently for the turbo charger to take over, but their efforts were unsuccessful.
At 0658, Portland Bay’s master notified Port Kembla VTS on very high frequency (VHF) radio channel 16 that the ship’s main engine had ‘failed’, that it was drifting towards the coast and requested tug assistance. Port Botany VTS, which was also monitoring channel 16 (and in contact with Port Kembla VTS), began sourcing available tugs in the area to assist the ship.
At 0716, when Portland Bay was 11 miles south of Botany Bay, and 5.8 miles from the nearest coastline, the master broadcast an ‘urgency’[11] message on channel 16. Marine Rescue New South Wales (Port Kembla) acknowledged this urgency message. At about 0730, Marine Rescue NSW suggested to the master that the ship be anchored. However, in the adverse weather conditions and the relatively deep water where the ship was, the master decided against anchoring.
Subsequently, at 0744, Port Kembla VTS notified the Australian Maritime Safety Authority’s (AMSA) Joint Rescue Coordination Centre (JRCC) that the ship was drifting towards the coast and at risk of grounding in about 1.5 hours. Meanwhile, Port Botany VTS received confirmation from Engage Marine, a harbour tug provider in Port Botany on the availability of tug SL Diamantina. Soon after, JRCC coordinated with Port Botany VTS to dispatch SL Diamantina to Portland Bay’s location.
At about 0800, JRCC also started planning for a possible evacuation of Portland Bay'screw in the event that the ship stranded on the rocky coastline, endangering the crew. The planning involved coordinating with others including the Australian Defence Force and NSW Police and the State’s Helicopter Rescue and Ambulance Services.
At 0815, Portland Bay’s master, after consultation with the ship’s managers, broadcast distress alerts on maritime satellite communication systems and marine radio frequencies. At 0830, the master sounded the ship’s general emergency alarm and mustered the crew, contemplating abandoning the ship.
Meanwhile, in the worsening situation, the Port Authority of NSW had assumed the role of ‘combat agency’[12] in accordance with NSW State Emergency Management Plan and the National Plan for Maritime Environmental Emergencies and established an incident management team (IMT). SL Diamantina left Botany Bay at 0848 and was expected to arrive at Portland Bay’s location 90 minutes later. Shortly after 0900, 3 rescue helicopters tasked by JRCC to evacuate non‑essential crew arrived at the ship’s location. However, the helicopters had to abandon their winching attempts due to the ship’s unpredictable heavy rolling and pitching, which increased the risk of the winching cable being fouled by structures or fittings on the ship’s deck.
At 0917, when the ship was about 1 mile from the nearest coastline and in water depths of about 45 m (Figure 3 and Figure 4), the master anchored the ship, using both the anchors to arrest its drift towards the coast.
Figure 3: Portland Bay's movements from 3‑ 6 July
Source: AHO and annotated by ATSB
Figure 4: Portland Bay's track showing key events
Source: AHO and annotated by ATSB
At about 1000, when SL Diamantina arrived near Portland Bay, the salvage company, United Salvage, had been appointed to direct Engage Marine and its tugs. Shortly after, the master agreed to connect SL Diamantina's towline under a standard salvage agreement. At 1055, after several unsuccessful attempts, the towline had been connected. The ship’s engineers then removed the damaged auxiliary blower impeller and fitted a blank on the blower trunk.
At 1051, JRCC issued an ‘on-task direction’ for the emergency towage vessel (ETV) for the NSW ‘area of operations’ under the National Plan[13] to assist Portland Bay (Svitzer Glenrock, based in Newcastle, was the ETV identified for this area in AMSA’s emergency towage capability map). A few minutes later, Bullara (operated by Svitzer Australia) and located in Port Jackson, Sydney (closer to the ship’s location) departed the port. Shortly after, another Engage Marine tug, SL Martinique, departed White Bay, Sydney, to join the response.
Meanwhile at the ship’s location, SL Diamantina’s tow line parted at 1158. Over the next hour, the line was reconnected twice only to part again. Portland Bay’s master then asked the tug master not to attempt reconnecting it. Weather conditions at the time were near gale force south‑south‑easterly winds with a heavy south-easterly swell (estimated to be 9 m by the tug master).
At about 1410, the tugs Bullara and SL Martinique arrived on the scene and connected tow lines to Portland Bay’s starboard and port shoulder,[14] respectively. By 1430, a new impeller had been fitted to auxiliary blower no.2 and the ship’s managers notified AMSA that the ship’s main engine was operable at limited rpm (up to half ahead).
By 1540, Portland Bay’s anchors had been weighed and the tugs began towing it away from the coastline. Soon after, the master informed JRCC that the main engine could not be operated at a rpm greater than slow ahead.
Later during the afternoon, the engine had to be stopped on 2 occasions due to high temperatures caused by scavenge space fires.[15] At 1842, Bullara’s tow line parted and, with only SL Martinique connected, Portland Bay again began closing with the coastline.
At 1957, JRCC tasked Svitzer Glenrock to depart Newcastle to join the response. Subsequently, the tug’s crew arrived onboard and conducted storing in preparation for their voyage.
At 2010, Portland Bay’s master decided to anchor the ship again (Bullara was unable to actively assist due to its broken tow line). By 2045, the master had deployed both anchors, the ship was 1.4 miles from the coast and maintaining its position. The average and maximum swell recorded off Sydney at the time were 5.03 m and 8.63 m, respectively. At about 2110, SLDiamantina was stood down by the salvors as it was low on fuel and instructed to return to Port Botany.
At 2227, after completion of pre-departure and towing gear checks, SvitzerGlenrock departed Newcastle in weather conditions that remained rough with gale force southerly winds and a heavy swell of about 8 m.
At about 1300 the following day, 5 July, when SvitzerGlenrock arrived at Portland Bay’s location, the swell was still estimated to be about 8 m. United Salvage then asked Bullara’s master retrieve the broken tow line to allow Svitzer Glenrock to be made fast. By 1515, once Svitzer Glenrock was made fast,JRCC dismissed Bullara.
At 1550, AMSA issued a direction[16]to the ship’s owner and master to proceed under tow to a suitable berth in Port Botany. Port Authority of New South Wales and United Salvage were also directed to facilitate the tow and the ship’s berthing in Port Botany. Later that afternoon, in response to AMSA’s direction, United Salvage prepared a towage plan for the passage to the berth.
At 0722 on 6 July, tug SLFitzroy arrived at Portland Bay’s location to assist with the towage and subsequent berthing of the ship. Following the arrival of the pilot vessel at 0845, SLFitzroy made fast to the ship and, by 0954, 2 harbour pilots, representatives from the salvor, including an engineer, had boarded. Shortly after 1000, the master started weighing the anchors and by 1051, with both anchors home, the tugs (Svitzer Glenrock, SL Martinique and SL Fitzroy) began towing the ship. The ship’s main engine was used at its minimum setting of dead slow ahead as needed to assist the tow.
At 1228, the ship entered Port Botany port limits and by 1312, tug SL Diamantina also made fast for the berthing in accordance with the plan. By 1454, Portland Bay was safely alongside at the berth in Hayes Dock. Subsequently, AMSA officers boarded and, following initial inquiries, detained[17] the ship on grounds that it was unseaworthy due to its unreliable main engine.
On 7 July, an AMSA port state inspection identified deficiencies related to the ship’s main engine and other machinery. Over the following days, inspections and maintenance of all cylinder units of the main engine, auxiliary blower no.2 and charge air cooler were completed in accordance with the engine manufacturer’s recommendations.
On 13 July, following repairs, while the ship was still alongside, the main engine was tested to the satisfaction of the ship’s classification society surveyor and the engine manufacturer’s representative with an AMSA surveyor in attendance. The ship was then released from detention, and later that day, it departed Port Botany for Gisborne, New Zealand.
Context
Portland Bay
Portland Bay was owned by Uhland Shipping, classed with Nippon Kaiji Kyokai (Class NK) and managed and operated by Pacific Basin Shipping, Hong Kong. The Hong Kong registered 169 m bulk carrier was built in 2004 by Imabari Ship Building Company, Japan.
At the time of the incident, Portland Bay had a crew of 21, of which 13, including the master and chief engineer, had joined the ship in Port Kembla on 21 and 22 June 2022, about 12 days before the incident.
The master had about 23 years of seagoing experience with about 18 years in the rank of master. The master joined Pacific Basin shipping in 2017 as chief mate before gaining command on its ships. The incident voyage was the master’s first assignment on Portland Bay.
The chief engineer had about 30 years of seagoing experience. The chief engineer joined Pacific Basin shipping in 2016 and was promoted to chief engineer in 2021. The incident voyage was the second assignment as chief engineer after joining Portland Bay for the first time.
Machinery
Portland Bay’s propulsion was provided by a Makita Mitsui MAN-B&W 6S42MC engine, delivering 5,850 kW at 129 rpm, driving a single, fixed‑pitch, four‑bladed, right-handed propeller. The ship had a service speed of about 14 knots at 85% ‘maximum continuous rating’[18], which was 122 rpm (full sea speed).
The main engine was fitted with 2 auxiliary blowers, which generally operated in automatic mode providing air for the engine at low engine speeds. The blowers were designed to cease operation at higher engine speeds when the exhaust gas driven turbocharger could meet the engine’s air demand.
Further Investigation
A team of ATSB investigators attended Portland Bay in Port Botany to collect relevant documentary and recorded electronic evidence, and interviewed the master and the chief engineer. The ATSB also obtained relevant evidence from Pacific-Basin Shipping, AMSA, Port Authority of New South Wales, Engage Marine, Svitzer Australia and BoM.
The investigation is continuing and will include a review and assessment of:
Portland Bay’s activities and movements in relation to calling at Port Kembla
further analysis of data from the ship’s voyage data recorder to verify key event times
the ship’s main engine maintenance and performance, including auxiliary blower operation
the incident reporting and emergency response on board the ship
the emergency response by authorities with respect to the State and National Plans.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] One knot, or one nautical mile per hour, equals 1.852 kilometres per hour.
[2] The Beaufort scale of wind force, developed in 1805 by Admiral Sir Francis Beaufort, enables sailors to estimate wind speeds through visual observations of sea states.
[4] Unless stated otherwise, all speeds in the report are over the ground.
[5] Fire and safety rounds conducted in the ship’s accommodation spaces at regular intervals, especially in hours of darkness, to check for fire hazards or other hazards, such as unsecured equipment and open watertight doors.
[6] Surge is the forward and aft motion of the vessel due to rapid acceleration and deceleration.
[7] Significant wave height is traditionally defined as being the average height of the highest one-third of the waves experienced over time. It is also referred to as ‘total wave height’. About 14% or one in every 7 waves will be higher than the significant wave height.
[8] Maximum wave height (Hmax) can be up to twice the significant wave height.
[9] Not Under Command (NUC) – A vessel, which due to exceptional circumstances is not able to manoeuvre as required by the rules under Convention on the International Regulations for Preventing Collisions at Sea, 1972, as amended (COLREGs), and is therefore unable to keep out of the way of another vessel.
[10] The automatic identification system (AIS) is a very high frequency (VHF) radio broadcasting system which enables AIS equipped vessels and shore-based stations to send and receive identifying information.
[11] The urgency signal consists of the words ‘PAN PAN’ and indicates that the station sending it has a very urgent message to transmit concerning the safety of a vessel, aircraft, or person.
[12] A Combat Agency is the agency identified in State and/or Commonwealth emergency management plans as the agency primarily responsible for controlling the response to a particular emergency.
[13] The National Plan for Maritime and Environmental Emergencies (National Plan) includes arrangements for emergency towage capability based around the Australian coast and is managed by AMSA.
[14] A shoulder is the area where a ship’s hull form changes from the bow shape to the parallel mid body.
[15] Scavenge space fire is fire of flammable mixture (cylinder oil, unburnt fuel and carbon) which can collect in the scavenge space of an engine. Fire in the scavenge air space can be extinguished by steam, water mist or CO2
[16] The Protection of the Sea (Powers of Intervention) Act 1981 provides AMSA powers to take measures and issue directions to prevent or respond to pollution of the sea by oil or other substances.
[17] A detention is an intervention action taken by the port State when the condition of the ship or its crew does not correspond substantially with the applicable conventions. The action is taken to ensure that the ship will not sail until it can proceed to sea without presenting a danger to the ship or persons on board, or without presenting an unreasonable threat of harm to the marine environment, whether or not such action will affect the scheduled departure of the ship.
[18] Maximum Continuous Rating (MCR) is the maximum output power for the engine running continuously under safe conditions.
Occurrence summary
Investigation number
MO-2022-006
Occurrence date
04/07/2022
Location
22 km south of Port Botany
State
New South Wales
Report release date
15/05/2025
Report status
Final
Investigation level
Systemic
Investigation type
Occurrence Investigation
Investigation status
Completed
Mode of transport
Marine
Occurrence class
Serious Incident
Highest injury level
None
Ship details
Name
Portland Bay
IMO number
9276200
Ship type
Dry bulk carrier
Flag
Hong Kong
Manager
Pacific Basin Shipping, Hong Kong
Departure point
Port Kembla, New South Wales
Destination
Port Kembla, New South Wales (Port Botany for refuge)
On 23 May 2022, a De Havilland Canada DHC-8-102, registered VH-QQB and operated by Skytrans, was conducting a scheduled passenger flight from Brisbane to Chinchilla, Queensland. Approaching top of descent, the flight crew were alerted to an engine control unit (ECU) failure on the right engine. The ECU failure meant that reverse thrust would not be available on the right engine to assist in decelerating the aircraft on landing, but they assessed it was safe to continue with the planned approach.
During the landing, the aircraft veered to the left of the runway centreline. Towards the end of the runway, the left main landing gear ran off the runway.
What the ATSB found
The ATSB found that, after experiencing an ECU failure on the right engine, the flight crew opted to continue with the planned flight in accordance with the guidance in the available operator’s procedures.
Upon landing with a tailwind and further down the runway than usual, the flight crew experienced reduced braking effectiveness when the anti-skid system activated after the outboard right main wheel locked up after touchdown for unknown reasons. The system released brake pressure on the outboard wheel on both main landing gears, extending the landing roll.
While assessing the available braking performance, the crew missed a standard call that would have prompted the captain to transition to the tiller to provide directional control as the aircraft decelerated. In an attempt to slow the aircraft, the captain applied reverse thrust on the left engine which produced asymmetric deceleration. The aircraft veered slightly left, and the captain elected to use the emergency brake to slow the aircraft on the relatively short runway. Due to the runway being narrow, the left wheels departed the sealed runway surface in the final stages of the landing roll.
The investigation identified that the procedures permitting the flight crew to continue the flight after the ECU failure did not include consideration of other factors that could increase the required landing distance, including a tailwind and a wet runway, or that a narrow runway increased the risk of a veer off due to asymmetric thrust.
The investigation also found that the acceptable means of compliance guidance material for the Civil Aviation Safety Regulations 1998 relating to required landing performance did not clearly convey the intent of the regulations relating to the discontinuation of an approach to a runway when surface conditions were unexpectedly wet.
What has been done as a result
In response to this incident, the operator updated their procedures for continued flight following an ECU failure to prohibit the use of a narrow runway unless operationally required in an emergency.
Revisions to the operating procedures also prohibited the use of short runways with a tailwind.
The Civil Aviation Safety Authority have also added extra explanatory text to the guidance material to better explain the intention of the regulations around the assurance of landing performance and how these requirements can be met.
Safety message
Pilots and operators should remain mindful that unexpected events can combine to produce undesirable outcomes. Procedures for managing an equipment failure should take into account factors that may influence performance or other operational considerations. These could include tyre lock up, runway surface condition or the presence of a tailwind when landing on a short and narrow runway. Increased safety margins in procedural documentation can help ensure flight crew make appropriate decisions when managing unexpected events.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
On 23 May 2022 at 0720 local time, a De Havilland Canada DHC-8-102 aircraft, registered VH‑QQB and operated by Skytrans, departed Brisbane Airport on a scheduled passenger flight to Chinchilla Airport, Queensland with 3 crew and 26 passengers on board. The captain was pilot flying (PF), and the first officer was pilot monitoring (PM).[1]
At 0740, when approaching the top of descent, the flight crew noticed the engine control unit (ECU) warning light illuminate alerting them to an ECU failure on the right engine. Failure of the ECU meant reverse thrust would not be available on that engine on landing. The flight crew consulted the company procedures for managing an ECU failure, which permitted continuing the flight to Chinchilla. The flight crew checked the weather conditions for landing and elected to conduct a straight-in approach to runway 32,[2] with a tailwind of about 5 kt that was within acceptable limits. They also noted that there were some showers in the area.
The aircraft landed at 0806 and both flight crew reported that the aircraft touched down further along the runway than intended, but still within the company’s permitted touchdown zone.[3] Upon touchdown, the PF reported putting both propellers into beta range[4] and applying the brakes, but little or no braking occurred. The PF announced ‘no brakes’ to the PM, and the flight crew verified the brake hydraulic pressure indicators were indicating within the normal range. The PM also attempted to apply the brakes, but the aircraft was not slowing at the expected rate. In response, the PF moved the left thrust lever to reverse, and the aircraft deviated left of the runway centreline.
The PF reported the main concern at that point was stopping the aircraft. To avoid locking up the wheels, the PF made 3 applications of the emergency brake,[5] which was effective at slowing the aircraft. The PM recalled that, as the aircraft decelerated, they did not make the standard 60 kt call that would have prompted the PF to release the control column to the PM and assume directional control using the tiller[6] once the aircraft had slowed to around taxi speed. The PF reported that they did not use the tiller to assist in maintaining directional control because at the time they did not think they were at risk of a runway excursion.
After stopping the aircraft on the turning pad[7] at the end of runway 32, the flight crew taxied the aircraft to the apron via the normal taxiway and the passengers disembarked. The crew were alerted by a cabin crew member that the outer right wheel did not rotate during the landing roll. The PF then conducted an inspection of the aircraft and noticed the outer tyre on the right-side landing gear was deflated, with a flat spot that extended fully through the tyre (Figure 1). There was also mud on the left wheels.
Figure 1: Deflated outer right tyre
Source: Skytrans
The PF then walked the length of the runway and saw tyre marks indicating that the aircraft had deviated off the left side of the runway just before the runway turning pad (Figure 2), and that the outer right tyre had ‘dragged’ on the runway from the point of touchdown.
Figure 2: Tyre marks showing runway excursion to the left of runway
Source: Skytrans, annotated by the ATSB
Context
Flight crew information
The captain had been flying for over 30 years and had about 20,000 hours of aeronautical experience with about 6,500 hours on DHC-8 aircraft. The first officer had been flying for about 20 years and had about 7,500 hours of aeronautical experience, which included experience flying DHC-8 aircraft. Both flight crew had experienced an engine control unit (ECU) failure in flight prior to this incident.
Aircraft information
General
The De Havilland Canada DHC-8-102 aircraft is a high-wing, pressurised airframe powered by 2 turboprop engines, each driving a four-blade constant speed propellor. Skytrans had operated VH‑QQB since 2007.
Engine control unit
Each aircraft engine was fitted with an ECU. The primary function of the ECU is for fuel flow regulation and torque management to optimise performance while protecting the engine from operational hazards such as exceedances of certain engine parameters, including temperature and RPM. The ECU monitors the engine operating condition through various engine and airframe inputs. It also commands the torque motor in the engine hydromechanical unit[8] to optimise fuel flow to the engine and set a reference torque indicator ‘bug’ on the associated engine torque gauge in the cockpit instrumentation.
In the event of an internal fault, the ECU will drop offline, and engine management will revert to manual control. In manual mode:
the pilot assumes fuel control
the ECU MANUAL mode light will illuminate on the caution panel
there will normally be a difference between the 2 engine power lever positions for the same torque
engine response will be slower above 15,000 ft and for torque settings below 50%
engine surging is possible above 15,000 ft
there are limitations on the use of lower power lever settings, especially after landing, due to the engine under-speed governor, normally controlled by the ECU, being unavailable.
When the ECU is operating in manual mode, reverse thrust is no longer available for that engine/propeller on landing.
Anti-skid braking
Anti-skid systems are designed to minimise aquaplaning and the potential tyre damage that can occur when a wheel is locked or rotating at a speed which does not correspond to the speed of the aircraft. The system compares the speed of the aircraft with the rotational speed of each main wheel. If the speed of a wheel is too slow for the existing aircraft speed, the brake on that wheel is released momentarily to allow the rotational speed to increase and prevent the tyre from skidding. The anti-skid system in the DHC-8-102 is set for heavy airframe loads and when the aircraft is lighter or in slippery conditions, heavy braking may result in a short-term skid.
The system logic is activated by weight on wheels (WOW) proximity switches that close once the weight of the aircraft settles on the main landing gear after touchdown. These switches work in pairs through 2 channels (WOW 1 and WOW 2) to the skid control unit (SCU). There are 2 wheels on each main landing gear strut. The WOW 1 sensors provide input from the proximity switches of the inside wheel on each gear strut to the SCU. The SCU then controls the brakes on the inside wheel of each main gear strut. Similarly, WOW 2 sensors provide a signal to the SCU for the brake of the outside wheel on each of the main landing gear struts.
In addition, there is a ‘spin-up’ protection, ensuring brake pressure is not available to the braking system until the wheels are rolling on the runway surface at 35 kt. If a skid is detected, the skid control valve will provide a 3‑second delay to allow the wheels to spin up before braking is available. If the skid continues for more than 3 seconds, the system response is to release brake pressure on the corresponding wheel of the opposite gear leg through the WOW channels and the SCU, which reduces the braking performance and extends the landing roll.
Once the spin-up protection is no longer required, anti-skid protection is available down to a design limited minimum speed of 12 kt. Activation of the emergency brake disables the anti-skid system.
Engineering inspection
Engineers visually inspected the right landing gear following the incident and did not identify any defects with the brake pack or axle that would have led to the outer wheel lock up. Both right wheels were subsequently replaced. Significantly, the operator identified that, as the ECU system and the brake system are not connected, the wheel lock up was almost certainly unrelated to the ECU failure.
Managing the ECU failure
The operator used the aircraft flight manual and quick reference handbook procedures to manage an engine with an ECU in manual mode.
The flight crew were alerted to an ECU issue by the illumination of the ‘#2 Eng Manual’ caution light on the caution/warning panel. They then consulted the quick reference handbook for ECU operating in manual mode to determine the required actions. The handbook indicated that the power lever for the affected engine should not be moved below ‘DISC’ on landing, which included to the reverse thrust position.
The flight crew then consulted the Minimum Equipment List in relation to 1 ECU inoperative which stated that:
One [ECU] may be inoperative provided:
a. operations are conducted in compliance with the Airplane Flight Manual (AFM) supplement 10 OPERATION WITH ONE ECU INOPERATIVE; and
b. nose wheel steering and anti-skid brake control system operate normally.
The AFM supplement 10 OPERATION WITH ONE ECU stated (in relation to approach/landing with 1 ECU inoperative):
During approach, a maximum torque difference of 10% may be used to reduce POWER lever asymmetry.
Meteorological information
The aerodrome forecast (TAF),[9] current at the time of the approach, included wind from 120° (true) at 6 kt and scattered cloud at 2,000 ft above the airport, with visibility greater than 10 km. The meteorological aerodrome report (METAR),[10] issued at 0800, indicated that the wind was from 140° (true) at 4 kt with overcast cloud at 10,000 ft. The 1-minute weather data from Chinchilla Airport’s automated weather station recorded a south‑easterly wind at 3–4 kt at 0740 (when the aircraft was at top of descent) and an east‑south‑easterly at 5–6 kt at 0806 (when the aircraft touched down). The maximum wind gust within that period was 6 kt.
Based on the METAR, TAF and recorded observations, the prevailing wind produced an approximate 5 kt tailwind for an approach to runway 32 around the time of landing. The maximum acceptable tailwind stated in the flight crew operating manual was 10 kt. The pilot flying elected to conduct a straight-in approach despite a light tailwind because they assessed it was easier to manage a stabilised approach with the failed ECU. The tailwind component was within the operational limits, and they assessed sufficient runway distance available for a safe landing.
While no rain was forecast for the scheduled time of arrival, the area forecast indicated the presence of light showers in the area. These showers may not have produced sufficient rainfall to have been recorded with the METAR observations indicating there had been no rainfall in the 24 hours prior to the occurrence. The flight crew advised that at the time of landing, the runway was ‘damp’, and that the aircraft braking would be at or close to normal. Photographs of the runway taken after the occurrence (Figure 2) showed moisture on the runway surface. It was not shiny and there was no visible standing water.
A briefing note from the Flight Safety Foundation, FSF ALAR Briefing Note 8.5 – Wet or Contaminated Runways stated that a runway is considered damp when ‘the surface is not dry, but when the moisture on it does not give it a shiny appearance’.
Runway surface condition definitions
At the time of the occurrence, operators were required to operate in compliance with Civil Aviation Safety Regulations (CASR) Part 121 (Australian air transport operations - larger aeroplanes) performance requirements. During the 6-month transition period from the commencement of Part 121 on 2 December 2021, a deferral provision allowed operators to rely on their existing operations manual, written to comply with Civil Aviation Order (CAO) 20.7.1B Aeroplane weight and performance limitations – specified aeroplanes above 5 700 kg – all operations (turbine and piston-engined), supplemented by annexures to bring their document suite into compliance with the new Part 121.
CASR Part 121 MOS did not recognise ‘damp’ as a runway condition.
The runway surface condition definitions in Part 121 (Australian larger aeroplanes) Manual of Standards included:
dry: a runway is dry if the surface area required for a take-off or landing:
a) has no visible moisture;
b) is not contaminated.
wet: a runway is wet if the surface area required for a take-off or landing:
a) is not dry; and
b) is not contaminated.
contaminated: a runway is contaminated if more than 25% of the surface area required for a take-off or landing is covered by any of the following:
a) water or slush more than 3 mm deep
b) loose snow more than 20 mm deep
c) compacted snow or ice.
Landing performance
A briefing note from the Flight Safety Foundation, FSF ALAR Briefing note 8.3 - Landing distances stated that actual landing distance is affected by various operational factors, with those relevant to this incident being:
runway condition (dry, wet or contaminated by standing water, slush, snow or ice)
wind conditions
type of braking (pedal braking or autobrakes, use of thrust reversers)
anti-skid system failure
system malfunctions (e.g. increasing final approach speed and/or affecting lift-dumping capability and/or braking capability).
Civil Aviation Safety Regulations (CASR) 1998 Part 121 Chapter 9 Division 2 – Landing performance outlined the required factors to be applied to landing performance calculations to account for runway surface conditions. This was based on approved weather reports or forecasts,[11] or a combination of weather reports and forecasts. CASR Part 121 – Dictionary defined what constituted an approved weather report and who could provide one. Licensed pilots were included in the list.
CASR Part 121 – Manual of Standards (MOS) Chapter 9 made the distinction between pre-flight and in-flight requirements when calculating the landing performance. This required the crew to obtain the latest forecast and reports to ascertain the runway surface conditions for the time of arrival. The Civil Aviation Safety Authority's (CASA’s) Acceptable Means of Compliance and Guidance Material for Part 121 of the CASR referenced the United States Federal Aviation Administration’s (FAA’s) Safety Alert For Operators (SAFO 19001) which defined ‘at time of arrival’ as a point in time close enough to the airport to allow the crew to obtain the most current meteorological and runway surface conditions considering pilot workload and traffic surveillance, but no later than the commencement of the approach procedures or visual approach pattern.
CASA advised:
It is not acceptable to do an in-flight landing performance check at top of descent (or earlier) that is based on an expectation that the runway should be dry and then land on a runway that is known to be wet (other than dry) without ensuring (by calculation) that the wet (other than dry) landing performance is assured.
The operator’s manual required landing distance calculations be conducted in-flight. These calculations were to be based on weather reports or observations from an approved source.[12] The procedure to complete the in-flight landing performance check was defined in the Regulated take-off weight manual (RTOW)[13] for the DHC-8. The RTOW calculation required the use of the latest METAR and ATIS[14] or AWIS[15] information to assure the landing performance. The requirement to conduct this in-flight check complied with Part 121 MOS Chapter 9.13 Landing distance – in-flight requirements.
Recorded flight data
The aircraft had an onboard flight data recorder that had been modified by a previous operator. This resulted in difficulties extracting the FDR data, and inconsistencies found in some of the downloaded parameters brought the reliability of the data into question. Consequently, where suspect values could not be resolved and an alternate reliable source of information was available, the FDR data was not used.
The FDR did not record any parameters for the wind at Chinchilla Airport, however, the GPS data recorded the equivalent of a 12 kt tailwind when the aircraft touched down. This was inconsistent with the recorded weather observations (see the section titled Meteorological information), which indicated a steady 5–6 kt tailwind for a landing on runway 32. While both sets of data indicated that a tailwind was present for the landing, the magnitude of the FDR‑derived value was considered potentially suspect, so the Bureau of Meteorology recorded observations were utilised to determine the likely conditions. From the recorded data available the following key information was determined:
the ECU failure occurred at 0740:30
the aircraft touched down at 0806:15
upon touchdown the indicated airspeed was about 90 kt which was consistent with the target airspeed.
The touchdown point could not be definitively determined however, the weight-on-wheels and squat switch parameters indicated the aircraft touched down approximately halfway down the runway (approximately 510 m beyond the runway 32 threshold). Further analysis of the data showed multiple vertical and longitudinal acceleration spikes along with GPS altitude reaching ground level coinciding with a large pitch rate oscillation approximately 4 seconds before that position. This indicated that touchdown may have occurred about 300 m beyond the runway 32 threshold. This was consistent with photographs of the main wheel skid marks on the runway.
The rotation speed at touchdown and the point that the right outer wheel deflated could not be determined from the recorded parameters.
The manufacturer was provided with a copy of the data from the flight data recorder for their analysis, however they were unable to interpret the data. Given the basic landing parameters that were available, the manufacturer calculated that the crew would have needed all remaining runway to stop from a normal approach if the touchdown point was as indicated by the weight on wheels squat switch parameters. This calculation was based on the flight manual performance data for a dry runway.
Runway dimensions
Chinchilla Airport is a certified non-controlled aerodrome located in south-eastern Queensland. The airport has 2 runways, one clay runway (runway 03/21) unsuitable for use by a Dash 8 aircraft, and one sealed runway 14/32. This runway was 1,069 m in length and 18 m wide with a turn pad at each end of the runway (Figure 3). Part 139 (Aerodromes) Manual of Standards (MOS) 2019 stated that 18 m was the minimum runway width for aerodrome design.
Figure 3: Chinchilla runway 14/32 design
Source: Airservices, annotated by the ATSB
Runway 14/32 had undergone rehabilitation works that included resurfacing in 2015. Technical documentation indicated that a symmetrical crown existed for the first 300 m of runway 32 with a 5 cm drop from the runway centreline to both runway edges. The remaining 769 m possessed a uniform 1.5% downward slope from left to right across the runway. This transverse slope was within the permitted range specified in section 6.08 of the Civil Aviation Safety Regulations - Part 139 (Aerodromes) Manual of Standards(2019), and opposite the direction of the runway excursion.
A technical inspection of the aerodrome was conducted in February 2023 as part of the ongoing certification requirements of the airport. This inspection found that the runway surface contained minor rutting at the north-western end of runway 14/32 but the ruts did not hold water and were not considered a safety issue.
Safety analysis
After experiencing an ECU failure on the right engine during flight, the flight crew consulted the operator procedures and opted to continue with the planned flight based off that guidance. The pilot flying (PF) had also experienced ECU failures before and was comfortable managing the limitations associated with the failure. The flight crew knew they would not have reverse thrust available on the right engine to assist with slowing the aircraft upon landing, however they had a plan for how to manage that limitation.
The aircraft landed longer than the flight crew intended, but probably still within the touchdown zone. However, this reduced the runway length available to stop the aircraft. The tail wind and the wet runway may have also increased the stopping distance required.
Upon landing the outer right tyre locked up, causing the anti-skid system to activate and release brake pressure on both outboard wheels. The reason for the lock up could not be determined, but it resulted in only the inboard wheels providing a braking force. The reduced braking effectiveness was a surprise to the pilots as they were not expecting any issues with braking performance, other than the lack of reverse thrust on the right engine. In response, the main focus of the flight crew became stopping the aircraft before the end of the runway.
That focussed attention resulted in the flight crew missing a standard call, which would have prompted the captain to transition to the tiller for directional control. As the crew did not assess that the aircraft was at risk of a lateral runway excursion, this missed call was not detected and their focus remained on stopping the aircraft in the remaining runway. However, as they were landing on a narrow runway the margin for error was reduced, and in the final stages of the landing roll the left landing gear departed the sealed runway surface. The flight crew were unaware of the runway excursion until after conducting a walk around of the aircraft and seeing mud on the tyres.
The operator’s procedures for managing an ECU failure that were utilised by the flight crew when assessing whether to continue with the planned flight were ineffective at prompting the crew to consider other unrelated factors that could affect landing distance. For example, there was no consideration of the impact of a tailwind, a wet runway, or the risk of a runway excursion off a narrow runway due to the asymmetric deceleration associated with the ECU failure.
The operator had a procedure that required the crew to calculate landing performance for the reported runway surface conditions. The expectation was that these would be checked in-flight and provide the assurance of landing performance prior to arrival.
Part 121 MOS that replaced the CAO under the regulatory reform, required the crew to perform an in-flight performance calculation based on reports and forecasts valid at the time of arrival. In explanatory documentation produced by CASA,[16] which included reference to FAA SOFO 19001, it was acceptable to conduct an in-flight planning check during the descent, but not after the commencement of the approach procedures or visual approach.
CASA advised that this should be interpreted to mean that where an arrival takes place to a runway that is forecast and reported to be dry, but upon arrival is found to have visible moisture on its surface, then the landing must not be continued until the wet landing performance is known. This may require a missed approach to allow time for the crew to confirm, by calculation, that the wet performance can be assured prior to landing.
However, the explanation in the acceptable means of compliance guidance material did not clearly convey this intention and did not make the requirement to discontinue the approach clear in the event the runway surface was unexpectedly wet.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the runway excursion involving a De Havilland Canada DHC-8, VH-QQB at Chinchilla Airport, Queensland on 23 May 2022.
Contributing factors
After landing, the anti-skid system activated when the outer right main wheel locked up, resulting in reduced braking effectiveness.
While managing the combination of unrelated technical failures affecting directional control, the aircraft veered off the narrow runway.
Other factors that increased risk
The operator’s procedures for managing an ECU failure did not include consideration of other factors that could increase the required landing distance, including a tailwind and a wet runway, or that a narrow runway increased the risk of a veer off due to asymmetric thrust.
The acceptable means of compliance guidance material did not clearly convey the intention of the Civil Aviation Safety Regulations 1998 - Part 121 (Australian larger aeroplanes) Manual of Standards 2020 subsections 9.10 – 9.13 that landing performance must be assured at all times.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by the operator
In response to this incident, on 25 May 2022, Skytrans issued 2 flight operations notices (FON) which have since been incorporated into the operations manual:
FON 2022-11: Short runway operating requirements was issued to all pilots which included not to land on a short runway with a tailwind. A short runway was defined as less than 1,101 m for DHC-8 aircraft.
FON 2022-12: Operations to narrow runways with ECU in manual mode was issued to DHC-8 pilots that stated that unless in an emergency, operations to a narrow runway with an ECU in manual mode was prohibited.
Safety action by the Civil Aviation Safety Authority
To clarify the expectation around the calculation of landing performance data, and to provide guidance on how the regulatory requirements can be met, the Civil Aviation Safety Authority has drafted an amendment to the Civil Aviation Safety Regulations 1998 - Part 121 (Australian larger aeroplanes) Acceptable means of compliance and guidance material (AMC/GM) for inclusion in an upcoming revision. This revision includes the following text:
In-flight monitoring of runway surface conditions (dry, wet or contaminated)
Section 9.13 of the Part 121 MOS requires the PIC to ensure, during the flight and before landing, that the landing performance requirements specified in this MOS section are met for the aerodrome of intended landing. An element of these requirements is determining whether the runway to be used is dry, wet or contaminated.
The determination of the runway surface condition is required to be based on any weather report or forecast, or any combination of weather reports and forecasts. For the avoidance of doubt, the words in the MOS “…during the flight and before landing…” do not indicate that a singular determination can be made once during the flight and relied upon for the entire remainder of the flight. To satisfy their obligations regarding ensuring the safety of the flight under regulation 91.215 of CASR, PICs [pilots in command] are expected to check for updated forecasts and reports at regular intervals throughout the flight and base their determination of runway surface condition on these reports and forecasts.
The intent is that landing performance is assured at all times. This can be achieved by the operator evaluating the effect of multiple runway surface conditions for the most limiting aircraft configuration and including appropriate procedures in the exposition. This is particularly recommended where the aircraft landing configuration is restricted due to, abnormal or emergency situations encountered during flight and/or a narrow runway and/or the runway length is minimal.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
flight crew
aircraft operator
aircraft manufacturer
Bureau of Meteorology
References
Civil Aviation Safety Authority. (2019). Civil Aviation Safety Regulations 1998 - Part 139 (Aerodromes) Manual of standards 2019. Australian Government.
Civil Aviation Safety Authority. (2020). Civil Aviation Safety Regulations 1998 - Part 121 (Australian larger aeroplanes) Manual of Standards 2020. Australian Government.
Flight Safety Foundation 2000b ‘ALAR briefing note 8.5 – Wet or contaminated runways’, Flight Safety Digest, August-November 2000
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
An initial draft of this report was provided to the following directly involved parties:
the flight crew of VH-QQB
Skytrans Pty Ltd
Bureau of Meteorology
The Transportation Safety Board of Canada
DeHavilland Aircraft of Canada Limited
Civil Aviation Safety Authority
Submissions on that draft report were received from:
the flight crew of VH-QQB
Skytrans Pty Ltd
DeHavilland Aircraft of Canada Limited
Civil Aviation Safety Authority
After changes, a revised draft report was provided to the directly involved parties.
Submissions on that draft report were received from:
Skytrans Pty Ltd
Civil Aviation Safety Authority
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Pilot Flying (PF) and Pilot Monitoring (PM): Procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
[2] Runway number: The number represents the magnetic heading of the runway. Runway 32 indicates a heading of 320°.
[3] Touchdown zone means the portion of a runway, beyond the threshold, where landing aeroplanes are to first contact the runway.
[4] In beta range, the power lever directly controls propeller blade angle. Beta range of operation consists of power lever positions from flight idle to maximum reverse.
[5] The emergency brake system provides a means for applying brakes should the normal brake system fail.
[6] The tiller, located on the left side panel of the left seat, is used for directional control of the aircraft on the ground.
[7] Turn pad: A defined area on a land aerodrome adjacent to a runway for the purpose of completing a 180-degree turn on a runway.
[8] Hydromechanical unit: Regulates fuel flow to the fuel nozzles in response to power requirements and flight conditions.
[9] Terminal Area Forecast (TAF): A TAF is a coded statement of meteorological conditions expected at an aerodrome and within a radius of five nautical miles of the aerodrome reference point.
[10] Meteorological Aerodrome Report (METAR): A routine report of meteorological conditions at an aerodrome. METAR are normally issued on the hour and half hour.
[11]Civil Aviation Safety Regulations1998 Dictionary defines approved weather forecasts as those made by the Bureau of Meteorology (BOM), and approved weather reports as those made by the BOM for aviation purposes, an automatic weather station at an aerodrome approved by the BOM, a pilot or a person appointed by the aerodrome operator to make visibility assessments under CASR Part 139 – Manual of standards.
[12] The operator’s manual defined approved sources of domestic forecasts and reports as those generated by Air Services Australia or the Bureau of Meteorology.
[13] Regulated take-off weight (RTOW) manual – Document to determine the maximum weight in which an aircraft can take off from a particular runway under specific conditions (winds, weather, specific aircraft configuration, etc,).
[14] Automatic terminal information services (ATIS): Operational information required by aircraft for take-off or landing is broadcast on a dedicated frequency and/or on the voice channel of radio navigation aids.
[15] Aerodrome weather information service (AWIS): actual weather conditions, provided via telephone or radio broadcast, from Bureau of Meteorology (BoM) automatic weather stations, or weather stations approved for that purpose by the BoM.
On 10 June 2022, the flight crew of a Boeing 737-476SF freight aircraft, registered ZK-TLJ, noted a 340 ft discrepancy between the captain’s and first officer’s altitude when operating in reduced vertical separation minimum airspace after departing Perth Airport, Western Australia. They had also observed an airspeed and Mach number difference, but this was within the manufacturer’s stipulated limits. The aircraft was descended, and the flight crew completed the Quick Reference Handbook - Airspeed Unreliable procedure. It was determined that the first officer’s instruments were reliable for a return to Perth. After landing, ground crews found foreign residue adhered to the lower surfaces of all 4 pitot-static probes.
What the ATSB found
The ATSB established that, during an engine ground run 2 days prior to the incident, the pitot‑static probe covers were not removed, and the automatic pitot heat was not isolated as required by the ground run procedures checklist. As a result, the covers melted onto the probes. Although cleaned, residue remained on the probe surfaces, which had the potential to compromise the accuracy of the pitot-static instruments in-flight. It was also established that pitot‑static probe covers made from polyvinyl chloride material were used, which increased the risk of the covers melting onto the probes if left on during engine operation.
Air traffic control were not advised of the altitude discrepancy of 340 ft, which exceeded the maximum allowed altimetry system error for reduced vertical separation minimum airspace of 200 ft. Therefore, adequate vertical separation with other aircraft could not be assured by air traffic control.
What has been done as a result
The maintenance organisation has undertaken several procedural initiatives to reduce the likelihood of melted pitot-static probe covers in the future. The most notable being the use of high temperature resistant Kevlar™ covers replacing the extant polyvinyl chloride covers. They have also ensured that checklists are readily available, and the safety briefing conducted at the start of each day discusses threat and error management, and local hazards.
Safety message
Aircraft barometric air data sensing instrumentation components are extremely sensitive to damage and disruption. This incident highlights the importance of maintaining a high level of attention to damage and contamination when working on, and inspecting these components, particularly on aircraft certified to operate in reduced vertical separation minimum airspace. Where there is doubt, the probes should be removed and tested by an approved facility. Further, it demonstrates the need to appropriately action and complete checklists, and for flight crew to advise air traffic control of altimetry system errors.
The investigation
Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
On 10 June 2022, an Airwork Boeing Company 737 aircraft, registered ZK-TLJ, was being operated as a freight service from Perth via Port Hedland, Western Australia to Christmas Island. On board were the captain as pilot monitoring, first officer (FO) as pilot flying,[1] an avionics licenced aircraft maintenance engineer (LAME), and load master.
At about 0951 Western Standard Time,[2] the aircraft departed Perth on climb to the designated cruising altitude of flight level (FL)[3] 330, operating in reduced vertical separation minimum (RVSM)[4] airspace. As the FO’s altimeter passed FL 320, the FO called ‘one to go’ in reference to the approaching designated cruise altitude. The captain noted that the call was made early according to their altimeter reading.
The aircraft levelled off at FL 330 (33,000 ft) using the FO’s altimeter coupled to autopilot B.[5] At that time, the flight crew noted the captain’s altimeter displayed 32,660 ft. They also noted differences between the captain’s and FO’s indicated airspeed and Mach number of 265 kt and 269 kt, and 0.745 M, and 0.762 M, respectively.
The flight crew, in discussion with the LAME and Airwork maintenance watch, decided to return to Perth for maintenance. At this stage, they assessed that the aircraft was overweight for a direct return and landing at Perth, so they decided to continue on the current heading and carry out troubleshooting to determine the accuracy of the altimeters. The Quick Reference Handbook (QRH) Airspeed Unreliable procedure was consulted to determine the validity of the displayed airspeed and altitude. The procedure makes use of a table, which required the aircraft to descend to FL 300, the flight crew to set the aircraft pitch attitude and Mach indications against the aircraft weight and adjust the engine N1[6] speed to achieve level flight. By comparing the values displayed against the known configuration, the accuracy of the instruments could be assessed.
An air traffic control (ATC) clearance was requested and provided for a descent to FL 300 and the flight crew completed the QRH procedure. They determined that the FO’s instruments were reliable, and the remainder of the flight was conducted using those instruments.
The flight crew notified ATC that they required a return to Perth for ‘operational reasons’, and a clearance was provided. On descent into Perth, the flight crew noted that the altitude discrepancy on their altimeters began to decrease until about 10,000 ft, from which point they provided consistent indications. The aircraft landed at Perth without further incident.
Post-flight inspection
After landing at Perth, engineering staff inspected the 4 combined pitot-static probes and found residue on all 4 probe surfaces (Figure 1). All of the probes were subsequently removed, and the pitot‑static lines were flushed with nitrogen. This was carried out in accordance with the manufacturer’s maintenance procedures, which did not require a sample of any debris to be collected and analysed. Therefore, the presence of debris in the pitot-static system was not determined.
The probes were replaced with serviceable items, the system was tested, assessed serviceable, and the aircraft returned to service. The pitot-static probe covers onboard the aircraft were also inspected and found to have had a temporary repair applied to them (Figure 1).
Figure 1: Pitot-static probe and covers
Source: Airwork, annotated by the ATSB
Context
Pitot-static system
The pitot-static system is a set of air pressure-sensitive instruments used to measure an aircraft’s airspeed and altitude. Erroneous altimetry indications can be induced by a partial or full blockage of the static air pressure sensing system, or by turbulent air over the static pressure sensing ports.[7] Static pressure sensing instruments are carefully designed to minimise the risk of turbulent air over the sensing ports, however a small amount of contamination or damage to the ports, or area surrounding the ports, can result in turbulent air and a reduction in instrumentation accuracy.
The 737-476SF has 4 combined pitot-static probes fitted to the nose of the aircraft, 2 alternate flush static ports for the standby altimeter, and connecting tubing. The pitot-static lines are self‑draining, and where this is impractical, drain traps are provided. The pitot-static probes are independently connected to the 2 independent air data computers (ADC1 and ADC2), which convert the barometric pitot-static pressures into a digital signal to be displayed on the captain and FO altitude, airspeed, and Mach instruments. The pitot-static probes are electrically heated to prevent the formation of ice on the probes which can disrupt or block the normal flow of air.
In April 2021, the aircraft was made compliant with United States Federal Aviation Administration airworthiness directive[8] 2019-09-10. This required completion of Boeing alert service bulletin SB737-30A-1064, which modified the pitot heat system to energise automatically on engine start to avoid inadvertent flight into icing conditions with pitot-static heat off. The system senses the engine running using the low oil pressure switch on either engine.
Pitot-static probe covers
Pitot-static probe covers are used to provide protection from contamination when on the ground. Covers were not routinely fitted to the aircraft during turn around inspections, except in locations where an increased risk of contamination existed. The covers generally travelled with the aircraft and were fitted and removed by ground crew as required. The covers were to be fitted during extended periods on the ground.
The aircraft maintenance organisation had substituted the Boeing recommended Kevlar™[9] pitot‑static probe covers with locally manufactured items, made from a commercially available polyvinyl chloride material. The Kevlar™ covers were specifically designed to withstand high temperature associated with the inadvertent application of pitot-static heat, without causing damage to the pitot-static probes.
Ground maintenance
On 8 June 2022, a scheduled engine wash was conducted on the right engine by Airwork maintenance personnel, assisted by contract maintenance personnel, at Brisbane Airport. The maintenance personnel comprised of a certifying LAME, a participating LAME, and an AME under supervision. The contract maintenance personnel operated the ground support equipment.
The engine wash procedure required several dry motors[10] of the engine for the introduction of the detergent solution and rinse, followed by operation of the engine at idle for 10 minutes.
The operator’s internal investigation established that the task was completed in stages, alternating between the certifying LAME and the participating LAME. Further, there was limited communications between the LAMEs, and they performed the task from memory without reference to the Airwork 737-300/400 ground run procedures checklist. This checklist required the pitot‑static covers to be removed, and the pitot-static heat circuit breakers to be opened to disable the heat system, prior to motoring or starting the engine.
Following completion of the wash, the participating LAME noticed that all 4 pitot-static probe covers had remained fitted during the dry motor and engine run operations, which resulted in the covers melting onto the probes. The covers were subsequently removed, and the tubes were cleaned using a plastic scraper, a scouring pad and solvent. A detailed visual inspection was carried out on the probes, and they were assessed serviceable. The aircraft was returned to service on 9 June 2022 and completed about 11.5 hours of flying over 7 sectors with no reported incidents, prior to the flight on 10 June 2022.
The damaged covers were hung on a board with a note describing the incident and that replacement covers had been ordered. Later that day, another engineer saw the covers, and put flame proof tape on them so that they could be reused until the replacements arrived.
ATSB examination
The 4 probes were sent to the ATSB’s technical facilities in Canberra for detailed examination. That examination identified varying amounts of foreign residue adhered to the lower surface of all 4 pitot-static probes. The right upper and lower probes presented with foreign object debris in the pitot drain ports. The source of this debris could not be determined.
The depth of the residue varied between almost none on the right upper probe, to a maximum of about 0.4mm in an uneven, rippled profile on the right lower probe (Figure 2). An internal examination was not conducted.
Figure 2: Pitot-static probe residue
Source: ATSB
Recorded information
Quick Access Recorder (QAR) data from the incident and previous flights was analysed by Boeing and the ATSB. By design, the QAR only recorded data from ADC1, which precluded the direct reading of the FO’s altitude indications. However, the QAR also recorded altitude data from the traffic alert and collision avoidance system,[11] which was acquired from the selected transponder. On the incident flight the transponder was set to acquire data from ADC2. From this the FO’s altitude indications were able to be indirectly determined.
The analysed data for the 7 flights between Brisbane and Perth showed minor discrepancies between the captain’s and FO’s altimeter during climb and descent, but no notable discrepancy in cruise flight was recorded. It could not be determined from this data if the transponder/ traffic alert and collision avoidance system was selected to acquire data from ADC1 or ADC2 during these flights. The recorded magnitude of the climb and descent altimetry error was small and unlikely to be noticed by flight crews. The source of these errors could not be determined from the recorded data and could have resulted for various reasons not linked to the ground maintenance incident on 8 June 2022.
The incident flight analysis showed that the FO’s altimeter indicated a higher reading than the captain’s, varying between 300 ft and 390 ft, throughout the cruise portion of the flight. Information regarding the reported airspeed and Mach number discrepancy could not be obtained from the recorded data due to the ADC limitation described above. Using the values provided by the flight crew, the discrepancy was within the 20 kt or 0.030 M requirement specified in the QRH, for the airspeed indicators to be considered reliable.
Reduced vertical separation minimum airspace
The aircraft’s transponder was manually selected to use data from either ADC1 or ADC2. The altitude information passed from the selected ADC to the transponder was also used by ATC and the aircraft’s traffic alert and collision avoidance system to monitor aircraft altitude and maintain safe vertical separation between other aircraft.
During the incident flight, the aircraft was operating in reduced vertical separation minimum airspace (RVSM), which was between FL 290 and FL 410. In RVSM airspace, vertical separation is reduced from 2,000 ft to 1,000 ft. Aircraft are required to meet specified minimum accuracy requirements for airspeed and altitude, as well as a specific RVSM minimum equipment list, prior to being approved to fly in RVSM airspace. Flight crews are also required to closely monitor the altimeters for agreement prior to entering and throughout flight in RVSM airspace.[12] If there is a disagreement of greater than 200 ft and the flight crew believe that one of the primary altimeters is functioning normally, they must couple the autopilot to that altimeter and notify ATC ‘For information, operating on one primary altimeter only’.[13]
According to the International Civil Aviation Organization,[14] altimetry system errors may occur for various reasons including from damage to the pitot-static system. These faults can send incorrect data to ATC and the traffic alert and collision avoidance system, as well as the aircraft’s altimeters. In turn, this could result in a breakdown of vertical separation and increase the risk of collision, as depicted in Figure 3, if the error is not detected by the flight crew and reported to ATC.
Figure 3: Altimetry system error risk
Source: International Civil Aviation Organization
Safety analysis
Altitude discrepancy
The FO’s call of 1,000 ft remaining until the assigned cruising altitude of FL330 differed from what was observed at that time by the captain on their respective altimeter. Likewise, after reaching that altitude, a 340 ft discrepancy was also identified between the FO’s and captain’s altimeters. This was consistent with the recorded flight data, which showed about the same discrepancy at the top of climb. The discrepancy varied during cruise flight between about 300–390 ft and always maintained a FO’s altimeter high indication. At the time, the flight was operating with a reduced vertical separation of 1,000 ft between other aircraft.
While the flight crew also identified slight differences between the indicated airspeeds and Mach numbers, these were within the manufacturer’s stipulated error limits for flight as stated in the Quick Reference Handbook.
Plastic pitot covers
The aircraft manufacturer recommended the use of Kevlar™ pitot-static probe covers as this material could withstand the high temperatures associated with the automatic operation of the pitot heat system at engine start if the covers were inadvertently left fitted. However, the operator had sourced locally made polyvinyl chloride covers, which were less resistant to heat. This increased the risk of the covers melting onto the probes if left on during engine operation.
Covers not removed prior to maintenance
The Airwork 737-300/400 ground run checklist required the removal of the pitot‑static probe covers and isolation of the pilot heat system. However, the operator reported that the checklist was not used when performing the scheduled engine wash 2 days prior to the incident flight. Rather, maintenance personnel completed the task by memory. This resulted in the pitot-static probe covers not being removed and the pitot-static heat circuit breakers not being opened prior to engine motoring and start. The risk of performing a maintenance error was potentially exacerbated by the maintenance personnel carrying out the task in alternating stages, with limited communication between them, as reported by the operator. As a result, the covers melted, and residue was deposited onto all 4 pitot-static probes.
Pitot-static probe residue
After identifying that the pitot-static probe covers had melted, the probes were cleaned and a visual inspection performed, before being returned to service. However, a post-incident inspection of the probes and the ATSB’s examination found residue from the covers remained on the probe surfaces.
Despite this, the analysis of the QAR data showed a stable altimetry system error extending back to the 7 flights after the engine wash. Further, the 7 flights had been completed between the wash and the incident flight with no reported altitude discrepancies from flight crews. Although the decision to not replace the pitot-static probes increased the risk of error resulting from turbulent air over the static pressure sensing ports, the QAR data did not demonstrate a link between the remaining residue and the incident flight.
Altimetry error in RVSM airspace
Consistent with the recorded data, the flight crew noted a 340 ft altitude discrepancy when at FL 330. If the primary altimeters diverged by greater than 200 ft when operating in RVSM airspace, ATC were to be notified. While the captain notified ATC that they required a descent and a subsequent return to Perth for operational reasons, they did not advise them of the discrepancy. This was based on the flight crew’s understanding that they had established the FO’s altimeter was accurate.
Altimetry system errors not only result in erroneous indications to the flight crew, but the protection systems afforded by ATC and the aircraft’s traffic alert and collision avoidance system can also be degraded. Therefore, it is important that flight crews advise ATC of any errors so ATC can assure adequate vertical separation exists with other aircraft.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the unreliable altitude indications involving Boeing 737-476SF, ZK-TLJ, about 167 km west of Meekatharra Airport, Western Australia on 10 June 2022.
Contributing factors
While operating in reduced vertical separation minimum airspace, a 340 ft discrepancy between the captain’s and first officer's altitude indication was observed when at the designated cruise altitude.
Other factors that increased risk
The operator used pitot-static probes made from polyvinyl chloride material, which increased the risk of the covers melting onto the probes if left on during engine operation.
During ground maintenance 2 days prior, the pitot-static probe covers were not removed, and the automatic pitot heat was not isolated as required by the Airwork 737-300/400 ground run procedures checklist. As a result, the covers melted onto the probes.
Although cleaned, residue remained on the pitot-static probe surfaces, which had the potential to compromise the accuracy of the pitot-static instruments in-flight.
Air traffic control were not advised of the 340 ft altitude discrepancy between the altimeters, which exceeded the maximum allowed altimetry system error for reduced vertical separation minimum airspace. Therefore, adequate vertical separation with other aircraft was not assured.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by Airwork
Airwork advised that they have taken the following safety actions:
Changed all pitot-static probe covers to Boeing ‑approved recommended covers that are made of heat resistant material (Kevlar™).
They will release a safety statement after every potential safety occurrence as an interim measure prior to the completion of a formal internal investigation.
This occurrence will be included in the Airwork engineering human factors training course.
Airwork engineers conduct safety briefing at the start of the day to identify hazards/risks and control measures to prevent harm. The form used for the briefing was reviewed and additional information was included, providing guided cues for discussions regarding threat and error management, and local hazards.
Ensured that checklists are readily available to use before the commencement of engine ground runs.
Reviewed the change and risk management processes when there is an airworthiness directive.
Published a safety alert around the importance of submitting a safety report as soon as practicable after an event has occurred.
Published a safety alert to engineers and all staff about the importance of using checklists.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
captain
Airwork safety and engineering personnel
Boeing Aircraft Company
recorded flight data
Bureau of Meteorology
Airservices Australia.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the flight crew
Airwork
United States National Transportation Safety Board
New Zealand Transport Accident Investigation Commission
Boeing Aircraft Company
Civil Aviation Safety Authority.
Submissions were received from:
Airwork
Boeing Aircraft Company
the flight crew.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Pilot flying (PF) and pilot monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances, such as planning for descent, approach, and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
[2] Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.
[3] Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 330 equates to 33,000 ft.
[4] In airspace above 29,000 ft, vertical separation requirements are reduced from 2,000 ft to 1,000 ft. For further information, see the section titled Reduced vertical separation minimum airspace.
[5] The autopilot is manually selected by the flight crew to utilise data from air data computer 1 (autopilot A) or air data computer 2 (autopilot B).
[6] N1: Engine fan and low-pressure compressor rotational speed, expressed as a percentage of manufacturer defined revolutions per minute.
[7]Fage, A. (1936). On the Static Pressure in Fully-Developed Turbulent Flow. Proceedings of the Royal Society of London. Series A, Mathematical and Physical Sciences, vol. 155, no. 886, pp. 576–96.
[8] Airworthiness directive: A mandatory regulatory document which requires the registered operator to comply with the requirements to address an unsafe condition on an aircraft
[9] Kevlar: a proprietary high strength, heat resistant synthetic fibre.
[10] Dry motor: turning the engine compressor using the engine starter motor for a defined time, without the introduction of fuel, to prevent engine start.
[11] Traffic alert and collision avoidance system (TCAS): a type of airborne collision avoidance system (ACAS).
[13] Aeronautical Information Publication (AIP) Australia, En Route 1.1 – GENERAL RULES, Section 8 – VERTICAL SEPARATION IN THE AUSTRALIAN FIR, Subparagraph 8.4 – Operational Procedures After Entering the RVSM Flight Level Band – RVSM Approved Aircraft, sub sub paragraph8.4.2 – Failure of One Primary Altimetry System and 8.4.5 – Divergence in Primary Altimetry Systems’ Indication.
On 30 May 2022, freight train 2BS4, operated by Pacific National (PN), departed from Acacia Ridge, Queensland (Qld), for Sydney Freight Terminal, Chullora, New South Wales (NSW).
At approximately 0030 on 31 May 2022, shortly after passing through Kyogle, NSW, a bogie of one empty wagon in the middle of the consist derailed, dragging for approximately 2.3 km before separating from the train. This led to the derailment of 11 empty wagons and caused significant damage to rolling stock and track infrastructure.
What the ATSB found
The section of track in which the initial wagon derailed had a known track geometry defect and was under a temporary speed restriction at the time of the derailment.
The track geometry defect was not subject to increased monitoring beyond routine scheduled inspections and had likely degraded since it was last inspected.
It was found that action taken to manage the geometry defect was largely informal and did not capture the information or data required to allow Australian Rail Track Corporation (ARTC) to make informed decisions on the management of the defect.
The ARTC asset management system, along with track certification forms containing measurements from before and after temporary rectification works, were not used as required by procedures to inform ARTC management that major works were needed.
It was also found that the geometry defect was not included in the plan for major works scheduled for the weekend following the derailment. The corridor management team was intending to rectify the defect during these major works by informally redirecting resources from another job.
Lastly, it was found that while ARTC did have compliance monitoring and auditing procedures in its safety management system, there was no evidence that these activities were being carried out in accordance with the relevant policies and procedures.
What has been done as a result
Following this incident ARTC implemented the Decision Support Platform (DSP), ensuring its availability across the entire ARTC network.
The DSP is described by ARTC as its centralised system for integrating and analysing asset condition data, imagery, and maintenance records, bringing together information from many systems into one source. The platform provides a visual dashboard of asset health, degradation trends, reoccurring issues and risk indicators, enabling more accurate forecasting, supports programs such as resurfacing, grinding and rerailing, and strengthens evidence‑based decision‑making across the entire ARTC network for tasks including:
track geometry analysis for resurfacing activities
track geometry degradation modelling, and
rail height management.
In August 2023, ARTC also established a dedicated engineering function within the Interstate Network Asset Maintenance business unit. This function included a cohort of 8 track and civil engineers to provide technical support for ARTC provisioning centres and maintainers in each section of the interstate network. Part of this function includes the monitoring of track condition and deterioration through physical presence on the AK car track monitoring vehicle and frequent review of defect data and trends, including geometry measurements, ultrasonic test results and Vehicle Track Interaction (VTI) records.
Additionally, ARTC described enhancements to assessment tools for identifying special locations with an increased risk of track instability. The requirements for managing these special locations were defined in the ‘Track and Civil Code of Practice – Section 6 Track Lateral Stability’ and associated procedures. ‘ETP‑06‑01 Managing Track Stability (ver. 1.1)’ was updated to incorporate the use of assessment tools in analysing and identifying potential special locations. An algorithm-based tool, Special Location Identification Program (SLIP), is also used to identify areas that may be classified as Special Locations, based on criteria defined in the relevant standards.
Following an internal assurance audit, ARTC also committed to the following safety actions:
set up an asset integrity risk process to identify critical controls and their owners to mitigate each key risk. This will include an initial assessment of control health and any priority actions required to mitigate the key risks to a tolerable level. This will involve consultation with risk managers and relevant general managers across the organisation.
review and update the operations asset services assurance ‘second line of defence’ guideline. This will be finalised as the ‘Asset Integrity Second Line of Defence Audit Procedure’, and will address accountabilities, authority and linkage to key risks.
The current assurance framework procedure (AMT-PR-017) will be retired, and a dedicated asset maintenance assurance framework document will be created.
It is intended that the ‘Asset Integrity Second Line of Defence Audit Procedure’ will address the use of the enterprise asset management system and its usage for ensuring the data provided adequately informs the DSP, in turn ensuring ARTC is suitably informed of its asset maintenance needs.
Safety message
Asset management procedures and standards exist within a rail transport operator’s safety management system to ensure that assets are managed effectively and safely.
It is vital to the operation of a safe network that standards and procedures are followed, and that rail transport operators assure themselves that asset management activities are being managed in compliance with their procedures to achieve the best possible safety outcomes.
It is therefore essential that rail transport operators also have documented compliance monitoring processes in place, to verify that qualified workers assigned to complete safety critical tasks are consistently doing so, in accordance with standards and procedures, and opportunities for improvement in these areas are addressed.
When used appropriately, asset management systems should accurately inform rail transport operators of the condition of their assets, and enable them to identify recurring issues, assess risk, allocate resources and ensure work is performed to ensure assets are safe and fit for purpose.
Proactive analysis of data providing insight into asset condition and recurring issues is also crucial in managing risk and preventing incidents.
The occurrence
Events prior to the derailment
At approximately 2150 on 30 May 2022 Pacific National‑operated 2BS4 freight train departed Acacia Ridge, Queensland (Qld), for Sydney Freight Terminal, Chullora, New South Wales (NSW).
The crew described the journey as relatively uneventful, aside from receiving an unrelated Condition Affecting the Network (CAN) warning for Casino, communicated to the crew by the ARTC Network Control Officer (NCO) at Junee, NSW.
The track was described as ‘fairly flat’, with no heavy grades, however there were numerous speed boards indicating temporary speed restrictions to observe, which the crew reported was typical for this route.
At approximately 0025 on 31 May, 2BS4 approached a caution board indicating the approach to a temporary speed restriction (TSR). The driver reported slowing the train to between 16 km/h and 20 km/h when entering the 100 m, 20 km/h TSR area at track kilometrage 828.450 km.[1] The driver recalled noticing the track to be ‘visibly kinked’ at 2 locations within this area as they approached.
Although the crew recalled being concerned with the condition of the track, the driver and Driver’s Assistant (DA) believed the existing speed restriction indicated that the condition was being managed and so proceeded through the TSR area at the signposted speed. CCTV footage from the front of the train showed a significant left to right shift and slight dip of the locomotive as it passed over the 2 separate, visible track defects.
Once 2BS4 passed the clearance board indicating the end of the TSR, at approximately 828.350 km, the driver activated a counter on the locomotive control panel to assist in determining when the rear of the train would be clear of the TSR. Once 2BS4 was clear of the 20 km/h TSR, the driver began to accelerate to the 70 km/h posted track speed.
The derailment
At approximately 0030, the driver described an audible warning and a red light on the locomotive’s dashboard, indicating that they had ‘lost the air’, referring to the loss of air pressure in the train’s braking system.[2] This caused the train brakes to automatically apply with the train coming to a stand at the 825.200 km mark.
The driver contacted the Junee NCO to report this unexpected stoppage, informing them that they would attempt to identify the cause with a visual inspection.
The DA exited the locomotive to investigate, walking towards the rear of the train in the down direction, and identified that the train had separated. They then advised the driver that there had been a derailment.
There was approximately 500 metres of separation between the rear of the intact train and the derailed portion. The first derailed wagon identified was positioned sideways across the tracks, with further derailed wagons located on either side of the track.
A total of 11 empty wagons were found to have derailed in the incident, out of the consist of 56.
Figure 1: Top view of derailment
Source: YouTube (Drone footage by Kris McDonald)
Events post-derailment
Following the report of the derailment to ARTC network control from the crew of 2BS4, the line was closed by ARTC at 0102 hours.
Once removed from site, the derailed wagons were transported to a facility at Acacia Ridge for post-incident inspection and analysis.
Track repairs were completed and the North Coast line was certified for rail traffic at 1900 on 5 June 2022 with a temporary speed restriction of 40 km/h.
Context
Location
The North Coast line is a single, bi-directional line with several passing loops facilitating freight and passenger services between Sydney and Brisbane. This line forms part of the North/South corridor on the ARTC Interstate Network. The up direction is travelling towards Sydney, while the down direction is towards Brisbane. The incident occurred at a location known as Cedar Point while travelling in the up direction between Kyogle and Casino on the NSW North Coast.
Figure 2: Map of area
Source: Google Earth, annotated by OTSI
Involved parties
The Australian Rail Track Corporation (ARTC) manages and maintains approximately 8,500 km of rail network across 5 states in Australia. In NSW, ARTC leases the mainline interstate corridors from the NSW Government through a 60‑year lease agreement signed in 2004. ARTC is responsible for managing and maintaining these rail corridors in accordance with its accredited safety management system.
The section of track between Telarah, NSW, and Acacia Ridge, Qld, was managed by a corridor manager based in Coffs Harbour, NSW. A local area manager overseeing the NSW North Coast, specifically Casino/Coffs Harbour including this incident location, was responsible for managing the maintainers and the maintenance and inspection activities they carry out, required for compliance and safety.
ARTC also had an asset management team responsible for asset lifecycle management, including monitoring asset performance and planning and executing major project and/or capital works.
ARTC conducted its own internal investigation into the incident, which was supplied to the ATSB as evidence for this report.
Pacific National (PN) was a freight and coal rail services operator, responsible for moving regional exports, bulk goods, grain, and agricultural products on the eastern seaboard. PN conducted its own internal investigation into the incident, which was also supplied to the ATSB as evidence for this report.
NSW TrainLink (NSWT) was a train and coach operator in Australia, providing passenger services throughout New South Wales and the Australian Capital Territory, along with interstate services into Victoria and Queensland. While not directly involved in the incident on the day, NSWT services to Casino, NSW, and Brisbane, Qld, frequently used the North Coast line in the lead‑up to the incident.
Environmental and weather conditions
The weather on the day of the derailment was clear and sunny with a daytime temperature of 17°C recorded at 0900 by the Australian Government Bureau of Meteorology (BoM) at Casino Airport, NSW, approximately 23 km from the incident location. There was no recorded rainfall in the preceding 24-hour period, however, greater than normal rainfall of 1,187mm was recorded in the local region in the 5 months leading up to the derailment.
Train information
The train consist provided by PN recorded 2BS4 comprised of 3 locomotives hauling 56 wagons. NR89 was the lead locomotive, with NR49 and 9323 assisting. The train was listed as 1199.327 metres in length, with 1728.996 of trailing tonnage. It was hauling a combination of containerised freight and empty wagons.
Train crew
The train crew, consisting of a driver and driver’s assistant, signed on at approximately 2120, with the train departing at 2150. The driver and driver’s assistant each had over 30 years of driving experience and were both qualified and experienced in the operation of the locomotives, and on the route between Acacia Ridge and Sydney Freight Terminal, Chullora, NSW.
Both crew members described being well rested and free from the effects of fatigue on the night of the incident.
Network control
The North Coast Line in NSW was controlled and monitored by the Coast B network control officer (NCO) situated in ARTC’s Network Control Centre South (NCCS) in Junee, NSW.
A system of safeworking known as rail vehicle detection (RVD) was used in the derailment area. This system used continuous track-circuiting or axle counters to detect the presence of rail traffic in a block[3] and prevent following rail traffic entries into the same occupied blocks using signals.
Responsibilities of the ARTC NCO included the planning and management of trains over their area of control, including the control and recording of train performance, and the safe movement of trains and track vehicles in accordance with ARTC safeworking rules and procedures.
Train control reporting
A train control report (TCR) was typically created by network control if an incident or condition affecting the network reported to them was likely to affect train running or was a safety concern.
According to the ARTC enterprise asset management system document AMT‑PR‑010 v1.0 p14, reportable incidents were usually identified by field maintainers, train controllers and train crews. For incidents or conditions reported by train crews the NCO was required to record the information on their train control graph or, where used, in the train register book, and notify the relevant maintainer.
TCR incidents that were related to ARTC managed assets were then required to be added to ARTC’s enterprise asset management system, Ellipse, by the responsible track maintenance personnel as a TCR work request.
TCR work requests included information such as a TCR number, incident type and comments, and a work order number for investigation and review of the asset by maintainers and engineering personnel.
Following a field investigation and a subsequent engineering review, corrective actions were identified and/or undertaken and recorded in Ellipse with failure codes assigned to the known condition.[4] This was done in accordance with ARTC’s code of practice, which prescribed the appropriate course of management for the known condition.
Reporting obligations of train crew
Rules and procedures prescribed by ARTC in ‘ANGE 206 Reporting and Responding to a Condition Affecting the Network (CAN)’ outlined the reporting requirements and obligations of all train crews using the ARTC network, relating to unsafe or abnormal conditions. Conditions that affected the safety of rail operations in the ARTC NSW network were to be reported by crew promptly to the NCO responsible for the affected portion of track.
Pacific National (PN) Learner Technical Guides ‘TLIC 0024 Operate rail traffic with due consideration of route conditions’ and ‘TLIF 0028 Respond to abnormal situations and emergencies’ required PN train crew to report abnormal situations enroute to the network owner.
NSWT drivers were also required to adhere to NSW Trains’ train working procedure ‘NTTWP 100 Responsibilities of Train Crews’. This detailed a driver’s duties including to immediately inform the NCO or any other relevant employees of any incident, problem or defect relating to trains, signalling, track or overhead wiring, or any other problem affecting or likely to affect train services.
NSWT drivers were also expected to adhere to the NSW Trains professional driving guide (PDG). This document advised drivers to report any operational issues that could cause concern to their supervisor and/or to the NCO.
Apart from an initial TCR recorded by ARTC network control in April 2021, only one other TCR was generated for the TSR site on 15 March 2022, approximately 2.5 months prior to the derailment.
There were no other reports recorded as received by ARTC network control pertaining to this site, including on the day of the derailment.
Temporary speed restrictions
ARTC’s engineering procedure for TSRs, PP-163, stated:
infrastructure defects can be detected within the rail corridor during a planned inspection or work process.
The procedure described that:
• all defects that require a temporary speed restriction shall be reported to train control by the person or persons identifying the defect
• when a train crew reports a fault, the network controller shall notify the relevant maintainer and prepare a TCR
• when a train crew reports a fault, the network controller shall notify the relevant maintainer and prepare a TCR
• the maintainer categorises the infrastructure defect condition based on criteria provided in ARTC Track and Civil Code of Practice and ARTC Engineering Standards and determines the speed restriction based on the defect level
• the maintainer estimates response times to conduct an unscheduled inspection or repairs the defect and records this information on ‘PP163F-01, Speed Restriction Notification’ form
• the maintainer positions speed boards around the fault site as soon as practicable (usually within 24 hours) and must notify the network controller immediately of any amendments to TSR’s via the ‘PP163F-01 Speed Restriction Notification’ form to ensure train crews are adequately informed
• the NCO was required to notify the crew of every train passing through the area of the speed restriction until this information was published.
The TSR could be removed once the defect had been rectified, however Engineering (Track and Civil) Procedure ‘PP-135 Mechanised Track Surfacing 7.5 Speed Restrictions – General’ specified that speed restrictions following surfacing, or levelling of track, may need to remain in place if:
• track geometry was inadequate, or there was a risk of a geometry fault developing as the track settled, or
• track lateral stability had been reduced.
In this instance, a 40 km/h TSR remained on several occasions following corrective tamping[5] conducted by the local maintenance crew at the incident location.
Records, correspondence and paperwork related to implementing, altering and the reasons for temporary speed restrictions between 828.350 km and 828.450 km, in the 3 months prior to the derailment of 2BS4 were limited to one ‘PP163F-01 Speed Restriction Notification’ form (Figure 3) along with several track certification forms (see Manual forms).
Figure 3: PP163F-01 Temporary Speed Restriction Notification form
Source: ARTC
ARTC asset management and assurance
Asset assurance framework
ARTC document INF‑PR‑002 Assurance Framework describes the 3‑level assurance framework applied to ARTC’s railway operations risk controls at the time of the incident.
Section 3.1.2, described as the ‘first line of defence’, defines line management monitoring requirements. Each line manager is responsible for determining how assurance reviews are conducted, including sample checks, staff discussions, and team meetings.
Section 3.2, as the ‘second line of defence’, assigns business units responsibility for developing annual assurance plans. For 2021–2022, an Annual Asset Assurance Plan was developed and implemented to monitor asset management activities.
Lastly, Section 3.4, or ‘third line of defence’ outlines that the internal audit plan incorporates all third‑line assurance audits. These audits are intended to provide assurance to ARTC management and the board that effective controls are in place to manage ARTC’s strategic risks. Relevant to asset assurance, the internal audit plan for this period included the following 7 asset maintenance and inspection‑related audits:
HV 02A Inspection and Maintenance – Hunter Valley – Structures Management
HV 02B Inspection and Maintenance – Hunter Valley – Points & Crossings
HV 02C Inspection and Maintenance – Hunter Valley – Level Crossing Management
IS 02A Inspection and Maintenance – Interstate – Structures Management
IS 02B Inspection and Maintenance – Interstate – Points & Crossings
IS 02C Inspection and Maintenance – Interstate – Level Crossing Management
ARTC provided copies of ‘INF‑PR‑002 Assurance Framework’, extract of annual asset assurance plan and extract of the FY22–FY24 internal audit plan which were in place at the time of the incident.
Assurance auditing
At interview, an ARTC representative responsible for management of the corridor between Telarah to Acacia Ridge at the time, indicated that historically, recurring defects had not been recorded very well, and that no proactive analysis was done on potentially recurring defects.
The representative advised that track maintenance and safety‑related decisions were monitored by an assurance process, with an assurance team assigned to do checks on the maintainers. The representative explained these checks covered prework briefings, application of track geometry standards, adherence to procedures, and generally ensuring work was being carried out correctly, with paperwork in place and information recorded correctly.
It was also explained that assurance teams regularly went out and provided coaching if something wasn’t done correctly during regular site visits.
ARTC was subsequently unable to provide any evidence of compliance auditing and/or assurance activities taking place on maintenance personnel responsible for this area.
ARTC track and civil standards and guidelines
Ellipse
ARTC maintained an enterprise asset management system (EAMS) to manage assets throughout their lifecycle and to ensure that assets were fit for safe and reliable operation of trains over ARTC infrastructure. The EAMS was designed to enable ARTC to manage the condition of network infrastructure as described in procedure ‘AMT-PR-010 - Enterprise Asset Management’. The EAMS computerised maintenance management system (CMMS), called Ellipse, was used by track maintenance personnel to record defects and manage maintenance and repairs.
Known conditions, a term used by ARTC to describe known track defects, initiated the bulk of the work orders in Ellipse. Condition data was to be recorded for all known conditions, with any deterioration recorded, including for those conditions which may not have reached a mandatory intervention point but would still benefit from monitoring.
Once entered, known conditions were to be managed in Ellipse in accordance with ‘AMT‑WI-024 Known Condition Management’ by:
recording the appropriate corrective action
determining the urgency of the required work
creating work orders for completion of repairs or condition monitoring activities
planning, scheduling, and assigning of corrective works
developing long term condition-based asset management strategies, and planning capital/project repair works.
The procedure for managing work orders, ‘AMT-WI-025 Work Order Management’, described the process, system (Ellipse) and operational requirements of how to create, plan, schedule, package, assign, execute and close out work.
Work orders were required for all work, and could originate from multiple sources, maintenance schedule tasks (MST), job estimates, known conditions or ad hoc situations.
MSTs were system‑generated tasks, such as track inspections, and were based on predetermined schedules. The works management function within Ellipse was used to initiate and record the process.
Timeframes for these tasks were set out in the code of practice and would vary based on the different types of infrastructure being monitored.
The system provided work orders to support the allocation of budget, the planning of resources, time and materials, and recording the details of works completed. All work performed was to be recorded against the asset in the Ellipse system.
Overall, the EAMS and its associated systems, specifically Ellipse, were intended to monitor scheduled inspections and the status of known conditions and defects to ensure that the planned and corrective work had been completed effectively and in the required timeframe as required by ARTC’s safety management system.
Recording requirements of known conditions
‘ETE-00-02 – Track Patrol, Front of Train, General and Detailed Inspections’ defines requirements for maintainers conducting track inspections to:
record essential information detailing the condition of the track; monitor variations of track conditions over time; prepare priority-based asset maintenance and renewal programs.
It also defines maintainers being responsible for recording and/or reporting the results of their inspections including defects found, and observations made.
This data is then intended to be used to manage the rectification and inform the urgency of corrective maintenance and assists the asset management team in scoping of planned future refurbishment and replacement works, as described in the procedure, ‘AMT‑PR‑010 – Enterprise Asset Management System’.
Manual forms
Manual track certification forms recording completed tamping works were provided by ARTC, showing that the derailment site had been the subject of several maintenance interventions in the months prior to the derailment.
These forms recorded track geometry measurements before and after various rectification works being performed. OTSI observed these forms were often incomplete, with missing details including the absence of sign‑off by a manager or supervisor, while others lacked supporting information to explain the reasons for temporary speed restrictions and other actions taken.
Maintainers conducting track patrols or inspections were required to report the results of their inspections including repaired defects on ‘EGP1001F-01 Inspection/Defects Found Report’ form, either using hard copies or electronic formats.
ARTC indicated that these manual forms were used as there was ‘no IT system per se’ for recording track geometry measurements during track inspections. It was explained that conditions are assessed in accordance with the code of practice and ‘any exceedants (sic) are recorded into the AMS’ (asset management system), in this case Ellipse.
However, when requested, ARTC was unable to provide any inspection forms or evidence of exceedances recorded in Ellipse for the known defects located at the derailment site.
Track and civil code of practice
ARTC track and civil code of practice response booklet ETW-00-01 is a work instruction which includes assessment and response tables to be used as a guideline by maintenance teams when responding to known conditions and defects.
Section 1.1 of this booklet details response codes for defects based on applied speed restrictions. Notes specific to the codes assigned indicate ‘If repairs cannot be made prior to the passage of the next train, the speed restriction should be implemented along with an appropriate increase in the monitoring until actions are taken to restore the track’.
Track geometry
The Rail Industry Standards Board (RISSB) defined track geometry as ‘the horizontal and vertical alignment, cross level and cant of the track’.
Cross level was defined as:
the difference in level of the two rails in a track, and is also known as superelevation or cant.
Top and line
ARTC’s procedures referred to top (vertical alignment), which is the relative level of the track top along the length of the rail. The limit is specified by a measurement of the variation in vertical line (height) of the top surface of the rail.
Figure 4: Vertical alignment – top
Simplified cross section of track structure showing loss of track top geometry measured on the rail head. Source: OTSI
Line measurement, also known as horizontal alignment, was a measure of the horizontal displacement of the track structure from the design alignment (Figure 5).
Figure 5: Horizontal alignment – line
Source: OTSI
Superelevation and twist
Superelevation, also referred to as cant, or cross level on level track, was the difference in height between the outer and the inner rail.
Twist was the variation in the cross level between 2 track locations separated by a nominated distance interval. The maintenance twist tolerances were measured over short (2 m) and long (14 m) distances and were measured in mm (2 m twist measurement shown in Figure 6).
At slow speed on curves, any superelevation (mm) of the outer (high) rail decreases the gravitational forces on the wheels running on that rail because of the lean of the vehicle body and the shift in centre of gravity towards the inner (low) rail. This reduction in wheel load, together with the flange force acting on the outer rail, increases the wheel lateral over vertical (L/V) ratio and so increases the tendency of the wheel to climb the rail.
Figure 6: Cross level and twist
Source: OTSI derived from RISSB Standards
Track geometry standards
ARTC Track and Civil Standard ‘ETS-05-00 Section 5 - Track Geometry’ specified ARTC’s track geometry standards.
The document provided inspection guidelines for track maintainers and track geometry tolerances to be achieved following corrective maintenance tamping activities.
Source: ARTC Engineering Track and Signal Standard – ETS-05-00 Section 5 Track Geometry
The document also provided guidance on geometry parameters including the classification of defects against maintenance limits, and the required response category for the measurement.
Response categories defined the maximum period allowed to elapse before the next inspection, and/or repair of track geometry defects once assessed against specified limits.
The response category was determined by a matrix (Table 2) comparing the measured track defect with normal track speed in the area. A defect in an area with higher track speeds would attract a higher response category than the same defect on track with a lower track speed.
Source: ARTC Engineering Track and Signal Standard – ETS-05-00 Section 5 Track Geometry
The document also described how imposing a speed restriction may moderate the response category, and therefore the response requirements. For example, using a restricted line speed to determine the response category as though it were the original track speed, may reduce the response category and therefore the required inspection time, or delay the required repair. A defect that was re-inspected and found to have not increased in size may continue to be managed in the same way.
Table 3: ETS-05-00 Table 5-16 ARTC inspection and repair response standards by response category
Source: ARTC Engineering Track and Signal Standard – ETS-05-00 Section 5 Track Geometry
Temporary speed restrictions (TSR) could therefore be used to manage and prioritise the inspection and repair of defects.
Use of a TSR to moderate the response category did not require civil engineer approval, and was a common method used by ARTC on the North Coast line at the time of the incident.
It is important to note the defect measurements defined in this guideline were based on isolated geometric defects. However, it also references that a more stringent response may be necessary if deterioration of the infrastructure both at the defect and on adjoining track was evident.
Other related standards
Stable track geometry requires the entire track structure to be designed and maintained to standards. This includes appropriate design and management of the track formation, track structure, ballast, and drainage, taking into consideration local and transient conditions.
ARTC’s ‘RTS 3432, Track Drainage – Inspection and Maintenance’, provided similar guidance on the inspection and maintenance of track drainage as the ETS-05-00 document does for track geometry.
Track drainage is described in this document as necessary, as ‘without adequate track drainage, track formation may become saturated leading to weakening and subsequent failure’, and formation failure may be indicated by ‘repeated top and line problems’ amongst other track instability defects.
Section 5.2.2 described that it is necessary to set priorities for drainage maintenance so that the worst locations can be repaired first, with ratings dependant on a number of factors, including mud pumping through ballast, foul ballast, water ponding and top and line problems. The document also suggested possible remedies for a list of typical problems encountered by type of drainage.
Mud hole guidelines
ARTC’s ‘ETH-10-01 Mud Hole Management Guideline’ described mudholes as ‘areas where ballast had become contaminated with fine materials like dirt or clay’ and provided guidance on the management of mud holes.
The guideline explained that this contamination causes the ballast to retain water, creating a muddy, slurry-like substance around the track sleepers. This mud infiltration can then compromise the stability and integrity of the track structure, leading to uneven track surfaces, reduced load-bearing capacity, with the potential to be hazardous to train operation.
The guideline described the different types of mudholes, their likely causes and possible prevention.
‘Section 3, Assessment of Mudholes’ described that individual mud holes may require ongoing monitoring with increased regular general inspections scheduled.
Ellipse, and the information recorded within it, was to be used for planning and controlling the remedial work in addition to planning and controlling any increased inspections.
Figure 8: Example – soft formation mud hole
Source: ARTC Safety and Systems Track and Civil Guideline – ETH-10-01 – Mud Hole Management Guideline
Ballast code of practice
Similarly, ARTC’s ‘Engineering (Track and Civil) Code of Practice Section 4 Ballast’ specified ballast standards and assessment responses which included increased general monitoring if required.
The standard specified that a knowledge of local factors that may affect the track’s deterioration rate and performance history was required.
If any increased monitoring was determined to be necessary, it would be required to be continued until rectification work was carried out.
Earthworks code of practice
‘Engineering (Track and Civil) Code of Practice Section 8 Earthworks, General Inspection’ specified that scheduled general inspections should be of sufficient detail to observe and document earthwork conditions and changes in condition that affect their vulnerability to instability. This inspection was to include identification of defects and conditions.
General inspections were to be scheduled at intervals appropriate to each location dependant on its nature, condition and other seasonal factors but would not exceed 12 months or as otherwise specified by ARTC e.g. in an approved technical maintenance plan.
Sections of track with identified conditions indicating a vulnerability to earthworks instability were to be nominated and managed as special locations[6] until rectification or earthworks stabilisation work could be carried out. Specialist geotechnical advice together with detailed inspections may have been necessary for this purpose.
Incident site observations and evidence
Track geometry
Onsite photographic evidence of the track at the initial derailment location showed a significant loss of top, line and superelevation/cross level.
Figure 9: Post-incident view of track at point of initial derailment, facing in the down direction
Source: OTSI
There was a sign posted temporary speed restriction in place of 20 km/h between 828.350 km and 828.450 km.
Site photos post‑incident showed significant water saturation of the surrounding area, within the TSR boundaries. There was also notable sinking of the ballast at 2 locations, which had caused visible top depressions of the track.
Figure 10: Post-incident view of track at point of initial derailment, facing in the down direction
Side view of track, demonstrating the loss of top due to sinking soft formation. Source: OTSI
The initial point of mount was located within the TSR at 828.350 km with the wheel flange riding on top of the rail until the initial complete derailment of one bogie (2 wheelsets) at 828.346 km.
Following this derailment, notable damage to track side infrastructure, such as wheel strikes to track sleepers, and impact damage to level crossing plates and guard rails[7] was evident for approximately 2.3 km, indicating that the derailed wagon remained connected to the train for this distance. Significant damage to the wheel treads of 2 wheelsets, examined by the ATSB post‑incident, was consistent with sustained ballast and sleeper strikes.
A final separation event at approximately 826.280 km resulted in the remaining wagons derailing, coming to a rest on the up and down sides of the track.
The front and rear portions of the train which remained on track were then brought to a stand due the subsequent loss of air supply to the train’s automatic braking system following the separation.
Track foundation
ARTC’s post‑incident track condition report noted that ballast condition around the area was observed to be severely fouled and of poor quality, with indications of crushed and undersized ballast, which can decrease water drainage. The formation exhibited areas of saturation consistent with a soft formation defect.[8]
ARTC also noted in their investigation report a drain under the track at 828.420 km that was holding water on the up side (Figure 11). This same drain had water trickling from it on the down side indicating that the formation was holding water.
Post incident, significant saturation within the formation was identified, requiring excavation to obtain a solid foundation on which to rebuild track. (Figure 12).
Track maintenance records for scheduled track inspection and tamping activities that took place at this location prior to the incident made no mention of such significant formation issues, or that soft formation had been considered as the potential cause for repeated track geometry issues (see History and management of track defect).
Drainage culvert directly below initial derailment site (828.420 km) showing pooled water beneath the track and formation. Source: OTSI
Figure 12: ARTC post-incident track works
A significant amount of mud and water was found under the formation during post-derailment rectification works. Source: ARTC
Track geometry measurements post‑incident
Post‑derailment track measurements taken by ARTC, and noted in its internal investigation report, detailed that the track exhibited a significant loss of top track geometry at 2 locations within the TSR with depressions of approximately 150 mm.
Also, track measurements taken between 828.300 km and 828.509 km recorded a combination of twist and superelevation track geometry defects consistent with an E1 category defect as per ARTC Track and Civil Standards. An E1 Category defect required that the track be inspected and repaired prior to the passing of the next train.
Figure 13: Onsite track geometry measurements
Track measurements taken onsite post ‑incident, detailing point of mount, locations of categorised track geometry defects, temporary speed restriction limits and infrastructure details. X‑axis details track measurement station numbers at 2 m intervals from the point of mount at 0. Y‑axis details distance measurement in mm. Source: ARTC Data (graph constructed and annotated by OTSI)
Derailed wheels and bogie inspections post‑incident
Wheel profile measurements were taken by the ATSB at Acacia Ridge following the relocation of the derailed bogies and wheel sets.
Wheel flange[9] height, angle and width measurements were taken with a standard wheel gauge (shown in Figure 14). The examined wheel sets were found to meet the operator’s minimum standards, although one wheelset was identified to have a flange width of 19.5 mm, close to the thin flange defect limit of 19 mm.
This wheelset also exhibited some evidence of arrises[10] on both flanges, although these were also noted as being within tolerance, being less than 1.5 mm in height.
Figure 14: Wheel limiting dimensions
Wheel condemning operational limits are guided by an industry code of practice. Measurement of derailed wheelsets. Source: Rail Industry Standards Board (RISSB) Wheel defects code of practice and ATSB
The wheel tread condition of the derailed bogies was also examined and identified bogie RRXE 649 (lead bogie of the 29th vehicle RQRY 1011W) had sustained the most damage.
A general inspection of that bogie was also carried out and did not identify any bogie suspension, bogie rotation or wheel tread defects outside of the rolling stock operator’s safe operational standard.
Technical maintenance plan (TMP)
‘ETP-00-03 Civil Technical Maintenance Plan’ set out ARTC’s routine inspection requirements for rail track and civil infrastructure in terms of mandatory inspection tasks and inspection intervals. The TMP specified:
which items were to be inspected
what inspection tasks were to be carried out
when inspection was required.
The inspection tasks and inspection intervals defined in this document were mandatory for all ARTC managed track.
The TMP referenced the applicable standards documents, manuals and codes of practice for the associated infrastructure element.
The TMP also contemplated that additional inspection scope or increased frequencies may be required in response to infrastructure condition or accelerated deterioration rates, noting that increasing frequencies could be authorised by the local maintenance management team.
The factors below are what ARTC recommended should be considered when increasing inspection frequencies:
fixed points within the local area (e.g. bridges, turnouts, etc.)
previous track history
effectiveness of local drainage
curves
existence of adjacent or multiple mud holes in the track sections.
These factors were to be considered to assist with the management of local conditions in accordance with the applicable standards and ensure that inspection and measurement of track geometry was done often enough to detect geometry defects and manage any deterioration.
ARTC Track and Civil Standard ‘ETE-00-02 – Track Patrol, Front of Train, General and Detailed Inspections’ set out the standards for the track and civil inspections which were to be carried out on ARTC track and civil assets. ‘Section 3’ detailed the types of inspections, such as track patrol and front of train inspections (see Types of inspections). It describes the purpose of each of these inspections, along with the scope, and reference to the applicable asset element maintenance standard.
‘Section 2.2’ detailed the related responsibilities for maintenance personnel conducting track inspection activities and included specific responsibilities for the corridor manager, area manager and maintenance personnel, and the recording and reporting requirements for individuals in these roles.
It was also specified within this document that during track patrol inspections, specific locations may be subject to General inspection. General inspections were typically visual and included the elements of a track patrol inspection plus inspection of all readily visible elements of the infrastructure and elements known to contain critical defects.
An up-to-date defect list and a list of specific locations requiring attention was recommended to be obtained prior to carrying out the track patrol. Specific attention was to be paid to any deterioration at known defect locations.
Types of inspections
The types of inspections carried out on the ARTC network are detailed in Table 4:
Table 4: ARTC inspection guidelines
Type
Frequency
Method
Scheduled track patrol inspection (Walking or on‑rail vehicle)
All main lines at intervals as specified in the approved Technical Maintenance Plan not exceeding 7 days where not specified.
Loops at intervals as specified in the approved Technical Maintenance Plan not exceeding 28 days where not specified [2]
Visual inspection
On-rail vehicle ride where used
Manual measuring equipment as required
Scheduled on train inspection
All main lines as specified in the approved Technical Maintenance Plan not exceeding 6 months where not specified
Visual inspection
Vehicle ride
Scheduled track geometry car inspection or equivalent
All main lines as specified in the approved Technical Maintenance Plan not exceeding 4 months where not specified
Crossing loops as specified in the approved Technical Maintenance Plan not exceeding 24 months where not specified.
Measuring car with ability to measure gauge, top, horizontal alignment, cross level, short twist, and long twist
Record type, size and location of defects
Un-scheduled inspection in response to defined or other events
As necessary to ensure safety where for any reason (e.g. slips, floods, earthquakes, driver reports, irregularity reports etc.) it may be suspected that the geometry may have been significantly affected.
As required
Source: ARTC Track and Civil Standard – Section 5 Track Geometry (Table 5-13 - Inspection Guidelines)
AK car inspections and data
The ARTC AK car[12] was a set of 3 converted passenger carriages equipped with technology to measure and record track geometry. The cars travelled over the ARTC standard gauge network measuring safety‑critical track parameters.
ARTC supplied data from Ellipse for all track inspections conducted between 13 April 2021 and 31 May 2022 near the derailment site. Three separate AK car inspections were conducted on 22 September 2021, 19 January 2022 and 11 May 2022.
No track geometry exceedances were detected by the AK cars on these occasions in the area where the derailment occurred, between 828.350 km and 828.450 km. There were defects of varying degrees recorded by these AK car runs in the areas surrounding the initial derailment location. The closest to the derailment site was one gauge exceedance located at 828.254 km, approximately 150 metres from the site of the derailment of 2BS4.
The PP163F-01 speed restriction notification form for track between 828.350 km – 828.450 km (the initial derailment site) recorded tamping and resurfacing was performed on 29 April 2022, with an amended 40 km/hr speed restriction applied to the area.
The 40 km/h TSR remained in place at the time of the AK car inspection on 11 May, with the speed board visible on the AK car end of train track recording CCTV.
The PP163F-01 speed restriction notification form showed that on 26 May, 5 days before the derailment, the speed was reduced from 40 km/h to 20 km/h, citing poor track geometry as the reason for this further reduction.
The Ellipse system did not contain any track measurement data, or further information pertaining to these activities.
Noting that a speed restriction was in place when the AK car inspection was conducted, OTSI queried whether the track speed was materially important to the accuracy of the AK car’s track geometry readings. ARTC confirmed in writing that the speed at which an AK car is travelling does not affect its ability to detect rail geometry defects.
Specifically, ARTC indicated that there was not an optimal speed at which an AK car is required to travel to record accurate track data.
Track maintenance
Tamping
Spot tamping (tamping of short lengths of track to improve track geometry or remove specific defects), took place using an excavator with a fitted tamping attachment. This process involved the working and compressing of ballast into the voids beneath sleepers, intended to make the formation more stable and durable. This type of work is generally conducted by the local maintenance team and intended to correct minor defects or temporarily correct track geometry issues.
The ARTC document ‘Engineering (Track and Civil) Procedure PP-135 Mechanised Track Surfacing’ provided technical and operational procedures for mechanised track surfacing, including planning and carrying out surfacing, additional requirements for special situations, description of surfacing machines, guidelines for the operation of surfacing machines, and was referenced in conjunction with ARTC ‘Track and Civil Code of Practice – Track Geometry’.
Engineering (Track and Civil) Procedure ‘PP-135 Mechanised Track Surfacing 2.1 Planning’ detailed that in planning, consideration should also be given to the available budget allocations, and the capabilities and/or limitations of the equipment to be used. In line with this procedure, it would need to be determined during planning by the maintainer whether or not the use of certain methods and equipment for corrective works were appropriate for the task.
Considerations when planning this work should aim to minimise the amount of between ‑cycle spot tamping and/or speed restrictions.
Role requirements of a track maintainer
ARTC described[13] that a track maintainer was required to:
• Implement track maintenance, conduct mandatory systematic inspection, examination, condition monitoring and functional checks on the rail infrastructure and take appropriate action to ensure rail infrastructure was in a safe operational condition, including recording and reporting of defective infrastructure to maintain a valid defect recording system.
During interview the maintenance work group leader described being satisfied with the management of this defect using temporary speed restrictions and monitoring, however described:
The section of track as ‘worse’ in comparison to others.
They noticed that defects at the location would routinely reappear within weeks, sometimes days, of corrective works being undertaken.
They were unclear in their requirement to permanently record information and observations relating to the changing track condition, and where hard-copy forms and notes were stored once submitted.
They were unclear what the process was for escalation should they be concerned about a defect that was consistently deteriorating.
While information was recorded sporadically across multiple entries pertaining to the defect at the initial derailment location, no specific information detailing the recurring fault, deterioration of track, specific corrective actions, TSR implementations or increased monitoring was recorded in the asset management system by the maintainers or area managers responsible for this location.
Project request and possession planning
The corridor managers responsible for infrastructure maintenance were required to submit requests for major works to the asset management team for approval and incorporation into the Asset Management Plan (AMP).
Managers used data and dashboards generated from records in Ellipse to recognise trends and patterns to identify areas on the network that required further investigation and/or major works, and also to prioritise these works.
Requests for work were therefore generated from information in Ellipse recorded by the maintenance team.
Requests for work were required to be supported by appropriate evidence, such as:
known conditions recorded in Ellipse
information on the overall condition of the asset
any other pertinent factors.
Requests for work that were approved by the asset management team were recorded as projects in the AMP interim database. Work Requests (or projects) residing in the AMP interim database were then reviewed and validated by the relevant stakeholders as part of the annual condition inspections.
Planned works of this nature were typically performed under Local Possession Authority (LPA), where a line is closed for a designated period of time, which required significant planning to be submitted and approved under the AMP before budgetary allocations and resources could be determined.
Procedures which define the process of identifying and authorising track access to the ARTC Network, including for possession work, were outlined in ARTC’s Corridor Access Management Procedure – COR-PR-028’. The procedure applied to ARTC workers, contractors doing work for ARTC, and third parties who enter the ARTC Network, and specified the requirements for planning to execute the work safely, and to keep the worksite safe including the method of protection to be used.
ARTC described the procedure as aiming to:
improve safe and effective track access
improve the efficiency of work and minimise impact on train running by effective planning of work, minimising mobilisations and maximising the use of track time
provide details on how we plan on undertaking the work in a safe environment
provide the ability to view all work in the Rail Corridor and address unauthorised access to keep all our staff, contractors and third-parties safe
provide an integrated work plan, providing visibility of what work is occurring, where and when, removing the need for phone calls to provide this information.
Prior to 31 May 2022, no project work requests or formal possession planning had been generated, submitted or undertaken for work to be performed at the site of the derailment of 2BS4.
History and management of track defect
ARTC records indicated a significant increase in maintenance activity at the derailment location in the 2 months prior to the incident. A combination of temporary speed restriction records, tamping activities recorded in the Ellipse system and a train control report were noted in response to known geometry defects at this location. However, there was minimal detail on what was found or what actions were taken in many of these records.
Approximately 13 months prior to the derailment on 13 April 2021 the driver of NSWT XPT service NT31 reported rough riding due to a suspected dip in the track between approximately 828.300 and the 828.500 km mark near Kyogle. The condition was investigated by an ARTC maintainer later that day. The defect was determined to be in tolerance to continue with normal train running, however it was recorded that it would require repairs, and a work order to schedule and complete this work was raised the following day.
Temporary repairs were conducted at this site on 16 April 2021, described in the work order as ‘tamp, line and box up with excavator’, indicating that an excavator was used to correct the alignment of the track and formation supporting it.
Further repairs were conducted at this location on 19 April 2021 under the same work order, where a 40 km/h temporary speed restriction was implemented. This was noted on the track certification form to remain in place for one week, however the 40 km/h TSR remained on this location until 25 May 2021.
It was not noted or explained in the records why the TSR was to remain in place at the conclusion of the work, or why it remained in place for this amount of time.
Following these corrective actions, scheduled track inspections were conducted in this area, at an average interval of one week with the longest gap recorded as 8 days. These scheduled track inspection intervals were compliant with procedures. No further observations or references to any track geometry defects were recorded in the Ellipse asset management system against the assigned jobs for any of these inspection activities, aside from the closing of each work order to indicate the job was complete.
Approximately 2.5 months prior to the derailment a front of train inspection[14] was conducted on 7 March 2022, followed by another scheduled track inspection on 11 March 2022, neither of which recorded any issues with the track.
On 15 March 2022 the driver of Pacific National train 2SB3 reported to the Junee NCO a track geometry issue at 828.400 km at Kyogle. The train was reportedly travelling at 55 km/h before reducing speed after encountering the defect. There was no temporary speed restriction in place at the time with the speed posted at 70 km/h for freight trains for this section of track.
A maintainer attended the defect location 30 minutes after the report and determined that the track would require adjustment and tamping. A 40 km/h temporary speed restriction was implemented. No track measurements were put on record to support this decision.
A scheduled track inspection took place on 18 March 2022, which recorded no issues or defects. There was no record of any works being done between the maintainer’s inspection on 15 March, that identified defects, and the scheduled track patrol on 18 March.
On 23 March 2022, a 20 km/h temporary speed restriction was implemented at this location, with the reason described in the speed restriction notification as ‘poor top and line’ (see Top and line). No other details or measurements were recorded in Ellipse or supplied to support this action, and scheduled track inspections immediately after this activity did not contain any further information.
Several more repair activities occurred at this location over the next 2 months, prior to the derailment, with limited detail recorded on what was done and why. The activities included track tamping conducted on 11 April 2022 and 21 April 2022. The work order related to the most recent TCR was closed, and subsequent scheduled track inspections provided no further detail on the condition of the line.
The area was again tamped with a resurfacing machine on 29 April 2022, one month prior to the derailment, and a 40 km/h temporary speed restriction was implemented. This was described in the ARTC ‘PP163F-01 Speed Restriction Notification’ as ‘tamped by resurfacing machines’, however, no documentation or measurements were provided to support this.
On 26 May 2022, temporary repair works were conducted at the site. A 20 km/h temporary speed restriction was implemented following this work and noted on the track certification form as due to ‘formation issues’, with sections of this form also incomplete. This was described in the ARTC ‘PP163F-01 Speed Restriction Notification’ as ‘poor track geometry’. No further documentation or recorded information was supplied.
The final scheduled track inspection prior to the derailment was recorded in the ARTC asset management system as ‘fully complete’ on 27 May 2022, with no details of the track condition or any restrictions in place at this location, although the 20 km/h temporary speed restriction remained in place at this time, and the previous day’s track certification form showed defects remained in the track geometry.
Figure 15: Extract track certification form
Track measurements before and after corrective works on 26 May 2022 showing outstanding defects. Source: ARTC
Table 5: Notable dates in management of track defect
13 April 2021
Driver NT31 reports ‘rough riding between 828.300 and 828.500 kilometre mark near Kyogle.
16 April 2021
Temporary repairs – ‘tamp, line and box up with excavator’ completed
19 April 2021
Further repairs conducted, 40 km/h TSR implemented
25 May 2021
40 km/h TSR lifted
Regular inspection schedule maintained with minimal recorded observations
7 March 2022
Front of train inspection conducted, no defects recorded
11 March 2022
Scheduled track inspection conducted, no defects recorded
15 March 2022
2SB3 reported track geometry issue to at 828.400 km at Kyogle. 40 km/h TSR implemented – inspected, no measurements recorded
18 March 2022
Scheduled track inspection conducted – no defects recorded
23 March 2022
20 km/h TSR implemented described in the speed restriction notification as ‘poor top and line.’ No further information.
11 April 2022
Track tamping conducted, no details recorded
29 April 2022
Track tamping conducted – 40 km/h TSR implemented, no details recorded
26 May 2022
20-km/h TSR implemented following partial repair – track certification form and speed restriction notification describes ‘poor track geometry’
27 May 2022
Scheduled track inspection marked as ‘fully complete’ – no details of existing TSR or track defect
31 May 2022
2BS4 derails within the 20 km/h TSR location
Although this section of track demonstrated it was vulnerable to earthworks instability, by way of repeated track geometry defects, and subsequent excavator tamping activities, ARTC did not provide evidence that the area was subject to any increased monitoring by the maintenance crew.
There was also no evidence of changes to the standard inspection schedule, engagement of specialist geotechnical analysis or advice, or that the site had been nominated as a special location for additional attention.
Regulatory oversight
The Office of the National Rail Safety Regulator
The Office of the National Rail Safety Regulator (ONRSR) was the regulatory agency for rail in Australia. It was not a government agency, but an independent body corporate established under the Rail Safety National Law Act 2012. Its functions were to regulate the rail transport industry in Australia through its rail safety accreditation regime and the Rail Safety National Law (RSNL). ONRSR set requirements for rail safety management systems (SMS), conducted compliance activities including audits and inspections, and enforced the RSNL.
ONRSR routinely issued guidelines on its website designed to provide key information and clarification to both the rail industry and public on legislative, regulatory and technical matters associated with safe railway operations.
Asset management guidelines
ONRSR Guideline – ‘Asset Management, 13.3 Asset operation and maintenance’ stated in part that Rail Transport Operators (RTOs)[15] ‘should monitor ongoing compliance with their nominated standards and processes in order to ensure that their railway operations continue to be safe and perform efficiently.’
Also, ‘planning should be documented and controlled in a computer maintenance management system’ and that all maintenance tasks are signed off for compliance.
This document also detailed requirements for ‘monitoring asset performance’, ‘failure management and corrective action’ and the management of the life cycle of assets, such as track and signalling infrastructure.
ONRSR also expected RTO’s such as ARTC to have in place:
evidence of ongoing compliance with the RTO’s nominated standards and processes, and management of identified risks
asset maintenance plans and procedures
evidence of identifying and eliminating safety risks
evidence of reporting and managing any performance issues and corrective actions
evidence of the use of trending performance against the predicted strategic life of an asset for tracking performance and planning for renewals
processes for identifying faults and failures and undertaking corrective action
evidence of the consideration of asset management in SMS provisions for: security and emergency management, notifiable occurrences, and interface management.
Safety management systems guidelines
ONRSR Guideline – ‘Safety Management Systems, 6.10 Safety audit arrangements’ described the requirement for a documented internal audit program which is focused around auditing those processes of the SMS which pose the greatest risk to safety.
ONRSR Guideline – ‘Safety Management Systems, 6.20 Process control’ described the requirement to ensure the organisation has a system to define, control and manage the operational and engineering processes to ensure assets are fit for purpose for rail infrastructure and rolling stock operations.
As a minimum ONRSR would expect:
Records of inspections are kept and form the maintenance history of the asset to confirm:
effective monitoring to ensure compliance to standards, operating rules, processes and procedures
the date the inspection has been carried out and by whom
the defects or non-conformances detected (location, description)
defects or non-conformances have been reported for rectification
defects are prioritised, safely managed and reviewed until rectified
condition of the infrastructure/rolling stock (and any restrictions) has been reported to staff responsible for the day’s operation
defects are rectified, checked and dated by staff with the competence and responsibility for ensuring assets are returned to service fit for purpose
the maintenance work carried out on each asset (both routine and rectifying defects) has been recorded (e.g. a maintenance log for each asset)
assurance that technical maintenance plan requirements are met, and the review of work order process or inspection test plan process is undertaken to demonstrate evidence of work being conducted as per standards
back to service, monitoring of human performance, random audits and inspections and other safety observations
that general engineering and operational system safety requirements are complied with.
ARTC indicated that it had various activities and functions in place related to the monitoring and oversight of maintainers responsible for the NSW North Coast corridor, however ARTC was unable to supply any evidence of maintenance team compliance audits or assurance activities specific to this area.
Other standards and guidelines
The Rail Industry Safety and Standards Board
The Rail Industry Safety and Standards Board (RISSB) was a non-government, member ‑based, not-for-profit that developed Australian standards, guidelines, codes of practice and rules on behalf of the Australian rail industry.
RISSB supported the rail industry’s regulation model by providing standards, guidance, and advice which helps industry prove that it is meeting its safety obligations.
RISSB Infrastructure Standard ‘AS-7635 – Track geometry’ was developed to specify track geometry standards for design, construction, commissioning, monitoring, maintenance, and modification of rail tracks in Australia. ‘Section 4 Monitoring and maintenance, 4.1 Inspection’ – frequency and tasks stated ‘at locations with a known history of geometry defects, the frequency of inspections should be increased as determined by the Rail Infrastructure Manager (RIM), or ARTC in this instance.’
When describing the management of track defects using TSR, ‘Section 4.2.1 Speed restriction’ stated ‘speed restrictions may be used to manage the risk from track geometry defects, enabling the increase of timeframes for required response actions’.
The standard advised caution was required though when using speed restrictions to manage twist and cyclic defects, as lower speed can increase the likelihood of vehicle dynamic derailments and makes further mention when discussing geometry defects that reducing speed could increase the risk of derailment.
This guideline also advised that a combination of defects that are considered to act together should also require a more stringent response.
‘Section 4.2.3 Repeat faults’ recommended ‘the RIM may consider a mechanism for monitoring repeat track geometry faults, defined as those recorded during consecutive track inspections. For those sites where the geometry fault has increased in magnitude it is advisable for a supervisory site inspection to be conducted, to ensure that the right method of correction is applied’.
Similar occurrences
RO-2019-004 Derailment of Pacific National coal train MR280 – Baerami, New South Wales, on 6 February 2019
At 0325 Eastern Daylight saving Time on 6 February 2019, a Pacific National loaded coal train, MR280, travelling from Moolarben to Kooragang Coal Terminal, derailed near Baerami on the Ulan branch line on the Hunter Valley Network. All wheels of the leading bogie of the 88th wagon derailed and travelled in a derailed state for approximately 1.83 km. As the derailed train reached the points of the Baerami crossing loop, another 5 wagons derailed and 3 wagons rolled on their side, narrowly missing a stationary empty coal train UL369.
It was considered that the contributing factors to the derailment were a result of individual actions, where personnel had not executed the intent of the ARTC code of practice and/or had not followed procedures as required. As a result of this, and the safety actions taken by ARTC, the ATSB considered it was unlikely that further investigation would identify any systemic safety issues or further important safety lessons for the enhancement of transport safety and the investigation was discontinued.
In response to the incident, the ARTC took safety action, including implementing a daily ‘known conditions review’ meeting at all provisioning centres so that call outs, TCR’s and known conditions could be frequently reviewed with other current information and ensure appropriate controls were in place for the management of defects
RO-2017-014 Derailment of grain train 8838N – Narwonah, New South Wales, on 1 October 2017
On 1 October 2017, a Pacific National loaded grain train 8838N was travelling on the ARTC rail network from Nevertire to Manildra in north-west New South Wales. The train consisted of 2 locomotives and 23 wagons. The train was travelling south at Narwonah when 11 loaded grain wagons located at the rear of the consist derailed. An emergency brake application occurred due to the uncoupling, which brought the front portion of the train to a stand. There were no injuries but there was substantial damage to 9 wagons and track infrastructure.
There were track defects identified in the vicinity of the derailment site prior to the derailment, and the maintenance of defects in this section of track was not successful in preventing the defects from re-occurring.
ARTC committed to several safety actions as a result of this incident, including changes made to the ARTC maintenance system to address systemic issues. ARTC also commenced a work program titled ‘Asset management improvement program’, which focused on improving the functionality of the enterprise asset management system and its supporting business processes.
Safety analysis
Introduction
On 30 May 2022, freight train 2BS4, operated by Pacific National, departed Acacia Ridge, Queensland, for Sydney, New South Wales. The train consisted of 3 locomotives and 56 wagons, hauling a combination of containerised freight and empty wagons.
At approximately 0030 hours on 31 May 2022, while traversing the North Coast line between Casino and Kyogle, New South Wales, 2BS4 encountered a temporary speed restriction of 20 km/h. While passing through this area, a wagon in the consist derailed, dragging for approximately 2 km, where the train then parted and a total of 11 wagons derailed.
It was determined that 2BS4 initially derailed due to a combination of track geometry defects, in an area under temporary speed restriction.
This safety analysis will discuss the track defects responsible for the derailment, and how the condition was being managed, including the use of ARTC’s enterprise asset management system.
Wheel examination of derailed vehicles
Due to the extensive damage to wagons, bogies and track infrastructure it was unable to be determined exactly which wagon separated from the consist first. However, it was likely, due to the damage observed on its wheelsets, that wagon number RQRY1011W, the 29th wagon in the consist, initially partially derailed at the TSR site and dragged for approximately 2.3 km before derailing completely, pulling the 28th wagon RKBY20455Q away from the consist. Once the wagons separated from the front of the train, the momentum of the trailing wagons has then contributed to the subsequent derailment and pile up of the remaining vehicles.
Wheel profile measurements taken by the ATSB at Acacia Ridge following the relocation of the affected bogies and wheel sets measured for flange height, angle and thickness with a standard wheel gauge. The overall condition of the examined wheel sets was found to meet the operator’s minimum standards for safe operation.
One wheelset of bogie RRXE 649 was noted to have the flanges close to the thin flange defect limit of 19 mm and exhibited an arris on both flanges. This type of wheel tread condition was indicative of a bogie with a higher angle of attack, with this likely to produce an increased lateral flange force on the outside rail head in a curve.
However, that condition was unlikely to have been a major factor in contributing to the derailment, as the flange steepness (worn but also within the operator’s standard for safe operation) likely counteracted the effects of an increase in lateral flange force arising from a higher angle of attack.
All bogies were also found to be within minimum operating standards.
Track geometry condition at derailment site
A combination of multiple short and long twist E1 track geometry defects were found at the initial derailment site, along with 2 top defects in the vicinity of the point of mount.
Had these defects been detected prior to the passage of 2BS4, ARTC would have been required to rectify the defects prior to the next train in accordance with their Track and Civil Standard (Table 3).
From the evidence obtained it is likely the derailment occurred due to a combination of track geometry conditions (multiple E1 short and long twists) that resulted in rolling stock wheel unloading, wheel climb onto the rail head and subsequent derailment of both wheels of a single bogie on vehicle RQRY 1011W.
The derailment mechanism was consistent with the outer (high) rail wheels unloading on a single bogie at slow speed that was progressing into a curve with too much superelevation. Those conditions were likely to have decreased the force on those wheels leading to wheel climb and subsequent derailment. The multiple E1 twists over the TRS limit could also have induced vehicle body roll in advance of the point of mount further contributing to the wheel unloading experienced.
The track geometry conditions were due to a soft formation issue at the site as evidenced by poor ballast condition, water saturation, and repeated track geometry issues.
The resulting degradation of the track structure at multiple locations prior to the derailment point of mount was considered to have resulted in both track top and alignment defects on the day, sufficient to initiate the derailment.
Although the contribution of the rolling stock/track interaction was unable to be quantified, the extent of the track structure defects and the rate of their apparent deterioration following maintenance interventions became the central focus of OTSI’s investigation to identify safety learnings.
Progression of track formation defect
Observations of train crew
The driver’s assistant of 2BS4 recalled in interview that the track was worsening in condition since their last trip through the area approximately one week before and described this crossing as far worse than previous trips.
The driver’s assistant described that, in their experience, a 20 km/h speed for this defect was not acceptable, and they had intended to report to network control that the track should have been closed, had the derailment not occurred.
The driver of a previous train to traverse this section the day before described it in interview as the worst TSR they had ever seen in their time, although explained that drivers are generally not qualified to make judgements on whether a track should remain open.
The driver of 2BS4 suggested that, in their opinion, the track should have been closed to rail traffic and assessed, describing visible track geometry issues as it was traversed.
All train crew interviewed in relation to this incident confirmed a worsening of the condition of the track in comparison to their last trip and considered the track to be of an unacceptable standard.
Although there were no train control reports received by network control in the days preceding the derailment of 2BS4, it was suggested by various train crew in interview that driver reports for the same track faults repeatedly, especially when it is being managed by an existing speed restriction, were not taken as seriously by network control and generally not followed up.
It was also suggested that drivers would typically be less likely to report a track defect that is under some form of speed restriction, as this would indicate that the issue with the track has been identified by ARTC and was ‘being managed.
Progression of defect
A track certification form indicated that a temporary and partial repair was conducted at the derailment location on 26 May 2022, 4 days prior to the derailment. This form noted that the track geometry post‑corrective action was suitable for full track speed but also recorded that the repair did not fully rectify the track defects at this location to desired limits after corrective maintenance (see Table 1). Despite the geometry being noted as suitable for full track speed, a 20 km/h temporary speed restriction was put in place citing ‘TSR imposed due to formation issues’. This level of speed restriction on a compliant track indicates that the maintenance team had assessed that the formation issues were severe and the geometry defects likely to re‑occur.
According to ARTC Track and Civil Response Booklet (ETW-00-01), ‘increased monitoring should be continued until rectification work is carried out’. Although the rectification work conducted on this day did not repair the defect, and a speed restriction remained in place, no further inspection or monitoring of this site was conducted, and no further information was entered into the EAMS to suggest that there was a concern over the condition of the track at this location.
Several of the characteristics identified by ARTC as typical of mudholes, or underlying soft formation issues, were consistent with the conditions observed by maintenance personnel in interview and train crews traversing this section of track. Those conditions included water saturation, failing formation and general track instability. However, the area was not subject to any additional monitoring in between routine scheduled inspections.
From the last temporary repair on 26 May 2022, until the derailment, 24 trains traversed this section of track. All trains using this section of track in this timeframe were doing so under a 20 km/h speed restriction, concluding in the derailment of 2BS4, 4 days later.
Rapid deterioration of track geometry had been identified on at least one prior occasion, reported by train crew between the scheduled track monitoring cycle of 7 days, with the train crew’s report resulting in corrective action.
It was likely that the soft formation defect has caused the track geometry to degrade to an unsafe condition in the 4 days following the track’s last repair and inspection, unbeknownst to ARTC in the absence of heightened monitoring or further repair.
Contributing factor
2BS4 derailed on a section of track which had progressed to an unsafe condition since the partial correction of a recurring defect 4 days earlier. The defect had a known history of recurrence but was not subject to increased monitoring.
Planning for rectification works
ARTC advised that a track possession had been planned in which the work intended to correct the soft formation was scheduled to take place. However, ARTC was unable to supply documentation and pre-planning paperwork to support these plans, or evidence that the defect area concerned was included in any plans for the planned possession window. It was found during further investigation that no such documentation existed, and no formal planning had taken place.
Track inspection activities and temporary repairs to the track were not carried out in a systematic manner with inconsistencies in accompanying paperwork. This included track certification forms which were submitted with incomplete track measurements, ambiguous or absent descriptions of work completed, and the absence of manager or supervisor sign-off.
It is unlikely that the information contained within the asset management system alone would have been sufficient to determine the extent of the issue, nor would it have provided the corridor or asset manager with an accurate indication of what resources, such as personnel and equipment, would be required to repair the defect, with no verifiable record of information to inform the severity of it.
Defect management records
OTSI’s review of maintenance records and track measurements taken before and after tamping activities by ARTC found that the TSR location had a history of significant superelevation/cross level loss prior to the derailment, but little information on the defect itself.
ARTC’s maintenance team managed the track defect between 828.350 km and 828.450 km by repeated temporary corrective maintenance and temporary speed restrictions.
However, track condition was not recorded in Ellipse pre or post these activities or recorded after scheduled maintenance activities.
The recording of track conditions within ARTC’s Ellipse system and detailed track inspection records was required by the ‘AMT-PR-010 Enterprise asset management system’ procedures. These records were required to support work requests to the asset management team and to prioritise major works.
The maintenance work group leaders stated lack of familiarity with ARTC’s specific recording and escalation process, (see also Recording requirements of known conditions), along with ARTC’s inability to locate manual defect records likely impeded the dissemination of the defect details, and escalation within the organisation, hindering the ability of management to respond appropriately.
Information that should have been recorded in the Ellipse system as required by ARTC’s procedures may have been used to identify the deteriorating condition and instigate further investigation into the track geometry issues or initiate more stringent monitoring. However, in this instance, that information was either not recorded, or not available to provide reliable insight into the track condition.
Corrective works and tamping
There was no evidence that planning or assessments had taken place in accordance with Engineering (Track and Civil) Procedure ‘PP-135 Mechanised Track Surfacing 2.1 Planning’ to support the ongoing use of tamping at the derailment site.
According to the procedure consideration should be given to the capabilities and/or limitations of the equipment being used.
The recurrence of track defects at the same location over a period of at least 12 months was an indication that the spot tamping approach was insufficient to address the repeated track geometry track defects, and that further exploration of the underlying cause was required to manage the defect.
Track possession planning
In interview, ARTC senior management representatives acknowledged not being fully across the severity of the issue but explained that there was a plan to undertake further corrective work in an upcoming possession window.
In its investigation report ARTC also document that ‘plans to undertake corrective works on the embankment formation were in place to occur on the weekend of 4 and 5 June 2022’.
However, no documentation or formal submission was supplied to the ATSB to support these statements.
ARTC acknowledged in a further information request that the detailed planning for the formation reconstruction had not been completed prior to 31 May 2022. ARTC representatives described in interview that the actual plan was to reallocate resources from a nearby planned track possession and conceded that the necessary pre‑possession work rectification planning for this specific defect had not been completed.
An ad-hoc planning method was therefore being used to scope major works on the line. This may have compromised ARTC's ability to ensure work was being performed as per ARTC’s code of practice and in accordance with its asset management plan, and redirected resources assigned to repair another defect without appropriate risk assessment and prioritisation.
Methodical planning and documenting of planned track work, such as that described in ‘Corridor Access Management Procedure - COR-PR-028’ was, according to ARTC, essential to ensuring that the efficiency and integrity of the work can be monitored and adhered to, and the correct and necessary safety measures specific to the work location and environment can be implemented prior to work commencing. This planning was to ensure that all risks associated with planned work were accounted for and eliminated or mitigated where possible.
Insufficient planning, scoping and resourcing had the potential to increase the health and safety risk to workers and create inefficiencies in work conducted when necessary and essential pre-work planning and risk assessment was not carried out.
Contributing factor
In the absence of appropriate records in the asset management system, no formal planning was in place to permanently rectify the known defect, which was in a state of deterioration.
Detection and management of recurring defects
Track maintenance activities prior to incident
Evidence collected by the ATSB has indicated that scheduled track inspections were carried out in accordance with ARTC code of practice, although there was no evidence of increased monitoring of this site.
There was no indication from information supplied by ARTC that these routine track inspections were detecting anything out of the ordinary occurring with this section of track, which is inconsistent with other sources of information supplied, indicating an increase in corrective work surrounding this defect.
For instance, irregular tamping activities took place to correct track geometry faults on numerous occasions, however evidence supplied to support the decision‑making behind these activities indicated an absence of information which would otherwise allow ARTC to make fully informed decisions.
Enterprise asset management and Ellipse
The information entered into the ARTC Ellipse system relating to work undertaken onsite did not inform responsible personnel that this recurring fault required special attention.
There was no detailed information found in asset management system records, against any of the scheduled track inspection activities at this location. An increase in tamping activities and a greater reliance on temporary speed restrictions may have indicated a more serious issue, which would normally have triggered a more stringent response. However, nothing was noted in these records which indicated it had been raised as a concern.
Speed restrictions were implemented in response to the track condition, however, specific details relevant to the defect were not recorded in Ellipse. Scheduled track inspections conducted immediately before and after tamping, and the introduction or removal of speed restrictions, also recorded no information on the defect.
If track measurements were undertaken by civil staff to determine the level of response required for this defect, details of these were not recorded in the Ellipse asset management system.
The repeated implementation of a 40 km/h TSR at this location following corrective works indicates that the civil representative responsible for this location reasonably anticipated a recurrence of the fault, and that track stability was reduced or compromised. The information describing and explaining this action, however, was not documented in Ellipse as required on any of these occasions.
It was not clear based on the evidence supplied how the data that was retained from track patrols, inspections or corrective works could have informed ARTC of the presence of a defect which could be considered problematic or recurring. The information recorded was not in compliance with the requirements of ARTC’s ‘AMT-PR-010 – Enterprise asset management system’ procedure.
With the limitations in data and information available in the Ellipse system in this case, it is unlikely that ARTC would have had a reliable and informative data set to highlight the necessity for increased monitoring of this defect, and or significant repairs, allowing the underlying soft formation condition to continue to degrade.
This hindered the ability for the necessary planning and resource allocation to take place, as the information needed to inform ARTC of the scale of work and resources required was not accurate, and in some cases non-existent.
These issues with record keeping, the quality of inspections and appropriate repair had been identified previously by the ATSB as safety issues requiring action based on previous similar incidents (see Similar occurrences), specifically the ATSB Narwonah investigation report identified similar issues such as:
ensuring that defect rectification work is undertaken to an acceptable quality
ensuring that inspection activities are thorough
network issues are captured within ARTC’s enterprise asset management system for planning and future rectification
interrogating network data to identify where reoccurring issues are developing and request project work to rectify.
Contributing factor
ARTC did not reliably identify, monitor and analyse recurring track defects which resulted in a reduced capability to:
monitor deterioration of the track
recognise the need to conduct increased unscheduled track patrols
identify capacity to plan for its corrective maintenance. (Safety Issue)
Monitoring and oversight of maintenance activities
Auditing and assurance of maintainers
Along with ARTC’s assurance framework and audit plan (see Asset assurance framework), to ensure the compliance of their maintainers conducting work on rail infrastructure and to inform corridor management on their effectiveness and performance ARTC detail their activities included:
daily visual management centre (VMC) toolbox meetings
scheduled and unscheduled inspections
TCR and train control rail event functions
It was explained that this was how ARTC ensured work was being carried out ‘effectively’. However, no evidence was provided to demonstrate these assurance activities were being carried out, nor any evidence that they had been formalised in documents or procedures.
ARTC relied on a task being marked as complete within the asset management system to validate that the work was completed, with minimal follow up and verification of this task completion.
There was no evidence of any previous auditing activities on rail maintenance personnel conducting rail maintenance tasks in the North/South corridor, suggesting that any safety actions taken in response to previous incidents have likely been implemented in an informal manner.
This informality did not support a proactive approach to managing potential safety issues in the rail corridor, such as the treatment of track defects.
The lack of evident auditing or verification of effective maintenance activities has resulted in a limited visibility at an organisational level within ARTC that the scheduled and unscheduled maintenance tasks being carried out were achieving the desired result. This did not provide the organisation with adequate insight into the thoroughness of its track inspection activities.
Informal meetings and discussions would not provide sufficient assurance that maintainers were applying the appropriate methods to reduce risks, or carrying out essential tasks to completion without a formal auditing or checking system in place as prescribed in the ONRSR guidance, especially where detailed data is lacking.
Contributing factor
While ARTC had a process for monitoring its maintainers when carrying out inspections and rectifications, it was unable to provide evidence of these activities being conducted. (Safety Issue)
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the derailment involving Pacific National freight train 2BS4, near Kyogle, New South Wales, on 31 May 2022.
Contributing factors
2BS4 derailed on a section of track which had progressed to an unsafe condition since the partial correction of a recurring defect 4 days earlier. The defect had a known history of recurrence but was not subject to increased monitoring.
In the absence of appropriate records in the asset management system, no formal planning was in place to permanently rectify the known defect, which was in a state of deterioration
ARTC did not reliably identify, monitor and analyse recurring track defects which resulted in a reduced capability to:
monitor deterioration of the track
recognise the need to conduct increased unscheduled track patrols
identify capacity to plan for its corrective maintenance. (Safety issue)
While ARTC had a process for monitoring its maintainers when carrying out inspections and rectifications, it was unable to provide evidence of these activities being conducted. (Safety issue)
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
ARTC ability to detect and manage recurring defects
Safety issue description: While ARTC had a process for monitoring its maintainers when carrying out inspections and rectifications, it was unable to provide evidence of these activities being conducted.
Glossary
AK car
Track inspection vehicle
Alignment
May be referred to as horizontal or vertical alignment. Horizontal alignment is the design horizontal alignment of track (i.e. straights, curves, etc.), vertical alignment is the design vertical alignment of track (gradients and vertical curves).
Bi-directional Line
A section of track where rail traffic can run in either direction
Bogie
A structure incorporating suspension elements and typically fitted with wheels and axles, used to support rail vehicles at or near the ends and capable of rotation in the horizontal plane.
CAN
Condition affecting the network
Cant
Also referred to as superelevation, is used for intended height difference in the rails (i.e. where the track is inclined in a curve), and the term 'cross level' is used for the unintended height difference (i.e. due to track irregularity). The term used to denote the raising of the outer rail on curved track to allow higher speeds than if the 2 rails were level. Cant compensates for the centrifugal force arising from a train traversing a curve.
DA
Driver’s Assistant
Derailment
An incident in which one or more wheelsets run off the track.
EAMS
Enterprise asset management system
Line
Horizontal alignment of the rails. Line is generally measured using the offset at a defined point along a chord of defined length. For vertical alignment, see top.
LPA
Local possession authority
Maintainer
ARTC infrastructure staff or contractors who detect and repair any defective infrastructure asset
MST
Maintenance schedule tasks
NCO
Network control officer
ONRSR
Office of the National Rail Safety Regulator which accredited the light rail operator under the Rail Safety National Law NSW 2012
RIM
Rail infrastructure manager
RTO
Rail transport operator
RVD
Rail vehicle detection
SMS
Safety management system
Superelevation
Also referred to as track cant, is used for intended height difference in the rails (i.e. where the track is inclined in a curve), and the term 'cross level' is used for unintended height difference (i.e. due to track irregularity). The term used to denote the raising of the outer rail on curved track to allow higher speeds than if the 2 rails were level. Cant compensates for the centrifugal force arising from a train traversing a curve.
Tangent Point
The intersecting point of track center-line tangents between curves, transitions and straight track.
TCR
Train control report
TMP
Technical maintenance plan
Top
Vertical alignment of the rails. Top is generally measured using the offset at a defined point along a chord of defined length. For lateral alignment, see line.
Track gauge
The distance between the inside running (or gauge) faces of the 2 rails making up track, measured between points 16 mm below the top of the rail heads.
Transition curve
A curve of uniformly varying radii used to connect straight and curved tracks or curves of different radii.
TSR
Temporary speed restriction
Sources and submissions
Sources of information
The sources of information during the investigation included:
the driver and driver’s assistant of 2BS4 and another driver who conducted operations for Pacific National
Australian Rail Track Corporation (ARTC)
ARTC North / South rail corridor asset maintenance services personnel
ARTC network control graphs and audio recordings
Pacific National
Bureau of Meteorology (BOM)
Office of the National Rail Safety Regulator (ONRSR)
Rail Industry Safety Standards Board (RISSB)
New South Wales TrainLink
Australian Transport Safety Bureau (ATSB), and previous ATSB rail investigation reports
track maintenance data and track inspection footage
ARTC network rules, procedures, standards and guidelines
front-of-train CCTV footage, onboard event recorder and onsite photographs
Google Earth.
References
ARTC Track and Civil Standards
ARTC Asset Management Procedures and Work Instructions
ARTC Train Control Reports
ARTC Safety & Environment Investigation Report- Derailment of Train 2BS4 826.350 km Kyogle, NSW- 31 May 2022- TCR 6218 2022
RISSB Infrastructure Standard – AS 7635:2023 Track Geometry
ONRSR Guideline - Asset Management
ONRSR Guideline – Safety Management Systems
ONRSR Safety Message: Ad hoc systems and procedures vs Safety Management Systems
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Australian Rail Track Corporation (ARTC)
Pacific National (PN)
NSW TrainLink (NSWT).
Any submissions from those parties will be reviewed and, where considered appropriate, the text of the draft report will be amended accordingly.
A submission was received from:
Australian Rail Track Corporation (ARTC).
The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.
Rail safety investigations in New South Wales
Most transport safety investigations into rail accidents and incidents in New South Wales (NSW) and Victoria are conducted in accordance with the Collaboration Agreement for Rail Safety Investigations and Other Matters between the Commonwealth Government of Australia, the State Government of NSW and the State Government of Victoria. Under the Collaboration Agreement, rail safety investigations are conducted and resourced in NSW by the Office of Transport Safety Investigations (OTSI) and in Victoria by the Chief Investigator, Transport Safety (OCI), on behalf of the ATSB, under the provisions of the Transport Safety Investigation Act 2003.
The Office of Transport Safety Investigations (OTSI) is an independent statutory body which contributes to improvements in the safety of bus, ferry and rail passenger and rail freight services in NSW by investigating safety incidents and accidents, identifying system-wide safety issues and sharing lessons with transport operators, regulators and other key stakeholders. Visit www.otsi.nsw.gov.au for more information.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
Investigations under the TSI Act do not apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings.
Under the TSI Act investigations endeavour to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner.
TSI Act investigations are not for the purpose of taking administrative, regulatory or criminal action.
About ATSB reports
ATSB investigation reports are organised with regard to international standards or instruments, as applicable, and with ATSB procedures and guidelines.
Reports must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner.
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Commonwealth Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this report is licensed under a Creative Commons Attribution 4.0 International licence.
The CC BY 4.0 licence enables you to distribute, remix, adapt, and build upon our material in any medium or format, so long as attribution is given to the Australian Transport Safety Bureau.
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1]The km distance is measured from Platform 1, Central Station, Sydney, New South Wales.
[2]When the air pressure is lost, the brakes automatically apply to stop the train as a safety measure.
[3] Block: a portion of track with defined limits, usually denoted by fixed lineside signals, between which only one rail traffic movement is permitted at any one time.
[4]A ‘known condition’ is defined by ARTC as a shortcoming or imperfection with an item of equipment, component or part, that may or may not need work or monitoring.
[5]Tamping: a process involving ballast being packed around the sleepers of a track to ensure correct track geometry.
[6]Engineering (Track & Civil) Code of Practice Section 8 Earthworks, 8.3.1 special locations are defined as track sections prone to (e.g. with a history of) earthworks instability.
[7]Guard rails (also known as restraining rails, check rails, or girder rails) are placed inside or outside the running rails, designed to restrain lateral movement of a train’s wheels if it derails, keeping it aligned with the track and preventing it from falling off or damaging nearby infrastructure.
[8]Soft formation of ballast is denoted to occur when there are inadequate drainage systems causing water to accumulate in the track bed, saturating the ballast and subgrade. When these materials become waterlogged, they lose their strength and become soft and depress to form a puddle under the ballast. The ballast sinks into the formation and this leads to loss of track geometry.
[9] Flange: protruding portion of the wheel profile which provides lateral restraint and guidance on the rail.
[10]Arrises: raised lips on the top of the wheel flange caused by metal flow.
[11]The term used to describe the vertical movement of a section of track due to the force of rolling stock traversing it
[12]The AK car was also referred to as a ‘continuous track geometry recording car’,
[14]A front of train (FoT) inspection is an inspection which assists in the assessment of track by enabling the reaction of trains to the track structure to be experienced. The inspection is to be carried out from the Driver’s compartment of the fastest train over the length where this is practical to gather information about infrastructure defects or condition.
[15]Rail Transport Operators defined by Rail Safety National Law and includes Rail Infrastructure Managers (RIMs) such as ARTC.
On 27 May 2022, a Singapore Airlines Airbus A350-941, registered 9V-SHH, was being prepared for a regular public transport flight from Brisbane Airport, Queensland to Changi Airport, Singapore. Just prior to the aircraft being pushed back for departure, a refueller on an adjacent bay informed the licenced aircraft maintenance engineer responsible for the aircraft turnaround that the pitot probe covers were still fitted. Subsequently, the covers were removed just before pushback.
What the ATSB found
The ATSB found that the procedural risk controls for the removal of the pitot probe covers were circumvented when a licenced aircraft maintenance engineer certified for the removal of the covers in the technical log and removed a warning placard from the flight deck without visual or verbal confirmation that the covers had been removed.
Further, a final walk-around of the aircraft by maintenance personnel to ensure it was correctly configured for flight was also not conducted. This represented the last procedural opportunity to identify that the covers had not been removed. Similarly, it was established from closed-circuit television footage of Singapore Airlines turnarounds at Brisbane Airport that the majority of flight crew pre-flight inspections observed around the time of this occurrence were truncated and not undertaken in accordance with company procedures. This included the occurrence flight.
The ATSB also identified that Heston MRO had not yet implemented an acceptable method for accounting for tooling and equipment prior to aircraft pushback, although this had been identified as a safety issue in investigation AO-2018-053. Also, Heston MRO did not track the work hours of personnel who had dual roles within the company for fatigue management purposes, even though there was a requirement in the fatigue management policy to do so.
Lastly, the pitot probe covers fitted to the aircraft were about 3 m above eye height and had relatively short streamers, which were not conspicuous and limited the possibility of incidental identification.
What has been done as a result
Heston MRO no longer requires the Brisbane regional manager position to undertake dual responsibilities, which included aircraft maintenance certification requirements, Further, Heston MRO now tracks the work hours of all employees for fatigue management purposes.
Singapore Airlines has communicated with flight crew about the requirements of their pre-flight walk-around checks and why they are important. In addition, Singapore Airlines has also provided Heston MRO at Brisbane with pitot probe covers that have longer streamers to ensure better conspicuity.
Safety message
Airspeed is a critical flight parameter, which is particularly important to flight crew during take-off and initial climb. It is the basis for their awareness of flight conditions such as the approach of aerodynamic stall and determination of critical decision points. This occurrence demonstrates how assumptions and procedural omissions can lead to unsafe conditions. In this case, the potential for an aircraft to commence a take-off with erroneous or absent airspeed indications due to the pitot probe covers remaining fitted.
Fatigue is a known factor in maintenance errors and can have a range of adverse influences on human performance. Therefore, it is important that organisations appropriately track all hours worked by safety critical employees to ensure they are receiving adequate rest and safeguard against the effects of fatigue.
Finally, this investigation recognises the positive actions of the refueller, who was working on the adjacent bay and had identified that the pitot covers remained fitted. This serves as a reminder that all line personnel have a safety role and should always speak up if they see or feel that something is not right.
The occurrence
On 27 May 2022, a Singapore Airlines Airbus A350-941 aircraft, registered 9V-SHH, was being prepared by maintenance personnel on bay 81 for a regular public transport flight from Brisbane Airport, Queensland to Changi Airport, Singapore, as flight number SQ256.
The engineering maintenance contractor had provided a licenced aircraft maintenance engineer (LAME) and an aircraft maintenance engineer (AME) to conduct its regular receipt, dispatch, certification, and maintenance duties during the aircraft’s scheduled 2-hour turnaround. The LAME (who was also the regional manager) was supervising the AME and assisting with the turnarounds of SQ256 and another aircraft on an adjacent bay. The AME had started with the contractor 3 weeks prior and had not completed all their induction training. On the day, the AME was conducting headset (turnaround coordinator) duties.[1]
Closed-circuit television footage from bay 81 showed that, between 0705 and 0727 local time, the LAME instructed the AME through the external walk-around inspection of the transit check for the aircraft. At 0732, the AME utilised an elevated work platform to install covers on all 4 pitot probes[2] in accordance with airline and company procedures specifically for Brisbane Airport. At about the same time, the LAME entered the flight deck to check the technical log for defects. As part of the pitot cover installation and removal procedures, the LAME made an entry in the technical log that the covers had been fitted and then placed a warning placard on the flight deck engine control pedestal to also show that the pitot covers were fitted.
Between 0852:18 and 0854:03, the first officer conducted a pre-flight walk-around. The walk‑around was truncated from the nose of the aircraft to the right engine, across to the left engine and back to the airbridge. From the footage, the first officer looked up at and likely observed the fitted pitot covers, however, they were required to be fitted at that time as per the operator’s procedure.
At 0859, the LAME arrived back on bay 81 after tending to an aircraft on an adjacent bay. The LAME conferred with the AME about fuel figures and talked to the flight crew via headset to confirm the fuel upload.
About 5 minutes later, the LAME re-entered the flight deck, certified for the transit check in the technical log, cleared the technical log entry for the fitment of the pitot covers, and removed the pitot cover warning placard from the flight deck pedestal. The LAME then returned to the tarmac and placed the placard on the dashboard in their work vehicle.
At 0913, the LAME returned to the tarmac at the nose of the aircraft and conversed with the AME for about 3 minutes. With 4 minutes remaining until the expected pushback[3] time, the LAME told the AME that they were going to the adjacent bay to complete the refuelling of another aircraft. The AME remained at bay 81 to conduct the pushback headset duties (Figure 1).
Around this time, anaircraft refueller on an adjacent bay observed that SQ256 appeared ready to pushback, but the pitot covers were still fitted. When the LAME reached the aircraft at the adjacent bay, the refueller immediately pointed to SQ256 and informed the LAME that the covers were fitted (Figure 2).
Figure 1: Security footage of bay 81 showing SQ256 4 minutes before pushback with the pitot covers fitted and the LAME moving towards the adjacent bay
Source: Brisbane Airport Corporation, annotated by the ATSB
Figure 2: Security footage of the refueller pointing towards SQ256 and informing the LAME that the pitot covers were fitted
Source: Brisbane Airport Corporation, annotated by the ATSB
The LAME returned to SQ256 and alerted the AME that the pitot covers were still fitted. At about the same time, the flight crew requested pushback approval from air traffic control and turned on the aircraft beacons. The aerobridge began to retract away from the aircraft.
The flight crew then notified the AME on the headset that they were ready to pushback. The AME, having just been informed that the pitot covers were fitted, told the flight crew to standby as they were in the process of removing the pitot covers.
With 2 minutes remaining until the expected departure time, the LAME positioned an elevated work platform on each side of the nose and removed the pitot covers (Figure 3).
Figure 3: LAME removing the pitot covers
Source: Brisbane Airport Corporation, annotated by the ATSB
Context
Operator information
Operator arrangements for support services at Brisbane Airport
Much like other international airlines, Singapore Airlines had significantly scaled back services to Brisbane during the COVID-19 pandemic (2020 to 2021), halving its services from 28 to 14 flights per week. The airline had increased services to Brisbane to 21 flights from March 2022.
Singapore Airlines’ Brisbane Airport engineering services were contracted to Heston MRO. The requirements for the services of Heston MRO were also significantly reduced across all airlines it serviced during the pandemic. Therefore, its workforce was significantly reduced, and the remaining engineering staff had their hours decreased considerably. In 2022, when the Australian Government opened its borders to international travel, Heston MRO abruptly returned to normal operations, which equated to a significant increase in demand from airlines requiring their service.
Maintenance personnel information
Licenced aircraft maintenance engineer and regional manager
Qualifications and experience
The LAME joined Heston MRO in July 2021 and had licence coverage on several large aircraft and engine types, and extensive line maintenance experience over several years. The LAME’s main role was as the regional manager for south-east Queensland. In that role, the LAME was responsible for managing engineering operations for Heston MRO at Brisbane, Wellcamp and Gold Coast airports. The LAME also had responsibilities that included certification requirements at Brisbane Airport, storage and movement of aircraft at Wellcamp, and regular LAME functions when there were unscheduled LAME absences.
72-hour history
The LAME indicated that, in the 72-hours prior to the occurrence day (on Friday), they had:
About 6 to 7 hours sleep on Tuesday after a workday average of 12 hours.
On Wednesday, the LAME covered work spanning 2 shifts. One was conducting the return to service of an aircraft at Wellcamp with a commute starting at 0530 and a return to their residence at 1700. The second shift was line duties to cover another LAME’s absence starting at 1900 and working until midnight. Following those shifts, the LAME estimated that they had about 6 hours sleep.
On Thursday, the LAME reported that they worked from home conducting administration duties and slept for about 7 hours before the occurrence shift.
On Friday, the LAME commenced work at 0630.
During interview, the LAME was asked about their level of fatigue on the day of the occurrence utilising an alertness scale. The scale estimated alertness using descriptive anchors numbered from 1 to 7, with 1 being fully alert and 7 being completely exhausted. The LAME stated that they varied between 4 to 6 on the scale but seemed to be ‘moderately tired and let down’ on most days, which is 5 on the scale.
Dual roles
In 2022, the LAME/regional manager's dual roles progressively became more demanding as turnaround services increased, and aircraft were being removed from storage post COVID-19. They were recorded in the roster as working 7.5 hours, Monday to Friday. However, they reported that their workdays were often up to 12 hours with work also being conducted on weekends. Further, in their capacity as a LAME, conducting turnarounds was often required to cover shifts for other LAMEs due to sickness. For example, they reported that they had recently covered a shift for another LAME, following their own long workday. That workday exceeded the maximum work hour requirement and prescribed rest period between shifts.
The LAME also described that they seemed to be constantly in the state of being ‘moderately tired and let down’ due to the demands of their dual roles. The LAME mentioned that family and friends had expressed concern about the LAME’s stress levels and the amount of work they were doing. An internal company report into the occurrence had also noted that the LAME stated:
They could not remember the last time they had a full day of rest. In their own words, ‘’even when at home, they were working to catch up with their duties’’.
The report concluded that:
Based on the statements provided, [the LAME] seemed distracted. It is not clear if this was due to the activities that he assisted the Malaysian Aircraft with or if [they] were struggling with fatigue.
As Heston MRO did not track the LAME’s work hours for fatigue monitoring purposes (as per Heston MRO fatigue management policy, refer to section titled Heston MRO fatigue management program) the ATSB was unable to fully ascertain the extent of the LAME’s level of fatigue and how it may have affected their performance.
Aircraft maintenance engineer
The aircraft maintenance engineer (AME) joined Heston MRO 3 weeks prior to the occurrence and had a total of 2 weeks line experience with the company. The AME had completed a partial induction program, and training that included coordination/headset duties. Prior to joining Heston MRO, the AME had experience working on defence and civilian aircraft (not including the Airbus A350) conducting heavy maintenance. Some turnaround functions were conducted for a period of 6 months, although this was 2 years prior to the occurrence.
An internal Heston MRO report post-occurrence identified that, while the AME had completed a partial induction program and other training, they should not have been undertaking tasks unsupervised.
The AME reported that, on the day of the occurrence, they had just returned from 2 days off, were alert and well rested.
Pitot probes and covers
Pitot probes
Pitot probes (or part of the multi-function probes) are components of the aircraft’s pitot-static system. The Airbus A350 has 4 probes, which are attached to the nose of the aircraft (Figure 4). The pitot probe consists of a tube pointing directly into the airflow, measuring the stagnation pressure called total pressure. This total pressure information and the static pressure delivered by static ports on the fuselage are used to compute the aircraft’s indicated airspeed and Mach number. If the tube is partially or completely blocked, airspeed indications will be inaccurate. Airspeed is a critical parameter for flight.
Figure 4: Airbus A350 aircraft showing left side probes with covers fitted
Source: Airbus
Contamination by mud wasps at Brisbane Airport
Historically, mud wasps have been known to build nests in aircraft pitot probes, entering through the forward-facing opening. Nesting and food material placed in the tube blocks the probe, to the point where it may no longer provide accurate airspeed information. A partial blockage, such as that resulting from the first addition of mud for a nest in the pitot, may be enough to cause anomalous airspeed readings as air flow is disturbed.
The Civil Aviation Safety Authority airworthiness bulletin02-052 (Issue 6) Wasp Nest Infestation – Alert, stated that the potential for pitot probe contamination may arise within 20 minutes of availability. There may not be external signs of the presence of a nest or partial nest within the probe, and there have been numerous occurrences at Brisbane Airport where pitot probes were blocked during turnarounds. For that reason, the Brisbane Airport Corporation recommended the use of pitot probe covers during turnarounds.
Pitot probe covers
Pitot probe covers provide protection from foreign object obstruction when the aircraft is on the ground. The need for pitot probe covers is dependent on several factors, such as the duration the aircraft is on the ground, and local factors such as wildlife and weather. There may be a formal requirement by operators to fit pitot probe covers in these circumstances. As pitot probes are heated in-flight, maintainers need to wait 15-30 minutes for them to cool after landing before fitting covers (Airbus 2016).
Pitot probe covers typically incorporate a ‘remove before flight’ warning streamer (also known as a flag or ribbon) intended to alert relevant personnel of its presence. Several characteristics contribute to the conspicuity of the streamer. Red streamers can provide effective contrast against a white fuselage in good light but may not be as attention-attracting in poor lighting such as night, especially when they are dirty. Reflective materials may be helpful at night.
Another factor is length. Streamers come in various lengths, but its visibility may be improved by fitting an extended streamer or incorporating a lanyard between the cover and its streamer. Shorter streamers are less likely to draw a person’s attention when in their visual field even if they are not paying particular attention to that area. A longer streamer, or one with a lanyard, is more likely to move if wind is present. However, it has been reported that the greater force on longer streamers in strong winds can occasionally drag the covers off.
Figure 5 shows standard pitot probe covers fitted to the lower probes of an Airbus A350, which were estimated to be about 3 m above eye level. The Heston MRO internal report into this occurrence noted that:
The Pitot Cover streamers used at the station were short. They are not long enough to bring about attention to passers-by below the aircraft – refer photos [attached as Figure 5].
Heston MRO and Singapore Airlines had a procedure for the installation and removal of the pitot covers at Brisbane Airport, which is summarised as follows:
During the arrival procedures and after a short period of pitot cool down time, all pitot covers will be fitted.
A warning placard will be placed on the flight deck pedestal stating that the pitot covers are fitted (Figure 6).
An entry will be made in the aircraft technical log stating that the pitot covers have been fitted.
The pitot covers are to be removed no earlier than 30 minutes prior to departure or as directed by the customer (Singapore Airlines is 20 minutes prior to departure).
Following pitot cover removal, the entry in the aircraft technical log can then be closed and the placard removed from the flight deck and returned to the transit toolbox in accordance with Heston MRO’s transit toolbox procedure (below).
Figure 6: Flight deck warning placard
Source: Heston MRO
A review of the closed-circuit television (CCTV) footage for several Singapore Airlines turn arounds showed that the pitot covers were removed, on average about 30 minutes prior to departure, with the latest removal (other than the occurrence turnaround) being 15 minutes prior.
On the day of the occurrence, the LAME had placed the warning placard in the flight deck when the pitot covers were fitted. About 10 minutes prior to departure, CCTV footage showed that the LAME re-entered the aircraft. The LAME removed the warning placard and closed out the entry in the technical log. The CCTV footage also showed that, after leaving the aircraft, the LAME placed the placard on the dashboard of their vehicle rather than the tool control container.
The LAME stated that they had not verified that the pitot covers were removed or requested that the AME remove the covers. However, when the LAME closed out the technical log entry, they had assumed the AME had removed the covers by that time. The AME reported that they had previously been told by another LAME that they should not remove the pitot covers without being instructed to do so and therefore had not removed them.
Transit toolbox procedure
Heston MRO had a documented tool control procedure, which required maintenance personnel to:
record the removal of company tooling from its storage location, and
account for all tooling prior to certifying an aircraft for release to service and at the end of a shift.
It was the responsibility of the regional manager to review the movement of tooling and if any tooling was not returned to its storage location at the end of a shift it was to be recorded in a shift handover diary.
Heston MRO supplied basic tooling specific to aircraft turnarounds in a transit toolbox. This included a headset to communicate with the flight crew, marshalling wands, and a steering bypass pin[4] specific to an aircraft type. Additional items such as pitot probe covers and remove before flight placards could be added to the transit toolbox as required. The relevant procedure required the toolbox removal from its storage location be recorded, and for its return to be recorded along with a condition check of the items it contained. At the time of the occurrence, there was no requirement to check the toolbox for its contents (including pitot covers) before an aircraft was dispatched.
General tool control procedure
Heston MRO had a general tool control procedure in its operational procedures manual titled Maintenance Certifications and Certificate for Releaseto Service, which stated:
A certificate for release [CRS] to service will only be issued after all tooling and equipment used in the maintenance event has been accounted for and removed from the aircraft. The certifier is to ensure that the aircraft has been returned to its original airworthy state before issuing the CRS.
Turnaround inspection procedures
Introduction
There were 4 walk-around inspections required between the aircraft’s arrival and its dispatch. These were the:
post arrival walk-around inspection conducted by maintenance personnel (sometimes incorporated into the transit check)
external component of the transit check conducted by maintenance personnel
external component of the pre-flight inspection conducted by one of the flight crew
final walk-around inspection conducted by maintenance personnel (sometimes included as the final component of the transit check).
Post arrival check
The purpose of this inspection is to identify if there are any defects on the aircraft before or during the flight rather than during the post-flight ground handling functions.
Transit check
Singapore Airlines’ procedures dictated that the aircraft undergo a transit check (a type of engineering general inspection) while in Brisbane. This required certification in the technical log when completed.
The transit check procedure began with tasks mainly related to verifying the aircraft’s airworthiness, and later tasks were primarily concerned with verifying the aircraft’s general condition (that no damage had been incurred during the turnaround) and readiness for flight. The final components of that inspection included the below.
Following the aircraft refuelling, the transit check takes on a preparation for flight aspect to ensure that the aircraft is correctly configured for flight. The inspection titled Final included:
• Remove the protective covers from the aircraft (if installed).
• Record the Transit Check in the aircraft technical log. Make sure an authorized person releases the aircraft [This is the point where the LAME certifies that the transit check has been conducted].
• Ensure Technical Log, Cabin Defect Log, IFE Defect Log, all Deferred Defect Logs, Refuelling Log, Notes To Pilots and Engineers (NPE) and Maintenance Work Sheets are reviewed and completed as necessary. Ensure spare logs stowed on board [This is the point where the LAME certifies for the pitot cover removal].
• Perform final aircraft walk-around:
◦ Make sure that all crew doors, cargo compartment doors and service panel doors are correctly closed and secured.
◦ Make sure that no damage has been caused by ground equipment, during loading and/or servicing. …
Flight crew pre-flight inspection
Singapore Airlines’ procedures stipulated that flight crew must conduct an exterior aircraft inspection (walk-around) about 30 minutes prior to departure. The procedure required that, during the walk-around, flight crew focus on safety critical areas of the aircraft to ensure:
…the general condition of the aircraft is satisfactory and that the visible aircraft components and equipment are safe for the flight…
Maintenance personnel usually inspect the aircraft before the flight. In the absence of maintenance personnel, a flight crewmember performs this walkaround before the flight. Items marked by (*) must be performed again by a flight crewmember before the flight.
The procedure required the extremities of the wings, airframe, and tail section to be inspected. Figure 7 shows the path that flight crew should take when conducting the pre-flight walk-around inspection. The numbers represent pause points to inspect a particular section of the aircraft, and each are associated with certain check items. One of the items to be checked was the condition of the pitot probes. As per the procedure, some of the items did not require checking if they were already inspected by maintenance personnel. However, the inspection path to be followed remained the same.
Figure 7: Schematic showing pre-flight walk-around path in blue with pause inspection points numbered
Source: Singapore Airlines
Maintenance final inspection
A final walk-around inspection of the aircraft was required by Singapore Airlines and Heston MRO procedures. The final walk-around was the responsibility of the headset/turnaround coordinator (the AME) or the turnaround supervisor (the LAME) after all the passenger and cargo doors were closed. It can be combined as part of the final transit check inspection, which was certified by the LAME. The final walk-around inspection was the last opportunity to ensure:
there were no aircraft defects or damage
foreign objects were not located near, in or on the aircraft
doors and panels were secure
all covers and pins were removed.
There was also a reference to check for pitot cover removal in the Heston MRO departure procedures for Brisbane Airport, and the training and testing documentation for dispatching an aircraft.
The AME reported that they completed the final walk-around inspection. However, a review of CCTV footage showed that, while the AME had removed the aircraft chocks, they did not complete the inspection as per the procedure. Likewise, the LAME was not observed conducting the inspection.
Review of other walk-around inspections
A review of the CCTV footage of 5 Singapore Airlines turnarounds at Brisbane Airport around the time of the occurrence showed that none of the pre-flight inspections conducted by flight crew (including the occurrence flight) followed the complete path in accordance with the above procedure. As per Table 1, some of the inspections were substantially truncated and conducted with reduced diligence. For the final engineering walk-around, the day of the occurrence was the only time observed where the inspection was not conducted by maintenance personnel.
Table 1: CCTV footage assessment for flight crew pre-flight inspections and final engineering walk-around
Flight number/date
Flight crew pre-flight walk-around
Final engineering walk-around
SQ256 23-05-22
Partial – Duration 3 minutes 5 seconds. On phone during part of the inspection and did not look in left engine intake.
Completed in full.
SQ256 24-05-22
Partial – Duration 1 minute 45 seconds. Did not inspect the outer wings, empennage or tail.
Completed in full.
SQ256 25-05-22
Partial – Duration 2 minutes 2 seconds. Did not inspect the left side fuselage, left outer wing or engine intake.
Completed in full.
SQ256 26-05-22
Partial – Duration 3 minutes 11 seconds. Did not inspect the left outer wing.
Completed in full.
SQ256 27-05-22 (incident flight)
Partial – Duration 1 minute 45 seconds. Did not inspect the outer wings, empennage or tail.
Not carried out.
Fatigue management
Heston MRO fatigue management program
The Heston MRO safety management system included a section on fatigue management, which stated that:
The Fatigue Management program aims to identify and assess fatigue related risks and issues within the workplace and aid in the implementation of process and procedure to manage and control fatigue.
The Fatigue Management program applies to all HESTON MRO staff and specialist maintenance providers. Fatigue is generally associated with tiredness after work or effort, either physical or mental.
Symptoms of fatigue include weakness, stress, depression, health problems and the tendency to make mistakes or errors.
Excessive hours of work, poor planning, insufficient staff, bad shift scheduling and a work environment without proper control of temperature, humidity or noise are all known to contribute to fatigue.
The Heston MRO process for the management of fatigue was divided into key areas such as:
roster design
hours of work
detection and monitoring fatigue in the workplace
identification of fatigue risks and control measures
fatigue risks strategies
fatigue investigation
training.
Heston MRO utilised a web-based program to manage maximum hours per period worked and the maximum hours per day worked through the establishment of rostered cyclic rules. The rules for the design of rosters included:
no planned shift to exceed 12 hours
no actual (worked) shift to extend beyond 14 hours unless a risk assessment had been performed
the hours of planned work are based on 38 hours per week, 76 hours per fortnight and/or 152 hours per month
shift start times to move forward from one day to the next, that is, early starts and then progress through to starting in afternoons
a requirement for a 10-hour minimum stand-down period between shifts.
The requirements above were incorporated into the design of rosters with the aim of an equal distribution of work hours among employees and the tracking of hours worked for fatigue management purposes.
Heston MRO management responsibilities and accountabilities
In accordance with the Heston MRO fatigue management program, the person in the role of regional manager was responsible for ensuring:
All employees were provided with rostered shifts within the fatigue risk management guidelines.
Employees were aware of the fatigue management procedures and familiar with their responsibilities and accountabilities. In addition, if an employee was required to work beyond the fatigue management guidelines an appropriate risk assessment was performed, with mitigation strategies implemented.
That the hours of work were monitored to include overtime, shift allocation and shift changes with the aim of preventing unacceptable levels of fatigue accrual.
Where there was an operational need to extend shift hours or alter personnel shift patterns, the regional manager was required to perform a risk assessment, implement mitigating strategies in consultation with the human resources manager. The human resources manager provided oversight governance to ensure compliance with legislative requirements.
Noting that the LAME/regional manager was conducting dual roles, the ATSB asked Heston MRO if their total work hours were monitored in accordance with the fatigue management policy. They stated:
[The LAME] is hired as and has the position of [Regional] Manager. As the manager, [the LAME] is required to manage the fatigue levels of all [their] subordinates, and this includes [themselves].
[They] do not sign in/out of work and there is no time monitoring.
[They] are asked regularly about ensuring [they] are receiving sufficient rest – and if [they] are not – to ensure that [they] gets some.
The ATSB further asked if other personnel had dual roles and if all their hours were tracked for fatigue monitoring purposes. Heston MRO indicated that, at the time of the occurrence they had a total of 4 employees who had dual management and aircraft operational roles whose total hours were not monitored for fatigue management purposes. However, all other LAMEs and AMEs not undertaking dual roles had their hours tracked.
During the week of the incident, the LAME/regional manager conducted 2 shifts amounting to about 17 hours on the same day to cover for a LAME who was absent from work. While the LAME/regional manager notified the Quality and Safety manager about the extra shift, a risk assessment was not conducted as per the company’s fatigue management program.
ATSB SafetyWatch - Fatigue management
The SafetyWatch is a set of broad safety concerns that the ATSB has identified through investigation findings and from occurrence data reported by industry. At the time of this report, the ATSB had identified fatigue management as a safety concern and stated:
Despite increased awareness across the transport sector, fatigue remains one of the most relevant ongoing concerns for safe transport. Fatigue impairment has been identified as a contributory factor in numerous aviation, maritime and rail accidents.
Human fatigue is a condition primarily caused by inadequate or bad sleep, or by staying awake for too long. Things like underlying health conditions, medication, and stress can amplify the likelihood and effects of fatigue.
Fatigue can have a range of adverse effects on human performance, including:
• decreased short-term memory
• slowed reaction time
• decreased work efficiency
• reduced motivational drive
• increased variability in work performance
• increased errors of omission
• increased risk tolerance.
These symptoms can occur before an individual experiences the “feeling” of fatigue.
On 18 July 2018, a Malaysia Airlines Airbus A330, registered 9M-MTK, took off on a regular public transport flight from Brisbane, Queensland to Kuala Lumpur, Malaysia. As the covers had been left on the aircraft’s 3 pitot probe’s, the instruments showed a red speed flag in place of the airspeed indication from early in the take‑off, and unrealistically low airspeeds afterwards. The flight crew did not respond to the speed flags until the aircraft’s speed was too high for a safe rejection of the take-off, and the take‑off was continued.
The ATSB investigation subsequently identified safety factors across a range of subjects including flight deck and ground operations, aircraft warning systems, air traffic control, aerodrome charts, and risk and change management. The report safety message stated:
The loss of airspeed data due to mud wasp ingress can occur even after brief periods, and the use of pitot probe covers for aircraft turnarounds at Brisbane is largely an effective defence. However, it introduces another risk, which is the potential for aircraft to commence a take-off with pitot probe covers still fitted…
For all individuals working in the aviation industry, the occurrence shows that coordination and diligence can make a difference. Several individuals on the night—as well as their counterparts on other occasions—all acted as though the conduct of various external aircraft inspections was someone else’s responsibility; in fact, all had separate, key roles in detecting problems with the aircraft before departure. Had all such inspections been conducted diligently it is very likely that the pitot probe covers would have been seen and subsequently removed…
As a result of the investigation, a safety issue for Aircraft Maintenance Services Australia (rebranded to Heston MRO in 2019) was identified:
Aircraft Maintenance Services Australia did not have a reliable method to account for tooling and equipment (such as pitot probe covers) prior to aircraft dispatch when providing non-certifying engineering support.
In February 2022, in response to the safety issue, Heston MRO advised that it had implemented a procedure for all toolboxes taken to aircraft. Based on the below, the ATSB closed this safety issue. The procedure required that:
All toolboxes (including the transit toolboxes) will carry a notebook inside the box.
The above notebook will have the below drawn table.
An audit of the contents of the toolbox will be carried out and signed for prior to the use of any of the contents from the toolbox.
After all work on the aircraft and prior to pushback – the contents of the toolbox will be re-audited and signed for to ensure all contents have been returned to the box.
It should be noted that, at the time of this occurrence in May 2022, the procedure described above was not utilised or implemented as advised.
In addition to the above, the ATSB’s investigation also identified the following findings regarding the conspicuity of the pitot probe covers and inspections:
Although suitable for use in most situations, the streamers attached to the pitot probe covers supplied and used for A330 operations by Aircraft Maintenance Services Australia provided limited conspicuity due to their overall length, position above eye height, and limited movement in wind. This reduced the likelihood of incidental detection of the covers, which is important during turnarounds.
Malaysia Airlines flight crew and engineers did not fully complete the required aircraft inspections.
The Malaysia Airlines engineer did not perform a final walk-around inspection of the aircraft, including a check for pitot probe covers, as required by the transit check that the engineer had certified as complete. The engineer assumed that the walk-around would be completed by the support engineer and/or ground handlers.
Safety analysis
Introduction
A Singapore Airlines Airbus A350-941 aircraft was being prepared for a regular public transport flight from Brisbane Airport, Queensland to Changi Airport, Singapore. Just prior to the aircraft being pushed back for departure, a refueller on an adjacent bay noticed that the pitot probe covers were still fitted. The refueller informed the licenced aircraft maintenance engineer (LAME) responsible for the aircraft turnaround and the covers were subsequently removed just before pushback.
This analysis will discuss the actions of maintenance personnel regarding the removal of the pitot probe covers prior to pushback and incomplete walk-around inspections by both maintenance and flight crew. It will also consider tooling control procedures and the conspicuity of the pitot probe covers used. The LAME’s workload and fatigue management of personnel with dual roles will also be examined.
Pitot cover installation and removal procedures
As per the procedure, on arrival of the aircraft at Brisbane, a warning placard was placed on the flight deck and a corresponding entry made in the technical log indicating that the pitot probe covers had been fitted. Prior to departure, the placard was to be removed and the log entry was to be closed once the pitot covers had been taken off. While there was a procedure in place that was designed to ensure that pitot cover removal had occurred, on this occasion, the LAME reported that they had assumed rather than verifying that the covers were removed by the AME. However, the AME, who was new to the organisation, had been told that they were not to remove the covers without instruction from a LAME. While there was no communication from the LAME either to instruct the AME to remove the covers or to visually check that they had been removed, the LAME certified the log entry as completed. Likewise, the closed-circuit television (CCTV) footage showed that the LAME had removed the placard and placed it in their work vehicle, although the covers remained fitted to the aircraft.
Transit toolbox procedure
The primary function of tool control is to prevent tooling remaining on board (or fitted to) an aircraft prior to its departure. Its secondary function is to account for tooling as an asset. The Heston MRO tool control requirements at the time of the occurrence for the transit toolbox were not a reliable means to account for tooling (such as pitot probe covers) prior to aircraft dispatch. This was due to the procedural checks for toolbox contents (including pitot covers and the warning placard) being carried out when returning the tooling at the end of a shift, rather than prior to aircraft dispatch. Therefore, the transit toolbox procedure was not an effective method of tool control, but rather, a check for inventory at the end of a shift.
Tool control was highlighted as a safety issue following a previous incident investigated by the ATSB (AO-2018-053). At the time of drafting the final report into that incident (March 2022) Heston MRO (previously AMSA) advised the ATSB that the tool control procedure had been changed to incorporate a requirement to check for the contents of the transit toolbox before pushback. That safety enhancement was accepted by the ATSB, and the safety issue was closed. However, at the time of this occurrence (May 2022), the ATSB identified that the tool control procedure remained unchanged. Therefore, the same safety issue has been identified as a result of this investigation.
There was a company requirement for a general post‑maintenance tool control check. However, tools used for line maintenance, turnaround and ground handling of aircraft require specific controls to ensure they have been accounted for prior to flight. Had there been a robust tool control procedure in place for the transit toolbox contents, such as the one previously identified by Heston MRO, then it was likely that the pitot covers would have been identified as missing from the transit toolbox and removed in a timely manner, prior to pushback.
Maintenance personnel final walk-around
The LAME left the bay to refuel another aircraft, leaving the relatively inexperienced AME (on aircraft type and at Heston MRO) to dispatch the aircraft by themselves. The AME reported that they completed the final walk-around, however, the closed-circuit television footage showed that they had removed the aircraft chocks but had not completed the inspection as per the procedure. Likewise, and consistent with the footage, the LAME reported that they did not conduct the inspection as they had assumed this had been completed by the AME as part of their headset coordinator responsibilities.
The final walk-around represented the last procedural opportunity to identify that the aircraft was correctly configured for flight with all panels and doors closed, pins and covers removed. Given the AME’s limited experience, direct supervision would have been prudent until such time as the LAME was satisfied that the AME could conduct the turnaround functions effectively. Irrespective, had a final inspection been conducted, it was likely that the pitot covers would have been identified as it was one of the check items in the final walk-around procedure.
Flight crew pre-flight walk-around inspection
Much like final walk-around inspections, flight crew pre-flight inspections are an important risk control to ensure that the aircraft is prepared and configured for flight. If inspections are not done correctly, it increases the risk of defects not being identified and/or the aircraft not being correctly configured for flight.
The closed-circuit television footage of 5 Singapore Airlines turnarounds showed that none of the pre‑flight inspections were completed in full by flight crew in accordance with the company procedure. The pre-flight walk-around inspection was generally conducted about 30 minutes prior to departure. As the pitot probe covers were not required to be removed until 20 minutes prior, the flight crew could expect to see the covers fitted during their inspection. Despite this, pre-flight inspections need to be completed in full and with careful diligence. Each one needs to be conducted with the mindset that it may be the sole opportunity to detect damage or other irregularities and confirm the aircraft’s readiness for flight.
Licenced aircraft maintenance engineer workload and Heston MRO fatigue management
The LAME reported that the workload associated with the dual role of LAME/regional manager had become considerably more demanding post the COVID-19 pandemic This was consistent with observations made by their family and friends, and from their 72-hour work history, which showed some long days including a double shift. Consequently, they were constantly moderately tired.
In addition, while Heston MRO had a fatigue management policy in place, 4 employees who had combined management and operational duties (including the LAME) did not have all their work hours tracked and assessed for fatigue calculation purposes. Therefore, aside from an individual self-reporting, Heston MRO could not assess or assure that those employees were not experiencing the negative effects of elevated fatigue levels. Fatigue has been shown to significantly raise the likelihood of errors and omissions and increase the risk of an incident involving those personnel. While the LAME worked significant hours outside the normal roster periods, the ATSB was unable to accurately determine if they were experiencing a level of fatigue that may have contributed to the occurrence. Regardless, without appropriate tracking of their hours, Heston MRO had no way of knowing if the LAME (and others) were experiencing high levels of fatigue.
Pitot probe cover characteristics
The purpose of a ‘remove before flight’ streamer, attached to an item of ground support equipment such as a pitot probe cover, is to gain the attention of someone who is not primarily looking for the equipment. Several characteristics contribute to the conspicuity of streamers including the colour and length. The streamers attached to the pitot probe covers provided by maintenance personnel were relatively short, and when fitted, were about 3 m above eye height, which may be difficult to detect.
As highlighted in the ATSB’s previous investigation, a human’s perceptual system is sensitive to motion, particularly in their peripheral vision (McKee and Nakayama 1984; Wickens and others 2013). A shorter streamer may not necessarily attract a person’s attention, particularly if they are not focussed on that area, but strong winds may occasionally drag the covers off with a longer stream. Operators need to balance the likelihood of this occurring against the need to ensure their removal before flight through the use of longer streamers.
While the maintenance personnel responsible for the aircraft departure did not conduct a final aircraft walk-around inspection, the limited conspicuity of the pitot probe covers used reduced the likelihood of incidental detection of the covers. There are incidental opportunities that arise for ground crews to notice pitot probe covers while conducting unrelated tasks such as attaching a tug and pushing the aircraft back, or in this case, the refueller working on an adjacent bay. The likelihood of this incidental detection is increased with the use of larger or brighter streamers that hang into the view of ground staff, particularly in positions that are closer to the aircraft. This is especially important when there are increased time pressures and fewer opportunities for their removal during turnarounds.
Refueller identification of pitot probe covers
For this occurrence, it was an incidental detection made with a wider view of the aircraft by a refueller working on an adjacent bay that led to the identification of the covers. The immediate action of the refueller by advising the LAME ensured that the covers were removed prior to pushback, thereby preventing the flight crew commencing a take-off with erroneous or absent airspeed indications.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the flight preparation event involving Airbus A350-941 registered 9V-SHH at Brisbane Airport, Queensland, on 27 May 2022.
Contributing factors
The licenced aircraft maintenance engineer certified for the removal of the pitot covers in the technical log and removed a warning placard from the flight deck without visual or verbal confirmation that the pitot covers had been removed.
Heston MRO had not yet implemented a previously proposed and accepted method to account for tooling and equipment (such as pitot probe covers) prior to aircraft pushback. (Safety issue)
Maintenance personnel responsible for the aircraft departure did not conduct a final aircraft walk-around inspection. That inspection was the last procedural opportunity to identify that the pitot covers had not been removed.
Other factors that increased risk
The licenced aircraft maintenance engineer was undertaking dual roles as both regional manager and engineer. This increased the risk of a fatigue-related maintenance error occurring as a result of a significantly expanded workload in the months that preceded this incident.
Heston MRO did not track the work-related hours of personnel with dual management and operational roles (including the licenced aircraft maintenance engineer) for fatigue calculation purposes. Therefore, there was an increased risk of a fatigue‑related incident involving those personnel. (Safety issue)
The majority of Singapore Airlines flight crews (observed around the time of the incident) did not fully complete the required pre-flight walk-around inspections. (Safety issue)
Although suitable for use in most situations, the streamers attached to the pitot probe covers used for the Airbus A350 operations at Brisbane Airport provided limited conspicuity due to their overall length, position above eye height, and limited movement in wind. This reduced the likelihood of incidental detection of the covers, which is important during turnarounds. (Safety issue)
Other findings
The refueller on an adjacent bay identified that the pitot covers were still fitted and advised maintenance personnel to ensure that they were removed prior to pushback.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
The initial public version of these safety issues and actions are provided separately on the ATSB website, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website as further information about safety action comes to hand.
Safety issue description: Heston MRO had not yet implemented a previously proposed and accepted method to account for tooling and equipment (such as pitot probe covers) prior to aircraft pushback.
Safety issue description: Heston MRO did not track the work-related hours of personnel with dual management and operational roles (including the licenced aircraft maintenance engineer) for fatigue calculation purposes. Therefore, there was an increased risk of a fatigue related incident involving those personnel.
Safety issue description: The majority of Singapore Airlines flight crews (observed around the time of the incident) did not fully complete the required pre-flight walk-around inspections.
Safety issue description: Although suitable for use in most situations, the streamers attached to the pitot probe covers supplied and used for A350 operations by Heston MRO at Brisbane Airport provided limited conspicuity due to their overall length, position above eye height, and limited movement in wind. This reduced the likelihood of incidental detection of the covers, which is important during turnarounds.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Additional safety action Heston MRO
Heston MRO has advised the ATSB that they have implemented an additional procedure, which required the placement of a warning placard on the communications panel where the ground headset connects to (Figure 8).
Figure 8: Warning placard fitted to the ground communication panel
Source: Heston MRO
Glossary
AME
Aircraft maintenance engineer
CCTV
Closed-circuit television
LAME
Licenced aircraft maintenance engineer
Sources and submissions
Sources of information
The sources of information during the investigation included:
the aircraft refueller
the licenced aircraft maintenance engineer
the aircraft maintenance engineer
Heston MRO
Singapore Airlines
Brisbane Airport Corporation
Closed-circuit television footage.
References
Airbus (2016) ‘Pitot probe performance covered on the ground’, Safety First, July, 22: 6–13.
McKee, S. P., & Nakayama, K. (1984). The detection of motion in the peripheral visual field. Vision Research, 24(1), 25–32.
Wickens, CD, Hollands, JG, Banbury, S and Parasuraman, R (2013) Engineering psychology and human performance, 4th Ed. Pearson, United States.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
aircraft refueller
licenced aircraft maintenance engineer
aircraft maintenance engineer
Heston MRO
Singapore Airlines
Brisbane Airport Corporation
Civil Aviation Safety Authority.
Submissions were received from:
Heston MRO
Singapore Airlines.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1]Headset duties, also called turn around coordination, involved communicating between the ground and flight deck via a headset connected in the nose area of the aircraft.
[2]Pitot probes provide air data computers and flight instruments with airspeed information and are ineffective if covered or blocked. The term pitot probes also include the multi-function probes fitted to the Airbus A350, which measure total pressure, total air temperature and angle of attack measurements.
[3]Pushback: using a tug to push an aircraft backwards from the terminal so that it can then taxi under its own power.
[4]A steering bypass pin when fitted to an aircraft allows it to be manoeuvred on the ground.
Preliminary report
Report release date: 19/08/2022
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
On 27 May 2022, a Singapore Airlines Airbus A350-941, registered 9V-SHH, was being prepared on bay 81 for a regular public transport flight from Brisbane Airport, Queensland to Changi Airport, Singapore, as flight number SQ256. Just prior to the aircraft being pushed back for departure, it was identified that the pitot probe covers were still fitted to the aircraft.
The engineering maintenance contractor had provided a licenced aircraft maintenance engineer (LAME) and an aircraft maintenance engineer (AME) to conduct scheduled receipt, dispatch, certification, and maintenance duties during the aircraft’s scheduled 2-hour turnaround.
Apart from performing line maintenance duties, the LAME was also the contractor’s regional manager for Brisbane, Wellcamp, and Coolangatta airports. At the time of the occurrence, the LAME was also supervising the AME and assisting with the turnarounds on SQ256 and another aircraft on an adjacent bay.
The AME had started with the contractor 3 weeks prior and had not completed all of their induction training at the time of the occurrence. On the day of the occurrence, the AME was conducting headset duties.
During the preparation of SQ256, the following events occurred:
Between 0705 and 0727 Eastern Standard Time,[1] the LAME instructed the AME through the external walk-around inspection of the transit check for the Airbus A350. At 0732 the AME utilised an elevated work platform to install covers on all 4 pitot probes[2] in accordance with airline and company procedures specifically for Brisbane Airport. At about the same time, the LAME entered the flight deck to check the technical log for defects. As part of the pitot cover installation and removal procedures, the LAME made an entry in the log that the covers had been fitted and then placed a warning placard on the flight deck engine control pedestal to also show that the pitot covers were fitted.
Between 0852:18 and 0854:03, the first officer conducted a preflight walk-around. The walk-around was truncated from the nose, to the right engine, across to the left engine and back to the airbridge. The aircraft operator’s procedures also required the extremities of the wings, airframe, and tail section to be inspected, however this was not carried out. The first officer looked up at and likely observed the fitted pitot covers, however they were required to be fitted at that time as per the operator’s policy.
At about 0859 the LAME arrived back on bay 81 after tending to an aircraft on an adjacent bay. The LAME conferred with the AME about fuel figures and talked to the flight crew via headset to confirm the fuel upload.
At 0904 the LAME re-entered the flight deck, certified for the transit check in the technical log, cleared the technical log entry for the fitment of the pitot covers, and removed the pitot cover warning placard from the flight deck pedestal. The LAME then returned to the tarmac and placed the placard on the dash in their work vehicle. The LAME stated that they had not verified that the pitot covers were removed, or requested that the AME remove the pitot covers, but assumed that they would have been removed by that time.
At 0913, the LAME returned to the tarmac at the nose of the aircraft and conversed with the AME for about 3 minutes. With 4 minutes remaining until the expected pushback[3] time, the LAME told the AME that they were going to the adjacent bay to complete the refuelling of another aircraft. The AME remained at bay 81 to conduct the pushback headset duties (Figure 1).
An aircraft refueller on an adjacent bay observed that the Singapore Airlines aircraft appeared ready to pushback, but the pitot covers were still fitted. When the LAME reached the aircraft at the adjacent bay, the refueller immediately pointed to the SQ256 and informed the LAME that the pitot covers were still fitted (Figure 2).
The LAME returned to SQ256 and alerted the AME that the pitot covers were still fitted. At about the same time, the flight crew requested pushback approval from air traffic control and turned on the aircraft beacons. The aerobridge began to retract away from the aircraft.
The flight crew then notified the AME on the headset that they were ready to pushback. The AME, having just been informed that the pitot covers were fitted, told the flight crew to stand by as they were in the process of removing the pitot covers.
With 2 minutes remaining until the expected departure time, the LAME positioned an elevated work platform on each side of the nose to remove the pitot covers (Figure 3). Pushback commenced just after the covers were removed.
Figure 1: Security footage of bay 81 showing SQ256 4 minutes before pushback with the pitot covers fitted and the LAME moving towards the adjacent bay
Source: Brisbane Airport Corporation, annotated by the ATSB
Figure 2: Security footage of the refueler pointing towards SQ256 and informing the LAME that the pitot covers were fitted
Source: Brisbane Airport Corporation, annotated by the ATSB
Figure 3: LAME removing pitot covers 1 minute prior to departure time
Source: Brisbane Airport Corporation, annotated by the ATSB
The security video footage did not show that the required final walk-around of the aircraft was conducted by either the LAME or the AME prior to dispatch.
Related occurrence
Mud wasp are a well-known hazard at Brisbane Airport. They can rapidly build nests in pitot probes and, accordingly, operators and related organisations need to ensure they fit pitot probe covers when aircraft are parked at the airport. Similarly, these organisations need to have procedures to ensure the covers are removed before the aircraft commences taxiing for take-off. An aircraft being cleared to commence taxiing and then take-off with all pitot probe covers still fitted is a serious event.
On 18 July 2018, a Malaysia Airlines Airbus A330, registered 9M-MTK, took off on a regular public transport flight from Brisbane, Queensland to Kuala Lumpur, Malaysia. Covers had been left on the aircraft’s 3 pitot. The instruments showed a red speed flag in place of the airspeed indication from early in the take‑off, and unrealistically low airspeeds afterwards.
The flight crew did not respond to the speed flags until the aircraft’s speed was too high for a safe rejection of the take-off, and the take‑off was continued. The flight crew’s initial radio announcement of an urgency situation was not heard by the air traffic controller.
The ATSB investigation subsequently identified safety factors across a range of subjects including flight deck and ground operations, aircraft warning systems, air traffic control, aerodrome charts, and risk and change management. In its Safety message section, the ATSB report stated:
The loss of airspeed data due to mud wasp ingress can occur even after brief periods, and the use of pitot probe covers for aircraft turnarounds at Brisbane is largely an effective defence. However, it introduces another risk, which is the potential for aircraft to commence a take-off with pitot probe covers still fitted…
For all individuals working in the aviation industry, the occurrence shows that coordination and diligence can make a difference. Several individuals on the night—as well as their counterparts on other occasions—all acted as though the conduct of various external aircraft inspections was someone else’s responsibility; in fact, all had separate, key roles in detecting problems with the aircraft before departure. Had all such inspections been conducted diligently it is very likely that the pitot probe covers would have been seen and subsequently removed…
Further details of this investigation can be found on the ATSB website.
Further investigation
To date, the ATSB has interviewed the engineers and refueller, and reviewed the airport security video footage of the SQ256 turnaround.
The investigation is continuing and will include examination of:
flight crew pre-flight inspection procedures
engineering final walk-around procedures
induction training procedures
training records for the LAME and AME
Heston MRO fatigue management policies and procedures
Heston MRO change management policies and procedures
security video recordings of aircraft turnarounds
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
At about 0311 local time on 4 May 2022, the 225 m bulk carrier Rosco Poplar was transiting the Great Barrier Reef via Hydrographers Passage under the conduct of a coastal pilot. Upon suddenly noticing that a reef sector light was indicating red, the pilot ordered a course correction. This was followed almost immediately by the activation of an alert from the ship’s electronic navigational equipment indicating that the ship was passing less than 200 m from Bond Reef (normal clearance was about 1,500 m). The ship's course was corrected and the remaining pilotage was conducted uneventfully.
What the ATSB found
The ATSB found that during the early stages of the pilotage, one of the ship’s 3 GPS units began outputting incorrect positional data, likely due to an antenna malfunction. Because the bridge navigational equipment, including the electronic chart display and information system (ECDIS), radars and automatic identification system (AIS), were receiving a single position input from the same GPS unit, the ship’s position was incorrectly displayed on all these systems. However, no alarms were triggered from the failure because the GPS unit incorrectly indicated that position accuracy was within acceptable limits.
The investigation found that the pilot and bridge team solely relied on GPS positioning to monitor the ship’s progress and did not maintain a proper lookout through use of radar and visual observations. As a result, they did not identify that the position reported on the ECDIS units was incorrect and that the ship had deviated significantly from the planned track.
It was also identified that the pilot had not correctly configured their portable pilot unit (PPU) to be independent of the ship’s position sensors. This resulted in the PPU displaying the same incorrect position as the ship’s ECDIS units.
Additionally, ineffective pilotage and bridge resource management (BRM) contributed to the occurrence. An inadequate master-pilot information exchange did not establish individual roles and responsibilities for watchkeeping and communication, while the second mate was given tasks which distracted them from their duties for monitoring the passage plan and maintaining a proper lookout. As a result, the pilot and bridge team’s situation awareness progressively declined in the absence of adequate communication and a shared mental model of the pilotage.
The ATSB also identified that, following receipt of an unusual grounding alert display associated with the Rosco Poplar’s GPS malfunction, the vessel traffic services operator assessed it as erroneous. Consequently, the pilot and ship’s crew were not provided with timely advice of the indicated proximity to Bond Reef.
Finally, the ATSB identified that the check pilot system implemented by the Australian Maritime Safety Authority (AMSA) did not provide the intended competency assurance. The investigation identified significant variations in the application of assessment standards between individual check pilots, indicating that assessment outcomes were not a valid and reliable indicator of competency. Further, due to the absence of any processes for analysing assessment results, AMSA had not identified these inconsistencies.
What has been done as a result
While in Australia, the ship’s bridge navigational system was updated by shore technicians with new GPS units and a reconfigured wiring system to interconnect the electronic navigational aids. The update facilitated multiple GPS inputs for the different aids, providing greater redundancy in the event of single GPS unit failures.
AMSA advised that a review of coastal pilotage under the current legislation was underway. As part of this review, AMSA intended to review the effectiveness and assurance provided through the check pilot framework with a view to making recommendations for improvements.
The ATSB issued a safety recommendation to AMSA to address factors limiting the effectiveness of its check pilot framework as a system for coastal pilot competency assurance.
Safety message
The occurrence highlights that the various concepts, techniques, and attitudes that together comprise bridge resource management are essential defences against human error. In confined waters such as compulsory pilotage areas, the margins for navigation errors are significantly reduced. Effective communication and coordination between the pilot and bridge team are necessary requirements for establishing a shared mental model of the pilotage so that evolving and critical situations can be identified and appropriately managed.
Compulsory coastal pilotage remains an essential defence against serious shipping accidents in the Great Barrier Reef. It is therefore important that coastal pilots meet necessary competency and performance standards. Furthermore, any assessment system that assures those standards must produce consistent and accurate outcomes. If sufficient measures are not implemented to ensure assessment standards are interpreted and applied consistently irrespective of the assessor, the outcomes are unreliable.
Summary video
The occurrence
On the evening of 3 May 2022, the 225 m bulk carrier Rosco Poplar arrived off Blossom Bank pilot boarding ground to embark a coastal pilot by helicopter for its transit of the Great Barrier Reef via Hydrographers Passage (Figure 1). The ship was in ballast and bound for Hay Point to load coal.
Figure 1: Navigational chart showing Blossom Bank pilot boarding ground
Source: Australian Hydrographic Office, annotated by ATSB
At 2300 local time, Rosco Poplar’s master arrived on the navigation bridge (bridge) and discussed preparations for the pilotage with the officer of the watch (second mate). Checks of the ship’s main engine, steering gear and navigational equipment were conducted. Meanwhile, crewmembers on the main deck prepared for the helicopter’s arrival.
The ship was equipped with 2 electronic chart display and information system (ECDIS) units. Global positioning system (GPS) data for both ECDIS units and the radars was provided by one of the 3 GPS units.
At 0140 on 4 May 2022, pilot helicopter landed on the ship’s helicopter landing cargo hold hatch cover and the pilot disembarked. By 0145, the pilot had joined the bridge team, which included the master, second mate and an able seaman at the helm. The pilot ordered ‘maximum speed’[1], then checked the ship’s position and course on the ECDIS and gave helm orders to take it towards the compulsory pilotage limits and join the 218° (T) course inbound for Hydrographers Passage (Figure 2). Visibility was clear, with the only other traffic in the area being another inbound ship, Camellia Island, about 6 nautical miles (miles)[2] ahead (Figure 3). The tide was ebbing with high water at Bugatti Reef having occurred at 2355 on 3 May, with a height of tide of 2.72 m above chart datum.[3] Tidal stream data[4] indicated that the strongest predicted tidal stream would be about 5.4 knots setting in a 016° (T) direction in the vicinity of Bond Reef at 0255.
Figure 2: Entrance to Hydrographers Passage
Source: Australian Maritime Safety Authority, annotated by ATSB
At 0149, the pilot identified that the waypoints for the planned route had been input into the ECDIS units but not the radars or the GPS units. The pilot then told the master that the passage plan required the route to be programmed into all of the ship’s navigational systems and asked for the waypoints to be entered into both radars.
The pilot then connected his portable pilot unit (PPU) to the automatic identification system (AIS) pilot plug, located at the forward part of the bridge. After connecting the PPU, the pilot set up a tablet device (iPad) next to the secondary ECDIS console on the chart table, located in the aft part of the bridge. The PPU connected wirelessly to the iPad, which displayed GPS and AIS information on electronic navigation chart (ENC) software installed on it (see the section titled Portable pilot unit).
While setting up the PPU, the pilot became aware that the master had not previously transited Hydrographer’s Passage so he advised the master that there was a 7-8 knot opposing current and reiterated the ‘maximum speed’ requirement.
Meanwhile, the master and second mate determined that the waypoints would need to be manually entered for each radar. The second mate began the task, starting with the s-band radar, located on the starboard side of the bridge.
At 0158, the pilot asked the master if the pilotage provider company’s standard master-pilot information exchange (MPX) checklist had been received. When the master advised that it had not, the pilot told the master that all bridge team members had to read and sign the checklist. The pilot then produced a copy of the checklist and conducted an MPX with the master confirming that all the ship’s machinery and equipment was in working order and there were no defects. When the MPX concluded at about 0204, the pilot asked the master to make a hard copy of the checklist after it had been signed.
At 0215, the second mate informed the pilot that the waypoints had been input into the s-band radar. Shortly after, as the ship approached the compulsory pilotage limit near Blossom Bank, the pilot ordered a heading[5] of 218° to line up the ship along the 218° (T) leading line indicated by the White Tip Reef lights ahead (Figure 3). At 0218, the pilot made a ‘pilot commencing duties’ report to the coastal vessel traffic service (REEFVTS) via VHF radio and advised the master that he was taking over the conduct of the ship.
Figure 3: Navigational chart with Rosco Poplar’s radar display overlaid (grey) at 0217
Source: Australian Hydrographic Office, annotated by ATSB
At about the same time, the second mate moved to the x-band radar to input waypoints. The pilot reported that at this time, he was monitoring the ship’s progress visually and on the 2 ECDIS displays, which the pilot compared to the position displayed on the PPU. At 0234, the second mate completed the waypoint input for the x-band radar and returned it to operational mode.
At 0239, the master alerted the second mate to discrepancies between the ship’s heading displayed on the radar and ECDIS units. They discussed those discrepancies in their native language (Mandarin) over the next 20 minutes with no resolution. During this discussion, the master recalled experiencing a similar error on board the ship on a previous voyage. Neither raised any concern with the pilot, nor did he ask them what they were discussing.
As the ship passed the Ferris Shoal waypoint at 0246, the pilot ordered a 202° heading towards the next waypoint to track the ship 0.8 miles to the west of Bond Reef light beacon (Figure 4). According to the pilot, he saw that Little Bugatti Reef sector light was white at the time (the white and red sectors indicate safe and unsafe waters, respectively).
Figure 4: Standard planned routes near Bond Entrance (inbound tracks are blue)
Source: Australian Maritime Safety Authority, annotated by ATSB
About 2 minutes later, the pilot ordered a heading of 195°and over the following 20 minutes, continued to give heading orders ranging from 193° to 202°. Meanwhile, at 0301, the second mate carried out a position crosscheck by using the line of position (LOP) function on the ship’s ECDIS, using the range and bearing of Little Bugatti Reef sector light directly from the ECDIS, which indicated the ship was on the planned track. During this period, the master observed that the flashing white light fine on the port bow had closed until it was almost directly ahead of the ship. The master did not query the pilot to identify the light and assumed it was not Bond Reef beacon but some other light.
At 0307, the pilot ordered a heading of 190°. Then, at 0311, having suddenly noticed that the Little Bugatti Reef sector light was indicating red, the pilot ordered 205°.
About 1 minute later, multiple GPS and AIS status alarms sounded and the GPS input source displayed on the ECDIS briefly changed from ‘GPS1’ to ‘DR’ (dead reckoning[6]) mode. Camellia Island’s AIS return also disappeared from the radar and ECDIS displays. While these alarms were sounding, the pilot repeated the previous 205° heading order. At 0313, when Rosco Poplar’sGPS position reappeared on the ECDIS and the PPU displays, it was 1 cable (185 m) west of Bond Reef beacon - the ship’s indicated GPS position had almost instantaneously moved about 0.92 of a mile (1,704 m) to the east (Figure 5). As the ship passed abeam of Bond Reef, the pilot and bridge team saw its light very close to port.
Figure 5: Rosco Poplar’s track, as displayed on the ship’s ECDIS
Source: RP ECDIS, annotated by ATSB
The pilot noted that the PPU and ECDIS displays both showed that the indicated position had suddenly shifted and said to the master ‘captain, your waypoint is off; we were here, now suddenly we are here – that’s why we were looking at this light’. While the ship remained on a heading of 205° to return to the planned route, the pilot, master and second mate discussed the error.
Meanwhile, at 0313 a series of alerts, including a potential grounding alert, were generated by the REEFVTS decision support tool (DST)[7]. The duty vessel traffic service operator (VTSO) noted that these alerts were associated with multiple dead reckoning (DR) targets for Rosco Poplar (Figure 6). The VTSO assumed this was due to a DST system error. The VTSO checked the ship’s displayed position and track to determine if intervention was required.
Figure 6: Rosco Poplar's track information at 0313, as displayed at REEFVTS
Source: Australian Maritime Safety Authority
At 0313, the VTSO noted that the ship’s position had suddenly shifted close to Bond Reef, after which it had started tracking away from the reef. The VTSO decided against calling the pilot/ship’s crew and began investigating the suspected DST system error. From about 0321, the VTSO made several internal calls to Gladstone VTS and others, which seemed to confirm a possible system error. At 0330, the VTSO started calling the ship (on VHF channel 11) but could not establish contact until 0336 (on VHF channel 14). In the subsequent discussion with the pilot, it was confirmed that the ship had in fact passed close to Bond Reef.
The pilotage continued uneventfully until its conclusion at 0836, when the ship departed the compulsory pilotage limit near Tern Island (Figure 1). The pilot made a ‘ceasing pilot duties report’ to REEFVTS before departing the ship by helicopter at 0854. The ship proceeded to the anchorage area off Hay Point where it anchored at 1230.
Events following the pilotage
Following the pilotage, the master and REEFVTS submitted incident reports for the near-miss grounding to the Australian Maritime Safety Authority (AMSA). Rosco Poplar remained at anchor over the following days where 2 obsolete GPS units and their antennas were replaced by shore technicians (this work had been scheduled a few weeks earlier).
On 31 May 2022, AMSA conducted a port state inspection and detained the ship on the grounds that the master and mates demonstrated inadequate operational proficiency with respect to safe navigation.
On 9 June 2022, following remedial training of the officers to the satisfaction of AMSA and the ship’s classification society, the ship was released from detention. The following day, the ship berthed at Hay Point coal terminal and began cargo operations. While it was berthed, ATSB investigators attended the ship to collect evidence for its investigation.
On 10 June, after completing loading its cargo of coal, the ship sailed and transited Hydrographers Passage outbound uneventfully.
Context
Rosco Poplar
Rosco Poplar was built in 2008 by Oshima Shipbuilding, Japan, registered in Hong Kong and classed with China Classification Society (CCS). At the time of the occurrence, the ship was owned by the Poplar Shipping Company, Hong Kong and managed and operated by Bernhard Schulte Shipmanagement, China.
Rosco Poplar had an overall length of 225 m, a moulded breadth of 32.26 m and a depth of 20.05 m. At its summer draught of 14.43 m, the ship had a deadweight of 82,331 tonnes. Propulsive power was provided by a single Kawasaki Heavy Industries 2‑stroke, single‑acting diesel engine that developed 9,373 kW at 88 rpm. The main engine drove a single, fixed-pitch propeller, which gave the ship a service speed of 14.5 knots.
Crew
Rosco Poplar had a crew of 21 Chinese and Burmese nationals, including the master.
The master had 16 years of seagoing experience and held a master’s certificate of competency, issued in 2017. The master’s seagoing experience had primarily been on container ships, having transitioned to bulk carriers in 2020. The master gained their first command in 2021 and had joined Rosco Poplar in March 2022.
The second mate had over 10 years of seagoing experience, with 4 years at that rank. The second mate had previously worked on container ships and bulk carriers, served on Rosco Poplar in 2017 as third mate and joined the ship as second mate in March 2022.
The able seaman had over 10 years seagoing experience and joined Rosco Poplar in late 2021.
Bridge equipment layout and configuration
Rosco Poplar was equipped with 2 Furuno EC3000 electronic chart display and information system (ECDIS) units. The primary unit was situated on the starboard side of the bridge, between the s-band and x-band radar units (Figure 7). The secondary ECDIS unit was fitted on the chart table behind the primary unit and radars. The automatic identification system (AIS) unit was located beneath the bridge window panels, forward of the primary ECDIS unit.
Figure 7: Rosco Poplar's navigational equipment
Source: ATSB
At the time of the occurrence, 2 Japan Radio Company (JRC) differential[8] GPS units and a Furuno GPS unit were installed on the chart table near the secondary ECDIS unit. The data output feed from each GPS unit was connected to a 3-way selector switch, adjacent to the units (Figure 7 and Figure 8). A single output feed from the selector switch was connected via a JRC data buffer to a secondary buffer which distributed the data to the navigational equipment, including both ECDIS units, both radars, AIS unit and the voyage data recorder (VDR). The JRC JCY 1800 type VDR recorded bridge and communication audio, radar images and various other navigational data.
Figure 8: Diagram of bridge equipment configuration
Source: ATSB (adapted from Taylor Marine)
While the secondary buffer was equipped with dual data input ports, the single data output from the JRC buffer had been split into 2 parallel outputs, which were then connected to each port. This configuration meant that all the ship’s navigational equipment derived a single source of positional data from the GPS unit selected via the 3-way switch at that time.
The antennae for the JRC GPS units were located on the ship’s monkey island, on top of the bridge. They were slightly to starboard of the ship’s centreline and in line with the forward part of the bridge structure. The Furuno GPS antenna was fitted to the port side upper railing of the monkey island and positioned aft of the JRC antennae.
Global positioning system
The master and second mate both reported that ‘GPS 1’ was selected during the pilotage, this being one of the JRC units (Figure 9). Due to the location of the 3-way switch, files obtained from the VDR and ECDIS following the occurrence were unable to provide GPS source information necessary for confirming which of the 3 GPS units was selected during the pilotage.
Figure 9: Arrangement of the GPS units
Source: Taylor Marine, annotated by ATSB
The JRC units consisted of a JLR 7700MKII differential GPS, paired with a JLR 4331 differential GPS‑capable antenna. The manufacture of both the GPS and antenna were discontinued in 2012, and with spare parts no longer available for some time before the occurrence, were considered obsolete. In January 2022, the ship’s management company decided to replace the JRC units during the ship’s call at Hay Point.
The antenna contained the GPS module, which output pre-processed positional data to the bridge equipment. The output data included time and date, ship’s position, position type and accuracy information, set datum information and the GPS-calculated speed over ground (SOG) and course over ground (COG).
The last date rollover[9] for the JRC units occurred in April 2019 and both had been appropriately adjusted by the ship’s crew in accordance with the manufacturer’s operating manual.
Automatic identification system
The AIS unit was a JRC JHS-182 model. While the transponder for the AIS unit contained its own GPS sensor, the unit had an optional input for an external position sensor. The data for this external input was supplied from the secondary buffer. The AIS unit had been programmed to reference the Furuno antenna location to accurately indicate the ship’s position. This meant that whenever either of the JRC GPS units were selected via the 3-way switch, there was an offset to the ship’s indicated position by about 10 m to starboard and 6 m forward of its actual position, reflective of the distance between the JRC unit and Furuno antenna locations.
Electronic chart display and information system (ECDIS)
An ECDIS is a type or class of electronic chart display system. The International Hydrographic Organization (IHO) stated that an electronic chart display system is a ‘general term’ for a configuration of electronic equipment, software, and nautical chart data capable of integrating position, speed and heading data to display the vessel’s position and movement through the water, superimposed on an electronic chart.[10] The 2 classes of electronic chart display systems comprise ECDIS and electronic chart systems (ECS). A key distinction between them is that while ECDIS can be used to meet SOLAS[11] chart carriage requirements, ECS cannot and is only to be used to assist navigation.
Rosco Poplar was equipped with ECDIS as its primary means of navigation. An ECDIS was first recognised as being able to meet the SOLAS chart carriage requirements in 2002 and by July 2018, the fitting of ECDIS became mandatory for almost all ships. An ECDIS, as defined in the IMO ECDIS performance standards,[12] means:
a navigation system which, with adequate back-up arrangements, can be accepted as complying with the up-to-date chart required by regulations V/19 and V/27 of the 1974 SOLAS convention, as amended, by displaying selected information from a system electronic navigational chart (SENC) with positional information from navigation sensors to assist the mariner in route planning and route monitoring, and if required display additional navigation-related information.
Since electronic systems cannot be considered completely failsafe, IMO performance standards for ECDIS require that the ‘overall system’ includes both a primary ECDIS and an adequate, independent back-up arrangement that provides:
independent facilities enabling a safe takeover of the ECDIS functions to ensure that a system failure does not result in a critical situation
a means to provide for safe navigation for the remaining part of the voyage in case of ECDIS failure.
The performance standards allow for considerable flexibility in respect to how the ECDIS is integrated on board the ship to meet the back-up requirements. The IHO identifies 2 common interpretations in respect to the minimum functional requirements and what constitutes ‘adequate’ back-up arrangements:
a second ECDIS, connected to an independent power supply and a separate GNSS[13] position input
up to date paper nautical charts sufficient for the intended voyage.
Rosco Poplar was equipped with 2 ECDIS units with independent power supplies and 3 GPS units available to provide data to the ECDIS units. While this may have satisfied the IMO performance standards with respect to back-up arrangements, the configuration of the installation meant that only one GPS unit could provide a single source of positional information to both ECDIS units at any one time and selection between each GPS unit required manual input using the 3-way selector switch.
The pilot
Rosco Poplar’s pilot became a coastal pilot in 2009, following a long career as a merchant seafarer, including 24 years as master on ships trading in Australia and New Zealand. The pilot had worked exclusively in Hydrographers Passage and held an unrestricted pilot licence for this pilotage area.[14] The pilot had conducted 1,684 pilotages through Hydrographers Passage, including 840 inbound voyages, before the occurrence.
Since 2015, the pilot had undertaken 4 pilot check voyages[15] in Hydrographers Passage, each assessed by a different check pilot. On each occasion, no deficiencies were identified with respect to the pilot’s performance.
Auriga
Under the Australian Maritime Safety Authority’s (AMSA) Marine Order 54 (Coastal pilotage) (MO54), coastal pilots must be engaged through AMSA-licenced pilotage providers. The duty of a licensed pilotage provider is to provide pilots and pilot transfers to ships and maintain a safety management system to ensure the safe navigation of the ships in compulsory pilotage areas.[16]
Rosco Poplar’s pilot at the time of the occurrence had been engaged through Auriga, one of 2 private companies which provided coastal pilotage services throughout the Great Barrier Reef (GBR). Auriga was formed in 2021 when the Western Australia-based marine pilotage and logistics services provider, Argonaut Marine Group, merged with Australian Reef Pilots (ARP). At the time of the merger, ARP was an established pilotage provider in the GBR, having formed in 1993 when the provision of Queensland coastal pilotage services was privatised. Auriga employed about 40 pilots for its pilotage operations in the GBR.
Auriga had in place a pilotage operations safety management system (SMS), designed to meet the regulatory standards necessary for the company to hold its licence. The SMS had last been revised in June 2020, when the company traded as ARP. It contained a set of standard operating procedures to assist and guide pilots in their daily practical pilotage tasks. A key objective of the SMS was to minimise the risk of a major accident resulting in personal injury, environmental harm or property damage or loss.
Great Barrier Reef Marine Park
The Great Barrier Reef is a vast network of coral reefs, shoals and islands off Australia’s north‑east coast, stretching for over 1,200 miles from Bundaberg in the south to Cape York in the north (Figure 10). It is the world’s largest and most diverse reef ecosystem, internationally renowned for its scientific, cultural and environmental importance. In 1981, the GBR was inscribed on the United Nations Educational, Scientific and Cultural Organization (UNESCO) world heritage list for its outstanding universal value.
Figure 10: The Great Barrier Reef region (Designated Shipping Areas are highlighted)
Source: Great Barrier Reef Marine Park Authority
The GBR region has been protected as a multi-use marine park since the enactment of the Great Barrier Reef Marine Park Act 1975. The legislation established the Great Barrier Reef Marine Park Authority (GBRMPA) and provided a framework for the long-term protection and conservation of the marine park, including management of the various activities that occur within it. The authority carries out its function through the formulation of policies, enforcement of regulations, education initiatives, establishment of partnerships, research, monitoring and reporting.
Of necessity, ships must travel through navigationally complex channels within the marine park to gain access to 11 regional ports situated along the Queensland coast. The local and Australian economies are heavily dependent on the considerable volume of trade conducted through these ports, particularly the export of bulk cargoes.
In 1990, the IMO declared the GBR region as the world’s first particularly sensitive sea area (PSSA)[17] in recognition of the environmental importance of the GBR and the need for special measures to protect it against pollution from ships. These measures include restrictions on discharges from ships, ship routeing practices, compulsory pilotage, mandatory ship reporting and monitoring, coastal vessel traffic services and an extensive network of visual and electronic navigation aids.
Designated Shipping Areas (DSA) in the marine park were established by GBRMPA as shown in Figure 10. The DSAs are designed to help minimise environmental impacts from shipping, while having regard for the shipping industry and Australia’s international maritime obligations. The total area available for ship navigation is approximately 80% of the marine park. Additionally, the Australian Government introduced the Marine Parks (Great Barrier Reef Coast) Zoning Plan in 2003 to complement existing protection mechanisms. The plan divides the marine park into areas that fall into one of 8 zones, with different activities allowed and/or prohibited in each zone. Ships are only permitted in the ‘general use’ zones which, in addition to the DSA, makes up the area within which navigation through the marine park is allowed.
Hydrographers Passage falls within the DSA and ships seeking to transit the area are subject to the rules and regulations made under both international and domestic regulatory instruments.
Hydrographers Passage
Hydrographers Passage provides a deep-water shipping route through the GBR between Blossom Bank pilot boarding ground (PBG), near the entrance to the passage, and the Cumberland Islands, northeast of Mackay (Figure 11). It is the shortest route to the Coral Sea from ports located on the coast of central and southern Queensland, including those at Mackay and Hay Point. Hence, most of the seaborne trade between these ports and ports abroad, particularly the export of coal from Hay Point, passes through Hydrographers Passage.
Figure 11: Map showing Hydrographers Passage (shipping route is indicated in red)
Source: Australian Reef Pilots, annotated by ATSB
The distance along the route from Blossom Bank to the port limits of Mackay and Hay Point is about 115 miles. At its narrowest point, the route is about 1 mile wide and has a minimum charted depth of 25 m. It is navigable by any size of ship visiting the region’s ports.
Ships passing through Hydrographers Passage can encounter strong currents which interact with the geography of the reefs on either side of the route. The flood tide sets south‑south‑west and the ebb tide sets north‑north‑east, the rate varying between spring and neap tides. Between Ferris Shoal and Bond Reef, streams of over 5 knots during spring tides can be encountered, with sets across the track occurring near the time of high and low water. As navigation through the narrow Hydrographers Passage can be challenging, AMSA provides an integrated network of fixed and floating visual and electronic aids in the area, which is also covered by a coastal vessel traffic service.
Pilotage is compulsory through Hydrographers Passage for ships over 70 m, as well as for loaded oil and chemical tankers and gas carriers, irrespective of size. The compulsory pilotage area extends from Blossom Bank PBG to the vicinity of Tern Island. The distance along the shipping route between these two locations is about 80 miles and the pilotage typically takes 5 to 7 hours. Pilot transfers usually occur in the vicinity of Blossom Bank PBG and Tern Island and are conducted by helicopters operating from Mackay Airport.
The pilotage
Global positioning system failure
Mode and accuracy
The GPS data recorded by the Rosco Poplar’s VDR included accuracy as a parameter, displayed as a horizontal dilution of precision (HDOP) value. If the HDOP was reported in the data sentence as having a value greater than 4, this would trigger a visual alert on the radar and ECDIS units, indicating insufficient accuracy for navigation. Additionally, these data sentences would report the GPS mode that was displayed on the radar and ECDIS.
During the pilotage, prior to the time of failure, the HDOP value varied between 1 and 7 and HDOP alerts were displayed on the radar units. The GPS mode alternated between differential GPS and standard GPS (values 2 and 1 respectively), until changing to 0 (invalid fix) at 0312:15 local time.
Time of failure
Following the occurrence, the ATSB reconstructed Rosco Poplar’s actual track during the approach to Bond Reef using the ship’s x-band radar display images recorded by the VDR with corresponding navigational chart features in the vicinity (Figure 12).
Figure 12: Position indicated by GPS at 0305 vs actual position (radar overlaid in grey)
Source: Australian Hydrographic Office, annotated by ATSB
The x-band radar display images captured by the VDR indicated that at 0218, the radar was switched to standby mode when the route waypoint input task was commenced. At 0218:07, the last captured image of the radar screen prior to the waypoint input displayed 2 AIS virtual aid‑to‑navigation returns, and the nearby ship Camellia Island, and each had coincident radar and AIS returns. This indicated that the GPS position input to the radar was accurate at that time. Just prior to this, at 0217:40, the HDOP value changed from 5 to 1, with a change in satellites-in-view also recorded. After 0217:40, no further changes to the HDOP value and satellite-in-view were recorded until the GPS position was lost at 0312:15.
Following the completion of the waypoint input, and returning the radar to active mode, the radar image captured at 0234:52 showed a separation of Camellia Island’sradar return from its reported AIS position, indicating that the selected GPS unit was no longer providing an accurate position (Figure 13). This separation gradually increased and the ship began to deviate from the planned route towards Bond Reef beacon (visible on the radar display) as the pilot’s heading orders were based on the erroneous position and track displayed on the ECDIS and PPU. Assessment of the ship’s reconstructed actual track indicates that by about 0256, it had deviated far enough from its planned track to be within the red zone of Little Bugatti reef sector light ahead.
Figure 13: Radar image at 0235
Source: Rosco Poplar, annotated by ATSB
From the approximate time at which the GPS unit began providing inaccurate positional data, until the loss of GPS signal altogether at 0312:15, the ship’s actual position deviated approximately 0.92 miles (1,704 m) from the position indicated by its GPS. The invalid position placed the ship on the planned 202° (T) track rather than indicating its actual position, with the deviation gradually increasing over this period as the ship actually made good a course of approximately 195° (T) (Table 1).
Table 1: Deviation distance of ship from reported position
Time
Deviation of ship from reported position (nautical miles)
2:52:07
0.54 (1,000 m)
2:54:07
0.56
2:56:07
0.59
2:58:07
0.64
3:00:07
0.67
3:02:07
0.72 (1,333 m)
3:04:07
0.75
3:06:07
0.81
3:08:07
0.83
3:10:07
0.89
3:11:07
0.92 (1,704 m)
Failure mode
The ATSB attended the ship after the scheduled removal and replacement of the JRC GPS units and their antennae was completed. As a result, inspection and testing of the GPS units to determine the exact cause of the failure was not possible.
The GPS units’ manufacturer, JRC, advised that the likely cause of the error was an internal failure related to the antenna of the selected GPS unit. From the time the GPS unit began to malfunction until 0312:15, when the GPS position was lost, the unit continued to send processed data of invalid position, without updating the accuracy information. Hence, the invalid position data did not generate any positional error alerts on the GPS unit, which would also have triggered alerts on connected navigational aids. It was not until the GPS position was lost that the ECDIS units started displaying that the GPS unit had regressed to dead reckoning mode (to indicate that it had reverted to estimating position based on the ship’s heading and log speed). The exact reason why the GPS unit did not detect the positional error could not be determined due to the limited available data.
While the manufacturer noted that spoofing or jamming were potential sources of interference in older model GPS units, no other vessels in the area at the time of the pilotage reported an error.
There were no potential interactions identified between the crew and the ship’s navigational aids that could be considered to have led to the gradual degradation of the GPS position accuracy.
Correction of position
Data from the ship’s VDR indicated that, after the GPS status changed from 1 to 0 at 0312:15, the GPS provided blank data sentences containing no data for a period of about 36 seconds. This resulted in multiple audible bridge alarms being triggered, which were also displayed on the ship’s radar and ECDIS units. The invalid position indicated by the GPS aligned with the time at which these alarms were triggered. At 0312:51, the GPS status changed from 0 to 1 and the GPS position of the ship began displaying accurately on the ECDIS units and PPU, indicating it was 0.92 of a mile (1,704 m) to the east of its previously indicated position.
The cause of this reset could not be determined. The GPS unit may have performed an internal correction and reset itself or alternatively, someone on the bridge may have reset the unit or used the 3-way GPS selector switch to change over to a different GPS unit to provide input to the ECDIS units and other navigational equipment.
The master reported to AMSA that they switched over to a different GPS unit when they realised the ship was perilously close to Bond Reef, but this could not be confirmed when ATSB investigators interviewed the master later. While selection to a different GPS unit would usually result in the GPS signal being continual, a reset would normally take approximately 30 to 60 seconds to complete.
Bridge resource management
Bridge resource management (BRM) can be defined as the effective management and utilisation of all resources, human and technical, available to the bridge team to ensure the safe completion of the vessel’s voyage.[18]
Effective BRM facilitates communication, cooperation and coordination among the individuals involved in a ship’s navigation to counter the risks associated with single-person errors. Features of effective BRM include, but are not limited to, passage planning, appropriate information exchange, delegation of duties, situation awareness and effective communication.
Ships are generally exposed to higher risks in pilotage areas because of the smaller margins of safety due to factors which include the reduced depth and width of fairways, increased traffic, tidal variations and stronger currents. Despite the duties and obligations of a pilot, their presence on board does not relieve the master or officer of the navigational watch from their duties and obligations for the safety of the ship.[19] It is essential that pilots and bridge team members observe effective BRM practices and work closely together to execute the passage plan and actively monitor the ship’s progress.
It is a requirement of the STCW that deck officers be competent in BRM principles. Similarly, MO54 required coastal pilots to undertake BRM training every 4 years as part of their continual professional development.
Many serious maritime accidents during pilotage have been attributed to ineffective BRM and in many such incidents, it was found that the master and deck officers ceased to monitor the navigation and position of the ship once the pilot had boarded.
Passage plan
The agreed passage plan, its understanding and the establishment of a ‘shared mental model’ by the entire bridge team forms the basis of a safe voyage under pilotage conditions.
Rosco Poplar’s passage plan for the pilotage followed the Queensland Coastal Passage Plan (QCPP). The QCPP was first developed in 2011 as the standard industry passage plan by AMSA and the coastal pilot working group (CPWG) under a different title and updated and renamed in 2013. Under MO54, the QCPP is the approved passage plan for pilots and ship masters.
A key aim of the QCPP is to improve the readiness of ships transiting coastal pilotage areas by ensuring that passage plans, waypoints and other planning is completed in a standardised manner. The QCPP provides detailed guidance for:
standard routes (a set of relevant waypoints) and planning chartlets
REEFVTS and reporting requirements
preparation for pilot boarding
master-pilot information exchange
under-keel clearance (UKC) and draught restrictions
bridge resource management.
In the days prior to Rosco Poplar’s arrival at Blossom Bank PBG, Auriga provided the master (via email) the passage plan waypoints and information to assist with preparation for the pilotage passage. When the pilot boarded, the waypoints had been input into the ECDIS units, but not into the radars and GPS units, as required by the passage plan.
Position and track monitoring
When navigation is planned through coastal or restricted waters, the ship’s progress along the planned track must be continuously monitored.
While the introduction of modern electronic aids for real-time position monitoring such as ECDIS and PPUs enhance situation awareness and provide multiple monitoring tools, their effectiveness depends on the accuracy of the sensors providing heading, position, and speed data. Traditional navigation methods involving visual transits, clearing ranges and techniques, such as parallel indexing (PI) in particular, provide real-time position and cross-track monitoring, independent of these GPS position sensors. Therefore, the effective use of these techniques remains essential for navigation within coastal or confined waters and are required competencies for coastal pilots under AMSA’s check pilot assessment framework (see the section titled Check pilot system).
The Auriga pilotage operations safety management system (SMS) required its pilots to use visual observation of transits and radar techniques, including PI and clearing ranges to complement a PPU and ECDIS. Accordingly, the company’s standard passage plan for Hydrographers Passage included details of the specific transits, PI and clearing ranges for each leg of the route.
Rosco Poplar’s SMS also included guidance for position monitoring and crosschecks by fixing the ship’s position at regular intervals using radar and visual observations to confirm the accuracy of the ECDIS. The prescribed frequency of crosschecks depended on the ship’s area of operation. For inland navigation, including navigation in confined, restricted and pilotage waters, the procedure recommended a crosscheck at least every 30 minutes. The SMS provided that if there were any doubts regarding GPS position accuracy, then more frequent crosschecks were to be carried out.
Master-pilot information exchange
The early exchange of information between the pilot, master and bridge team should ensure that all personnel have a common understanding of the passage plan and their individual roles and responsibilities for executing it. An aim of the exchange is to bring the resources of the pilot together with those of the ship’s bridge team in a structured and team-orientated way. This ensures that all personnel maintain a shared mental model of the pilotage, during which critical decisions and actions are based on accurate information and challenged where necessary to elicit appropriate responses.
Auriga had implemented a master-pilot information exchange (MPX) checklist and aide memoire, which were specific to its coastal pilotage operations and adopted from standardised procedures promulgated by AMSA. The checklist was designed to prompt the pilot and master to agree on the passage plan and discuss important information about the ship and its equipment to ensure all systems were in working order and appropriately configured for the pilotage. The accompanying aide memoire document included discussion topics relating to BRM principles, including bridge organisation, watchkeeping and communication requirements during the pilotage, including challenge and response. Under Auriga’s pilotage operations SMS, a key aim of the MPX was to clarify each bridge team member’s roles and responsibilities for the pilotage.
Prior to taking over the conduct of Rosco Poplar, the pilot used the checklist to verify some aspects of the ship’s preparedness for the pilotage. Bridge audio obtained from the VDR captured the MPX conversation. The master informed the pilot of the gyro error and advised that the ECDIS was operating normally with appropriately updated charts. The pilot checked the rudder indicator and noted that the bridge was not equipped with a functional rate of turn (ROT) indicator. The master informed the pilot that the main engine and steering gear were in working order and advised that both anchors were available and ready for emergency use.
After establishing that the master had made the mandatory ‘pre-entry report’ to REEFVTS, the pilot checked that the magnetic compass light was functional and verified the ship’s draught of 7 m, thereby concluding the MPX.
While the aide memoire was signed by both the pilot and master, its contents were not referred to during the exchange. Significantly, the MPX had not established each bridge team member’s roles and responsibilities in respect to monitoring the ship’s progress.
Situation awareness and distraction
Situation awareness may be defined as the ability of an individual to possess a mental model of what is going on at any one time and to make projections as to how the situation will develop.[20] Situation awareness provides the foundation for effective decision‑making and response measures in the event of the situation changing. In team environments where individuals are required to perform different, interdependent tasks essential for accomplishing a common goal, effective collaboration and coordination between the individuals are critical factors for the acquisition and maintenance of situation awareness.
Situation awareness on ships can be degraded by distractions, which interrupt an individual from their primary tasks, increasing the likelihood for error. Distractions may be related to the task or from some external, unrelated source or event. While distractions may be commonplace and can usually be managed, it is easy to become drawn into a distraction and overlook much more critical events with serious implications for the safety of the ship.[21]
While modern ships are equipped with multiple technical information sources aimed at reducing human error, these systems can also increase workload and create distractions when not managed effectively.
Lookout
The International Regulations for Preventing Collisions at Sea, 1972, as amended (COLREGs) provide internationally agreed rules and measures to prevent collisions. The COLREGs generally apply to all vessels at sea. With respect to keeping a lookout, Rule 5 of the COLREGs (Look-out), stated:
Every vessel shall at all times maintain a proper look-out by sight and hearing as well as by all available means appropriate in the prevailing circumstances and conditions so as to make a full appraisal of the situation and of the risk of collision.
In this context, available means included radar and AIS.
The International Convention of Standards for Training, Certification and Watchkeeping[22] (STCW) also provided that the lookout must be able to give full attention to the keeping of a proper lookout and no other duties shall be undertaken or assigned, which could interfere with that task.
Rosco Poplar’s SMS included procedures for keeping a proper lookout, which were consistent with the COLREGS and STCW requirements. Auriga’s pilotage SMS contained similar provisions with respect to keeping a lookout during pilotage, including emphasis on the STCW guidance that the lookout is not given tasks which could interfere with their lookout duties. The procedure also required that the pilot’s PPU was not to be used to the exclusion of other navigational aids, and that keeping a proper lookout through visual observations and proper use of radar were the primary means for maintaining a proper lookout.
Communication
Recorded bridge audio data indicated that, after the early exchanges between the pilot and bridge team, there was no further communication regarding the ship’s progress until immediately after its near grounding. Following the MPX, the pilot had continued to give helm orders while the second mate and master discussed discrepancies between the ship’s heading displayed on the radar and ECDIS units.
When interviewed by the ATSB after the occurrence, the master stated that as the ship proceeded from Ferris Shoal, he observed that the relative bearing of a flashing white light had been closing on the port bow and was almost directly ahead of the ship. Being unfamiliar with the area, the master did not query the pilot to identify the light and assumed it was not Bond Reef beacon but some other light.
Bridge audio data indicated that at 0311, the pilot ordered a course change to 205° after sighting the red sector light on Little Bugatti Reef. It was not until 0313, after the GPS position had reset and started indicating that the ship was significantly off the planned track that the pilot discussed the event with the master.
Portable pilot unit
A PPU is an aid to pilotage operations with the intent to improve safety and efficiency of the operation. Its primary use is to provide independent, accurate GPS position, course and speed information. A PPU also provides other information such as charts, passage plan and AIS information.
While PPU technology continues to become more sophisticated, a basic PPU typically consists of a tablet or laptop device loaded with electronic chart software, and a sensor to provide GNSS positional and AIS data. The sensor may have its own independent antenna to obtain the data, or it may connect to the ship’s pilot plug to obtain positional, heading and AIS data from its navigational equipment.
The use of these units during pilotages can provide an additional level of information to the pilot, aiding situation awareness. While PPU use is broadly encouraged by pilotage associations worldwide, several guidelines have been published to inform pilots on best practice for PPU use and highlight the potential risks involved with their improper set-up and use.[23]
Set-up and use
The PPU used by the pilot at the time of the occurrence was a KSNTEK brand, model number KSN55-C (Figure 14). The unit was a dual-channel AIS receiver, with in‑built GNSS and rate of turn (ROT) capability. The unit could operate independently or be connected to the ship’s navigational systems via the pilot plug. The unit displayed position, speed, course, heading and ROT information on its own LCD screen and was also capable of displaying that information on a tablet or computer device equipped with electronic navigational charts (ENC). Auriga provided its pilots with tablet devices and SEAiq Pilot software.[24]
Figure 14: KSN55-C model PPU and example SEAiq chart display on a tablet device
Source: Auriga
When connected via the ship’s AIS pilot plug, the PPU’s inbuilt AIS receiver was designed to automatically switch off and the unit would then receive data from the ship’s AIS unit. This data included position, speed over ground (SOG), course over ground (COG), heading, and, if available, ROT information. In addition, AIS data for other ships in the area could also be displayed. After connection to the pilot plug, there was an option to continue transmitting and displaying positional data derived from the PPU. The selection could be made through the unit’s display menu.
These settings allowed the user to determine the source of each parameter for the ship (position, SOG, COG, heading and ROT), which was displayed via a status bar on the pilot’s tablet device. The PPU instruction manual stated that the PPU heading was not recommended for use, with a preference for the ship’s AIS unit data for this parameter, but that the ROT from the PPU should be used.[25]
The pilot stated that the PPU was connected to the ship’s AIS plug. The pilot incorrectly believed the PPU’s GPS data was independent of the ship’s GPS input with only AIS data sourced from the ship’s unit. The pilot also stated that they were unaware of the ability to change these settings.
Following the occurrence, neither the pilot nor Auriga were able to provide raw PPU data files for the pilotage. Therefore, the specific settings used by the pilot could not be determined. However, SEAiq data provided by Auriga for the time of the occurrence included the same positional data recorded by the ship’s VDR and communicated via the AIS to REEFVTS.
Alarms
The SEAiq pilot software included alarm and data verification options. These included a ‘show device GPS’ option, which displayed the pilot’s tablet device’s internal GPS position along with the position from the selected PPU or AIS source. The option, if enabled, was intended to be used to help validate information reported from independent sources.
Separately, the software also included a verification alarm. If enabled, an alarm would sound if the PPU internal GPS position differed by more than 100 m from the position derived via the AIS pilot plug. The alarm could be silenced by the pilot, however, it would only remain disabled for one minute if the condition continued to exist.
Training and procedures
The Auriga pilotage operations SMS provided that the PPU was a supplementary aid to be used in conjunction with traditional pilotage methods and ship navigational equipment. It also emphasised that because the accuracy and reliability of ships’ position sensors cannot be easily verified, the PPU should be configured to utilise its own independent position sensor. A further requirement was that the pilot regularly check the positional accuracy of the PPU by comparing its position with leading and sector lights and radar ranges of charted features.
Auriga also trained pilots in the use of the PPU and SEAiq software, including implementation of an induction presentation. This presentation emphasised the importance of ensuring that the unit’s internal GPS be used to avoid ship system errors. While the presentation contained detailed information about using the software, it did not contain information about multiple PPU settings and how these were selected during set-up.
Vessel traffic service
Vessel traffic service (VTS)[26] providers in Australia are authorised and appointed by AMSA in accordance with its obligations as a competent authority under SOLAS Chapter V/12 and IMO Resolution A.1158.32 (20). Additionally, AMSA is responsible for ensuring any VTS provider it authorises complies with the relevant requirements of the Navigation Act2012 and Marine Order 64 – Vessel Traffic Services, especially in relation to the conditions imposed on its authorisation.
The Great Barrier Reef and Torres Strait vessel traffic service (REEFVTS) is a coastal VTS provided by Queensland’s maritime safety regulator, Maritime Safety Queensland (MSQ). As the appointed VTS authority, MSQ is responsible for its day-to-day operation and delivery. While AMSA has no direct involvement in the day-to-day operations of REEFVTS, it maintains a high‑level strategic role for service provision. The respective responsibilities of AMSA and MSQ, as well as their joint arrangements for REEFVTS governance and funding, are set out in a memorandum of understanding between the 2 organisations.
The traffic service had VTS centres at Townsville and Gladstone, which were manned 24 hours a day by vessel traffic service operators (VTSOs). The declared objectives of REEFVTS were to enhance navigational safety in the area by interacting with shipping, to minimise the risk of a ship‑related incident, environmental damage and pollution and to provide the ability for a quicker response to an incident. Unlike air traffic control in the aviation industry, REEFVTS does not control or direct traffic. The service’s main role is to assist shipping by providing relevant information and advice.
The 2 major components of REEFVTS are a ship reporting system and monitoring and surveillance systems incorporating the use of AIS, automated position reporting via Inmarsat‑C[27] polling, VHF radio reports and radar. These monitoring and surveillance systems were integrated into a decision support tool (DST) known as maritimeCONTROL, implemented in 2020 to replace and improve on the previous system.
The DST traffic image display used ENCs on which ship position and track information was displayed in real time using data from AIS and, where available, radar, in addition to Inmarsat‑C polling reports. The DST allowed for the configuration of boundaries to areas of critical interest, including potential grounding locations, unplanned route deviations and critical turn locations.The establishment of the boundaries enabled the DST to generate visual and audible alerts to notify the duty VTSO of developing situations potentially dangerous to navigation. These automatic alerts were intended to enhance the duty VTSO’s situation awareness and enable timely interaction with a ship if necessary.
Procedures were established by REEFVTS for responding to DST alerts and assessing whether an unsafe situation was developing. While these provided that a ship’s unplanned deviation from its planned route or proximity to shallow water could be indicative of an unsafe situation, the duty VTSO was to use their professional judgment in deciding whether to interact with the ship, such as instances where the ship’s current track indicated a risk of grounding. This reflected guidance from the International Association of Marine Aids to Navigation and Lighthouse Authorities (IALA) which provided that ‘before navigational support is provided and if time permits, a VTS should make an assessment of capabilities and conduct other relevant checks’.[28]
The primary technology used by the DST to track ships in real time was AIS, the carriage of which is mandatory on all international-voyaging ships over 300 gross tons and all passenger ships. A ship’s AIS transponder contains a VHF transmitter which automatically broadcasts information such as its position, speed, and navigational status. This information is electronically exchanged with that of other nearby ships, as well as with AIS base stations that relay the information to the relevant VTS provider. As such, the effectiveness of AIS as a tool for VTS monitoring purposes depends on the accuracy of the transmitted information, such as GPS data, and the ship’s compliance with reporting procedures including static data, such as voyage details. While AIS transmissions can be vulnerable to different sources of interference, advancements since its introduction in the early 2000s have resulted in it being widely used for VTS traffic monitoring.
Unlike AIS, shore-based radar stations allow for independent traffic surveillance and monitoring by VTS. Radar coverage is generally limited by weather conditions and the number and range of radar stations. Additionally, it does not provide information about the identity of a ship, its particulars or planned route, and a VTS needs to obtain such information from other sources. Some DST systems, such as the one used at REEFVTS, can combine both AIS and radar information to provide greater accuracy and certainty in respect to a ship’s position and progress.
Before 2015, REEFVTS operated 5 radar stations positioned at significant locations across the Great Barrier Reef region, such as DSAs. Each radar station had an effective operational range of 36 miles, which resulted in an effective radar coverage of less than 20% of the REEFVTS area.
In 2015, the REEFVTS Management Group, consisting of AMSA and MSQ personnel, decided to decommission all radar stations, except the one at Hammond Island covering part of the Torres Strait. The group reasoned that AIS had proven sufficiently reliable as REEFVTS’ primary real‑time monitoring technology, while radar use was mostly limited to detecting ships not reporting via AIS, which had become increasingly infrequent (although less so in the Torres Strait).
By June 2017, 4 radar stations had been decommissioned, including the one located at Penrith Island in 2015. This radar station was some 70 miles from the outer reaches of the Hydrographers Passage and slightly less from its entrance (Bond Entrance, where this incident occurred), which meant those parts of the pilotage area were outside its effective 36 mile radar coverage.
Regulation of coastal pilotage
Compulsory pilotage requirements for the Inner Route of the GBR north of Cairns and Hydrographers Passage were established in 1991 and later extended to areas of the Whitsundays and Torres Strait (Figure 15).
Figure 15: Great Barrier Reef and Torres Strait compulsory pilotage areas
Source: Australian Maritime Safety Authority
Although complemented by measures, such as REEFVTS and a comprehensive system of navigational aids, coastal pilotage is a key defence against shipping incidents within the GBR and Torres Strait. Ships are generally exposed to higher risks in these confined waterways, where factors such as the reduced depth and width of fairways, increased traffic, tidal variations and stronger currents leave little margin for navigational errors. Therefore, it is essential that the service provided by coastal pilots are as safe and effective as possible.
Since 1993, AMSA has been responsible for the regulation of coastal pilotage. In carrying out this function, AMSA has implemented a regulatory framework for coastal pilotage operations under MO54. Its provisions set out the licence requirements for pilots and pilotage providers, the performance of pilot duties and safe operating standards for both pilots and providers. The check pilot system is a core component of the regulatory framework.
Check pilot system
In 2003, AMSA implemented the check pilot system declaring it an important initiative for the ongoing professional development of coastal pilots and a tool for maintaining pilot competency.[29] Under the system, all coastal pilots are required to undertake a check pilot voyage in the area, or areas, for which they are licensed, at least every 2 years. A check pilot voyage is defined by MO54 as ‘a voyage on which a pilot’s competency is being assessed by a check pilot’. While the assessments are conducted on behalf of AMSA, the check pilots conducting assessments are current pilots employed by either of the 2 pilotage providers. Usually, the check pilot and the pilot being assessed are from the same provider.
Check pilot concept and reliability challenges
The check pilot concept has its origins in the aviation industry. Since 1999, check pilot systems in the Australian aviation sector have been underpinned by a competency-based training and assessment (CBTA) framework.[30] Under a CBTA approach, a person is trained to meet specified standards that define the skills, knowledge and behaviours required to safely and effectively perform a task in a particular context and is then assessed for competence against those standards.[31] Australian vocational education and training (VET) has been ‘competency-based’ since the late 1980s and is built upon the Australian Qualifications Framework (AQF), which forms the basis for educational and professional assessment requirements.[32] In the context of coastal pilotage, the AMSA check pilot system was developed to reflect applicable AQF competency level criteria[33] and established CBTA principles.[34]
The specific competency standards used for assessing coastal pilot competency were captured in the AMSA Form 15 checklist titled ‘Check voyage / assessment transit details’ (Appendix A). The checklist contained 79 performance elements under 10 different performance criteria, developed to reflect best coastal pilotage practice. The criteria covered:
personal safety
master and pilot information exchange (MPX)
passage planning and execution
availability of nautical charts and publication
VHF radio use
bridge resource management (BRM)
rest management
contingency planning
navigation and electronic equipment use
pilot licencing and legal requirements.
The Form 15 criteria were similar to standards used for assessing pilot proficiency in aviation in that they consisted of both technical skills, such as knowledge and equipment use, and non‑technical skills (NTS).[35] The NTS were most prevalent in criteria relating to BRM and MPX, which incorporated performance elements involving situation awareness, decision-making, communication and teamwork.
A guidance document supplemented the checklist with rules and principles for check voyages assessments. This document contained information about how assessments were to be conducted, the construct of performance elements and the prescribed remedial actions if significant deficiencies were identified.
Generally, assessment of the human factors inherent in NTS performance relies on the observation of behaviours which contribute as evidence of competency.[36] In the aviation industry, this requirement has led to the development of comprehensive training and assessment systems which typically provide a framework of behavioural markers. These are aimed at assisting assessors to make valid and reliable judgements regarding competency and performance, particularly in respect to NTS.
Consistent and accurate application of assessment standards is fundamental to ensuring the quality of any assessment system. If assessors cannot be trained to be interchangeable, then assessment outcomes will depend more on the assessor than the behaviours of those being observed.[37] Overly harsh applications of assessment standards may give rise to needless additional training and costs, while having a negative effect on the career and motivation of the person being assessed. Alternately, assessing a person as competent when they have in fact underperformed could have serious safety implications.
Research indicates that reliable assessment of airline pilots’ NTS has at times proven difficult, with some studies revealing unacceptably low inter‑rater reliability (IRR)[38] in the assessment of flight crew performance.[39] In one 2013 study it was observed that assessors of the same performance often applied the same or similar reasons to arrive at different assessment outcomes or used different reasons to arrive at the same outcome.[40] Such variability in the application of standards poses a risk to the desired competency assurance objectives of the assessment process.
Factors which may influence IRR can be complex and include the experience, biases, motivations and perceptions of the assessor, the nature of the task or scenario and the particular dimension being observed, such as factors involving cognitive and social performance.[41] Variation between assessors in respect to cognitive criteria including situation awareness may also arise due to the unspecific construct of the assessment criteria, requiring them to speculate about what is going on in the mind of the person being assessed instead of focusing on observable performance.[42]
In recognition of the importance of IRR, aviation regulators have sought to ensure it is considered in the development and monitoring of operators’ training and assessment systems. In a 2011 advisory publication concerning non‐technical skills training and assessment[43], the Civil Aviation Safety Authority (CASA) advised:
Any behavioural rating system must be underpinned by adequately trained assessors. The training of raters is quite a complex undertaking. Instruction should develop thorough understanding of the science of rating scales, the characteristics of the actual rating system used, sources of rater bias, the concept of inter-rater reliability, debriefing skills, and procedures to calibrate and optimise the accuracy of observations and ratings.
In the maritime industry, research concerning how NTS are assessed, particularly in respect to pilotage, has been relatively limited. The Australian Marine Pilots Institute (AMPI) developed a code of good practice for pilot competency and performance.[44] Last revised in 2020, it is noted within the document that:
AMPI has identified the need to develop better processes for assessing the performance of marine pilots. The intent is to offer support and remediation to pilots where this is appropriate.
This AMPI Code identified 9 competencies representing pilot best practice and 25 associated behavioural markers which AMPI has used for its competence and performance guide. The Code identifies behavioural markers indicative of both good and bad performance for each competency. AMPI notes that:
Markers of good behaviour can provide guidance to pilots regarding exemplary behaviour whereby they may be seen as a role model for trainees or other pilots. Markers of poor behaviour may help to identify early evidence of underperformance and provide a basis for support and remediation of underperforming pilots before safety or standards are compromised. It should be noted that the good and poor behavioural markers represent the extremes of pilot performance. There is a wide spectrum of normal and appropriate pilot behaviour between these extremes – the ‘shades of grey’ of pilotage practice. Patterns of behaviour, behavioural markers, performance measures, resources and supports are identified for each of the AMPI Competencies. The behavioural markers do not represent an exhaustive list but are examples of what may be considered in ‘good’ and ‘poor’ behaviour.
Like the studies conducted in the aviation industry, the AMPI guidance highlights the complexity of assessing NTS aspects of pilot competency and performance. The AMSA check pilot system, which comprised the Form 15 checklist and accompanying guidance, did not feature a framework of behavioural markers to guide check pilots in interpreting the performance elements contained within the checklist.
For a competency-based assessment system to be a valid and reliable measure of competency, assessors must be provided with adequate training, instruction and guidance to ensure assessment standards are consistently interpreted and applied, irrespective of the assessor conducting the assessment. In practice, achieving this consistency can be a complex and difficult undertaking requiring appropriate consideration of all the various factors, which have the potential to limit the effectiveness of the system overall.
Check pilot licencing and training
According to AMSA,[45] check pilot licence eligibility requirements under MO54 were intended toensure coastal pilots with extensive operational experience were engaged to assess coastal pilot performance. Applications for a check pilot licence were endorsed and submitted to AMSA by the respective pilotage provider on behalf of the pilot.
Applicants were required to hold an unrestricted coastal pilot licence and to have performed the duties of a licenced pilot during a sufficient number of transits of the relevant pilotage area, as specified under MO54. Additionally, applicants were required to undertake an oral examination, an AMSA-approved psychometric assessment and a workplace assessment training course from an approved training provider.
The workplace assessment training consisted of 4 assessment-specific units from a certificate IV level course in workplace training and assessment, accredited under the Australian qualifications framework. The course content was designed to be generic for all VET purposes and applicable to many professions and industries. As such, it did not include specific training for assessing any of the competencies, skills or behaviours unique to coastal pilotage. However, from 2020, as an alternative to the workplace assessment training course, AMSA began accepting the completion of a more specific ‘Assess Competency as a Marine Check Pilot’ course. This course was delivered by a Queensland-based maritime training provider and was designed to include training for assessing competencies, skills and behaviours for all maritime pilots, including coastal pilots.
Previous ATSB findings relating to pilot checking
In February 2009, the oil tanker Atlantic Blue grounded on Kirkcaldie Reef in the Torres Strait while a coastal pilot was conducting it. A subsequent ATSB investigation (report MO-2009-001) found that, in addition to other contributing factors, the pilot’s passage plan and piloting system, did not define off-track limits or make effective use of recognised BRM tools (the pilot was also a licensed check pilot). More importantly, that investigation found that regular assessments of the pilot’s procedures and practices under the check pilot system, conducted over several years, had not resolved these apparent deficiencies.
Following the release of the ATSB’s findings in the Atlantic Blue investigation, the ATSB was advised that AMSA, AMPI and a number of coastal pilots held concerns that systemic issues, which could impact on the safe operation of coastal pilots and the ability to fully develop a safety culture, may exist. Consequently, the ATSB initiated a broad scope systemic safety issue investigation into coastal pilotage, which also examined the check pilot system. During this investigation (report MI-2010-011), the ATSB reviewed all 550 check voyage assessments conducted since the system’s introduction, interviewed a number of industry stakeholders and surveyed all 82 pilots to analyse potential safety issues.
Analysis of the 550 check voyage assessments and supporting evidence identified a significant safety issue. No pilot had ever been deemed unsatisfactory, with a 100% pass rate since the introduction of the check pilot system. The ATSB concluded that the system was ineffective as a measure to assess the adequacy of the individual systems of coastal pilotage and pilot competency, with the following factors limiting the effectiveness of the system:
absence of uniform assessment standards against which to make an objective assessment because there is no pilotage safety management system with standard, risk-analysed pilotage procedures and practices;
conflicts of interest as a result of the check pilot being remunerated by the pilotage provider to assess a peer on behalf of AMSA;
conflicts of interest as a result of the working relationships between the pilots and between pilots and their provider; and
lack of a formal review process for each assessment to ensure corrective action is taken and for continuous improvement.
Over the next few years, AMSA provided the ATSB 6 updates on the progress of safety action that it was undertaking to address the safety issue. In October 2012, AMSA advised that it had developed a common industry passage plan (the QCPP) and standard operating procedures for coastal pilots. It also stated that it was conducting a review into check pilotage and training requirements, including an investigation into the potential use of simulators for training purposes. The issue relating to independence of check pilots, including how they were engaged and remunerated was to also feature in AMSA’s review.
In 2013, AMSA further advised it had implemented an electronic process to track and develop reports based on check pilot assessments, providing it with the means to identify potential trends and then work to address those trends. In the same update, AMSA stated that it was also seeking to improve the check pilot system through successive meetings with the coastal pilot training working group (CPTWG) that included coastal pilots and representatives from pilotage providers and AMSA.
In subsequent updates, AMSA advised that the check pilot framework was considered an item for ongoing review and that it continued to work with the CPTWG to make improvements. It also stated that ‘the check pilot framework, incorporating aspects related to check pilot selection, training, check runs, check assessment criteria and the use of simulation, has been agreed by the CPTWG as one of the key areas of the group’s future work and focus.’
In 2015, a new requirement was introduced for pilotage providers to endorse, via nomination, prospective check pilot applicants to AMSA (as opposed to individual pilots nominating themselves). This requirement was to ‘address inconsistencies between the aspirations of individual pilots, and the commercial ramifications related to internal remuneration arrangements for check pilots.’
In February 2016, AMSA provided its last update and advised that it had reviewed the contents of the guidance notes for check pilot assessment voyages and the Form 15 checklist. The review resulted in incremental and relatively minor changes to the checklist, considered to improve the form by simplifying the completion requirements and removing duplication of information. This update stated that assessments were ‘registered and reviewed in full by AMSA for consistency, detection of any trends and/or behaviours and whether any further action may be required.’
In March 2016, after assessing the residual risk from the safety issue taking into account the various safety actions that AMSA advised had been taken, the ATSB closed the safety issue as having been adequately addressed.
In March 2023, during the course of this investigation, AMSA advised that no trend analysis of assessment outcomes had been conducted, citing the extremely low frequency of deficiencies identified in assessments as the principal reason for not doing so. The ATSB obtained check voyage assessment records since 2017 to analyse and verify this claim (see the section titled Assessment outcomes since 2017).
Check voyage assessment construct
For each of the 79 performance elements contained in the Form 15 checklist, of which 37 were denoted as safety critical, pilots were to be assessed as either ‘satisfactory’ (S), ‘satisfactory with deficiencies’ (SWD) or ‘unsatisfactory’ (U). A pilot would receive an overall U assessment if they were assessed as U in any safety critical performance element. An overall SWD assessment would result if the pilot was assessed as U in any element that was not safety critical, or if assessed as SWD in more than 25% of the elements in any single performance criteria.
When completing the checklist, a check pilot could include optional notes in a section provided for each of the 10 performance criteria, where considered necessary. Assessment outcomes were documented in the Form 15 checklist and submitted to the pilotage provider and AMSA. Completed assessments were to be reviewed by AMSA to determine if any remedial action was required.
If a pilot received an overall assessment result of U, they were required to cease pilotage duties until they completed an AMSA-approved remedial training program and successfully performed an additional check pilot voyage. If a pilot received an SWD overall assessment, they could continue pilotage duties but were required to complete remedial training, with another check voyage recommended within 3 months of the initial assessment. Digital copies of completed assessments were retained by AMSA in its electronic Certification and Pilotage System (CPS) database.
Assessment outcomes since 2017
The ATSB reviewed 490 check voyage assessments conducted between 2017 and 2023 across all compulsory pilotage areas, including Hydrographers Passage. These assessments related to 103 individual pilots from the 2 pilotage providers and had been conducted by 30 individual check pilots.
The review identified that no pilot had ever been assessed as U for any performance element, criteria or overall assessment. An overall SWD assessment occurred on one occasion. Sixty‑two assessments contained one or more SWD scores under various performance elements, which translated to 13% of the assessments identifying any deficiencies or areas for improvement. Of the 103 pilots assessed, 47 (46%) received at least one SWD score for a performance element on at least one check voyage.
Of the 62 check voyage assessments that contained one or more SWD scores, a total of 159 SWD scores were recorded against individual performance elements, with some assessments recording multiple SWDs. This number represented 0.41% of the total number of elements that were assessed across all 490 check voyages conducted during the period (Table 2). Additionally, for each of the 10 performance criteria, the number of SWD scores recorded against elements in each criteria did not exceed 0.69% of the total number of elements assessed during the period.
Table 2: Percentage of SWD scores identified in all check voyage assessments
Performance criteria (# of performance elements)
Total number of times elements were assessed in 490 check voyages
Number of elements marked as SWD
% of total elements in all assessments marked SWD
PC 1: Personal Safety (2)
980
0
0%
PC 2: Master/Pilot Exchange (MPX) (2)
980
2
0.20%
PC 3: Passage Planning & Execution (18)
8,820
37
0.42%
PC 4: Availability of Nautical Charts & Publications (5)
2,450
13
0.53%
PC 5: VHF Radio Usage (7)
3,430
7
0.20%
PC6 - Bridge Resource Management (BRM) (9)
4,410
20
0.45%
PC7 - Rest Management (11)
5,390*
1
0.09%
PC8 - Contingency Planning (3)
1,470
6
0.41%
PC9 - Navigational and Electronic Equipment Usage (12)
5,880
41
0.69%
PC10 - Pilot Licence Conditions and Legal Requirements (10)
4,900
32
0.65%
PC 1 – PC 10 (79)
38,710
159
0.41%
* It was noted that on shorter check pilot voyages, such as those through Hydrographers Passage, ‘rest management’ criteria were assessed as ‘not applicable’ since pilots were not required to take rest breaks on these voyages.
Source: Australian Maritime Safety Authority, as assessed by ATSB
In order to better understand the extremely low numbers/proportion of deficiencies indicated by the data, the ATSB reviewed the number of deficiencies identified by each check pilot. A significant difference in the application of assessment standards between individuals was identified (Figure 16), which was characterised by the following notable features:
Two (2) check pilots (from different pilotage providers) conducted 7.7% of the total number of assessments and accounted for 58% of the total deficiencies identified.
Eight (8) check pilots conducted 25% of the total number of assessments and accounted for 90% of the total deficiencies identified
Twelve (12) check pilots conducted 32% of the total number of assessments and never identified any deficiencies
Figure 16: Proportion of deficiencies identified by each check pilot
Source: ATSB
The ATSB applied the Kruskal-Wallis[46] test to the data to determine whether there was a statistically significant difference between the application of assessments between individual check pilots. This test showed that the probability of obtaining the distribution of such assessment results by random chance alone would be less than 1 in 10,000. That is, the distribution was likely influenced by differences in how individual check pilots conducted their assessments.
Further, data analysis indicated that the rate of deficiencies identified per check voyage did not vary significantly between individual pilots being assessed, or which pilotage provider they were from. The check voyage assessment outcomes were predominantly a function of the individual check pilot conducting the assessment, regardless of which provider they worked for.
Safety analysis
Introduction
At about 0313 local time on 4 May 2022, the 225 m bulk carrier, Rosco Poplar, came within 200 m of grounding on Bond Reef while under pilotage through Hydrographers Passage, in the Great Barrier Reef. At about the same time, the ship’s 2 electronic chart display and information system (ECDIS) units that displayed its position suddenly shifted 0.92 miles (1,704 m) from the last displayed position, which had been on the planned track. The pilot and bridge team visually verified that the ship had narrowly missed Bond Reef. The pilot then conducted the ship back towards the planned track and completed the pilotage without further incident.
The ATSB investigation found that the ship had been deviating from its planned track for a significant period without the navigational error being detected by anyone on the bridge, or by the coastal vessel traffic service monitoring its progress. This analysis examines the factors and circumstances leading up to the near grounding, including the malfunction of the global position system (GPS) unit and the installation configuration of the ship’s electronic bridge navigational equipment. Factors relating to the effectiveness of bridge resource management (BRM) and the pilotage, including use of the pilot’s portable pilot unit (PPU) are also discussed. Additionally, the effectiveness of the Australian Maritime Safety Authority’s (AMSA) check pilot system as a framework for providing pilot competency assurance is analysed.
GPS antenna fault
The GPS unit providing positional data to the ship’s electronic bridge navigation equipment, including both ECDIS units, radars and automatic identification system (AIS), malfunctioned and began sending invalid positional data. The error gradually increased as the pilotage progressed, however, no alarms were communicated as the unit also incorrectly reported that position accuracy was within acceptable limits.
Analysis of the available data identified that the fault occurred between 0218 and 0235. During that period, the ship was approaching the entrance to Hydrographers Passage and was at a critical stage of the pilotage. While the exact error mode could not be determined, it was most likely caused by a GPS antenna fault and not by any external GPS interference or intervention by a bridge team member.
The correction of the GPS position observed at 0313 was most likely a result of the GPS unit resetting automatically or being manually reset by the master.
Sole reliance on GPS positioning
The pilot and bridge team placed sole reliance on GPS positional data to monitor the ship’s progress exclusively using the ECDIS and PPU displays without anyone verifying this information via radar and/or visual observations and position fixing. The pilot gave heading orders solely based on incorrect information from these displays, assuming that a strong ebb tidal stream was setting the ship across the track. The predicted stream was actually setting in a 016° direction nearly reciprocal to the ship’s heading. As a result, the inaccuracy of the GPS position and subsequent deviation from the planned track was not identified.
During the pilotage, the second mate was distracted from their lookout duties after being tasked by the pilot to input waypoints into the ship’s 2 radars. The master was also intermittently distracted by this task, which took some 45 minutes to complete, concluding at 0234. As the second mate occupied one radar unit at a time during this period to complete the task, a radar unit was always available to monitor the ship’s progress and verify its position. However, since neither the pilot nor any bridge team member was using radar to monitor the position, they did not identify that the AIS and radar returns for the nearby ship, Camellia Island, were diverging increasingly apart (indicating a discrepancy with the ship’s plotted AIS position), or that the ship was deviating from the planned track and towards the radar return of Bond Reef light.
Similarly, adequate visual observation of Bond Reef light and the sector light at Little Bugatti Reef would have provided a clear indication that the ship was deviating from the planned track. However, as this means was also not used, it was not until at least 37 minutes after the ship began deviating off course that the pilot visually identified that the ship was displaced to the east of the planned track.
Configuration of the ship’s navigational equipment
While Rosco Poplar’s electronic navigation system configuration complied with the relevant International Maritime Organization requirements and performance standards, it was inherently vulnerable to single GPS unit failures. Because the ECDIS units, radars, AIS and Global Maritime Distress Safety System (GMDSS) were only able to receive the same single GPS data input from either of the 3 GPS units at any one time, the invalid position output from the malfunctioning GPS unit was received and displayed by all these navigational aids.
If multiple GPS outputs had been available to each navigational aid, with alternate GPS units selected on each aid, it is likely that one of them would have displayed the ship’s position accurately and the discrepancy would have been identifiable. Further, most modern ECDIS units facilitate multiple position sensor inputs. These can be configured to cross reference positional data inputs and trigger alarms in the event of a deviation between those inputs. Such set-ups provide a defence against navigational errors resulting from single GPS failures.
Vessel traffic service surveillance
The coastal vessel traffic service (REEFVTS) decision support tool (DST) was dependent on ships’ AIS information to monitor traffic in real time. Rosco Poplar’s AIS-transmitted position continued to incorrectly show the ship was near the planned track after the GPS unit malfunctioned and, therefore, REEFVTS remained unaware of its deviation from the track. When the GPS unit reset, the transmitted position correctly indicated that the ship was about 200 m from Bond Reef. This resulted in the decision support tool (DST) triggering alerts, including a potential grounding alert.
The unusual nature of the ship’s AIS-transmitted GPS position error and the associated series of alerts resulted in the VTSO thinking they were due to a DST system error. They therefore decided to investigate the assessed error (no other position sensor, such as radar, was available to crosscheck) and this consumed significant time. Consequently, about 23 minutes elapsed before the VTSO contacted the ship and was advised that the ship had actually come close to grounding and the associated alert had been correctly generated.
While REEFVTS procedures allow reasonable flexibility for VTSOs to appraise the situation before intervening, and while the observed unusual alerts, ship position and tracking information may have been associated with a system error, checking with the pilot/ship’s crew is always the safest and most efficient course of action when the alert could be legitimate. In this instance, the closest point of approach to Bond Reef had already been passed by the time the alert was received, and so a dangerous navigational situation was not imminent. However, in order to maximise the safety benefit from vessel traffic services, prompt contact with the ships’ crew whenever there is doubt about the validity of an alert could avoid a future serious occurrence, such as a grounding.
Conduct of the pilotage
Bridge resource management
The prevention of errors during pilotage is primarily dependent on effective BRM to establish coordination between the pilot, master and bridge team, taking due account of the ship's systems and the equipment available to the pilot. However, BRM during this pilotage was ineffective. The master-pilot information exchange (MPX) did not establish adequate coordination between the pilot, master and second mate and communication on the bridge was minimal. As a result, the situation awareness of the pilot and bridge team progressively declined in the absence of a shared mental model.
While a key aim of the MPX was to establish individual roles and responsibilities for watchkeeping and expectations for communication during the pilotage, these requirements were neither discussed nor implemented. The subsequent lack of coordination on the bridge meant that greater priority was given to the task of inputting waypoints into the radars as instructed by the pilot without any mutual understanding as to who was doing what in respect to the more critical task of monitoring the ship’s progress. Neither the pilot nor the ship’s bridge team used either radar for parallel indexing and other monitoring techniques, such as clearing ranges or visual transits. As a result, when the GPS unit malfunctioned, no-one had sufficient situation awareness to identify the error.
The master had doubts regarding the position of the ship and the accuracy of its navigational equipment, but these were not communicated to the pilot. Had the master raised these concerns, a subsequent appraisal of the situation might have identified the erroneous GPS position. If the expectations for challenge and response had been established during the MPX, the master might have felt more inclined to voice concerns to the pilot. Similarly, had the pilot alerted the bridge team after identifying at 0311 that the ship was displaced to the east of the planned track, a more urgent appraisal of the situation might have been undertaken.
Configuration of the portable pilot unit
The use of portable pilot units (PPU) is widely encouraged as an additional source of information to improve safety, efficiency and situation awareness during pilotage. However, the improper set‑up of the pilot’s PPU at the time of the occurrence likely compounded the pilot’s degraded mental model of the pilotage.
Contrary to industry guidance and Auriga’s pilotage operations safety management system, the pilot did not ensure the GPS output from their PPU was independent of the ship’s navigation equipment once it was connected to the AIS pilot plug. As a result. both the ECDIS units and the PPU displayed the same invalid positional data from the ship’s malfunctioning GPS unit. Believing that the PPU was independently reporting its position, the pilot may have been misled into believing the PPU and ECDIS units were accurate.
If the PPU had been configured by the pilot as intended, the use of the independent PPU GPS would have identified a difference in the location between the PPU and the incorrect position reported via the AIS. Additionally, had alarm systems on the PPU been enabled, these may have alerted the pilot to the invalid GPS position. However, in the absence of sound pilotage practise and effective BRM, the incorrect configuration of the PPU was not identified.
Check pilot system
The construct of the AMSA check pilot system and its accompanying guidelines indicate that it was a competency-based assessment framework, intended to provide assurance of coastal pilot competency. However, analysis of 490 assessment outcomes for check voyages conducted between 2017 and 2023 revealed that the system did not provide such assurance. Of note, significantly inconsistent application of assessment standards between individual check pilots was evident. The extent of this inconsistency indicates that varying assessment outcomes were dependent on the individual check pilot conducting the assessment rather than being reflective of pilot competency.
Throughout the period in which the 490 check voyages were conducted, the system produced a near 100% pass rate, with no ‘unsatisfactory’ results recorded. A negligible fraction of the total performance elements assessed were recorded as ‘satisfactory with deficiencies’ and there were no instances where formal remedial actions under the system were triggered and initiated. A previous ATSB systemic investigation (MI-2010-011) had also identified the check pilot system’s unrealistic 100% pass rate. That investigation’s finding was based on all 550 check voyage assessments conducted since the system’s introduction.
Overall, the results of analysis of the large amount of check pilot data showed that the check pilot system had not resulted in any significant benefit to coastal pilot competency by way of formalised corrective action and continual improvement. As AMSA has never conducted any trend analysis of the check voyage assessments, stating that this was primarily due to the low number of deficiencies identified overall, it did not identify the inconsistent application of assessment standards by individual check pilots. In the absence of sufficient monitoring of check pilot practices, factors which may have limited the system’s effectiveness such as assessor bias, unclear assessment standards and insufficient training and guidance for assessors, had not been identified and corrected.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the near grounding of Rosco Poplar off Bond Reef, Hydrographers Passage, Queensland on 4 May 2022.
Contributing factors
Rosco Poplar’s GPS unit probably malfunctioned due to a fault with its antenna, resulting in erroneous ship’s position data. This incorrect data was then provided to all navigational aids, including both electronic chart display and information system (ECDIS) units, automatic identification system (AIS) and the pilot’s portable pilotage unit (PPU).
The PPU had not been configured as required to source position data independent of the ship’s GPS unit.
The pilot and the ship’s bridge team were relying solely on the PPU and ECDIS units to monitor the ship's progress. Consequently, they did not identify that the ship had deviated from the planned track until the GPS unit reset and began indicating the correct position, which was about 200 m from Bond Reef.
The pilotage was not conducted appropriately, including effective track monitoring and proper bridge resource management, due to a combination of:
an inadequate master and pilot information exchange
roles and responsibilities not being properly defined
an absence of monitoring using visual bearings and radar, including parallel indexing
non-essential tasks for the pilotage phase that distracted the bridge team
the absence of a shared ‘mental model’ of the pilotage.
Other factors that increased risk
The configuration of Rosco Poplar's electronic navigation equipment was vulnerable to single GPS unit errors because, at any given time, only one of the ship’s 3 GPS units could be selected to provide positional data to all the ship's navigational equipment.
Following receipt of an unusual grounding alert display associated with the Rosco Poplar’s GPS malfunction, the vessel traffic service operator assessed it as erroneous. Consequently, the pilot/ship’s crew were not provided with timely advice of the indicated proximity to Bond Reef.
The check pilot system was ineffective in providing the Australian Maritime Safety Authority (AMSA) assurance of the competency of coastal pilots, mainly due to the inconsistent and unreliable application of assessment standards between different check pilots. Further, AMSA had not implemented a system to identify the inconsistent application of standards or the trends in assessment outcomes readily apparent in the data that it had held for many years. (Safety issue)
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the marine industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The check pilot system was ineffective in providing the Australian Maritime Safety Authority (AMSA) assurance of the competency of coastal pilots, mainly due to the inconsistent and unreliable application of assessment standards between different check pilots. Further, AMSA had not implemented a system to identify the inconsistent application of standards or the trends in assessment outcomes readily apparent in the data that it had held for many years.
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Australian Maritime Safety Authority takes safety action to identify and address factors limiting the effectiveness of its check pilot framework as a system for coastal pilot competency assurance.
Glossary
AIS
Automatic Identification System
AMSA
Australian Maritime Safety Authority
CASA
Civil Aviation Safety Authority
CBTA
Competency Base Training and Assessment
COLREG
Convention on the International Regulations for Preventing Collisions at Sea
ECDIS
Electronic Chart Display and Information System
ECS
Electronic Chart System
ENC
Electronic Navigational Chart
GBRMPA
Great Barrier Reef Marine Park Authority
GMDSS
Global Maritime Distress Safety System
GNSS
Global Navigation Satellite System
GPS
Global Positioning System
IMO
International Maritime Organisation
MPX
Master and pilot information exchange
MSQ
Maritime Safety Queensland
NSCV
National Standard for Commercial Vessels
OOW
Officer of the Watch
PPU
Portable Pilot Unit
PSSA
Particularly Sensitive Sea Area
QCPP
Queensland Coastal Passage Plan
REEFREP
Great Barrier Reef and Torres Strait Ship Reporting System
REEFVTS
Great Barrier Reef and Torres Strait Vessel Traffic Service
SMS
Safety management system
SOLAS
The International Convention for the Safety of Life at Sea, 1974, as amended.
STCW
Standard for Training Certification and Watchkeeping
VDR
Voyage Data Recorder
VTSO
Vessel Traffic Service Operator
Sources and submissions
Sources of information
The sources of information during the investigation included:
the pilot of Rosco Poplar
the master, second mate and able seaman on board Rosco Poplar
records, documents, manuals, and logbooks from Rosco Poplar
records, documents and manuals from Auriga
Australian Maritime Safety Authority
Maritime Safety Queensland
Great Barrier Reef and Torres Strait Vessel Traffic Service
Bernhard Schulte Shipmanagement China
recorded information from Rosco Poplar’s voyage data recorder
Japan Radio Company
References
International Hydrographic Organization, 2018, Publication S-66, Facts about electronic charts and carriage requirements, Edition 1.1.0, IHO, Monaco. Available at https://iho.int/.
International Maritime Organization, 2006, Revised performance standards for electronic chart display and information systems (ECDIS), Resolution MSC.232 (82), IMO, London.
Australian Maritime Safety Authority, 2014, Marine Order 54 – Coastal pilotage, AMSA, Canberra.
Focus on Bridge Resource Management, Washington State Department of Ecology, 2007.
International Association of Marine Aids to Navigation and Lighthouse Authorities, January 2022, Guideline G1089; Provision of a VTS, Ed 2.0.
International Maritime Organisation, Recommendations on training and certification and on operational procedures for maritime pilots other than deep-sea pilots, Resolution A.960 (23).
International Maritime Organisation, The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers 1978, as amended, IMO, London.
Australian Maritime Safety Authority, 2014, Marine Order 54 – Coastal pilotage, AMSA, Canberra.
Alexander L, Casey M J 2008, Use of Portable Piloting Units by Maritime Pilots, Canadian Hydrographic Conference.
Civil Aviation Safety Authority, Advisory Circular AC 61-09 v1.0, Competency-based Training and Assessment for Flight Crew, April 2002.
Professional Standards Councils, Competency-based Frameworks and Assessment.
International Marine Pilots Association, Guidelines on the Design and Use of Portable Pilot Units, 2016.
Australasian Marine Pilots Institute, PPU Code of Good Practice – For the Implementation and Use of Portable Piloting Units, 2nd Ed. 2020.
Australian Maritime Safety Authority, 2019, Marine Order 63 (Vessel reporting systems) 2019, AMSA, Canberra.
Australian Maritime Safety Authority, Pilot Advisory Notes 10/03 and 01/04, Check Pilots and Check Pilot Voyages.
Civil Aviation Safety Authority, Advisory Circular AC 61-09 v1.0, Competency-based Training and Assessment for Flight Crew, April 2002.
Flin R, Martin L 2001, Behavioural Markers for Crew Resource Management: A Review of Current Practice, The International Journal of Aviation Psychology, 11(1), 95–118.
Franks P, Hay S, Mavin T 2014, Can Competency-based Training Fly?: An Overview of Key Issues for Ab Initio Pilot Training, International Journal of Training Research 12(2): 132–147.
Weber D E, Mavin T J, Roth W M, Henriqson E, Dekker S W A (2014), Exploring the Use of Categories in the Assessment of Airline Pilots’ Performance as a Potential Source of Examiners’ Disagreement, Journal of Cognitive Engineering and Decision Making, 8(3), 248–264.
Weber D E, Roth W M, Mavin T, Dekker S W A 2013, Should we Pursue Inter-rater Reliability or Diversity? An Empirical Study of Pilot Performance Assessment, Aviation in Focus – Journal of Aeronautical Sciences, 4. 34-58.
Gontar J, Hoermann H J 2015, Inter-rater Reliability at the Top End: Measures of Pilots’ Non‑Technical Performance, The International Journal of Aviation Psychology, 25(3/4), 171-190.
Civil Aviation Safety Authority, CAAP SMS-3(1): Non-Technical Skills Training and Assessment for Regular Public Transport Operations.
Australasian Marine Pilots Institute, Code of Good Practice – Marine Pilot Competence and Performance, 2nd Ed. 2020.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Australian Maritime Safety Authority
Maritime Safety Queensland
The pilot of Rosco Poplar
Auriga
the master, second mate and able seaman of Rosco Poplar
Bernhard Schulte Shipmanagement China
Submissions were received from:
Australian Maritime Safety Authority
Maritime Safety Queensland
Auriga.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Appendices
Appendix A
Check Voyage / Assessment Transit Details (AMSA Form 15)
An extract (first 3 pages) from the Australian Maritime Safety Authority Form 15 pilot check voyage checklist used by check pilots to assess and record coastal pilot competency.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1]The pilot’s pilotage plan stated the transit would be at full sea speed, which is the speed when on passage at sea.
[3]Predicted low water was at 0612 with a height of tide of 1.23 m above chart datum.
[4]Nautical chart Aus 802, Australian Hydrographic Office.
[5]All ship’s headings are reported in degrees true unless specified otherwise.
[6]Dead reckoning (DR) is a method for determining the estimated position of a ship by advancing from a known fix of position along the ship’s ordered course and speed.
[7]Decision support tools (DST) are used by VTS providers to help enhance situation awareness and the decision‑making process of VTS personnel by providing analysis and insight to developing or emergency situations, in real time, near real time and for long-term planning (see the section titled Vessel traffic service).
[8]Differential GPS utilises a network of fixed ground stations to enhance the accuracy of location data collected by a GPS.
[9]GPS units calculate dates utilising a week counter. In older systems, the counter resets after every 1,024 weeks (referred to as ‘GPS rollover’, and systems need to be manually adjusted, usually via a software upgrade, when the rollover occurs so that they remain accurate.
[10]International Hydrographic Organization, 2018, Publication S-66, Facts about electronic charts and carriage requirements, Edition 1.1.0, IHO, Monaco.
[11]The International Convention for the Safety of Life at Sea (SOLAS) 1974, as amended.
[12]International Maritime Organization, 2006, Revised performance standards for electronic chart display and information systems (ECDIS), Resolution MSC.232 (82), IMO, London.
[13]Global Navigation Satellite System (GNSS) is a broad term encompassing the various types of satellite-based positioning, navigation and timing (PNT) systems used globally, of which GPS is one such type.
[14]For Hydrographers Passage, an unrestricted pilot licence issued under coastal pilotage regulations permitted the licensee to pilot all types of ships through the pilotage area with no restrictions in respect to draught or type of ship. Pilots may obtain an unrestricted licence once they have accrued the necessary experience and training while holding a trainee licence and a restricted licence, which precluded them from piloting certain types of ships.
[15]The Australian Maritime Safety Authority Marine Order 54 (Coastal pilotage) stated ‘a pilot check voyage is a voyage on which a pilot’s competency is being assessed by a check pilot’.
[16]AMSA, 2014, Marine Order 54 – Coastal pilotage, Canberra.
[17]An area of the marine environment that needs special protection through action by the International Maritime Organization (IMO) because of its significance for recognised ecological, socio-economic or scientific attributes where such attributes may be vulnerable to damage by international shipping activities.
[18]Focus on Bridge Resource Management. Washington State Department of Ecology, 2007.
[19]IMO, Recommendations on training and certification and on operational procedures for maritime pilots other than deep‑sea pilots, Resolution A.960 (23).
[20]Hetherington C 2006, Safety in Shipping: The Human Element, Journal of Safety Research vol. 37, 401–411.
[22]IMO, The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers 1978, as amended, IMO, London.
[23]See for example, International Marine Pilots Association, Guidelines on the Design and Use of Portable Pilot Units, 2016, and, Australasian Marine Pilots Institute, PPU Code of Good Practice – For the Implementation and Use of Portable Piloting Units, 2nd Ed. 2020.
[24]SEAiq Pilot is a software application designed specifically for use by pilots in navigating ports and pilotage areas. It provides navigation tools, position information of own and other vessels, with information displayed over nautical charts.
[25]Heading from ship source will be more accurate; ROT is not always available in AIS transmissions.
[26]IMO Resolution A.1158.32 (20) defines a vessel traffic service (VTS) as a service implemented by a Government with the capability to interact with vessel traffic and respond to developing situations within a VTS area to improve safety and efficiency of navigation, contribute to the safety of life at sea and support the protection of the environment.
[27]Inmarsat-C is a two-way store and forward communication system transmitting messages from ship-to-shore, shore‑to‑ship and ship-to-ship, operated by telecommunications company Inmarsat.
[28]International Association of Marine Aids to Navigation and Lighthouse Authorities, January 2022, Guideline G1089; Provision of a VTS, Ed 2.0.
[29]AMSA, Pilot Advisory Notes 10/03 and 01/04, Check Pilots and Check Pilot Voyages.
[30]Franks P, Hay S, Mavin T 2014, Can Competency-based Training Fly?: An Overview of Key Issues for Ab Initio Pilot Training, International Journal of Training Research 12(2): 132–147.
[31]Civil Aviation Safety Authority, Advisory Circular AC 61-09 v1.0, Competency-based Training and Assessment for Flight Crew, April 2002.
[32]Professional Standards Councils, Competency-based Frameworks and Assessment.
[33]AQF levels and the AQF levels criteria are an indication of the relative complexity and/or depth of an achievement and the autonomy required to demonstrate it.
[34]AMSA 15 (07/19), Guidance Notes for Check Pilot Assessment Voyages.
[35]Non-technical skills are interpersonal skills which include communication skills, leadership skills, teamwork skills, decision-making skills and situation awareness skills.
[36]CASA, Advisory Circular AC 61-09 v1.0, Competency-based Training and Assessment for Flight Crew, April 2002.
[37]Flin R, Martin L 2001, Behavioural Markers for Crew Resource Management: A Review of Current Practice, The International Journal of Aviation Psychology, 11(1), 95–118.
[38]Inter-rater reliability (IRR) is a sensitivity measure of how closely a group of raters agree with each other. This does not refer to a standard grading but measures the results of the assessors’ gradings against one another.
[39]Weber D E, Mavin T J, Roth W M, Henriqson E, Dekker S W A 2014, Exploring the Use of Categories in the Assessment of Airline Pilots’ Performance as a Potential Source of Examiners’ Disagreement, Journal of Cognitive Engineering and Decision Making, 8(3), 248–264.
[40]Weber D E, Roth W M, Mavin T, Dekker S W A 2013, Should we Pursue Inter-rater Reliability or Diversity? An Empirical Study of Pilot Performance Assessment, Aviation in Focus – Journal of Aeronautical Sciences, 4. 34-58.
[41]Gontar J, Hoermann H J 2015, Inter-rater Reliability at the Top End: Measures of Pilots’ Non-Technical Performance, The International Journal of Aviation Psychology, 25(3/4), 171-190.
[42]Weber D E, Mavin T J, Roth W M, Henriqson E, Dekker S W A (2014), Exploring the Use of Categories in the Assessment of Airline Pilots’ Performance as a Potential Source of Examiners’ Disagreement, Journal of Cognitive Engineering and Decision Making, 8(3), 248–264.
[43]Civil Aviation Safety Authority, CAAP SMS-3(1): Non-Technical Skills Training and Assessment for Regular Public Transport Operations.
[44]Australasian Marine Pilots Institute, Code of Good Practice – Marine Pilot Competence and Performance, 2nd Ed. 2020.
[46] The Kruskal-Wallistest is a rank-based nonparametric test that can be used to determine if there are statistically significant differences between 2 or more groups.
NSW TrainLink passenger service ST21 was running from Sydney, New South Wales, to Melbourne, Victoria, on the ARTC standard gauge interstate network. The service departed Sydney on the evening of 23 May 2022 and was approaching Melbourne the following morning, 24 May.
A temporary speed restriction (TSR) had been applied on the standard gauge track at the Moonee Ponds Creek Bridge, about 24 km from Melbourne. The TSR was an interim safety measure in response to a rough ride report made by the driver of an earlier train. Trains were being warned of the speed restriction by radio call from train control through a procedure known as a condition affecting network (CAN) warning. The CAN issued for the TSR advised of a 40 km/h speed restriction between 24 km and 24.4 km.
On the standard gauge route to Melbourne, track distances between 27 km and 16 km were repeated to accommodate a divergence of the standard gauge and broad gauge routes on the approach to Melbourne. For Melbourne-bound trains on the standard gauge route (such as ST21), track kilometres decreased down to 16 km before stepping back up to 27 km and then again reducing towards Melbourne. Moonee Ponds Creek Bridge was located about 3 km after this step change in track kilometrage.
ST21 received the CAN warning for the TSR. However, the train was slowed at the wrong location and crossed the Moonee Ponds Creek Bridge (the location of the TSR) at about 0703 travelling at between 100 km/h and 110 km/h. Soon after passing over the bridge, the driver recognised they may have slowed at the incorrect location and contacted ARTC train control.
What the ATSB found
The CAN warning issued to the driver of ST21 was ambiguous as it identified only the kilometrage without any further location description. The kilometrage of between 24.0 km and 24.4 km specified in the warning occurred twice on the path of train ST21, about 11 km apart. ST21 was slowed at the first 24.4 km location encountered and subsequently proceeded at high speed through the TSR location at the Moonee Ponds Creek Bridge.
The method of warning trains of a TSR was an administrative control which relied on the effective communication of information between train controllers and drivers, and its correct application. It was found that the administrative processes used by ARTC to warn train crew about temporary speed restrictions were vulnerable to errors in creation and communication. There were opportunities to improve existing processes and to adopt technology-supported solutions to reduce risk associated with the implementation of temporary speed restrictions.
What has been done as a result
ARTC has implemented an electronic system for generating CAN warnings that prompts train controllers to provide 2 types of location identification information. This is now the primary method ARTC uses for generating CAN warnings and should reduce the risks associated with missed information during creation of the warnings. ARTC also plans to upgrade the electronic system to enable digital transmission of CAN warnings to train crew. When implemented, this has the potential to reduce the risks associated with communication of warnings.
In addition, ARTC has undertaken several associated actions including the briefing of network controllers to raise awareness of kilometrage changes and the importance of including location information in CAN warnings. Briefings have been supported by the dissemination of updated information to controllers and other rail safety workers.
Safety message
In the Australian rail context, administrative processes have often been established for long periods of time while technology has improved. Opportunities exist for safety improvement in rail safeworking through the modernisation of administrative controls and adoption of technology-supported solutions.
The occurrence
Prior to the incident
On 23 May 2022, at about 2120 local time, the driver of a V/Line train experienced a rough ride at the Moonee Ponds Creek Bridge in the local government area of Merri-bek[1] in Victoria (Figure 1). This occurred while the train was travelling towards Melbourne on the Australian Rail Track Corporation (ARTC) interstate network.
Figure 1: A NSW TrainLink XPT on the Moonee Ponds Creek Bridge
Source: Schony747
The driver reported the rough ride to the ARTC network control officer (NCO) responsible for the section of standard gauge track which included the Moonee Ponds Creek Bridge. This NCO controlled train movements between Somerton which was north of the bridge, and Melbourne to the south.
In response to the report and following discussion with maintenance personnel, the NCO placed a temporary speed restriction (TSR) of 40 km/h on a section of track between 24.0 track km[2] and 24.4 track km covering the Moonee Ponds Creek Bridge. For Melbourne-bound trains, the TSR commenced at 24.4 km and continued until the train passed 24.0 km.
The TSR location was on the standard gauge track about 3 km south of a step change in track kilometres at the Jacana flyover (see Location information). The step change was due to the longer route of the standard gauge line to Melbourne after it diverged from the broad gauge line at the flyover. This step change resulted in there being two 24.4 km locations about 11 km apart, one either side of the change at the flyover (Figure 2).
Figure 2: A schematic of the railway routes around the Jacana flyover
The schematic shows the kilometre change at Jacana flyover, the northern and southern 24.4 km locations and the northern limit of the NCO’s area of control. It is not drawn to scale. Source: Office of the Chief Investigator (OCI)
Journey of passenger train ST21
ST21 was a scheduled XPT passenger train service, operated by NSW Trains trading as NSW TrainLink,[3] from Sydney, New South Wales, to Melbourne in Victoria. It travelled from Sydney to Junee in southern New South Wales without incident, arriving at about 0228 on 24 May. At Junee, there was a driver change and the incoming driver was tasked to complete the journey to Melbourne. ST21 departed Junee soon after and crossed into Victoria about 2 hours later, continuing its journey to Melbourne.
At about 0605, while passing Seymour, the driver of ST21 was contacted on the railway network radio by the NCO responsible for the Somerton to Melbourne section. This was not the same NCO who had initially received the rough ride report as a shift change had occurred. This second NCO advised that they needed to provide the driver with a condition affecting network (CAN) warning for a location between Somerton and Tullamarine.[4] The driver replied that their train was currently a long way away from there and they would contact the NCO when the train was closer (Figure 3).
Figure 3: Map of train ST21’s route
The map shows the Donnybrook to Melbourne section with the full journey from Sydney inset. It is not drawn to scale. Source: Digital Atlas of Australia,annotated by OCI
Subsequently at 0641, the driver stopped ST21 at Donnybrook (at about 38 km) and called the NCO to receive the CAN warning. The NCO issued the CAN warning to the driver, informing them that there was a 40 km/h TSR in place between 24.0 km and 24.4 km. This exchange involved the driver of ST21 transcribing the verbal advice received from the NCO onto their CAN form and reading it back. Descriptive location information, such as the applicable line section, or that the TSR was on a bridge was not discussed during this exchange.
After the radio exchange, ST21 resumed its travel towards Melbourne. The driver recalled that they placed their copy of the CAN warning form onto the driving console and began monitoring the kilometre markings that the train passed, comparing them to the kilometrage for the TSR location on the form. They recalled that they saw the 26 km post and prepared to slow their train.
At about 0653 the driver reduced the train’s speed to just under 40 km/h as ST21 approached the 24.4 km location north of the Jacana flyover. This reduced speed was maintained until, after passing 24.0 km, the speed of the train was increased to resume normal speed running.
ST21 continued its journey, passed Somerton and made a scheduled stop at Broadmeadows. It departed Broadmeadows with about 50 passengers on board and proceeded over the Jacana flyover, where the standard gauge track kilometres changed, resetting to 27 km.
ST21 overspeed
At about 0703, ST21 approached 24.4 km near the Moonee Ponds Creek Bridge (south of the Jacana flyover). The driver recalled seeing 2 track workers as the train approached the bridge. In response the driver sounded the horn to warn them of the train’s approach. The workers acknowledged the horn with an ‘all clear’ hand signal and the train proceeded across the bridge. The train’s speed was not reduced, and it went through the TSR location at between 100 km/h and 110 km/h. The driver recalled the transit felt rougher than usual.
Soon after, the driver sighted the 21 km post.[5] They recalled that this prompted them to consider their location, the rough ride, and the workers at the bridge. They realised that the CAN warning may have been for the section of track across the Moonee Ponds Creek Bridge, rather than the location where they had reduced speed earlier.
At about 0705 the driver called the NCO responsible for the section to clarify where the CAN warning applied and reported that they had reduced speed at the other 24.4 km location. This was a third NCO as another shift change had occurred.
The train continued and arrived at its destination, Southern Cross Station in Melbourne, at 0831. The CAN warning was cancelled at about 0836 by the duty NCO. This was done in response to a track work group reporting that they had found and repaired a track geometry issue associated with the rough ride report. No further trains passed over the location after ST21 while the CAN warning was in effect.
Context
Location information
Overview
The standard gauge route between Sydney and Melbourne is part of the interstate rail network managed by the Australian Rail Track Corporation (ARTC). For much of its length in Victoria, it runs parallel to (and east of) a broad gauge route that is used by both the Melbourne metropolitan network (to Craigieburn) and the Victorian regional network (to Seymour). However, when approaching Melbourne from the north, the standard gauge track took a more circuitous route to the south‑west that was 11 km longer than the broad gauge route (Figure 3).
North of the Jacana flyover, the same track kilometrage was used for the parallel broad gauge and standard gauge tracks. The kilometres on these parallel routes were based on the distance to Melbourne travelling on the broad gauge route. An adjustment was required on the standard gauge track to accommodate its longer route to Melbourne. This adjustment was made at the Jacana flyover at which point kilometrage changed from 16 km back up to 27 km in the direction of travel of ST21 towards Melbourne (Figure 4).
Figure 4: Kilometre change notification on the standard gauge track at Jacana flyover
The figure shows the standard gauge track a short distance after it had passed over the broad gauge tracks at the Jacana flyover. The signage indicates a change (from 16 km) to 27 km and then kilometrage decreasing towards Melbourne. Source: OCI
Location of the TSR
The Moonee Ponds Creek Bridge was a heritage listed steel trestle bridge which was first constructed in the 1920s. It carried a standard gauge track and a dual gauge track which formed part of the Tullamarine crossing loop. The dual gauge track was not used by either the V/Line train that reported the rough ride or ST21.
The 40 km/h temporary speed restriction between 24.0 and 24.4 km encompassed the full length of the bridge (Figure 5). The normal speed for the standard gauge track in this location was 115 km/h. In the direction of travel of ST21, immediately prior to the bridge was a curve with a 95 km/h speed limit.
Figure 5: The location of the TSR at the Moonee Ponds Creek Bridge
Source: OCI
Network control
Sections of control
Train movements on the standard gauge route from Sydney to Melbourne were controlled by ARTC. The route was comprised of several sections with a network control officer (NCO) designated to each section. Within Victoria, there were 2 sections of control:
The section between Albury (New South Wales) and Somerton (Victoria). This section of control was referred to as ‘Main South C’ and was controlled by NCO located in Junee in New South Wales.
The section between Somerton and Southern Cross Station (Melbourne). This was grouped with some other related sections that were together referred to as ‘Melbourne’. The group was controlled by NCO based at Mile End in South Australia.
The changeover between these 2 sections of control occurred at Somerton signal SOM 4, about 6 km north of the Jacana flyover.
Safeworking
Rail safeworking describes the system of operating rules and procedures used to provide safe operation of rail traffic and protection of people and property. ARTC operating rules for Victoria were defined in the ARTC Code of Practice for the Victorian main line operations (CoP).[6]
Section 1 of the CoP included rules related to reporting and responding to a condition affecting network (CAN). This included the need for:
train drivers and track workers to report ‘conditions that can or do affect the safety of rail operations’ to the responsible NCO
NCO’s to ‘give written warning to rail traffic crews using a CAN form’ in circumstances where ‘temporary speed restrictions have been reported and no signs erected’.
The CoP contained rules and procedures relating to the use of the CAN form and an example of the blank form.
ARTC also published a procedure relating to temporary speed restriction (TSR).[7] The procedure described that when train drivers reported a fault, the NCO was to notify a maintainer. The maintainer was to determine the appropriate response including the speed of any required TSR and the time required for implementing speed warning signs and inspection.
Rough ride report
Train drivers could report a rough ride to the relevant NCO when they considered that the dynamic response of their train to the geometry of the track had been excessive. It was sometimes also described as a ‘rough track’. On the evening prior to the occurrence the driver of a V/Line train had experienced a rough ride. They reported to the NCO that this occurred ‘at the approach to the bridge at 24.2’. The NCO asked for and received clarification from the driver that the location was at the Moonee Ponds Creek Bridge.
In response, the NCO contacted the track inspector for this track section (the maintainer) and informed them of the reported rough ride at the Moonee Ponds Creek Bridge. The track inspector recommended that a 40 km/h TSR be applied between 24.0 km and 24.4 km until the track could be inspected. The NCO recorded the location of the TSR on the train control graph.[8]
Condition affecting network (CAN) warning
The NCO prepared a CAN warning, to be issued to the drivers of trains that would pass through the location while the TSR was in place. The ARTC CoP required the CAN warning, as a TSR had been placed with no other method (such as signage) implemented to warn train drivers of the speed restriction.
The blank CAN warning form[9] included spaces in the relevant section for the NCO to enter the speed and location limits of the TSR. Within the spaces for the location limits was light grey text that read ‘location and km’ (Figure 6). There was no further instruction that described how to fill out this section of the form or supported the need to provide 2 methods of identifying locations (location and kilometres).
Figure 6: Extract from a blank CAN warning form with boxes for specifying TSR limits
This CAN form extract shows the space provided for specifying TSR limits and some instruction on the required content in light grey text. Source: ARTC, annotated by OCI
The detail recorded by the NCO on the form was ‘40 km/h between km 24.000 and km 24.400’ (Figure 7). No other location information was included. The NCO had noted ‘no signs erected’ in section 5, to identify to drivers receiving the warning that speed warning boards were not present.
Figure 7: Sections 4 and 5 of the CAN warning form, as prepared by the NCO
Source: ARTC
Issue of CAN warning
The NCO who prepared the CAN warning form did not issue it to any train drivers as there were no rail movements through the location before the end of their shift. The NCO who replaced them on the following shift issued the CAN warning to 6 train drivers, the last being the driver of train ST21. A third NCO, on the subsequent shift, issued the CAN warning to a single train driver before cancelling the warning following advice from track workers that a track issue related to the rough ride report had been repaired.
In all cases, the CAN warning was issued to train drivers by voice communication over network radio. Recordings of the network radio communication indicated that the NCO who issued the CAN multiple times followed a pattern. On 4 of 6 occasions,[10] including for ST21, they first contacted the train to inform them that a CAN warning was required for ‘Somerton to Tullamarine’. The CAN warning was then issued in a separate radio call. For ST21, the time between radio calls was long, about 36 minutes. However, for the 3 other trains, the time between the first contact and issuing the CAN warning was short, ranging from less than 1 minute to about 6 minutes.
Each time the NCO issued the CAN warning they read the contents of the form to the train driver. The driver transcribed it onto their own copy of the form and read it back to the NCO. The NCO then either confirmed that the readback was correct or appropriate corrections were made. Location information was not discussed during the issue of any of the CAN warnings other than the as written limits ‘between km 24.000 and km 24.400’.
Recorded information
Event recorder
The XPT train used Hasler RT data recorders fitted to the leading and trailing power cars. The tape from the leading power car (XP2003) showed the train speed from when the driver stopped the train to receive the CAN warning, at Donnybrook, until after it passed the location where the TSR was applied (Figure 8).
Figure 8: The tape recording from XP2003 showing train speed
This figure shows the approximate train speed after departing Donnybrook. The location where the train slowed to below 40 km/h (the northern location) is shown in blue, and the location of the TSR (the southern location) is shown in orange. Source: NSW Trains, annotated by OCI
ST21 slowed at the first 24.4 km location encountered (the northern location). After travelling over the Jacana flyover where the kilometrage reset to 27 km, it then passed the southern 24.4 km location, where the TSR started, travelling at between 100 km/h and 110 km/h. This was below the normal 115 km/h speed limit and consistent with ST21 accelerating out of a preceding curve that had a 95 km/h speed limit.
ICE radio GPS speed
All trains operating on the ARTC network were required to be fitted with an In-Cab Communication Equipment (ICE) digital train radio system. ICE was specifically designed for the rail industry and integrates both voice and electronic (data) transmission and a GPS unit. The equipment on board the trains broadcast position and speed information, which was received and recorded by ARTC. Although the GPS recording frequency and precision were low, it provided an estimate of train speed.
Five other trains (all freight) were issued the CAN warning and passed over the rough ride location while the TSR was active and before ST21. The GPS recordings from these trains showed 3 had slowed to below 40 km/h while 2 exceeded this speed by substantial margins (Table 1).
Table 1: Estimated train speed
Train number
Nearest km post
Estimated speed (km/h)
Average speed (km/h)
2CM7
25
24
74
78
76
1BM4
25
24
56
62
59
2CM3
25
24
39
32
36
2MB9
23
25
33
28
30
2SM7
25
24
35
36
35
Track geometry
The vertical track geometry at the rough ride location was measured by track workers on the day of the occurrence. They recorded that a 25 mm vertical geometry irregularity was present when measured at the mid-point of a 6 m chord. When compared to ARTC’s defect limits,[11] this irregularity was a defect requiring maintenance. ARTC reported that it was subsequently repaired by hand tamping, a process of lifting the track and packing ballast under the sleeper to support it.
Track geometry was also regularly measured by the track recording vehicle (the AK car). The most recent measurement was on 4 April 2022, about 7 weeks prior to the occurrence. ARTC’s exceedance report for this measurement did not include a geometry defect at or near the rough ride location.
Electronic transmission of TSR
ARTC’s code of practice permitted CAN warnings to be issued ‘using electronic transmission’. However, this was not an implemented method on ARTC track in Victoria at the time of the occurrence. Instead, the NCO provided the warning to the driver of ST21 by dictation and readback of a written CAN warning form using radio voice communication.
The standard radio installed on trains on the ARTC network was the ICE radio which was capable of providing both voice and electronic (data) to train drivers. The electronic transmission capability of the ICE radio system could transmit safeworking information, including notification of TSR locations. If electronic transmission was used, the information could be provided to drivers to read and respond to on an in-cab display. As the system monitored train locations by GPS, it could also provide an alert to drivers when their train was approaching a location with a TSR applied.
At the time of the incident, another Australian railway was using the ICE radio electronic transmission capability as part of its safeworking system (Hjort 2015). The system, as implemented, provided an alert to train drivers when they were approaching a TSR location.
Repeated track kilometres
The ARTC standard gauge network in Victoria contained at least 6 other locations where there was a step change in kilometrage at a fixed location. None occurred for the same reason as the change at Jacana flyover (alignment with a parallel track). However, at least 2 locations (at Pyrenees and Newport) created the realistic possibility of ambiguous location identification. This was because repeated kilometrage was separated by moderate distances.[12]
Some other railways have adopted kilometre identification processes that addressed this type of ambiguity. For example, a freight railway in the Pilbara region of West Australia used a prefix on kilometre markings that avoided duplication (Figure 9).
Figure 9: An example location marked using the ‘C’ prefix on an Australian railway
Source: Monash Institute of Railway Technology
On the Pilbara network, 2 parallel tracks deviated from each other and took different routes (with different path lengths) before realigning. There was a step change in track kilometres on the longer route when the tracks realigned that resulted in repeated kilometrage. Ambiguity was avoided as the kilometres on the longer route within the deviation were described with a ‘C’ prefix. The second instance of the same kilometres that occurred after tracks realigned were described without a prefix.
Studies and other occurrences
RAIB Safety digest: South Wales overspeeds
In 2025 the British Rail Accident Investigation Branch (RAIB) published a report into overspeed occurrences during blanket speed restrictions (RAIB Safety digest 03/2025). The report emphasised the importance of robust and effective processes for delivery of safety-critical messages about speed restrictions. Additionally, it encouraged the use of available technology (such as automatic radio broadcasts) to reinforce existing processes.
ATSB Safety study: Safe work on track
In 2017, the ATSB published the results of a safety issue investigation into reported notifiable occurrences while maintenance work was being performed on or near railway tracks (ATSB investigation RI-2014-011).
The study considered occurrences over a 5-year period between July 2009 and June 2014. It found that incorrect identification of worksite location (either position or limits) was one of the highest occurrence categories in terms of risk exposure to track workers. More than 50% of the occurrences in this category were assessed as having increased or high-risk exposure.
Although the study was related to work on track rather than train running, it quantified the risk associated with incorrectly identifying and communicating locations in systems of safeworking.
Relevant occurrences
Wallan derailment February 2020
In February 2020 near Wallan in Victoria, train ST23 proceeded through a turnout with a 15 km/h speed limit at high speed and derailed (ATSB investigation RO-2020-002). The investigation identified that the driver probably expected to remain on the straight track through Wallan (which was not speed restricted), rather than be routed through the loop at a restricted speed. Information on the routing of ST23 through Wallan Loop was provided to the driver in a paper document. The investigation highlighted an over‑reliance on administrative controls and the missed opportunities to use existing and emerging technologies to manage risk associated with human error.
TSR location errors in June 2023
On 8 June 2023, ARTC reported 2 occurrences[13] of incorrect location information being given to train crews on CAN warnings. They occurred in the context of a high workload for the NCO following track geometry measurements which required TSR’s at several locations at short notice.
In the first instance, at about 1100, a TSR was requested between 90.5 km and 90.7 km in the track section between Gheringhap and Inverleigh. However, the NCO recorded the location on the CAN warning form as between 95 km and 97 km. A train driver was issued the CAN warning and their train proceeded through the intended location of the TSR at normal speed before slowing at the location described on the CAN warning.
About one hour later, another TSR was requested, this time between 161 km and 161.7 km, although no additional location description was provided to the NCO. The NCO recorded that this was within the Barwon Park to Wingeel Loop track section on the CAN form, however the kilometrage was not within this section. A train driver was issued the CAN warning and their train proceeded through the location of the geometry defect at normal speed. As the train approached Wingeel Loop the train driver realised that the kilometre and section descriptions given did not match and reported the issue.
Safety analysis
Introduction
On 24 May 2022, the driver of train ST21 travelling from Sydney to Melbourne reported that they had unintentionally travelled over the Moonee Ponds Creek Bridge at high speed while a 40 km/h temporary speed restriction (TSR) was in place.
This analysis discusses:
the warning for the temporary speed restriction
train driver response to the warning
systems used for temporary speed restrictions
reporting of speed exceedance.
The warning for the temporary speed restriction
The location of the required 40 km/h TSR was at the Moonee Ponds Creek Bridge. The first NCO established that this was the location in communication with the reporting V/Line train driver. The NCO also conveyed this to the track inspector who specified the kilometre limits of the TSR which encompassed the bridge.
A CAN warning was then prepared by the NCO with the limits of the speed restriction described as being between 24.000 km and 24.400 km. This was inconsistent with the CAN form design which indicated that the limits of the TSR should include both km and location information. It was probably not an uncommon practice to include kilometre limits only, and none of the drivers issued with the CAN warning questioned the absence of a location description.
However, the specified limits could apply to 2 locations for rail traffic, due to the step change in kilometrage that occurred at the Jacana flyover. These locations were about 11 km apart and both were on the path of train ST21 from the location where the driver received the warning.
Both the NCO who created the CAN warning and the NCO who issued the warning to ST21 controlled the ‘Melbourne’ area of the ARTC network. This area included the 24.4 km location south of the Jacana flyover. It did not include the other 24.4 km location north of Somerton. This probably contributed to a belief by both NCO’s that the kilometre limits alone adequately described the location.
Contributing factor
The warning for the temporary speed restriction identified the location using kilometrage, without a location description. The specified kilometrage occurred twice along the path of train ST21, about 11 km apart.
Train driver response to the warning
The driver of ST21 described that, after receiving the CAN, they began monitoring the approaching kilometre posts. Around the 26 km post, they commenced slowing in anticipation of arriving at 24.4 km. The train’s event recorder indicated that it slowed to 40 km/h as it approached the first (northern) 24.4 km location.
After observing the 24 km post, ST21 resumed normal speed. The driver believed that the CAN warning had been complied with and no longer actively monitored kilometre markings for the TSR location. Subsequently, they did not slow at the location of the TSR. Instead ST21 accelerated from 100 km/h to 110 km/h through the second (southern) 24.4 km to 24.0 km location.
There was additional information available to the driver of ST21 relating to the location of the TSR. In a conversation about 36 minutes before receiving the CAN warning, the NCO advised the driver of the need to issue a warning for the section ‘Somerton to Tullamarine’. In addition, the communicating NCO was only responsible for the section south of Somerton which did not include the first (northern) 24.4 km location. It is unlikely that the driver considered the earlier conversation with the NCO or the NCO’s area of control when receiving and implementing the CAN warning.
Contributing factor
Train ST21 was slowed at the first 24.4 km location encountered and subsequently proceeded at high speed through the second 24.4 km location where the temporary speed restriction applied.
Systems used for temporary speed restrictions
A CAN warning was the method used by ARTC to immediately slow rail traffic in response to the rough ride report. It was implemented until any potential risk associated with the rough ride report could be assessed and appropriately addressed. It was an administrative control which relied on the effective communication of information between NCOs and drivers, and the correct application of the information.
The hierarchy of controls is a commonly understood concept that describes the relative effectiveness of different types of risk controls. Administrative controls include work methods or procedures that are designed to minimise exposure to a hazard as well as the information, training and instruction needed to ensure workers can work safely (Safe Work Australia 2018). Administrative controls are recognised as having comparatively low effectiveness but are used when higher levels of control such as engineering controls or elimination are not available. They can be vulnerable to unintentional error including in implementation and communication.
The vulnerability of administrative systems to unintentional error has been highlighted in research, other investigations and repeat events. A report into overspeed occurrences in the United Kingdom emphasised the importance of robust and effective processes for the delivery of safety-critical communication of speed restrictions. A further study showed that incorrect identification of location was one of the event categories that commonly exposed track workers to high safety risk. Occurrences on the ARTC network in June 2023 are further examples of the vulnerability of its administrative systems for applying TSR.
In this occurrence, the communicated location information was ambiguous. This was due to the presence of duplicated track kilometres in this area and the omission of other forms of location description. Opportunities to reduce the likelihood of ambiguity using existing controls included:
the use of prefixes on duplicate kilometre markings to create distinction, as implemented by another Australian railway
improvement in the CAN warning form design by creating separate fields for km and location, reducing the likelihood of omission
greater clarity in work instructions to reinforce the requirement to describe location.
There was also opportunity to implement technology-supported solutions with the potential to reduce risk associated with the implementation of temporary speed restrictions. This included solutions utilising ICE radio (as fitted to all trains on the ARTC network). Another local network utilised ICE radio to alert drivers as they approached a TSR location. If well designed, such systems provide opportunities to reduce or eliminate many of the possible location‑related errors that may occur.[14]
Other factor that increased risk
The administrative controls used by ARTC to warn train crew about temporary speed restrictions were vulnerable to errors in creation and communication. There were opportunities to improve the effectiveness of existing controls and adopt technology-supported solutions. (Safety issue)
Reporting of speed exceedance
The driver voluntarily reported the overspeed to train control immediately after becoming aware that it had occurred, as they were concerned that other trains may also overspeed through the TSR location. Their action, and the motivation for it, was representative of a commitment to safety.
Other finding
The driver of ST21 self-reported the overspeed to train control, promptly informing others of the risk.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the exceedance of temporary speed restriction by XPT ST21 in Merri-bek, Victoria, on 24 May 2022.
Contributing factors
The warning for the temporary speed restriction identified the location using kilometrage, without a location description. The specified kilometrage occurred twice along the path of train ST21, about 11 km apart.
Train ST21 was slowed at the first 24.4 km location encountered and subsequently proceeded at high speed through the second 24.4 km location where the temporary speed restriction applied.
Other factors that increased risk
The administrative controls used by ARTC to warn train crew about temporary speed restrictions were vulnerable to errors in creation and communication. There were opportunities to improve the effectiveness of existing controls and adopt technology-supported solutions. (Safety issue)
Other findings
The driver of ST21 self-reported the overspeed to train control, promptly informing others of the risk.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the Rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action
Safety issue description: The administrative controls used by ARTC to warn train crew about temporary speed restrictions were vulnerable to errors in creation and communication. There were opportunities to improve the effectiveness of existing controls and adopt technology‑supported solutions.
Glossary
ARTC
Australian Rail Track Corporation
CAN
Condition affecting network
CoP
Code of Practice
ICE
In-Cab communications equipment
NCO
Network Control Officer
TSR
Temporary speed restriction
Sources and submissions
Sources of information
The sources of information during the investigation included the:
ARTC
Driver of ST21
Network Control Officer
References
Hjort, G., (2015). Implementation of electronic train order working on the NSW country regional network. AusRAIL 2015.
Safe Work Australia, (2018). Code of Practice – How to manage work health and safety risks.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to directly involved parties. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Rail safety investigations in Victoria
Rail safety investigations in Victoria are conducted by the Office of the Chief Investigator (OCI) in accordance with a collaboration agreement with the ATSB.
OCI is the operational office of the Chief Investigator, Transport Safety, a statutory position established in the Transport Integration Act 2010 (Vic) to provide independent, no-blame investigation of transport safety matters in Victoria.
Under the collaboration agreement with the ATSB, OCI staff exercise powers and perform functions under the Transport Safety Investigation Act 2003 (Cth), and reports are approved for release under the TSI Act by the ATSB Commission.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
Investigations under the TSI Act do not apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings.
Under the TSI Act investigations endeavour to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner.
TSI Act investigations are not for the purpose of taking administrative, regulatory or criminal action.
About ATSB reports
ATSB investigation reports are organised with regard to international standards or instruments, as applicable, and with ATSB procedures and guidelines.
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Commonwealth Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this report is licensed under a Creative Commons Attribution 4.0 International licence.
The CC BY 4.0 licence enables you to distribute, remix, adapt, and build upon our material in any medium or format, so long as attribution is given to the Australian Transport Safety Bureau.
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1]At the time of the occurrence, the Local Government Area of Moreland had commenced a process to select a new name. It was subsequently renamed Merri-bek in September 2022.
[2]Track kilometre (track km): refers to the distance along a track from a known location. On the Victorian section of the interstate rail network the 0 km reference is Southern Cross Station in Melbourne. References to km in this report are track km.
[3]NSW Trains was an agency of the NSW State Government and within a division of Transport for NSW (TfNSW). It operated regional passenger services throughout New South Wales and interstate to Brisbane, Canberra and Melbourne.
[4]The southern 24.4 km location (with TSR) at Moonee Ponds Creek Bridge was within the Tullamarine passing loop.
[5]Km post: physical posts are placed to one side of the track every kilometre along the ARTC network displaying the track kilometres. In this instance, the driver specifically recalled seeing the post, not the general location.
[6]TA20 – ARTC Code of Practice for the Victorian main line operations, version 3.0
[7]ARTC engineering procedure PP-163: Speed restriction management, version 1.6
[8]A diagram showing operational information on train movements within a control area.
[9]ANRF 004 – Condition affecting the network (CAN), version 2.1
[10]It is likely that this pattern also occurred on the other 2 occasions. However, recordings of the initial conversations on those occasions were not identified.
[11]ARTC, Engineering (Track & Civil), Code of Practice, Section 5, Track Geometry, Version 3.
[12]In the 4 other locations the change was unlikely to create a realistic possibility of ambiguity. One location was a positive change (where the kilometre values in between were not used) that did not create repeated kilometrage. The others did contain locations of common kilometrage. However, they occurred either so close together as to be of no consequence, or so far apart that the extended time and distance involved would likely provide enough defence against misidentification.
[13]Notifiable occurrence: an accident or incident associated with railway operation reported to the regulator (ONRSR), as required by the Rail Safety National Law Regulations 2012.
[14]With any safety‑critical change, appropriate consideration is required to ensure that new error modes are not introduced.
Preliminary report
Report release date: 31/08/2022
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
Introduction
On 23 May 2022, the XPT passenger train ST21 departed Central Station in Sydney, New South Wales at about 2039,[1] on a scheduled service to Southern Cross Station in Melbourne, Victoria via Goulburn, Junee and Albury (Figure 1). The train was operating on the interstate standard gauge track[2] between Sydney and Melbourne. On board were the driver, four passenger services crew and 57 passengers.
Figure 1: Standard gauge rail route from Sydney to Melbourne
Source: Google Maps with annotations by the Chief Investigator, Transport Safety
At about 2121 that same evening, the driver of a V/Line train reported rough track at about the 24.2 km[3] location at the Moonee Ponds Creek Bridge, in the Local Government Area of Moreland. The report was made to the Australian Rail Track Corporation (ARTC) Network Control at Mile End,[4] in South Australia. In response, ARTC placed a temporary speed restriction (TSR) over that portion of the track, from 24.0 to 24.4 km.
Passage of XPT passenger train ST21
ST21 travelled from Sydney to Junee without incident, arriving at Junee at about 0228 on 24 May. Following a change of driver, the train departed at 0233. ST21 then made a scheduled stop at Albury at 0407 for about six minutes, before resuming its travel to Melbourne. At about 0605, while passing Seymour in Victoria, the Mile End Network Control Officer (NCO) responsible for the section south of Somerton, that contained the Moonee Ponds Creek Bridge, called the driver by network radio. In this call, they advised the driver of train ST21 that there was a Condition Affecting Network (CAN) warning between Somerton and Tullamarine. The driver replied that they would contact the NCO when the train was closer to that location.
At 0641, ST21 stopped at signal ES376 at Donnybrook and the driver called the responsible Mile End NCO for details of the CAN warning. The driver was informed that there was a TSR in place between the 24.000 km and 24.400 km locations and that there were no signs erected. This exchange involved the driver of ST21 transcribing the verbal advice from the NCO onto their CAN form and reading it back. At 0644 the NCO confirmed that the driver’s read-back was correct and soon after ST21 resumed its travel towards Melbourne. During this radio exchange between the driver and NCO and the issuing of the CAN warning, the line section affected was not discussed.
After departing Donnybrook, ST21 arrived at the 24.4 km location (north of Somerton) at about 0653. The driver reduced the train’s speed to just under 40 km/h and after passing the 24.0 km mark resumed normal speed. In this section, the standard gauge track on which ST21 was travelling was a single bi-directional track that runs parallel to and on the east side of the two Melbourne metropolitan broad gauge tracks (Figure 2).
Figure 2: Looking towards 24.4 to 24.0 km location where ST21 reduced speed.
Source: Chief Investigator, Transport Safety
The train continued its journey and entered the Mile End Network Control territory at 0656 when it passed signal SOM4[5] located at about the 21.8 km mark. At about 0658, ST21 made a scheduled two-minute stop at Broadmeadows station. The train then departed Broadmeadows station with about 50 passengers and travelled towards Jacana Junction.
The train travelled via the Jacana flyover that passed over the broad gauge tracks. On the flyover, kilometrage marking on the standard gauge line changed from 16 km to 27 km, and from this point decreased heading towards Melbourne (Figure 3).[6]
Figure 3: Kilometre change signboard after track passed over the broad gauge lines
The figure shows the standard-gauge track a short distance after it had passed over the broad gauge tracks (at the Jacana Flyover) Source: Chief Investigator, Transport Safety
After clearing the flyover, the train’s speed was increased and at about 0703 ST21 approached the Moonee Ponds Creek Bridge at about 100 km/h. The train speed was not reduced, and the train passed over the bridge and across the rough track location. The 24.4 km mark was at the east end of the bridge, the rough track was at around the 24.2 km mark, just past midway on the bridge, and the 24.0 km mark was just past the west end of the bridge (Figure 4).[7]
Figure 4: Moonee Ponds Creek Bridge, looking west towards Melbourne
The figure shows the two tracks that crossed the Moonee Ponds Creek Bridge. ST21 was travelling on the standard gauge track. Source: Chief Investigator, Transport Safety
At about 0705, ST21 approached the 21 km post. The driver noticed this km post and realised that the CAN warning for reduced speed may have referred to the section of track across the Moonee Ponds Creek Bridge, and not to the earlier section where they had reduced speed.
The driver of ST21 called the Mile End Network Control to clarify the correct location of the TSR and reported that they had reduced speed at the 24.4 km mark before Somerton.
The train continued to Southern Cross Station and arrived at 0831.
Context
Track information
The XPT service was operating on the interstate standard gauge track from Sydney to Melbourne. The track was part of the Defined Interstate Rail Network (DIRN) and was managed by the Australian Rail Track Corporation (ARTC).
For trains travelling toward Melbourne, the standard and broad gauge tracks ran parallel approaching Jacana before taking divergent routes. The standard gauge track crossed over the broad gauge at the Jacana Flyover and was routed via western Melbourne, whereas the broad gauge lines continued in a more direct route towards Melbourne (Figure 5). The standard gauge route between Jacana and Melbourne was about 27 km and the broad gauge route about 16 km.
Figure 5: Broad gauge and standard gauge routes to and from Melbourne
Source: Google Maps with annotations by the Chief Investigator, Transport Safety
To accommodate the longer standard gauge distance between Jacana and Melbourne, the standard gauge track included a step change in its kilometrage at the 27 km mark, measured from Southern Cross Station. For standard gauge trains travelling toward Melbourne, the kilometrage changed from 16 km to 27 km. This kilometrage change occurred on the Jacana Flyover and was sign posted (Figure 3).
As a result of this kilometrage change point, standard gauge trains travelling toward Melbourne would encounter the kilometrage marks between 27 and 16 km twice, on either side of the Jacana Flyover kilometrage change point.
Network control
Rail traffic on the ARTC network was managed from ARTC network control centres. Network Control Officers (NCO) located within the centres were responsible for the movement of trains and track vehicles in accordance with ARTC Safe Working Rules and Procedures.
Network control centres were assigned different regions. For the Sydney to Melbourne standard gauge route, the ARTC control centre in Junee managed the movement of trains between Sydney and Somerton signal SOM4, located about 21.8 rail-km from Melbourne. South of this signal, the Mile End control centre in South Australia was responsible for rail traffic. The NCO on the Melbourne Metro Network Control Board at Mile End covered the area from Somerton to Moonee Ponds Creek, Appleton Dock and North Dynon.
Junee Network Control was responsible for the control of signal SOM4, and required clearance from the NCO on the Mile End Melbourne Metro Network Control Board before releasing a train into the region controlled by Mile End Network Control.
The Condition Affecting Network (CAN) warning
In accordance with the ARTC Code of Practice, a Condition Affecting the Network (CAN) form was required to provide written warning to rail traffic when there was a temporary speed restriction and no signs erected.[8] The NCO responsible for the section was required to arrange for train crew to receive the CAN warning before they entered the affected portion of track, and dictate the CAN warning details to the crew. The train crew was required to acknowledge the CAN warning and in the case of a temporary speed restriction, proceed through the affected section at no greater than the specified reduced speed.
In this instance, the Condition Affecting the Network (CAN) warning was initiated following a report of rough track by the driver of a V/Line train, at 2121 the previous evening. ARTC placed a temporary speed restriction of 40 km/h at the location of rough track. The TSR was withdrawn at 0836 on 24 May after completion of works at the location.
Weather and visibility
On this day, civil twilight commenced at 0652 and sunrise was at 0721. There was no rain at the time and the visibility was clear.
Further investigation
To date, the ATSB has:
inspected the location of the occurrence
examined train operational information
examined radio communications between driver and network control
examined train control records
interviewed relevant parties
commenced collection of relevant procedural documentation
The investigation is continuing and will include further review and investigation of:
the track condition that led to the temporary speed restriction (TSR)
the operation of the train, including the circumstances that led to ST21 traversing Moonee Ponds Creek Bridge at a speed exceeding the TSR
the processes and risk controls associated with the establishment of a temporary speed restriction and its communication to drivers
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Australian Transport Safety Bureau
About the ATSB
The ATSB is an independent Commonwealth Government statutory agency. It is governed by a Commission and is entirely separate from transport regulators, policy makers and service providers.
The ATSB’s purpose is to improve the safety of, and public confidence in, aviation, rail and marine transport through:
independent investigation of transport accidents and other safety occurrences
safety data recording, analysis and research
fostering safety awareness, knowledge and action.
The ATSB is responsible for investigating accidents and other transport safety matters involving civil aviation, marine and rail operations in Australia, as well as participating in overseas investigations involving Australian-registered aircraft and ships. It prioritises investigations that have the potential to deliver the greatest public benefit through improvements to transport safety.
The ATSB performs its functions in accordance with the provisions of the Transport Safety Investigation Act 2003 and Regulations and, where applicable, international agreements.
Rail safety investigations in Victoria
Most transport safety investigations into rail accidents and incidents in Victoria and New South Wales (NSW) are conducted in accordance with the Collaboration Agreement for Rail Safety Investigations and Other Matters between the Commonwealth Government of Australia, the State Government of Victoria, and the State Government of New South Wales. Under the Collaboration Agreement, rail safety investigations are conducted and resourced in Victoria by the Chief Investigator, Transport Safety (CITS) and in New South Wales by the Office of Transport Safety Investigations (OTSI), on behalf of the ATSB, under the provisions of the Transport Safety Investigation Act 2003.
The Chief Investigator, Transport Safety(CITS) is a statutory position established in 2006 to conduct independent, no-blame investigation of transport safety matters in Victoria. CITS has a broad safety remit that includes the investigation of rail (including tram), marine and bus incidents.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available on the ATSB website. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
[1] All times stated are in Australian Eastern Standard Time (AEST). All arrival and departure times at stations are from the NSW Trains Timetable Report.
[2] Referred to as the Defined Interstate Rail Network (DIRN).
[3] Measured from Southern Cross Station, Melbourne.
[4] ARTC Network Control Centre West, Mile End, that was responsible for traffic control south of Somerton. This area included the section containing Moonee Ponds Creek Bridge.
[5] On passing this signal, control for ST21 transferred from the Junee to the Mile End Network Control.
[6] There was a step change in kilometrage at this point in the standard gauge track because its distance to Melbourne was 11 km longer than the broad gauge route. The change occurred on the Jacana Flyover, a short distance beyond the bridge where the standard gauge track passed over the broad gauge.
[7] The Moonee Ponds Creek Bridge was approximately 350 m long and extended from 24.40 km to 24.05 km marks.
[8]TA20 – ARTC Code of Practice for the Victorian Main Line Operations, Section 6d, Warning Rail Traffic